Encapsulated Remote Switched Port Analyzer
Feature Overview
ERSPAN allows you to mirror traffic from a switch port and send it to a remote analysis device across a Layer 3 network. It encapsulates mirrored packets using GRE and transmits them through a Layer 3 tunnel, with the full original packet included in the GRE payload.
You can configure ERSPAN to monitor ingress, egress, or bidirectional traffic on a given port. It supports mirroring between any ports, regardless of port type or module configuration. The GRE tunnel must terminate on an external analysis host; it cannot terminate on the switch itself.
ERSPAN is disabled by default.
The following figure shows a typical ERSPAN data flow. In the figure, traffic going into and out of the monitor port (in this case, traffic between Host 2 and Host 3) is also sent to Host 1 across the ERSPAN tunnel.
Requirements
This feature requires the following conditions for enablement and usage:
Considerations
Consider the following when configuring and using this feature:
- ERSPAN operates in Layer 3 environments only.
- GRE tunneling must be supported across the routed path between the switch and the analysis host.
- The GRE tunnel cannot be terminated on the switch.
- Support is added for ICX 8200 devices in FastIron 10.0.10h_cd1.
- Speed mismatches between the source and destination interfaces can cause packet drops or incomplete mirroring.
- ERSPAN has not been validated with third-party implementations; interoperability may vary.
- Enabling ERSPAN can increase CPU and memory usage, particularly in high-throughput environments.
- A maximum of four active mirroring sessions are allowed per device.
Limitations
Note the following limitations regarding this feature:
- RUCKUS ICX 7150, ICX 7150-ES, and ICX 8100 devices do not support ERSPAN.
- VLAN-based mirroring is not supported.
- Source IP addresses must be configured from the default VRF; non-default VRFs are not supported.
- Performance may degrade if there are interface speed mismatches or excessive mirrored traffic.
Best Practices
- Set up your analysis host to receive and process GRE-encapsulated packets before enabling ERSPAN to ensure mirrored traffic is captured and interpreted correctly without loss or misrouting.
- Match interface speeds between the source and analyzer ports to prevent packet drops caused by speed mismatches, which can compromise traffic analysis accuracy.
- Monitor system resource usage during active ERSPAN sessions, especially in high-traffic environments, to avoid performance degradation due to increased CPU and memory load.
- Maintain a clear record of mirroring configurations—including source and destination IPs, session directions, and VRF assignments—to simplify troubleshooting and support future scalability.
