08-24-2009 08:27 AM - edited 03-04-2019 05:49 AM
we configured the SPAN in the 3560 switch:
monitor session 1 source int g0/2
monitor session 1 destination interface Gi0/12
and we have sniffer software install on the Laptop and connect to interface g0/12.
can i say, for ALL the traffic coming in and out from port g0/2 to send to g0/12?
our port g0/2 connect to firewall, how come we cannot sniffer some traffic?
08-24-2009 08:36 AM
Hello,
Your present SPAN configuration seems to be OK - both ingress and egress traffic from Gi0/2 should be copied to Gi0/12. Are you suggesting that on the Gi0/12, no copy of the traffic is being sent out to your sniffer? Can you make sure that your sniffer sets the NIC to the promiscous mode?
Best regards,
Peter
08-25-2009 12:42 AM
thanks for your reply, yes, my NIC is set to promiscous mode, the problem is some traffic can be captured, while some are not. and I am use wireshark.
08-25-2009 01:34 AM
Hello,
Can you describe which traffic in particular is not copied to the Gi0/12 interface?
Best regards,
Peter
08-25-2009 10:59 AM
Drop your interfaces back to 100Mbps and try again.
08-24-2009 07:07 PM
What sniffing software are you using and have you ever sniffed before?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: