The traffic mirroring feature in Hyper-V Manager is used to deploy a virtual Network Security appliance in TAP mode.
Note
These procedures assume that the interface pairs are configured in TAP mode on the Network Security appliance.
Layer 2 TAP mode
The following steps are required to configure the Network Security monitoring port as the destination for the traffic:
In Hyper-V Manager, select the virtual machine.
Click Settings.
Locate and expand the network adapter.
Click Advanced Features.
Under Port Mirroring, select Destination as the Mirroring mode.
Layer 3 TAP mode
In a Layer 3 TAP deployment, an external device creates a VXLAN or ERSPAN tunnel through which Layer 2 frames are encapsulated in Layer 3 packets and sent to the monitoring interfaces on the virtual Network Security appliance.
The following steps are required to configure the Network Security monitoring port as the destination for the traffic:
Use the policymgr layer3-mode enable command in the Network Security CLI to enable Layer 3 forwarding. For detailed information and additional commands, see the "Layer 3 Forwarding Using VRF Instances" information in the Network Security System Administration Guide.
Configure an IP address for the destination network interface in each port pair.