04-27-2022 11:27 PM
my source port is a access port with no IP assigned and then i wireshark the dest port I can only see ARP, Broadcast... I can't see any other traffic passing thru that access port. why?
04-28-2022 12:57 AM
can't see any TLS, HTTP, HTTPS or any handshake.
04-28-2022 04:43 AM
It sounds like you haven't configured a SPAN/monitor session in the switch. It would be normal for a regular access port to only see broadcasts or traffic directed to the local MAC address.
04-28-2022 04:11 PM - edited 04-28-2022 04:11 PM
post the config and monitor session information
try :
monitor session 1 dest int gig0/1 both (change the interface as per requirement)
04-28-2022 06:16 PM
Gi1/0/1 is just an layer 2 access port to firewall(gateway) but we can't see session traffic on monitoring port Gi1/0/13.
I want to monitor the traffic out/in to the firewall and to see all kinds of traffic.
04-29-2022 03:29 AM
Hello
Change the destination port to be a trunk and source from the FW access port vlan
Example:.
interface int Gi1/13
description span session 1 for gig0/1
switchport mode trunk
switchport trunk allowed vlan x (firewall vlan)
monitor session 1 source vlan vlan x (firewall vlan)
monitor session 1 destination interface Gi1/13
05-04-2022 01:42 AM
I've made the changes accordingly but my monitoring Palo Tap mode interface still not capturing anything.
04-29-2022 04:40 AM
how does your config look interface and monitor session
05-03-2022 11:25 PM
source int
interface GigabitEthernet1/0/1
description To FW port 4
switchport access vlan 1001
switchport mode access
spanning-tree portfast
destination int
interface GigabitEthernet1/0/13
description Palo monitor port
switchport access vlan 1001
switchport mode access
switchport nonegotiate
05-05-2022 07:18 PM
I found another thread https://community.cisco.com/t5/switching/only-seeing-broadcast-traffic-on-cisco-3750-monitoring-port/td-p/3805037/page/2
Same issue as my setup, I only see broadcast traffic.
05-05-2022 07:35 PM
I found some bug of this 3650, my current IOS XE is 3.6.4.E. I think need to upgrade to resolve. version.https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3650/software/release/3e/release_notes/OL3264701.html#pgfId-940845
https://quickview.cloudapps.cisco.com/quickview/bug/CSCvb60207
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: