Mirror
This skill should be used when the user asks to configure or troubleshoot port/flow mirroring on Huawei CloudEngine / S series switches for traffic analysis and packet capture. Covers local port mirror, remote port mirror (RSPAN/Layer-2/Layer-3), local flow mirror, ACL-based mirror, MQC-based mirror, and observe port (镜像目的端口) configuration. Applicable platforms S/CE switches (V200R011C10+/V200R022C00+) and USG firewalls (V500R005C20+/V600R007C20+) with platform-specific syntax differences.From its SKILL.md
npx -y skills add nanxiaoyao/network-huawei-skills --skill mirrorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
8.5 KB, ~3.0k tokens by cl100k_base, as published. Nobody here has run it
华为交换机镜像配置技能 (mirror)
适用平台 S 系列 V200R011C10+ | CE 系列 V200R022C00+ 文档来源 华为产品文档 dc_cfg_mirror_*
镜像把流量复制一份送到观察口 用于流量分析 抓包 安全审计 不影响原业务
触发场景
- 业务异常 要抓包定位
- 安全审计 流量监听
- 接 IDS/IPS/流量分析仪
- 排查广播风暴 / ARP 异常
- 验证 ACL 是否生效
- 配置远程镜像 跨设备送流量
镜像类型对比
| 类型 | 复制源 | 复制到 | 适用 |
|---|---|---|---|
| 本地端口镜像 Local Port | 接口入/出/双向 | 本机另一接口 | 单机抓包 最简单 |
| 远程端口镜像 RSPAN | 接口流量 | 远端设备的接口(经 VLAN 传输) | 跨设备抓包 |
| 本地流镜像 Local Flow | 符合 ACL 的流量 | 本机另一接口 | 精确抓取某类流量 |
| 远程流镜像 | 符合 ACL 的流量 | 远端接口 | 跨设备精准抓 |
| MQC 镜像 | 流分类匹配的流 | 本机/远端 | 灵活分类 |
基本概念
| 术语 | 解释 |
|---|---|
| 镜像源 mirror source | 被复制流量的接口或流 |
| 观察口 observe-port | 接收复制流量的接口(接抓包设备) |
| 镜像方向 | inbound 入 / outbound 出 / both 双向 |
| 镜像比例 | 全部 1:1 或按比例采样 |
配置三步走 本地端口镜像
1 配置观察口
system-view
observe-port 1 interface GigabitEthernet 0/0/24
观察口接抓包电脑或流量分析仪 不能再做其他业务
2 配置镜像源
interface GigabitEthernet 0/0/1
port-mirroring to observe-port 1 inbound # 入向
port-mirroring to observe-port 1 outbound # 出向
port-mirroring to observe-port 1 both # 双向
3 验证
display observe-port
display port-mirroring
远程镜像 RSPAN
拓扑
[源SW] → 业务VLAN透传镜像VLAN → [中间SW] → [目的SW with 观察口]
配置 源 SW
# 1 创建镜像 VLAN
vlan 100
description Mirror-VLAN
quit
# 2 观察口指向镜像 VLAN
observe-port 1 vlan 100
# 3 镜像源接口
interface GigabitEthernet 0/0/1
port-mirroring to observe-port 1 inbound
# 4 上联口透传镜像 VLAN
interface GigabitEthernet 0/0/24
port link-type trunk
port trunk allow-pass vlan 100
配置 中间 SW
# 只需透传镜像 VLAN
interface GigabitEthernet 0/0/1
port link-type trunk
port trunk allow-pass vlan 100
interface GigabitEthernet 0/0/2
port link-type trunk
port trunk allow-pass vlan 100
配置 目的 SW
# 1 镜像 VLAN
vlan 100
# 2 抓包口加入镜像 VLAN
interface GigabitEthernet 0/0/24
port link-type access
port default vlan 100
抓包设备从该接口收到所有源 SW 的镜像流量
本地流镜像(按 ACL)
# 1 定义 ACL 圈定关心的流量
acl number 3000
rule 5 permit tcp source 10.1.1.0 0.0.0.255 destination-port eq 80
quit
# 2 创建流分类
traffic classifier c1
if-match acl 3000
quit
# 3 创建流行为 引用观察口
traffic behavior b1
mirror to observe-port 1
quit
# 4 流策略绑定
traffic policy p1
classifier c1 behavior b1
quit
# 5 接口下发
interface GigabitEthernet 0/0/1
traffic-policy p1 inbound
命令体系
观察口
| 命令 | 视图 | 说明 |
|---|---|---|
| observe-port <id> interface <if> | system | 本地观察口 |
| observe-port <id> vlan <vid> | system | 远程观察口(送到 VLAN) |
| observe-port <id> interface <if> untag-packet | system | 去 Tag 输出 |
| undo observe-port <id> | system | 删除 |
| display observe-port [<id>] | - | 查看 |
端口镜像
| 命令 | 视图 | 说明 |
|---|---|---|
| port-mirroring to observe-port <id> { inbound | outbound | both } | interface | 接口启用镜像 |
| undo port-mirroring to observe-port <id> | interface | 取消 |
| display port-mirroring | - | 端口镜像列表 |
流镜像(MQC)
| 命令 | 说明 |
|---|---|
| traffic classifier <name> | 进入流分类 |
| if-match acl <num> | 匹配 ACL |
| if-match dscp <val> | 匹配 DSCP |
| if-match vlan-id <vid> | 匹配 VLAN |
| traffic behavior <name> | 进入流行为 |
| mirror to observe-port <id> | 行为:镜像 |
| traffic policy <name> | 流策略 |
| classifier <c> behavior <b> | 关联 |
| traffic-policy <name> { inbound | outbound } | 接口下发 |
流镜像(简化 ACL 方式)
# 部分款型支持 直接 ACL 配镜像
acl number 3000
rule 5 permit ip source ...
