Port Mirroring (SPAN Port)
Port Mirroring lets a gateway listen to traffic on a mirror port or SPAN port on a switch. The mirror port on a Check Point gateway is typically configured to monitor and analyze network traffic with no effect on the physical network. The mirror port duplicates the network traffic and records the activity in logs.
You can use mirror ports to:
- Monitor the use of applications in your organization, as a permanent part of your deployment
- Evaluate the capabilities of the Application Control and IPS Software Blades before you purchase them
The mirror port does not enforce a policy. You can only use it to see the monitoring and detection capabilities of the blades.
Benefits of a mirror port include:
- There is no risk to your production environment.
- It requires minimal set-up configuration.
- It does not require expensive TAP equipment.
|