© 2006 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The ProCurve 3500yl/5400zl/6200yl Switch Software Update NPI Technical Training NPI Technical Training Version 1.0b 6 December 2006
© 2006 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. Traffic Mirroring Section
3 Traffic Mirroring Allows you to monitor traffic to detect threats or troubleshoot problems Advantages Allows you to monitor traffic from the local switch or from multiple remote switches Eliminates the need for a monitoring port on every switch Reduces the number of necessary security appliances Network Stations 5400zl Switch 3500yl Switch IDS/IPS* Traffic is selected based on port, VLAN, or ACL. Selected traffic is mirrored to another switch. Destination switch forwards mirrored traffic to IDS/IPS. *Intrusion detection system (IDS)/ Intrusion prevention system (IPS)
4 Remote Traffic Mirroring Allows you to monitor traffic to detect threats or troubleshoot problems from across the network and bring information back to the analyzer. Network Stations 5400zl Switch 3500yl Switch IDS/IPS* *Intrusion detection system (IDS)/ Intrusion prevention system (IPS)
5 Guidelines for Using Traffic Mirroring Two types of traffic mirroring: Local mirroring—source and destination are on the same switch Remote mirroring—source and destination are on different switches Each switch can be the: Originator for four mirror sessions, with the destination on either the local switch or another switch Destination for 32 mirror sessions Network 5400zl Switch 3500yl Switch IPS/IDS Four mirror sessions originate on the local 5400zl Switch. The 3500yl Switch can receive up to 28 additional mirror sessions.
6 Guidelines for Using Traffic Mirroring Continued For local mirroring, configure exit ports: Configure multiple mirror sessions to use the same exit port Load balance mirror sessions across multiple exit ports Core IDS/IPS
7 Overview of Configuration Steps 1. Configure the destination switch for remote traffic mirroring. 2. Configure the source switch. Define the session number and the destination for the mirror session on the source switch. – Local traffic mirroring—port on the same switch – Remote traffic mirroring—another 3500yl, 5400zl, or 6200yl Switch Define the source interface and the direction of traffic – Ports, including mesh ports – Static trunks – Static virtual LANs (VLANs) – Direction of traffic—inbound, outbound, or both directions Apply an optional Access Control List (ACL) to further select traffic. – Select inbound traffic on the source interface with an extended or standard ACL
8 Overview of Configuration Steps 3.For remote traffic mirroring, enable jumbo frames to mirror information fields larger than 1446 bytes (untagged) or (tagged) On both source and destination switches Any infrastructure switches in between The end stations, in this case the IPS/IDS if you know the originating frame was larger than 1522 bytes. 5400zl Switch 3500yl Switch IPS/IDS Mirror session originates on the local 5400zl Switch. The destination is on the remote 3500yl Switch. ProCurve (config)# vlan jumbo
9 Configuring the Destination Switch 1.For remote traffic mirroring, configure the source and destination of the mirror session on the destination switch ProCurve_dst_switch(config)# mirror endpoint ip port Options IP address of the VLAN or subnet on which the mirrored traffic enters or leaves the source switch The unique UDP port number to use for the session IP address of the VLAN or subnet for the exit port on the destination switch Exit port on the destination switch These settings must match the settings you will configure on the source switch.
10 Configuring the Source Switch Remote traffic mirroring 2.Configure the source switch —For remote traffic mirroring, identify the mirror session, the source, and the destination. – Replace with the number to identify this mirror session. – Assign an optional name if you want an easier way to identify the session. – Ensure the other settings match those configured on the destination switch. ProCurve_source_switch(config)# mirror [name ] remote ip
11 Configuring the Source Switch Local traffic mirroring For local traffic mirroring, identify the session and configure the exit port ProCurve_source_switch(config)# mirror [name ] port Core IPS/IDS Exit port is port 8.
12 Configuring the Source Switch Define the originating interface Define the originating interface as a port, trunk, or mesh port ProCurve_source_switch(config)# interface monitor all [in | out | both] mirror [mirror...] Options Port, trunk, or mesh [in | out | both]Direction of traffic that you want mirrored: in = traffic entering port out = traffic exiting port both = all traffic Number for this mirror session
13 Define the originating interface as a VLAN or VLANs – Replace with a VLAN or a range or VLANs. ProCurve_source_switch(config)# vlan monitor all [in | out | both] mirror [mirror...] Configuring the Source Switch Select the originating interface 5400zl Switch Network VLAN 1 VLAN 2
14 Using an ACL to Further Select Traffic Optional To use an ACL to select traffic arriving on an interface, enter: – Replace with the name of the ACL you have configured. ProCurve_source_switch(config)# interface monitor ip access-group in mirror [mirror...] ProCurve_source_switch(config)# vlan monitor ip access-group in mirror [mirror...]
15 Enabling Jumbo Frames 3.For remote traffic mirroring, enable jumbo frames on the source switch, destination switch, and any intervening infrastructure switches For example: ProCurve_Source (config)# vlan 8 jumbo ProCurve_Destination (config)# vlan 8 jumbo ProCurve_Infrastructure (config)# vlan 8 jumbo
16 Traffic Mirroring show Commands View information about mirror sessions configured on the switch ProCurve# show monitor [ ] Network Monitoring SessionsStatus Type Sources active port 1 2 active IPv4 3 3 active port 1 4 Inactive Mirror endpoint Type Dest Address Source Address UDP Src UDP Dst Port IPv A17 Port = local mirror session IPv4 = remote mirror session Indicates # of criteria for mirror session
17 Example Configuration Source Switch Destination Switch IPS/IDS Running configuration: !Dst switch! vlan 8 untagged 1-5 ip address jumbo exit mirror endpoint ip port 22 Running configuration: !Source switch! vlan 8 untagged B1-B24 ip address jumbo exit mirror 1 remote ip interface B1 monitor all both mirror 1 exit interface B2 monitor all both mirror 1 exit Originating interface
18