Cisco Switching/Routing :: 6509 - Doing IDS Via SPAN Ports

Dec 13, 2011

I am hoping you can provide me with some opinions, feedback, thoughts on the following. We have some Cisco 6509 switches in our environment currently hitting around 60% usage on the Router overall statistics.
 
Now we are looking at implementing an intrusion detection system but by being as least invasive as possible to the network. Our thoughts are to utilize a SPAN port on the switches to send traffic to the NIDS device but we have concerns of the following. The limitations of SPAN sessions on 6509's . The overhead on the switch of turning a SPAN session on and leaving it on permanently.

View 1 Replies


ADVERTISEMENT

Cisco Switching/Routing :: 6509 - Nexus And Span Sessions

Oct 24, 2011

I am in the early planning stages for a 6509 to Nexus 7K migration. Based on my experience with the 7K's at a previous company where we ran into a lot of issues, I am trying to be very careful.
 
I am more at home with the 6500 chassis and know what I can do with them.  I remember running into a limitation on the Nexus that involved their not supporting span sessions like the 6500's do.  Is that still the case ? 
 
If that isnt an option in the short term, I will need to look at a substantial investment in ethernet tap's to replace the lost span functionality because the security group's heavy use of span sessions.

View 1 Replies View Related

Cisco Switching/Routing :: Usb Ports On 6509 Supervisors

May 21, 2013

what the usb ports are used for on the supervisor cards?
 
I want to back up my file system, can I use a USB stick in the USB port to do this ? or are they for console use ?

View 4 Replies View Related

Cisco Switching/Routing :: EIGRP And HSRP Being Broadcast To End User Ports On 6509?

Nov 14, 2011

Is there away to disable the mulicasting of eigrp and hsrp to the end user ports on a 6509?

View 2 Replies View Related

Cisco Switching/Routing :: 6509 - 802.1x And Voice VLAN / Enable Dot1x On User's Ports On The Switch

Sep 17, 2012

I have a Cisco 6509 with IOS "s222-ipservicesk9_wan-mz.122-18.SXF16.bin"I need to enable dot1x on user's ports on the switch. each user is connected to the switch through the IP phone.
 
I just found out that I can not enabled dot1x on trunk port. I have tried to use "switchport voice vlan " but I got:
 
Switch(config-if)#switchport voice vlan 123
Command rejected: Gi7/20 is Dot1x enabled port.
 
let me know what should I do to get dot1x working?
 
Note: I have connected a laptop directly to the port and dot1x is working fine.

View 5 Replies View Related

Cisco Switching/Routing :: Remote Span With C2960

Mar 12, 2013

I am trying to configure RSPAN for one of my client. They have Server-Client VTP architecture. Voice Recording Server is connected to C4507. Agents are connected to C2960 and C3750. I got 2 sessions configured and the connectivity is a as follows:

1. Voice Recording Server-----C4507-----C2960-----C2960-----Agent IP Phones (Session 1)
2. Voice Recording Server-----C4507-----C3750-----Agent IP Phones (Session 2)
 
Recording works with Session-2 but not with Session-1. I understand the problem could be due to multiple reasons: 1.1. C2960 is working in client VTP mode so i cannot add remote span command under the vlan configuration. 1.2. C2960 has LANLITE IOS image which i am not sure if it supports Remote Span.

View 2 Replies View Related

Cisco Switching/Routing :: SPAN Configuration In Catalyst 3750

Dec 31, 2011

I have CISCO catalyst with VLANs (VLAN ID 33, 36, 40-53) configured. I need to configure port mirroring in Switch 3750 for NAC (Network Access Control).  I need to Monitor all the VLANs. Here is the SPAN configuration of switch: [code] Monitor session 1 source vlan 33 , 36 , 40 – 53.Monitor Session 1 destination interface fa 1/0/8  (here I am not able to set encapsulation dot1q ) because the error occurred saying %one or more dest port do not support the encapsulation%.

View 5 Replies View Related

Cisco Switching/Routing :: How To Setup SPAN On 4900m Switch

Feb 12, 2013

I currently have IOS image cat4500e-entservices-mz.122-53.SG5.bin.  According to my research it appears SPAN is supported on this OS.  However, after looking at procedure notes using websites like here:

[url]... I cannot find and obviously not figure out how to use the SPAN  command.  My main objective is to simply setup a port mirror on one of my TenGigabitEthnet interfaces and from what I read SPAN is the best way to setup a tap interface on a cisco switch.

View 2 Replies View Related

Cisco Switching/Routing :: VTP Traffic Not Seen On SPAN Port On 3750

Dec 12, 2011

Been dealing with a strange problem for several days now.  It started out with a problem that I thought was VTP related but ended up being something else.  I setup a span port on a 3750 that I am connected to that was mirroring the trunk connection coming into the switch.
 
