05-08-2011 07:58 AM - edited 03-06-2019 04:57 PM
Hi, I've a problem with SPAN. it doesn't send icmp packets to my sniffer. For example: R1 - SW1 - R2, I can do ping between R1 and R2 but I can't see this icmp packets in wireshark through monitor session destination port. If I replace router by PC I can see all icmp packets. Why have I problem only with icmp packets generated by routers??
05-08-2011 08:14 AM
can you post your SW1 configuration?
05-08-2011 08:17 AM
interface FastEthernet0/1
switchport access vlan 1
interface FastEthernet0/2
switchport access vlan 1
monitor session 1 source interface Fa0/1 , Fa0/2
monitor session 1 destination interface Fa0/24 encapsulation replicate
05-08-2011 08:49 AM
Post configuration of fas0/24
Also "show interface fas0/24"
and remove "encapsulation replicate" parameter
05-08-2011 08:54 AM
I removed encapsulation replicate parameter but sniffer doesn't detect ICMP packets generated on routers.
SW1#sh interfaces fastEthernet 0/24
FastEthernet0/24 is up, line protocol is down (monitoring)
Hardware is Fast Ethernet, address is 001c.57bc.d19a (bia 001c.57bc.d19a)
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 100Mb/s, media type is 10/100BaseTX
input flow-control is off, output flow-control is unsupported
ARP type: ARPA, ARP Timeout 04:00:00
Last input never, output 05:54:18, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 1000 bits/sec, 2 packets/sec
37 packets input, 6409 bytes, 0 no buffer
Received 37 broadcasts (6 multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog, 6 multicast, 0 pause input
0 input packets with dribble condition detected
32601 packets output, 2722061 bytes, 0 underruns
0 output errors, 0 collisions, 1 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier, 0 PAUSE output
0 output buffer failures, 0 output buffers swapped out
05-08-2011 08:57 AM
are you saying it doesn't see only ICMP and sees everything else?
what kind of sniffer are you using? Did you try PC with wireshark running?
05-08-2011 09:01 AM
Yes, I see for example arp packets but don't see ICMP. If I connect 2 pc and make ping I can see arp and ICMP. I think the problem is the ICMP type of routers. I'm using Wireshark.
05-08-2011 09:08 AM
IOS uses the standard ICMP echo and echo reply for the pings.
Can you post router configs?
05-08-2011 09:15 AM
R1#sh run
Building configuration...
Current configuration : 1096 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R1
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
!
no aaa new-model
dot11 syslog
ip source-route
!
!
!
!
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
!
!
archive
log config
hidekeys
!
!
!
!
!
!
!
!
interface FastEthernet0/0
ip address 10.0.0.1 255.0.0.0
duplex auto
speed auto
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet0/1/0
!
interface FastEthernet0/1/1
!
interface FastEthernet0/1/2
!
interface FastEthernet0/1/3
!
interface Serial0/0/0
no ip address
shutdown
no fair-queue
clock rate 2000000
!
interface Serial0/0/1
no ip address
shutdown
clock rate 2000000
!
interface Vlan1
no ip address
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 FastEthernet0/0
no ip http server
no ip http secure-server
!
!
!
!
!
!
!
!
!
control-plane
!
!
!
line con 0
exec-timeout 0 0
line aux 0
line vty 0 4
login
!
scheduler allocate 20000 1000
end
R2#sh run
Building configuration...
Current configuration : 1086 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R2
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
!
no aaa new-model
dot11 syslog
ip source-route
!
!
!
!
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
!
!
!
!
!
archive
log config
hidekeys
!
!
!
!
!
!
!
!
interface FastEthernet0/0
ip address 10.0.0.2 255.0.0.0
duplex auto
speed auto
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet0/1/0
!
interface FastEthernet0/1/1
!
interface FastEthernet0/1/2
!
interface FastEthernet0/1/3
!
interface Serial0/0/0
no ip address
shutdown
no fair-queue
clock rate 2000000
!
interface Serial0/0/1
no ip address
shutdown
clock rate 2000000
!
interface Vlan1
no ip address
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 FastEthernet0/0
no ip http server
no ip http secure-server
!
!
!
!
!
!
!
!
!
control-plane
!
!
!
line con 0
exec-timeout 0 0
line aux 0
line vty 0 4
login
!
scheduler allocate 20000 1000
end
I've tested the same in other switches and routers and I had the same problem. It's illogical and strange
05-08-2011 09:21 AM
Post full config of the switch?
What model and IOS version running on the switch?
05-08-2011 09:31 AM
I've two models:
3560
3560g
and IOS c3560-advipservicesk9-mz.122-46.SE.bin
SW1#sh running-config
Building configuration...
Current configuration : 1559 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SW1
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
system mtu routing 1500
ip subnet-zero
!
!
!
!
!
!
!
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
!
interface FastEthernet0/1
switchport access vlan 1
!
interface FastEthernet0/2
switchport access vlan 1
!
interface FastEthernet0/3
!
interface FastEthernet0/4
!
interface FastEthernet0/5
!
interface FastEthernet0/6
!
interface FastEthernet0/7
!
interface FastEthernet0/8
!
interface FastEthernet0/9
!
interface FastEthernet0/10
!
interface FastEthernet0/11
!
interface FastEthernet0/12
!
interface FastEthernet0/13
!
interface FastEthernet0/14
!
interface FastEthernet0/15
!
interface FastEthernet0/16
!
interface FastEthernet0/17
!
interface FastEthernet0/18
!
interface FastEthernet0/19
!
interface FastEthernet0/20
!
interface FastEthernet0/21
!
interface FastEthernet0/22
!
interface FastEthernet0/23
!
interface FastEthernet0/24
!
interface GigabitEthernet0/1
!
interface GigabitEthernet0/2
!
interface Vlan1
no ip address
!
ip classless
ip http server
ip http secure-server
!
!
!
control-plane
!
!
line con 0
line vty 5 15
!
!
monitor session 1 source interface Fa0/1 , Fa0/2
monitor session 1 destination interface Fa0/24
end
05-08-2011 09:38 AM
Are you sure you have the setting in wireshark "capture packets in promiscuous mode"?
05-08-2011 09:40 AM
ooo yes!!
05-08-2011 09:42 AM
post ipconfig /all from your wireshark PC?
05-08-2011 09:48 AM
I can see CDP, VTP, PAgP, DTP, ARP, STP but ICMP from 1 access port to other access port is impossible!!!! I don't have any problem with wireshark PC because the same system detects all packets, included ICMP when I change routers by PC's.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide