Port Monitoring
Port Monitoring
Port Monitoring is a feature that copies all incoming or outgoing packets on one port and forwards
(mirrors) them to another port. The source port is the monitored port (MD) and the destination port is the
monitoring port (MG). Port Monitoring functionality is dif ferent between platforms, but the behavior is the
same, with highlighted exceptions.
This chapter is divided into the following sections:
•
Important Points to Remember on page 787
•
Port Monitoring on E-Series on page 788
•
Port Monitoring on C-Series and S-Series on page 789
•
Configuring Port Monitoring on page 792
•
Flow-based Monitoring on page 793
Important Points to Remember
•
On the E-Series, Port Monitoring is supported on TeraScale and ExaScale platforms.
•
Port Monitoring is supported on physical ports only; VLAN and port-channel interfaces do not support
port monitoring.
•
A SONET port may only be a monitored port.
•
The Monitored (source, "MD") and Monitoring ports (destination, "MG") must be on the same switch.
•
In general, a monitoring port should have
FTOS permits a limited set of commands for monitoring ports; display them using the command
monitoring port also may not be a member of a VLAN.
•
There may only be one destination port in a monitoring session.
•
A source port (MD) can only be monitored by one destination port (MG). The following error is
displayed if you try to assign a monitored port to more than one monitoring port.
FTOS(conf)#mon ses 1
FTOS(conf-mon-sess-1)#$gig 0/0 destination gig 0/60 direction both
FTOS(conf-mon-sess-1)#do show mon ses
SessionID
---------
FTOS(conf-mon-sess-1)#mon ses 2
FTOS(conf-mon-sess-2)#source gig 0/0 destination gig 0/61 direction both
% Error: MD port is already being monitored.
is supported on platforms:
Source
------
1
Gi 0/0
e c s z
and
no ip address
no shutdown
Destination
Direction
-----------
---------
Gi 0/60
both
36
as the only configuration;
Mode
Type
----
----
interface
Port-based
Port Monitoring | 787
. A
?