Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureHard
A network security team needs to capture traffic from multiple VLANs traversing a core switch and send it to a centralized security appliance located in a different data center, several hops away. The security appliance only has a single network interface. Which SPAN variant is best suited for this requirement, considering the remote location and the need to encapsulate the mirrored traffic?
- APort-based SPAN
- BRemote SPAN (RSPAN) VLAN
- CEncapsulated Remote SPAN (ERSPAN)
- DLocal SPAN (LSPAN)
Show answer & explanationAnswer & explanation
Correct answer: C. Encapsulated Remote SPAN (ERSPAN)
Encapsulated Remote SPAN (ERSPAN) is designed for mirroring traffic from source ports/VLANs distributed across multiple switches and sending it to a destination session on a different switch over a routed network. It encapsulates the mirrored traffic in a GRE tunnel, allowing it to traverse Layer 3 boundaries and reach a remote destination.
Why the other options are wrong
- A. Port-based SPAN is a form of LSPAN, mirroring traffic from a specific port on the same switch, not suitable for remote, multi-VLAN monitoring.
- B. RSPAN VLAN extends monitoring across multiple switches within the same Layer 2 domain (VLAN), but cannot cross Layer 3 boundaries.
- D. LSPAN only mirrors traffic to a destination port on the same switch, not suitable for remote monitoring across routed networks.
Encapsulated Remote SPAN (ERSPAN)
A Cisco feature that allows mirroring traffic from source ports/VLANs on a switch and sending it to a destination port on a different switch or analyzer across a Layer 3 network by encapsulating the mirrored traffic in a GRE tunnel.
- Supports monitoring across Layer 3 boundaries.
- Encapsulates mirrored traffic using GRE.
- Requires source and destination ERSPAN sessions.
Memory trick: ERSPAN: Encapsulate Remotely, Span Everywhere