The analyzer device must be configured to receive the mirrored traffic from the E-series router’s analyzer interface. You can use the default keyword with the interface command to configure an interface as the virtual router’s default analyzer interface; it is then used when an analyzer interface is not explicitly specified in the ip mirror command. You cannot configure multiaccess interfaces, such as IP over Ethernet, as default analyzer interfaces.
You can configure any type of IP interface on the E-series router as an analyzer interface, except for special interfaces such as SRP interfaces, null interfaces, and loopback interfaces. An interface cannot be both an analyzer interface and a mirrored interface at the same time. A single analyzer interface can serve multiple mirrored sessions.
The receive side of an analyzer interface is disabled; all traffic attempting to access the router through an analyzer interface is dropped. Analyzer interfaces drop all nonmirrored traffic.
You can configure IP or GRE analyzer interfaces to enable traffic to flow between tunnel endpoints that are local to the router. The tunnel can be located on a shared tunnel server port or line module. For a complete list of the line modules and I/O modules available for ERX-14xx models, ERX-7xx models, and the ERX-310 router, see ERX Module Guide. For more information about line modules and IOAs available with the E120 and E320 routers, see E120 and E320 Module Guide.
Policies are not supported on analyzer interfaces. When you configure an analyzer interface, existing policies are disabled, and no new policies are accepted.