[c-nsp] Unicast storms

Saku Ytti saku+cisco-nsp at ytti.fi
Thu Jul 5 10:51:53 EDT 2007


> Make trunk (tagged) port where you have monitor PC and SPAN all
> traffic to it, as it doesn't have anything it should receive, it'll
> only receive broadcast and flooded traffic, then you can
> use tshark/tcpdump to ditch the broadcast and check only flooded
> unicast.

Of course no need for SPAN here, just trunk (tagged) port
will suffice. Thanks Tarko.

-- 
  ++ytti


More information about the cisco-nsp mailing list