Hello everyone,
we have an issue with decoding Tenant SPAN in wireshark. The scenario is a ping from outside the fabric to a VM connected via a VMMdomain.
The ICMP request is decoded fine:
But the reply is messed up. As I marked there are 8 bytes added after the Source-MAC of the Ethernet-Header. After those extra bytes we have the correct Ethertype for IPv4 (0x0800) and everything seems fine.
So here is the question: Where do those extra bytes come from? Why are they only in one direction? Is the SPAN session setup not correct? Do we need to change decoding sessions in Wireshark?
Any input is much appreciated.
Thanks you
Nik