10-29-2009 08:23 AM - edited 03-06-2019 08:22 AM
Hello! We have a 6500 running Cat OS 8.8-5-8. We have a snort device that we would like to monitor our server vlan with, Vlan 101. I setup this snort on a port, 2/28, which is a GB port on a WS-X6548-GE-TX card.
We have experienced some server performance issues since I setup the span. Intermittently we cannot gain access to a server, ping is slow to respond, drops ping requests, no rdp, etc. It sure seems suspicious that it is due to this span. I moved some of the servers that were connected in the same banks as this snort port to another card and port, and they now perform fine.
My question is, am I doing this wrong? Is there a different way to accomplish this and not effect performance?
My command I ran on the switch was:
#switch port analyzer
set span permit-list disable
set span 101 2/28 both session 1 inpkts disable learning enable multicast enable
10-29-2009 09:09 AM
You could be running into something like this.
Read this. 6548's not really a good choice to run large server farms on. this sounds like what you are seeing.Seeing that you are spanning a whole vlan which is a lot of traffic.
http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a00801751d7.shtml#ASIC
10-29-2009 01:19 PM
Perfect. Now what I wanted to hear, but it explains alot! Thanks for the quick reply.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide