Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Now in this topology I'm not using genus 3 genus 3 and Sysco viral do not currently support spam.
So what I'm using are physical Cisco routers which are connected to 20 950 physical Cisco switches which
in turn are connected to 30 750 Cisco switches I've got a PCI connected to the 30 750 switch and it's
running wire shock and we'll use it to capture traffic from the network.
Now I'm going to demonstrate in a moment that when traffic is sent from Rod a 1 2 rod or 2.
In other words unique cost traffic such as pings or telnet or sent from router 1 to Rod add to the traffic
will be sent to the first 29 50 which in turn will be sent to the first 30 750 which in turn will be
sent to the thirty seven fifty two switch and that will continue until the traffic arrives at about
a 2 thus capturing P.S. will not have visibility of unit cost traffic because when the MAC address table
of switch one is populated it's simply going to switch the traffic from this interface to for example
this interface to forward the traffic it to traffic is only going to be sent out of this interface if
it's sent it to unknown unit cost addresses multicast addresses or broadcast addresses or specifically
sent to this capturing device so the capturing device will have no visibility of traffic sent from road
a one two road a two unless we enable span or port of monitoring on the thirty seven fifty switch.
So firstly demonstrate that traffic sent from Rado want to write it to is not received by the capturing
P.C. and then will configure span on the switch so that the P.C. is able to capture the traffic using
Y shock.
Now in this topology I'm not using genus 3 genus 3 and Cisco viral do not currently support spam.
So what I'm using are physical Cisco routers which are connected to 29 50 physical Cisco switches which
in turn are connected to 30 750 Cisco switches.
I've got a PCI connected to the 30 750 switch and it's running wires shock and we'll use it to capture
traffic from the network.
Now I'm going to demonstrate in a moment that when traffic is sent from Rod a 1 2 rod a 2.
In other words unique cost.
Traffic such as pings or telnet or sent from router 1 to Rod add to the traffic will be sent to the
first 20 50 which in turn will be sent to the first 30 750 which in turn will be sent to the thirty
seven fifty two switch and that will continue until the traffic arrives at right at 2.
Thus capturing P.S. will not have visibility of unit cost traffic because when the MAC address table
of switch one is populated it's simply going to switch the traffic from this interface to for example
this interface to forward the traffic to it to traffic is only going to be sent out of this interface
if it's sent to unknown unique cost addresses multicast addresses or broadcast addresses or specifically
sent to this capturing device.
So the capturing device will have no visibility of traffic sent from road a 1 2 Road a 2 unless we enable
span or port of monitoring on the thirty seven fifty switch.
So firstly demonstrate that traffic sent from Rado want to write it to is not received by the capturing
P.C. and then will configure span on the switch so that the P.C. is able to capture the traffic using
Y shock as the console of the 37 50 switch show MAC address table some MAC addresses are listed in the
table
what I'll do now is ping from wrote a one to Robert to show IP interface brief Rada one has this IP
address and write it to has this IP address which we can see on the console of right a T so that is
the IP address of Robert A T
A 1 is once again able to ping Robert it 2 so when we look at the MAC address table off switch one previously
we only had those three MAC addresses in the table but now notice we have this MAC address as well as
this MAC address in the table I have configured the MAC address of a one as follows some using a Cisco
vendor code MAC address and to make it simple I've specified the MAC address of root of 1 as follows
On rather it too often something similar so MAC address is the Cisco vendor code zeros and a two so
at this point the first thirty seven fifty switch has learnt about the MAC addresses of right one and
wrote a two to keep things simple I haven't configured any villains all devices on VLAN 1 Let's capture
traffic in why shock on our P.C..
So it's currently receiving some traffic
let's do a ping from route one to write it to once again and I'll filter for ICMP traffic in the output.
Here you can see that the PCI is not receiving any ICMP traffic from router 1 2 out of 2 and in the
same way if reported to pings write a one no ICMP traffic is shown on the capturing.
P.S. but if four out of one pings this window's P.C. which has an IP address of 10 dot wondered one
to triple to
notice we see the ICMP packets.
So why shock is able to capture traffic from 10 1 1 1 going to 10 1 1 2 2 2 so the piece is not able
to capture unique cost traffic st from road 1 to round 2.
What about multicast traffic in this example you can see that the ICMP traffic was received to the multicast
address so wrought a one with IP address tendered wandered wandered one be sending traffic to the multicast
address 239 wandered wandered 1
you can see as an example that the source MAC addresses Route One destination MAC address is 0 1 0 0
5 v which is the multicast MAC address in IP version for as you can see over there what about a broadcast
so ping tendered one that one the 255 and I'll just repeat this once as you can see here broadcast traffic
is being received by the P.C. so in other words unique cos traffic is sent from router 1 to the capturing
device is forwarded out of this port and that's based on the Mac address
shown here as learnt by the 30 750 switch on this P.C.
on have changed.
The MAC address in Windows
2s a bunch of zeros and a one.
So the MAC address is
eleven zeros followed by one.
And that was learnt by the switch on Fost Ethan at 1 0 5 as shown over here so unique cost traffic gets
forwarded to the P.C. multicast traffic gets forwarded to the P.C. and that's because multicast MAC
addresses are not added to the MAC address table in the same way that a unit cost of MAC addresses are
broadcast traffic is also forwarded to the P.C..
So to summarize
I'll restart to the white shock capture unicorns.
Traffic sent from Rhonda want to write it too is not received by the capturing device multicast traffic
is received broadcast traffic is received if we want to capture traffic from right one to write it to
for troubleshooting as an example we would need to enable span on this port or merging to use the other
term so that traffic sent and received on this port or this port or on V land 1.
In this example is forwarded out of this port so that the capturing device can see the traffic as another
example.
If we telnet from right of one to write it two and log in the capturing device does not see the Telnet
traffic so we can't see the session from Radha one to write it too.
And that's because the switch is doing what it's supposed to do.
It's forwarding traffic from this interface to this interface and not sending it out of unnecessary
ports.
So now let's configure span so that the capturing device can see the unit cost to traffic.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.