Encapsulated Remote Switched Port Analyzer

Encapsulated Remote Switched Port Analyzer (ERSPAN) mirrors traffic across Layer 3 networks using Generic Routing Encapsulation (GRE) tunneling, allowing you to analyze packets on a device not directly connected to the switch.

Feature Overview

ERSPAN allows you to mirror traffic from a switch port and send it to a remote analysis device across a Layer 3 network. It encapsulates mirrored packets using GRE and transmits them through a Layer 3 tunnel, with the full original packet included in the GRE payload.

You can configure ERSPAN to monitor ingress, egress, or bidirectional traffic on a given port. It supports mirroring between any ports, regardless of port type or module configuration. The GRE tunnel must terminate on an external analysis host; it cannot terminate on the switch itself.

ERSPAN is disabled by default.

The following figure shows a typical ERSPAN data flow. In the figure, traffic going into and out of the monitor port (in this case, traffic between Host 2 and Host 3) is also sent to Host 1 across the ERSPAN tunnel.

ERSPAN Data Flow

Requirements

This feature requires the following conditions for enablement and usage:

  • An analysis host capable of terminating and interpreting GRE-encapsulated traffic is required.
  • The source and destination IP addresses must be configured when defining the ERSPAN profile. The source IP can be any port on the router. The destination IP is the port on the destination host.

Considerations

Consider the following when configuring and using this feature:

  • ERSPAN operates in Layer 3 environments only.
  • GRE tunneling must be supported across the routed path between the switch and the analysis host.
  • The GRE tunnel cannot be terminated on the switch.
  • Support is added for ICX 8200 devices in FastIron 10.0.10h_cd1.
  • Speed mismatches between the source and destination interfaces can cause packet drops or incomplete mirroring.
  • ERSPAN has not been validated with third-party implementations; interoperability may vary.
  • Enabling ERSPAN can increase CPU and memory usage, particularly in high-throughput environments.
  • A maximum of four active mirroring sessions are allowed per device.

Limitations

Note the following limitations regarding this feature:

  • RUCKUS ICX 7150, ICX 7150-ES, and ICX 8100 devices do not support ERSPAN.
  • VLAN-based mirroring is not supported.
  • Source IP addresses must be configured from the default VRF; non-default VRFs are not supported.
  • Performance may degrade if there are interface speed mismatches or excessive mirrored traffic.

Best Practices

  • Set up your analysis host to receive and process GRE-encapsulated packets before enabling ERSPAN to ensure mirrored traffic is captured and interpreted correctly without loss or misrouting.
  • Match interface speeds between the source and analyzer ports to prevent packet drops caused by speed mismatches, which can compromise traffic analysis accuracy.
  • Monitor system resource usage during active ERSPAN sessions, especially in high-traffic environments, to avoid performance degradation due to increased CPU and memory load.
  • Maintain a clear record of mirroring configurations—including source and destination IPs, session directions, and VRF assignments—to simplify troubleshooting and support future scalability.

Prerequisites

  • Ensure the network is Layer 3-routed and supports GRE forwarding.
  • Verify that the analysis host is prepared to terminate GRE tunnels and interpret mirrored traffic.