Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

setup a monitor port on a Summit 48 port switch

Status
Not open for further replies.

xxsubz78x

IS-IT--Management
May 2, 2007
2
US
I need to setup a monitor port that will capture all the traffic that's going to all the ports. I have the user manual but I can't seem to find anywhere in there where it talks about how to do that.

I've done it before on a Cisco switch but I'm new to Extreme and not sure how to do this.

Basically I want all the traffic to go to one monitor port and I can use a sniffing program to look at all the traffic.
 
'enable mirroring to port xx'
what ever port you want the mirroring sent to

'configure mirroring add ports/vlans'
What you want sent to the mirror port

 
I found the section in the manual that talks about that. Thanks for the info. I just didn't know what it was called. Now I know it's called "port mirroring".

One more question: when I type in:
enable port mirroring to 3:8, it asks me if I want it tagged or untagged??

I know that if I setup a port to be tagged, that's like saying allowed vlan.

What would be the point of tagging a mirror port??
 
If you tag a port is because you're connecting a router or something alike, not a server or a pc for sniffing. If you are just connecting to the mirrored port to sniff it has to be untagged to the specific vlan.

The point of being able to tag a mirrored port is because you may want to monitor that specific traffic through another and completely different lan that goes through another router.
 
The port mirror "To" port will output the captured frames with or without VLAN tag headers. Hence the tagged or untagged option.

Really depends on the NIC and Packet Capture software.

If your PC NIC and packet capture software can read VLAN tags and you actually want to see them, select tagged

If you don't care about looking at the VLAN tags or your PC NIC and packet capture software do not support reading the tags, select untagged.

For example, I use Ethereal. If I use the embedded Broadcom NIC in my laptop it cannot read tags. If I use mirror to tagged I don't see anything in Ethereal. I must configure it as untagged so that my Broadcom NIC can see the packets.

If I use my PCMCIA Netgear card it does read tags. So if I attach to this port with Ethereal I will see the packets and L2 VLAN headers when I select tagged.

Hope this helps you.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top