> Make trunk (tagged) port where you have monitor PC and SPAN all
> traffic to it, as it doesn't have anything it should receive, it'll
> only receive broadcast and flooded traffic, then you can
> use tshark/tcpdump to ditch the broadcast and check only flooded
> unicast.

Of course no need for SPAN here, just trunk (tagged) port
will suffice. Thanks Tarko.

-- 
  ++ytti
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to