To configure the router to support CLI-based
packet mirroring:
Configure the analyzer interface, the route to the analyzer
device, and any static ARP entries.
Allow authorized users to have access to the mirror-enable command. The users can then make the
packet mirroring CLI commands visible and perform the following steps.
Configure the secure policy that forwards the mirrored
traffic to the analyzer device.
(Optional) For increased security, create an IPSec tunnel
between the analyzer interface and the analyzer device.
For interface-specific mirroring, attach the secure policy
to the interface.
For user-specific mirroring, configure the trigger that
identifies the user.