Routelearn.net
Course menu

Course 4: VLANs and TrunksLesson 1.4 (4 of 7 in this course)12 of 91 in the CCNA series

RSPAN

Mirroring traffic from a port on one switch to a packet analyser plugged into another switch.

Advanced · 6 min read · Before this: VLAN

RSPAN (Remote Switched Port Analyzer) is a Cisco feature that copies traffic from source ports or VLANs on one switch and carries the copies across trunk links in a dedicated RSPAN VLAN to a destination port on another switch, where a packet analyser captures them.

In simple terms: RSPAN lets you watch the traffic of a device on one switch with a capture tool plugged into a different switch.

The situation

A server on Floor 1 has intermittent problems and you want to capture its traffic, but your packet analyser is on Floor 3. Plain SPAN (port mirroring) copies traffic to another port on the same switch. RSPAN (Remote SPAN) carries those copies across switches inside a dedicated RSPAN VLAN.

What happens

trunktrunkServerGi1/0/10SW1 · Floor 1sourceSW2 · Floor 2transitSW3 · Floor 3destinationAnalyserGi1/0/48
  1. 1. Traffic to watch. The server's traffic flows through Gi1/0/10 as usual; nothing about it changes.
  2. 2. Copies ride the RSPAN VLAN. SW1 copies every frame and sends the copies into RSPAN VLAN 900 across the trunks.
  3. 3. Delivered to the analyser. SW3 takes the copies out of VLAN 900 and sends them to the analyser's port.

Why it needs a special VLAN: an RSPAN VLAN behaves differently from a normal one. MAC learning is turned off and the copies are simply flooded along the path, because they're not really addressed to anyone on that VLAN. Never put user devices in it, and allow it on every trunk along the path.

Cisco configuration

Every switch on the path (SW1, SW2, SW3)

vlan 900 remote-span

Marks VLAN 900 as an RSPAN VLAN. It must also be allowed on the trunks between the switches.

SW1 (source)

monitor session 1 source interface GigabitEthernet1/0/10 both monitor session 1 destination remote vlan 900

Copy traffic in both directions on the server's port into RSPAN VLAN 900.

SW3 (destination)

monitor session 1 source remote vlan 900 monitor session 1 destination interface GigabitEthernet1/0/48

Take whatever arrives in VLAN 900 and send it to the analyser's port.

How to verify

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show monitor session 1
Session 1
---------
Type                     : Remote Source Session
Source Ports             :
    Both                 : Gi1/0/10
Dest RSPAN VLAN          : 900
On SW1, Remote Source Session with the right source port and Dest RSPAN VLAN: 900. On SW3 you should see a Remote Destination Session with VLAN 900 as the source and Gi1/0/48 as the destination. Also check show interfaces trunk: VLAN 900 must be allowed on every trunk in between.

Practice

Predict · scenario 1

Sessions on SW1 and SW3 look correct, but the analyser sees nothing. SW2's trunks allow only VLANs 10 and 20.

Predict · scenario 2

Someone puts a printer's access port into VLAN 900.