Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

how to configure port mirroring on a cisco 2950

Posted on 2006-10-26
7
Medium Priority
?
951 Views
Last Modified: 2011-10-03
Hello,

I am evaluating surfcontrol software on a windows 2003 server with sp1. The server is a member server and has 2 nics. 1 for blocking and the other for destination. In order for surfcontrol to work I configured 2 ports on a cisco 2950 switch for port mirroring. Surfcontrol does not work. So i am going back to the company today and calling surfcontrol tech support. I want to make sure that i`ve configured the switch well.
This is how i configured it:

config t
monitor session 1 source interface fastethernet 0/24
monitor session 1 destination interface fastethernet 0/23
show monitor session 1
Source Ports:
    RX Only:       None
        TX Only:       None
        Both:          Fa0/24
Destination Ports: Fa0/23

copy runn start
 Are my configs ok?

Many thanks,
Tacobell2000


0
Comment
Question by:Tacobell2000
  • 4
  • 3
7 Comments
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17812069
Yeah, that looks correct.

Just make sure that fa0/24 is the port that goes out to your firewall if you have one and 0/23 is the port connected to your machine.

Cheers,
Rajesh
0
 

Author Comment

by:Tacobell2000
ID: 17812331
fa 0/24 is the source port and that is connected to 1 of the nics on the surfcontrol server. fa 0/23 is connected to the 2nd nic on the surfcontrol server. The firewall is connected to fa 0/16 on the same switch.
Am i doing this correctly,

Tacobell2000
0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 2000 total points
ID: 17813199
No, the idea is to make the packets reach the surfcontrol server and have it processed. So all the outgoing packets will be going to the firewall which is fa0/16.

So you need to mirror all the traffic from fa0/16 to 0/23

By the way this will enable you to monitor the traffic but not really control it. You'll get a feel of how it works. If you want it to be doing its job, you need to make the traffic pass through the surfcontrol server or have your firewall configured for web filtering and point the web filter server's address in the firewall. This way the firewall will first consult with the surfcontrol server before it allows any http traffic. What kinda firewall ?

Cheers,
Rajesh
0
Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

 

Author Comment

by:Tacobell2000
ID: 17813501
It is a a 2600 cisco router.
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17813567
That doesn't support what we are looking for, so you'll have to route it through the surfcontrol server itself. Just configure the span as I mentioned and call the support person.

Cheers,
Rajesh.
0
 

Author Comment

by:Tacobell2000
ID: 17813625
Thank you very much!
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17813650
Thanks.

Cheers,
Rajesh
0

Featured Post

Who's Defending Your Organization from Threats?

Protecting against advanced threats requires an IT dream team – a well-oiled machine of people and solutions working together to defend your organization. Download our resource kit today to learn more about the tools you need to build you IT Dream Team!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A 2007 NCSA Cyber Security survey revealed that a mere 4% of the population has a full understanding of firewalls. As business owner, you should be part of that 4% that has a full understanding.
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

581 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question