Hyper-V Port Mirroring with Tagged Traffic
i have asked question advanced threat analytics forum applies hyper-v port mirroring figured may helpful forum well. below scenario looking configure hyper-v port mirroring tagged traffic, can done , if how?
i attempting test ata , have created test dc , ata gateway connected same virtual switch on same hyper-v host (2012r2, recommended patches installed). have enabled "microsoft ndis capture" on virtual switch , configure dc source , secondary none routable vnic on gateway destination (1.1.1.1/30, no dns or gateway). vnics tagged on test vlan (all traffic must tagged on these hosts) , fear may issue. hyper-v port mirroring support tagged traffic? issue , if how solve problem.
i led assumption due following link: https://cloudbase.it/hyper-v-promiscuous-mode/
which states: "traffic generated on vm vnic set tag traffic vlan id cannot directly monitored on vm, unless trunking set on target" , suggests running following command: "set-vmnetworkadaptervlan vm3 -trunk -allowedvlanidlist "100,101" -nativevlanid 0"
however tried specified "mirror" nic the gateway as , it did not work. worth mentioning have not yet installed gateway , have used microsoft network monitor tool in promiscuous mode prescribed , returned no results ldap or kerberosv5. assistance appreciated.
hi diggity,
i have seen case mirroring not working. packets reaching hyper-v switch being tagged 802.1q tag, it caused hyper-v switch drop packets. please contact network guys see if packets can mirrored hyper-v switch without 802.1q tags.
if still not working, suggest open case microsoft, more in-depth investigation can done more satisfying explanation , solution issue.
here link:
https://support.microsoft.com/en-us/gp/support-options-for-business
best regards,
leo
please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com.
Windows Server > Hyper-V
Comments
Post a Comment