Vlan-Based Span - Cisco Catalyst 3550 series Software Configuration Manual

Multilayer switch
Hide thumbs Also See for Catalyst 3550 series:
Table of Contents

Advertisement

Understanding SPAN and RSPAN
If the bandwidth of the reflector port is not sufficient for the traffic volume from the corresponding
source ports and VLANs, the excess packets are dropped. A 10/100 port reflects at 100 Mbps. A Gigabit
port reflects at 1 Gbps.

VLAN-Based SPAN

VLAN-based SPAN (VSPAN) is the monitoring of the network traffic in one or more VLANs. You can
configure VSPAN to monitor only received (Rx) traffic, which applies to all the ports for that VLAN.
Use these guidelines for VSPAN sessions:
SPAN Traffic
You can use local SPAN to monitor all network traffic, including multicast and bridge protocol data unit
(BPDU) packets, and Cisco Discovery Protocol (CDP), VLAN Trunk Protocol (VTP), Dynamic
Trunking Protocol (DTP), Spanning Tree Protocol (STP), Port Aggregation Protocol (PagP), and Link
Aggregation Control Protocol (LACP) packets. You cannot use RSPAN to monitor Layer 2 protocols.
See the
In some SPAN configurations, multiple copies of the same source packet are sent to the SPAN
destination port. For example, a bidirectional (both Rx and Tx) SPAN session is configured for the
sources a1 Rx monitor and the a2 Rx and Tx monitor to destination port d1. If a packet enters the switch
through a1 and is switched to a2, both incoming and outgoing packets are sent to destination port d1.
Both packets are the same (unless a Layer 3 rewrite occurs, in which case the packets are different
because of the added Layer 3 information).
Catalyst 3550 Multilayer Switch Software Configuration Guide
24-6
Only traffic on the monitored VLAN is sent to the destination port.
If a destination port belongs to a source VLAN, it is excluded from the source list and is not
monitored.
If ports are added to or removed from the source VLANs, the traffic on the source VLAN received
by those ports is added to or removed from the sources being monitored.
VLAN pruning and the VLAN allowed list have no effect on SPAN monitoring.
VSPAN only monitors traffic that enters the switch, not traffic that is routed between VLANs. For
example, if a VLAN is being Rx-monitored and the multilayer switch routes traffic from another
VLAN to the monitored VLAN, that traffic is not monitored and is not received on the SPAN
destination port.
You cannot use filter VLANs in the same session with VLAN sources.
You can monitor only Ethernet VLANs.
"RSPAN Configuration Guidelines" section on page 24-16
Chapter 24
Configuring SPAN and RSPAN
for more information.
78-11194-09

Advertisement

Table of Contents
loading

Table of Contents