> Make trunk (tagged) port where you have monitor PC and SPAN all > traffic to it, as it doesn't have anything it should receive, it'll > only receive broadcast and flooded traffic, then you can > use tshark/tcpdump to ditch the broadcast and check only flooded > unicast.
Of course no need for SPAN here, just trunk (tagged) port will suffice. Thanks Tarko. -- ++ytti _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
