34-4
Catalyst 6500 Series Switch Cisco IOS Software Configuration Guide—Release 12.1 E
78-14099-04
Chapter 34 Configuring Local SPAN and RSPAN
Understanding How Local SPAN and RSPAN Work
Monitored Traffic
These sections describe the traffic that SPAN (local or remote) can monitor:
Monitored Traffic Direction, page 34-4
Monitored Traffic Type, page 34-4
Duplicate Traffic, page 34-4

Monitored Traffic Direction

You can configure SPAN sessions to monitor ingress network traffic (called ingress SPAN), or to monitor
egress network traffic (called egress SPAN), or to monitor traffic flowing in both directions.
Ingress SPAN copies network traffic received by the source ports and VLANs for analysis at the
destination port. Egress SPAN copies network traffic transmitted from the source ports and VLANs.
When you enter the both keyword, SPAN copies the network traffic received and transmitted by the
source ports and VLANs to the destination port.

Monitored Traffic Type

By default, local SPAN monitors all network traffic, including multicast and bridge protocol data unit
(BPDU) frames. RSPAN does not support BPDU monitoring.

Duplicate Traffic

In some configurations, SPAN sends multiple copies of the same source traffic to the destination port.
For example, in a configuration with a bidirectional SPAN session (both ingress and egress) for two
SPAN sources, called s1 and s2, to a SPAN destination port, called d1, if a packet enters the switch
through s1 and is sent for egress from the switch to s2, ingress SPAN at s1 sends a copy of the packet to
SPAN destination d1 and egress SPAN at s2 sends a copy of the packet to SPAN destination d1. If the
packet was Layer 2 switched from s1 to s2, both SPAN packets would be the same. If the packet was
Layer 3 switched from s1 to s2, the Layer-3 rewrite would alter the source and destination Layer 2
addresses, in which case the SPAN packets would be different.
SPAN Sources
These sections describe local SPAN and RSPAN sources:
Source Ports, page 34-4
Source VLANs, page 34-5

Source Ports

A source port is a port monitored for network traffic analysis. You can configure both switched and
routed ports as SPAN source ports. SPAN can monitor one or more source ports in a single SPAN session.
You can configure source ports in any VLAN. Trunk ports can be configured as source ports and mixed
with nontrunk source ports, but SPAN does not copy the encapsulation from a source trunk port.