Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureHard

A network security team needs to capture traffic from multiple VLANs traversing a core switch and send it to a centralized security appliance located in a different data center, several hops away. The security appliance only has a single network interface. Which SPAN variant is best suited for this requirement, considering the remote location and the need to encapsulate the mirrored traffic?

  1. APort-based SPAN
  2. BRemote SPAN (RSPAN) VLAN
  3. CEncapsulated Remote SPAN (ERSPAN)
  4. DLocal SPAN (LSPAN)
Show answer & explanation

Correct answer: C. Encapsulated Remote SPAN (ERSPAN)

Encapsulated Remote SPAN (ERSPAN) is designed for mirroring traffic from source ports/VLANs distributed across multiple switches and sending it to a destination session on a different switch over a routed network. It encapsulates the mirrored traffic in a GRE tunnel, allowing it to traverse Layer 3 boundaries and reach a remote destination.

Why the other options are wrong

  • A. Port-based SPAN is a form of LSPAN, mirroring traffic from a specific port on the same switch, not suitable for remote, multi-VLAN monitoring.
  • B. RSPAN VLAN extends monitoring across multiple switches within the same Layer 2 domain (VLAN), but cannot cross Layer 3 boundaries.
  • D. LSPAN only mirrors traffic to a destination port on the same switch, not suitable for remote monitoring across routed networks.

Encapsulated Remote SPAN (ERSPAN)

A Cisco feature that allows mirroring traffic from source ports/VLANs on a switch and sending it to a destination port on a different switch or analyzer across a Layer 3 network by encapsulating the mirrored traffic in a GRE tunnel.

  • Supports monitoring across Layer 3 boundaries.
  • Encapsulates mirrored traffic using GRE.
  • Requires source and destination ERSPAN sessions.

Memory trick: ERSPAN: Encapsulate Remotely, Span Everywhere

More Infrastructure questions