[c-nsp] SPAN - 6509 Switch

Paul Stewart pauls at nexicom.net
Thu Mar 17 13:26:01 EST 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi there...

I'm trying to capture all traffic in particular VLAN's and mirror them
to a port on our 6509.  Then use Ethereal to see what's going on inside
of these VLAN's .... we're seeing a TONNE of ARP and ICMP traffic
throughout our system and I need to figure out why...

Here's what I've got:

interface GigabitEthernet6/47
~ description Capture Port - Paul
~ no ip address
~ switchport
~ no cdp enable

interface Vlan50
~ description RAS Gear/Routers
~ ip address xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
~ ip access-group 100 out
~ no ip redirects


monitor session 1 source vlan 50
monitor session 1 destination interface Gi6/47


When I plug into Gig 6/47 I don't get a "mirror" of everything on
Vlan50... why not? :)  I need to sniff inside of VLAN's on a 6509 so any
input is much appreciated...

Thanks,

Paul

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)

iD8DBQFCOcu5qMetgU57IuQRAv+BAJ9abmoLxDulbROK+ltbGoq3yVuIMACgju23
5fTm3iMEHXOMIqEBFLzkySw=
=3SHF
-----END PGP SIGNATURE-----


More information about the cisco-nsp mailing list