Cisco Systems switch newbie - rspan over wan possible?

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
switch newbie - rspan over wan possible? jlmjlist 08-06-08
Posted by jlmjlist on August 6, 2008, 9:38 am
Please log in for more thread options


I can't get this to work and now wonder if it's even possible.
If possible how do I config intermediate 2621 router to handle rspan
traffic.
I have RSPAN working on LAN.
Thanks for any hints, etc.

Posted by Trendkill on August 6, 2008, 2:09 pm
Please log in for more thread options


> I can't get this to work and now wonder if it's even possible.
> If possible how do I config intermediate 2621 router to handle rspan
> traffic.
> I have RSPAN working on LAN.
> Thanks for any hints, etc.

I don't think this is possible. The way a RSPAN works (from my old
experience), is that a switch will copy each frame/packet into a
special RSPAN VLAN. Then any node in any switch on that vlan, can
'sniff' the traffic. Of course we have to then understand that the
RSPAN vlan would need to available in all switches (i.e. trunked).
Unless you are doing l2 over the WAN, I don't see how this would
work. Not to mention the major concerns I have about copying all LAN
traffic to a particular node of VLAN over a limited bandwidth WAN.
Not to say you don't know what you are doing (I'm sure you are aware
of your network limitations), but I would be very careful in this
circumstance.

Posted by Trendkill on August 6, 2008, 2:13 pm
Please log in for more thread options


>
> > I can't get this to work and now wonder if it's even possible.
> > If possible how do I config intermediate 2621 router to handle rspan
> > traffic.
> > I have RSPAN working on LAN.
> > Thanks for any hints, etc.
>
> I don't think this is possible. =A0The way a RSPAN works (from my old
> experience), is that a switch will copy each frame/packet into a
> special RSPAN VLAN. =A0Then any node in any switch on that vlan, can
> 'sniff' the traffic. =A0Of course we have to then understand that the
> RSPAN vlan would need to available in all switches (i.e. trunked).
> Unless you are doing l2 over the WAN, I don't see how this would
> work. =A0Not to mention the major concerns I have about copying all LAN
> traffic to a particular node of VLAN over a limited bandwidth WAN.
> Not to say you don't know what you are doing (I'm sure you are aware
> of your network limitations), but I would be very careful in this
> circumstance.

I think you are looking for Encapsulated Remote Span (ERSPAN). ERSPAN
will work over a routed network, but not sure your gear will support
you. Here are a few links:

http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/nativ=
e/configuration/guide/span.html#wp1059482

http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/nativ=
e/configuration/guide/span.html#wp1063324'

These are for a 6500 series, so you'll need to check your switch code
and your WAN. Very possible, but if I had to guess on a 2621, you are
probably out of luck.

Similar ThreadsPosted
switch newbie - rspan over wan possible? August 6, 2008, 9:38 am
Newbie ACL Help on Cisco Switch November 10, 2005, 12:49 pm
Newbie question - What's wrong with my switch? April 27, 2008, 7:50 pm
RSPAN no workie... December 16, 2005, 6:04 pm
4500 RSPAN ?? Does it work? January 30, 2006, 4:06 pm
Combined SPAN and RSPAN July 10, 2006, 6:18 am
RSPAN Ingress Problem July 25, 2007, 9:11 am
RSPAN Trunked port - 6509 October 27, 2005, 7:46 pm
RSPAN Trunked port - 6509 October 27, 2005, 7:46 pm
Switch/Switch problem fibre gigbit ethernet September 6, 2005, 12:33 pm
turn part of the cisco switch into a plain switch February 13, 2007, 1:27 am
trunking between Cisco Catalyst 500 switch and other type of switch March 28, 2006, 1:13 am
VLAN - switch -> trunk -> switch - priority queuing ? August 19, 2006, 2:31 pm
why cisco 2950 switch is called as catalyst switch December 8, 2006, 10:40 am
2950 switch to switch question July 17, 2007, 11:35 pm