Configuring an ERSPAN Profile

The following task configures an Encapsulated Remote Switched Port Analyzer (ERSPAN) profile to define a tunnel over a Layer 3 network from a router to a remote host. This allows mirrored packets to be sent to the remote host.

Ensure the router has a configured IP on at least one of its interfaces.

  1. Enter global configuration mode.
    device# configure terminal
    
  2. Create an ERSPAN profile and assign it a number.
    device(config)# monitor-profile 1 type erspan
    
    monitor-profile configuration mode is enabled.
  3. Enter the IP address of the source router.
    device(config-monitor-profile 1)# source-ip 10.1.1.1
    
    The IP address can be any address configured on the router.
  4. Enter the IP address of the destination host.
    device(config-monitor-profile 1)# destination-ip 1.1.1.1
    
    The IP address is for the host that is collecting the mirrored traffic, not the device.
  5. Exit monitor-profile mode.
    device(config-monitor-profile 1)# exit
    
  6. Verify the configuration.
    device(config)# show erspan profile 1
    Profile 1
    Type             ERSPAN
    Mirror destination reachable.*/Error condition - Mirror destination Not reachable/*
    Destination IP   10.1.1.100
    Destination MAC  0000.0000.0000
    Source IP        10.1.1.1
    Source MAC       cc4e.0000.0000
    Ports monitored:
      Input monitoring      : (U1/M1)   1 
      Output monitoring     : (U1/M1)   1 
    HW destination id for each device:
    stack_id/device:dest_id
    
    If Mirror destination Not reachable. appears in the output, refer to Troubleshooting ERSPAN reachability errors.

The following example configures an ERSPAN profile to define a tunnel over a Layer 3 network from a router to a remote host.

device# configure terminal
device(config)# monitor-profile 1 type erspan
device(config-monitor-profile 1)# source-ip 10.1.1.1
device(config-monitor-profile 1)# destination-ip 10.1.1.100

Next, you need to configure the monitor port.