[Snort-users] Cisco 6500 SPAN limitations, dropping packets, VACLs, RSPAN, real world

twig les twigles at ...131...
Wed Apr 28 09:10:05 EDT 2004

You ask a lot of tough questions and I'll be honest that I don't
know most the answers.  We've been using 6500s in our core for
years and sniffing/snorting off of them without a hitch the
entire time, both on CatOS and IOS.

We have about 14-15Mbps sustained traffic coming from tons of
different ports, vlans and src/dst pairs through the CatOS pair
and use the sniffers constantly to verify and troubleshoot
traffic and have never noticed any missing traffic so I'm not
sure what the ingress/egress limitations equate to in the

I tried the link but it was dead, even after signing into CCO
and pasting the .htm.... that got wrapped around in the email. 
Try posting here:

I have gotten a lot of good responses there as Cisco pays CCIEs
to lurk the board.  They have even given me crappy news (with
slight sugar-coating but not marketing fluff).  Let me know if
you don't have a CCO login and I'll just post your email.

With a few exceptions, secrecy is deeply incompatible with
democracy and with science.
     --Carl Sagan  

Do you Yahoo!?
Win a $20,000 Career Makeover at Yahoo! HotJobs  

More information about the Snort-users mailing list