01-06-2020 03:56 AM
Hi Gurus,
i faced quite strange behavior on the N7010 running 6.2(20) where with quite simple erspan session config i cannot see on the remote sniffer something different from CDP/LLDP/DCE/ARP/PIM/IGMP/STP...
monitor session 48 type erspan-source
erspan-id 148
vrf default
destination ip 10.0.43.239
source interface port-channel44 tx
rate-limit auto
Modules:
N7K-F248XP-25
N7K-SUP2
same time downstream C9K switch perfectly shows a lot of user's traffic egressing link from N7K side.
where to dig?
01-06-2020 04:26 AM - edited 01-06-2020 04:26 AM
Its quite old version of Nexus OS image, i can not able to replicate your Issue.
As per the ERSPAN document there is no VRF supported here. (not sure is this case with you). look at restriction and guidelines.
01-06-2020 12:29 PM
thanks Balaji
i didnt find any suspecious except "Layer 3 multicast egress packets cannot be spanned on F2 Series or F2e Series modules." I mirror traffic from the L2 portchannel which carries several VLANs some of which are terminated in the same switch (some VLANs belongs to non-default VRFs). Cisco TAC refused to support the case...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide