Services on the QFX Series - Juniper.net
Services on the QFX Series - Juniper.net
Services on the QFX Series - Juniper.net
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
CHAPTER 4<br />
C<strong>on</strong>figurati<strong>on</strong> Tasks<br />
C<strong>on</strong>figuring Port Mirroring<br />
• C<strong>on</strong>figuring Port Mirroring <strong>on</strong> page 23<br />
• C<strong>on</strong>figuring DHCP and BOOTP Relay <strong>on</strong> page 26<br />
You use port mirroring to copy packets and send <strong>the</strong> copies to a device running an<br />
applicati<strong>on</strong> such as a <strong>net</strong>work analyzer or intrusi<strong>on</strong> detecti<strong>on</strong> applicati<strong>on</strong> so that you can<br />
analyze traffic without delaying it. You can mirror traffic entering or exiting a port or<br />
entering a VLAN, and you can send <strong>the</strong> copies to a local access interface or to a VLAN<br />
through a trunk interface.<br />
We recommend that you disable port mirroring when you are not using it. To avoid creating<br />
a performance issue If you do enable port mirroring, we recommend that you select<br />
specific input interfaces instead of using <strong>the</strong> all keyword. You can also limit <strong>the</strong> amount<br />
of mirrored traffic by using a firewall filter.<br />
NOTE: If you want to create additi<strong>on</strong>al analyzers without deleting an existing<br />
analyzer, first disable <strong>the</strong> existing analyzer using <strong>the</strong> disable analyzer<br />
analyzer-name command.<br />
NOTE: You must c<strong>on</strong>figure port mirroring output interfaces as family<br />
e<strong>the</strong>r<strong>net</strong>-switching.<br />
• C<strong>on</strong>figuring Port Mirroring for Local Analysis <strong>on</strong> page 23<br />
• C<strong>on</strong>figuring Port Mirroring for Remote Analysis <strong>on</strong> page 24<br />
• Filtering <strong>the</strong> Traffic Entering an Analyzer <strong>on</strong> page 25<br />
C<strong>on</strong>figuring Port Mirroring for Local Analysis<br />
To mirror interface traffic to a local interface <strong>on</strong> <strong>the</strong> switch:<br />
1. If you want to mirror traffic that is ingressing or egressing specific interfaces, choose<br />
a name for <strong>the</strong> port-mirroring c<strong>on</strong>figurati<strong>on</strong> and c<strong>on</strong>figure what traffic should be<br />
mirrored by specifying <strong>the</strong> interfaces and directi<strong>on</strong> of traffic:<br />
Copyright © 2013, <strong>Juniper</strong> Networks, Inc.<br />
23