Span or port mirror?

Reply
L1 Bithead

Span or port mirror?

Is it possible to use interfaces on PA-5020 as span or mirrored ports of other active interfaces on the same device?

Highlighted
L6 Presenter

Re: Span or port mirror?

Hi...The port mirroring capability of the PA is for decrypted traffic only, and does not include non-decrypted traffic.  For example, SSL traffic can be decrypted by the PA and the contents inside the SSL tunnel can be forwarded out an Eth port set up as port mirroring.  Here's more info on port mirroring:

 

https://www.paloaltonetworks.com/documentation/60/pan-os/pan-os/decryption/configure-decryption-port...

 

If you want to span all traffic, it's best to do it at your switch.  

 

Thanks.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!