cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
564
Views
0
Helpful
2
Replies

Adding VLAN to VACL for IDSM2 Blackholes that VLAN

west-david
Level 1
Level 1

We have a 6509 running 12.2.18SXF with an IDSM-2 (5.0(6)). We are using VACLs to capture traffic from several VLANs onto the IDSM. Today, we added another VLAN to the IDSM by creating a VACL for that VLAN with the "action forward capture" statement. As soon as the VACL was applied to that VLAN, all traffic for that VLAN was blackholed. We reproduced this problem on another VLAN. Anyone seen this?

2 Replies 2

globalnettech
Level 5
Level 5

Hello David,

not sure if your problem still exists, but make sure that you add the VLAN whose traffic you want to capture to the list of allowed VLAN´s on the capture port (´switchport capture allowed vlan´).

Do you manage do get any traffic from any other VLAN captured at all ?

If possible, can you post the config of your 6509 ?

Regards,

GNT

Howdy,

Yeah, we already have about 13 VLANs being captured to the IDSM which is why I was concerned when adding a new one caused all traffic on that VLAN to drop. I'll be doing more testing on it later this week.

Thanks,

-DW

Review Cisco Networking for a $25 gift card