A 100G leaf uplink is mirrored to a 10G sensor port — what does the IDS miss when an intruder crosses at peak?
answer
- the sensor gets a copy, not the original
- best-effort by design, not a fault
- aggregate mirrored bandwidth against one port
- peak hour, not average hour
- no counter, no error, no syslog
basics
~20 sMirroring is best-effort: the switch copies up to the destination port's line rate and discards the rest without disrupting forwarding. At peak the sensor receives a fraction of the uplink, so an intruder's packets can simply never arrive.
solid answer
~50 sA mirror (SPAN) session hands the sensor a *copy*, and the copy has no delivery guarantee. A 100G uplink carries up to 100 Gb/s in each direction, so a full mirror can offer 200 Gb/s of frames to a 10G destination port. Once that port is at line rate the switch drops the surplus copies and keeps forwarding production traffic normally — that is the intended behaviour, which is why nobody on the network side sees a fault. The loss is concentrated in the busiest hour, and it is random with respect to flows: the sensor gets a stream that looks well formed but has holes, so stream reassembly fails, signatures spanning a gap never match, and connection records show impossibly short byte counts. Closing it costs money — a faster sensor port, a packet broker fanning out to several sensors, or deliberately mirroring less.
go deeper
Be ready to say that a mirror gives the sensor a copy and the copy is dropped first when the destination port fills, and to do the bandwidth arithmetic out loud for a full-duplex uplink.
Explain why the drop is invisible: production forwarding is unaffected, many platforms expose no mirror-drop counter, and the sensor's own counters start at its NIC so they cannot see loss upstream of it.
Show the operational consequence — holed streams, failed reassembly, short connection records — and that loss concentrates in the peak window when bulk data movement is least remarkable.
Own the framing that filtering deliberately is better than being oversubscribed accidentally: chosen coverage has an owner and a record, random discard has neither, and both leave the same number of bits uninspected.
## What a mirror session actually promises Port mirroring (SPAN, monitor sessions) tells a switch to duplicate frames seen on a set of source ports or VLANs and emit the duplicates out a destination port. Everything about that sentence is a courtesy. The switch's contract is with the *forwarding* path: production frames must go where the forwarding table says, at line rate, with the configured queueing. The mirrored copy is generated on a best-effort basis and is the first thing discarded when something is full. ## The arithmetic nobody does before ordering the sensor A 100 Gb/s leaf uplink is full duplex. Mirroring both directions offers up to 200 Gb/s of frames to the destination. A 10 Gb/s destination port can carry 10. Even if the uplink averages a modest 15% utilisation — 15 Gb/s each way, 30 Gb/s of copies — the destination is oversubscribed 3:1 and roughly two thirds of the mirrored frames are discarded before they ever leave the switch. The same arithmetic bites at the aggregation stage. A packet broker fanning several mirror sessions and taps into a handful of sensor ports adds its own oversubscription: many ingress ports, few egress ports, shallow buffers. ## Why it is silent This is the property that makes the leaf worth an interview question: - No error appears on the **source** interface. Production forwarding was never affected, so there is no CRC error, no output drop on the path the users care about. - Many platforms do not expose a counter for frames dropped by the mirror engine at all. On the ones that do, nobody is graphing it. - The **sensor** cannot see the loss either. Its own capture counters only start at its NIC; everything discarded upstream never reaches a counter it can read. A sensor reporting zero capture drops is entirely consistent with the switch having thrown away 60% of the copies. - The destination port sitting pegged at exactly line rate is usually the only visible symptom, and it looks like a healthy, well-used link. ## What a holed stream does to detection An engine that reassembles TCP streams needs the segments. With random gaps: reassembly of the affected stream fails or is abandoned; a pattern that straddles the missing bytes never matches; a connection record may still exist (the handshake got through) but with byte counts far below what actually moved, which reads like an aborted transfer rather than a gap. The dangerous version is the middle case — enough traffic arrives that the sensor looks alive and productive, and the missing fraction is invisible. ## Why the timing favours an intruder without them trying Loss is not spread evenly across the day. It appears when the fabric is busiest: the nightly backup window, month-end batch, storage replication, a large restore. That is also when bulk movement of data is unremarkable, which is exactly when an intruder staging an archive out of a database tier prefers to work. Nobody has to know about the mirror ceiling to benefit from it. So the direction of the claim matters: **no alert during the peak window proves nothing at all.** It is consistent with a quiet estate, with a rule that did not match, and with the packets never arriving. ## What you can do, and what each option costs | Option | What it buys | What it costs | | --- | --- | --- | | Mirror less, on purpose | Loss becomes *chosen* and documented instead of random | You must decide which VLANs or uplinks go uninspected, and own that decision | | Faster destination port / newer sensor NIC | Raises the ceiling | Optics, NIC, more cores to keep up with the extra traffic | | Packet broker with fan-out | One aggregation point, load-balanced across several sensors | Broker chassis, per-port licensing, sensor count multiplies | | Optical tap instead of mirror | Removes the switch's mirror engine as the constraint | Fibre re-patching, an outage window per link, and you still have to aggregate the tap's two outputs | The important framing for an interview: the first row is not a defeat. Deterministic filtering converts an unfunded, invisible, random discard into a coverage decision with a named owner. That is a strictly better position even though the sensor sees the same number of bits. ## The trap to avoid in the answer Do not reassure yourself with a five-minute average. Mirror drops happen at sub-second timescales; a destination port averaging 35% over five minutes can be at line rate for hundreds of milliseconds at a time, and every frame offered during those bursts is gone.
- The sensor port graph shows 35% average utilisation over five minutes. Why is that not reassurance?Because mirror drops occur at burst timescales. A five-minute average smears sub-second microbursts flat, and the destination port can be at line rate for hundreds of milliseconds inside a window that averages a third. Everything offered during those bursts was discarded. To see it you need sub-second counters or a burst-capable measurement, not the standard polling interval.
- If you cannot get more capacity this year, what is the best thing to change?Narrow the mirror on purpose. Mirror specific VLANs, uplinks or flow classes rather than everything, or filter high-volume backup and replication traffic out at the source or at the broker. The sensor still sees a subset, but the subset is now chosen, documented and stable, rather than a random slice that shifts with the traffic mix and disappears exactly at peak.
- Does the sensor's own capture drop counter tell you about this loss?No. Its counters begin at its own NIC and capture ring, so they measure only what was lost after delivery. Frames discarded by the switch's mirror engine or by an upstream broker were never presented to the sensor and appear nowhere in its statistics. A sensor honestly reporting zero drops can still be receiving a fraction of the link.
A mirror session is a photocopier bolted to the mail room: when the post surges the copier just skips pages. The letters still get delivered on time, so nothing looks broken — and only the person reading the copies is missing anything.
saying these in an interview costs you the question
- Says mirroring is lossless because the switch runs at line rate
- Treats an absence of alerts at peak as evidence of no attack
- Reads average utilisation as proof that no frames were dropped
- Expects mirror drops to show as errors on the source interface
- Assumes the sensor's own drop counter covers upstream loss