Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
You may experience some slow load times, errors, and slight inconsistencies. We ask for your patience as we finalize the launch. Thank you.

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

3560x SPAN Duplicate Packet Question

My question is likely to be answered by the basic way in which the SPAN functions but here are the details. 

My simple configuration is as follows: (ALL PORTS VLAN 1)

monitor session 1 source interface Gi0/1 - 2

monitor session 1 destination interface Gi0/16 ingress untagged vlan 1

I am running a pair of ASA 5510's in active/passive and Gi0/1 is my Active ASA and Gi0/2 is my passive ASA.

I have a single IDS box that is also my internal syslog repository running on Gi0/16.  There is only one NIC in this machine and one IP.

My problem is that syslog messages destined for the IDS box are duplicated in the logs.  I have found that if I change the source to only one port, the duplication goes away.  Also, if I change the source to only Rx or Tx the duplication goes away at all. So my question is how are these being duplicated if a unicast message is destined for a device attached to Gi0/16. Why does my SPAN configuration come into play at all here?  I am sure it has something to do with the ingress command and having both mirrored traffic and standard traffic travel over the same nic/switchport.  I need someone to help me understand this.  Thank you in advance.

Rob

  • LAN Switching and Routing
252
Views
0
Helpful
0
Replies