Configuring an ERSPAN Profile

An ERSPAN profile defines a tunnel over a Layer 3 network from a router to a remote host. Mirrored packets can then be sent to this remote host.

The router must have a configured IP on at least one of the interfaces.

  1. Enter global configuration mode.
    device# configure terminal
    
  2. Create an ERSPAN profile and assign it a number.
    device(config)# monitor-profile 1 type erspan
    
    This command puts you in monitor-profile mode.
  3. Enter the IP address of the source router.
    device(config-monitor-profile 1)# source-ip 10.1.1.1
    
    The IP address can be any IP on the router.
  4. Enter the IP address of the destination host.
    device(config-monitor-profile 1)# destination-ip 1.1.1.1
    
    The IP address is for the host that is collecting the mirrored traffic, not the device.
  5. Exit monitor-profile mode.
    device(config-monitor-profile 1)# exit
    
  6. Verify the configuration.
    device(config)# show erspan profile 1
    Profile 1
    Type             ERSPAN
    Mirror destination reachable.*/Error condition - Mirror destination Not reachable/*
    Destination IP   10.1.1.100
    Destination MAC  0000.0000.0000
    Source IP        10.1.1.1
    Source MAC       cc4e.0000.0000
    Ports monitored:
      Input monitoring      : (U1/M1)   1 
      Output monitoring     : (U1/M1)   1 
    HW destination id for each device:
    stack_id/device:dest_id
    
    If Mirror destination Not reachable. appears in the output, see the section Troubleshooting ERSPAN reachability errors.

ERSPAN profile configuration example

device# configure terminal
device(config)# monitor-profile 1 type erspan
device(config-monitor-profile 1)# source-ip 10.1.1.1
device(config-monitor-profile 1)# destination-ip 10.1.1.100
device(config-monitor-profile 1)# exit
device(config)# show erspan profile 1

Next, you need to configure the monitor port.