Ethernet Routing Switch 8600/8800 Engineering > Port Mirror via SMLT Cluster Technical Configuration Guide Avaya Data Solutions Document Date: Document Number: NN48500-630 Document Version: 1.0
2011 Avaya Inc. All Rights Reserved. Notices While reasonable efforts have been made to ensure that the information in this document is complete and accurate at the time of printing, Avaya assumes no liability for any errors. Avaya reserves the right to make changes and corrections to the information in this document without the obligation to notify any person or organization of such changes. Documentation disclaimer Avaya shall not be responsible for any modifications, additions, or deletions to the original published version of this documentation unless such modifications, additions, or deletions were performed by Avaya. End User agree to indemnify and hold harmless Avaya, Avaya s agents, servants and employees against all claims, lawsuits, demands and judgments arising out of, or in connection with, subsequent modifications, additions or deletions to this documentation, to the extent made by End User. Link disclaimer Avaya is not responsible for the contents or reliability of any linked Web sites referenced within this site or documentation(s) provided by Avaya. Avaya is not responsible for the accuracy of any information, statement or content provided on these sites and does not necessarily endorse the products, services, or information described or offered within them. Avaya does not guarantee that these links will work all the time and has no control over the availability of the linked pages. Warranty Avaya provides a limited warranty on this product. Refer to your sales agreement to establish the terms of the limited warranty. In addition, Avaya s standard warranty language, as well as information regarding support for this product, while under warranty, is available to Avaya customers and other parties through the Avaya Support Web site: http://www.avaya.com/support Please note that if you acquired the product from an authorized reseller, the warranty is provided to you by said reseller and not by Avaya. Licenses THE SOFTWARE LICENSE TERMS AVAILABLE ON THE AVAYA WEBSITE, HTTP://SUPPORT.AVAYA.COM/LICENSEINFO/ ARE APPLICABLE TO ANYONE WHO DOWNLOADS, USES AND/OR INSTALLS AVAYA SOFTWARE, PURCHASED FROM AVAYA INC., ANY AVAYA AFFILIATE, OR AN AUTHORIZED AVAYA RESELLER (AS APPLICABLE) UNDER A COMMERCIAL AGREEMENT WITH AVAYA OR AN AUTHORIZED AVAYA RESELLER. UNLESS OTHERWISE AGREED TO BY AVAYA IN WRITING, AVAYA DOES NOT EXTEND THIS LICENSE IF THE SOFTWARE WAS OBTAINED FROM ANYONE OTHER THAN AVAYA, AN AVAYA AFFILIATE OR AN AVAYA AUTHORIZED RESELLER, AND AVAYA RESERVES THE RIGHT TO TAKE LEGAL ACTION AGAINST YOU AND ANYONE ELSE USING OR SELLING THE SOFTWARE WITHOUT A LICENSE. BY INSTALLING, DOWNLOADING OR USING THE SOFTWARE, OR AUTHORIZING OTHERS TO DO SO, YOU, ON BEHALF OF YOURSELF AND THE ENTITY FOR WHOM YOU ARE INSTALLING, DOWNLOADING OR USING THE SOFTWARE (HEREINAFTER REFERRED TO INTERCHANGEABLY AS "YOU" AND "END USER"), AGREE TO THESE TERMS AND CONDITIONS AND CREATE A BINDING CONTRACT BETWEEN YOU AND AVAYA INC. OR THE APPLICABLE AVAYA AFFILIATE ("AVAYA"). Copyright Except where expressly stated otherwise, no use should be made of the Documentation(s) and Product(s) provided by Avaya. All content in this documentation(s) and the product(s) provided by Avaya including the selection, arrangement and design of the content is owned either by Avaya or its licensors and is protected by copyright and other intellectual property laws including the sui generis rights relating to the protection of databases. You may not modify, copy, reproduce, republish, upload, post, transmit or distribute in any way any content, in whole or in part, including any code and software. Unauthorized reproduction, transmission, dissemination, storage, and or use without the express written consent of Avaya can be a criminal, as well as a civil offense under the applicable law. Third Party Components Certain software programs or portions thereof included in the Product may contain software distributed under third party agreements ("Third Party Components"), which may contain terms that expand or limit rights to use certain portions of the Product ("Third Party Terms"). Information regarding distributed Linux OS source code (for those