Configuring Layer 3 remote port mirroring example
Network requirements
On the network shown in
Device A connects to the marketing department through GigabitEthernet 1/0/1, and to
•
GigabitEthernet 1/0/1 of Device B through GigabitEthernet 1/0/2; Device C connects to the server
through GigabitEthernet 1/0/2, and to GigabitEthernet 1/0/2 of Device B through GigabitEthernet
1/0/1.
Configure Layer 3 remote port mirroring to enable the server to monitor the bidirectional traffic of
•
the marketing department through a GRE tunnel.
Figure 70 Network diagram for Layer 3 remote port mirroring configuration
Source
device
Device A
GE1/0/1
VLAN-int10
10.1.1.1/24
Marketing
Dept.
Configuration procedure
Configure IP addresses for the tunnel interfaces and related ports on the devices.
1.
Configure IP addresses and subnet masks for related ports and the tunnel interfaces according to the
configurations shown in
Configure Device A (the source device)
2.
# Create tunnel interface Tunnel 0, and configure an IP address and subnet mask for it.
<DeviceA> system-view
[DeviceA] interface tunnel 0
[DeviceA-Tunnel0] ip address 50.1.1.1 24
# Configure Tunnel 0 to operate in GRE mode, and configure source and destination IP addresses for it.
[DeviceA-Tunnel0] tunnel-protocol gre
[DeviceA-Tunnel0] source 20.1.1.1
[DeviceA-Tunnel0] destination 30.1.1.2
[DeviceA-Tunnel0] quit
# Create and configure service loopback group 1 and specify its service type as tunnel.
[DeviceA] service-loopback group 1 type tunnel
# Assign a port (GigabitEthernet 1/0/3 for example) of the device to service loopback group 1.
[DeviceA] interface GigabitEthernet 1/0/3
[DeviceA-GigabitEthernet1/0/3] undo stp enable
Figure
70,
Intermediate
GE1/0/2
GE1/0/2
VLAN-int11
VLAN-int11
20.1.1.1/24
20.1.1.2/24
GRE tunnel
Tunnel0
50.1.1.1/24
Common port
Figure
70.
device
Device B
GE1/0/1
VLAN-int12
30.1.1.1/24
50.1.1.2/24
Source port
Monitor port
186
Destination
device
GE1/0/1
Device C
VLAN-int12
30.1.1.2/24
GE1/0/2
VLAN-int10
40.1.1.1/24
Tunnel0
Server