
24-17
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-09
Chapter 24 Configuring SPAN and RSPAN
Configuring RSPAN
Note
The RSPAN VLAN cannot be VLAN 1 (the default VLAN) or VLAN IDs 1002 through 1005
(reserved to Token Ring and FDDI VLANs).
•
You should create an RSPAN VLAN before configuring an RSPAN source or destination session.
•
If you enable VTP and VTP pruning, RSPAN traffic is pruned in the trunks to prevent the unwanted
flooding of RSPAN traffic across the network for VLAN-IDs that are lower than 1005.
•
Because RSPAN traffic is carried across a network on an RSPAN VLAN, the original VLAN
association of the mirrored packets is lost. Therefore, RSPAN can only support forwarding of traffic
from an IDS device onto a single user-specified VLAN.
Creating an RSPAN Session
First create an RSPAN VLAN that does not exist for the RSPAN session in any of the switches that will
participate in RSPAN. With VTP enabled in the network, you can create the RSPAN VLAN in one
switch, and VTP propagates it to the other switches in the VTP domain for VLAN-IDs that are lower
than 1005. See the
“Creating or Modifying an Ethernet VLAN” section on page 12-8
for more
information about creating an RSPAN VLAN.
Use VTP pruning to get efficient flow of RSPAN traffic, or manually delete the RSPAN VLAN from all
trunks that do not need to carry the RSPAN traffic.
After creating the RSPAN VLAN, begin in privileged EXEC mode, and follow these steps to start an
RSPAN source session and to specify the source (monitored) ports and the destination RSPAN VLAN.
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
no monitor session {session_number | all |
local | remote}
Clear any existing RSPAN configuration for the session.
For session_number, specify 1 or 2.
Specify all to remove all RSPAN sessions, local to remove all local
sessions, or remote to remove all remote SPAN sessions.
Step 3
monitor session session_number source
interface interface-id [, | -] [both | rx | tx]
Specify the RSPAN session and the source port (monitored port).
For session_number, specify 1 or 2.
For interface-id, specify the source port to monitor. Valid interfaces
include physical interfaces and port-channel logical interfaces
(port-channel port-channel-number).
(Optional) [, | -] Specify a series or range of interfaces. Enter a space
before and after the comma; enter a space before and after the
hyphen.
(Optional) Specify the direction of traffic to monitor. If you do not
specify a traffic direction, the source interface sends both sent and
received traffic. Only received (rx) traffic can be monitored on
additional source ports.
•
both—Monitor both received and sent traffic.
•
rx—Monitor received traffic.
•
tx—Monitor sent traffic.