cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
376
Views
0
Helpful
1
Replies

SPAN port validation

mpozorski
Level 1
Level 1

Hi there - Would anybody be willing to let me know if my SPAN port is configured correctly? I believe that it is configured correctly but I am looking for somobody to just look it over just to make sure that I am not missing something. Currently we have two core switches (3560-24TS) and 10 access switches (3560-48PS) and 2 2950 access swithes. I am trying to capture all of the VOIP traffic through the network which is configured on VLAN10. Here is how the SPAN is currently configured:

SWITCH 1

CORESW01#sh run | be monitor

monitor session 2 source interface Gi0/1 - 25 rx

monitor session 2 filter vlan 10

monitor session 2 destination remote vlan 500

CORESW01#sh monitor

Session 2

---------

Type : Remote Source Session

Source Ports :

RX Only : Gi0/1-25

Filter VLANs : 10

Dest RSPAN VLAN : 500

CORESW01#sh vlan remote-span

Remote SPAN VLANs

------------------------------------------------------------------------------

500-501

##################################################################################

SWITCH 2

CORESW02#sh run | be monitor

monitor session 1 source interface Gi0/1 - 25 rx

monitor session 1 filter vlan 10

monitor session 1 destination remote vlan 500

CORESW02#sh monitor

Session 1

---------

Type : Remote Source Session

Source Ports :

RX Only : Gi0/1-25

Filter VLANs : 10

Dest RSPAN VLAN : 500

CORESW02#sh vlan remote-span

Remote SPAN VLANs

------------------------------------------------------------------------------

500-501

######################################################################################

SWITCH 3

SW03#sh run | be monitor

monitor session 1 destination interface Gi0/3 - 4

monitor session 1 source remote vlan 500

SW01#sh monitor

Session 1

---------

Type : Remote Destination Session

Source RSPAN VLAN : 500

Destination Ports : Gi0/3-4

Encapsulation : Native

Ingress : Disabled

SW01#sh vlan remote-span

Remote SPAN VLANs

------------------------------------------------------------------------------

500-501

The sniffer is connected to port Gi0/3 on switch 3 and all of the access switches are plugged into both of the core switches. If somebody could please take a looks and let me know if I am missing something or if it looks solid I would appreciate it as there have been accusations that the SPAN port is not seeing all of the traffic. Thank you so much.

1 Reply 1

ebreniz
Level 6
Level 6

I think your configured is absolutely correct. It has to work. Each time that you issue a new set span command, the previous configuration is invalidated.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card