Community discussions

MikroTik App
 
jamthejame
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 65
Joined: Mon Jan 15, 2018 12:12 pm

Port Mirroring - Traffic direction (ingress / egress)? ... trying to find the answer

Sat Jun 09, 2018 1:13 am

So, I'm in the midst of implementing monitoring solution, Security Onion OS. Now, my plan is to monitor specific Ethernet ports on Mikrotik via port mirroring.

The Problem:
The system is very tight and allows only few things (by design). Now, if I connect Security Onion OS and the 'seniors' into mirror sources, everything is OK.... BUT I would like to also connect Security Onion OS to the internet as then I'll have much more ability to analyze traffic, however my biggest concern is if Security Onion OS gets compromised, the sensors can be used to get access to the Mikrotik's and possibly compromised them.

Question:
If using port mirroring, the 'source mirror' is sending copy of packets to 'target mirror' Ethernet. Now, can 'target mirror' also send packets back to mikrotik? basically, does 'mirror traffics' do both way traffic or is it just sending copies of packets one way?
 
expert
Member Candidate
Member Candidate
Posts: 102
Joined: Sun Dec 04, 2016 1:22 pm

Re: Port Mirroring - Traffic direction (ingress / egress)? ... trying to find the answer

Thu Dec 12, 2024 11:35 pm

If using port mirroring, the 'source mirror' is sending copy of packets to 'target mirror' Ethernet. Now, can 'target mirror' also send packets back to mikrotik? basically, does 'mirror traffics' do both way traffic or is it just sending copies of packets one way?
Did you find answer to that? I'm interested too if that mirror is bi-directional or just one way.