span and stacking switch and MSFC

From: Chiara Sambi (Sambi@ictc.it)
Date: 11/29/02

  • Next message: Bob Walder: "Gigabit IDs report"
    From: Chiara Sambi <Sambi@ictc.it>
    To: "'FOCUS-IDS@SECURITYFOCUS.COM'" <FOCUS-IDS@SECURITYFOCUS.COM>
    Date: Fri, 29 Nov 2002 15:06:45 +0100
    
    

    I have 2 switch Cisco 3548 in stack and i need to analyze the traffic that
    they sent to and receive from a management VLAN of an IDC that is I need to
    monitor a port as SPAN port, to put an IDS sensor. I wonder if i can put
    only one SPAN port to analyze ALL the traffic passing through the 2 switches
    or i need 2 SPAN ports, one for each switch. And what about RSPAN?

    And moreover I have read that on the switch Catalyst 6000 it is possible to
    use port 15/1 (or 16/1) as a SPAN source that will allow it to monitor
    traffic forwarded to the Multilayer Switch Feature Card (MSFC). So I'd like
    to know if i can use this port as source SPAN port for 2 different SPAN
    sessions, one for traffic TO the MSFC and one for the traffic FROM the MSFC,
    with 2 different SPAN destination ports. Is this a promiscuos port?

    All what u can tell me will be appreciated

    -----------------------------------
    Dott.sa Chiara Sambi
    Consultant

    ICT consulting
    20140 Milano
    via Vittor Pisani 22
    tel: +39 02 67642249
    fax: +39 02 67642243
    e-mail: sambi@ictc.it



    Relevant Pages

    • RE: Hub vs. Tap vs. SpanPort
      ... > SpanPort cause a lot of broadcast messages and reduce network performance. ... SPAN port itself? ... How does a span port interrupt the network? ... I tell the switch to send ...
      (Focus-IDS)
    • Re: SPAN Port Question
      ... > I'm trying to add a second sensor to a separate VLAN on a CISCO 5500 switch. ... > The network boyz tell me there can be only one SPAN port per switch. ...
      (Focus-IDS)
    • Re: Cat 2924
      ... Copyright 1986-2004 by cisco Systems, ... BOX in both H/W and S/W, compared to a C2924-XL Switch... ... FastEthernet0/1 failed front-end loopback test ... to make the port configuration "visible", you need to apply 2 commands ...
      (comp.dcom.sys.cisco)
    • Re: Cat 2924
      ... Copyright 1986-2004 by cisco Systems, ... BOX in both H/W and S/W, compared to a C2924-XL Switch... ... FastEthernet0/1 failed front-end loopback test ... to make the port configuration "visible", you need to apply 2 commands ...
      (comp.dcom.sys.cisco)
    • Gigabit Flexibility with Magnum 6K32T Managed Switch from GarrettCom, Inc.
      ... THROUGHPUT WITH MAGNUM 6K32T MANAGED SWITCH ... Gigabit port capability to four Gb ports when compared to the ...
      (comp.dcom.lans.ethernet)

  • Quantcast