[c-nsp] Monitoring device w/phone and PC behind it
Netfortius
netfortius at gmail.com
Thu May 4 08:08:57 EDT 2006
Let's say I have a "monitoring" device (imagine a sort of tap), with its own
MAC address, and which I want to connect to a Cisco switch port. Into the the
same device (acting transparent to the traffic behind it), on its opposite
port, I plug a phone, belonging to a voice VLAN, then, behind the phone, a
PC, on its own VLAN. My device will also be part of a VLAN, but neither that
of the phone, nor that of the PC "behind" the phone. This device will be
transparent to the traffic flowing through it, from the phone and PC, to the
upstream Cisco switch, and on further (with the exception of recording some
of this traffic characteristics), but will need to be communicated with, from
behind the Cisco switch it is plugged into. Here are my questions:
1. How would the Cisco switch port have to be configured, to accept this chain
of devices? I understand that a phone and PC behind it would allow some sort
of Cisco proprietary port configuration (auxilliary - somehow hybrid, still
802.1q, but not really trunk mode), vs. either access or "pure" trunk, but
dealing with three VLANs (two "data" ones, for my device and the PC, and on
voice one, for the phone) makes me think that the auxiliary port concept
won't work. But then the challenge becomes: if I use many such devices, on
many phones with PCs behind them, I will end up with a mess of trunk ports -
really not manageable, let alone risky
2. How wold 802.1x implemented on the Cisco switch port work in such a case
(assuming question "1." gets answered)?
As the above scenario is somehow theoretical, somehow rooted into what I would
like to implement as a sort_of traffic cop, with devices capable of doing
such, I would appreciate comments of any sort.
Thanks,
Stefan
More information about the cisco-nsp
mailing list