Hello, I have recently learn that ACI and IDS systems do not work because of the ACI does not support span(VLAN).
I have research a few things on the web about ACI and IDS sensors. Not much there really
So looking for some help on this issue.
I understand that IDS monitor sessions are setup for vlans they do not need IP address or use a IP address for this.
I have heard that ERSPAN is a idea to make this work with ACI and IDS system.
Idea I heard was you setup a GRE Tunnel with static IP route statement.
The port that IDS is connected to on your core switch gets change from L2 to L3 with loopback address.
The other connection is setup on the router or core device with a loopback address as well.
Has anyone try this or has a better Idea