10-06-2005 08:47 AM - edited 03-10-2019 01:40 AM
Hello,
We've got two PIX'es setup in failover mode, we had an issue a day or so ago when the secondary pix took over the IDS was dead in the water because the SPAN config on our 6500 is not duplicating both ports. Suggestions on getting the SPAN config to pass traffic in a failover mode?
Thanks,
Kevin
10-13-2005 05:51 AM
From what I understand, you need to include both the PIX ports (Primary and Secondary) in the SPAN configuration on your 6500 as the SPAN source ports. With that, even after failover, your SPAN will be able to capture the packets from the active PIX.
10-17-2005 07:24 AM
The ports that the PIXs are connected to both need to be SPAN sources. If you are using a Catalyst then use the 'monitor session <#> source interface..." command is what you need.
Here's the poorly written config guide..
http://www.cisco.com/univercd/cc/td/doc/product/lan/c3550/12225sec/3550scg/swspan.htm
And a fairly good field notice...
http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a008015c612.shtml
10-18-2005 02:34 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide