[c-nsp] SPAN - 6509 Switch

Tim Stevenson tstevens at cisco.com
Thu Mar 17 14:45:15 EST 2005


Both is the default, if you don't specify, you get both tx & rx.

Was the config you posted from the switch or hand-typed? eg, could the 
source & dest monitor session #s be mismatched/incorrect? Perhaps post a 
show monitor.

Tim

At 10:53 AM 3/17/2005, Paul Stewart declared:
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>oops... :)  going to try "both" and go from there...
>
>thanks for the feedback...
>
>Paul
>
>
>Voll, Scott wrote:
>| Did you use monitor session 1 source vlan 50 both?  What Sup are you
>| using?
>|
>| -----Original Message-----
>| From: Paul Stewart [mailto:pauls at nexicom.net]
>| Sent: Thursday, March 17, 2005 10:34 AM
>| To: Voll, Scott
>| Cc: cisco-nsp at puck.nether.net
>| Subject: Re: [c-nsp] SPAN - 6509 Switch
>|
>| Basically I want to sniff all the traffic going through that VLAN
>| inbound/outbound.  When I do sniff I only seem to stp and vtp traffic..
>| a little arp but that's it..
>|
>| Vlan50 has over 50 Mb/s of data on it
>|
>| Does that answer your question? :)
>|
>| Paul
>|
>|
>| Voll, Scott wrote:
>| | What do you mean by not getting a Mirror? Are you not receiving TX or
>| RX
>| | or Both?  Or are you looking for inter Vlan traffic?
>| |
>| |
>| |
>| | -----Original Message-----
>| | From: cisco-nsp-bounces at puck.nether.net
>| | [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Paul Stewart
>| | Sent: Thursday, March 17, 2005 10:26 AM
>| | To: cisco-nsp at puck.nether.net
>| | Subject: [c-nsp] SPAN - 6509 Switch
>| |
>| | Hi there...
>| |
>| | I'm trying to capture all traffic in particular VLAN's and mirror them
>| | to a port on our 6509.  Then use Ethereal to see what's going on
>| inside
>| | of these VLAN's .... we're seeing a TONNE of ARP and ICMP traffic
>| | throughout our system and I need to figure out why...
>| |
>| | Here's what I've got:
>| |
>| | interface GigabitEthernet6/47
>| | ~ description Capture Port - Paul
>| | ~ no ip address
>| | ~ switchport
>| | ~ no cdp enable
>| |
>| | interface Vlan50
>| | ~ description RAS Gear/Routers
>| | ~ ip address xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
>| | ~ ip access-group 100 out
>| | ~ no ip redirects
>| |
>| |
>| | monitor session 1 source vlan 50
>| | monitor session 1 destination interface Gi6/47
>| |
>| |
>| | When I plug into Gig 6/47 I don't get a "mirror" of everything on
>| | Vlan50... why not? :)  I need to sniff inside of VLAN's on a 6509 so
>| any
>| | input is much appreciated...
>| |
>| | Thanks,
>| |
>| | Paul
>| |
>-----BEGIN PGP SIGNATURE-----
>Version: GnuPG v1.4.0 (MingW32)
>
>iD8DBQFCOdIuqMetgU57IuQRAtoSAJ94uBrF7waoe+NcHi31PxMRHbD/qwCgg5Ol
>h2C7SDUPc14XlbvAl+506KY=
>=6OdA
>-----END PGP SIGNATURE-----
>
>
>_______________________________________________
>cisco-nsp mailing list  cisco-nsp at puck.nether.net
>https://puck.nether.net/mailman/listinfo/cisco-nsp
>archive at http://puck.nether.net/pipermail/cisco-nsp/



Tim Stevenson, tstevens at cisco.com
Routing & Switching CCIE #5561
Technical Marketing Engineer, Catalyst 6500
Cisco Systems, http://www.cisco.com
IP Phone: 408-526-6759
********************************************************
The contents of this message may be *Cisco Confidential*
and are intended for the specified recipients only.


More information about the cisco-nsp mailing list