Packet loss on mirror port on CRS326-24G-2S+ Rev. 2
Posted: Sat Jan 25, 2025 10:44 pm
I am trying to setup Securityonion to make a SOC in my home network. I use a Topton N100 firewall PC with 4x 2.5 gbit/s Intel i226-v network cards for Securityonion. The management interface is connected to Port9 (1 gbit/s), and the mirror interface is connected to the SFP1 port (2.5 gbit/s). I am using the MikroTik S+RJ10 for SFP module + shielded cat 6 RJ45 cables.
The SwOS version is 2.17 (the newest).
The switch is configured with these settings: When I download with approx. 700 mbit/s from the Internet (the router is on port 1, and the client is on port 24), the packet loss on the mirror port is approx. 52% (it is mentioned as 52% capture loss in Securyonion). Because there are no Zeek Loss or Suricata Loss in Securityonion, the high packet loss is not due to Securityonion (https://docs.securityonion.net/en/2.4/g ... pture-loss). Even with low download speed (under 30 mbit/s), the packet loss is high (over 20%).
I have tried the following:
- Limit the mirror ingress and mirror egress port in the Forwarding tab
- Disabled (unmark) mirror ingress and mirror egress on all ports in the Forwarding tab, and enabled (mark) "mirror" on all VLANs in the VLANs tab
I dont know how to move on from here, and what I may have done wrong in the configuration.
The SwOS version is 2.17 (the newest).
The switch is configured with these settings: When I download with approx. 700 mbit/s from the Internet (the router is on port 1, and the client is on port 24), the packet loss on the mirror port is approx. 52% (it is mentioned as 52% capture loss in Securyonion). Because there are no Zeek Loss or Suricata Loss in Securityonion, the high packet loss is not due to Securityonion (https://docs.securityonion.net/en/2.4/g ... pture-loss). Even with low download speed (under 30 mbit/s), the packet loss is high (over 20%).
I have tried the following:
- Limit the mirror ingress and mirror egress port in the Forwarding tab
- Disabled (unmark) mirror ingress and mirror egress on all ports in the Forwarding tab, and enabled (mark) "mirror" on all VLANs in the VLANs tab
I dont know how to move on from here, and what I may have done wrong in the configuration.