Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2Network AssuranceEasy

A network security analyst needs to capture traffic from a specific VLAN on a Cisco Catalyst 9300 switch and send it to an intrusion detection system (IDS) connected to another port on the *same* switch. The goal is to monitor all traffic entering and leaving that VLAN. Which SPAN configuration is required?

  1. Amonitor session 1 source vlan 10 destination interface Gi1/0/2
  2. Bmonitor session 1 source interface Gi1/0/1 rx and tx destination interface Gi1/0/2
  3. Cmonitor session 1 source interface Gi1/0/1 destination interface Gi1/0/2
  4. Dmonitor session 1 source remote vlan 10 destination remote vlan 20
Show answer & explanation

Correct answer: A. monitor session 1 source vlan 10 destination interface Gi1/0/2

To monitor all traffic for a specific VLAN on a single switch, the SPAN source should be configured as the VLAN itself. The destination is the interface connected to the IDS. Option B correctly uses 'source vlan' and 'destination interface' on the same switch, indicating a Local SPAN.

Why the other options are wrong

  • B. This monitors a single interface in both directions, not an entire VLAN.
  • C. This monitors only a single interface, not an entire VLAN.
  • D. This is an RSPAN configuration, involving remote VLANs and not appropriate for a single-switch VLAN monitoring requirement.

Local SPAN (LSPAN) VLAN Source

Local SPAN (LSPAN) allows mirroring traffic from source ports or VLANs to a destination port on the same switch. When a VLAN is configured as the source, all traffic flowing within that VLAN (ingress and egress) is mirrored.

  • Source and destination must be on the same switch.
  • Can mirror traffic from individual ports or entire VLANs.
  • Destination port should be dedicated to the monitoring device.

Memory trick: SPAN: Set the Source, Pick the Port, See the Packets.

More Network Assurance questions