In article <>,
David Hill <> wrote:
:Is there a way to copy packets between interfaces down a third interface for packet analysis?
:For example, I have a router with Eth1, Eth0, and a VPN tunnel tun0. I want to copy all packets between eth1 and eth0 down tun0, where I have an IDS running...
This feature is usually called "port span" or "port mirroring".
In Cisco parlance, the feature is SPAN or RSPAN, and it
is more associated with switches than with routers.
about
:
http://www.cisco.com/univercd/cc/td/...an.htm#xtocid1
I believe that this may be one of the rare instances in which
the Feature Navigator is wrong: it indicates support only on the
2600 and 3600 and 3700 series, but I find a large number of pages
describing configuring it for other models such as the 2950, 4000,
and 6000.
You might not be able to configure mirroring of just traffic
between two specified interfaces: normally you span a specific
interface, or span a VLAN, not traffic -between- two interfaces.
--
Live it up, rip it up, why so lazy?
Give it out, dish it out, let's go crazy, yeah!
-- Supertramp (The USENET Song)