Solved

Port mirroring

Posted on 2009-07-01
5
455 Views
Last Modified: 2012-08-13
I have one main switch, and 4 other switches which are connected on a LAG.
I want to be able to monitor all of these switches with my software. Right now my main switch has a port mirror port setup plugged into a nic of a server. That port mirror is mirroring many ports. The problem is i cannot mirror the LAG connections hence i can't get data for those 4 siwtches.

Can I setup a port monitor on the 4 switches, then plug those 4 port monitors into a dummy switch, which is in turn plugged into a nic to my server/ or will that cause problems with traffic boucning or like a loop?

so SWITCH 1 ---> DUMMY SWITCH <--- SWITCH 2
                                        |
                                        |
                                       V
                                  NIC on server
0
Comment
Question by:shankshank
  • 3
  • 2
5 Comments
 
LVL 14

Accepted Solution

by:
steveoskh earned 500 total points
ID: 24758489
Not sure I know the term LAG.   The problem with this is total traffic.  If you have 20 PC's on each switch all connected at 100mb and a gig connection to your monitor box you will quickly over load the pipe going to your monitor.   In your diagram, if the dummy switch was a hub the nic on your server would see all the traffic from the monitor ports feeding the hub.  Here again with Hubs limited to 100mb, you probably have too much traffic.
You could have PC's on each switch that capture the traffic and then load the files into the server for analysis.  This could work especially well since you could limit the packet to just specific data and not capture everything.  
Do you have a lot of port to port traffic on your outer switches?   In other words if your main switch has your servers and Internet connection most of the traffic will pass through that switch and you would capture the traffic you need.
0
 
LVL 5

Author Comment

by:shankshank
ID: 24772593
LAG is when you take multiple ports and connect them to another switch. giving more throughput and if one cable port fails there is faillover.

so right now I have my ASA5505 device and a few other servers setup to port mirror on one port. The machine on that mirror port is running NTOP. I'm not seeing the data I want to see though. I mean i see some, but it seems liek there should be FAR more communication on the port with the ASA
0
 
LVL 14

Expert Comment

by:steveoskh
ID: 24772862
Sorry, I don't use Cisco gear, so I was not familiar with the term.  I assume you are also using Cisco switches?  You may need to look into the switch specs to see what it does with monitor traffic if there is more than it can handle.   Like a lot of things, monitoring is a trade off of differing goals.
If you want to monitor primarily web traffic, just monitor the port going to the ASA.
If you want to monitor all traffic happening on your network, you have a problem.   If I understand correctly you have multiple duplex gigabit connections between switches.  You want to send this traffic to a server through a simplex gigabit connection.  As you are seeing there is more traffic than the switch or your server can process and the packets are dropped.
Using the mirror port on my HP switches has been adequate for my needs, but I am monitoring 100mb ports mirrored to a gig port so the traffic volume was not an issue.
A network tap (I have not used one) on the uplinks splits the traffic into a seperate send and receive stream allowing a monitoring device to see the full traffic.
With my HP switches I can see graphically how much traffic is on each port.   If you can do something similar with your switch, how much traffic are you seeing on the monitor port?
0
 
LVL 5

Author Comment

by:shankshank
ID: 24772874
Well I just setup the port with the ASA5505 to mirror, and I am not seeing like detailed web traffic etc..

The LAG term was with the dell switch.

0
 
LVL 14

Expert Comment

by:steveoskh
ID: 24773041
Are you seeing any traffic from other machines?  Or are you only seeing broadcast and traffic to and from this particular server.   Some nics did not support a promiscuos mode and would drop other traffic.  Some monitor programs only work with specific brands or model NIC's.

This question may pertain
http://www.experts-exchange.com/Hardware/Networking_Hardware/Switches/Q_23403785.html

From http://supportapj.dell.com/support/edocs/network/pc33xx/en/33xxrnot.pdf
LAG ports can not be mirrored.
In cases where both source and destination ports are Gigabit ports, some of the packets may be dropped due to the stacking management traffic.

Another post indicated that VLAN traffic will not mirror on Dell switches.

I have found some switches need to be reset before they will mirror.  I could not confirm this for Dell.
Have you checked for any patches or firmware updates to the switch?  

I did find  http://www.miarec.com/knowledge/how-configure-port-mirroring-dell-powerconnect-2700-series which indicates a change to managed mode is required.   I doubt this applies to your situation.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
forward schedule of change 1 51
policy routing to fw2 18 68
DNS and NSLOOKUP 21 74
Microsoft Surface Pro 4 networking 4 30
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question