The customer's switch only can mirror traffic in one port.
Original mirror port is use for another security device.
Core Switch----------> Security Monitor Device
We want to use look like below.
Core Switch----------> Paloalto(V-wire) --------->Security Monitor Device
Is it OK?
Solved! Go to Solution.
If your "Security Monitor Device" is the end device, ie. not connected to any other device in the network that should be fine. Vwire just acts as bump in the wire. When a packet is received from one of the vwire ports, it forwards it out its corresponding port. That means, same packet will be flowing through core switch to client (normal flow) and through PAN -> Sec. Monitor Device (Spanned traffic). If there are connections from Security Monitor Device to a switch or other devices that might cause a loop for the packets.
You can have 2 span ports from the switch (if possible) and use 1 of the interface on PAN as TAP mode and achieve same results. This configuration will not forward packets to Security Monitor Device though.
Hope this helps.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!