Solved

Looking for a switch to do VLAN mirroring or port mirroring with several ports

Posted on 2013-06-13
8
763 Views
Last Modified: 2016-11-23
Hello All,
We are looking at a product called LANGuardian. It's an agentless software that will allow us to track network traffic. The way it work is with port mirroring. My "gotcha" if you will, is that I have several physical servers that I would like to mirror as well, especially our shared storage. Currently we use Dell PowerConnect switches. They only allow for up to 4 source ports. I would probably need close to 30, maybe more. Someone mentioned to me Cisco Catalyst, HP or 3Com. I am not familiar with them so I am in the dark and was hoping someone else has done something similar and can recommend a switch that will do what I need. I've also been told that VLAN mirroring should work but I'm getting different explanations on what that really is.
0
Comment
Question by:msidnam
  • 4
  • 3
8 Comments
 
LVL 15

Expert Comment

by:max_the_king
ID: 39244655
Hi,
I use cisco catalyst to do this, although i do not use LANGuardian (i use CAPSA) and it works really well.
Here is a link with full explanation

http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_55_se/configuration/guide/swspan.html

also, be aware that cisco models will vary on price if you want gigabit (1000) ports or FastEthernet ports (10/100).

hope this helps
max
0
 
LVL 2

Author Comment

by:msidnam
ID: 39245538
Thank you. do you monitor several ports on one switch or do you use the VLAN mirroring?
0
 
LVL 7

Expert Comment

by:unfragmented
ID: 39246431
I see mirroring (SPAN) on a switch as a secondary function, and not something a switch was designed to do.  I suspect thats why many switches are limited to only a few concurrent mirroring sessions.

If you need to monitor a large number of ports, you may want to consider network taps instead, which obviously do not impact the network switch.
0
 
LVL 15

Expert Comment

by:max_the_king
ID: 39246900
Hi msidnam,
i monitor all the ports of the switch through the one that i choose to redirect the mirror, and i even span across multiple switches.
Basically you need to choose one port tht listens to all the others and send the results to the software that analyzes the traffic, in your case LANGuardian. Please note that when you do a mirror of the port, that port is really not accessible on the network, because it just listens to all the traffic: this means, in other words, that you can reach the LANGuardian machine only on its console, and not by any other means (rdp, remote access, and the like).

hope this helps
max
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 2

Author Comment

by:msidnam
ID: 39249155
I have a demo of the LANGuardian working, it just seems that if i need to monitor more than 4 physical servers i may have issues.
0
 
LVL 15

Expert Comment

by:max_the_king
ID: 39255988
Hi,
this is from languardian website:
http://www.netfort.com/languardian/architecture
it seems you shouldn't have problems on mirroring multiple ports.
It may be a limitation of your trial version.

Port monitoring
back to top Most network core switches have the ability to copy network traffic from one port on the switch to another. This feature, which is called port monitoring or port mirroring, enables LANGuardian to capture traffic data for analysis.

Port monitoring is given different names by different switch vendors:

    On a Cisco Systems switch, port monitoring is called Switched Port Analyzer (SPAN). You will often see references in the documentation to a SPAN port.
    On 3Com switches, it is called a Roving Analysis Port (RAP).
    The documentation for HP switches uses the term trunk monitoring.

Configuring a monitoring port on your switch involves the following steps:

    Identify an unused switch port to designate as a monitoring port for LANGuardian.
    Identify the switch ports you want to monitor (these are often called source ports).
    Configure the switch to associate the source ports with the monitoring port.

The switch will send a copy to the monitoring port of all data flowing through the source ports. LANGuardian captures the data from the monitoring port for analysis. The actual data itself is not affected and there is no performance impact.

max
0
 
LVL 2

Author Comment

by:msidnam
ID: 39256103
I guess my biggest question is will the cisco catalayst (or another switch) be able to monitor more than 20 ports at a time to one destination port?

I have the LANGuardian configured and working with no problem. However, my Dell 6248P can only monitor 4 ports and i have around 15 or more physical server that i want monitored  including the router which will grab anything on the edge.
0
 
LVL 15

Accepted Solution

by:
max_the_king earned 500 total points
ID: 39256136
Hi,
yes, you can monitor all the ports you want and mirror their content to the port where the LanGuardian is.
I do it with Colasoft Capsa software and Cisco catalyst 2960G.

max
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now