组网需求:
Switch A为目的交换机,Switch A通过GigabitEthernet 1/1/2和监控设备PC2相连,GigabitEthernet 1/1/2为镜像目的端口,Switch B为中间交换机,Switch A的Trunk端口GigabitEthernet 1/1/1和Switch B的Trunk端口GigabitEthernet 1/1/1相连,Switch B的Trunk端口GigabitEthernet 1/1/2和Switch C的Trunk端口GigabitEthernet 1/1/1相连,Switch C为源交换机,Switch C的端口GigabitEthernet 1/1/2和PC1相连,GigabitEthernet 1/1/2为镜像源端口,定义GigabitEthernet 1/1/3为反射端口。
组网图:
|
配置步骤:
SwitchC的配置:
1.进入系统视图
<SwitchC> system-view
2.创建并进入VLAN10,设置VLAN10为remote-probe vlan
[SwitchC] vlan 10
[SwitchC-vlan10] remote-probe vlan enable
[SwitchC-vlan10] quit
3.进入G1/1/1端口视图
[SwitchC] interface GigabitEthernet 1/1/1
4.设置端口为trunk,并允许vlan10通过
[SwitchC-GigabitEthernet1/1/1] port link-type trunk
[SwitchC-GigabitEthernet1/1/1] port trunk permit vlan 10
[SwitchC-GigabitEthernet1/1/1] quit
5.设置远程源镜像组
[SwitchC] mirroring-group 1 remote-source
6.设置G1/1/2为源端口,并对进方向报文进行监控
[SwitchC] mirroring-group 1 mirroring-port GigabitEthernet 1/1/2 inbound
7.设置G1/1/3为远程反射端口
[SwitchC] mirroring-group 1 reflector-port GigabitEthernet 1/1/3
8.设置镜像组1的remote-probe vlan为10
[SwitchC] mirroring-group 1 remote-probe vlan 10
Switch B的配置:
1.设置vlan10为remote-probe vlan
[SwitchB] vlan 10
[SwitchB-vlan10] remote-probe vlan enable
[SwitchB-vlan10] quit
2.将端口G1/1/1设为trunk口并允许vlan10通过
[SwitchB] interface GigabitEthernet 1/1/1
[SwitchB-GigabitEthernet1/1/1] port link-type trunk
[SwitchB-GigabitEthernet1/1/1] port trunk permit vlan 10
[SwitchB-GigabitEthernet1/1/1] quit
3.将端口G1/1/2设为trunk口并允许vlan10通过
[SwitchB] interface GigabitEthernet 1/1/2
[SwitchB-GigabitEthernet1/1/2] port link-type trunk
[SwitchB-GigabitEthernet1/1/2] port trunk permit vlan 10
Switch A的配置:
1.设置vlan10为remote-probe vlan
[SwitchA] vlan 10
[SwitchA-vlan10] remote-probe vlan enable
[SwitchA-vlan10] quit
2.将端口G1/1/1设为trunk口并允许vlan10通过
[SwitchA] interface GigabitEthernet 1/1/1
[SwitchA-GigabitEthernet1/1/1] port link-type trunk
[SwitchA-GigabitEthernet1/1/1] port trunk permit vlan 10
[SwitchA-GigabitEthernet1/1/1] quit
3.设置远程监控镜像组
[SwitchA] mirroring-group 1 remote-destination
4.设置端口G1/1/2为监控端口
[SwitchA] mirroring-group 1 monitor-port GigabitEthernet 1/1/2
5.设置镜像组1的remote-probe vlan为10
[SwitchA] mirroring-group 1 remote-probe vlan 10
配置关键点:
1.不能将缺省VLAN、管理VLAN设置成Remote-probe vlan;
2.需要通过配置保证Remote-probe VLAN从源交换机到目的交换机的二层互通性;
3.支持远程镜像的设备包括:H3C S3100、H3C S3600-EI、H3C S5600、H3C S5100、Quidway S3900-EI、Quidway S5100和Quidway S5600系列交换机。