hardware:erspan
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| hardware:erspan [2018/05/01 21:28] – [Why ERSPAN for Network Monitoring] veera | hardware:erspan [2018/05/01 21:38] (current) – [On MTU and packet sizes] veera | ||
|---|---|---|---|
| Line 24: | Line 24: | ||
| To provide network packets to Trisul Network Analytics or other NSM tool running inside a Virtual Machine. Particularly when the administrators of the VM are unable to provide a promiscuous mode physical interface. | To provide network packets to Trisul Network Analytics or other NSM tool running inside a Virtual Machine. Particularly when the administrators of the VM are unable to provide a promiscuous mode physical interface. | ||
| + | |||
| + | Recently, we had a customer who was consolidating all their server systems on a Nutanix VM farm. They wanted to put TrisulNSM also on a VM on that farm instead of a physical box. Since the Nutanix does not yet support a physical port mirror at the VM level (( Nutanix [[https:// | ||
| ==== ERSPAN Use case 2 : Temporary monitoring ==== | ==== ERSPAN Use case 2 : Temporary monitoring ==== | ||
| - | When you want to temporarily monitor an interface without having to do any extra cabling that would be required for a physical layer SPAN. If you are already doing ERSPAN, then adding an extra port is trivial. | + | If you are already doing ERSPAN, then adding an extra port is trivial. |
| Line 36: | Line 38: | ||
| In ERSPAN, there is a concept of Source and Destination session. A //source session// specifies interfaces from which traffic is captured | In ERSPAN, there is a concept of Source and Destination session. A //source session// specifies interfaces from which traffic is captured | ||
| - | Here we only configure a //source ERSPAN session// to the IP address of the TrisulNSM Virtual Machine. | + | Here we only configure a //source ERSPAN session// to the IP address |
| <code cisco> | <code cisco> | ||
| Line 49: | Line 51: | ||
| no shutdown | no shutdown | ||
| </ | </ | ||
| + | |||
| + | ==== On MTU and packet sizes ==== | ||
| + | <note important> | ||
| - | <note important> | + | |
| - | + | ||
| - | | + | |
| - You also need to set the MTU on any bridges you create on the VM infrastructure. | - You also need to set the MTU on any bridges you create on the VM infrastructure. | ||
| - If you dont set the MTU to a higher numbers, then packets will be truncated as per the ERSPAN documentation. Some implementations may fragment the IP packets, which will they place a load on the NSM tool to reassemble the packets. | - If you dont set the MTU to a higher numbers, then packets will be truncated as per the ERSPAN documentation. Some implementations may fragment the IP packets, which will they place a load on the NSM tool to reassemble the packets. | ||
hardware/erspan.1525190306.txt.gz · Last modified: 2018/05/01 21:28 by veera