10-22-2008 07:36 AM - edited 03-06-2019 02:04 AM
Hi Guys,
I have 4 6500 switch and have layer 2 etherchannle with STP running across them.
6500-1-------6500-2
| |
| |
6500-3------6500-4
I have various servers connected to all 4 switches. now i want to monitor the traffic between those servers. I plan to use VLAN based RSPAN so that I can connect Sniffer(dedicated) only one switch.
But i see one limitaiton of RSPAN that one of the switch where Sniffer is connected (i.e destination port)i also have source ports/vlan.. Will that allow me to do ?
If not, what is best way to have monitoring for above requirment....
Thanks in advance,
Regards,
Chintan
10-22-2008 10:26 AM
You can have multiple RSPAN sessions on the 6500 series.
Ex.
Monitor Session 10 Source Remove Vlan 890
Monitor Session 10 Destination Interface Gig1/1
Monitor Session 20 Source Interface Gig1/2
Monitor Session 20 Destination Remote Vlan 890
Monitor Session 30 Source Interface Gig1/3
Monitor Session 30 Destination Remove Vlan 890
On the switch with the Sniffer connected you will need session 10, on all switches session 20/30 are all you will need to do to send traffic to the sniffer.
10-24-2008 02:32 AM
you mean that on the switch where the sniffer is to be connected, it has the destination port and some source ports and vlans?
I don't think its going to be an issue to you as you are allowed to do this via RSPAN.
Cheers to all.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: