Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureHard
A network security team has detected suspicious traffic patterns originating from multiple internal hosts, suggesting a potential DDoS attack or malware infection. They need to capture and analyze all traffic traversing a specific core switch port that connects to a critical server farm, and send this captured traffic to an intrusion detection system (IDS) located on a different network segment. Which Cisco feature would allow this remote capture and forwarding of traffic?
- AERSPAN
- BNetFlow
- CRSPAN
- DSPAN
Show answer & explanationAnswer & explanation
Correct answer: A. ERSPAN
ERSPAN (Encapsulated Remote SPAN) is the most suitable solution. It allows traffic from a source port or VLAN to be encapsulated into a GRE tunnel and forwarded to a destination on a different network segment, enabling remote analysis by an IDS.
Why the other options are wrong
- B. NetFlow collects flow statistics (who, what, where, when) but does not capture and forward actual packet contents for deep inspection by an IDS.
- C. RSPAN (Remote SPAN) allows mirroring traffic across multiple switches within the same Layer 2 domain (VLANs), but it does not encapsulate traffic for transport across Layer 3 boundaries to an IDS on a different segment.
- D. SPAN (Switched Port Analyzer) mirrors traffic locally on the same switch, which is not suitable for sending traffic to a remote IDS.
ERSPAN
ERSPAN (Encapsulated Remote SPAN) is a Cisco feature that allows monitoring of traffic from source ports/VLANs and encapsulates it into a GRE tunnel for forwarding across Layer 3 networks to a remote destination for analysis.
- Mirrors traffic from source to destination.
- Encapsulates traffic in GRE.
- Transports across Layer 3 boundaries.
- Ideal for remote monitoring by IDS/analyzers.
- Requires source, destination, and GRE tunnel configuration.
Memory trick: ERSPAN's the tunnel, L3's the way, for IDS to see traffic far away.