cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
600
Views
5
Helpful
3
Replies

Span before or after ACL enforcment

rhague
Level 1
Level 1

I needed to limit traffic on an Ethernet connection coming from another agency so I only saw the IP addresses I wanted.  I put an inbound ACL on the interface on my 3750.  Now I want to verify the ACL effectiveness, so I spanned traffic from that port to another to feed to my Wireshark for analysis.  I do not see the unwanted traffic, but I wasn't certain if the was the ACL's work or there just wasn't any traffic.

So here's the question: does the span take place before or after the ACL enforcement?  I've been looking for a diagram that shows the flow thru the 3750 (e.g. first ACL then NAT the Span then...) but I haven't ben able to find one.  Any ideas?

3 Replies 3

Jon Marshall
Hall of Fame
Hall of Fame

rhague wrote:

I needed to limit traffic on an Ethernet connection coming from another agency so I only saw the IP addresses I wanted.  I put an inbound ACL on the interface on my 3750.  Now I want to verify the ACL effectiveness, so I spanned traffic from that port to another to feed to my Wireshark for analysis.  I do not see the unwanted traffic, but I wasn't certain if the was the ACL's work or there just wasn't any traffic.

So here's the question: does the span take place before or after the ACL enforcement?  I've been looking for a diagram that shows the flow thru the 3750 (e.g. first ACL then NAT the Span then...) but I haven't ben able to find one.  Any ideas?

Span on ingress (rx) will send copies of all packets to the span destination port even if that packet is subsequently dropped by an interface acl.

Span on egress (tx) will process the acl on the packet and if it is allowed will then send a copy to the SPAN destination port.

See this link for more details -

3750 SPAN traffic

Jon

Answered my question completely. Thank you for your assistance.

-Ray

No problem, glad to have helped.

Jon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card