agentsclimarketplace

Mirror

Skill nanxiaoyao/network-huawei-skills/mirror

Huawei network device (USG firewall + S/CE switch) CLI skills pack for OpenClaw AI agent — also usable as a standalone cheatsheet.

Install
npx -y skills add nanxiaoyao/network-huawei-skills --skill mirror

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

This skill should be used when the user asks to configure or troubleshoot port/flow mirroring on Huawei CloudEngine / S series switches for traffic analysis and packet capture. Covers local port mirror, remote port mirror (RSPAN/Layer-2/Layer-3), local flow mirror, ACL-based mirror, MQC-based mirror, and observe port (镜像目的端口) configuration. Applicable platforms S/CE switches (V200R011C10+/V200R022C00+) and USG firewalls (V500R005C20+/V600R007C20+) with platform-specific syntax differences.

SKILL.md

8.5 KB, ~3.0k tokens by cl100k_base, as published. Nobody here has run it

华为交换机镜像配置技能 (mirror)

适用平台 S 系列 V200R011C10+ | CE 系列 V200R022C00+ 文档来源 华为产品文档 dc_cfg_mirror_*

镜像把流量复制一份送到观察口 用于流量分析 抓包 安全审计 不影响原业务

触发场景

  • 业务异常 要抓包定位
  • 安全审计 流量监听
  • 接 IDS/IPS/流量分析仪
  • 排查广播风暴 / ARP 异常
  • 验证 ACL 是否生效
  • 配置远程镜像 跨设备送流量

镜像类型对比

类型复制源复制到适用
本地端口镜像 Local Port接口入/出/双向本机另一接口单机抓包 最简单
远程端口镜像 RSPAN接口流量远端设备的接口(经 VLAN 传输)跨设备抓包
本地流镜像 Local Flow符合 ACL 的流量本机另一接口精确抓取某类流量
远程流镜像符合 ACL 的流量远端接口跨设备精准抓
MQC 镜像流分类匹配的流本机/远端灵活分类

基本概念

术语解释
镜像源 mirror source被复制流量的接口或流
观察口 observe-port接收复制流量的接口(接抓包设备)
镜像方向inbound 入 / outbound 出 / both 双向
镜像比例全部 1:1 或按比例采样

配置三步走 本地端口镜像

1 配置观察口

system-view
observe-port 1 interface GigabitEthernet 0/0/24

观察口接抓包电脑或流量分析仪 不能再做其他业务

2 配置镜像源

interface GigabitEthernet 0/0/1
 port-mirroring to observe-port 1 inbound      # 入向
 port-mirroring to observe-port 1 outbound     # 出向
 port-mirroring to observe-port 1 both         # 双向

3 验证

display observe-port
display port-mirroring

远程镜像 RSPAN

拓扑

[源SW] → 业务VLAN透传镜像VLAN → [中间SW] → [目的SW with 观察口]

配置 源 SW

# 1 创建镜像 VLAN
vlan 100
 description Mirror-VLAN
 quit

# 2 观察口指向镜像 VLAN
observe-port 1 vlan 100

# 3 镜像源接口
interface GigabitEthernet 0/0/1
 port-mirroring to observe-port 1 inbound

# 4 上联口透传镜像 VLAN
interface GigabitEthernet 0/0/24
 port link-type trunk
 port trunk allow-pass vlan 100

配置 中间 SW

# 只需透传镜像 VLAN
interface GigabitEthernet 0/0/1
 port link-type trunk
 port trunk allow-pass vlan 100
interface GigabitEthernet 0/0/2
 port link-type trunk
 port trunk allow-pass vlan 100

配置 目的 SW

# 1 镜像 VLAN
vlan 100

# 2 抓包口加入镜像 VLAN
interface GigabitEthernet 0/0/24
 port link-type access
 port default vlan 100

抓包设备从该接口收到所有源 SW 的镜像流量

本地流镜像(按 ACL)

# 1 定义 ACL 圈定关心的流量
acl number 3000
 rule 5 permit tcp source 10.1.1.0 0.0.0.255 destination-port eq 80
 quit

# 2 创建流分类
traffic classifier c1
 if-match acl 3000
 quit

# 3 创建流行为 引用观察口
traffic behavior b1
 mirror to observe-port 1
 quit

# 4 流策略绑定
traffic policy p1
 classifier c1 behavior b1
 quit

# 5 接口下发
interface GigabitEthernet 0/0/1
 traffic-policy p1 inbound

命令体系

观察口

命令视图说明
observe-port <id> interface <if>system本地观察口
observe-port <id> vlan <vid>system远程观察口(送到 VLAN)
observe-port <id> interface <if> untag-packetsystem去 Tag 输出
undo observe-port <id>system删除
display observe-port [<id>]-查看

