Created on 07-22-2015 05:34 PM Edited on 08-18-2024 01:31 PM By Jean-Philippe_P
Description
Scope
Solution
Note:
The hardware switch does not support multiple source ports. To specify multiple source ports for SPAN, it is possible to use a software switch instead.
config system switch-interface
edit <port>
set span enable
set span-source-port <port> <port> <----- Multiple ports specified separated by space.
set span-dest-port <port>
set span-direction {both | tx | rx}
end
end
Note:
If mirroring WAN interfaces is required, it is necessary to create a virtual switch interface and add at least two ports to it: one for the WAN connection and one for the mirror port. The virtual switch interface should function as the WAN connection without issues.
It is important to note that before adding the WAN port to the virtual switch, it is necessary to remove the WAN port from all existing references. After configuring the virtual switch and the port mirroring, it is recommended to update the firewall policies and any other references to replace the old WAN interface with the new WAN-SPAN interface.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.