02-20-2019 01:50 PM - edited 03-03-2019 09:00 AM
I'm trying to decide which option is better to capture all the traffic inside vmware (vswitch), so far the solution will include a virtual machine per host which then it will forward all the traffic to an IP (example 1.1.1.1) on an isolated VLAN.
The question is: do I want that IP and VLAN on all the switches or on a dedicated switch.
The goal is to minimize the impact on any of the uplinks and potential problems due misconfiguration.
I would like to have comments about either design.
Thanks!
Rolando A. Valenzuela
02-20-2019 03:44 PM - edited 02-20-2019 03:46 PM
So you looking all VM's traffic to be monitor, After traffic span to Arista, what is the device you going to use to capture this mirrored traffic ? do you have TAP ?
Instead of extending Esxi to another switch, why not consider created inside Esxi, create VM to capture that information for you.
example of this guide :
https://blog.architecting.it/vsphere-vds-span-port-with-wireshark-in-2-minutes/
https://www.gigamon.com/products/virtual-and-cloud/gigavue-vm.html
http://www.veryxtech.com/products/test-platforms/virtual-vnf-network-taps/
02-25-2019 08:37 PM
02-26-2019 12:23 AM
yes, since original post was asked only Esxi environment i have give the approach how we can do, if you have other infrastrucutre that also need to be monitor.
you have option.
1. RSPAN
2. TAP
Since you have mentioned you want to send traffic to Asrista and there you going to monitor, then go with that plan as you are comfortable.
Also look at the kind of traffic you monitor.
02-26-2019 07:02 AM
02-21-2019 06:04 PM
02-25-2019 08:39 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide