<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RSPAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/rspan/m-p/439111#M91355</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RSPAN is used if the source of the interesting traffic is on one switch and the analyzer (the capturing device, say IDS) is on the other switch. Both switches must be connected over a trunk that passes the RSPAN VLAN traffic. I am not sure if this traffic can be transported over layer 3, but I believe some tunneling techiques may be used. Anyone tried this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Oct 2005 13:08:01 GMT</pubDate>
    <dc:creator>vkapoor5</dc:creator>
    <dc:date>2005-10-28T13:08:01Z</dc:date>
    <item>
      <title>RSPAN</title>
      <link>https://community.cisco.com/t5/network-security/rspan/m-p/439110#M91354</link>
      <description>&lt;P&gt;Is there anyway to do RSPAN from one site to HQS over layer three connection. I got IDS at HQS and i want to capture traffic from site ? cisco documents talk about RSAPN over layer 2 network but in my case it is going to be layer 3 because it has to come to HQS from site. any idea on how to acheive this. THanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Altaf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rspan/m-p/439110#M91354</guid>
      <dc:creator>altaf007</dc:creator>
      <dc:date>2019-03-10T09:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: RSPAN</title>
      <link>https://community.cisco.com/t5/network-security/rspan/m-p/439111#M91355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RSPAN is used if the source of the interesting traffic is on one switch and the analyzer (the capturing device, say IDS) is on the other switch. Both switches must be connected over a trunk that passes the RSPAN VLAN traffic. I am not sure if this traffic can be transported over layer 3, but I believe some tunneling techiques may be used. Anyone tried this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Oct 2005 13:08:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rspan/m-p/439111#M91355</guid>
      <dc:creator>vkapoor5</dc:creator>
      <dc:date>2005-10-28T13:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: RSPAN</title>
      <link>https://community.cisco.com/t5/network-security/rspan/m-p/439112#M91357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have heard of some new IOS feature which can perform this task. Does anyone know its name or have a link?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Dec 2005 08:06:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rspan/m-p/439112#M91357</guid>
      <dc:creator>tcherkon</dc:creator>
      <dc:date>2005-12-22T08:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: RSPAN</title>
      <link>https://community.cisco.com/t5/network-security/rspan/m-p/439113#M91359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I too have this same problem.  I would love to know if anybody finds a solution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Nov 2006 21:17:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rspan/m-p/439113#M91359</guid>
      <dc:creator>rutledgec</dc:creator>
      <dc:date>2006-11-30T21:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: RSPAN</title>
      <link>https://community.cisco.com/t5/network-security/rspan/m-p/439114#M91360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think what you are looking for is known as ERSPAN (encapsulated RSPAN).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ERSPAN is done thorugh a routed network with the ERSPAN packets inside of a GRE Tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have any experience configuring or using ERSPAN, so I can't provide much help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But here is a link to a User Guide that contains some more information:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/routers/ps368/products_configuration_guide_chapter09186a008069952a.html" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/routers/ps368/products_configuration_guide_chapter09186a008069952a.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like to have quite a few restrictions even down to particular versions of both software and even hardware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Howp this at leasts gets you a starting point for more research.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2006 00:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rspan/m-p/439114#M91360</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2006-12-01T00:13:27Z</dc:date>
    </item>
  </channel>
</rss>

