Solved

how to configure port mirroring on a cisco 2950

Posted on 2006-10-26
7
904 Views
Last Modified: 2011-10-03
Hello,

I am evaluating surfcontrol software on a windows 2003 server with sp1. The server is a member server and has 2 nics. 1 for blocking and the other for destination. In order for surfcontrol to work I configured 2 ports on a cisco 2950 switch for port mirroring. Surfcontrol does not work. So i am going back to the company today and calling surfcontrol tech support. I want to make sure that i`ve configured the switch well.
This is how i configured it:

config t
monitor session 1 source interface fastethernet 0/24
monitor session 1 destination interface fastethernet 0/23
show monitor session 1
Source Ports:
    RX Only:       None
        TX Only:       None
        Both:          Fa0/24
Destination Ports: Fa0/23

copy runn start
 Are my configs ok?

Many thanks,
Tacobell2000


0
Comment
Question by:Tacobell2000
  • 4
  • 3
7 Comments
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17812069
Yeah, that looks correct.

Just make sure that fa0/24 is the port that goes out to your firewall if you have one and 0/23 is the port connected to your machine.

Cheers,
Rajesh
0
 

Author Comment

by:Tacobell2000
ID: 17812331
fa 0/24 is the source port and that is connected to 1 of the nics on the surfcontrol server. fa 0/23 is connected to the 2nd nic on the surfcontrol server. The firewall is connected to fa 0/16 on the same switch.
Am i doing this correctly,

Tacobell2000
0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 500 total points
ID: 17813199
No, the idea is to make the packets reach the surfcontrol server and have it processed. So all the outgoing packets will be going to the firewall which is fa0/16.

So you need to mirror all the traffic from fa0/16 to 0/23

By the way this will enable you to monitor the traffic but not really control it. You'll get a feel of how it works. If you want it to be doing its job, you need to make the traffic pass through the surfcontrol server or have your firewall configured for web filtering and point the web filter server's address in the firewall. This way the firewall will first consult with the surfcontrol server before it allows any http traffic. What kinda firewall ?

Cheers,
Rajesh
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:Tacobell2000
ID: 17813501
It is a a 2600 cisco router.
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17813567
That doesn't support what we are looking for, so you'll have to route it through the surfcontrol server itself. Just configure the span as I mentioned and call the support person.

Cheers,
Rajesh.
0
 

Author Comment

by:Tacobell2000
ID: 17813625
Thank you very much!
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17813650
Thanks.

Cheers,
Rajesh
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

What’s a web proxy server? A proxy server is a server that goes between clients and web servers, used in corporate to enforce corporate browsing policy and ensure security. Proxy servers are commonly used in three modes. A)    Forward proxy …
If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now