SPAN problem

Unanswered Question
Aug 24th, 2009

we configured the SPAN in the 3560 switch:

monitor session 1 source int g0/2

monitor session 1 destination interface Gi0/12

and we have sniffer software install on the Laptop and connect to interface g0/12.

can i say, for ALL the traffic coming in and out from port g0/2 to send to g0/12?

our port g0/2 connect to firewall, how come we cannot sniffer some traffic?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Peter Paluch Mon, 08/24/2009 - 08:36


Your present SPAN configuration seems to be OK - both ingress and egress traffic from Gi0/2 should be copied to Gi0/12. Are you suggesting that on the Gi0/12, no copy of the traffic is being sent out to your sniffer? Can you make sure that your sniffer sets the NIC to the promiscous mode?

Best regards,


shibindong Tue, 08/25/2009 - 00:42

thanks for your reply, yes, my NIC is set to promiscous mode, the problem is some traffic can be captured, while some are not. and I am use wireshark.

Peter Paluch Tue, 08/25/2009 - 01:34


Can you describe which traffic in particular is not copied to the Gi0/12 interface?

Best regards,



This Discussion