Network Management Configuration Guide, Cisco Catalyst IE9300 Rugged Series Switches

PDF

Network Management Configuration Guide, Cisco Catalyst IE9300 Rugged Series Switches

Information about configuring ERSPAN

Want to summarize with AI?

Log in

Describes the information sections that provide details about configuring ERSPAN functionality on network devices. This reference assists administrators in locating specific configuration parameters and operational requirements.


This topic provides information about configuring ERSPAN functionality on network devices.


Restrictions for configuring ERSPAN

The restrictions for this feature are:

  • Truncation is supported only on IPv4 spanned packets and not on Layer 2 packets without an IP header.

  • Configure the ERSPAN destination interface for only one session. Do not configure the same destination interface for multiple ERSPANs or SPANs.

  • You can configure either a list of ports or a list of VLANs as a source, but cannot configure both for a given session.

  • Do not configure filter IP, MAC, or VLAN access-group and filter SGT together.

  • When a session is configured through the ERSPAN CLI, the session ID and the session type cannot be changed. To change them, you must use the no form of the commands to remove the session and then reconfigure it.

  • If you configure ERSPAN source sessions, locally-sourced RSPAN VLAN traffic from source trunk ports carrying RSPAN VLANs is not copied.

  • If you configure ERSPAN source sessions, locally-sourced ERSPAN GRE-encapsulated traffic from source ports is not copied.

  • If you disable the ip routing command for IPv4 connections, ERSPAN traffic will not flow to the destination port.


ERSPAN sources

The Cisco ERSPAN feature supports the following sources:

  • Source ports: A source port that is monitored for traffic analysis. Source ports in any VLAN can be configured and trunk ports can be configured as source ports along with nontrunk source ports.

  • Source VLANs: A VLAN that is monitored for traffic analysis.


ERSPAN destination ports

An ERSPAN destination port is a Layer 2 or Layer 3 port that

  • receives traffic from ERSPAN source for analysis

  • becomes dedicated exclusively for ERSPAN feature use when configured, and

  • can be configured as a trunk port to transmit encapsulated traffic.

ERSPAN destination port behavior

When you configure a port as a destination port, it can no longer receive any traffic. The port is dedicated for use only by the ERSPAN feature. An ERSPAN destination port does not forward any traffic except that required for the ERSPAN session. You can configure trunk ports as destination ports, which allows destination trunk ports to transmit encapsulated traffic.


SGT-based ERSPAN

A Security Group Tag (SGT) is a 16-bit value that

  • the Cisco Identity Services Engine (ISE) assigns to the user or endpoint session upon login

  • the network infrastructure treats SGT as another attribute assigned to the session and inserts the Layer 2 tag into all traffic from that session

  • supports a maximum of 50 SGT policies per session on a platform.

SGT filtering configuration restrictions

You cannot configure SGT filtering on an existing flow-based SPAN (FSPAN) or VLAN filter session


Prerequisites for configuring ERSPAN

Apply the access control list (ACL) filter before forwarding the monitored traffic to the tunnel.