Policy-Based Mirroring

You can now apply mirrors to policy profile rules by using a "control group" mirror referenced by a unique control index number. These control group mirrors are etsysMirrorDestinationControlEntry entries in the ENTERASYS-MIRROR-CONFIG-MIB (Mirror MIB). A Mirror MIB instance (designated by a control index) can be associated with up to four "physical" mirrors, each being one destination port (or tunnel).

Supported Platforms

Summit X450-G2, X460-G2, X670-G2, and ExtremeSwitching X440-G2, X465, X590, X620, X690, X870 series switches.

Limitations

  • Mirrors with multiple destination ports are not supported.
  • A maximum of four concurrently enabled mirrors is supported.
  • A maximum of four control group (Mirror MIB) instances can be created using the CLI.
  • Mirrors on admin profile rules are not supported.
  • Mirroring cannot be enabled on LAG and MLAG ports.
  • Mirroring index cannot be assigned for default mirrors.

New CLI Commands

create mirror control_index

configure mirror control_index [ add | delete ] mirror_name

enable mirror control_index {mirror mirror_name}

disable mirror control_index {mirror mirror_name}

Changed CLI Commands

Changes are underlined.

configure policy rule profile_index [ether ether | icmp6type icmp6type | icmptype icmptype | ip6dest ip6dest |ipdestsocket ipdestsocket | ipfrag | ipproto ipproto | ipsourcesocket ipsourcesocket | iptos iptos | ipttl ipttl | macdest macdest | macsource macsource | port port | tcpdestportIP tcpdestportIP | tcpsourceportIP tcpsourceportIP | udpdestportIP udpdestportIP | udpsourceportIP udpsourceportIP ] {mask mask } {port-string [ port_string | all]} {storage-type [non-volatile | volatile]} {drop | forward} {syslog syslog} {trap trap} {cos cos } {mirror-destination control_index} {clear-mirror}

delete mirror mirror_name {control_index} | all]

show mirror [mirror_name | control_index | mirror_name_li] | [all | enabled]

The following show commands now display mirror action information:

show policy capability

show policy rule {all | {profile-index profile_index | admin-profile} ether {ether} | icmp6type {icmp6type} | icmptype {icmptype} | ip6dest {ip6dest} | ipdest {ipdest} | ipfrag | ipproto {ipproto} | ipsource { ipsource } | iptos { iptos } | ipttl { ipttl } | macdest { macdest } | macsource { macsource } | port { port } | tcpdestportIP { tcpdestportIP } | tcpsourceportIP { tcpsourceportIP } | udpdestportIP { udpdestportIP } | udpsourceportIP { udpsourceportIP }} {mask mask } {port-string [ port_string | all]} {storage-type [non-volatile | volatile]} {drop | forward} {cos cos | admin-pid admin_pid }} {detail | wide} {port-hit}