Never saw an VTP traffic come across the connection but doing a sh vtp status indicated the traffic was arriving and getting processed.  When I found some debug commands (debug sw-lan vtp), I was also able to see the packets go between switches.  Seeing this issue concerns me that there is other traffic that isnt showing up during a span session.
 
I know that doing a span on a switch, especially using a trunk port as a source, isnt a good idea.  Since I didnt have a TAP at time, this was my only choice.  I have since borrowed a NetOptics TP-CU3 tap from a good friend and was able to confirm the VTP traffic was going across the trunk connection between switches.
 
All of my 3750's are running 12.2.55.SE.

View 8 Replies View Related

Cisco Switching/Routing :: Can't Configure SPAN On 800 Series Router

May 1, 2013

I have a Cisco 881 router running 15.1(4)M4. I am trying to configure SPAN on it to mirror my outside interface (source) to one of my LAN interfaces (dest).
 
!--- WAN interface
interface FastEthernet4
description Comcast WAN$ETH-WAN$

[Code]......
 
As you can see from the above output there is a problem with the command on this interface. When I try to set Fa0 as my source it works fine:
 
rtr(config)#mon session 1 source int fastEthernet 0
rtr(config)#
 
Is this because fa4 is layer 3 and fa0 is a switchport? If so, is there another way to set fa4 as the source?

View 4 Replies View Related

Cisco Switching/Routing :: 6513 Span Session Limit?

Jul 12, 2012

I have a need to capture some traffic but my core 6513's are already using the limit of 2 span sessions. I can't edit any of the sessions either because I want to source traffic from vlans and you can only do one or the other. Is using a VACL with 'switchport capture' on the destination interface an option ? E.g. I want to source traffic from vlan 10,20,30,40 and send the all to interface Gi10/10 ? Is there any caveats ? I dont need to be too granular with the ACL's but just capture all traffic in those vlans.

View 2 Replies View Related

Cisco Switching/Routing :: How Many Span / Rspan Can Configure In Cat6500

Mar 16, 2011

i will be creating combination of SPAN and RSPAN on catalyst 6506 according to the link
 
[URL]
 
im planning to implement this on two 6506 switches will this work? or do i violate the number of monitor session? sorce span?
 
sw1
monitor session 1 source interface Fa5/18monitor session 1 destination interface Fa5/48
monitor session 2 source interface Fa6/34monitor session 2 destination interface

[Code].....

View 1 Replies View Related

Cisco Switching/Routing :: Nexus 7000 Span Limitation

Apr 18, 2012

I've learned recently that the Nexus 7000 only allows the configuration of a maximum of 2 Monitor sessions for spanning traffic. I only have one monitor session left and I need to do the following. 2 Core Nexus 7000 boxes with 2 different traffic probes/sniffers to each nexus( eg Sniffer 1 connects to Switch A on interface eth 1 and to Switch B on eth 1 ; Sniffer 2 connects to Switch A on eth 2 and to Switch B on eth 2.) My plan was to setup a standard session with multiple sources and destinations then on the interfaces connecting to the sniffers run a trunk and do 'sw trunk allowed xxxxx' and filter what I need to go to each sniffer box. However I've recently found out that some of my source traffic is coming from Port-Channel interfaces. Is there a way I can get around this and still do the filtering within only 1 monitor session ?

View 1 Replies View Related

Cisco Switching/Routing :: 4900 Span Configuration On Switches

Sep 16, 2012

i have configured SPAN on cisco 4900 series switches its a Loacal SPAN . as there is only commnads to complete this activity but hard luck its not working.

View 5 Replies View Related

Cisco Switching/Routing :: 3750 - SPAN Configuration For Websense

Jul 3, 2012

I have configured SPAN in cisco 3750 switch as below mentioned. but the destination port protocol is down.
 
Network Diagram:
 
switch(config)#monitor session 1 source interface gigabitethernet1/0/1switch(config)#monitor session 1 destination interface gigabitethernet1/0/11 ingress vlan 1

[Code]....

View 8 Replies View Related

Cisco Switching/Routing :: SPAN SIP And Wireshark 2950 Configuration

May 26, 2013

I have cisco 2651 with one L3 interface ip 172.26.18.200. This Cisco is gateway from E1 PRI (PBX Aastra MX-ONE TSW) to SIP (Asterisk). This cisco 2651 connected to cisco 2950 in port Fa 0/12. Fa 0/12 is in VLAN 518 (dot1q).

On cisco 2950 i made next commands:
 
# monitor session 1 source interface Fa 0/12 both encap dot1q
# monitor session 1 destination interface Fa 0/9
#sho monitor session 1
[Code].....

View 2 Replies View Related

Cisco Switching/Routing :: SPAN Port Configuration On 3750?

May 23, 2012

I'm trying to configure a mirror port on a 3750. This configuration needs to replicate data from local ports, but I need that also act as a regular access port.
 
With the initial configuration, SPAN port, there is no problem, all the data of the configurated ports is replicating in the configurated port. On the port configurated as mirror there is a PC connected for audio recording. When the port is not operating as SPAN there is communications without problem over the LAN. But when I configure the port as SPAN, communication is interrupted.
 
Here is the actual configuration:
 
SWITCH1-PISO7#sh monitor session 1
Session 1
---------
Type                   : Local Session

[Code]......

View 5 Replies View Related

Cisco Switching/Routing :: 802.1 Span And Wireshark To See P-bits And Vlan Tags

Dec 30, 2009

I do not see 802.1Q tags nor do I see p-bits (COS) in my wireshark captures. My setup is not working and I have no way to verify (sniff) that the 6509 is setting the p-bits to 3. [code]

View 4 Replies View Related

Cisco Switching/Routing :: 2960 -Destination Port Not Responding Over SPAN

Jun 8, 2012

i have configured SPAN over cisco 2960 to monitor source port traffic but after configuration i dont able to get response from destination port  as my NMS is attached on destination port so i lost its web interface.
 
Configuration is as under.
 
monitor session 1 source interface gigabitEthernet0/5  (Source Port on Vlan 100) monitor session 1 destination interface gigabitEthernet0/1 (Destination Port on Vlan 200)

View 2 Replies View Related

Cisco Switching/Routing :: Nexus 7K (6.x) / SPAN To Multiple Destinations Does Not Work

May 18, 2013

I have a single Nexus 7K (6.x) with only F2 modules and I would like to SPAN the same source interfaces and vlans to mulitple destination servers (interfaces).  When configuring SPAN to a single destination traffic gets replicated successfully but when I add an additional destination to the same SPAN session then none of the destination interfaces receive any traffic.  As soon as modify the SPAN to include only a single destination interface it works again.  I'm guess this is a limitation of the Nexus 7K 6.x code or the F2 modules. 

View 4 Replies View Related

Cisco Switching/Routing :: NEXUS 7k Span Session Getting Twice Data To Port

Jun 9, 2013

I'm setting up a montitor session on a NEXUS 7K as below.we are receiving in 150M of data and 0 data going out port 9/25.but port 4/24 shows 300M to the span port?

View 1 Replies View Related

Cisco Switching/Routing :: Creating A Span Port On Router 3640

Oct 1, 2012

i am running c3640-is-mz.124-21.bin on a cisco router 3640. i am trying to create a monitor session in the CLI and everytime i type the command Router(config)#monitor session 1 interface ethernet2/1 % Invalid input detected at '^' marker. Router(config)#monitor session 1 interface ethernet2/1 ^% Invalid input detected at '^' marker. i get the error invalid input ?

View 10 Replies View Related

Cisco Switching/Routing :: 3725 SPAN Not Supported On Some Routed Interfaces?

Dec 12, 2012

I'm trying to configure a SPAN session on a Cisco 3725 router, but it won't let me complete the command. The router has two Fast Ethernet interfaces: 0/0 and 0/1. I'm trying to configure a SPAN session with Fa0/0 as the source interface and Fa0/1 as the destination interface. [code] But when I try to configure the session, it seems like it's giving me the option to configure the SPAN session, but in the end the router won't let me: [code] When I type "?", why would it give me the option of using the Fast Ethernet interface as source port, then when I try to execute the command, it doesn't like it?

View 7 Replies View Related

Cisco Switching/Routing :: Configuring Span Port On 6513 Switch

Mar 2, 2012

I have two servers, connected on two(Different) 6513 directly connected switches. Both these servers are in the same Vlan.
 
I have to monitor communication these two servers. I have a system connected on one of the 6513 switch, where network tool wireshark is installed.
 
How to configure span port.
 
switch 6513-1# show run int Gi10/43  --------------------Server 1 is connected
 
switch 6513-2# show run int Gi9/45 ------------------------Server 2 is connected
 
switch 6513-2# show run int Gi9/46 ------------------------System on which network tool wireshark is installed.

View 9 Replies View Related

Cisco Switching/Routing :: How Many VLANs Can Span In Monitor Session On Nexus 7K

Mar 3, 2013

rsbd7k01-p-vdca(config)# monitor session 2
rsbd7k01-p-vdca(config-monitor)# source vlan ?
<1-3967> 
rsbd7k01-p-vdca(config-monitor)# source vlan 1 - 3967
ERROR: vlan 33-3967: Number of source vlans exceeds maximum
rsbd7k01-p-vdca(config-monitor)#

View 3 Replies View Related

Cisco Switching/Routing :: Not Capturing Span Traffic On WS-4510 / SupervisorV / 12.2(54)SG1

Mar 22, 2012

I have configured Span port on our 4510. We have an application 5view server to monitor trafic connected to G9/17 Since we have changed the network connection from physical Giga port and add a Port-channel instead, we don't see any more trafic from the new Port-channel to G9/17
 
We have the configuration below on our 4510 :
 
monitor session 1 source interface Gi4/6
monitor session 1 source interface Po20
monitor session 1 filter vlan 311 - 312 , 375
monitor session 1 destination interface Gi9/17
  
From the commands show, we don't see the trafic duplication from the source to the destination port :
 
Port Source
 
4510-5567#sh int po20
Port-channel20 is up, line protocol is up (connected)
Hardware is EtherChannel, address is 0016.9de2.a818 (bia 0016.9de2.a818)

[Code].....

View 2 Replies View Related

Cisco Switching/Routing :: 6509 To 6509-E Chassis Upgrade?

Nov 21, 2011

I currently have a couple of 6509 chassis (router/switches) with the following hardware blades:

     x3     48 ports
     x1     NAM
     x2     Sup720
     Running 12.2(18)SXF3
 
I am keeping the four Sup720 modules and have purchased new versions of the others blades including two new 6509-E chassis?Can I take my stand-by Sup720 out of the production machine and insert it into the new chassis?

View 2 Replies View Related

Cisco Switching/Routing :: Upgrade Of 6509 To 6509-E Chassis

Nov 21, 2011

I currently have a couple of 6509 chassis (router/switches) with the following hardware blades:

x3     48 ports
x1     NAM
x2     Sup720

Running 12.2(18)SXF3.I am keeping the four Sup720 modules and have purchased new versions of the others blades including two new 6509-E chassis. Can I take my stand-by Sup720 out of the production machine and insert it into the new chassis?

View 2 Replies View Related

Cisco Switching/Routing :: Effects Of SPAN Port Configuration On 4507R+E Switch?

Oct 29, 2011

I read quite a few documents on configuring SPAN on a cisco switch but none of them mention any limitations or any kind of CPU load it can have on a switch. I need to configure this on one of our switches and would like to know if there are any implications related to SPAN.

View 5 Replies View Related

Cisco Switching/Routing :: SPAN / Monitoring Destination Port Behaviour - 2960 LAN

Jan 16, 2012

In s SPAN session , normally the destination prt is used for monitoring purpose only. But could destination port be used to access the equipement or PC connected to that port , for a 2960 LAN BASE image  switch .

View 2 Replies View Related

Cisco Switching/Routing :: Catalyst 6500 - Cannot See Return Traffic On SPAN Session?

Jan 31, 2012

On a Catalyst 6500, we configured a SPAN session with VLAN 300 as a source. We configured the session bi-directional ("both" keyword). We connect a sniffer on the SPAN destination port.
 
Strangely enough, we only see the traffic from the VRF to the firewall, but not the reverse traffic ! What can be the problem ?

View 2 Replies View Related

Cisco Switching/Routing :: 5596 VLAN Traffic Span Across Vpc Peer-link

Apr 22, 2013

I have pair of 5596 switches in vPC. One host say "HOST A" is connected to the primary vPC peer and other "HOST B" on secondary vPC peer.Both are in same VLAN 10. Both hosts are vpc orphan ports as their NIC is configured in active/standby mode.I have configured span session on both vPC peers with span source as VLAN 10 in rx mode.Span destination is connected to secondary vPC peer. The issue here is that I am not able to capture the traffic originating from HOST A destined to HOST B which is traversing vPC peer-link.Same issue occurs for the traffic in reverse way and span destination on primary vPC peer. In a nutshell, any traffic which crosses vPC peer-link is not getting captured.
 
What could be the issue and is there any solution for it. Below mentioned is the span config and relevant interfaces. [code]

View 4 Replies View Related

Cisco Switching/Routing :: Monitor Session Local SPAN Small Output With 7606

Aug 22, 2012

I am having difficulties with getting SPAN traffic over my WS-X6704-10GE (CFC).
 
CISCO7606
ios 12.2(33)SRE6, SUP720-3BXL
 
Trying to use the span feature, put the commands listed below in and they entered successfully, but the port is not being mirrored.
 
interface TenGigabitEthernet1/1
description PUBLIC
dampening
mtu 9216
ip address x.x.x.x x.x.x.x
 [Code]....

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved