<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>excITingIP.com &#187; port mirroring</title>
	<atom:link href="http://www.excitingip.com/tag/port-mirroring/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.excitingip.com</link>
	<description>How innovative IT Network infrastructure makes IP excITing!</description>
	<lastBuildDate>Mon, 26 Jul 2010 03:36:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Port Mirroring in Switches and In-line network taps</title>
		<link>http://www.excitingip.com/330/port-mirroring-in-switches-and-in-line-network-taps/</link>
		<comments>http://www.excitingip.com/330/port-mirroring-in-switches-and-in-line-network-taps/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 10:53:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Active N/w Components]]></category>
		<category><![CDATA[advantages and disadvantages of port mirroring and in-line network taps]]></category>
		<category><![CDATA[applications of port mirroring]]></category>
		<category><![CDATA[in-line network taps]]></category>
		<category><![CDATA[port mirroring]]></category>

		<guid isPermaLink="false">http://www.excitingip.com/330/port-mirroring-in-switches-and-in-line-network-taps/</guid>
		<description><![CDATA[This article eloborates on what is port mirroring, what are its applications, some of the features of port mirroring, advantages and dis-advantages of port mirroring in network switches. We also take a look in to the alternative of port mirroring called In-line Network taps, their advantages and dis-advantages.

]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><span style="font-family: sans-serif;"><br />
</span></p>
<div style="text-align: justify;"><span style="font-family: sans-serif;">This article elaborates on what is port mirroring, what are its applications, some of the features of port mirroring, advantages and dis-advantages of port mirroring in network switches. We also take a look in to the alternative of port mirroring called In-line Network taps, their advantages and dis-advantages.</span></p>
<p><span style="font-family: sans-serif;"><strong>What is Port Mirroring in Network Switches?</strong></span></p>
<p><span style="font-family: sans-serif;">Certain network switches can forward the copy of all in-bound and outbound traffic (packets) from one port (or multiple ports like a VLAN group) to another port designated by an administrator, simultaneously without affecting the normal operation of a switch. This is required for monitoring the network traffic (using a protocol analyser, for example), monitoring the performance of a switch and other applications as mentioned below:</span></p>
<p><span style="font-family: sans-serif;"><strong>Applications of Port Mirroring:</strong> </span></p>
<p><span style="font-family: sans-serif;"><strong>¤ Network Monitoring: </strong>Port mirroring could be used for monitoring switch traffic for applications like enforcing policies concerning network usage, file sharing etc, locating abnormal or heavy bandwidth usage from particular stations or applications. </span></p>
<p><span style="font-family: sans-serif;"><strong>¤ Intrusion Detection (IDS): </strong>Port mirroring can be used to monitor all incoming traffic for any anomalous or abnormal behaviour. This can be done by using a separate application like a protocol analyser/IDS System which can analyse all the incoming packets without affecting the normal operation of the switch. </span></p>
<p><span style="font-family: sans-serif;"><strong>¤ Call Logging for IP Phones: </strong>A network switch can forward to the IP Logging (Recording) server/ application, a copy of all the packets sent or received by IP Phones as all VOIP Calls need to go through the IP PBX. But this way, all the calls are recorded &#8220;unobtrusively&#8221;. </span></p>
<p><span style="font-family: sans-serif;">¤ <strong>Data Leakage Prevention through the Web:</strong> Certain application use Port Mirroring to monitor the traffic that is being sent to the internet by the users. This can enable those DLP applications to analyse if certain confidential information like medical records/ credit card information/ IP designs etc. are being sent to some one en-masse through webmail etc.</span></p>
<p><span style="font-family: sans-serif;"><strong>Features:</strong> Generally there is a limit to number of ports that you can configure as &#8220;mirrored&#8221; ports and normally the bi-directional traffic is dis-allowed on mirrored ports and traffic is only allowed in to the ports. You can either set the switch to forward all the packets to the mirrored port or send one in x number of packets for statistical sampling (some applications may not need all the packets for analysis). In certain switches the port mirroring can be used along with a firewall by setting up a filter to select certain packets for port mirroring. </span></p>
<p><span style="font-family: sans-serif;"><strong>Advantages of Port Mirroring:</strong> Since single port or multiple ports (selectively) can be monitored over a normal network switch (without the need of any additional components), port mirroring is more economical, simple to set up, easy to use and does not interrupt the normal network processes.</span></p>
<p><span style="font-family: sans-serif;"><strong>Dis-advantages of Port Mirroring:</strong> Port mirroring can cause buffer overflow and dropped packets since all the packets go through a buffer in the switch. So, accurate time sensitive measurements like jitter, packet gap analysis or latency measurement can become difficult. Also, there is additional load imposed on the CPU of the switch affecting the operational performance of the switch.</span></p>
<p><span style="font-family: sans-serif;"><strong>In-line Network Taps:</strong></span></p>
<p><span style="font-family: sans-serif;">In-line taps are passive components that are inserted directly in to a link for copper cables. They re-transmit the data stream back to the link and the probe. So, this way, the lines maybe tapped to monitor network information for that port, without the network being aware of it. There are even passive optical taps available for traffic monitoring in optical cables that contain a pair of passive optical beam splitters which divides the light entering each channel and separately channeled out to the link and to the probe. </span></p>
<p><span style="font-family: sans-serif;"><strong>Advantages of network taps: </strong>Network taps are passive components and are invisible to the network. They are more accurate in monitoring network traffic/ analysis (especially the traffic which depend on the timing values) and can see 100% of traffic on that link (meaning there is no packet drops with this method). </span></p>
<p><span style="font-family: sans-serif;"><strong>Dis-advantages of network taps: </strong>An extra component needs to be purchased per link (as they can be installed only on one link at a time) and simultaneous monitoring of multiple ports may not be feasible.</span></p>
<p><span style="font-family: sans-serif;"><strong>excITingIP.com</strong></span></p>
<p style="text-align: justify;"><span style="font-family: sans-serif;">In case you have any questions, you can get in touch with us using the <a href="http://www.excitingip.com/contact-form" target="_blank">contact form</a> or leave a comment below. You can also participate in the discussions in the <a href="http://www.excitingip.com/forum/" target="_blank">Forum.</a> </span><br />
<span style="font-family: sans-serif;"> </span></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.excitingip.com/330/port-mirroring-in-switches-and-in-line-network-taps/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
