Configuring ACL-based Mirroring for ACLs Bound to Virtual Interfaces
For configurations that have an ACL configured for ACL-based mirroring bound to a VLAN, you must use the acl-mirror-port command on a physical port that is a member of the same VLAN. Additionally, only traffic that arrives at ports that belong to the same port group as the physical port where this command has been used is mirrored. This follows the same rules described in Specifying the destination mirror port for physical ports.
For example, in the following configuration, ports 1/1/7, 1/1/8, and 1/1/26 are in VLAN 222. Ports 1/1/7 and 1/1/8 belong to the same port group, while port 1/1/26 belongs to another port group.
device# configure terminal device(config)# vlan 222 device(config-vlan-222)# tagged ethernet 1/1/7 to 1/1/8 device(config-vlan-222)# tagged ethernet 1/1/26 device(config)# interface ethernet 1/1/7 device(config-if-e10000-1/1/7)# acl-mirror-port ethernet 1/1/1 device(config-if-e10000-1/1/7)# exit device(config)# ip access-list extended mirror-1 device(config-ext-ipacl-mirror-1)# permit ip any any mirror device(config-ext-ipacl-mirror-1)# exit device(config)# vlan 222 device(config-vif-222)# ip access-group mirror-1 in Extended IP access list mirror-1: 1 entries 10: permit ip any any mirror
In this configuration, the ACL-mirror-port command is applied to port 1/1/7, which is a member of VLAN 222. Because of this, ACL-based mirroring will only apply to VLAN 222 traffic that arrives on ports 1/1/7 and 1/1/8. It will not apply to VLAN 222 traffic that arrives on port 1/1/26 because that port belongs to a port group different from ports 1/1/7 and 1/1/8. This is because if you apply ACL-based mirroring on an entire VLAN, and enable mirroring in only one port region, traffic that is in the same VLAN but on a port in a different port region will not be mirrored.
To make the configuration apply ACL-based mirroring to VLAN 222 traffic arriving on port 1/1/26, you must add the following commands to the configuration.
device(config)# interface ethernet 1/5/3 device(config-if-e10000-1/5/3)# acl-mirror-port ethernet 1/1/1
If a port is in both mirrored and non-mirrored VLANs, only traffic on the port from the mirrored VLAN is mirrored. For example, the following configuration adds VLAN 225 to the previous configuration. In this example, ports 1/1/7 and 1/1/8 are in both VLAN 222 and VLAN 225. ACL-based mirroring is only applied to VLAN 222. Consequently, traffic that is on ports 1/1/7 and 1/1/8 that belongs to VLAN 225 will not be mirrored.
device(config)# vlan 222 device(config-vlan-222)# tagged ethernet 1/1/7 to 1/1/8 device(config-vlan-222)# tagged ethernet 1/1/26 device(config)# vlan 225 device(config-vlan-225)# tagged ethernet 1/1/7 to 1/1/8 device(config)# interface ethernet 1/1/7 device(config-if-e10000-1/1/7)# acl-mirror-port ethernet 1/1/1 device(config-if-e10000-1/1/7)# exit device(config)# ip access-list extended mirror-1 device(config-ext-ipacl-mirror-1)# permit ip any any mirror device(config-ext-ipacl-mirror-1)# exit device(config)# vlan 222 device(config-vif-222)# ip access-group mirror-1 in Extended IP access list mirror-1: 1 entries 10: permit ip any any mirror