Background
Exchange Technology is everywhere. The price of switches has been declining in recent years. Switching to desktop is already possible for most companies.
Users can obtain the desired bandwidth. However, this makes network maintenance and traffic monitoring increasingly difficult. This is true even for dedicated traffic monitoring devices or Protocol analyzers.
Switch Operation
Each added or removed network device changes the network structure. The switch changes its data forwarding table. All devices connected to the switch are stored in the data forwarding table. The switch obtains the MAC address of each network device and the port connected to these devices. If the forwarded data has a clear MAC address, the switch forwards the data to the corresponding port smoothly. Devices on other ports, including Protocol analyzers, cannot see the traffic. If the switch cannot determine the forwarding port, it will send a broadcast frame to all ports, multicast) the frame will be forwarded to one or several ports based on the multicast address.
Based on the above forwarding rules, a device connected to a port can only obtain the following types of data:
Broadcast Data
Multicast Data
Unicast data for this host
Data of the destination address that has not been learned by the switch
For these limited traffic, the role of the protocol analyzer is very limited.
Image
Most vswitches support image technology, which facilitates Fault Diagnosis for vswitches. We call it "grouping" or "Spanning ".
An image copies traffic from a port of the vswitch to another port (mirror port) for monitoring.
I. OptiView™Integrated analyzer OPV-INA) connected to a port. And set the traffic to the port of the mirrored host A in the receiving mode. The OPV-INA can capture traffic from host A to host B. The port connecting OPV is the mirror port, and the communication between A and B is not affected by the mirror port. Similar to an image between ports, image operations can also be performed between VLANs. The most typical image configuration is through the Console port or Telnet. Port Mirroring is a very useful feature that mirror ports can be used to connect test devices such as OPV-INA, OPV-WGA for protocol analysis. When you need to diagnose a fault, you can use remote control for monitoring or fault diagnosis. No physical connection changes are required at the site.
Despite the strong functionality of the image, be careful when using the image because it may generate switching loops, unexpected traffic, or some hosts may be inaccessible, resulting in unexpected malignant results.
Limitations of the image Function
On the one hand. When the diagnostic tool is connected to the Image Port. It is best to only receive data and not send data to the network, which is controlled by the functions of some vendors. Different product features may be different.
For vswitches. The image port can be specified as the "receive" mode. Or "receive/Send" mode. If only the "receive" mode is used.
Then the OPV-INA cannot actively search for the network. If you cannot make full use of its search function. It hinders its performance during testing. If the OPV-INA cannot respond to a network request. OPV-INA remote users cannot effectively control its work. You can send signals to OPV-INA. But the OPV-INA responds.
On the other hand. The speed of the Image Port is a problem. The port speed must be higher than the tested port traffic. For example. If host A is connected to port m. The OPV is connected to the 10 m port. The excess traffic will be discarded. 2 ).
It is worth noting that if the port to be mirrored is a 200 M full-duplex port, the total traffic may reach M. For a m Image Port, the excess part is discarded without any mark. Therefore, mirroring all traffic to a slow port that cannot provide sufficient bandwidth cannot complete the fault diagnosis task. For fault diagnosis, you need to know the forwarding mode of the vswitch. The default forwarding mode of most vswitches is "Storage and forwarding". This method is used to check whether the entire frame is correct before forwarding data frames, in this way, conflicting or wrong data will not be forwarded.
Generally, the forwarded traffic will also be sent from the source port to the mirror port. However, for fault diagnosis, there are deficiencies in the image, and the image data does not include the error data, unless the switch adopts a low-latency direct-through forwarding method, and the error occurs after the forwarding operation point is determined. Many vendors no longer provide low-latency direct forwarding in their products, so that the OPV-INA cannot detect conflicting and wrong data, unless the device to be tested by the OPV-INA is connected through the hub and OPV. When image technology is used for testing or monitoring. First, it is very important to understand the data forwarding technology of the tested vswitch. To learn about the switch mode, you can view related documents or switch settings.
SwitchTap Function
The SwitchTap function saves time, effort, and Security to implement images on LAN switches. The SwitchTap technology integrated in OVC application software provides a very clever way to view where the device is connected. The searched network devices can be classified by different types (such as routers. Vswitch. Servers ). The IP address and name are displayed. SwitchTap can mirror all data from a port or a VLAN to a network analyzer (such as OPV-INA. OPV-WGA ). This function is secure. It automatically displays the ports connected to the network analyzer. This avoids the trouble of configuring network devices.
Switch supported by SwitchTap
Cisco
Catalyst 2900 Catalyst 2926
Catalyst 2900XL Catalyst 2900MXL
Catalyst 3500XL Catalyst 5000
Catalyst 5000 Catalyst 5502
Catalyst 5505 Catalyst 5509
Catalyst 6000 Catalyst 6006
Catalyst 6009 Catalyst 6506
Catalytic 6509
Extreme *
Extreme Summit Extreme Alpine
Extreme Black Diamond **
Nortel
BayStack 450
Note:If the switch you selected does not support SwitchTap. "Unsupported Switch" is displayed in the dialog box ". You can use the switch option to select a suitable switch.
