ERSPAN, also known as Encapsulated Remote Switched Port Analyzer (SPAN), enables monitoring of traffic from multiple sources distributed over multiple switches. This monitored traffic is then delivered to the ERSPAN destination switch via IP network.
Do the following to configure ERSPAN Mirroring where the source port is a Physical Ethernet port and the destination ports are a RSPAN VLAN and another Physical Ethernet port.
SLX# configure terminal
SLX (config)# interface ethernet 0/2
SLX (conf-if-eth-0/2)# lldp disable
SLX (conf-if-eth-0/2)# exit
SLX (config)# monitor session 32 SLX (config-session-32)#
SLX (config-session-32)# source ethernet 0/1 destination erspan 1 source-ip 10.10.10.1 destination-ip 10.20.20.1 vrf vrf-for-erspan direction both SLX (config-session-28)#
The ingress traffic on ethernet port 0/1 will now be mirrored to the IP 10.20.20.1 over GRE tunnel.
This example summarizes the above configuration
SLX# configure terminal SLX (config)# interface ethernet 0/3 SLX (conf-if-eth-0/3)# lldp disable SLX (conf-if-eth-0/3)# exit SLX (config)# monitor session 32 SLX (config-session-32)# source ethernet 0/1 destination erspan 1 source-ip 10.10.10.1 destination-ip 10.20.20.1 vrf vrf-for-erspan direction both
This example shows the configuration of ERSPAN mirroring from a source port channel port to a destination IP over GRE.
SLX (config)# monitor session 33 SLX (config-session-33)# source port-channel 1 destination erspan 1 source-ip 10.10.10.1 destination-ip 10.20.20.1 vrf vrf-for-erspan direction both
This example shows the configuration of ERSPAN mirroring from a VE (ve 1) to an specific destination IP(10.20.20.1). This traffic is directed over IP GRE tunnel with a source IP (10.10.10.1).
SLX (config)# monitor session 34 SLX (config-session-34)# source ve 1 destination erspan 1 source-ip 10.10.10.1 destination-ip 10.20.20.1 direction rx vrf vrf-for-erspan flow-based SLX (config-session-34)# exit
This example shows the configuration of ERSPAN mirroring from a VLAN (vlan 100) to an specific destination IP(10.20.20.1). This traffic is directed over IP GRE tunnel with a source IP (10.10.10.1).
SLX (config)# monitor session 34 SLX (config-session-34)# source vlan 100 destination erspan 1 source-ip 10.10.10.1 destination-ip 10.20.20.1 direction rx vrf vrf-for-erspan flow-based SLX (config-session-34)# exit