RSPAN woes

Unanswered Question
May 10th, 2007
User Badges:

Hi


I have just set a RSPAN vlan and some ports to monitor but dont seem to be receiving any IP traffic. I can see the MAC addresses of hosts im trying to monitor across the RSPAN vlan.


Any ideas ?


Cheers



switch with sniffer connected


Session 1

---------

Type : Remote Destination Session

Source RSPAN VLAN: 900

Destination Ports : Fa0/32

Encapsulation : Native

Ingress: Disabled



switch with hosts trying to monitor



Rspan Type : Source

Destination : -

Reflector : Port 2/48

Rspan Vlan : 900

Admin Source : Port 2/2

Oper Source : Port 2/2

Direction : transmit/receive

Incoming Packets: -

Learning : -

Filter : -

Status : active


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Edison Ortiz Thu, 05/10/2007 - 07:45
User Badges:
  • Super Bronze, 10000 points or more
  • Hall of Fame,

    Founding Member

Can you post


show run | i monitor


from each switch ?


Richard Burts Thu, 05/10/2007 - 07:47
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

Stephen


Is there a trunk configured between the switches that is configured to carry VLAN 900? There needs to be a trunk between the switches for the RSPAN VLAN.


HTH


Rick

stephen.baugh Thu, 05/10/2007 - 22:34
User Badges:

Hi Rick


VLAN900 is allowed accross the trunk, I can see the MAC address of the host im trying to capture.


config as below


Host monitor switch


#switch port analyzer

set rspan source 2/2 900 both reflector 2/48 create


Switch with Sniffer connected

monitor session 1 destination interface Fa0/32

monitor session 1 source remote vlan 900






Richard Burts Fri, 05/11/2007 - 07:18
User Badges:
  • Super Silver, 17500 points or more
  • Hall of Fame,

    Founding Member

  • Cisco Designated VIP,

    2017 LAN, WAN

Stephen


Thanks for the additional information. Perhaps you can also post the configuration of the trunk on both switches. It might also be helpful if you would post the output of show trunk on both switches.


HTH


Rick

stephen.baugh Sun, 05/13/2007 - 22:38
User Badges:

Hi


Outputs for show trunk


Switch with sniffer connected


Port Mode Encapsulation Status Native vlan

Gi0/1 on 802.1q trunking 1

Gi0/2 on 802.1q trunking 1


Port Vlans allowed on trunk

Gi0/1 1-4094

Gi0/2 1-4094


Port Vlans allowed and active in management domain

Gi0/1 1,10-11,40,50,900,999

Gi0/2 1,10-11,40,50,900,999


Port Vlans in spanning tree forwarding state and not pruned

Gi0/1 1,10-11,40,50,900,999

Gi0/2 1,10-11,40,50,900,999


switch with hosts

Port Mode Encapsulation Status Native vlan

-------- ----------- ------------- ------------ -----------

2/49 on dot1q trunking 1


Port Vlans allowed on trunk

-------- ---------------------------------------------------------------------

2/49 1-1005,1025-4094


Port Vlans allowed and active in management domain

-------- ---------------------------------------------------------------------

2/49 1,10-12,15-16,20,50,60,90,102,230,900


Port Vlans in spanning tree forwarding state and not pruned

-------- ---------------------------------------------------------------------

2/49 1,10-12,15-16,20,50,60,90,102,230,900





Actions

This Discussion