From: Derek Pocoroba (dpocoroba@gmail.com)
Date: Thu May 29 2008 - 23:18:06 ART
Robert,
That setup should work fine. its a straightforward SPAN config. Also the
traffic should show up on SW4 with "term mon" and "deb ip pack" or "deb ip
pack det". Make sure SW4 has ip routing enabled on it.
HTH
On Thu, May 15, 2008 at 7:55 AM, Robert Smith <thecure007@gmail.com> wrote:
> Hi Alexei,
>
> I borrowed some switches which I am accessing remotely and there is where I
> am doing my switching labs. However I don't have access to a PC there, only
> to the switches.
>
> So in order to lab a SPAN scenario, I use two switches as hosts (sw1 and
> sw4) and one more switch to act actually as a switch doing span (sw3).
>
> I want to accomplish this:
> Sw1, sends a ping to a vlan interface on sw3. Sw3 with a monitor session
> takes that packet from the vlan and sends a copy to interface fa0/20.
>
>
> SW1(fa0/16)--------------------------(fa0/13)SW3(fa0/20)------------------(fa0/20)SW4
> (acts as a sending pc) (acts as a real switch)
> (acts
> as a destination pc)
>
> So I was wondering how to verify that SPAN is working with some kind of
> debug on the switch that is acting as the destination PC for the SPAN
> scenario.
>
> Do I really need a real pc with a sniffer installed connected to the span
> destination port to actually verify that the switch is sending copies of
> the
> original packets out its fa0/20?
>
> I am still unable to prove it with a switch with a no switchport interface
> connected to an access port acting as a destination span port.
>
> Thanks for your help,
>
>
>
>
>
>
> On Thu, May 15, 2008 at 4:18 AM, Alexei Monastyrnyi <
> alexeim@orcsoftware.com>
> wrote:
>
> > Robert,
> > sorry, I didn't get it from your first mail.
> >
> > What are you trying to achieve? Do you want to verify SPAN and build a
> > scenario around it? Or do you have this particular scenario with SPAN and
> > need to verify it?
> >
> > A.
> >
> > Robert Smith said the following on 5/14/2008 7:10 PM:
> >
> >> Hi Experts,
> >>
> >> I am trying to verify that the following scenario is working:
> >>
> >> SW1(fa0/16)------(fa0/13)SW3(fa0/20)----(fa0/20)SW4
> >>
> >> SW1:
> >> interface FastEthernet0/16
> >> no switchport
> >> ip address 21.21.21.1 255.255.255.0
> >> end
> >>
> >> SW4:
> >> interface FastEthernet0/20
> >> no switchport
> >> ip address 23.23.23.4 255.255.255.0
> >> end
> >>
> >> SW3:
> >> interface FastEthernet0/13
> >> switchport access vlan 21
> >> switchport mode access
> >> switchport nonegotiate
> >> end
> >> !
> >> interface FastEthernet0/20
> >> switchport access vlan 23
> >> switchport mode access
> >> switchport nonegotiate
> >> end
> >> !
> >> int vlan 21
> >> ip address 21.21.21.3 255.255.255.0
> >> !
> >> monitor session 2 source interface Fa0/13
> >> monitor session 2 destination interface Fa0/20
> >>
> >> So what I am trying to accomplish is... when sw1 pings sw3 int vlan21,
> sw3
> >> sends a copy of this traffic to sw4 on its fa0/20 port. However when I
> >> turn
> >> debug monitor all on sw3 and debug ip packet detail on sw4 on, I don't
> get
> >> any output. The ping in sw1 shows as successful.
> >>
> >> Is my verification method wrong? Am I missing something?
> >>
> >> Thanks in advance,
> >>
> >>
> >> _______________________________________________________________________
> >> Subscription information may be found at:
> >> http://www.groupstudy.com/list/CCIELab.html
>
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
>
>
>
>
>
-- Derek Pocoroba CCIE #18559
This archive was generated by hypermail 2.1.4 : Mon Jun 02 2008 - 06:59:18 ART