[c-nsp] SPAN - 6509 Switch

Voll, Scott Scott.Voll at wesd.org
Thu Mar 17 13:33:27 EST 2005


What do you mean by not getting a Mirror? Are you not receiving TX or RX
or Both?  Or are you looking for inter Vlan traffic?



-----Original Message-----
From: cisco-nsp-bounces at puck.nether.net
[mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Paul Stewart
Sent: Thursday, March 17, 2005 10:26 AM
To: cisco-nsp at puck.nether.net
Subject: [c-nsp] SPAN - 6509 Switch

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi there...

I'm trying to capture all traffic in particular VLAN's and mirror them
to a port on our 6509.  Then use Ethereal to see what's going on inside
of these VLAN's .... we're seeing a TONNE of ARP and ICMP traffic
throughout our system and I need to figure out why...

Here's what I've got:

interface GigabitEthernet6/47
~ description Capture Port - Paul
~ no ip address
~ switchport
~ no cdp enable

interface Vlan50
~ description RAS Gear/Routers
~ ip address xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
~ ip access-group 100 out
~ no ip redirects


monitor session 1 source vlan 50
monitor session 1 destination interface Gi6/47


When I plug into Gig 6/47 I don't get a "mirror" of everything on
Vlan50... why not? :)  I need to sniff inside of VLAN's on a 6509 so any
input is much appreciated...

Thanks,

Paul

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)

iD8DBQFCOcu5qMetgU57IuQRAv+BAJ9abmoLxDulbROK+ltbGoq3yVuIMACgju23
5fTm3iMEHXOMIqEBFLzkySw=
=3SHF
-----END PGP SIGNATURE-----



More information about the cisco-nsp mailing list