• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Possible to port mirror or duplicate packets?

Scheduled Pinned Locked Moved General pfSense Questions
5 Posts 3 Posters 2.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    sofakng
    last edited by Jan 3, 2013, 11:40 PM

    I have a strange question…

    Is it possible to "port mirror" or duplicate packets using pfSense?

    For example, whenever packets match a certain filter (i.e. TCP ADDR 192.168.0.25, port 80), duplicate that packet to another IP address, etc.

    Does that make sense?  It's sorta like a poor-man's port filtering.

    1 Reply Last reply Reply Quote 0
    • L
      loupalladino
      last edited by Jan 4, 2013, 12:51 AM

      What are you trying to do with the duplicated packet?

      I do this at the switch level - Cisco calls it "port monitoring".  I had ntop installed on pfsense and connected to the mirrored port on the switch.

      -Lou

      1 Reply Last reply Reply Quote 0
      • S
        sofakng
        last edited by Jan 4, 2013, 12:59 AM

        Yeah, I'm having a problem with my switch.  It's a Dell PowerConnect 2824 managed switch, and it supports port mirroring, but on my "low end" model it doesn't allow mirroring if VLANs are enabled which I use.

        What I'm trying to do is send any SIP INVITE packets to a sniffer application to read the caller id and broadcast it on my network (for call notifications, etc).

        I'd rather not setup a full SIP proxy or anything… The SIP sniffer I have already reads caller id so I just need to get those packets to my sniffer and my VOIP adapter (of course).

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Jan 4, 2013, 5:25 PM

          Not sure if you can do it with just one port, but if you bridge two ports together you can add a third port as a "span" port and it receives copies of every frame transmitted across the bridge.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • L
            loupalladino
            last edited by Jan 4, 2013, 5:28 PM

            I'm still somewhat of a pfsense newbie, but since there is no obvious "rule" (would be nice if there was PASS, BLOCK, REJECT, MIRROR :) ), not sure if can do this.  You could "rig" it up in a pinch using a hub…... I know, far less than ideal but if it limps you along in the meantime while you figure something else out, it's worth contemplating at the least.

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received