SPAN problem

Unanswered Question
Aug 24th, 2009

we configured the SPAN in the 3560 switch:

monitor session 1 source int g0/2

monitor session 1 destination interface Gi0/12

and we have sniffer software install on the Laptop and connect to interface g0/12.

can i say, for ALL the traffic coming in and out from port g0/2 to send to g0/12?

our port g0/2 connect to firewall, how come we cannot sniffer some traffic?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Peter Paluch Mon, 08/24/2009 - 08:36

Hello,

Your present SPAN configuration seems to be OK - both ingress and egress traffic from Gi0/2 should be copied to Gi0/12. Are you suggesting that on the Gi0/12, no copy of the traffic is being sent out to your sniffer? Can you make sure that your sniffer sets the NIC to the promiscous mode?

Best regards,

Peter

shibindong Tue, 08/25/2009 - 00:42

thanks for your reply, yes, my NIC is set to promiscous mode, the problem is some traffic can be captured, while some are not. and I am use wireshark.

Peter Paluch Tue, 08/25/2009 - 01:34

Hello,

Can you describe which traffic in particular is not copied to the Gi0/12 interface?

Best regards,

Peter

Actions

This Discussion