Solved

Cisco 2960 switch and Websense server

Posted on 2010-09-21
4
929 Views
Last Modified: 2012-05-10
Hi there,
On my cisco 2960 I am monitoring all traffic from port 48 to port 47 by offering the following command.
monitor session 1 source interface Gi0/48
monitor session 1 destination interface Gi0/47
My websense server has 2 NICS, one on port 47 which has no ip and just checks the traffic from port 48.  The other NIC on websense server has an IP 10.10.10.31 which goes into port 6.  Everything works well except when all the users are online then the traffic goes really slow.
Question:
-Is there anything else needed more in commands for monitoring traffic to make them specific for only internet traffic?  How and what is required?
-Should the websense server only check the http traffic on port 47 of switch 2960?  How
Help plz.
0
Comment
Question by:amanzoor
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 3

Accepted Solution

by:
blaslett earned 250 total points
ID: 33731028
WireShark is a free software tool that will do this for you. I have used it on many occasions with great success.

It allows you to set protocol fiters such as HTTP, FTP, whatever you want.

You can download it at :

http://www.wireshark.org/download.html

0
 
LVL 34

Assisted Solution

by:Istvan Kalmar
Istvan Kalmar earned 250 total points
ID: 33731892
HI,

I advise to mirror only the firewall internal leg, if you do it you only see the intenetnet traffic!
0
 
LVL 4

Author Comment

by:amanzoor
ID: 33734762
ikalmar:
Please let me know how to do that in steps.  What commands to put in?
Help plz
Thanks
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 33871496
Should be:

monitor session 1 source interface fa0/1  <--the interface you want to capture traffic on
monitor session 1 destination interface fa0/2  <--the interface you want to send the captured traffic to
0

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month6 days, 13 hours left to enroll

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question