[c-nsp] SPAN (forwarding mirrored traffic)

Gert Doering gert at greenie.muc.de
Fri Mar 18 09:57:27 EST 2005


Hi,

On Thu, Mar 17, 2005 at 06:17:52PM +0000, Carl Neenan wrote:
> Cisco               Juniper ERX     Juniper M-Series
> 3550  Port0/0<--------->1440<------------>M10i<------>Transit
>          +
> Mirrored +
> Traffic  +             
>          +             Foundry            Foundry
> 3550  Port0/5<-------->BigIron<---------->BigIron<-------->sniffer
>                                  dot1q
[..]
> I assumed the mirrored traffic would be flooded (unknown unicast mac
> address) but what state are the MAC addresses on the mirrored
> traffic??

Well... if you're sniffing both directions (TX and RX), the Foundry will
see packets with both src MACs on the "mirrored port", and so the MACs
are not "unknown" -> no flooding.

You'll need to have the Foundries mirror as well..

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             gert at greenie.muc.de
fax: +49-89-35655025                        gert at net.informatik.tu-muenchen.de


More information about the cisco-nsp mailing list