![background image](http://html.mh-extra.com/html/cisco/catalyst-2960-series/catalyst-2960-series_configuration-manual_66776561.webp)
•
A packet might be forwarded normally but dropped from monitoring due to an oversubscribed SPAN
destination port.
•
An ingress packet might be dropped from normal forwarding, but still appear on the SPAN destination
port.
•
An egress packet dropped because of switch congestion is also dropped from egress SPAN.
In some SPAN configurations, multiple copies of the same source packet are sent to the SPAN destination
port. For example, a bidirectional (both Rx and Tx) SPAN session is configured for the Rx monitor on port
A and Tx monitor on port B. If a packet enters the switch through port A and is switched to port B, both
incoming and outgoing packets are sent to the destination port. Both packets are the same unless a Layer 3
rewrite occurs, in which case the packets are different because of the packet modification.
Source Ports
A source port (also called a monitored port) is a switched or routed port that you monitor for network traffic
analysis. In a local SPAN session or RSPAN source session, you can monitor source ports or VLANs for
traffic in one or both directions. The switch supports any number of source ports (up to the maximum number
of available ports on the switch) and any number of source VLANs (up to the maximum number of VLANs
supported). However, the switch supports a maximum of four sessions (two sessions if switch is in a stack
with Catalyst 2960-S switches) (local or RSPAN) with source ports or VLANs. You cannot mix ports and
VLANs in a single session.
A source port has these characteristics:
•
It can be monitored in multiple SPAN sessions.
•
Each source port can be configured with a direction (ingress, egress, or both) to monitor.
•
It can be any port type (for example, EtherChannel, Gigabit Ethernet, and so forth).
•
For EtherChannel sources, you can monitor traffic for the entire EtherChannel or individually on a
physical port as it participates in the port channel.
•
It can be an access port, trunk port, routed port, or voice VLAN port.
•
It cannot be a destination port.
•
Source ports can be in the same or different VLANs.
•
You can monitor multiple source ports in a single session.
Source VLANs
VLAN-based SPAN (VSPAN) is the monitoring of the network traffic in one or more VLANs. The SPAN
or RSPAN source interface in VSPAN is a VLAN ID, and traffic is monitored on all the ports for that VLAN.
VSPAN has these characteristics:
•
All active ports in the source VLAN are included as source ports and can be monitored in either or both
directions.
•
On a given port, only traffic on the monitored VLAN is sent to the destination port.
•
If a destination port belongs to a source VLAN, it is excluded from the source list and is not monitored.
•
If ports are added to or removed from the source VLANs, the traffic on the source VLAN received by
those ports is added to or removed from the sources being monitored.
•
You cannot use filter VLANs in the same session with VLAN sources.
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
479
Information About SPAN and RSPAN
Summary of Contents for Catalyst 2960 Series
Page 96: ......
Page 196: ......
Page 250: ......
Page 292: ......
Page 488: ......
Page 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Page 590: ......
Page 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Page 620: ......
Page 750: ......
Page 1604: ......
Page 1740: ......
Page 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Page 2106: ......
Page 2118: ......
Page 2164: ......