SPAN problem

Unanswered Question
Aug 24th, 2009
User Badges:

we configured the SPAN in the 3560 switch:

monitor session 1 source int g0/2

monitor session 1 destination interface Gi0/12


and we have sniffer software install on the Laptop and connect to interface g0/12.


can i say, for ALL the traffic coming in and out from port g0/2 to send to g0/12?


our port g0/2 connect to firewall, how come we cannot sniffer some traffic?



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Peter Paluch Mon, 08/24/2009 - 08:36
User Badges:
  • Cisco Employee,

Hello,


Your present SPAN configuration seems to be OK - both ingress and egress traffic from Gi0/2 should be copied to Gi0/12. Are you suggesting that on the Gi0/12, no copy of the traffic is being sent out to your sniffer? Can you make sure that your sniffer sets the NIC to the promiscous mode?


Best regards,

Peter


shibindong Tue, 08/25/2009 - 00:42
User Badges:

thanks for your reply, yes, my NIC is set to promiscous mode, the problem is some traffic can be captured, while some are not. and I am use wireshark.

Peter Paluch Tue, 08/25/2009 - 01:34
User Badges:
  • Cisco Employee,

Hello,


Can you describe which traffic in particular is not copied to the Gi0/12 interface?


Best regards,

Peter


pompeychimes Tue, 08/25/2009 - 10:59
User Badges:
  • Bronze, 100 points or more

Drop your interfaces back to 100Mbps and try again.

pompeychimes Mon, 08/24/2009 - 19:07
User Badges:
  • Bronze, 100 points or more

What sniffing software are you using and have you ever sniffed before?

Actions

This Discussion