If I'm monitoring a port on SPAN, will traffic blocked by an access-list on that port still be copied by SPAN to the SPAN Destination port, or does SPAN monitoring take place after firewall filtering?
span only cature what traffic flowing through that port
so no traffic no capture
Getting Started
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: