cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1119
Views
0
Helpful
1
Replies

ACI with IDS setup

Adam Coombs
Level 1
Level 1

Hello, I have recently learn that ACI and IDS systems do not work because of the ACI does not support span(VLAN).

I have research a few things on the web about ACI and IDS sensors. Not much there really

So looking for some help on this issue. 

I understand that IDS monitor sessions are setup for vlans they do not need IP address or use a IP address for this. 

I have heard that ERSPAN is a idea to make this work with ACI and IDS system.

Idea I heard was you setup a GRE Tunnel with static IP route statement. 

The port that IDS is connected to on your core switch gets change from L2 to L3 with loopback address. 

The other connection is setup on the router or core device with a loopback address as well.

Has anyone try this or has a better Idea  

1 Reply 1

mclean.danny
Level 1
Level 1

Did you ever get this resolved? We are looking to do the same with Alienvault.

Save 25% on Day-2 Operations Add-On License