cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
295
Views
0
Helpful
1
Replies

Catalyst 6500 SPAN problems - part of the traffic not visible

Wojciech Mitus
Level 1
Level 1

Hello,

Consider the following configuration:

hardware: Catalyst 6500E with Supervisor Engine 720

switch#sh monitor

Session 10

----------

Type                   : Local Session

Source VLANs           :

    Both               : 10-14,18,189,211,213-214,223-224,240,242,244-245,264-265,267,270,272,274,520,522-523,525,527-533,536-537,539,547

Destination Ports      : Te6/1

Egress SPAN Replication State:

Operational mode       : Centralized

Configured mode        : Centralized (default)

As You can see, there are a lot of VLAN's (and a lot of traffic) going through this SPAN session.

One of the SPAN'ed VLAN's is VLAN10, with following SVI config:

interface Vlan10

ip address 10.1.10.2 255.255.255.0

ip flow ingress

standby 10 ip 10.1.10.1

standby 10 priority 130

standby 10 preempt

standby 25 ip 10.1.10.4

standby 25 priority 130

standby 25 preempt

standby 35 ip 10.1.10.7

standby 35 priority 130

standby 35 preempt

end

Problem is, that traffic directed to HSRP gateway in group 10 is not visible in SPAN session. When default gateway on host is changed to virtual address in group 25, traffic from this host appears on SPAN destination port as expected.

Any thoughts on what could cause such behavior?

Thanks,

WM

1 Reply 1

Wilson Bonilla
Level 3
Level 3

Hello.

1. Is vlan 10 in group 10 active in this switch?

2. If you check the arp table of one host in vlan 10, with the command arp -a (windows) is it pointing to the mac address of vlan 10 group 10 in the 6500?

3. What if you span the ingress physical ports of the 6500? do you see traffic in vlan 10?

Regards.

Wilson B.

Review Cisco Networking products for a $25 gift card