acl-mirror-port
Interface configuration mode
Use this command to set the destination port on which the traffic must be mirrored. The destination port must be the same for all ports in a port region. All traffic mirrored from any single port in a port region is mirrored to the same destination mirror port as traffic mirrored from any other port in the same port region. When a destination port is configured for any port within a port region, traffic from any ACL with a mirroring clause assigned to any port in that port region is mirrored to that destination port. This will occur even if a destination port is not explicitly configured for the port with the ACL configured.
To configure ACL-based mirroring for ACLs bound to virtual interfaces, use the
acl-mirror-port command on a physical port that is a member of the same VLAN as the virtual interface.
You can apply ACL-based mirroring on an entire VE, and enable mirroring in only one
port region; traffic that is in the same VE but on a port in a different port region
will not be mirrored. If a port is in both mirrored and non-mirrored VLANs, only traffic
on the port from the mirrored VLAN is mirrored.
The following example shows the ACL mirroring traffic from port 1/1/1 is mirrored to port 1/1/3.
device(config)# interface ethernet 1/1/1 device(config-if-e10000-1/1/1)# acl-mirror-port ethernet 1/1/3
The following example shows that ports from a port region must be mirrored to the same destination mirror port.
device(config)# interface ethernet 1/1/1 device(config-if-e10000-1/1/1)# acl-mirror-port ethernet 1/2/3 device(config)# interface ethernet 1/1/2 device(config-if-e10000-1/1/2)# acl-mirror-port ethernet 1/2/3
The following example shows ACL mirroring when the destination port within a port region is configured.
device(config)# interface ethernet 1/1/1 device(config-if-e10000-1/1/1)# ip access-group 101 in device(config)# interface ethernet 1/1/3 device(config-if-e10000-1/1/3)# acl-mirror-port ethernet 1/4/3
The following example shows how to specify the destination mirror port for LAG ports.
device(config)# lag blue static id 1 device(config-lag-blue)# ports ethernet 1/1/1 to 1/1/14 device(config)# interface ethernet 1/1/1 device(config-if-e10000-1/1/1)# acl-mirror-port ethernet 1/1/8
The following example shows how to configure ACL-based mirroring for ACLs bound to virtual interfaces.
device# configure terminal device(config)# vlan 10 device(config-vlan-10)# tagged ethernet 1/4/1 to 1/4/2 device(config-vlan-10)# tagged ethernet 1/5/3 device(config-vlan-10)# interface ve 10 device(config-vlan-10)# exit device(config)# ip access-list extended acl102 device(config-ext-ipacl-acl102)# permit ip any any mirror device(config-ext-ipacl-acl102)# exit device(config)# interface ethernet 1/4/1 device(config-if-e10000-1/4/1)# acl-mirror-port ethernet 1/5/1 device(config-if-e10000-1/4/1)# exit device(config)# interface ve 10 device(config-vif-10)# ip address 10.10.10.254/24 device(config-vif-10)# ip access-group acl102 in device(config-vif-10)# end device#
The following example shows the ACL-based mirroring for ports in both mirrored and non-mirrored VLANs.
device# configure terminal device(config)# vlan 10 device(config-vlan-10)# tagged ethernet 1/4/1 to 1/4/2 device(config-vlan-10)# tagged ethernet 1/5/3 device(config-vlan-10)# interface ve 10 device(config-vlan-10)# exit device(config)# vlan 20 device(config-vlan-20)# tagged ethernet 1/4/1 to 1/4/2 device(config-vlan-20)# exit device(config)# ip access-list extended acl102 device(config-ext-ipacl-acl102)# permit ip any any mirror device(config-ext-ipacl-acl102)# exit device(config)# interface ethernet 1/4/1 device(config-if-e10000-1/4/1)# acl-mirror-port ethernet 1/5/1 device(config-if-e10000-1/4/1)# exit device(config)# interface ve 10 device(config-vif-10)# ip address 10.10.10.254/24 device(config-vif-10)# ip access-group acl102 in device(config-vif-10)# end device#