端口镜像

命令视图说明
port-mirroring to observe-port <id> { inbound | outbound | both }interface接口启用镜像
undo port-mirroring to observe-port <id>interface取消
display port-mirroring-端口镜像列表

流镜像(MQC)

命令说明
traffic classifier <name>进入流分类
if-match acl <num>匹配 ACL
if-match dscp <val>匹配 DSCP
if-match vlan-id <vid>匹配 VLAN
traffic behavior <name>进入流行为
mirror to observe-port <id>行为:镜像
traffic policy <name>流策略
classifier <c> behavior <b>关联
traffic-policy <name> { inbound | outbound }接口下发

流镜像(简化 ACL 方式)

# 部分款型支持 直接 ACL 配镜像
acl number 3000
 rule 5 permit ip source ...
interface <if>
 acl-mirror to observe-port 1 inbound acl 3000

验证与查看

命令说明
display observe-port观察口列表
display port-mirroring端口镜像
display traffic-policy interfaceMQC 策略下发
display traffic-policy statistics interface <if>流量统计
display traffic classifier user-defined流分类

抓包建议

接抓包工具

  • 观察口接电脑 → Wireshark/tcpdump 抓包
  • 大流量场景接专用流量分析仪(如 NetScout)

限制流量

  • 直接全口镜像可能淹没观察口 → 用流镜像精确抓
  • 入向 + 出向 = 双向(不要重复配)
  • 镜像比例(部分款支持):port-mirroring to observe-port 1 inbound mirror-rate 10

常见陷阱

  • 观察口被加业务 → 抓包电脑收到的不只镜像流量
  • 观察口速率 < 源口总流量 → 观察口拥塞 镜像丢包
  • 远程镜像没在中间设备透传镜像 VLAN → 远端收不到
  • 镜像 VLAN 与业务 VLAN 冲突 → 业务异常
  • 出向镜像在高速口资源占用高 → 部分款型限制
  • 流镜像 ACL 写错 → 抓不到目标流量

排查流程

镜像不到流量
  |
  v
[1] display observe-port → 观察口是否配置
  |
[2] display port-mirroring → 镜像源是否生效
  |
[3] 观察口物理 UP?流量统计涨?
  |
[4] 远程镜像?检查中间链路 VLAN 透传
  |
[5] 流镜像?检查 ACL 是否匹配

相关文件

  • references/mirror-commands.md 完整命令
  • references/mirror-troubleshooting.md 故障排查

⚠️ 三平台命令语法差异(重要)

镜像在不同设备上语法差别大,使用前必须确认平台:

S 系列交换机(标准范式,本技能默认描述)

observe-port 1 interface GigabitEthernet 0/0/24
interface GigabitEthernet 0/0/1
 port-mirroring to observe-port 1 inbound
  • 观察口与镜像之间用 to 连接

CE 系列交换机

observe-port 1 interface GigabitEthernet 0/0/24 [cir 1000 mbps] [truncate packet 128]
interface GigabitEthernet 0/0/1
 port-mirroring observe-port 1 inbound          # 注意:没有 to
  • CE 命令没有 to 关键字port-mirroring observe-port <id> inbound 直接写)
  • CE 支持限速 cir 和截断 truncate(S 系列功能较弱)
  • CE 新增 observe-port group <id> 观察端口组(多端口聚合输出)
  • CE 配置完需要 commit 提交(二阶段提交模型)

USG 防火墙(V500/V600)

interface GigabitEthernet 1/0/1
 port-mirroring inbound                          # 直接在源接口启用
 port-mirroring outbound
  • 防火墙没有 observe-port 概念,镜像目的不可自由指定
  • 镜像流量送往内置 CPU 处理或专用诊断接口
  • 配合 capture-packet 抓包命令使用更常见
  • 没有 RSPAN(远程镜像)

三平台对比表

S 系列CE 系列USG 防火墙
观察口语法observe-port <id> interface <if>同 S❌ 无 observe-port
镜像启用port-mirroring to observe-port <id> inboundport-mirroring observe-port <id> inbound(无 to)port-mirroring inbound(直接接口启用)
远程镜像 RSPAN
流镜像(MQC)有限支持
限速/截断强(cir + truncate)-
配置提交savecommitsave
替代方案(防火墙抓包)--capture-packet interface <if> file-name xxx.pcap

选型建议

  • 抓包用:S/CE 走端口镜像送抓包电脑;USG 走 capture-packet 直接保存 pcap
  • 排查流量异常:S/CE 用流镜像+ACL 精确抓;USG 用安全策略日志 + 会话表

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.