cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Join Customer Connection to register!
283
Views
0
Helpful
0
Replies
teward
Beginner

ERSPAN between two Nexus 9k switches

I am working with a client that has two Nexus 9K switches.  I'm attempting to set up an ERSPAN from switch B to switch A.

 

I'm running into a problem where I can't configure the erspan-destination on switch A.

 

To my knowledge, this is done first by doing this from within the configuration terminal on Switch A (we already set up the erspan-source on Switch B to send to the IP on Switch A, so that configuration is omitted here for now):

monitor session 11 type erspan-destination
erspan-id 101
vrf monitoring
source ip 10.1.255.11
destination interface Ethernet1/15
no shut

However, the 9k does not accept this as valid syntax, and whenever I do monitor session 11 type erspan? to get the help, it only shows me erspan-source for the monitor.

 

Is there a way to get ERSPAN set up between the 9K switches such that B sends to A, and then A has a general span port that works for it, so that we can have one all-inclusive span port on Switch A that we can feed into our IDS/IPS on the border of the network for internal traffic monitoring and correlation?

 

If this is not possible, then how could we get the traffic on Switch B to be received at Switch A so that our existing SPAN port on Switch A can see Switch B's traffic (as ERSPAN should permit)?

0 REPLIES 0