VLAN-based Mirroring

The VLAN-based mirroring feature allows users to monitor all incoming traffic in one or more VLANs by sending a mirror image of that traffic to a configured mirror port. This feature meets the requirements of CALEA (Communications Assistance for Law Enforcement Act of 1994).

Configuration Notes for VLAN-based Mirroring

The following guidelines apply to VLAN-based mirroring configurations:

  • A VLAN must have at least one port member configured before monitoring can be configured.
  • Multiple VLANs can have monitoring enabled at the same time, and the maximum number of monitor-configured VLANs is 200 for ICX 7150 and 256 for all other RUCKUS ICX devices.
  • The mirror port is subject to the same scheduling and bandwidth management as the other ports in the system. If the amount of traffic being sent to the mirror port exceeds the available bandwidth, some of that traffic may be dropped.
  • All incoming traffic (tagged and untagged) in the VLAN is mirrored. mirroring is "as-is", and is not affected by the configuration of the mirror port itself. Incoming tagged traffic is sent out tagged and incoming untagged traffic is sent out untagged, regardless of which VLANs the mirror port belongs to, and whether the mirror port is tagged or untagged.
  • VLAN-based mirroring is supported on Layer 2 and Layer 3 images.
  • The ACL mirror filter can be added even if a Layer 2 VLAN is not present.
  • Layer 2 VLAN modification will not modify the ACL mirror filter.
  • The VLAN mirror configuration under the multi VLAN configuration mode depends on the number of VLANs and the platform. The configuration process can take up to 50 seconds to complete
  • ARP packets are not mirrored.