Configure IDSM with RSPAN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-19-2006 11:30 PM - edited 03-10-2019 03:23 AM
Hi
We have here two 6509 switches with an IDSM blade in each one.
I want one of them to monitor a remote port on a remote switch.
But I can not see traffic on the IEV.
That is the configuration I used:
We have a pre configured RSPAN vlan (555) on our VTP servers.
1. on the remote switch:
monitor session 2 source interface Gi6/37
monitor session 2 destination remote vlan 555
2. on the 6509:
monitor session 2 source remote vlan 555
monitor session 2 destination intrusion-detection-module 2 data-port 2
3. on the IEV:
made a new filter with the scope of addresses used on that network.
made a new view using the filter I made.
If I forgot something tell me...
Thank You!!
- Labels:
-
IPS and IDS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2006 11:53 AM
Not my area of expertise (RSPAN), but did you set up the IDSM2 ports to allow the proper vlans? This would be a switch config item, not an IPS config item.
Also, if you are running IPS 5 or 6, you can use the "packet" command to display what the IPS sensor is seeing on its sensing ports. Its a good way to see that your traffic is getting to the sensor.
Scott