Products that have distributed the Linux OS source code), and identifying the copyright holders of the Third Party Components and the Third Party Terms that apply to them is available on the Avaya Support Web site: http://support.avaya.com/copyright. Trademarks The trademarks, logos and service marks ("Marks") displayed in this site, the documentation(s) and product(s) provided by Avaya are the registered or unregistered Marks of Avaya, its affiliates, or other third parties. Users are not permitted to use such Marks without prior written consent from Avaya or such third party which may own the Mark. Nothing contained in this site, the documentation(s) and product(s) should be construed as granting, by implication, estoppel, or otherwise, any license or right in and to the Marks without the express written permission of Avaya or the applicable third party. Avaya is a registered trademark of Avaya Inc. All non-avaya trademarks are the property of their respective owners. Downloading documents For the most current versions of documentation, see the Avaya Support. Web site: http://www.avaya.com/support Contact Avaya Support Avaya provides a telephone number for you to use to report problems or to ask questions about your product. The support telephone number is 1-800-242-2121 in the United States. For additional support telephone numbers, see the Avaya Web site: http:// www.avaya.com/support. 2
Abstract This Technical Configuration Guide demonstrates how to setup port mirroring in an SMLT cluster to capture traffic from a voice VLAN for monitoring purposes. Revision Control No Date Version Revised By Remarks 1 07/19/2011 1.1 JVE Initial release 3
Table of Contents Figures... 5 1. SMLT Cluster with local port mirror... 7 1.1 Configuration File... 8 1.2 Verify Operations... 9 2. SMLT Cluster with local & remote port mirror... 12 2.1 Configuration File... 13 3. Reference Documentation... 16 4
Figures Figure 1: SMLT Cluster with local port mirror... 7 Figure 2: SMLT Cluster with remote and local port mirror... 12 5
Conventions This section describes the text, image, and command conventions used in this document. Symbols Tip Highlights a configuration or technical tip. Note Highlights important information to the reader. Warning Highlights important information about an action that may result in equipment damage, configuration or data loss. Text Bold text indicates emphasis. Italic text in a Courier New font indicates text the user must enter or select in a menu item, button or command: ERS5520-48T show running-config Output examples from Avaya devices are displayed in a Lucida Console font: ERS5520-48T show sys-info Operation Mode: Switch MAC Address: 00-12-83-93-B0-00 PoE Module FW: 6370.4 Reset Count: 83 Last Reset Type: Management Factory Reset Power Status: Primary Power Autotopology: Enabled Pluggable Port 45: None Pluggable Port 46: None Pluggable Port 47: None Pluggable Port 48: None Base Unit Selection: Non-base unit using rear-panel switch sysdescr: Ethernet Routing Switch 5520-48T-PWR HW:02 FW:6.0.0.10 SW:v6.2.0.009 Mfg Date:12042004 HW Dev:H/W rev.02 6
1. SMLT Cluster with local port mirror In this configuration example, we will configure the ERS 8600/8800 SMLT cluster with local port mirroring and setup the mirror to monitor only the VoIP VLAN 850 from edge switches 5520-20 and 5530-30. An external switch will be added to the SMLT cluster where it s only purpose is to provide a single port to the monitor application. If the monitor application supports multiple NICs, then we can eliminate switch 5520-25. Please note that additional SMLT clusters can also be added to switch 5520-23 (as illustrated by the red links as shown in figure 1) to extend the port mirroring capabilities to more than just one SMLT cluster. Figure 1: SMLT Cluster with local port mirror Overall, we will configure the following: Port Mirror SMLT Cluster o Goal is to only mirror VLAN 850, the voice VLAN, from the SMLT cluster to an external switch used for only port mirror 5520-25 as shown in the diagram o Setup local Port Mirror on 8800-5 & 8800-6 Mirrored ports 2/4 & 2/20 and monitor VLAN 850 Monitor port 2/18 Port Mirror - external switch 5520-25 o VLAN 850 see notes below o Mirror ports (many-to-one) 18 to 21 o Monitor port 22 Via switch 5520-25, we need to configure VLAN 850 with tagged port member 18 to 22. This is not required on 8800-5 & 8800-6 where monitor port 2/18 can be left untagged in default VLAN (VLAN 1). 7
