What does a port mirroring (SPAN) session on an Ethernet switch do, and why do you need one to capture other hosts' traffic?
answer
- a switch is not a hub
- known unicast goes to one port
- a copy, not a diversion
- source, direction, destination port
- receive means what the host sends
basics
~20 sA SPAN session makes an Ethernet switch copy frames received, sent, or both on chosen source ports or VLANs to a destination port for a capture host. It is needed because a switch sends known unicast only out of the destination's port.
solid answer
~50 sAn Ethernet switch learns which port each MAC address lives on and forwards known unicast only out of that port, so a capture host on a spare port sees its own traffic, broadcasts and the odd flooded frame, never two servers' conversation. Port mirroring - **SPAN** (Switch Port Analyzer) is one vendor's name for it that became the common shorthand - tells the switch to copy frames from source ports or VLANs, in the receive direction, the transmit direction or both, to a destination port. The originals are forwarded exactly as before; the copies are extra. Direction is the switch's view: *receive* on a server's port is what the server sends. Mirroring has no IEEE or IETF specification, so what is copied, whether tags survive and how drops are handled vary by platform, and copies are typically served after production traffic when the switch is busy.
go deeper
Recall that a switch forwards known unicast only to the destination's port, so capturing other hosts needs a mirror session that copies chosen source ports to a destination port.
Explain sources, directions and the destination port, and that receive means the frames the attached host sends; show why both directions are needed to see a whole conversation.
Treat a mirror as a best-effort copy the switch drops first under load; check direction, source coverage and destination speed before trusting what a capture is missing.
Weigh mirroring's zero-touch convenience against its lack of any standard or delivery guarantee when deciding whether operations can rely on it or permanent TAPs are needed.
## Why a spare switch port sees almost nothing An **Ethernet switch** learns which port each source MAC address arrives on and, once it knows a destination, forwards a unicast frame only out of that destination's port. Broadcast frames, multicast the switch does not constrain, and unicast to an address it has not learned yet are flooded to every port in the VLAN; nothing else is. So a **capture host** plugged into a spare port sees its own traffic, some broadcast and multicast, and the occasional flooded frame - never the steady conversation between two servers on other ports. Putting the capture interface into promiscuous mode does not change this. Promiscuous mode only stops the host's own network interface from discarding frames addressed to someone else; on a switch, those frames are never sent to the capture port in the first place. On an old shared hub every port heard everything, which is why "just plug in and listen" used to work. ## What a mirror session is made of **Port mirroring** asks the switch to make extra copies. Its common name, **SPAN** (Switch Port Analyzer), is one vendor's term that the industry adopted as shorthand. There is no IEEE or IETF specification of the feature, so every platform implements its own variant, but a local session always has the same parts: | Part | What it says | Typical choices | |---|---|---| | Source | which traffic to copy | one or more ports, or every port in a VLAN | | Direction | which way through the source | receive (into the switch), transmit (out of it), or both | | Destination | where the copies leave | one port, with the capture host attached | | Filter (optional) | which copies to keep | platform-dependent match rules | Direction is named from the switch's point of view. **Receive** on a server's port means the frames the server *sends* into the switch; **transmit** means the frames the switch delivers *to* the server. Mirroring both directions of one port shows that host's whole conversation. ## A copy, not a diversion - The original frame is forwarded **exactly as it would have been**; the mirror only adds a duplicate. The monitored hosts' traffic takes the same path at the same speed. - The destination port typically stops behaving as an ordinary port: it transmits the copies and usually does not learn addresses or forward normal traffic to the capture host. - Copies are **best effort**. When the switch is busy, mirrored copies are typically served after production traffic and dropped first, and nothing ever retransmits a lost copy. - What gets copied varies by platform: frames that fail the frame check sequence are typically discarded before any copy is made, some layer-2 control frames are typically not copied, and whether the original VLAN tag survives on the destination port depends on the platform and the session settings. ## Local, remote and encapsulated mirrors A **local** session keeps source and destination on one switch. When the capture host sits elsewhere, vendor extensions carry the copies. **RSPAN** places them in a VLAN reserved for the session so trunks can carry them to another switch. **ERSPAN** wraps each copy in GRE inside IP so it can be routed; its format is described only in an expired Informational Internet-Draft, `draft-foschiano-erspan-03`, never in an RFC. The alternative to all of them is a **TAP**, a device inserted into the link itself that copies the signal on the cable rather than asking the switch to copy frames. ## Checking a session before trusting the capture 1. **Is the direction right?** Receive-only on one host's port shows half of every conversation: requests without replies, data without acknowledgements. 2. **Does the source cover the path?** Traffic between two hosts that never crosses a mirrored port or VLAN is simply not in the capture. 3. **Is the destination fast enough?** Both directions of a full-duplex link can together offer twice the link speed to one destination port, and the excess is dropped. 4. **Is the capture host keeping up?** A host that drops copies looks, in the capture, exactly like a mirror that never sent them; that stage belongs to the capture tooling rather than to the switch. A mirror is the quickest way to see packets without touching cabling, which is why troubleshooting reaches for it first. Its weakness is the same as its strength: the switch decides what it copies, and it copies only what it has spare capacity for. Treat a mirror capture as strong evidence of what *was* there, and as weak evidence of what was not.
- On an Ethernet switch, why doesn't promiscuous mode on the capture host replace a mirror session?Promiscuous mode only stops the host's own interface from discarding frames addressed to someone else. On a switch the frames never arrive: known unicast is forwarded only out of the destination's port, so there is nothing for the capture port to keep. Promiscuous mode matters on a mirror's destination port, where the copies carry other hosts' addresses; it cannot create copies the switch never sends.
- In port mirroring, what do you lose by copying only one direction of a server's port?Receive on a server's port copies only what the server sends; transmit copies only what it receives. With one direction every conversation is one-sided - requests without replies, data without acknowledgements - so handshakes, round-trip times and retransmissions cannot be read. Mirror both directions of that one port, or, when both hosts sit on the same switch, receive on both of their ports.
A mirror session is like adding a CC address to everything one person sends: the original still reaches its recipient unchanged, the CC is an extra copy, and if the CC mailbox is full the copy is lost while the original is still delivered.
saying these in an interview costs you the question
- Promiscuous mode on the capture host is enough to see every host's traffic on a switch.
- A SPAN session diverts the monitored traffic, so the hosts lose packets while it runs.
- Mirroring the receive direction of a server's port shows the frames sent to that server.
- Port mirroring is an IEEE standard, so every switch copies exactly the same frames.
- A mirrored copy is delivered with the same guarantee as the original frame.