Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

SPAN port or Capture?

We currently have Cat6513 switches installed and our looking into an IDSM-2 module, but for the time being until we can actually purchase them, I would like to install a few snort sensor into the switch to "monitor" a few VLANs.

I've read where there are only two SPAN ports and to gain some type of correlation to the events, I figure I would need to install a separate snort sensor for each vlan. The problem is the limit of two SPAN ports. I heard that there is a way to utilize a "capture" feature on the 65xx systems.

Is the appropriate way for this to use the "capture" commands and if so how would I do that?

Also, I read where the SPAN ports have no performance impact on the switch, but would the "capture" commands?

I apologize if this is the wrong forum for this but I wasn't sure if this would be more of a switching or IDS question...

Thanks for any assistance!


New Member

Re: SPAN port or Capture?

The solution to that issue of only two span ports is to use VACLS. There is documentation in the Configuring the Cisco Intrusion Prevention System Sensor Using the Command Line Interface 5.1.

Refer to Catalyst 6500 Series Switch Command Reference for more information on trunk ports and ACLs.