Encapsulated Remote Switched Port Analyzer

Encapsulated Remote Switched Port Analyzer (ERSPAN) mirrors traffic across Layer 3 networks using Generic Routing Encapsulation (GRE) tunneling, allowing you to analyze packets on a device not directly connected to the switch.

Feature Overview

ERSPAN allows you to mirror traffic from a switch port and send it to a remote analysis device across a Layer 3 network. It encapsulates mirrored packets using GRE and transmits them through a Layer 3 tunnel, with the full original packet included in the GRE payload.

You can configure ERSPAN to monitor ingress, egress, or bidirectional traffic on a given port. It supports mirroring between any ports, regardless of port type or module configuration. TThe GRE tunnel must terminate on an external analysis host; it cannot terminate on the switch itself.

ERSPAN is disabled by default.

The following figure shows a typical ERSPAN data flow. In the figure, traffic going into and out of the monitor port (in this case, traffic between Host 2 and Host 3) is also sent to Host 1 across the ERSPAN tunnel.

ERSPAN Data Flow

Requirements

This feature requires the following conditions for enablement and usage:

  • An analysis host capable of terminating and interpreting GRE-encapsulated traffic is required.
  • The source IP address must be configured when defining the ERSPAN session.

Considerations

Consider the following when configuring and using this feature:

  • ERSPAN operates in Layer 3 environments only.
  • GRE tunneling must be supported across the routed path between the switch and the analysis host.
  • The GRE tunnel cannot be terminated on the switch.
  • Speed mismatches between the source and destination interfaces can cause packet drops or incomplete mirroring.
  • ERSPAN has not been validated with third-party implementations; interoperability may vary.
  • Enabling ERSPAN can increase CPU and memory usage, particularly in high-throughput environments.
  • A maximum of four active mirroring sessions are allowed per device.

Limitations

Note the following limitations regarding this feature:

  • RUCKUS ICX 8100 devices do not support ERSPAN.
  • VLAN-based mirroring is not supported.
  • Source IP addresses must be configured from the default VRF; non-default VRFs are not supported.
  • Performance may degrade if there are interface speed mismatches or excessive mirrored traffic.

Best Practices

  • Set up your analysis host to receive and process GRE-encapsulated packets before enabling ERSPAN to ensure mirrored traffic is captured and interpreted correctly without loss or misrouting.
  • Match interface speeds between the source and analyzer ports to prevent packet drops caused by speed mismatches, which can compromise traffic analysis accuracy.
  • Monitor system resource usage during active ERSPAN sessions, especially in high-traffic environments, to avoid performance degradation due to increased CPU and memory load.
  • Maintain a clear record of mirroring configurations—including source and destination IPs, session directions, and VRF assignments—to simplify troubleshooting and support future scalability.

Prerequisites

  • Ensure the network is Layer 3-routed and supports GRE forwarding.
  • Verify that the analysis host is prepared to terminate GRE tunnels and interpret mirrored traffic.