Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2Network AssuranceEasy
A network security analyst needs to capture traffic from a specific VLAN on a Cisco Catalyst 9300 switch and send it to an intrusion detection system (IDS) connected to another port on the *same* switch. The goal is to monitor all traffic entering and leaving that VLAN. Which SPAN configuration is required?
- Amonitor session 1 source vlan 10 destination interface Gi1/0/2
- Bmonitor session 1 source interface Gi1/0/1 rx and tx destination interface Gi1/0/2
- Cmonitor session 1 source interface Gi1/0/1 destination interface Gi1/0/2
- Dmonitor session 1 source remote vlan 10 destination remote vlan 20
Show answer & explanationAnswer & explanation
Correct answer: A. monitor session 1 source vlan 10 destination interface Gi1/0/2
To monitor all traffic for a specific VLAN on a single switch, the SPAN source should be configured as the VLAN itself. The destination is the interface connected to the IDS. Option B correctly uses 'source vlan' and 'destination interface' on the same switch, indicating a Local SPAN.
Why the other options are wrong
- B. This monitors a single interface in both directions, not an entire VLAN.
- C. This monitors only a single interface, not an entire VLAN.
- D. This is an RSPAN configuration, involving remote VLANs and not appropriate for a single-switch VLAN monitoring requirement.
Local SPAN (LSPAN) VLAN Source
Local SPAN (LSPAN) allows mirroring traffic from source ports or VLANs to a destination port on the same switch. When a VLAN is configured as the source, all traffic flowing within that VLAN (ingress and egress) is mirrored.
- Source and destination must be on the same switch.
- Can mirror traffic from individual ports or entire VLANs.
- Destination port should be dedicated to the monitoring device.
Memory trick: SPAN: Set the Source, Pick the Port, See the Packets.