[c-nsp] SPAN (forwarding mirrored traffic)

Niels Bakker niels=cisco-nsp at bakker.net
Sun Mar 20 15:11:33 EST 2005


* gert at greenie.muc.de (Gert Doering) [Sat 19 Mar 2005, 17:44 CET]:
> If you monitor one side only, the destination MAC for these packets should
> never show up as source MAC, and thus the Foundries *should* flood them...

It'll suck, as on Foundry BigIron switches unknown unicast is handled by
the CPU.  You can use an Extreme switch in such situations, those use an
architecture based on shared memory and will happily flood unknown
unicast at line rate.

I highly suggest limiting unknown unicast rates on Foundry switches to
protect the CPU.


	-- Niels.

-- 


More information about the cisco-nsp mailing list