Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Port Mirroring on a Cisco 2900 HELP...
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Tmor
n00b
n00b


Joined: 10 Mar 2005
Posts: 30

PostPosted: Thu Aug 18, 2005 2:34 pm    Post subject: Port Mirroring on a Cisco 2900 HELP... Reply with quote

Hello,

This is more of a Cisco issue, but I am having problems mirroring my ports on a Cisco 2924 switch.

When I issue the command on my gentoo box:

Code:
 tcpdump -n -i eth0

I get all kinds of switch trash (spanning tree, arp, broadcast), but no normal tcp traffic. The output of TCPDUMP is (very abbreviated):

Quote:
[timestamp]802.1d config 8000.00:....
[timestamp]arp who-has ....
[timestamp]CDPv2, ttl....


so on the switch itself I have configured the Fa0/24 port to:

Code:
port monitor FastEthernet 0/2


It appears that the port monitor isnt working at all.

Anyone have any ideas?

Thanks
_________________
A day without sunshine is like night...
Back to top
View user's profile Send private message
kashani
Advocate
Advocate


Joined: 02 Sep 2002
Posts: 2032
Location: San Francisco

PostPosted: Thu Aug 18, 2005 4:08 pm    Post subject: Reply with quote

That's the right config. I can't think of any reason it wouldn't work unless you've got a goofy version of IOS. You might want to try to install the Enterprise version, it usually supports extra features. Watchout as moving from a regular release to an en release can be funky. I'd atleast be on site, do it off hours, and backup the config.

I would however double check the logs and make sure that you're plugged into the right ports and whatnot.

kashani
_________________
Will personally fix your server in exchange for motorcycle related shop tools in good shape.
Back to top
View user's profile Send private message
Tmor
n00b
n00b


Joined: 10 Mar 2005
Posts: 30

PostPosted: Thu Aug 18, 2005 6:52 pm    Post subject: IOS Reply with quote

Upgrading the IOS was my next thought also. System image file is "flash:c2900XL-h2-mz-112.8.1-SA6.bin". I hope that upgrading fixes the problem. I have some 18 snort sensors planned and never thought they wouldnt work on a 2900 switch. I have them on the 2500, 4500, and 6500 series without a problem.
_________________
A day without sunshine is like night...
Back to top
View user's profile Send private message
kashani
Advocate
Advocate


Joined: 02 Sep 2002
Posts: 2032
Location: San Francisco

PostPosted: Fri Aug 19, 2005 5:35 am    Post subject: Reply with quote

IIRC there is a 2900-XL-EN and a regualr 2900-XL switch. Trying to put the EN IOS on the regular 2900 is problematic. I friend of mine ran into this when the switch didnt' come back up. I think he had to revert back to the old code. However it looks like you're running the original IOS it shipped with from about 6 years ago if that's the 11 code train and not 12.

kashani
_________________
Will personally fix your server in exchange for motorcycle related shop tools in good shape.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum