Hi all
I’m trying to figure out why I can only get ingress mirroring to work.
When tapping on ether24, I only get the ingress data from ether19.
Ether24 is only used for tapping (for use with IDS).
Ether19 mirroring is set to:
egress-vlan-mode=unmodified ingress-mirror-to=mirror1 ingress-mirroring-according-to-vlan=no egress-mirror-to=mirror1
I’ve tried setting this to the following:
fdb-uses: mirror0/mirror1/none
vlan-uses: mirror0/mirror1/none
mirror-egress-if-ingress-mirrored: no/yes
mirror-tx-on-mirror-port: no/yes
Current config:
/interface ethernet switch> print
name: switch1
type: QCA-8513L
bridge-type: customer-vid-used-as-lookup-vid
drop-if-no-vlan-assignment-on-ports:
drop-if-invalid-or-src-port-not-member-of-vlan-on-ports: ether1,ether2,ether3,ether4,ether5,ether6,ether7,ether8,ether9,ether10,ether11,ether12,ether13,ether14,ether15,ether16,ether17,ether18,ether19
unknown-vlan-lookup-mode: svl
forward-unknown-vlan: no
use-svid-in-one2one-vlan-lookup: no
use-cvid-in-one2one-vlan-lookup: yes
mac-level-isolation: yes
multicast-lookup-mode: dst-ip-and-vid-for-ipv4
override-existing-when-ufdb-full: no
unicast-fdb-timeout: 5m
ingress-mirror0: ether23,unmodified
ingress-mirror1: ether24,unmodified
ingress-mirror-ratio: 1/1
egress-mirror0: ether23,modified
egress-mirror1: ether24,modified
egress-mirror-ratio: 1/1
fdb-uses: mirror0
vlan-uses: mirror1
mirror-egress-if-ingress-mirrored: yes
mirror-tx-on-mirror-port: no
mirrored-packet-qos-priority: 0
mirrored-packet-drop-precedence: green
bypass-vlan-ingress-filter-for:
bypass-ingress-port-policing-for:
bypass-l2-security-check-filter-for:
name="ether19" ingress-customer-tpid=0x8100 egress-customer-tpid=0x8100 ingress-service-tpid=0x88A8 egress-service-tpid=0x88A8 learn=yes drop-secure-static-mac-move=no drop-dynamic-mac-move=no allow-unicast-loopback=no
allow-multicast-loopback=no action-on-static-station-move=forward drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=29 vlan-type=network-port allow-fdb-based-vlan-translate=no
allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid
egress-vlan-mode=unmodified ingress-mirror-to=mirror1 ingress-mirroring-according-to-vlan=no egress-mirror-to=mirror1 qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based
default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=yes pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no
pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0
priority-to-queue=0-15:0,1:1,2:2,3:3 per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes=""
queue-custom-drop-counter0-includes="" queue-custom-drop-counter1-includes="" policy-drop-counter-includes=""
name="ether24" egress-customer-tpid=0x8100 egress-service-tpid=0x88A8 learn=no drop-secure-static-mac-move=no drop-dynamic-mac-move=no allow-unicast-loopback=no allow-multicast-loopback=no action-on-static-station-move=forward
drop-when-ufdb-entry-src-drop=yes isolation-leakage-profile=30 vlan-type=network-port allow-fdb-based-vlan-translate=no allow-mac-based-service-vlan-assignment-for=all allow-mac-based-customer-vlan-assignment-for=all
filter-untagged-frame=no filter-priority-tagged-frame=no filter-tagged-frame=no egress-vlan-tag-table-lookup-key=egress-vid egress-vlan-mode=unmodified ingress-mirror-to=none ingress-mirroring-according-to-vlan=no
egress-mirror-to=none qos-scheme-precedence=ingress-acl-based,sa-based,da-based,dscp-based,protocol-based,vlan-based,pcp-based default-customer-pcp=0 default-service-pcp=0 pcp-propagation-for-initial-pcp=no
egress-pcp-propagation=no dscp-based-qos-dscp-to-dscp-mapping=yes pcp-or-dscp-based-qos-change-dei=no pcp-or-dscp-based-qos-change-pcp=no pcp-or-dscp-based-qos-change-dscp=no pcp-based-qos-drop-precedence-mapping=0-15:green
pcp-based-qos-dscp-mapping=0-15:0 pcp-based-qos-dei-mapping=0-15:0 pcp-based-qos-pcp-mapping=0-15:0 pcp-based-qos-priority-mapping=0-15:0 priority-to-queue=0-15:0,1:1,2:2,3:3
per-queue-scheduling=wrr-group0:1,wrr-group0:2,wrr-group0:4,wrr-group0:8,wrr-group0:16,wrr-group0:32,wrr-group0:64,wrr-group0:128 custom-drop-counter-includes="" queue-custom-drop-counter0-includes=""
queue-custom-drop-counter1-includes="" policy-drop-counter-includes=""