I am working with a client that has two Nexus 9K switches. I'm attempting to set up an ERSPAN from switch B to switch A.
I'm running into a problem where I can't configure the erspan-destination on switch A.
To my knowledge, this is done first by doing this from within the configuration terminal on Switch A (we already set up the erspan-source on Switch B to send to the IP on Switch A, so that configuration is omitted here for now):
monitor session 11 type erspan-destination
erspan-id 101
vrf monitoring
source ip 10.1.255.11
destination interface Ethernet1/15
no shut
However, the 9k does not accept this as valid syntax, and whenever I do monitor session 11 type erspan? to get the help, it only shows me erspan-source for the monitor.
Is there a way to get ERSPAN set up between the 9K switches such that B sends to A, and then A has a general span port that works for it, so that we can have one all-inclusive span port on Switch A that we can feed into our IDS/IPS on the border of the network for internal traffic monitoring and correlation?
If this is not possible, then how could we get the traffic on Switch B to be received at Switch A so that our existing SPAN port on Switch A can see Switch B's traffic (as ERSPAN should permit)?