How do you folks capture data for application analysis and troubleshooting - "monitors session" or VACLs??..(inline taps seems to be the best way but that can get very expensive).
Please correct me if I make any inaccurate statements.
Scenario: Two Cisco 6909s in HA mode - we want to be able to capture any traffic going through these switches. I have a port on each 6509 going to our monitoring equipment.
If I setup "monitor session" for all VLANs that seems to do the trick - but I get TONs of duplicate frames that max out my port at times...and it can be very cumbersome to remove them. In addition, only 2 mon sessions can be set up per switch.
If I setup VACLs for all the VLANs.....I miss traffic that gets routed *out* of that VLAN unless it's going to another VLAN that's being captured....i.e. if it goes to a port that's not in a VLAN - a routed port - I miss that data. I get traffic routed into that VLAN but not traffic routed out.
I don't know of any way to get all of the data with a VACL, and mon sessions have their previously mentioned limitations.
How would you approach this? Am I wrong about any of this?
Thanks in advance for any comments or suggestions.
Please correct me if I make any inaccurate statements.
Scenario: Two Cisco 6909s in HA mode - we want to be able to capture any traffic going through these switches. I have a port on each 6509 going to our monitoring equipment.
If I setup "monitor session" for all VLANs that seems to do the trick - but I get TONs of duplicate frames that max out my port at times...and it can be very cumbersome to remove them. In addition, only 2 mon sessions can be set up per switch.
If I setup VACLs for all the VLANs.....I miss traffic that gets routed *out* of that VLAN unless it's going to another VLAN that's being captured....i.e. if it goes to a port that's not in a VLAN - a routed port - I miss that data. I get traffic routed into that VLAN but not traffic routed out.
I don't know of any way to get all of the data with a VACL, and mon sessions have their previously mentioned limitations.
How would you approach this? Am I wrong about any of this?
Thanks in advance for any comments or suggestions.