Overview
This section explains how local SPAN uses Access Control Lists (ACLs) to filter and mirror ingress traffic based on specific capture criteria. It details the benefits of selective mirroring for both permitted and denied packets to enhance network monitoring and security.
Local SPAN with an Access Control List (ACL) is a traffic mirroring feature that:
-
filters and mirrors ingress traffic
-
considers only Access Control Entries (ACEs) with capture keyword for traffic mirroring
-
captures both permit and deny packets if the ACE contains the capture keyword, and
-
allows one IPv4 ingress ACL and one IPv6 ingress ACL per interface.
Benefits of local SPAN with ACL
These are the benefits of local SPAN with ACL:
-
Traffic Filtering: Local SPAN with ACL allows precise filtering of ingress traffic, ensuring that only relevant data is mirrored based on specific criteria.
-
Selective Mirroring: By using the capture keyword in ACEs, you can selectively mirror both permitted and denied packets, providing flexibility in monitoring.
-
Efficient Monitoring: Specifying one IPv4 and one IPv6 ingress ACL per interface streamlines monitoring processes and reduces unnecessary data capture.
-
Enhanced Network Security: Filtering and mirroring ingress traffic can help identify and analyze potential security threats or anomalies in network traffic.