Solved

SPAN output and regular traffic on the same switchport?

Posted on 2009-04-08
4
602 Views
Last Modified: 2012-05-06
I have a 3750 series switch that I'm trying to use along with ntop to monitor bandwidth usage by inside host on our network.

The ntop host has 1 NIC and is connected to G1/0/13 on the 3750.  G1/0/13 is an access port on VLAN 1, and I can communicate with the ntop host with no problems before I set up the SPAN session.

Our firewall's inside interface is on VLAN 208, and the 3750 is doing IP routing between our different VLANs, so I set up a SPAN session like this:

monitor session 1 source vlan 208
monitor session 1 destination interface Gi1/0/13 ingress untagged vlan 1

That seems to work as far as getting all of the packets sent to/from our firewall to ntop, however as soon as I set up the monitor session I can no longer ping the ntop host.  I thought the ingress keyword would permit traffic from the ntop host back into the switch and dump it on VLAN 1, but apparently that's not the case.

What do I need to do so I can send the output of the monitor session to the ntop host, AND still be able to communicate with the ntop host?
0
Comment
Question by:FWeston
  • 2
  • 2
4 Comments
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24099684
Yeah, that should work.

You can always use a second NIC in the nTop host and plug it into VLAN1 to be used for communication to the host and leave the g1/0/13 NIC as the capture only NIC.
0
 
LVL 3

Author Comment

by:FWeston
ID: 24099711
I thought about that, but the system ntop is running on is a SFF desktop, so I'd have to purchase a special low-profile NIC.  Since this should work, I'd like to figure this out before I spend money on something I shouldn't need.

What should I do to figure out why the above isn't working as I thought it should?
0
 
LVL 43

Expert Comment

by:JFrederick29
ID: 24107067
Personally I don't like mixing the capture and management traffic as you end up with the management and "normal" host traffic mixed in with your results.

If the SFF desktop has USB, here is a cheap option to add a second NIC:

http://www.newegg.com/Product/Product.aspx?Item=N82E16833124335&nm_mc=OTC-Froogle&cm_mmc=OTC-Froogle-_-Network+-+Interface+Cards-_-Linksys-_-33124335

Otherwise, I'll try to replicate this and see if it works for me.  Standby...
0
 
LVL 3

Accepted Solution

by:
FWeston earned 0 total points
ID: 24107207
I'm not sure what the root issue was, but I was able to achieve what I wanted by changing g1/0/13 to an access port on vlan 208.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The worst thing when starting a new job is when the previous Network Administrator left behind no documentation. How do you get into the devices? If you've been in this situation or just accidently mistyped your password, this article will hopefully…
This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now