<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RSPAN Sessions and IDS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/rspan-sessions-and-ids/m-p/471151#M95017</link>
    <description>&lt;P&gt;Are RSPAN "Sessions" Inclusive or exclusive of each other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you send traffic from 1 session to another?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;In other words, if I want to monitor 3 vlans with active hosts that reside across several switches including the one with the destination port (IDS) will this work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;monitor session 1 source vlan 10 - 12 rx&lt;/P&gt;&lt;P&gt;monitor session 1 destination remote vlan 555 reflector-port Fa0/10&lt;/P&gt;&lt;P&gt;monitor session 2 source remote vlan 555 &lt;/P&gt;&lt;P&gt;monitor session 2 destination interface Fa0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does Session 1 "move" the traffic to be inspected by session 2 (where the IDS is located per f0/24)?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Or does session 1 just send the traffic back over the Trunk (RSPAN Vlan) link?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:46:18 GMT</pubDate>
    <dc:creator>d-garnett</dc:creator>
    <dc:date>2019-03-10T09:46:18Z</dc:date>
    <item>
      <title>RSPAN Sessions and IDS</title>
      <link>https://community.cisco.com/t5/network-security/rspan-sessions-and-ids/m-p/471151#M95017</link>
      <description>&lt;P&gt;Are RSPAN "Sessions" Inclusive or exclusive of each other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you send traffic from 1 session to another?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;In other words, if I want to monitor 3 vlans with active hosts that reside across several switches including the one with the destination port (IDS) will this work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;monitor session 1 source vlan 10 - 12 rx&lt;/P&gt;&lt;P&gt;monitor session 1 destination remote vlan 555 reflector-port Fa0/10&lt;/P&gt;&lt;P&gt;monitor session 2 source remote vlan 555 &lt;/P&gt;&lt;P&gt;monitor session 2 destination interface Fa0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does Session 1 "move" the traffic to be inspected by session 2 (where the IDS is located per f0/24)?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Or does session 1 just send the traffic back over the Trunk (RSPAN Vlan) link?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rspan-sessions-and-ids/m-p/471151#M95017</guid>
      <dc:creator>d-garnett</dc:creator>
      <dc:date>2019-03-10T09:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: RSPAN Sessions and IDS</title>
      <link>https://community.cisco.com/t5/network-security/rspan-sessions-and-ids/m-p/471152#M95018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the line that confuses me:&lt;/P&gt;&lt;P&gt;monitor session 1 destination remote vlan 555 reflector-port Fa0/10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know what the "reflector-port Fa0/10" will do.  Is this a Cat 6K?  I have not seen that option in the Cat 6K documentation.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My experience has all been on the cat 6K.&lt;/P&gt;&lt;P&gt;On the Cat 6K with Native IOS if you execute the following commands:&lt;/P&gt;&lt;P&gt;monitor session 1 source vlan 10 - 12 rx &lt;/P&gt;&lt;P&gt;monitor session 1 destination remote vlan 555  &lt;/P&gt;&lt;P&gt;monitor session 2 source remote vlan 555 &lt;/P&gt;&lt;P&gt;monitor session 2 destination interface Fa0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then the session 1 traffic from vlans 10-12 WILL be spanned to port Fa0/24 (along with the traffic from remote spans from other connected switches).&lt;/P&gt;&lt;P&gt;The sesssion 1 source traffic WILL becomes session 2 source traffic in the above configuration on a Cat 6K.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I can't guarantee you is if the same will hold true on the span command on other Cisco switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2005 19:04:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rspan-sessions-and-ids/m-p/471152#M95018</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2005-11-28T19:04:26Z</dc:date>
    </item>
  </channel>
</rss>

