Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
So that was an example of basic span.
There are multiple options when you can figure span.
So let's remove our current session and then specify monitor session.
Let's create a new one of one source port is going to be interface fast Ethernet to 1 0 3.
In this example and I'm only going to do receiving of traffic monitor session destination
interface 1 0 5
rather 1 0 5 and hit enter.
Now I purposely are only creating one session with the same number to keep it simple but be aware that
you can create multiple span sessions.
There are some dependencies and rules with regards to span a span destination port can only be used
with one span session at a time a span destination port can also not be a span source port.
When you create a span destination port the switch no longer treats that port as a standard Ethan at
port.
As I demonstrated MAC addresses are not learned on that port and traffic received on that port is not
accepted by default.
You can remove a spam destination port by using the no monitor session and a number and the destination
interface and then add it to a different monitor session.
Some other words you can move it from one session to another multiple spans sources can be used within
a single span session one span session cannot mix interfaces and VLAN sources so you must either look
at multiple interfaces or multiple villains one span session can use any combination of directions so
transmit receive or both ether channel can be used as a source port in Port monitoring or span trunks
can also be used as source ports if required.
So in this example we've only got a single interface but we could change that to foster Ethernet.
1 0 3 and then specify a range of interfaces if required.
So let's say 1 0 1 and typical Cisco fashion.
The command is different here to other commands so I'll do receive on both those interfaces do show
run pipe include monitor or in our example span ports.
We're going to look at traffic received on 1 0 1 as well as 1 0 3 so I'll restart the Y shall capture
on of 1 I'm going to send a single ping to write it to what you'll notice even though we only looking
at receiving of traffic we captured both ping Echo as well as Echo reply so the echo would have been
received on this port when Rata 1 transmitted traffic to write at 2 and the Echo reply would have been
received on this port.
So hence we received both the echo and echo reply if we had only configured this port we would only
have received the echo and not the echo reply.
So let's do that.
So no monitor session 1
we only gonna capture the traffic received on this port and then we'll send it out of port 1 0 5.
So now when I clear the session and do a ping notice we only receive half the traffic so be careful
which ports are the source of your capture.
And be careful of the direction of traffic both will allow you to capture traffic in and out of that
port receive is only traffic received on that port transmit is traffic sent out of that port you could
as an example capture on the V Lan So let's get rid of session 1 and what I'll do is say v lan 1 received
traffic and the destination will be port 5 I'll clear the Y shore capture
and do a single ping again and notice here we see both the echo and echo reply message so this echo
reply has echo request because this port and this port on VLAN 1 this port 1 0 2 is actually shut down
in this topology so we could delete that port from the topology some show commands again show monitor
we can see that we've got one session enabled it's a local session we receiving traffic on VLAN 1 destination
port is 1 0 5 we're using a native encapsulation and ingress is disabled so traffic will be dropped
that's received on this port we can also look at detailed information so it's a local session.
They are no source ports configured.
We only have a source a villain configured and we capturing traffic received on VLAN 1 not transmitted
on VLAN 1.
A remote spend session is not configured.
The destination port for the span session is 1 0 5 of the options are not configured so let's have a
look at some of the options.
Show monitor session all at the moment no spend configuration is present on the system we can look at
local span we can even look at remote span remote Spanish used where you have a different source and
destination switch so the source port could be this port on switch to and the destination could be this
port on switch 1 So traffic will be captured on this port and sent to the capturing device on this switch
switch one so I'll configure a monitor session to monitor session pick a number like one source interface
fast ethernet 1 0 1 the destination.
In our example is going to be 1 0 5 seduce show run pipe include monitor that's what we've done.
If we tried to configure another session using the same destination port of interface if 1 0 5 notice
we told that to that port is already being used so we configured this port as the destination of session
1 we can't now configure it to be the destination for session 2 but we could as an example configure
session 2 and specify a different source.
So 1 0 1 as an example so do show run pop include monitor we've got two sources configured but only
one destination so show monitor session or we've got session 1 configured and Session 2 configured but
only session 1 is configured with a destination port Session 2 is not currently being used on one shock
device we should be able to capture traffic from Rado want to write it to which we can see unit cost
traffic sent from right I want to write it to it's being forwarded out of this port because of this
monitoring session traffic sent and received on f 1 slash 1 is going to be sent out of 1 0 5 and hence
we see the ICMP echo request and echo reply messages
now there's nothing stopping us moving the destination port from one session to another so we could
put a no in front of that command will now move it to Session 2 so that's accepted.
So what we've done now is move the destination port from session one to session to all clear that why
shock capture do the ping again and they're just we capturing the traffic because we capturing some
laconic traffic but in a different session.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.