Guidelines for Configuring Subscriber Secure Policy Mirroring on the Flow-Tap Service
The subscriber secure policy service runs on the flow-tap service infrastructure. When configuring subscriber secure policy mirroring, consider the following guidelines regarding the relationship between subscriber secure policy service and the flow-tap service:
- Subscriber secure policy inherits the limitations of the flow-tap service. For example, port mirroring and the flow-tap service cannot run simultaneously on the router. Therefore, port mirroring and subscriber secure policy mirroring cannot run simultaneously on the same router.
- You can configure one instance of the flow-tap service on the router. Both subscriber secure policy RADIUS-initiated mirroring and DTCP-initiated mirroring use the flow-tap service.
- If you configure both RADIUS-initiated mirroring and DTCP-initiated mirroring, and the two mirroring requests are the same, duplicate mirrored traffic is sent to the mediation device.
- You cannot delete the flow-tap service configuration while a subscriber secure policy mirroring session is active on the service.
