acl-mirror-port

Configures ACL-based inbound mirroring.
Syntax
acl-mirror-port ethernet unit/slot/port
no acl-mirror-port ethernet unit/slot/port
Parameters
ethernet unit/slot/port
Specifies the mirror port to which the monitored port traffic is copied.
Modes

Interface configuration mode

Usage Guidelines

Use this command to set the destination port on which the traffic must be mirrored. The destination port must be the same for all ports in a port region. All traffic mirrored from any single port in a port region is mirrored to the same destination mirror port as traffic mirrored from any other port in the same port region. When a destination port is configured for any port within a port region, traffic from any ACL with a mirroring clause assigned to any port in that port region is mirrored to that destination port. This will occur even if a destination port is not explicitly configured for the port with the ACL configured.

To configure ACL-based mirroring for ACLs bound to virtual interfaces, use the acl-mirror-port command on a physical port that is a member of the same VLAN as the virtual interface. You can apply ACL-based mirroring on an entire VE, and enable mirroring in only one port region; traffic that is in the same VE but on a port in a different port region will not be mirrored. If a port is in both mirrored and non-mirrored VLANs, only traffic on the port from the mirrored VLAN is mirrored.

Note: If a destination mirror port is not configured for any ports within the port region where the port-mirroring ACL is configured, the ACL does not mirror the traffic but the ACL is applied to traffic on the port.

The no form of the command removes the ACL mirror port.

Examples

The following example shows the ACL mirroring traffic from port 1/1/1 is mirrored to port 1/1/3.

device(config)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# acl-mirror-port ethernet 1/1/3

The following example shows that ports from a port region must be mirrored to the same destination mirror port.

device(config)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# acl-mirror-port ethernet 1/2/3
device(config)# interface ethernet 1/1/2
device(config-if-e10000-1/1/2)# acl-mirror-port ethernet 1/2/3

The following example shows ACL mirroring when the destination port within a port region is configured.

device(config)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# ip access-group 101 in
device(config)# interface ethernet 1/1/3
device(config-if-e10000-1/1/3)# acl-mirror-port ethernet 1/4/3

The following example shows how to specify the destination mirror port for LAG ports.

device(config)# lag blue static id 1
device(config-lag-blue)# ports ethernet 1/1/1 to 1/1/14
device(config)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# acl-mirror-port ethernet 1/1/8

The following example shows how to configure ACL-based mirroring for ACLs bound to virtual interfaces.

device# configure terminal
device(config)# vlan 10
device(config-vlan-10)# tagged ethernet 1/4/1 to 1/4/2
device(config-vlan-10)# tagged ethernet 1/5/3
device(config-vlan-10)# interface ve 10
device(config-vlan-10)# exit
device(config)# ip access-list extended acl102
device(config-ext-ipacl-acl102)# permit ip any any mirror
device(config-ext-ipacl-acl102)# exit
device(config)# interface ethernet 1/4/1
device(config-if-e10000-1/4/1)# acl-mirror-port ethernet 1/5/1
device(config-if-e10000-1/4/1)# exit
device(config)# interface ve 10
device(config-vif-10)# ip address 10.10.10.254/24
device(config-vif-10)# ip access-group acl102 in
device(config-vif-10)# end
device#

The following example shows the ACL-based mirroring for ports in both mirrored and non-mirrored VLANs.

device# configure terminal
device(config)# vlan 10
device(config-vlan-10)# tagged ethernet 1/4/1 to 1/4/2
device(config-vlan-10)# tagged ethernet 1/5/3
device(config-vlan-10)# interface ve 10
device(config-vlan-10)# exit
device(config)# vlan 20
device(config-vlan-20)# tagged ethernet 1/4/1 to 1/4/2
device(config-vlan-20)# exit
device(config)# ip access-list extended acl102
device(config-ext-ipacl-acl102)# permit ip any any mirror
device(config-ext-ipacl-acl102)# exit
device(config)# interface ethernet 1/4/1
device(config-if-e10000-1/4/1)# acl-mirror-port ethernet 1/5/1
device(config-if-e10000-1/4/1)# exit
device(config)# interface ve 10
device(config-vif-10)# ip address 10.10.10.254/24
device(config-vif-10)# ip access-group acl102 in
device(config-vif-10)# end
device#