Forward ERSPAN at the local Router

Unanswered Question
Dec 19th, 2009

Hello everybody,

I configured erspan on the remote and the local router and it works fine. For sniffing the packets I have to connect the packet sniffer (e.g. wireshark on a laptop) to an interface on the local router (i.e. the destination of the erspan traffic), but I want to connect the packet sniffer to a switch connected to the local router (because I am sitting behind the local switch). The problem is that the local router (a catalyst 6509) allows to forward the erspan traffic only to a hard interface (gigaethernet, tengigaeth) but not to a vlan or loopback. The switch and the local router are of course connected via a trunk, so actually I can configure rspan on the local switch but the problem the packet sniffer will see the whole traffic of the trunk link and not only the desired erspan traffic. Any solutions without crating a new link between the local router and the switch?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
scrye Fri, 04/15/2011 - 13:39

Just a wild guess, wonder if a VACL might help. I have no experience with VACLs, but they seem to be able to do many things ...



This Discussion

Related Content