Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

TCP reset from IPS (in passive mode) on 3550 swich with RSPAN/SPAN

Hi,

I was wondering if it is possible to get the tcp reset from IPS (in passive monitoring mode) using RSPAN/SPAN on 3550 switches, does the switch require an extra command in order to accept traffic from monitoring interface (IPS TCP reset).

thanks

thanks in advance

1 REPLY
Anonymous
N/A

Re: TCP reset from IPS (in passive mode) on 3550 swich with RSPA

Actually it is the "Inpkts" parameter on CatOS that allows it to accept inbound traffic on the SPAN destination. The "learning" is

to disable MAC address learning, since the IDS will spoof the MAC address of the server when it sends a TCP RST back to the client. So disable Mac learning on the switch.

126
Views
0
Helpful
1
Replies
CreatePlease to create content