<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic L4 Traffic Mon in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117841#M425</link>
    <description>&lt;P&gt;Does the traffic monitor support Cisco ports in spanned mode? We're trying to get it set up here, but not getting a lot of traffic picked up..&lt;/P&gt;</description>
    <pubDate>Thu, 18 Sep 2008 17:14:33 GMT</pubDate>
    <dc:creator>AndrewR_ironport</dc:creator>
    <dc:date>2008-09-18T17:14:33Z</dc:date>
    <item>
      <title>L4 Traffic Mon</title>
      <link>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117841#M425</link>
      <description>&lt;P&gt;Does the traffic monitor support Cisco ports in spanned mode? We're trying to get it set up here, but not getting a lot of traffic picked up..&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2008 17:14:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117841#M425</guid>
      <dc:creator>AndrewR_ironport</dc:creator>
      <dc:date>2008-09-18T17:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: L4 Traffic Mon</title>
      <link>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117842#M426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;BR /&gt;&lt;BR /&gt; There are two ways of doing L4 monitoring..&lt;BR /&gt;&lt;BR /&gt;    Simplex - single interface for both in and out  - interface is T1 &lt;BR /&gt;&lt;BR /&gt;    Duplex - 2 interfaces involved T1 - in and T2 - out..&lt;BR /&gt;&lt;BR /&gt;Normally a mirror port is configured where the t1 and t2 were connected..&lt;BR /&gt;&lt;BR /&gt;to mirror and sniff traffic in and out of the network... or firewall...&lt;BR /&gt;&lt;BR /&gt;kira&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 20:13:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117842#M426</guid>
      <dc:creator>angfeglandagan</dc:creator>
      <dc:date>2008-09-18T20:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: L4 Traffic Mon</title>
      <link>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117843#M427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kira,&lt;BR /&gt;&lt;BR /&gt;You have the correct idea, but your terms are switched:&lt;BR /&gt;&lt;BR /&gt;Duplex tap = both directions of traffic on a single interface.&lt;BR /&gt;Simplex tap = using T1 for outbound and T2 for inbound traffic. &lt;BR /&gt;&lt;BR /&gt;An example of the Cisco syntax for duplex L4TM is:&lt;BR /&gt;&lt;BR /&gt;&lt;I&gt;In and out traffic from fa1/1:&lt;/I&gt;&lt;BR /&gt;(config)# monitor session 1 source interface fa1/1 &lt;B&gt;both&lt;/B&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;I&gt;Spanned to the WSA T1 interface:&lt;/I&gt;&lt;BR /&gt;(config)# monitor session 1 destination interface fa1/39&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 22:31:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117843#M427</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2008-09-18T22:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: L4 Traffic Mon</title>
      <link>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117844#M428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another small tidbit:&lt;BR /&gt;&lt;BR /&gt;In duplex tap mode, the WSA can actually accept two bi-directional spans: One sent to T1, the other sent to T2. &lt;BR /&gt;&lt;BR /&gt;Undocumented feature  :wink:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 22:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117844#M428</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2008-09-18T22:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: L4 Traffic Mon</title>
      <link>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117845#M429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew, &lt;BR /&gt;&lt;BR /&gt;Another thought came up. I wanted to make sure that you are aware the the L4TM will only log &lt;B&gt;bad&lt;/B&gt; traffic. So you won't see all the traffic in the trafmon logs, like you would in the access logs. &lt;BR /&gt;&lt;BR /&gt;If you are trying to verify that the L4TM is working, I recommend telnetting from your client to www DOT ieplugin DOT com. &lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;Please do NOT go there with your browser - it is a malware propagation site.&lt;/B&gt;&lt;BR /&gt;&lt;BR /&gt;If the span is working properly, the WSA should see this traffic and log it in the trafmon logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Sep 2008 22:36:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117845#M429</guid>
      <dc:creator>jowolfer</dc:creator>
      <dc:date>2008-09-18T22:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: L4 Traffic Mon</title>
      <link>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117846#M430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the info! I'll try and give it another go today, if not next week..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2008 19:16:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/l4-traffic-mon/m-p/1117846#M430</guid>
      <dc:creator>AndrewR_ironport</dc:creator>
      <dc:date>2008-09-19T19:16:05Z</dc:date>
    </item>
  </channel>
</rss>

