Network Management Configuration Guide, Cisco Catalyst IE9300 Rugged Series Switches

PDF

Network Management Configuration Guide, Cisco Catalyst IE9300 Rugged Series Switches

ERSPAN

Want to summarize with AI?

Log in

Explains the Cisco Encapsulated Remote Switched Port Analyzer (ERSPAN) feature that allows monitoring traffic on ports or VLANs across a Layer 3 network using GRE encapsulation.


The Cisco Encapsulated Remote Switched Port Analyzer (ERSPAN) is a network monitoring feature that

  • allows you to monitor traffic on ports or VLANs and send the monitored traffic to destination ports over a Layer 3 (IP) network using Generic Routing Encapsulation (GRE) encapsulation,

  • sends traffic to a network analyzer, such as a Switch Probe device or a Remote Monitoring (RMON) probe,

  • supports source ports, source VLANs, and destination ports on different devices, which help remote monitoring of multiple devices across a network, and

  • supports encapsulated packets of up to 9180 bytes.

ERSPAN components and session limits

ERSPAN consists of an ERSPAN source session, routable ERSPAN GRE-encapsulated traffic, and an ERSPAN destination session.

You can configure an ERSPAN source session, an ERSPAN destination session, or both on a device. A device on which only an ERSPAN source session is configured is called an ERSPAN source device. A device on which only an ERSPAN destination session is configured is called an ERSPAN termination device. A device can act as both an ERSPAN source device and an ERSPAN termination device.

Oversubscription of traffic can lead to a drop in management traffic on the destination device. To avoid oversubscription, ensure that the destination session is configured and is working on the destination device, before configuring a source session on the source device.

For a source port or a source VLAN, the ERSPAN can monitor the ingress, egress, or both ingress and egress traffic. By default, ERSPAN monitors all traffic, including multicast and Bridge Protocol Data Unit (BPDU) frames.

Session limits:

  • A device supports up to 66 sessions.

  • You can configure a maximum of eight source sessions. The remaining sessions can be configured as RSPAN destination sessions.

  • A source session can be a local SPAN, RSPAN, or ERSPAN source session.

An ERSPAN source session is defined by these parameters:

  • A session ID

  • ERSPAN flow ID

  • list of source ports or source VLANs that are monitored by the session

  • optional attributes such as IP type of service (ToS) and IP Time to Live (TTL) related to the Generic Routing Encapsulation (GRE) envelope

  • destination and origin IP addresses are used as the destination and source IP addresses of the GRE envelope for the captured traffic.

Note
  • ERSPAN source sessions do not copy ERSPAN GRE-encapsulated traffic from source ports. Each ERSPAN source session can have either ports or VLANs as sources, but not both.

  • IPv4 delivery and transport headers are supported, including Type-II and Type-III headers.

    Port channels and switch virtual interfaces (SVIs) are supported.

Figure 1. ERSPAN configuration
The ERSPAN configuration illustrates the setup process for ERSPAN, highlighting the necessary components and connections for encapsulating and transporting network traffic without impacting CPU performance.