Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Port mirroring on SG-2100 and SG-3100

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pf.Beginner
      last edited by

      I have a question about port mirroring and the SG-2100 and SG-3100.

      I’ve been using pfSense on an old computer for use as a firewall between my lab network and home network. Circumstances mean that I will have to continue using my ISP router/modem for at least 6 months. The network looks like this (WAN on pfSense is configured as a static ipv4 address):

      Network1.png

      This is not an ideal setup, however I will soon be moving and can re-do the entire network at that time; nonetheless, I need to replace my pfSense box with a Netgate appliance right away.

      I would like to experiment with port mirroring and had planned to add a Raspberry-Pi to the network like this:

      Network2.png

      The Raspberry-Pi would analyze the traffic between the ISP router and Lab Network. I realize that pfSense can run Suricata, but I would like to use the Pi as shown in the diagram as a learning opportunity.

      I read that the SG-2100 and SG-3100 do not support STP on the LAN ports. I’m a beginner in networking and from what I have read STP ≠ port mirroring, but from what I have learned so far, it seems related.

      Can the SG-2100 or SG-3100 support port mirroring? Could the WAN of either appliance be mirrored to LAN1 (in the SG-2100) or to OPT (in the SG-3100)?

      Mirrored Ports.png

      johnpozJ JKnottJ 2 Replies Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @pf.Beginner
        last edited by

        Don't you have a smart switch.. Even cheap <$40 smart switch would support mirroring or span.. And no span is not the same as stp..

        Off the top of my head, I wouldn't think 2100 or 3100 support span/mirror port. But I would think a "lab" has a smart/managed switch in it ;)

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • JKnottJ
          JKnott @pf.Beginner
          last edited by

          @pf-beginner said in Port mirroring on SG-2100 and SG-3100:

          I read that the SG-2100 and SG-3100 do not support STP on the LAN ports. I’m a beginner in networking and from what I have read STP ≠ port mirroring, but from what I have learned so far, it seems related.

          Spanning Tree Protocol and mirroring are 2 different things. STP is used to prevent loops, when multiple switches are used. Mirroring allows you to monitor a network connection, using Wireshark or similar. The only thing they have in common is they both use a managed switch. For port mirroring, you can configure a managed switch as a data tap.

          PfSense running on Qotom mini PC
          i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
          UniFi AC-Lite access point

          I haven't lost my mind. It's around here...somewhere...

          P 1 Reply Last reply Reply Quote 0
          • P
            pf.Beginner @JKnott
            last edited by

            @jknott Thanks for the link to your data tap post, that's just the step-by-step guide I needed!

            @johnpoz I guess I've been watching too many networking videos on Youtube. The so-called "Lab" in the diagrams above could more accurately be termed "a disparate collection of various computers on a rudimentary network" 😁 I've got a little TP-Link switch somewhere, but I doubt it would be smart switch.

            johnpozJ 1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @pf.Beginner
              last edited by

              haha - then its not a "lab" ;)

              Buy yourself a $40 smart switch - then you can mirror/span whatever you want.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.