Rik Bain <> wrote in message news:< ainz.org>...
> On Mon, 22 Dec 2003 12:48:33 -0600, Bert Prefect wrote:
>
> > Hello,
> >
> > I have a Cisco Catalyst 4507. I have several webservers in a VLAN. The
> > ports for the webservers are all mirrored port 3/48 (an IDS server).
> >
> > ....#sh int fa 3/48
> > FastEthernet3/48 is up, line protocol is down (monitoring) ....
> >
> > I can't seem to get the line protocol to come up. So I can't see the
> > web traffic from the other servers. I do see on the IDS the Backup
> > server talk to the other servers nightly, but I should see web redirects
> > or web access failures, and so on on the IDS
> >
> > I've swapped out the cable, restarted the IDS, restarted the 4507, but
> > the line protocol does not come up.
> >
> > Any ideas?
> >
> > Thanks,
> > Bert
>
>
> Can you see traffic on that port? I think that the reason you see it
> that way is that when it is monitoring other ports, it will not accept
> ingress traffic and report as down.
>
> Rik Bain
Yesterday, I did see on the IDS some security scans (such as SYN FIN)
our ISP does on a monthly basis. Nothing beyond that and the internal
backup server events.
Thanks,
Bert
|