cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
97
Views
0
Helpful
1
Replies

SPAN and IDS cisco 6509

mateens
Beginner
Beginner

I have a question regarding SPAN. My main focus is to detect spams and viruses on the Employee VLAN.(We have server,student,guest and print VLANs too) using an IDS.

Would that traffic be detectable with my SPAN config which mirrors out/in traffic from Interface connected to ISP or should I use only the Employee VLAN int. as the source of the SPAN ?

Lets put it this way, Im confused about the  basic concept of how the traffic looks like when it leaves a vlan and routed out to the internet .

1 Reply 1

Jon Marshall
VIP Community Legend VIP Community Legend
VIP Community Legend

If you use the vlan as the source then you will be seeing on that vlans traffic.

If you use the interface connected to the ISP then you would presumably be seeing all traffic going to the internet which would be traffic from all vlans.

Is this what you are asking ?

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers