NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

wiredfence's avatar
wiredfence
Follower
Aug 16, 2026

GS316EP: Port mirroring fails to capture traffic between two ports isolated in their own VLAN

Setup:

I have two VLANs configured:

 

  • VLAN 1 (default): most ports, including my normal LAN traffic
  • VLAN 10: exactly two ports (Port 3 and Port 4), used for an isolated point-to-point link between my cable modem and router’s WAN port

 

Port mirroring is configured with sources = Ports 1, 3, 4 and destination = Port 16. Port 16 is a tagged member of both VLAN 1 and VLAN 10.

 

The problem:

Mirroring from Port 1 (VLAN 1) to Port 16 works perfectly — I can see all that traffic clearly on the destination.

 

Mirroring from Ports 3/4 (the isolated VLAN 10) to Port 16 captures nothing — not even a single packet — despite:

 

  • Port statistics confirming heavy, continuous real traffic on both Port 3 and Port 4
  • Port mirroring config showing all three ports (1, 3, 4) correctly listed as sources
  • Port 16 confirmed as a tagged member of both VLAN 1 and VLAN 10
  • Testing both untagged (tcpdump -i <iface> -n) and VLAN-tagged (tcpdump -i <iface> -n vlan) captures on the destination — zero packets either way, even during extended (60-90 second) active traffic generation

 

What I suspect:

Since VLAN 10 has exactly two ports and all traffic between them is essentially point-to-point, I suspect the switch ASIC may be using some kind of hardware fast-path/shortcut for this traffic pattern that bypasses the mirroring engine — but I can’t confirm this and haven’t found it documented anywhere.

 

Questions:

 

  1. Is this a known limitation/behavior of this switch (or its chipset) for isolated two-port VLANs specifically?
  2. Is there a configuration workaround (different VLAN mode, different port count in the isolated VLAN, disabling some hardware acceleration feature) that would make this mirror correctly?
  3. Has anyone successfully mirrored traffic on a similarly isolated VLAN segment on this or a similar NETGEAR model?

2 Replies

  • schumaku's avatar
    schumaku
    Guru - Experienced User
    wiredfence wrote:

    Port 16. Port 16 is a tagged member of both VLAN 1 and VLAN 10.

     

    You can't do that - the mirroring designation port must provide exact the mirrored port data - so the port where you collect all data mirrored in captive mode must never use any other purpose. 

     

    wiredfence wrote:

    Has anyone successfully mirrored traffic on a similarly isolated VLAN segment on this or a similar NETGEAR model?

     

    That isn't possible on typical small switches with port mirroring only.

     

    Not aware any industry standard software does allow to operate port mirrring adata toghether with actiove production data.

     

    You want to emulate the SPAN port possibilities you might know from the "big boys" e.g. on Cisco enterprise switches, where you can tunnel SPAN data through a dedicated, independant (SPAN) data channel.

     

    Local SPAN:

    Copies traffic between ports on the exact same switch.

     

    Remote SPAN (RSPAN):

    Sends mirrored data across a dedicated VLAN to a different switch.

     

    Encapsulated Remote SPAN (ERSPAN):

    Tunnels mirrored data across Layer 3 IP networks to reach central analysis tools.

     

    Most common aplications require the SPAN (mirrior port) data on a dedicated port, not carrying any addditional prfoducion or other data on top, typical examples are:

     

    Network Troubleshooting:

    Engineers use tools like Wireshark on the destination port to inspect live packet flows, pinpoint latency causes, and diagnose dropped connections. 

    Security Monitoring:

    Intrusion Detection Systems (IDS) and security platforms read mirrored feeds to spot malware signatures, scanning behavior, and unauthorized access attempts.

    Application Performance Management (APM):

    IT teams analyze transaction times and user data streams to ensure software applications run fast and reliably.

    Compliance and Forensics:

    Auditors record and review data streams to verify that systems follow data privacy rules or to investigate past network breaches.

     

  • StephenB's avatar
    StephenB
    Guru - Experienced User

    Not sure of the limitations, but I don't think port 16 should be connected to either VLAN.

     

    Since this is a pass-through connection you might try just mirroring port 3 (not both port 3 and port 4).  Every packet traversing port 3 is alse traversing port 4. 

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More