08-24-2009 08:27 AM - edited 03-04-2019 05:49 AM
we configured the SPAN in the 3560 switch:
monitor session 1 source int g0/2
monitor session 1 destination interface Gi0/12
and we have sniffer software install on the Laptop and connect to interface g0/12.
can i say, for ALL the traffic coming in and out from port g0/2 to send to g0/12?
our port g0/2 connect to firewall, how come we cannot sniffer some traffic?
08-24-2009 08:36 AM
Hello,
Your present SPAN configuration seems to be OK - both ingress and egress traffic from Gi0/2 should be copied to Gi0/12. Are you suggesting that on the Gi0/12, no copy of the traffic is being sent out to your sniffer? Can you make sure that your sniffer sets the NIC to the promiscous mode?
Best regards,
Peter
08-25-2009 12:42 AM
thanks for your reply, yes, my NIC is set to promiscous mode, the problem is some traffic can be captured, while some are not. and I am use wireshark.
08-25-2009 01:34 AM
Hello,
Can you describe which traffic in particular is not copied to the Gi0/12 interface?
Best regards,
Peter
08-25-2009 10:59 AM
Drop your interfaces back to 100Mbps and try again.
08-24-2009 07:07 PM
What sniffing software are you using and have you ever sniffed before?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide