Span Sessions

Unanswered Question
Jun 30th, 2008
User Badges:

Hi,

I have an issue with spanning a port on the switch. Please assist.


I have a switch of 4510R-E series with port 8/47 providing MAN lin kconnectivity to another office. I see the tx or rx load on the interface to be hitting 250 every 1 min or so. I would want to trace the traffic on this link. So, I thoght of spanning the traffic onto a system & analyze. th eport 8/47 is on VLAN 250. I configured the below:


monitor session 2 source vlan 250

monitor session 2 destination interface fa 8/11


I have my local system connected to fa 8/11 on the same switch. When I configure the span this way, I lose connectivity to the system on 8/11. The moment I remove the configurtaion, I am able to ping to the system & access the system. Why is this so?

How do I proceed with this ?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 2 (2 ratings)
Loading.
gpulos Mon, 06/30/2008 - 03:19
User Badges:
  • Blue, 1500 points or more

This is because the SPAN sets the port to only forward SPAN traffic. (the traffic to your sniffer/analyzer)


The SPAN port disables the forwarding of non SPAN traffic; any traffic from your PC, so the PC connectivity is in essence lost while the SPAN is in effect.


Utilize your sniffer/analyzer while the SPAN is in effect and it will capture all the traffic the SPAN sends to port 8/11.


Please see the following link for more SPAN info:


Characteristics of a SPAN Destination port:

http://www.cisco.com/en/US/products/hw/switches/ps708/products_tech_note09186a008015c612.shtml#charac_dest

dhananjoy chowdhury Tue, 07/01/2008 - 03:35
User Badges:
  • Silver, 250 points or more

Hi,

The best way to do this is that there should be two ethernet cards on the system -

- one card will be in promiscous mode , collecting all traffic from the SPAN port on the switch for analysing/sniffing traffic.


- the other card will be operating normally for network access.

dhananjoy chowdhury Tue, 07/01/2008 - 03:39
User Badges:
  • Silver, 250 points or more

Hi,

Suppose you have eth0 and eth1 on your system,

then

eth0 - (promiscous mode) - configure tools like Wireshark/Ethrreal to sniff traffic on this port. Connect this to the 8/47 port as in your case.

Eth1 - (access mode) - for your system to acces s network, connect this to the normal user VLAN port on the switch.


Rate if helpful.

dhananjoy

Actions

This Discussion