cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
602
Views
0
Helpful
5
Replies

SPAN problem

shibindong
Level 1
Level 1

we configured the SPAN in the 3560 switch:

monitor session 1 source int g0/2

monitor session 1 destination interface Gi0/12

and we have sniffer software install on the Laptop and connect to interface g0/12.

can i say, for ALL the traffic coming in and out from port g0/2 to send to g0/12?

our port g0/2 connect to firewall, how come we cannot sniffer some traffic?

5 Replies 5

Peter Paluch
Cisco Employee
Cisco Employee

Hello,

Your present SPAN configuration seems to be OK - both ingress and egress traffic from Gi0/2 should be copied to Gi0/12. Are you suggesting that on the Gi0/12, no copy of the traffic is being sent out to your sniffer? Can you make sure that your sniffer sets the NIC to the promiscous mode?

Best regards,

Peter

thanks for your reply, yes, my NIC is set to promiscous mode, the problem is some traffic can be captured, while some are not. and I am use wireshark.

Hello,

Can you describe which traffic in particular is not copied to the Gi0/12 interface?

Best regards,

Peter

Drop your interfaces back to 100Mbps and try again.

pompeychimes
Level 4
Level 4

What sniffing software are you using and have you ever sniffed before?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card