?
Solved

Cisco 2960 switch and Websense server

Posted on 2010-09-21
4
Medium Priority
?
938 Views
Last Modified: 2012-05-10
Hi there,
On my cisco 2960 I am monitoring all traffic from port 48 to port 47 by offering the following command.
monitor session 1 source interface Gi0/48
monitor session 1 destination interface Gi0/47
My websense server has 2 NICS, one on port 47 which has no ip and just checks the traffic from port 48.  The other NIC on websense server has an IP 10.10.10.31 which goes into port 6.  Everything works well except when all the users are online then the traffic goes really slow.
Question:
-Is there anything else needed more in commands for monitoring traffic to make them specific for only internet traffic?  How and what is required?
-Should the websense server only check the http traffic on port 47 of switch 2960?  How
Help plz.
0
Comment
Question by:amanzoor
  • 2
4 Comments
 
LVL 3

Accepted Solution

by:
blaslett earned 1000 total points
ID: 33731028
WireShark is a free software tool that will do this for you. I have used it on many occasions with great success.

It allows you to set protocol fiters such as HTTP, FTP, whatever you want.

You can download it at :

http://www.wireshark.org/download.html

0
 
LVL 34

Assisted Solution

by:Istvan Kalmar
Istvan Kalmar earned 1000 total points
ID: 33731892
HI,

I advise to mirror only the firewall internal leg, if you do it you only see the intenetnet traffic!
0
 
LVL 5

Author Comment

by:amanzoor
ID: 33734762
ikalmar:
Please let me know how to do that in steps.  What commands to put in?
Help plz
Thanks
0
 
LVL 34

Expert Comment

by:Istvan Kalmar
ID: 33871496
Should be:

monitor session 1 source interface fa0/1  <--the interface you want to capture traffic on
monitor session 1 destination interface fa0/2  <--the interface you want to send the captured traffic to
0

Featured Post

Take Control of Web Hosting For Your Clients

As a web developer or IT admin, successfully managing multiple client accounts can be challenging. In this webinar we will look at the tools provided by Media Temple and Plesk to make managing your clients’ hosting easier.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

588 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question