<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Restrictions of port mirroring on SecureStacks in ExtremeSwitching (Other)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-other/restrictions-of-port-mirroring-on-securestacks/m-p/11079#M2107</link>
    <description>Hi folks,&lt;BR /&gt;
&lt;BR /&gt;
i see some odd behavior in mirrored traffic on the customer side, and i am right now unsure if this need deeper investigation. Or can be clarified in the way how mirror ports are treated on enterasys.&lt;BR /&gt;
&lt;BR /&gt;
So i did a quick lab setup also also see similar odd behavior.&lt;BR /&gt;
&lt;BR /&gt;
(Host 172.16.31.164) &amp;lt;----&amp;gt; (Port48)(Switch C3)(Port48) &amp;lt;----&amp;gt; (Port 24)(Switch A2 IP adress 172.16.31.251 / host vlan 1)&lt;BR /&gt;
&lt;BR /&gt;
C3&lt;BR /&gt;
ge.1.30        31         N          untagged: 31 (traffic generator)&lt;BR /&gt;
ge.1.34        31         N          untagged: 31 (mirror Host)&lt;BR /&gt;
ge.1.48        31         N          untagged: 31 tagged: 2708,2732,2733,2734,2736&lt;BR /&gt;
&lt;BR /&gt;
A2&lt;BR /&gt;
fe.1.24        1          N          untagged: 1 tagged: 2708,2732,2733,2734,2736&lt;BR /&gt;
&lt;BR /&gt;
So when im pinging from host 172.16.31.164 to 172.16.31.251 pakets needs to be transmitted untagged in order to recive an reply.&lt;BR /&gt;
When i setup an mirrorport i see the pakets tagged with vlan 31 in my trace - which have to be incorrect. The reply is without tag - which is obviously correct.&lt;BR /&gt;
&lt;BR /&gt;
So the traffic that i see in the capture is not the traffic that is leaving the port.&lt;BR /&gt;
Which information gained from a paket capture can be trusted?&lt;BR /&gt;
&lt;BR /&gt;
I know its a tricky question, because it depends on the state of processing when the paket is replicated to that mirrorport.&lt;BR /&gt;
&lt;BR /&gt;
Here are some further information about the switch, that is doing the mirror port.&lt;BR /&gt;
&lt;BR /&gt;
set port mirroring create ge.1.48 ge.1.34&lt;BR /&gt;
set port mirroring enable ge.1.48 ge.1.34&lt;BR /&gt;
&lt;BR /&gt;
C3(rw)-&amp;gt;show port mirroring&lt;BR /&gt;
Port Mirroring&lt;BR /&gt;
==============&lt;BR /&gt;
Source Port     = ge.1.48&lt;BR /&gt;
Target Port     = ge.1.34&lt;BR /&gt;
Frames Mirrored = Rx and Tx&lt;BR /&gt;
Port Mirroring status enabled&lt;BR /&gt;
&lt;BR /&gt;
C3(rw)-&amp;gt;show ver&lt;BR /&gt;
&lt;BR /&gt;
Model           Serial #           Versions&lt;BR /&gt;
--------------  -----------------  -------------------&lt;BR /&gt;
&lt;BR /&gt;
C3G124-48P      09060162225J       Hw:BCM56504 REV 19&lt;BR /&gt;
                                   Bp:01.00.53&lt;BR /&gt;
                                   Fw:06.61.13.0006&lt;BR /&gt;
                                   BuFw:06.61.11.0006&lt;BR /&gt;
                                   PoE:608_3&lt;BR /&gt;
                                   CPLD:2.0&lt;BR /&gt;
&lt;BR /&gt;
I did not had the opportunity to narrow down the ood behavior at the customer side. But i still want to ask if this behavior can be subject of the mirror port.&lt;BR /&gt;
&lt;BR /&gt;
VM &amp;lt;----&amp;gt; (ge.2.38)(S3 code base probalbly 2014/2013)(lag.0.3 (2xtg memberports)) &amp;lt;===========&amp;gt; (lag.0.4)(B5) ---&lt;BR /&gt;
&lt;BR /&gt;
A mirror port of lag.0.3 shows that the connected VM sends broadcast traffic.&lt;BR /&gt;
A (rx/tx) mirror port sees the paket twice. 1x tagged(vlan 10), 1x untagged.&lt;BR /&gt;
A (tx) mirror port sees the paket twice. 1x tagged(vlan 10), 1x untagged.&lt;BR /&gt;
A (rx) mirror port sees the paket only untagged.&lt;BR /&gt;
&lt;BR /&gt;
The mac adress of that VM is only in VLAN 10 on the port 2.38.&lt;BR /&gt;
&lt;BR /&gt;
Could such a behavior subject on the way how the mirror port works internally? Why?&lt;BR /&gt;
I also tought that maybe vlan 10 is bridged somewhere with vlan 1 but than i should see the mac of the host in vlan 1, but i dont.&lt;BR /&gt;
If i tx the packet in vlan 1,10 and i rx the packet in vlan 2, then i should see the paket 3 times if i do a rx/tx trace?!&lt;BR /&gt;
&lt;BR /&gt;
Probably someone of you has experienced similar observations.&lt;BR /&gt;
&lt;BR /&gt;
thanks&lt;BR /&gt;
&lt;BR /&gt;
dirk&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Tue, 24 Feb 2015 20:54:00 GMT</pubDate>
    <dc:creator>dirk</dc:creator>
    <dc:date>2015-02-24T20:54:00Z</dc:date>
    <item>
