Solved

SPAN output and regular traffic on the same switchport?

Posted on 2009-04-08
4
605 Views
Last Modified: 2012-05-06
I have a 3750 series switch that I'm trying to use along with ntop to monitor bandwidth usage by inside host on our network.

The ntop host has 1 NIC and is connected to G1/0/13 on the 3750.  G1/0/13 is an access port on VLAN 1, and I can communicate with the ntop host with no problems before I set up the SPAN session.

Our firewall's inside interface is on VLAN 208, and the 3750 is doing IP routing between our different VLANs, so I set up a SPAN session like this:

monitor session 1 source vlan 208
monitor session 1 destination interface Gi1/0/13 ingress untagged vlan 1

That seems to work as far as getting all of the packets sent to/from our firewall to ntop, however as soon as I set up the monitor session I can no longer ping the ntop host.  I thought the ingress keyword would permit traffic from the ntop host back into the switch and dump it on VLAN 1, but apparently that's not the case.

What do I need to do so I can send the output of the monitor session to the ntop host, AND still be able to communicate with the ntop host?
0
Comment
Question by:FWeston
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24099684
Yeah, that should work.

You can always use a second NIC in the nTop host and plug it into VLAN1 to be used for communication to the host and leave the g1/0/13 NIC as the capture only NIC.
0
 
LVL 3

Author Comment

by:FWeston
ID: 24099711
I thought about that, but the system ntop is running on is a SFF desktop, so I'd have to purchase a special low-profile NIC.  Since this should work, I'd like to figure this out before I spend money on something I shouldn't need.

What should I do to figure out why the above isn't working as I thought it should?
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24107067
Personally I don't like mixing the capture and management traffic as you end up with the management and "normal" host traffic mixed in with your results.

If the SFF desktop has USB, here is a cheap option to add a second NIC:

http://www.newegg.com/Product/Product.aspx?Item=N82E16833124335&nm_mc=OTC-Froogle&cm_mmc=OTC-Froogle-_-Network+-+Interface+Cards-_-Linksys-_-33124335

Otherwise, I'll try to replicate this and see if it works for me.  Standby...
0
 
LVL 3

Accepted Solution

by:
FWeston earned 0 total points
ID: 24107207
I'm not sure what the root issue was, but I was able to achieve what I wanted by changing g1/0/13 to an access port on vlan 208.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Multicast on 3750x cisco router 1 57
Mac-address sticky 12 71
Patch panel 7 58
VTP Setup 4 22
This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question