Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Moitoring 2 switches which span port enabled

Status
Not open for further replies.

banalas

IS-IT--Management
May 23, 2001
22
US
I have to switches 6509 and 5000 both have a span port on them how can i monitor the traffic from both switches , can i do connecting to switches to a switch and connect my monitoring station to that switch, will i be able to do that or is there any different way

Please help

Thanks

 
I would consider looking at spanning on an aggregation point. Do you have these two switches connected together? Do they share a common vlan (ie vlan1) which contains the traffic you're intersted in? You can span 1 or more vlans but could get pretty busy for your network management station. Realize that monitoring the traffic from two large switches such as these could generate a tremendous amount of data. Can you simplify the traffic you're interested in by narrowing down on the application, hosts or specific segments?
 
I have what looks like the same scenario. I'd like to hear from inetworku on how this might work. From my reading, I can mirror several ports to a monitor port on a switch, but I can't see how to monitor several ports on two switches from a single monitor port. I've been considering the obvious- gunthnp's idea of having the IDS sit on both switches.

I have two C2950T-24's connected together by the two gig ports using etherchannel. 12 ports on each switch are on the vlan that I want to watch. The IDS monitor NIC is currently plugged into port 24 on switch 1. I can see this being tricky since all traffic (including 3 other vlans) goes through the etherchannel port. Gunthnp's suggestion is probably the simplest, but I'd like to know if this is possible.
 
you can also try rspan if the feature is available on both switches. you can configure two different monitoring sessions on one switch and one of them can monitor local ports and the other can monitor remote ports. once again the ios/cos images must support it.

search for remote spanning or remote span
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top