ERSPAN Installation: Difference between revisions

From Allegro Network Multimeter Manual
Jump to navigation Jump to search
Access restrictions were established for this page. If you see this message, you have no access to this page.
(Created page with "This section describes the '''ERSPAN installation''' for the Allegro Network Multimeter. '''ERSPAN''' is the abbreviation for ''Encapsulated Remote Switch Port Analyzer''. It...")
 
No edit summary
Line 5: Line 5:
=== What is the '''ERSPAN''' mode ===
=== What is the '''ERSPAN''' mode ===


The Allegro Network Multimeter works in the '''mirror port mode''' as a traffic receiving device that . It will '''NOT''' send any traffic on the measurement Ethernet ports.
The '''ERSPAN''' is an advanced switch feature that encapsulates mirrored traffic into an IP and GRE packet. The full method is described in the RFC draft [https://tools.ietf.org/html/draft-foschiano-erspan-03 https://tools.ietf.org/html/draft-foschiano-erspan-03].
 
The advantage of the '''ERSPAN''' mode is that it can be routed via IP and the ERSPAN generator can be at a different location than the Allegro network Multimeter. This allows very simple captures of a low-bandwidth remote device when.


=== How should the '''ERSPAN''' mode be used ===
=== How should the '''ERSPAN''' mode be used ===


The '''ERSPAN''' quality depends on the switch performance and the bandwidth and latency between the switch and the Allegro.
The '''ERSPAN''' quality depends on the switch performance and the bandwidth and latency between the switch and the Allegro. It will also add substantial load to the IP networks and can generate a packet storm when the ERSPAN packets themself are mirrored again into the ERSPAN tunnel.
 
See [[#Limitations]] for more details.
 
=== Where can I configure the '''ERSPAN''' mode ===
 
Please refer to you switch manual how to set up a switch ERSPAN channel.
 
The '''ERSPAN''' mode can be configured at '''Settings''' → '''Global Settings''' → '''Expert Settings''' → '''L3 Tunnel mode'''.
[[File:L3 tunnel mode.png|800px]]
 
You can enable the ERSPAN mode in parallel to the [[In-Line Installation]] or [[Mirror Port, TAP and Packet Broker Installation]] for one or multiple ports. Please be aware that the ERSPAN cannot work in parallel with the bridge mode for such a port.


The data plane ports of the Allegro should be connected in the '''mirror port mode''' to one or multiple mirror ports on a switch. The management port of the Allegro shall be connected to a regular switch port or to the out-of-band management switch.


See [[#Limitations]] for more details.


=== Where can I configure the '''Mirror Port Mode''' ===


Please refer to you switch manual how to set up a switch port as mirror port.


The '''Mirror Port Mode''' for the Allegro can be configured at '''Settings''' → '''Global Settings''' → '''Packet processing mode'''. The Interfaces can be configured to '''Bridge Mode''' or '''Sink Mode'''. The '''Sink Mode''' will disable the packet forwarding and sending on the Ethernet ports. Please switch to '''Sink Mode''' and save the settings at the bottom of the page
[[File:Sink mode.png|800px]]


== Data Plane Ports of Allegro Network Multimeters ==
== Data Plane Ports of Allegro Network Multimeters ==

Revision as of 13:48, 27 March 2020

This section describes the ERSPAN installation for the Allegro Network Multimeter. ERSPAN is the abbreviation for Encapsulated Remote Switch Port Analyzer. It is switch feature that encapsulates traffic into an IP/GRE tunnel.

General

What is the ERSPAN mode

The ERSPAN is an advanced switch feature that encapsulates mirrored traffic into an IP and GRE packet. The full method is described in the RFC draft https://tools.ietf.org/html/draft-foschiano-erspan-03.

The advantage of the ERSPAN mode is that it can be routed via IP and the ERSPAN generator can be at a different location than the Allegro network Multimeter. This allows very simple captures of a low-bandwidth remote device when.

How should the ERSPAN mode be used

The ERSPAN quality depends on the switch performance and the bandwidth and latency between the switch and the Allegro. It will also add substantial load to the IP networks and can generate a packet storm when the ERSPAN packets themself are mirrored again into the ERSPAN tunnel.

See #Limitations for more details.

Where can I configure the ERSPAN mode

Please refer to you switch manual how to set up a switch ERSPAN channel.

The ERSPAN mode can be configured at SettingsGlobal SettingsExpert SettingsL3 Tunnel mode. L3 tunnel mode.png

You can enable the ERSPAN mode in parallel to the In-Line Installation or Mirror Port, TAP and Packet Broker Installation for one or multiple ports. Please be aware that the ERSPAN cannot work in parallel with the bridge mode for such a port.




Data Plane Ports of Allegro Network Multimeters

Devices with built-in Network Ports

The Allegro 200, 500, 1000, 1200, 3000 and 3200 have built-in physical network ports.

Device Picture Number of Monitoring Ports Remarks
Allegro 200 Allegro-200 back cut.jpg 2
Allegro 500 Allegro-500 back cut.jpg
Allegro-500 front cut.jpg
4
Allegro 1000
Allegro 3000
Allegro-1000 front cut.jpg 7 Can be extended by extension cards.
Allegro 1200
Allegro 3200
Allegro-1200-front cut.jpg 7 Can be extended by extension cards.
Allegro x300
Allegro x500
none The Allegro x300 and x500 series do not have built-in network ports, see section extension cards below.

Devices with port extension cards

All Allegros with network card extension slots support the Mirror Port Mode. All extension cards have either 2 or 4 network ports.

Bypass extension cards

The bypass cards for the Allegro Network Multimeter deliver a fail-over when the software bypass is not active in Bridge Mode ( see In-Line Installation for more details ). The bypass is deactivated when the When the Mirror Port Mode / Sink Mode is active.

Grouping of multiple Links ( Trunk vs. separate links )

By default, the Allegro processes all incoming traffic as one big pipe and it does not use the port as an criteria to separate links. If you have connected separate links at the Allegro, please use the virtual link grouping feature to specify which ports belong together.

This feature can also be used to forward multiple links with a packet broker to one Allegro port with VLANs as a separation.

Limitations

Switch Limitations

Please be aware that the Allegro Network Multimeter can only analyze packets that have been forwarded by the switch port. Please also be aware that the exact packet timing and ordering depends on the switch implementation. Allegro recommends the installation of a TAP to prevent any switch side effects.