10-06-2005 08:47 AM - edited 03-10-2019 01:40 AM
Hello,
We've got two PIX'es setup in failover mode, we had an issue a day or so ago when the secondary pix took over the IDS was dead in the water because the SPAN config on our 6500 is not duplicating both ports. Suggestions on getting the SPAN config to pass traffic in a failover mode?
Thanks,
Kevin
10-13-2005 05:51 AM
From what I understand, you need to include both the PIX ports (Primary and Secondary) in the SPAN configuration on your 6500 as the SPAN source ports. With that, even after failover, your SPAN will be able to capture the packets from the active PIX.
10-17-2005 07:24 AM
The ports that the PIXs are connected to both need to be SPAN sources. If you are using a Catalyst then use the 'monitor session <#> source interface..." command is what you need.
Here's the poorly written config guide..
http://www.cisco.com/univercd/cc/td/doc/product/lan/c3550/12225sec/3550scg/swspan.htm
And a fairly good field notice...
http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a008015c612.shtml
10-18-2005 02:34 PM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: