Span or mirror ports are a convenient and inexpensive way to access traffic flowing through a network switch. Switches that support Span ports—typically high-end switches—can be configured to mirror traffic from selected ports or VLANs to the Span port, where monitoring tools can be attached. At first glance, it seems that a Span port could be a good way to connect an intrusion detection system (IDS), forensic recorder, or other security monitoring device
It is common for engineers to use Switched Port Analyzer (SPAN) feature as a method of capturing network traffic for later analysis. For example, in the event of an insider attack to ‘playback’ the packets as proof