Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
So now on 37 51 the switch that the monitoring station is connected to confetti monitor session.
We want to configure a spend session so we use the session command on do the switch 66 span sessions
could be configured if we wanted to configure span on the twenty nine fifty switch it doesn't support
the same number of sessions on the switch it only supports two sessions the number of active span sessions
however is switch dependent.
Have a look at the documentation of the switch here we'll simply configure session one to keep it simple
we need to specify a source as well as a destination of the span session so the source in our example
will be the LAN one and I want to capture traffic both sent and received in VLAN 1 you need to be careful
spanning a v lan if a lot of traffic is transmitted and received on that VLAN you could oversubscribed
the port as an example of the switch had 24 ports and you spanned all of those ports to this single
interface you would possibly overwhelm this physical interface as another example you don't want to
span a gigabit port to 100 make port and in the same way you need to make sure that your capturing device
can handle the traffic that it's receiving you don't want to as an example forward one gigabits per
second of traffic to P.C. with a slow CPSU that can't capture or handle the amount of traffic that you
throwing at it as an analogy we as people may drink water from a gloss or from a tap but generally not
from a fire hydrant because the rate of water that's sent out of a fire hydrant is far more than you
can drink so don't overload or overwhelm the port as well as the P.C. by sending too much spam traffic
out of this port so now monitor session we need to specify the same session no and we're going to specify
a destination in this case it's going to be a local interface on the switch fast ethernet 1 0 5 I'll
talk about the encapsulation and ingress options in a moment.
For now we're just going to forward the traffic out of the port so do show run pipe include monitor
we configured this command as well as this command on the switch show monitor
we can see that we have one active session it's a local session it's looking at traffic sent and received
on VLAN 1 that's the source destination is Port Fost Ethan at 1 0 5 we're using the native a villain
as the encapsulation ingress traffic is disabled so now on the capturing P.S. we'll filter for ICMP
and let's restart that capture
and en route a one all ping routed to and notice we can see the traffic which we weren't able to see
before.
Here is a source ICMP packet from router 1 Notice the MAC address ending in 0 1.
Going to write it to it's a unit cost here the IP addresses a 10 1 1 1 going to 10 1 1 2 it's an echo
request.
Here's the reply It's also a unique cost frame from Rod a 2 to write a 1 unit cost IP addresses it's
a ping reply now if write a 1 Telnet to write a 2 and logs in we should be able to see that telnet traffic
on the capturing device and we can so notice as an example he has some telnet information I'll scroll
down the road is asking for a password he has the password C I S CEO We could also follow the DCP stream
and we'll be able to see the password in this example because we are capturing traffic sent and received
on the V Line.
We're getting some duplicates but as an example if on top enable password show run and look at the running
config of that router if I fall to 4 telnet traffic again we'll be able to see the line Viti Y and the
password is shown on the line Viti y in the running config of the Rada.
So that's the conflict on the router and here it's seen in the wash out capture.
I could once again follow the TCB stream and I'll see the full configuration of the rudder as captured
on the monitoring station.
So what's happening now is when traffic is received or sent on VLAN 1 it's been forwarded out of this
port and the capturing device running why shark is able to view the traffic.
So what we did is create a monitoring session monitor session 1 capturing on VLAN 1 and the destination
as fast Ethernet.
1 05 if we remove the monitoring session so do show run pipe include monitor we can see that there's
no output in other words the monitoring session has been removed.
Now when we do the capture
and we for instance filter for ICMP traffic and paying a T from Route 1 we don't see any output.
So no ICMP traffic is shown if we fall to 4 telnet
and then Telnet to 10 1 1 2.
We don't see anything but if we put to the monitoring session back so monitor session choose a number
one.
And in this case all monitor and interface if one 0 3 which is this interface over here and we'll do
both and then we'll specify a destination of first Ethan at 1 0 5 what we should see now is once that
kicks in as you can see over there we are able to see the Telnet information so there's the prompt of
wrote it to and if I scroll up we can see the password.
So the right is asking for a enabled password and he has the password that I typed which Cisco and then
I pressed into once again if we follow that stream you can see the password that was typed so it's as
simple as that to create a monitoring session to show.
Monitor in this example we've got session one which was a local session capturing traffic in and out
of this port and it's going to this destination port 1 0 5 encapsulation is native English traffic is
disabled.
So let's talk about ingress traffic when you enable span on a switch as we've got over here the switch
no longer learns mac addresses on the span destination port it also doesn't allow traffic to be received
from that port.
So if road A one pings write a t it works
and the MAC addresses are shown in the MAC address table but rather one is not able to ping the capturing
device.
So filtering for ICMP the pings are being received from Radio a 1 to the P.C. but no replies are being
accepted by the switch.
So in other words the ping from rudder one to the capturing device is received on this port and because
of the port mirroring or span the traffic is being sent out of this port and is received by the capturing
device.
But when the capturing device replies that traffic is not accepted on the destination spend port.
So the pings are failing
so once again notice there were no successes on the ping from of one to the capturing device.
And just to confirm that is the IP address of the capturing device if we want to allow that device to
send traffic we have to configure the monitoring session to receive that traffic.
So destination interface is fast ethernet 1 0 5
and we have to add this option ingress to enable ingress traffic forwarding
and to specify that is on tagged traffic in VLAN 1.
So I'll start the capture again
and let's see if Rada one is able to ping that capturing station notice the pings succeed here's the
ping from Route One to the capturing device here's the reply and the pings succeeded.
So just to prove that again I'll do a repeat of just one
play the one shall capture one ping.
There's the ping sent from Rada one he has the reply we've seen duplicates because we are looking at
traffic sent and received on this port.
So we are receiving duplicates because we are sending traffic to the monitoring station that's received
or transmitted on this port.
So we get some duplicates but they point to remember is that if we don't use the ingress command the
monitoring station is not able to participate in the network.
Essentially the Mac address is removed from the Mac address table so the Mac addresses is not learnt
as you can see over here.
Traffic is not allowed to be received on this interface but with the ingress option it can be received
and the device is allowed to participate in the network.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.