08-12-2021 12:23 PM
How do you configure a span port on an SDA router? C9500
Thanks.
08-12-2021 01:36 PM
check this user guide help you :
08-13-2021 11:32 AM
What kind of SPAN?
SPAN (mirror a port and send the traffic to another port directly connected to the switch):
monitor session 1
source interface x/x both
destination interface x/x encapsulation-replicate
RSPAN (mirror a port and send the traffic on a VLAN instead): Rarely used in SDA as there are no trunks to work with
ERSPAN (mirror a port and send the traffic to a remote device, encapsulating the traffic on an IP /GRE tunnel):
ip access-list extended RTP
10 permit udp any any eq 1234
monitor session 10 type erspan-source
description RTP_Test -
source interface/vlan/etc
filter ip access-group RTP ----- ACL to only replicate relevant traffic
destination
erspan-id 100
mtu 9000 ----- Set by default
ip address 192.168.32.11 ------- Remote recording / capture server
origin ip address 172.19.1.72 --- Loopback 0 IP from the fabric node
no shut
None of these can be yet automated by DNAC; the traffic copy feature can only support router platforms as per the time of this writting
02-01-2022 05:16 AM
@jalejand Does SDA support ERSPAN session across the fabric between two ENs? I have conducted several tests, but not getting expected results. My test case platform info: Both ENs are C9300-48UXM running 17.03.04
08-16-2021 10:18 AM
Running DNAC 1.3.3.6 and don't have the service.
02-03-2022 12:13 PM
I think you have to go for a upgrade of your DNAC.
At least DNAC Version 2.2.3.4 brings the following support.
You can configure Switched Port Analyzer (SPAN) and Encapsulated Remote Switched Port Analyzer (ERSPAN) sessions on switches to share IP traffic for application assurance and endpoint analytics. |
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide