This procedure uses TACACS+ and vty access lists to manage the users who have access to the mirror-enable command. An authorized user who issues the mirror-enable command then gains access to the packet mirroring CLI commands and information.
This technique enables you to restrict the visibility and use of packet mirroring commands to a controlled, authorized group of users.
Configure the router either to allow or disallow authorization when the TACACS+ servers are not available.
This procedure ensures that packet mirroring commands are never sent out of the E-series router—only the mirror-enable command is sent. The packet mirroring configuration and all information about mirrored interfaces and subscribers are available only to users who are authorized for the packet mirroring CLI commands on the router.