Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

SPAN on ASR9K just doesn't work

I'm confused and none of the documents I'm reading is helping.  I'm trying to do a local SPAN session on an ASR9K.  I'm using source ports that are sub-interfaces, like te0/4/0/5.1024 (but do not have the "l2transport" option enabled).  My destination port is l2transport, I only see broadcast traffic from those links come into the sniffer, never any type of regular traffic.  I have never been able to get this to work.  My config is below, what am I not understanding here?

monitor-session MONTEST

destination interface GigabitEthernet0/3/0/18

!

interface GigabitEthernet0/3/0/18

description sniffer port

l2transport

!

interface TenGigE0/4/0/5.1024

description Monitored Port

vrf EX-DEM

ipv4 address 61.8.44.1 255.255.255.252

monitor-session MONTEST

!

encapsulation dot1q 1024

!

tm

3 REPLIES
Cisco Employee

SPAN on ASR9K just doesn't work

hi tm,

you probably need an acl on l3 interfaces that have a capture keyword on them.

see section L3 Spanning Example from https://supportforums.cisco.com/docs/DOC-15772

regards

xander

Xander Thuijs CCIE #6775 Principal Engineer ASR9000, CRS, NCS6000 & IOS-XR
New Member

Re: SPAN on ASR9K just doesn't work

This is my config I just tried.  Still, no packets.  I removed the bundle-ether interface that I was also looking at to get rid of the LACP messages.  So only the L2 broadcasts were coming across, I can't seem to pick up any L3 traffic and this is so frustrating becuase it would take me 2 secs to have this working on a 7600.

ipv4 access-list SPAN

10 permit ipv4 any any capture

20 permit icmp any any capture

30 permit ipv4 any any

!

interface TenGigE0/4/0/5.1024

description Monitored Port

vrf EX-DEM

ipv4 address 61.8.44.1 255.255.255.252

monitor-session MONTEST

  acl

!

encapsulation dot1q 1024

ipv4 access-group SPAN ingress

ipv4 access-group SPAN egress

!

Cisco Employee

SPAN on ASR9K just doesn't work

your config seems fine with this Tm.

can you check the np counters for the NP attached to the te 0/4/0/5 interface to make sure packets are captured by the span and acl for replication.

also what version are you using for this exercise? and what smu's do you have installed? there have been some span issues and I want to rule out those from playing up on us here.

regards

xander

Xander Thuijs CCIE #6775 Principal Engineer ASR9000, CRS, NCS6000 & IOS-XR
214
Views
0
Helpful
3
Replies