We are adding another three switches into the environment and would like to sniff traffic from all four switches without an additional IDS devices or NICs if possible. My intention is to configure the new switches as follows...
The original config was done by a former colleague so I just wanted to check whether this was the best way of doing it.
Also, should I remove the monitor session x filter packet-type good rx so that the IDS sees all packets? I would have thought that you want your IDS to see all packets? This command appears to be a default and appears any time I configure a monitoring session.
I'm running cat4500-ipbasek9-mz.122-54.SG1.bin on a Cisco 4948
Hmmm, it doesn't seem to be working. I'm seeing the traffic from the other switches but not for the one to which the IDS is attached. It's like it won't let me take the VLAN 34 traffic and send it to a RSPAN session on the same switch