Users Guide

EXEC mode
EXEC Privilege mode
show run monitor session
Dell#show run monitor session
!
monitor multicast-queue 7
Dell#
Enabling Flow-Based Monitoring
Flow-based monitoring conserves bandwidth by monitoring only specied trac instead of all trac on the interface. This feature is
particularly useful when looking for malicious trac. It is available for Layer 2 and Layer 3 ingress trac. You can specify trac using
standard or extended access-lists.
NOTE: Flow-based monitoring is not supported for egress trac.
1 Enable ow-based monitoring for a monitoring session.
MONITOR SESSION mode
flow-based enable
2 Dene IP access-list rules that include the keyword monitor. For port monitoring, Dell Networking OS only considers trac matching
rules with the keyword
monitor.
CONFIGURATION mode
ip access-list
Refer to .
3 Apply the ACL to the monitored port.
INTERFACE mode
ip access-group access-list
Example of the flow-based enable Command
To view an access-list that you applied to an interface, use the show ip accounting access-list command from EXEC Privilege
mode.
Remote Port Mirroring
While local port monitoring allows you to monitor trac from one or more source ports by directing it to a destination port on the same
switch/router, remote port mirroring allows you to monitor Layer 2 and Layer 3 ingress and/or egress trac on multiple source ports on
dierent switches and forward the mirrored trac to multiple destination ports on dierent switches.
Remote port mirroring helps network administrators monitor and analyze trac to troubleshoot network problems in a time-saving and
ecient way.
In a remote-port mirroring session, monitored trac is tagged with a VLAN ID and switched on a user-dened, non-routable L2 VLAN. The
VLAN is reserved in the network to carry only mirrored trac, which is forwarded on all egress ports of the VLAN. Each intermediate
switch that participates in the transport of mirrored trac must be congured with the reserved L2 VLAN. Remote port monitoring
supports mirroring sessions in which multiple source and destination ports are distributed across multiple switches
Port Monitoring
663