interface <if>
acl-mirror to observe-port 1 inbound acl 3000
验证与查看
| 命令 | 说明 |
|---|---|
| display observe-port | 观察口列表 |
| display port-mirroring | 端口镜像 |
| display traffic-policy interface | MQC 策略下发 |
| display traffic-policy statistics interface <if> | 流量统计 |
| display traffic classifier user-defined | 流分类 |
抓包建议
接抓包工具
- 观察口接电脑 → Wireshark/tcpdump 抓包
- 大流量场景接专用流量分析仪(如 NetScout)
限制流量
- 直接全口镜像可能淹没观察口 → 用流镜像精确抓
- 入向 + 出向 = 双向(不要重复配)
- 镜像比例(部分款支持):
port-mirroring to observe-port 1 inbound mirror-rate 10
常见陷阱
- 观察口被加业务 → 抓包电脑收到的不只镜像流量
- 观察口速率 < 源口总流量 → 观察口拥塞 镜像丢包
- 远程镜像没在中间设备透传镜像 VLAN → 远端收不到
- 镜像 VLAN 与业务 VLAN 冲突 → 业务异常
- 出向镜像在高速口资源占用高 → 部分款型限制
- 流镜像 ACL 写错 → 抓不到目标流量
排查流程
镜像不到流量
|
v
[1] display observe-port → 观察口是否配置
|
[2] display port-mirroring → 镜像源是否生效
|
[3] 观察口物理 UP?流量统计涨?
|
[4] 远程镜像?检查中间链路 VLAN 透传
|
[5] 流镜像?检查 ACL 是否匹配
相关文件
- references/mirror-commands.md 完整命令
- references/mirror-troubleshooting.md 故障排查
⚠️ 三平台命令语法差异(重要)
镜像在不同设备上语法差别大,使用前必须确认平台:
S 系列交换机(标准范式,本技能默认描述)
observe-port 1 interface GigabitEthernet 0/0/24
interface GigabitEthernet 0/0/1
port-mirroring to observe-port 1 inbound
- 观察口与镜像之间用
to连接
CE 系列交换机
observe-port 1 interface GigabitEthernet 0/0/24 [cir 1000 mbps] [truncate packet 128]
interface GigabitEthernet 0/0/1
port-mirroring observe-port 1 inbound # 注意:没有 to
- CE 命令没有
to关键字(port-mirroring observe-port <id> inbound直接写) - CE 支持限速
cir和截断truncate(S 系列功能较弱) - CE 新增
observe-port group <id>观察端口组(多端口聚合输出) - CE 配置完需要
commit提交(二阶段提交模型)
USG 防火墙(V500/V600)
interface GigabitEthernet 1/0/1
port-mirroring inbound # 直接在源接口启用
port-mirroring outbound
- 防火墙没有 observe-port 概念,镜像目的不可自由指定
- 镜像流量送往内置 CPU 处理或专用诊断接口
- 配合
capture-packet抓包命令使用更常见 - 没有 RSPAN(远程镜像)
三平台对比表
| 项 | S 系列 | CE 系列 | USG 防火墙 |
|---|---|---|---|
| 观察口语法 | observe-port <id> interface <if> | 同 S | ❌ 无 observe-port |
| 镜像启用 | port-mirroring to observe-port <id> inbound | port-mirroring observe-port <id> inbound(无 to) | port-mirroring inbound(直接接口启用) |
| 远程镜像 RSPAN | ✅ | ✅ | ❌ |
| 流镜像(MQC) | ✅ | ✅ | 有限支持 |
| 限速/截断 | 弱 | 强(cir + truncate) | - |
| 配置提交 | save | commit | save |
| 替代方案(防火墙抓包) | - | - | capture-packet interface <if> file-name xxx.pcap |
选型建议
- 抓包用:S/CE 走端口镜像送抓包电脑;USG 走
capture-packet直接保存 pcap - 排查流量异常:S/CE 用流镜像+ACL 精确抓;USG 用安全策略日志 + 会话表
What ships with it: 2 files
7.8 KB alongside SKILL.md
references/
- mirror-commands.md3.6 KB
- mirror-troubleshooting.md4.2 KB