#加组
set groups mirror_pkts_in forwarding-options port-mirroring instance mirror_in input rate 1
set groups mirror_pkts_in forwarding-options port-mirroring instance mirror_in family inet output interface ge-1/2/1.0 next-hop 10.10.1.2
set groups mirror_pkts_out forwarding-options port-mirroring instance mirror_out input rate 1
set groups mirror_pkts_out forwarding-options port-mirroring instance mirror_out family inet output interface ge-1/2/2.0 next-hop 10.10.1.6
#匹配策略
set firewall family inet filter mirror_in apply-groups mirror_pkts_in
set firewall family inet filter mirror_in term catch_all then port-mirror-instance mirror_in
set firewall family inet filter mirror_in term catch_all then accept
set firewall family inet filter mirror_out apply-groups mirror_pkts_out
set firewall family inet filter mirror_out term catch_all then port-mirror-instance mirror_out
set firewall family inet filter mirror_out term catch_all then accept
#对应板卡
set chassis fpc 1 pic 2 port-mirror-instance mirror_in
set chassis fpc 1 pic 2 port-mirror-instance mirror_out
#加源
set interfaces ge-1/2/9 unit 0 family inet filter input mirror_out
set interfaces ge-1/2/9 unit 0 family inet filter output mirror_in
#目标策略,前提目标接口有ip地址
set forwarding-options port-mirroring instance mirror_in input rate 1
set forwarding-options port-mirroring instance mirror_in input run-length 1
set forwarding-options port-mirroring instance mirror_in family inet output interface ge-1/2/1.0 next-hop 10.10.1.2
set forwarding-options port-mirroring instance mirror_in family inet output no-filter-check
set forwarding-options port-mirroring instance mirror_out input rate 1
set forwarding-options port-mirroring instance mirror_out input run-length 1
set forwarding-options port-mirroring instance mirror_out family inet output interface ge-1/2/2.0 next-hop 10.10.1.6
set forwarding-options port-mirroring instance mirror_out family inet output no-filter-check
#绑定目标mac
set interfaces ge-1/2/1 description mirror-out
set interfaces ge-1/2/1 unit 0 family inet address 10.10.1.1/30 arp 10.10.1.2 mac 00:90:0b:1b:0b:dd
set interfaces ge-1/2/2 description mirror-in
set interfaces ge-1/2/2 unit 0 family inet address 10.10.1.5/30 arp 10.10.1.6 mac 00:90:0b:1b:0b:de
阅读(644) | 评论(0) | 转发(0) |