Solved

Port mirroring

Posted on 2009-07-01
5
453 Views
Last Modified: 2012-08-13
I have one main switch, and 4 other switches which are connected on a LAG.
I want to be able to monitor all of these switches with my software. Right now my main switch has a port mirror port setup plugged into a nic of a server. That port mirror is mirroring many ports. The problem is i cannot mirror the LAG connections hence i can't get data for those 4 siwtches.

Can I setup a port monitor on the 4 switches, then plug those 4 port monitors into a dummy switch, which is in turn plugged into a nic to my server/ or will that cause problems with traffic boucning or like a loop?

so SWITCH 1 ---> DUMMY SWITCH <--- SWITCH 2
                                        |
                                        |
                                       V
                                  NIC on server
0
Comment
Question by:shankshank
  • 3
  • 2
5 Comments
 
LVL 14

Accepted Solution

by:
steveoskh earned 500 total points
Comment Utility
Not sure I know the term LAG.   The problem with this is total traffic.  If you have 20 PC's on each switch all connected at 100mb and a gig connection to your monitor box you will quickly over load the pipe going to your monitor.   In your diagram, if the dummy switch was a hub the nic on your server would see all the traffic from the monitor ports feeding the hub.  Here again with Hubs limited to 100mb, you probably have too much traffic.
You could have PC's on each switch that capture the traffic and then load the files into the server for analysis.  This could work especially well since you could limit the packet to just specific data and not capture everything.  
Do you have a lot of port to port traffic on your outer switches?   In other words if your main switch has your servers and Internet connection most of the traffic will pass through that switch and you would capture the traffic you need.
0
 
LVL 5

Author Comment

by:shankshank
Comment Utility
LAG is when you take multiple ports and connect them to another switch. giving more throughput and if one cable port fails there is faillover.

so right now I have my ASA5505 device and a few other servers setup to port mirror on one port. The machine on that mirror port is running NTOP. I'm not seeing the data I want to see though. I mean i see some, but it seems liek there should be FAR more communication on the port with the ASA
0
 
LVL 14

Expert Comment

by:steveoskh
Comment Utility
Sorry, I don't use Cisco gear, so I was not familiar with the term.  I assume you are also using Cisco switches?  You may need to look into the switch specs to see what it does with monitor traffic if there is more than it can handle.   Like a lot of things, monitoring is a trade off of differing goals.
If you want to monitor primarily web traffic, just monitor the port going to the ASA.
If you want to monitor all traffic happening on your network, you have a problem.   If I understand correctly you have multiple duplex gigabit connections between switches.  You want to send this traffic to a server through a simplex gigabit connection.  As you are seeing there is more traffic than the switch or your server can process and the packets are dropped.
Using the mirror port on my HP switches has been adequate for my needs, but I am monitoring 100mb ports mirrored to a gig port so the traffic volume was not an issue.
A network tap (I have not used one) on the uplinks splits the traffic into a seperate send and receive stream allowing a monitoring device to see the full traffic.
With my HP switches I can see graphically how much traffic is on each port.   If you can do something similar with your switch, how much traffic are you seeing on the monitor port?
0
 
LVL 5

Author Comment

by:shankshank
Comment Utility
Well I just setup the port with the ASA5505 to mirror, and I am not seeing like detailed web traffic etc..

The LAG term was with the dell switch.

0
 
LVL 14

Expert Comment

by:steveoskh
Comment Utility
Are you seeing any traffic from other machines?  Or are you only seeing broadcast and traffic to and from this particular server.   Some nics did not support a promiscuos mode and would drop other traffic.  Some monitor programs only work with specific brands or model NIC's.

This question may pertain
http://www.experts-exchange.com/Hardware/Networking_Hardware/Switches/Q_23403785.html

From http://supportapj.dell.com/support/edocs/network/pc33xx/en/33xxrnot.pdf
LAG ports can not be mirrored.
In cases where both source and destination ports are Gigabit ports, some of the packets may be dropped due to the stacking management traffic.

Another post indicated that VLAN traffic will not mirror on Dell switches.

I have found some switches need to be reset before they will mirror.  I could not confirm this for Dell.
Have you checked for any patches or firmware updates to the switch?  

I did find  http://www.miarec.com/knowledge/how-configure-port-mirroring-dell-powerconnect-2700-series which indicates a change to managed mode is required.   I doubt this applies to your situation.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Don’t let your business fall victim to the coming apocalypse – use our Survival Guide for the Fax Apocalypse to identify the risks and signs of zombie fax activities at your business.
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now