10-21-2005 07:52 AM - edited 03-10-2019 01:42 AM
Is there anyway to do RSPAN from one site to HQS over layer three connection. I got IDS at HQS and i want to capture traffic from site ? cisco documents talk about RSAPN over layer 2 network but in my case it is going to be layer 3 because it has to come to HQS from site. any idea on how to acheive this. THanks
Altaf
10-28-2005 06:08 AM
RSPAN is used if the source of the interesting traffic is on one switch and the analyzer (the capturing device, say IDS) is on the other switch. Both switches must be connected over a trunk that passes the RSPAN VLAN traffic. I am not sure if this traffic can be transported over layer 3, but I believe some tunneling techiques may be used. Anyone tried this?
12-22-2005 12:06 AM
I have heard of some new IOS feature which can perform this task. Does anyone know its name or have a link?
Thanks
11-30-2006 01:17 PM
I too have this same problem. I would love to know if anybody finds a solution.
11-30-2006 04:13 PM
I think what you are looking for is known as ERSPAN (encapsulated RSPAN).
The ERSPAN is done thorugh a routed network with the ERSPAN packets inside of a GRE Tunnel.
I don't have any experience configuring or using ERSPAN, so I can't provide much help.
But here is a link to a User Guide that contains some more information:
Looks like to have quite a few restrictions even down to particular versions of both software and even hardware.
Howp this at leasts gets you a starting point for more research.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide