cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
455
Views
0
Helpful
3
Replies

SPAN Config

kevin.atwood
Level 1
Level 1

Hello,

We've got two PIX'es setup in failover mode, we had an issue a day or so ago when the secondary pix took over the IDS was dead in the water because the SPAN config on our 6500 is not duplicating both ports. Suggestions on getting the SPAN config to pass traffic in a failover mode?

Thanks,

Kevin

3 Replies 3

vkapoor5
Level 5
Level 5

From what I understand, you need to include both the PIX ports (Primary and Secondary) in the SPAN configuration on your 6500 as the SPAN source ports. With that, even after failover, your SPAN will be able to capture the packets from the active PIX.

brymiller
Level 1
Level 1

The ports that the PIXs are connected to both need to be SPAN sources. If you are using a Catalyst then use the 'monitor session <#> source interface..." command is what you need.

Here's the poorly written config guide..

http://www.cisco.com/univercd/cc/td/doc/product/lan/c3550/12225sec/3550scg/swspan.htm

And a fairly good field notice...

http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a008015c612.shtml

abdel_n
Level 1
Level 1

I confirm what “vkapoor5” and “brymiller” noted about ports connected to both active and standby ports that must be SPAN source ports on the switch.

Here is a simple configuration example (Cat OS and IOS).

I hope you have already resolve that issue.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card