[c-nsp] SPAN - 6509 Switch

Paul Stewart pauls at nexicom.net
Thu Mar 17 13:53:34 EST 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

oops... :)  going to try "both" and go from there...

thanks for the feedback...

Paul


Voll, Scott wrote:
| Did you use monitor session 1 source vlan 50 both?  What Sup are you
| using?
|
| -----Original Message-----
| From: Paul Stewart [mailto:pauls at nexicom.net]
| Sent: Thursday, March 17, 2005 10:34 AM
| To: Voll, Scott
| Cc: cisco-nsp at puck.nether.net
| Subject: Re: [c-nsp] SPAN - 6509 Switch
|
| Basically I want to sniff all the traffic going through that VLAN
| inbound/outbound.  When I do sniff I only seem to stp and vtp traffic..
| a little arp but that's it..
|
| Vlan50 has over 50 Mb/s of data on it
|
| Does that answer your question? :)
|
| Paul
|
|
| Voll, Scott wrote:
| | What do you mean by not getting a Mirror? Are you not receiving TX or
| RX
| | or Both?  Or are you looking for inter Vlan traffic?
| |
| |
| |
| | -----Original Message-----
| | From: cisco-nsp-bounces at puck.nether.net
| | [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Paul Stewart
| | Sent: Thursday, March 17, 2005 10:26 AM
| | To: cisco-nsp at puck.nether.net
| | Subject: [c-nsp] SPAN - 6509 Switch
| |
| | Hi there...
| |
| | I'm trying to capture all traffic in particular VLAN's and mirror them
| | to a port on our 6509.  Then use Ethereal to see what's going on
| inside
| | of these VLAN's .... we're seeing a TONNE of ARP and ICMP traffic
| | throughout our system and I need to figure out why...
| |
| | Here's what I've got:
| |
| | interface GigabitEthernet6/47
| | ~ description Capture Port - Paul
| | ~ no ip address
| | ~ switchport
| | ~ no cdp enable
| |
| | interface Vlan50
| | ~ description RAS Gear/Routers
| | ~ ip address xxx.xxx.xxx.xxx xxx.xxx.xxx.xxx
| | ~ ip access-group 100 out
| | ~ no ip redirects
| |
| |
| | monitor session 1 source vlan 50
| | monitor session 1 destination interface Gi6/47
| |
| |
| | When I plug into Gig 6/47 I don't get a "mirror" of everything on
| | Vlan50... why not? :)  I need to sniff inside of VLAN's on a 6509 so
| any
| | input is much appreciated...
| |
| | Thanks,
| |
| | Paul
| |
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (MingW32)

iD8DBQFCOdIuqMetgU57IuQRAtoSAJ94uBrF7waoe+NcHi31PxMRHbD/qwCgg5Ol
h2C7SDUPc14XlbvAl+506KY=
=6OdA
-----END PGP SIGNATURE-----


More information about the cisco-nsp mailing list