SPAN on PPPOE iface ?
I want to to mirror my pppoe connection. This pppoe is build on top of a vlan which relies itself on a physical nic.
With a bridge and a span port, I am able to mirror traffic from the physical nic (green) and from the vlan interface (blue). But no packet is transmitted to the span port if I try to mirror the pppoe interface itself (orange).
I saw some answers on previous posts saying that mirror must be done on switch, not on pfsense. But how can you do this if you want to get rid of pppoe information in you mirrored packets ?
EDIT : pfsense version 2.4.4-RELEASE (amd64)
Any thoughts/help ?
Have you solved your problem ?
I use the upstream switch for the port mirroring and the target (snort/ELK) is smart enough to ignore pppoe encapsulation.