Cisco Support Community
Community Member

3850 - SPAN port

I recently swapped out a 3750 stack with a 3850 stack and I am not getting the same results when I am spanning a port.

I am mirroring the switchport connected to the inside of our ASA and sending the traffic to the switchport of my IDS.  I have noticed that the captures do not seem to contain traffic destined TO the internet (transmitted from the source port).  It contains TX traffic that is destined to the inside ASA interface but not traffic that should be flowing through the ASA.

I do see the return web traffic (RX).

My config is the same that I used on the 3750 so I am not sure what is going on.

3850-switch#sh monitor session 1

Session 1


Type                   : Local Session

Source Ports           :

    Both               : Gi1/0/10

Destination Ports      : Gi1/0/11

    Encapsulation      : Native

          Ingress      : Disabled

3850-switch#sh run int g1/0/10

Building configuration...

Current configuration : 63 bytes


interface GigabitEthernet1/0/10

switchport mode access


3850-switch#sh run | inc monitor

monitor session 1 source interface Gi1/0/10

monitor session 1 destination interface Gi1/0/11

Everyone's tags (1)
CreatePlease to create content