09-05-2020 07:41 PM
Is it possible to create a span/mirror port on the Firepower 1010 device using the FMC console? I am using the firewall in routed mode but want all the network traffic to be mirrored on one port so I can do some traffic analysis with the security onion.
09-06-2020 12:19 AM
09-06-2020 05:44 AM - edited 09-06-2020 06:00 AM
I tried to make one port passive but I didnt see any traffic on it. I have 5 routed networks on the firepower device. I have the passive port connected to an esxi server.
09-06-2020 07:44 AM
Are you sure the traffic is leaving the ESXi server on that port? That's by far the most likely cause of an issue such as you describe.
09-06-2020 08:40 AM - edited 09-06-2020 08:40 AM
I was thinking that the firewall would be the one sending ALL the traffic to the passive port. From there I would connect from the firewall "Span" port >>>>to the computer's 2nd network interface I was going to use for analysis.
09-06-2020 11:49 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide