I recently installed 11 Catalyst 6500 switches and enabled span with a VLAN as a source. The Sniffer sees two of everything. When I enter all of the ports on the switch instead of the VLAN I see normal traces. I verified Spanning Tree, HSRP, Interfaces, CAM tables and enabled UDLD. All seems normal. I've installed over 70 Catalyst 6000 switches in 8 different sites and never had this problem. The other sites are running ver. 6.3.5. This site is running 7.3.2. Looked in the release notes and found no reference to this problem.
I've run into this when the source consists of multiple VLANs (if a packet goes in one VLAN and out another and both VLANs are sourced, you'll see the packet twice). Perhaps the same applies when only one VLAN is involved (the packet goes in and then out the same VLAN, so it's SPAN'd both times if the SPAN port is bi-directional).
I think this might be normal, and depending on the supervisor engine, packets may be copied twice if they were switched in the same VLAN with VSPAN configured for ingress and egress sessions, if they were routed, they will be different for sure.
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...