
24-2
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-09
Chapter 24 Configuring SPAN and RSPAN
Understanding SPAN and RSPAN
Figure 24-1 Example SPAN Configuration
Only traffic that enters or leaves source ports or traffic that enters source VLANs can be monitored by
using SPAN; traffic that gets routed to ingress source ports or source VLANs cannot be monitored. For
example, if incoming traffic is being monitored, traffic that gets routed from another VLAN to the source
VLAN is not monitored; however, traffic that is received on the source VLAN and routed to another
VLAN is monitored.
RSPAN extends SPAN by enabling remote monitoring of multiple switches across your network. The
traffic for each RSPAN session is carried over a user-specified RSPAN VLAN that is dedicated for that
RSPAN session in all participating switches. The SPAN traffic from the sources is copied onto the
RSPAN VLAN through a reflector port and then forwarded over trunk ports that are carrying the RSPAN
VLAN to any RSPAN destination sessions monitoring the RSPAN VLAN, as shown in
Figure 24-2 Example of RSPAN Configuration
SPAN and RSPAN do not affect the switching of network traffic on source ports or source VLANs; a
copy of the packets received or sent by the source interfaces are sent to the destination interface.
You can use the SPAN or RSPAN destination port to inject traffic from a network security device. For
example, if you connect a Cisco Intrusion Detection System (IDS) Sensor Appliance to a destination
port, the IDS device can send TCP Reset packets to close down the TCP session of a suspected attacker.
1 2 3 4 5 6 7 8 9 10 11 12
Port 5 traffic mirrored
on Port 10
3
2
1
4
5
6
7
8
9
11
12
10
Network analyzer
43580
Source switch
Intermediate switch
Destination switch
74727
RSPAN
source port
RSPAN
destination port
Reflector
port
RSPAN
VLAN
RSPAN
VLAN