Hi Goncalo,
6 months before i play around and test this feature also - X460 - 22.2.x. I was also disappointed because it does not really help in field (customers environment) - it can help in lab environment.
The heaviest burden is that only CPU bound traffic are captured (reliable). BUT on a modern LAN Switch most traffic is handled by ASIC not by CPU. Thats the why you not see what you expect.
This feature is (from my point of view) only a fall-out for GTAC and developers to analyse why CPU or bcmRX process load is heavy. (It seems) that all cases are not considered.
Maybe you can get better results if you redirect interesting Traffic via ACL to CPU (that is a possible Action with Extreme ACLS). But i never test this.
Another possibility is to use "Mirroring to Remote IP Addresses".
But you can see at this thread below - it works also not satisfactory ;-(
https://community.extremenetworks.com/extreme/topics/exos-using-new-feature-mirroring-to-remote-ip-a...
i hope EXOS developers will retouch and improve in both cases.
At Fortigate firewalls for example you have the same problem with sniffing/debugging and ASIC-based traffic handling. There you can disable this "Network process offload" for specific traffic to see and debug all interessted traffic with sniffer and debug tools.
That will be what i wish for EXOS too.
Regards,
Matthias