909 Posts

February 10th, 2011 08:00

The settings look correct.

So wireshark can see packets on port 1/g15 but websense cannot?  Are these on the same machine?  If so, then websense is not configured correctly.

If you have more information please post, along with the configuration of ports 1/g48 and 2/g48.

2 Posts

February 11th, 2011 00:00

Please find the interface details

 

console#show interfaces switchport ethernet 2/g48

Port: 2/g48
VLAN Membership mode:Access Mode
Operating parameters:
PVID: 177
Ingress Filtering: Enabled
Acceptable Frame Type: Untagged
Default Priority: 0
GVRP status:Disabled
Protected:Disabled
Port 2/g48 is member in:
VLAN    Name                              Egress rule   Type
----    --------------------------------- -----------   --------
177                                       Untagged      Static

Static configuration:
PVID: 177
Ingress Filtering: Enabled
Acceptable Frame Type: Untagged

Port 2/g48 is statically configured to:
VLAN    Name                              Egress rule
----    --------------------------------- -----------
177                                       Untagged

Forbidden VLANS:
VLAN    Name
----    ---------------------------------

console#show interfaces switchport ethernet 1/g48
Port: 1/g48
VLAN Membership mode:Access Mode
Operating parameters:
PVID: 177
Ingress Filtering: Enabled
Acceptable Frame Type: Untagged
Default Priority: 0
GVRP status:Disabled
Protected:Disabled
Port 1/g48 is member in:
VLAN    Name                              Egress rule   Type
----    --------------------------------- -----------   --------
177                                       Untagged      Static

Static configuration:
PVID: 177
Ingress Filtering: Enabled
Acceptable Frame Type: Untagged
Port 1/g48 is statically configured to:
VLAN    Name                              Egress rule
----    --------------------------------- -----------
177                                       Untagged

Forbidden VLANS:
VLAN    Name
----    ---------------------------------

909 Posts

February 11th, 2011 07:00

Configuration looks correct.  Websense may be either configured incorrectly or having a problem with the tagged and untagged packets.  You should contact websense on this.

This switch port monitoring feature works where all monitored egress traffic appears on the monitor destination port as tagged.  Ingress traffic appears as untagged or tagged (depending on the whether the ingress traffic is tagged or not) on the monitor destination port.  So in your case, since the switch is receiving untagged traffic on the ingress port (i.e. it is set to an access port), the traffic appears on the destination monitor port as untagged.

If websense needs all traffic as tagged, you should change your uplink ports to send/receive tagged traffic (use trunk or general mode).  If websense needs all traffic as untagged, checkout the followoing link for configuring the interface on your pc/server to preserve/remove tags.

http://wiki.wireshark.org/CaptureSetup/VLAN#head-81781716144f2855ab0aff2f8b752e95f2562efb

 

 

No Events found!

Top