Wired Intelligent Edge

 View Only
  • 1.  Mirroring in an 8325 VSX Topology

    Posted Jul 10, 2023 04:51 PM

    I have a vsx pair of 8325 switches that I want to set up mirroring on for all of my MC-LAGS.  I have a security appliance that the mirrored traffic will be sent to.  For the destination, would I set up a single 10G interface going to the appliance on just the primary switch in the mirror session and then specify all of the MC-LAGs as the source interface?  Does the same mirror session and source/destinations need to be set up on the secondary switch as well?  If so, do I need to have a MC-LAG going to my appliance from the destination interface on each VSX paired switch? 



  • 2.  RE: Mirroring in an 8325 VSX Topology

    Posted Jul 12, 2023 01:35 AM

    VSX nodes work independently as regards to mgmt/control-plane.

    so one need to configure mirroring on both nodes. (I have not tested this)



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 3.  RE: Mirroring in an 8325 VSX Topology

    Posted Jul 12, 2023 04:42 AM

    That's how I have it set up now.  Session 1 on primary VSX switch, session 2 on secondary vsx switch with the same SFP+ interface on each switch as the the session destination.  I then have each of my downstream MC-lags as the source for each session on each switch.  Each destination interface will go to a separate SFP+ port on the security appliance.  Will test it when I go live with my network Saturday.  Thanks.




  • 4.  RE: Mirroring in an 8325 VSX Topology

    Posted Jul 13, 2023 04:06 AM
    Hi! ...and how your Security Appliance is dealing with two different monitoring sessions from the collected data point of view? I mean...it's absolutely a possible setup...but I'm asking because (...I'm thinking of...) isn't there the need to let the Security Appliance to "reconcile" (or just manage) ingressing packets streams "as if" they are coming from a single source instead of two...or not? ...or, probably, my assumption here is largerly erroneous.

    I'm asking because we are in the process (we are at an early stage to be honest) of evaluating the connection of a Snort based appliance to one of ours VSX Clusters.