{"id":3817,"date":"2018-11-09T14:09:34","date_gmt":"2018-11-09T13:09:34","guid":{"rendered":"http:\/\/nil2.kis.fri.uniza.sk\/?p=3817"},"modified":"2019-05-17T14:31:42","modified_gmt":"2019-05-17T12:31:42","slug":"span","status":"publish","type":"post","link":"https:\/\/nil.uniza.sk\/en\/span\/","title":{"rendered":"Port-Mirroring"},"content":{"rendered":"<h2><a id=\"PortMirroring_0\"><\/a>Port-Mirroring<\/h2>\n<p>Port mirroring is used on a network switch to send a copy of network packets seen on one switch port (or an entire VLAN) to a network monitoring connection on another switch port. This is commonly used for network appliances that require monitoring of network traffic such as an intrusion detection system, passive probe or real user monitoring (RUM) technology that is used to support application performance management (APM).<\/p>\n<p>In our particular case, the faculty provided us with a Cisco Catalyst 2960 switch. We have configured this switch to mirror all internet-bound data traffic traversing the interface connected to network gateway, to the interface connected to Moloch server. As a result, we can now monitor all inbound and outbound lab traffic.<\/p>\n<pre><code>Switch(config)#monitor session 1 source fa0\/1 both  \n<\/code><\/pre>\n<p>\u2013 This command specifies source interface as <strong>fa 0\/1<\/strong>. The parameter \u201cboth\u201d specifies both directions to be monitored.<\/p>\n<pre><code>Switch(config)#monitor session 1 destination interface fa0\/24 \n<\/code><\/pre>\n<p>\u2013 This command defines the destination interface of mirrored traffic<\/p>\n<p><img decoding=\"async\" title=\"Port Mirror\" src=\"https:\/\/i.imgur.com\/KFz0YHB.png\" alt=\"Port-Mirror\" \/><\/p>\n<h3><a id=\"Sources_18\"><\/a>Sources<\/h3>\n<ul>\n<li><a href=\"http:\/\/opac.crzp.sk\/?fn=detailBiblioFormChild3&amp;sid=B7A4F0D5DE0EE4D8F05E77CD7EE5\">CRZP<\/a> Komplexn\u00fd syst\u00e9m pre detekciu \u00fatokov a archiv\u00e1ciu d\u00e1t &#8211; Moloch<\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Port-Mirroring Port mirroring is used on a network switch to send a copy of network packets seen on one switch port (or an entire VLAN) to a network monitoring connection on another switch port. This is commonly used for network appliances that require monitoring of network traffic such as an intrusion detection system, passive probe&#8230;<\/p>","protected":false},"author":6,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"footnotes":""},"categories":[872,751,687],"tags":[876,878,880,882],"class_list":["post-3817","post","type-post","status-publish","format-standard","hentry","category-network-security-moloch-en","category-monitoring-en","category-monitoring-management-measurement","tag-port-mirror","tag-port-mirroring","tag-span","tag-span-port"],"taxonomy_info":{"category":[{"value":872,"label":"Moloch"},{"value":751,"label":"Monitoring"},{"value":687,"label":"Monitoring, Management, Measurement"}],"post_tag":[{"value":876,"label":"port mirror"},{"value":878,"label":"port-mirroring"},{"value":880,"label":"SPAN"},{"value":882,"label":"SPAN port"}]},"featured_image_src_large":false,"author_info":{"display_name":"Tom\u00e1\u0161 Moko\u0161","author_link":"https:\/\/nil.uniza.sk\/en\/author\/tomas-mokos\/"},"comment_info":4,"category_info":[{"term_id":872,"name":"Moloch","slug":"network-security-moloch-en","term_group":0,"term_taxonomy_id":870,"taxonomy":"category","description":"","parent":707,"count":14,"filter":"raw","cat_ID":872,"category_count":14,"category_description":"","cat_name":"Moloch","category_nicename":"network-security-moloch-en","category_parent":707},{"term_id":751,"name":"Monitoring","slug":"monitoring-en","term_group":0,"term_taxonomy_id":749,"taxonomy":"category","description":"","parent":747,"count":2,"filter":"raw","cat_ID":751,"category_count":2,"category_description":"","cat_name":"Monitoring","category_nicename":"monitoring-en","category_parent":747},{"term_id":687,"name":"Monitoring, Management, Measurement","slug":"monitoring-management-measurement","term_group":0,"term_taxonomy_id":685,"taxonomy":"category","description":"","parent":0,"count":5,"filter":"raw","cat_ID":687,"category_count":5,"category_description":"","cat_name":"Monitoring, Management, Measurement","category_nicename":"monitoring-management-measurement","category_parent":0}],"tag_info":[{"term_id":876,"name":"port mirror","slug":"port-mirror","term_group":0,"term_taxonomy_id":874,"taxonomy":"post_tag","description":"","parent":0,"count":1,"filter":"raw"},{"term_id":878,"name":"port-mirroring","slug":"port-mirroring","term_group":0,"term_taxonomy_id":876,"taxonomy":"post_tag","description":"","parent":0,"count":1,"filter":"raw"},{"term_id":880,"name":"SPAN","slug":"span","term_group":0,"term_taxonomy_id":878,"taxonomy":"post_tag","description":"","parent":0,"count":1,"filter":"raw"},{"term_id":882,"name":"SPAN port","slug":"span-port","term_group":0,"term_taxonomy_id":880,"taxonomy":"post_tag","description":"","parent":0,"count":1,"filter":"raw"}],"_links":{"self":[{"href":"https:\/\/nil.uniza.sk\/en\/wp-json\/wp\/v2\/posts\/3817","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nil.uniza.sk\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nil.uniza.sk\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nil.uniza.sk\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/nil.uniza.sk\/en\/wp-json\/wp\/v2\/comments?post=3817"}],"version-history":[{"count":0,"href":"https:\/\/nil.uniza.sk\/en\/wp-json\/wp\/v2\/posts\/3817\/revisions"}],"wp:attachment":[{"href":"https:\/\/nil.uniza.sk\/en\/wp-json\/wp\/v2\/media?parent=3817"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nil.uniza.sk\/en\/wp-json\/wp\/v2\/categories?post=3817"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nil.uniza.sk\/en\/wp-json\/wp\/v2\/tags?post=3817"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}