I have 2 6500 hybrid MSFC3 with span ports configured for Surf Control. Specifically the span ports are monitoring the inside interfaces of the PIX firewalls and mirroring the traffic to the monitoring interface of the Surf Control appliance.
Here is the following span configuration:
Destination : Port 2/37
Admin Source : Port 2/4
Oper Source : Port 2/4
Direction : transmit/receive
Incoming Packets: disabled
Learning : enabled
Multicast : enabled
Filter : -
The Surf Control is not seeing the return packet from the PIX for devices not directly routed out the L3 vlan.