09-24-2015 02:01 PM - edited 03-08-2019 01:56 AM
My old faithful switch died yesterday so I replaced it with an SG200-50 smart switch. Now I'm attempting to configure a port span for packet capture. I want to capture all traffic in & out of the network for my Websense Triton filter. How do I configure a port span that captures all traffic on ports 1-47 and mirrors that traffic to port 48?
Any help would be greatly appreciated!!!
09-24-2015 05:17 PM
SG200 only supports up to 4 source ports but if all the ports are running on the same vlan you can mirror the vlan or up to 4 vlans.
Port mirroring | Traffic on a port can be mirrored to another port for analysis with a network analyzer or RMON probe. Up to 4 source ports can be mirrored to one destination port. A single session is supported. | |||||||||||
VLAN mirroring | Traffic from a VLAN can be mirrored to a port for analysis with a network analyzer or RMON probe. Up to 4 source VLANs can be mirrored to one destination port. A single session is supported. |
Configuration:
See:http://www.cisco.com/c/dam/en/us/td/docs/switches/lan/csbss/sf20x_sg20x/administration_guide/78-21139.pdf - page 77
To enable mirroring:
STEP 1 Click Administration > Diagnostics > Port and VLAN Mirroring.
This page contains the following fields:
• Destination Port—Port to which traffic is to be copied; the analyzer port.
• Source Interface—Interface, port, or VLAN from which traffic is sent to the
analyzer port.
• Type—Type of monitoring: incoming to the port (Rx), outgoing from the port
(Tx), or both.
• Status— Displays one of the following values:
- Active—Both source and destination interfaces are up and forwarding
traffic.
- Not Ready—Either source or destination (or both) are down or not
forwarding traffic for some reason.
STEP 2 Click Add to add a port or VLAN to be mirrored.
STEP 3 Enter the parameters:
• Destination Port—Select the analyzer port to where packets are copied. A
network analyzer, such as a PC running Wireshark, is connected to this port.
If a port is identified as an analyzer destination port, it remains the analyzer
destination port until all entries are removed.
• Source Interface—Select the source port or source VLAN from where
traffic is to be mirrored.
• Type—Select whether incoming, outgoing, or both types of traffic are
mirrored to the analyzer port. If Port is selected, the options are:
Administration: Diagnostics
Viewing CPU Utilization and Secure Core Technology
79 Cisco Small Business 200 Series Smart Switch Administration Guide
7
- Rx Only—Port mirroring on incoming packets.
- Tx Only—Port mirroring on outgoing packets.
- Tx and Rx—Port mirroring on both incoming and outgoing packets.
STEP 4 Click Apply. Port mirroring is added to the Running Configuration.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide