View previous topic :: View next topic |
Author |
Message |
Tmor n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 10 Mar 2005 Posts: 30
|
Posted: Thu Aug 18, 2005 2:34 pm Post subject: Port Mirroring on a Cisco 2900 HELP... |
|
|
Hello,
This is more of a Cisco issue, but I am having problems mirroring my ports on a Cisco 2924 switch.
When I issue the command on my gentoo box:
I get all kinds of switch trash (spanning tree, arp, broadcast), but no normal tcp traffic. The output of TCPDUMP is (very abbreviated):
Quote: | [timestamp]802.1d config 8000.00:....
[timestamp]arp who-has ....
[timestamp]CDPv2, ttl....
|
so on the switch itself I have configured the Fa0/24 port to:
Code: | port monitor FastEthernet 0/2 |
It appears that the port monitor isnt working at all.
Anyone have any ideas?
Thanks _________________ A day without sunshine is like night... |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
kashani Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
![](images/avatars/9629732313ee51df8c5935.jpg)
Joined: 02 Sep 2002 Posts: 2032 Location: San Francisco
|
Posted: Thu Aug 18, 2005 4:08 pm Post subject: |
|
|
That's the right config. I can't think of any reason it wouldn't work unless you've got a goofy version of IOS. You might want to try to install the Enterprise version, it usually supports extra features. Watchout as moving from a regular release to an en release can be funky. I'd atleast be on site, do it off hours, and backup the config.
I would however double check the logs and make sure that you're plugged into the right ports and whatnot.
kashani _________________ Will personally fix your server in exchange for motorcycle related shop tools in good shape. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Tmor n00b
![n00b n00b](/images/ranks/rank_rect_0.gif)
Joined: 10 Mar 2005 Posts: 30
|
Posted: Thu Aug 18, 2005 6:52 pm Post subject: IOS |
|
|
Upgrading the IOS was my next thought also. System image file is "flash:c2900XL-h2-mz-112.8.1-SA6.bin". I hope that upgrading fixes the problem. I have some 18 snort sensors planned and never thought they wouldnt work on a 2900 switch. I have them on the 2500, 4500, and 6500 series without a problem. _________________ A day without sunshine is like night... |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
kashani Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
![](images/avatars/9629732313ee51df8c5935.jpg)
Joined: 02 Sep 2002 Posts: 2032 Location: San Francisco
|
Posted: Fri Aug 19, 2005 5:35 am Post subject: |
|
|
IIRC there is a 2900-XL-EN and a regualr 2900-XL switch. Trying to put the EN IOS on the regular 2900 is problematic. I friend of mine ran into this when the switch didnt' come back up. I think he had to revert back to the old code. However it looks like you're running the original IOS it shipped with from about 6 years ago if that's the 11 code train and not 12.
kashani _________________ Will personally fix your server in exchange for motorcycle related shop tools in good shape. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|