Site icon KerKer 的模組世界

[Juniper] 交換器(Switch)埠鏡像(port mirroring)設定

<p>邊做邊學,順便留個筆記,若有錯誤請不吝指教。<&sol;p>&NewLine;<p>所有Juniper相關文章列表:<a href&equals;"https&colon;&sol;&sol;kerker&period;website&sol;juniper-junos-&percnt;E7&percnt;B3&percnt;BB&percnt;E5&percnt;88&percnt;97-&percnt;E6&percnt;96&percnt;87&percnt;E7&percnt;AB&percnt;A0&percnt;E5&percnt;88&percnt;97&percnt;E8&percnt;A1&percnt;A8&sol;">Juniper JunOS 系列文章列表<&sol;a><&sol;p>&NewLine;<p>埠鏡像&lpar;port mirroring&rpar;即將一個port上的流量複製一份到另一個port上,以達到監控、除錯等目的。<&sol;p>&NewLine;<p>以下為使用juniper EX-2200實作之方法:<&sol;p>&NewLine;<p><&excl;--more--><&sol;p>&NewLine;<ol>&NewLine;<li>接入switch ä¹‹å¾Œé€²å…¥é…ç½®æ¨¡å¼ã€‚<&sol;li>&NewLine;<&sol;ol>&NewLine;<pre>Juniper-SW&colon;RE&colon;0&percnt; cli&NewLine;&NewLine;Juniper-SW&gt&semi; edit&NewLine;<&sol;pre>&NewLine;<ol start&equals;"2">&NewLine;<li>配置要mirroring的port,這裡可以選擇要監控的流向&lpar;ingress、egress&rpar;,本次實作則是將兩個配置都做了。指令中的PM1為該鏡像的名稱,可以視自己管理方便配置。<&sol;li>&NewLine;<&sol;ol>&NewLine;<pre>Juniper-SW&num;set ethernet-switching-options analyzer PM1 input egress interface ge-0&sol;0&sol;0&period;0&NewLine;&NewLine;Juniper-SW&num;set ethernet-switching-options analyzer PM1 input ingress interface ge-0&sol;0&sol;0&period;0&NewLine;<&sol;pre>&NewLine;<ol start&equals;"3">&NewLine;<li>配置用來進行監控的port。<&sol;li>&NewLine;<&sol;ol>&NewLine;<pre>Juniper-SW&num;set ethernet-switching-options analyzer PM1 output interface ge-0&sol;0&sol;10&period;0&NewLine;<&sol;pre>&NewLine;<ol start&equals;"4">&NewLine;<li>配置完成後使用show指令進行檢查。<&sol;li>&NewLine;<&sol;ol>&NewLine;<p>Juniper-SW&num; show ethernet-switching-options<&sol;p>&NewLine;<p>如果成功則可以看到內容如下<&sol;p>&NewLine;<pre>analyzer PM1 &lbrace;&NewLine; input &lbrace;&NewLine; ingress &lbrace;&NewLine; interface ge-0&sol;0&sol;0&period;0&semi;&NewLine; &rcub;&NewLine; egress &lbrace;&NewLine; interface ge-0&sol;0&sol;0&period;0&semi;&NewLine; &rcub;&NewLine; &rcub;&NewLine; output &lbrace;&NewLine; interface &lbrace;&NewLine; ge-0&sol;0&sol;10&period;0&semi;&NewLine; &rcub;&NewLine; &rcub;&NewLine;&rcub;&NewLine;<&sol;pre>&NewLine;<ol start&equals;"5">&NewLine;<li>可以使用wireshark在port ge-0&sol;0&sol;10擷取封包測試是否能擷取到送往ge-0&sol;0&sol;0的封包。另外需注意的是用來監控的port是無法連上internet的,且該port也不能配置任何vlan設定。<&sol;li>&NewLine;<&sol;ol>&NewLine;

Exit mobile version