Traffic Mirroring Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Release

PDF

Traffic Mirroring Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Release

Restrictions for local SPAN

Want to summarize with AI?

Log in

This section provides the generic and ACL-specific restrictions for implementing local SPAN, such as limitations on egress mirroring and interface types. Understanding these constraints ensures proper configuration and avoids unsupported setups.


Generic restrictions for local SPAN

The generic restrictions for local SPAN include:

  • Egress mirroring isn’t supported. From Release 26.3.1 onwards, egress mirroring is introduced.

  • The physical interface used as destination can’t be a bundle member link.

  • GRE tunnels are not supported as source or destination interfaces.

  • Per-source interface mirroring statistics isn’t supported. However, SPAN session statistics are supported. The session statistics contain the total number of packets mirrored by the session.

  • A destination interface can’t be a mirrored source interface and vice versa.

  • NetFlow or sFlow configuration is not supported on interfaces that already have a local SPAN session configured.

  • SPAN over BVI is not supported.

  • The dropped packets at NPU cannot be captured by regular SPAN session. For capturing dropped packets at NPU, use the mirror forward-drop packets feature.

  • Local SPAN destinations support only L2 and L3 physical main interfaces. The router does not support bundle interfaces, sub-interfaces, BVIs, or tunnel interfaces.

  • Mirroring for BVI interfaces on Cisco Silicon One A100, K100, P100, and P200 ASIC-based systems is not supported.

  • The router does not support port-level SPAN for Rx or Tx traffic.

ACL restrictions for local SPAN

The ACL restrictions for local SPAN include:

  • ACLs for Local SPAN are applied only in ingress direction.

  • If the ACL keyword is present in monitor-session configuration for an interface but no ACL is applied to that interface, traffic packets are not mirrored.

  • ACL for MPLS traffic isn’t supported.

  • Local SPAN egress sessions do not support ACLs or Security ACLs on the same path.