Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ERSPAN from N7K to N1K

Customer has a packet analzyer application on a virtual machine that needs to receive traffic from across their network.  So, we would like to create a monitor session that would be sourced from a physical ASA connected to an N7K, with a destination being a monitoring (promiscuous only) NIC on a virtual machine in ESXi behind a Nexus 1000v.

 

The topology is this:

ASA > N7K > 6248 FIs > 5108 Chassis > B200 M3 blade ESXi > N1K > monitoring NIC on virtual machine.

 

I thought maybe we could do an ERSPAN on the N7K with a destination IP of the virtual machine monitoring NIC, but the vendor says we can't put an IP address on that NIC and must be in promiscuous mode.

 

RSPAN is gone in NX OS, leaving us with only local and ERSPAN types of monitor sessions.  Has anyone ever configured a monitor session such as this?  I have seen countless examples in forum posts and Cisco docs of sourcing FROM the Nexus 1000v to an external device or even itself, but I have yet to see a configuration example where you source it from an N7K, across the FI's, and a destination of a NIC on a virtual machine requiring promiscuous mode behind the Nexus 1000V.

 

Thoughts anyone?

 

Thanks!

Kevin

  • Server Networking
30
Views
0
Helpful
0
Replies