SwitchTap features
The image Configuration window of the SwitchTap application is displayed below.
The following is the switch status window.
Name is the most suitable Name detected by the OVC Application
IP Address is the IP Address of the vswitch.
Type is the switch Type detected by the OVC application. You can also manually change the Type
Mirror Sessions Configured provides the number of image dialogs Configured for the vswitch, which is the maximum number of images supported by the vswitch in the ARC.
Note: The number of image dialogs is currently running, not applied.
Refresh the image status to view the current image status.
Properties open the vswitch Properties window and select vswitch. However, you need to enter the vswitch password, enter the Telnet password to connect to the vswitch, and enter the privileged mode password to configure it. To configure the image, enter the two passwords.
Manage Mirror Sessions opens the current image dialog window for the selected switch.
You can add or clear an image for a vswitch. The switch name is displayed in the title of the window.
Mirror Sessions displays all configured image dialogs for the selected vswitch. Each configured image Displays the following information:
Name is the destination port of the image, including the module number, port number, and VLAN number.
Packet Direction indicates whether the Image Port Traffic allows two-way outbound and inbound traffic), or whether only outgoing traffic is allowed ).
Add Session is in the Select foreign port Destination dialog box. You can set the mirror port for the selected vswitch.
Note: When the maximum number of images that the switch can receive is reached, the number of images cannot be increased.
Use the routing portcategories configuration tree to select a port to connect to a device and set it to an Image Port. Once you select a port to be mirrored, the port information is displayed in the list on the right. If there are other devices connected to this Port, you can View it through the View Port button. View Port displays the devices connected to this Port in a tree structure.
The "Accept Incoming Packets" option indicates that two-way data can be accepted during mirroring.
Restrict Source Ports to Single VLAN selection column, which is used for configuration when the selected switch has multiple VLANs.
Note: After the Configuration is complete, You must select Apply Mirror Configuration on the Configuration homepage to Apply the Configuration.
Remove Session clear image
Remove All Mirror Sessions to stop All image operations.
Fluke Networks Tool
In the Fluke Networks Tool window, the following information is displayed:
The Selected Tool displays the Fluke Networks Tool that can be called by SwitchTap.
IP Address Fluke Networks tool Address
Module Fluke Networks
Port Fluke Networks
VLAN Fluke Networks
· Shared Port indicates that the vswitch Port is a Shared Port that connects multiple devices. The background color is displayed in yellow. If
It is a switch and is displayed in red.
Interface Type the Interface Type of the port connected by the Fluke Networks tool.
Status: port Status (Up or Down)
View Port displays the device type connected to the Port in a tree.
Configure as Mirror Port-Configure the selected Port as the Mirror Port in the selection bar, and then use the Apply Mirror configuration button.
Sources for this Mirror Port displays the source Port of the image. this window is disabled before being selected in the Configure as Mirror Port selection column, which is dark gray.
After you click Add Source, the Select multiple port Source dialog box is displayed. List alternative source ports in a tree.
Add Source can be used repeatedly to Add Source ports to multiple images.
Remove Source: Clear the selected image.
Apply Mirror Configuration to Apply Mirror Configuration. You can use SwitchStatus to view the Refresh in the window to Refresh the configuration result.
Configure as Mirror Port can also be deselected through the selection bar, and the configuration will be cleared.
Setting an image using SwitchTap is an important function of the switch. SwitchTap allows you to easily create, manage, and clear images. Using images can monitor network performance and diagnose faults. However, the use of images may also cause some problems. It is important to understand the image principles and correct configuration. Selecting an appropriate Image Port is a rigorous task. If you select a port shared by multiple devices for mirroring, it may cause harm to the network, such as forming a switching loop and generating overload traffic. Due to the complexity of the network, we only provide some general principles:
After carefully reading the manual, each vendor may have different products and understand the limits of each function, even if different versions of software are used for the same hardware product.
Suppose there is an analysis tool in the network, such as Fluke Networks OPV-WGA, to use the monitoring port to connect to the switch port as the mirror port, rather than the Management port connected to the port.
The switch does not receive data from the mirror port to avoid routing loops. If the Image Port is a shared port, you can avoid sending data to the network.
It is recommended that the Image Port and source port be in the same VLAN.
Some switches do not allow VLAN mixing. Even if the Image Port is not a shared port, the switch cannot mirror data from other VLANs.
Possible faults
If an image is configured to cause network problems, you need to quickly clear the image:
Use Remove All Mirror Sessions to clear All images for the selected vswitch.
Manually disconnect the Image Port. In this way, you can spend more time to eliminate the problem.
You can use Telnet, WEB, or Console configuration lines to directly connect to the vswitch for viewing or configuration.