cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
589
Views
0
Helpful
1
Replies

SPAN port not seeing all of the traffic

d.worthley
Level 1
Level 1

I have 2 6500 hybrid MSFC3 with span ports configured for Surf Control. Specifically the span ports are monitoring the inside interfaces of the PIX firewalls and mirroring the traffic to the monitoring interface of the Surf Control appliance.

Here is the following span configuration:

Destination : Port 2/37

Admin Source : Port 2/4

Oper Source : Port 2/4

Direction : transmit/receive

Incoming Packets: disabled

Learning : enabled

Multicast : enabled

Filter : -

The Surf Control is not seeing the return packet from the PIX for devices not directly routed out the L3 vlan.

1 Reply 1

aghaznavi
Level 5
Level 5

The SPAN feature was introduced on switches because of a fundamental difference that switches have with hubs. When a hub receives a packet on one port, the hub sends out a copy of that packet on all ports except on the one where the hub received the packet. After a switch boots, it starts to build up a Layer 2 forwarding table on the basis of the source MAC address of the different packets that the switch receives. After this forwarding table is built, the switch forwards traffic that is destined for a MAC address directly to the corresponding port

http://www.cisco.com/en/US/products/hw/switches/ps708/products_tech_note09186a008015c612.shtml#descp

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card