You can use a traffic mirror to filter and copy network traffic from an elastic network interface (ENI) of VPC to CVM clusters in the same VPC, which is suitable for scenarios including security audit, troubleshooting and business analysis. This document introduces how to create a traffic mirror.
Traffic mirror is now in beta test. To apply for it, please submit a ticket. We recommend saving the link to the Traffic Mirror Console, so you can log in to the Console without applying again.
Make sure that the traffic mirror source and traffic mirror target are in the same VPC and the traffic mirror source has a route table entry for the traffic mirror target.
Open the link in response to your [ticket submitted] (https://console.cloud.tencent.com/workorder/category) and log in to Traffic Mirror Console. In the top Region selector, choose the region that you used to create a traffic mirror.
Click +New on the Traffic mirroring page.
Each VPC supports creating a maximum of 5 traffic mirrors.
Configure the traffic collection as follows:
Enter a name for the traffic mirror, which cannot exceed 60 characters.
Select a Network.
Select a Collection Range:
Select a Collection Type: select the traffic direction as needed. There are three options: All traffic, Traffic out and Traffic in.
Select a Traffic filtering: select a method to filter out unnecessary traffic and keep the mirror small and lightweight.
N/A: all traffic configured will be collected.
Quintuple: the traffic that meets quintuple conditions will be collected. When this option is selected, you also need to set Protocol, Source IP range, Destination IP range, Source port, and Destination port. You can optionally click Add to create another filter condition, and only the traffic that meets all of filter conditions will be collected.
The next hop is the NAT gateway: when the next hop is the NAT gateway, the traffic will be collected. When this option is selected, you also need to search for a NAT gateway next to Condition.
After completing the configuration, click Next.
Set the receiving traffic as follows:
- If this field is left empty, no traffic will be mirrored. So enter at least one receiving IP.
- Separate IPs with line breaks or commas.
- The traffic generated by the receiving IP in a VPC will not be collected.
After completing the configuration, click OK.
Return to the Traffic mirroring page. If the traffic mirror that you just created shows in the list with Collect Traffic enabled, the traffic mirror is created successfully.