2010年5月15日 星期六

Port Mirror/SPAN

 image   

使用Port Monitor的方式
1. 將fa0/1介面的流量轉送一份至fa0/23介面上
(conf)#int fa 0/23
(conf-int)#port monitor int fa 0/1

2. 將vlan1的流量轉送一份至 fa0/23介面上
(conf)#int fa 0/23
(conf)#port monitor vlan 1

驗證與除錯指令
show port monitor

使用Monitor Session的方式
1. 將fa0/1介面的流量轉送一份至fa0/23介面上
(conf)#monitor session 1 source interface fastethernet 0/1
(conf)#monitor session 1 destination interface fastethernet 0/23

2. 將vlan1的流量轉送一份至fa0/23介面上
(conf)#monitor session 1 source vlan 1
(conf)#monitor session 1 destination interface fastethernet 0/23

驗證與除錯指令
show monitor session 1

image  

使用Monitor Session to VLAN的方式
1. 設定SW1為VTP Server
(conf)#vtp domain cisco
(conf)#vtp version 2
(conf)#vtp mode server
(conf)#vtp password cisco
(conf)#vlan 1
(conf-vlan)#name Management-VLAN
(conf-vlan)#exit
(conf)#vlan 88
(conf-vlan)#name Monitor-VLAN
(conf-vlan)#exit
(conf)#int fa 0/22
(conf-int)#switchport mode trunk
(conf-int)#exit

2. 設定SW2為VTP Clinet
(conf)#vtp domain cisco
(conf)#vtp version 2
(conf)#vtp mode client
(conf)#vtp password cisco
(conf)#int fa 0/22
(conf-int)#switchport mode trunk
(conf-int)#exit


3. 將SW2上vlan1的流量轉送到vlan88上
(conf)#monitor session 1 source vlan 1
(conf)#monitor session 1 destination remote vlan 88

4.將SW1上vlan88的流量轉送到fa0/23介面上
(conf)#vlan 88
(conf-vlan)#remote-span 
(conf)#monitor session 1 source remote vlan 88
(conf)#monitor session 1 destination interface fastethernet 0/23

驗證與除錯指令
show monitor session 1

參考文件
http://www.cisco.com/en/US/products/hw/switches/ps708/products_tech_note09186a008015c612.shtml

沒有留言:

張貼留言