Jump to content
Калькуляторы

Cisco 4500x-16 и битое зеркало СОРМ

Добрый день!

Пытаюсь на коммутаторе Cisco 4500x-16 запустить зеркало для СОРМ по схеме 1 в 1 порт (10G). Трафика немного - до 4 Гбит вход / 1 Гбит исход. Однако даже при таком трафике СОРМ не видит трафик. 

У кого-то был позитивный опыт использования cisco 4500x для зеркала трафика?

Share this post


Link to post
Share on other sites

так вообще не видит или видит, но битый? sh int с киски на интерфейсе, как настроили зеркалирование? и что за сорм, какое соединение?

Share this post


Link to post
Share on other sites

настройки самые простые

monitor session 1 source interface Te1/4
monitor session 1 destination interface Te1/5
monitor session 1 filter packet-type good rx
show interfaces tenGigabitEthernet 1/5
TenGigabitEthernet1/5 is up, line protocol is down (monitoring)
  Hardware is Ten Gigabit Ethernet Port, address is 881d.fc66.5b44 (bia 881d.fc66.5b44)
  Description: SORM
  MTU 1546 bytes, BW 10000000 Kbit/sec, DLY 10 usec, 
     reliability 255/255, txload 96/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive set (10 sec)
  Full-duplex, 10Gb/s, link type is auto, media type is 10GBase-SR-*
  input flow-control is on, output flow-control is on 
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input 00:00:28, output never, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 0 bits/sec, 0 packets/sec
  5 minute output rate 3782197000 bits/sec, 499545 packets/sec
     39129 packets input, 2504256 bytes, 0 no buffer
     Received 39129 broadcasts (39129 multicasts)
     0 runts, 0 giants, 0 throttles 
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 input packets with dribble condition detected
     398797967955 packets output, 379069520250445 bytes, 0 underruns
     0 output errors, 0 collisions, 3 interface resets
     0 unknown protocol drops
     0 babbles, 0 late collision, 0 deferred
     0 lost carrier, 0 no carrier
     0 output buffer failures, 0 output buffers swapped out

СОРМ спецтех

говорят, что видит битый (но это со слов сотрудников органов)

Share this post


Link to post
Share on other sites

Можете сами проверить трафик, заверните к себе на сервер, если сможете из трафика целые архивы достать - то с трафиком у вас нормально.

У нас WS-C4500X-32, RSPAN, нормально сдались.

Share this post


Link to post
Share on other sites
1 час назад, 911 сказал:

настройки самые простые


monitor session 1 source interface Te1/4
monitor session 1 destination interface Te1/5
monitor session 1 filter packet-type good rx

show interfaces tenGigabitEthernet 1/5
TenGigabitEthernet1/5 is up, line protocol is down (monitoring)
  Hardware is Ten Gigabit Ethernet Port, address is 881d.fc66.5b44 (bia 881d.fc66.5b44)
  Description: SORM
  MTU 1546 bytes, BW 10000000 Kbit/sec, DLY 10 usec, 
     reliability 255/255, txload 96/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive set (10 sec)
  Full-duplex, 10Gb/s, link type is auto, media type is 10GBase-SR-*
  input flow-control is on, output flow-control is on 
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input 00:00:28, output never, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 0 bits/sec, 0 packets/sec
  5 minute output rate 3782197000 bits/sec, 499545 packets/sec
     39129 packets input, 2504256 bytes, 0 no buffer
     Received 39129 broadcasts (39129 multicasts)
     0 runts, 0 giants, 0 throttles 
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 input packets with dribble condition detected
     398797967955 packets output, 379069520250445 bytes, 0 underruns
     0 output errors, 0 collisions, 3 interface resets
     0 unknown protocol drops
     0 babbles, 0 late collision, 0 deferred
     0 lost carrier, 0 no carrier
     0 output buffer failures, 0 output buffers swapped out

СОРМ спецтех

говорят, что видит битый (но это со слов сотрудников органов)

а если патч заменить? такая вот мысль пришла

Share this post


Link to post
Share on other sites
!
interface TenGigabitEthernet1/52
 description SORM-MIRROR
 no cdp enable
!
monitor session 1 source vlan 119 - 129 , 135 - 142
monitor session 1 destination interface Te1/52
monitor session 1 filter packet-type good rx
!

У нас 4948, такие вот настройки.

S-Core#sh int Te1/52
TenGigabitEthernet1/52 is up, line protocol is down (monitoring)
  Hardware is Ten Gigabit Ethernet Port, address is e02f.6da4.8633 (bia e02f.6da4.8633)
  Description: SORM-MIRROR
  MTU 1500 bytes, BW 10000000 Kbit, DLY 10 usec, 
     reliability 255/255, txload 159/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive set (10 sec)
  Full-duplex, 10Gb/s, link type is auto, media type is 10GBase-LR
  input flow-control is on, output flow-control is off
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input never, output never, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 19599049
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 0 bits/sec, 0 packets/sec
  5 minute output rate 6272693000 bits/sec, 845276 packets/sec
     0 packets input, 0 bytes, 0 no buffer
     Received 0 broadcasts (0 multicasts)
     0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 input packets with dribble condition detected
     6007018248218 packets output, 5660988873668191 bytes, 0 underruns
     0 output errors, 0 collisions, 0 interface resets
     0 babbles, 0 late collision, 0 deferred
     0 lost carrier, 0 no carrier
     0 output buffer failures, 0 output buffers swapped out

От вас отличается только этим - input flow-control is on, output flow-control is off

И откуда у вас вдруг счётчик инпутов набежал на зеркальном-то порту?

39129 packets input, 2504256 bytes, 0 no buffer
     Received 39129 broadcasts (39129 multicasts)

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this