cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1714
Views
0
Helpful
5
Replies

What Virtual interface is the TAP / P1 in S300v?

keithsauer507
Level 5
Level 5

When deploying the C300v virtual WSA the ovf file deploys the VM with 5 network adapters.  What network adapter would be used for a TAP interface?  I cabled a ESXi host to a spare nic, put it in promiscuous mode and binded it to network adapter 2 to start.  Nothing.  Moved it to 4... so far nothing.  But yet I'm not sure how long I need to wait.

 

The switchport its plugged into is the same switchport that our now retired physical S170 appliance tap interface was connected to, so I know the cisco port mirror is setup correctly as its mirroring the port that leaves our network and goes out to the Internet.

 

5 Replies 5

keithsauer507
Level 5
Level 5

62 views and no response?

 

Cisco doesn't know either.  Opened a case last week.  Got a very generic response.  Replied back with screen shots of vmware virtual appliance config showing all the NICs and a screen shot of the interfaces screen in the web gui which has no coloration to which vmnic.

 

Cisco really needs to update their documentation since no one on this forum and more importantly no one at Cisco can give a quick answer.  This should be easy.

I thought I'd replied...

as far as I know, T1/T2 are the NIC 4 and 5 in the VM...

 

 

jeffhouston
Level 1
Level 1

I am having a similar issue except I cannot get vWSA to recognize NIC's in Windows Hyper-v S100v. My goal is to convert S170 hardware into virtual. My hardware appliance is running M1 (management), P1 (data), and L4 traffic monitor as Simplex TAP: T1 in and T2 out, I'm not sure how to replicate this virtually with Hyper-V.

I have searched extensively for more information about this unsuccessfully and expecting Cisco to have a guide of some sort but what I have found is vague on the subject for all VM platforms.

So when I ssh into the cli of the WSA (sorry for all of the acronyms.. .part of being in IT!)...  there is a command to look at the nics.

Type etherconfig

then type media

 

It will list them out with mac addresses and if the link is up and what speed.  This shows me that 1 Management is up at 1000baseT full-duplex, as is 4 T1 is up as well.

 

However in the L4TM logs there is never any data.  We even added some IP's in the L4 settings to test this feature, but it doesn't block or log anything.  Just to test that I have the port mirror setup correctly, I added a second nic to a Windows VM and put it on this network.  I ran wireshark on that NIC and low and behold I witnessed all of the traffic traversing our outbound link to our inline IDS/IPS that sits between our network and our Internet switch where our load balancers and ISP's terminate.

 

So I know that this mirror works fine.  In vmware its just a simple NIC with promiscouous mode set to accept.  We have called this TAP1.  We have another that is the same configuration called TAP2 that is feeding an Extreme Networks Purview applications analytics appliance.  This has no issues at all and it is classifying every piece of traffic traversing through our core switch stacks.  I don't know what the issue is with the virtual WSA running 10.5.2.  There are a lot of bugs in this version but a new release is not expected until Q1 2018.  I hope this is fixed in the next build, as well as periodic reports failed and random coring on o365 hosted sharepoint (onedrive)  (temp fixed by putting it in bypass).  The fortigate guys are pushing hard to make us move and sometimes that option looks better and better every day.

 

 

TAC finally figured out that I am hitting bug CSCvg28652 https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg28652/?reffering_site=dumpcr

 

In async os 10.5.1-296 L4TM shows nothing, blocks nothing even if interface is configured properly on T1/T2 port.

 

That's 4 critical bugs we've encountered on this p*** poor release so far.  The next release can't come fast enough.  I want to install it the second it is posted.