66-6
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 66 Configuring SPAN and RSPAN
About SPAN and RSPAN
•
VSPAN monitors only traffic that enters the switch, not traffic that is routed between VLANs. For
example, if a VLAN is being Rx-monitored, and the multilayer switch routes traffic from another
VLAN to the monitored VLAN, that traffic is not monitored and is not received on the SPAN
destination port.
•
You cannot use filter VLANs in the same session with VLAN sources.
•
You can monitor only Ethernet VLANs.
SPAN Traffic
You can use local SPAN to monitor all network traffic, including multicast and bridge protocol data unit
(BPDU) packets, Cisco Discovery Protocol (CDP), VLAN Trunk Protocol (VTP), Dynamic Trunking
Protocol (DTP), Spanning Tree Protocol (STP), and Port Aggregation Protocol (PAgP) packets. You
cannot use RSPAN to monitor Layer 2 protocols. See the
“RSPAN Configuration Guidelines” section on
for more information.)
In some SPAN configurations, multiple copies of the same source packet are sent to the SPAN
destination port. For example, a bidirectional (both Rx and Tx) SPAN session is configured for the
sources a1 Rx monitor and the a2 Rx and Tx monitor to destination port d1. If a packet enters the switch
through a1 and is switched to a2, both incoming and outgoing packets are sent to destination port d1.
Both packets are the same (unless a Layer-3 rewrite occurs, in which case the packets are different
because of the added Layer 3 information).
SPAN and RSPAN Session Limits
You can configure a maximum of sixteen SPAN/RSPAN sessions (eight concurrent sessions with
ingress-only sources and eight concurrent sessions with egress-only sources). Bidirectional sources
count as both ingress and egress. RSPAN destination sessions count as a session containing an ingress
source.
Default SPAN and RSPAN Configuration
shows the default SPAN and RSPAN configuration.
Table 66-1
Default SPAN and RSPAN Configuration
Feature
Default Setting
SPAN state
Disabled.
Source port traffic to monitor
Both received and sent traffic (
both
).
Filters
All VLANs, all packet types, all address types.
Encapsulation type (destination port)
Native form (no encapsulation type header).
Ingress forwarding (destination port)
Disabled.
Host learning (destination port)
Disabled.
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...