07-26-2018 04:28 PM - edited 07-29-2018 05:53 PM
I've been tasked to gather what are the 'conversation' between VLANs to build an ACL.
As it's a standard Core/Distribution and Access environment, as the core/distribution switch are configured with HSRP and only L2 on the access switches (trunk to the dist/core). There are a total of 5 VLAN (10, 20, 30, 40, 50 for instance) that i would need to SPAN, my question are :
1- Will it be sufficient to perform local VLAN SPAN on the HSRP active switch only ? (only interested with intervlan traffic for eg, between Vlan 10 and Vlan 20 for instance)
2- Will be pre-configuring the monitor session without wireshark connected affecting the CPU utilization ?
3- ACL Logging not recommended as we do not want to risk the CPU utilisation spiking and causing the network goes down.
4- Netflow not supported on the L3 device (Catalyst 3750 without SM)
Thanks in advance,
Solved! Go to Solution.
07-27-2018 07:32 PM
07-26-2018 09:26 PM - edited 07-26-2018 09:26 PM
Hi
Not sure you'll be satisfied with span. I mean you need to have a solid device receiving all the traffic.
I would suggest to use netflow capabilities. You'll have src and dst ip and based on this you'll be able to tell which Vlans communicate together.
What type of device you've?
07-26-2018 09:38 PM
07-27-2018 07:32 PM
07-29-2018 05:27 PM
07-29-2018 06:51 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide