RE: ID sensors on a Cisco Catalyst 6509 switch

From: David Alejandro Hernandez Alonso (david.hernandez@corp.terralycos.com)
Date: 08/08/01


Message-ID: <86D5B070C6E7D211AFDA00609780B4310C2B8FCD@CIDINTEXCHANGE>
From: David Alejandro Hernandez Alonso <david.hernandez@corp.terralycos.com>
To: Jay.Leek@nokia.com, focus-ids@securityfocus.com
Subject: RE: ID sensors on a Cisco Catalyst 6509 switch
Date: Wed, 8 Aug 2001 10:58:16 -0500 


Yes you can, but you can only create up to 2 span ports
to watch traffic in "both" or rx directions from the source
and up to 4 span ports with tx directions.

When you setup the span, you need to append the keyword 'create'
at the end, just to don't overwrite you previous span session.

i.e.
set span 1 3/3 create

Regards.

David Hdz.
Information Security Manager
Terra Networks México

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/sw_6_2/confg_gd/
span.htm

-----Original Message-----
From: Jay.Leek@nokia.com [mailto:Jay.Leek@nokia.com]
Sent: Wednesday, August 08, 2001 10:39 AM
To: focus-ids@securityfocus.com
Subject: ID sensors on a Cisco Catalyst 6509 switch

*** PGP Signature Status: unknown
*** Signer: Unknown, Key ID = 0x54AE3FA3
*** Signed: 8/8/01 8:41:49 AM
*** Verified: 8/8/01 10:50:34 AM
*** BEGIN PGP VERIFIED MESSAGE ***

Does anyone know if it is possible to setup multiple spanning ports
to different destinations from different sources on a Cat 6509? We
have 4 VLANs on a Cat 6509 and are needing to monitor a segment in
each of the VLANs using 4 different ID sensors. So we need to setup
4 different spanning ports. Well, the Catalyst software is not
allowing us to do it. I cannot help but think that we are missing
something because I would think that this would not be a problem for
a Cat 6509. I am going to look into the IOS version of the software
to see if it may be possible with it as we are not currently running
it on this switch, but I thought that I would ask and see if someone
else has run into this problem first. Thanks in advance for your
help.

BR,

_______________________________
Jay Leek
Nokia, Inc.
Global Network Security
Mobile (Finland): +358-50-346-8800 (Current)
Mobile (USA): +1-469-231-1999

*** END PGP VERIFIED MESSAGE ***



Relevant Pages

  • RE: Caching a sniffer
    ... I'm aware of SPAN, of course. ... sniffing, not PREVENT it. ... devices from going into promiscuous mode, or shut down the switch ... > It's called Port Mirroring or SPAN. ...
    (Security-Basics)
  • Re: Troubleshooting DHTML and Javascript
    ... I display one of several spans when the user mouses over some code. ... Inside the span are several tabs. ... Switch from one span to another and reset the fields. ... when I set a javascript alert to display what the old visible ...
    (comp.lang.javascript)
  • Re: Troubleshooting DHTML and Javascript
    ... I display one of several spans when the user mouses over some code. ... Inside the span are several tabs. ... Switch from one span to another and reset the fields. ... when I set a javascript alert to display what the old visible ...
    (comp.lang.javascript)
  • Troubleshooting DHTML and Javascript
    ... I display one of several spans when the user mouses over some code. ... Inside the span are several tabs. ... Switch from one span to another and reset the fields. ... when I set a javascript alert to display what the old visible ...
    (comp.lang.javascript)