Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SG-1100 span port only sending broadcast and multicast

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    11 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      thisguy
      last edited by

      Hi all, have a brand new SG-1100 all set up with LAN going to AP/switch and OPT going to IDS for full capture. LAN interface is a member of a bridge with OPT as the SPAN port. No other configuration or packages installed except a couple port forwarding rules.

      I tried multiple physical and virtual machines (Linux and Windows) with Wireshark connected and all firewalls disabled as well and on all of them and for some reason I can only see broadcast and multicast traffic coming through. Looking at the traffic graph it seem like all traffic is getting sent to opt.

      graph.PNG

      Any ideas?

      1 Reply Last reply Reply Quote 1
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        It's almost certainly being filtered by the switch. Unfortunately we don't yet have a way to enable a span port on the switch which is what would be required here.
        Your only option there would be to use a USB NIC. Those are generally not recommended though. Performance can vary wildly.

        Steve

        1 Reply Last reply Reply Quote 0
        • T
          thisguy
          last edited by

          Oh no, really? That's unfortunate as I was hoping buying the SG-1100 fit perfect in what I needed, this was the last piece. I didn't want to have to add an additional switch and another hop, keep it powered on UPS, just for a span/mirror port.

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            It may be possible in some CLI script way. Let me see what I can find....

            1 Reply Last reply Reply Quote 0
            • T
              thisguy
              last edited by

              I owe you some beers sir!

              1 Reply Last reply Reply Quote 0
              • T
                thisguy
                last edited by

                Thanks again for looking into this, just checking if anything turned up?

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Nothing yet I'm afraid. I did look into it but the available tools may not be sufficient.

                  I have asked upstream.

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • T
                    thisguy
                    last edited by

                    Really appreciate the effort, I will keep an eye out.

                    1 Reply Last reply Reply Quote 0
                    • Z
                      zombat
                      last edited by

                      @stephenw10 said in SG-1100 span port only sending broadcast and multicast:

                      Nothing yet I'm afraid. I did look into it but the available tools may not be sufficient.
                      I have asked upstream.
                      Steve

                      Hi, any luck with the span port? I am looking at the same setup as well.

                      Thanks

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Not directly in the switch. I believe the switch hardware can do it but poking the correct registers in the switch to make it do it proved difficult.
                        I was hoping to be able to use etherswitchcfg directly since it has direct register capability but it seems only a limited subset are accessible.

                        Steve

                        Z 1 Reply Last reply Reply Quote 0
                        • Z
                          zombat @stephenw10
                          last edited by

                          @stephenw10 Thanks Steve.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.