1.1 Configuration File ERS 8800 Cluster Port Mirror Mode Monitor Ports Mirror Ports both 2/4,4/20 2/18 ERS 5520-25 Port Mirror Mode Monitor Ports Mirror Ports many-to-one 22 18 to 21 ERS 8800 Cluster ACL Type ACE Match ACE Debug invlan (VLAN 850) Ports 2/4 and 2/20 Mirror enabled with dst-port 2/18 ERS 5520-25 VLAN VLAN Port Members Tagging 850 18 to 22 18 to 22 ERS-5 DIAG CONFIGURATION diag mirror-by-port 1 create in-port 2/4,2/20 out-port 2/18 diag mirror-by-port 1 mode both R-MODULE FILTER CONFIGURATION filter act 2 create filter act 2 ethernet port filter act 2 apply filter acl 1 create invlan act 2 filter acl 1 vlan add 850 filter acl 1 ace 1 create name "rpm" filter acl 1 ace 1 action permit filter acl 1 ace 1 debug mirror enable mirroring-dst-ports 2/18 filter acl 1 ace 1 ethernet port eq 2/4,2/20 filter acl 1 ace 1 enable ERS-6 DIAG CONFIGURATION diag mirror-by-port 1 create in-port 2/4,2/20 out-port 2/18 diag mirror-by-port 1 mode both R-MODULE FILTER CONFIGURATION filter act 2 create filter act 2 ethernet port filter act 2 apply filter acl 1 create invlan act 2 filter acl 1 vlan add 850 filter acl 1 ace 1 create name "rpm" filter acl 1 ace 1 action permit filter acl 1 ace 1 debug mirror enable mirroring-dst-ports 2/18 filter acl 1 ace 1 ethernet port eq 2/4,2/20 filter acl 1 ace 1 enable 8
5520-25!! *** VLAN ***! vlan create 850 type port 1 vlan ports 18-22 tagging tagall filterunregistered-frames disable vlan configcontrol flexible vlan members 850 18-22 vlan configcontrol automatic!! *** Port Mirroring ***! port-mirroring mode ManytoOneRxTx monitorport 22 mirror-ports 18-21 1.2 Verify Operations ERS 8800 Cluster Switch Step 1 Verify port mirror configuration 8800-5 8800-6> show diag mirror-by-port Result: Response from 8800-5: Diag Mirror-By-Port ID MIRRORED_PORT MIRRORING_DEST ENABLE MODE REMOTE-MIRROR-VLAN-ID 1 2/4,2/20 2/18 true both 0 Response from 8800-6: Diag Mirror-By-Port ID MIRRORED_PORT MIRRORING_DEST ENABLE MODE REMOTE-MIRROR-VLAN-ID 1 2/4,2/20 2/18 true both 0 Step 2 Verify ERS 8800 cluster monitor port simply shows monitor port is in default VLAN 8800-5 8800-6> show port info vlan port 2/18 9
Result: Response from 8800-5: Port Vlans PORT DISCARD DISCARD DEFAULT VLAN UNTAG NUM TAGGING TAGFRAM UNTAGFRAM VLANID IDS DEFVLAN -------------------------------------------------------------------------------- 2/18 disable false false 1 1 disable Response from 8800-6: Port Vlans PORT DISCARD DISCARD DEFAULT VLAN UNTAG NUM TAGGING TAGFRAM UNTAGFRAM VLANID IDS DEFVLAN -------------------------------------------------------------------------------- 2/18 disable false false 1 1 disable Step 3 Verify ACL configuration 8800-5 8800-6> show filter acl config 1 1 Result: Response from 8800-5: Filter ACL-ACE Configuration -------------------------------------------------------------------------------- filter acl 1 create invlan act 2 filter acl 1 vlan add 850 filter acl 1 ace 1 create name rpm filter acl 1 ace 1 action permit filter acl 1 ace 1 debug mirror enable filter acl 1 ace 1 ethernet 2/4,2/20 2/4,2/20 filter acl 1 ace 1 enable Response from 8800-6: Filter ACL-ACE Configuration 10
-------------------------------------------------------------------------------- filter acl 1 create invlan act 2 filter acl 1 vlan add 850 filter acl 1 ace 1 create name rpm filter acl 1 ace 1 action permit filter acl 1 ace 1 debug mirror enable filter acl 1 ace 1 ethernet 2/4,2/20 2/4,2/20 filter acl 1 ace 1 enable 11
2. SMLT Cluster with local & remote port mirror As an alternative to configuration example 1, we can configure the ERS 8600/8800 SMLT cluster with local and remote port mirroring and setup the mirror to monitor only the VoIP VLAN 850 from edge switches 5520-20 and 5530-30. In this example, an external switch will be added to SMLT cluster switch 8800-6 only where it s only purpose is to provide a single port to the monitor application. If the monitor application supports multiple NICs, then we can eliminate switch 5520-25. Overall, we will configure the following: Figure 2: SMLT Cluster with remote and local port mirror Goal is to only mirror VLAN 850, the voice VLAN to monitor connected to switch 5520-25 o Setup Remote Port Mirror on 8800-5 Mirrored ports 2/4 & 2/20 and monitor VLAN 850 Remote