Hello everyone,
I am trying to mirror my traffic and feed the monitor port of a security onion.
When i am doing a tcpdump at the security onion all i can see is broadcast packets and arp.
There is something special for configuration?
Searched and haven’t found a solution, but many refers to this issue.
Show the configuration from /interface/bridge and /interface/ethernet … it’s likely that your switch has HW offload enabled (otherwise it wouldn’t be able to switch traffic at wirespeed) and port mirroring doesn’t actually work.