Span monitor session for VLAN 1

Unanswered Question
Jun 15th, 2009

We'd like to create a monitor session that covers all the traffic on a Catalyst 6513 switch. The only VLAN currently configured on the switch is the native VLAN 1, so I figured I could span the entire VLAN thus capture all traffic that traverses the switch. However, while the IOS allows me to create the session and enter VLAN 1 as the source VLAN, when I check the session it shows as having no source VLAN configured. Am I not allowed to span the switches native VLAN?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Giuseppe Larosa Mon, 06/15/2009 - 10:56

Hello Patrick,

just a warning even a powerful C6513 can be impaired if the traffic volume is much greater then the destination port speed: we have seen cpu to go as high as 100% on C6509 for a span session trying to push 3Gbps of traffic out a single GE port where the IDS is connected.

the following chapter from ios 12.2SXF can help

http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/native/configuration/guide/span.html#wp1102614

and the command reference for monitor session command

http://www.cisco.com/en/US/docs/ios/lanswitch/command/reference/lsw_m1.html#wp1015931

it is clearly stated that valid vlan-id is 1-4094 on C6500/7600.

Hope to help

Giuseppe

Actions

This Discussion