Solved

Cisco 2960 switch and Websense server

Posted on 2010-09-21
4
921 Views
Last Modified: 2012-05-10
Hi there,
On my cisco 2960 I am monitoring all traffic from port 48 to port 47 by offering the following command.
monitor session 1 source interface Gi0/48
monitor session 1 destination interface Gi0/47
My websense server has 2 NICS, one on port 47 which has no ip and just checks the traffic from port 48.  The other NIC on websense server has an IP 10.10.10.31 which goes into port 6.  Everything works well except when all the users are online then the traffic goes really slow.
Question:
-Is there anything else needed more in commands for monitoring traffic to make them specific for only internet traffic?  How and what is required?
-Should the websense server only check the http traffic on port 47 of switch 2960?  How
Help plz.
0
Comment
Question by:amanzoor
  • 2
4 Comments
 
LVL 3

Accepted Solution

by:
blaslett earned 250 total points
Comment Utility
WireShark is a free software tool that will do this for you. I have used it on many occasions with great success.

It allows you to set protocol fiters such as HTTP, FTP, whatever you want.

You can download it at :

http://www.wireshark.org/download.html

0
 
LVL 34

Assisted Solution

by:Istvan Kalmar
Istvan Kalmar earned 250 total points
Comment Utility
HI,

I advise to mirror only the firewall internal leg, if you do it you only see the intenetnet traffic!
0
 
LVL 4

Author Comment

by:amanzoor
Comment Utility
ikalmar:
Please let me know how to do that in steps.  What commands to put in?
Help plz
Thanks
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
Comment Utility
Should be:

monitor session 1 source interface fa0/1  <--the interface you want to capture traffic on
monitor session 1 destination interface fa0/2  <--the interface you want to send the captured traffic to
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now