Port Mirror VLAN used is 999 o Setup local Port Mirror on 8800-6 Local port mirror monitor ports 2/4 & 2/20 and monitor VLAN 850 Remote Port Mirror monitor port is 2/18 see note below Local Port Mirror monitor port is 2/17 see note below Add connection between 8800-5 & 8800-6 (port 2/3) for Remote Port Mirror see note below Port Mirror - external switch 5520-25 o Identical configuration as shown in example 1 Please note remote port mirror will not work over an IST link. An additional link must be created between the SMLT cluster (port 2/3 as shown in figure 2). The remote port mirror monitor port cannot be shared with a local port mirror monitor port. In this example, we used port 2/17 for the local port mirror monitor port and port 2/18 as the remote port mirror monitor port on switch 8800-6. 12
2.1 Configuration File Please refer to example 1 for switch 5520-25 configuration. ERS 8800-5 - VLAN VLAN Port Members Tagging 999 2/3 2/3 ERS 8800-6 - VLAN VLAN Port Members Tagging 999 2/3,2/18 2/3 ERS 8800-5 Remote Port Mirror Interface Settings Port Mode Dst-mac VLAN 2/3 Source (default) 00:1e:1f:48:f1:9c 999 ERS 8800-6 Remote Port Mirror Interface Settings Port Mode Dst-mac VLAN 2/18 termination 00:1e:1f:48:f1:9c 999 On the remote port mirror termination switch, enter the following command to view the destination MAC. 8800-6> config ether 2/18 remote-mirroring info port 2/18 Enable = TRUE Mode = termination srcmac = 00:1e:1f:48:f0:51 dstmac = 00:1e:1f:48:f1:9c ether-type = 0x8103 vlan-id-list = 999 ERS 8800-6 Local Port Mirror Mode Monitor Ports Mirror Ports both 2/4,4/20 2/17 ERS 8800-5 ACL Type ACE Match ACE Debug invlan (VLAN 850) Ports 2/4 and 2/20 Mirror enabled with dst-port 2/3 13
ERS 8800-6 ACL Type ACE Match ACE Debug invlan (VLAN 850) Ports 2/4 and 2/20 Mirror enabled with dst-port 2/17 ERS-5 PORT CONFIGURATION - PHASE I ethernet 2/3 perform-tagging enable VLAN CONFIGURATION - PHASE I vlan 999 create byport 1 name "RPM_999" vlan 999 ports add 2/3 member portmember PORT CONFIGURATION - PHASE II ethernet 2/3 default-vlan-id 999 ethernet 2/3 remote-mirroring create ethernet 2/3 remote-mirroring dstmac 00:1e:1f:48:f1:9c ethernet 2/3 remote-mirroring enable true DIAG CONFIGURATION diag mirror-by-port 1 create in-port 2/4,2/20 out-port 2/3 diag mirror-by-port 1 mode both diag mirror-by-port 1 remote-mirror-vlanid 999 ERS-6 PORT CONFIGURATION - PHASE I ethernet 2/3 perform-tagging enable VLAN CONFIGURATION - PHASE I r vlan 999 create byport 1 vlan 999 ports add 2/3,2/18 member portmember PORT CONFIGURATION - PHASE II ethernet 2/3 default-vlan-id 999 ethernet 2/18 remote-mirroring create ethernet 2/18 remote-mirroring mode termination ethernet 2/18 remote-mirroring dstmac 00:1e:1f:48:f1:9c ethernet 2/18 remote-mirroring add-vlan-id 999 ethernet 2/18 remote-mirroring enable true DIAG CONFIGURATION diag mirror-by-port 1 create in-port 2/4,2/20 out-port 2/17 diag mirror-by-port 1 mode both R-MODULE FILTER CONFIGURATION filter act 2 create filter act 2 ethernet port filter act 2 apply filter acl 1 create invlan act 2 filter acl 1 vlan add 850 filter acl 1 ace 1 create name "rpm" R-MODULE FILTER CONFIGURATION filter act 2 create filter act 2 ethernet port filter act 2 apply filter acl 1 create invlan act 2 filter acl 1 vlan add 850 filter acl 1 ace 1 create name "rpm" 14
filter acl 1 ace 1 action permit filter acl 1 ace 1 debug mirror enable mirroring-dst-ports 2/3 filter acl 1 ace 1 ethernet port eq 2/4,2/20 filter acl 1 ace 1 enable filter acl 1 ace 1 action permit filter acl 1 ace 1 debug mirror enable mirroring-dst-ports 2/17 filter acl 1 ace 1 ethernet port eq 2/4,2/20 filter acl 1 ace 1 enable 15
3. Reference Documentation Document Title Publication Number Description Remote Port Mirroring Technical Configuration Guide Troubleshooting Avaya Ethernet Routing Switch 8800/8600 NN48500-604 NN46205-703 2011 Avaya Inc. All Rights Reserved. Avaya and the Avaya Logo are trademarks of Avaya Inc. and are registered in the United States and other countries. All trademarks identified by, TM or SM are registered marks, trademarks, and service marks, respectively, of Avaya Inc. All other trademarks are the property of their respective owners. Avaya may also have trademark rights in other terms used herein. References to Avaya include the Nortel Enterprise business, which was acquired as of December 18, 2009. 16