cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
290
Views
0
Helpful
2
Replies

VLAN Span

peter.mark
Level 1
Level 1

I recently installed 11 Catalyst 6500 switches and enabled span with a VLAN as a source. The Sniffer sees two of everything. When I enter all of the ports on the switch instead of the VLAN I see normal traces. I verified Spanning Tree, HSRP, Interfaces, CAM tables and enabled UDLD. All seems normal. I've installed over 70 Catalyst 6000 switches in 8 different sites and never had this problem. The other sites are running ver. 6.3.5. This site is running 7.3.2. Looked in the release notes and found no reference to this problem.

2 Replies 2

t.baranski
Level 4
Level 4

I've run into this when the source consists of multiple VLANs (if a packet goes in one VLAN and out another and both VLANs are sourced, you'll see the packet twice). Perhaps the same applies when only one VLAN is involved (the packet goes in and then out the same VLAN, so it's SPAN'd both times if the SPAN port is bi-directional).

jawad1979
Level 1
Level 1

Hi,

I think this might be normal, and depending on the supervisor engine, packets may be copied twice if they were switched in the same VLAN with VSPAN configured for ingress and egress sessions, if they were routed, they will be different for sure.

Hope I helped

Jawad