[c-nsp] SPAN - 6509 Switch
Paul Stewart
pauls at nexicom.net
Thu Mar 17 13:33:45 EST 2005
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Basically I want to sniff all the traffic going through that VLAN
inbound/outbound. When I do sniff I only seem to stp and vtp traffic..
a little arp but that's it..
Vlan50 has over 50 Mb/s of data on it
Does that answer your question? :)
Paul
Voll, Scott wrote:
| What do you mean by not getting a Mirror? Are you not receiving TX or RX
| or Both? Or are you looking for inter Vlan traffic?
|
|
|
| -----Original Message-----
| From: cisco-nsp-bounces at puck.nether.net
| [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Paul Stewart
| Sent: Thursday, March 17, 2005 10:26 AM
| To: cisco-nsp at puck.nether.net
| Subject: [c-nsp] SPAN - 6509 Switch
|
| Hi there...
|
| I'm trying to capture all traffic in particular VLAN's and mirror them
| to a port on our 6509. Then use Ethereal to see what's going on inside
| of these VLAN's .... we're seeing a TONNE of ARP and ICMP traffic
| throughout our system and I need to figure out why...
|
| Here's what I've got:
|
| interface GigabitEthernet6/47
| ~ description Capture Port - Paul
| ~ no ip address
| ~ switchport
| ~ no cdp enable
|
| interface Vlan50
| ~ description RAS Gear/Routers
| ~ ip address xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
| ~ ip access-group 100 out
| ~ no ip redirects
|
|
| monitor session 1 source vlan 50
| monitor session 1 destination interface Gi6/47
|
|
| When I plug into Gig 6/47 I don't get a "mirror" of everything on
| Vlan50... why not? :) I need to sniff inside of VLAN's on a 6509 so any
| input is much appreciated...
|
| Thanks,
|
| Paul
|
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)
iD8DBQFCOc2JqMetgU57IuQRAvqLAJ9DLWRPAt5rNRbiZMrLFfp/3tq6DACfZ8X3
xlMI2ks7JL/Sa9M952qhZ4g=
=fAL1
-----END PGP SIGNATURE-----
More information about the cisco-nsp
mailing list