The situation
A server on Floor 1 has intermittent problems and you want to capture its traffic, but your packet analyser is on Floor 3. Plain SPAN (port mirroring) copies traffic to another port on the same switch. RSPAN (Remote SPAN) carries those copies across switches inside a dedicated RSPAN VLAN.
What happens
- 1. Traffic to watch. The server's traffic flows through Gi1/0/10 as usual; nothing about it changes.
- 2. Copies ride the RSPAN VLAN. SW1 copies every frame and sends the copies into RSPAN VLAN 900 across the trunks.
- 3. Delivered to the analyser. SW3 takes the copies out of VLAN 900 and sends them to the analyser's port.
Why it needs a special VLAN: an RSPAN VLAN behaves differently from a normal one. MAC learning is turned off and the copies are simply flooded along the path, because they're not really addressed to anyone on that VLAN. Never put user devices in it, and allow it on every trunk along the path.
Cisco configuration
Every switch on the path (SW1, SW2, SW3)
vlan 900
remote-spanMarks VLAN 900 as an RSPAN VLAN. It must also be allowed on the trunks between the switches.
SW1 (source)
monitor session 1 source interface GigabitEthernet1/0/10 both
monitor session 1 destination remote vlan 900Copy traffic in both directions on the server's port into RSPAN VLAN 900.
SW3 (destination)
monitor session 1 source remote vlan 900
monitor session 1 destination interface GigabitEthernet1/0/48Take whatever arrives in VLAN 900 and send it to the analyser's port.
How to verify
SW1#show monitor session 1 Session 1 --------- Type : Remote Source Session Source Ports : Both : Gi1/0/10 Dest RSPAN VLAN : 900
show interfaces trunk: VLAN 900 must be allowed on every trunk in between.Practice
Sessions on SW1 and SW3 look correct, but the analyser sees nothing. SW2's trunks allow only VLANs 10 and 20.
Someone puts a printer's access port into VLAN 900.