This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

cisco span

0
1

When sniffing on a cisco span, it looks like the Rx and TX traffic are buffered. If I look at one tcp session I get a range off Tx packets and after that a whole rage of Rx tcp ack packages. (more then 20 in a row). Is this normal span behavoir?

asked 07 Oct '15, 04:57

stobbe99's gravatar image

stobbe99
6234
accept rate: 0%


One Answer:

3

I think your question is: "By creating a SPAN port, does traffic to the SPAN port become affect?"

The answer is: YES! Even Cisco in their own white paper states:

"Cisco warns that the switch treats SPAN data with a lower priority than regular port-to-port data. In other words, if any resource under load must choose between passing normal traffic and SPAN data, the SPAN loses and the mirrored frames are arbitrarily discarded. This rule applies to preserving network traffic in any situation. For instance, when transporting remote SPAN traffic through an Inter Switch Link (ISL), which shares the ISL bandwidth with regular network traffic, the network traffic takes priority. If there is not enough capacity for the remote SPAN traffic, the switch drops it."

Link to white paper: http://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/san-consolidation-solution/net_implementation_white_paper0900aecd802cbe92.html

So depending on the load of your switch, your traffic might be affected.

Also, here is another great article: http://www.lovemytool.com/blog/2007/08/span-ports-or-t.html

In the article, it states: "Spanning or mirroring changes the timing of the frame interaction (what you see is not what you get)"

answered 07 Oct '15, 11:59

Amato_C's gravatar image

Amato_C
1.1k142032
accept rate: 14%