cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
787
Views
0
Helpful
6
Replies

ACI ERSPAN Destination outside of the fabric

joeharb
Level 5
Level 5

We have a need to send an ERSPAN outside of the fabric to a device that has inline taps attached.  Am I correct in assuming that if that device has Layer 3 Endpoint within ACI this is possible?  I have configured a POC with a VM that is within the ACI fabric, but will need to migrate outside.

Thanks,

Joe

1 Accepted Solution

Accepted Solutions

Remi-Astruc
Cisco Employee
Cisco Employee

Hi @joeharb ,

If you mean having the ERSPAN destination behind a L3Out connection, that is not possible. The destination must be learned as local Endpoint in the Fabric (meaning not L3Out).

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/troubleshooting/b_APIC_Troubleshooting/b_APIC_Troubleshooting_chapter_0110.html#id_37668:~:text=ERSPAN%20destination%20IPs%20must%20be%20learned%20in%20the%20fabric%20as%20an%2...

Regards

Remi Astruc

View solution in original post

6 Replies 6

Remi-Astruc
Cisco Employee
Cisco Employee

Hi @joeharb ,

If you mean having the ERSPAN destination behind a L3Out connection, that is not possible. The destination must be learned as local Endpoint in the Fabric (meaning not L3Out).

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/troubleshooting/b_APIC_Troubleshooting/b_APIC_Troubleshooting_chapter_0110.html#id_37668:~:text=ERSPAN%20destination%20IPs%20must%20be%20learned%20in%20the%20fabric%20as%20an%2...

Regards

Remi Astruc

So sorry didn't mean to mark as a solution....no the this end device will be a layer 2 adjacent device.

Will that work?

So what do you mean with "Destination outside of the fabric" and "a VM that is within the ACI fabric, but will need to migrate outside"?

Remi Astruc

We currently have Gigamon TAP's connected to our 7K's. We have migrated most of our traffic from a 5K/2K to ACI. Layer 3 still resides on the 7K's but Layer 2 has been moved to ACI. The 5K's were setup to send ERSPAN traffic to the 7K's which in turn would dump that traffic to the Gigamon Ports. I want to add layer 3 to a BD that also has a Layer 3 presence on the 7K's. Then change my destination of the ERSPAN to an IP address that actually resides on the 7K but will be layer 2 adjacent from the ACI Fabric.
Hope this clarifies the question better.
Thanks,
Joe

Remi-Astruc
Cisco Employee
Cisco Employee

As long as the BDs are L2 only, no ERSPAN can be used in the Fabric.

When a BD is L3 and the ERSPAN destination IP is learned in the BD/EPG, ERSPAN will work.

Regards

Remi Astruc

That is what I am thinking, once I add a L3 address to BD, it will then be able to learn the destination address of the ERSPAN. I have this scheduled for tomorrow night so hopefully I will be able to respond with good results.

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License