Users Guide

Table Of Contents
destination# show running-configuration monitor
!
monitor session 1
destination interface ethernet1/1/26:1
flow-based enable
source interface ethernet1/1/12 rx
no shut
destination#
destination# show monitor session all
S.Id Source Destination Dir Mode Source IP Dest IP DSCP TTL Gre-Protocol
State Reason
-----------------------------------------------------------------------------------------
---------
1 ethernet1/1/12 ethernet1/1/26:1 rx flow N/A N/A N/A N/A N/A
true Is UP
NOTE: In OS10, the RSPAN vlan tag is not removed from the mirrored traffic.
View monitoring session
OS10(conf-mon-rpm-source-10)# do show monitor session all
S.Id Source Destination Dir SrcIP DstIP DSCP TTL State Reason
---------------------------------------------------------------
1 vlan10 vlan 100 rx N/A N/A N/A N/A true Is UP
Encapsulated remote port monitoring
You can also have the monitored traffic transmitted over a port-channel network to a remote analyzer. The encapsulated
remote port monitoring (ERPM) session mirrors traffic from the source ports, LAGs, or source VLANs. It forwards the traffic
using routable GRE-encapsulated packets to the destination IP address specified in the session.
Restrictions and limitations
IP address:
The source IP address must be a valid local IP address for the session.
The destination IP address must be on a remote L3 node that supports standard GRE decapsulation.
If the destination IP address is not reachable, the session goes down.
Session:
OS10 supports only the ERPM source session and the encapsulated packets terminate at the destination IP address (the
remote analyzer).
OS10 does not support an ERPM destination session and decapsulation of ERPM packets at the destination switch.
You can configure a maximum of four ERPM sessions with a maximum of 128 source ports in each session. You can configure
the four ERPM sessions by one of the following methods:
Single directional with either four ingress or four egress sessions.
Bi-directional with two ingress and two egress sessions.
Monitor:
You can monitor a source VLAN only through flow-based monitoring. Only ingress is supported in flow-based source VLAN
monitoring.
You cannot monitor an RPM VLAN as a source.
OS10 does not support monitoring VLAN subinterfaces and CPU-generated packets.
Configuration:
You cannot configure an interface with ERPM traffic as a source for an ERPM session.
You cannot configure the same destination IP address for two sessions.
You cannot configure an interface that serves as egress for a GRE tunnel as a source interface.
ERPM supports only GRE-over-IPv4 tunneling.
ERPM does not support Equal Cost Multi Path (ECMP).
You can use third-party devices as only tunnel-transit devices.
710
Layer 2