      <title>Restrictions of port mirroring on SecureStacks</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-other/restrictions-of-port-mirroring-on-securestacks/m-p/11079#M2107</link>
      <description>Hi folks,&lt;BR /&gt;
&lt;BR /&gt;
i see some odd behavior in mirrored traffic on the customer side, and i am right now unsure if this need deeper investigation. Or can be clarified in the way how mirror ports are treated on enterasys.&lt;BR /&gt;
&lt;BR /&gt;
So i did a quick lab setup also also see similar odd behavior.&lt;BR /&gt;
&lt;BR /&gt;
(Host 172.16.31.164) &amp;lt;----&amp;gt; (Port48)(Switch C3)(Port48) &amp;lt;----&amp;gt; (Port 24)(Switch A2 IP adress 172.16.31.251 / host vlan 1)&lt;BR /&gt;
&lt;BR /&gt;
C3&lt;BR /&gt;
ge.1.30        31         N          untagged: 31 (traffic generator)&lt;BR /&gt;
ge.1.34        31         N          untagged: 31 (mirror Host)&lt;BR /&gt;
ge.1.48        31         N          untagged: 31 tagged: 2708,2732,2733,2734,2736&lt;BR /&gt;
&lt;BR /&gt;
A2&lt;BR /&gt;
fe.1.24        1          N          untagged: 1 tagged: 2708,2732,2733,2734,2736&lt;BR /&gt;
&lt;BR /&gt;
So when im pinging from host 172.16.31.164 to 172.16.31.251 pakets needs to be transmitted untagged in order to recive an reply.&lt;BR /&gt;
When i setup an mirrorport i see the pakets tagged with vlan 31 in my trace - which have to be incorrect. The reply is without tag - which is obviously correct.&lt;BR /&gt;
&lt;BR /&gt;
So the traffic that i see in the capture is not the traffic that is leaving the port.&lt;BR /&gt;
Which information gained from a paket capture can be trusted?&lt;BR /&gt;
&lt;BR /&gt;
I know its a tricky question, because it depends on the state of processing when the paket is replicated to that mirrorport.&lt;BR /&gt;
&lt;BR /&gt;
Here are some further information about the switch, that is doing the mirror port.&lt;BR /&gt;
&lt;BR /&gt;
set port mirroring create ge.1.48 ge.1.34&lt;BR /&gt;
set port mirroring enable ge.1.48 ge.1.34&lt;BR /&gt;
&lt;BR /&gt;
C3(rw)-&amp;gt;show port mirroring&lt;BR /&gt;
Port Mirroring&lt;BR /&gt;
==============&lt;BR /&gt;
Source Port     = ge.1.48&lt;BR /&gt;
Target Port     = ge.1.34&lt;BR /&gt;
Frames Mirrored = Rx and Tx&lt;BR /&gt;
Port Mirroring status enabled&lt;BR /&gt;
&lt;BR /&gt;
C3(rw)-&amp;gt;show ver&lt;BR /&gt;
&lt;BR /&gt;
Model           Serial #           Versions&lt;BR /&gt;
--------------  -----------------  -------------------&lt;BR /&gt;
&lt;BR /&gt;
C3G124-48P      09060162225J       Hw:BCM56504 REV 19&lt;BR /&gt;
                                   Bp:01.00.53&lt;BR /&gt;
                                   Fw:06.61.13.0006&lt;BR /&gt;
                                   BuFw:06.61.11.0006&lt;BR /&gt;
                                   PoE:608_3&lt;BR /&gt;
                                   CPLD:2.0&lt;BR /&gt;
&lt;BR /&gt;
I did not had the opportunity to narrow down the ood behavior at the customer side. But i still want to ask if this behavior can be subject of the mirror port.&lt;BR /&gt;
&lt;BR /&gt;
VM &amp;lt;----&amp;gt; (ge.2.38)(S3 code base probalbly 2014/2013)(lag.0.3 (2xtg memberports)) &amp;lt;===========&amp;gt; (lag.0.4)(B5) ---&lt;BR /&gt;
&lt;BR /&gt;
A mirror port of lag.0.3 shows that the connected VM sends broadcast traffic.&lt;BR /&gt;
A (rx/tx) mirror port sees the paket twice. 1x tagged(vlan 10), 1x untagged.&lt;BR /&gt;
A (tx) mirror port sees the paket twice. 1x tagged(vlan 10), 1x untagged.&lt;BR /&gt;
A (rx) mirror port sees the paket only untagged.&lt;BR /&gt;
&lt;BR /&gt;
The mac adress of that VM is only in VLAN 10 on the port 2.38.&lt;BR /&gt;
&lt;BR /&gt;
Could such a behavior subject on the way how the mirror port works internally? Why?&lt;BR /&gt;
I also tought that maybe vlan 10 is bridged somewhere with vlan 1 but than i should see the mac of the host in vlan 1, but i dont.&lt;BR /&gt;
If i tx the packet in vlan 1,10 and i rx the packet in vlan 2, then i should see the paket 3 times if i do a rx/tx trace?!&lt;BR /&gt;
&lt;BR /&gt;
Probably someone of you has experienced similar observations.&lt;BR /&gt;
&lt;BR /&gt;
thanks&lt;BR /&gt;
&lt;BR /&gt;
dirk&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Feb 2015 20:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-other/restrictions-of-port-mirroring-on-securestacks/m-p/11079#M2107</guid>
      <dc:creator>dirk</dc:creator>
      <dc:date>2015-02-24T20:54:00Z</dc:date>
    </item>
  </channel>
</rss>

