SPAN output and regular traffic on the same switchport?
Posted on 2009-04-08
I have a 3750 series switch that I'm trying to use along with ntop to monitor bandwidth usage by inside host on our network.
The ntop host has 1 NIC and is connected to G1/0/13 on the 3750. G1/0/13 is an access port on VLAN 1, and I can communicate with the ntop host with no problems before I set up the SPAN session.
Our firewall's inside interface is on VLAN 208, and the 3750 is doing IP routing between our different VLANs, so I set up a SPAN session like this:
monitor session 1 source vlan 208
monitor session 1 destination interface Gi1/0/13 ingress untagged vlan 1
That seems to work as far as getting all of the packets sent to/from our firewall to ntop, however as soon as I set up the monitor session I can no longer ping the ntop host. I thought the ingress keyword would permit traffic from the ntop host back into the switch and dump it on VLAN 1, but apparently that's not the case.
What do I need to do so I can send the output of the monitor session to the ntop host, AND still be able to communicate with the ntop host?