02-14-2010 02:46 AM - edited 03-06-2019 09:42 AM
Hi all,
When I connected the wireshark to the normal L2 access port in vlan 2 and capture the packets. I am noticing lots of tcp traffic between different ports in my wireshark . I checked the core switch cisco 4507R but could not seen any span configured . Most of the ports are trunk ports and other unused ports are shutdown.My wireshark connected port is access port in vlan 2.
Could anyone guide me the work around.
swami
02-14-2010 02:50 AM
Hi all,
When I connected the wireshark to the normal L2 access port in vlan 2 and capture the packets. I am noticing lots of tcp traffic between different ports in my wireshark . I checked the core switch cisco 4507R but could not seen any span configured . Most of the ports are trunk ports and other unused ports are shutdown.My wireshark connected port is access port in vlan 2.
Could anyone guide me the work around.
swami
Hi Swami,
Wireshark is enbled in system which is connected to switch port so what ever traffic coming in or out in that particular port will captured in your desktop which is running wireshark, If you want to configure or want to sniff particular port then configure span port in switch and configure wireshark pc as destination port in span configuration, hope that clear !!
If helpful do rate the post
Ganesh.H
02-14-2010 05:12 AM
Hello Swami,
check with
sh monitor session all
if no SPAN is on the system your device has its CAM table overloaded (MAC flooding attack)
check this with:
sh mac address-table dyn count
or
sh mac-address-table dyn count
look for the final lines that tell how many MAC addresses are in the CAM table and gives you the size of the CAM table.
Hope to help
Giuseppe
02-14-2010 07:35 AM
I presume it is only VLAN2 traffic you are seeing. If you are seeing traffic that doesn't belong in VLAN 2, then something is seriously wrong, and we need to look deeper.
If you have connected your wireshark to an acess port, then you should expect to see some traffic, even if the wireshark port is not specifically concerned with it. To be precise, you will see:
So, to understand what is going on, I really need to get a feel for what proportion of this traffic is broadcast, how much is multicast, and how much is flooded unicast.
Kevin Dorrell
Luxembourg
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: