• Forums
    • Public Forums
      • Community Connect
      • Dynatrace
        • Dynatrace Open Q&A
      • Application Monitoring & UEM
        • AppMon & UEM Open Q&A
      • Network Application Monitoring
        • NAM Open Q&A
  • Home /
  • Public Forums /
  • Network Application Monitoring /
  • NAM Open Q&A /
avatar image
Question by Wei D. · May 20, 2015 at 06:49 AM ·

ERSPAN v.s Promisc Mode

Dear All,

I've encountered a conflict when try to monitor the traffic in VM deployed on EXSi 5.1 using ERSPAN, ERSPAN requires an IP address on the destined network interface to span the network traffic, but AMD can not be configured to capture those traffic on the destined network interface if IP address is configured, can AMD set the network interface with IP address to capture mode? has anyone experienced such problem before? any suggestion is highly appreciated.

The AMD is installed in VM as well, on different host from the monitored applications.

Thanks a lot!

-Wei

Comment

People who like this

0 Show 0
10 |2000000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Toggle Comment visibility. Current Visibility: Viewable by all users

Up to 10 attachments (including images) can be used with a maximum of 50.0 MiB each and 250.0 MiB total.

3 Replies

  • Sort: 
  • Most voted
  • Newest
  • Oldest
avatar image

Answer by Mike H. · May 21, 2015 at 02:24 AM

The IP address on the ERSPAN is not necessarily connected to the  destination interface of the AMD it is specifically used to terminate the tunnel and can simply belong to the switch itself, you can also then use local SPAN to take the ERSPAN destination port and "mirror" it to the desired output/destination port. As Chris points out the AMD is not capable of terminating ERSPAN, which is why it needs to be terminated on the switch itself. There may be other caveats associated with this which is why you're not seeing any traffic on the AMD, for ERSPAN to work any switch or device the tunnel passes through must be capable of supporting ERSPAN otherwise the header will not be recognized and teh tunnel will not establish correctly. In your set up how do you traverse between the two enclosures, you need to ensure that any devices on that interacting path is ERSPAN capable.

Comment
Antoine B.

People who like this

1 Show 0 · Share
10 |2000000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Toggle Comment visibility. Current Visibility: Viewable by all users

Up to 10 attachments (including images) can be used with a maximum of 50.0 MiB each and 250.0 MiB total.

avatar image

Answer by Chris V. · May 20, 2015 at 11:46 PM

The AMD isn't a ERSPAN destination, so can't receive that traffic.

Now - the following is unsupported/untested, just something I've given some thought to as this has been raised at a customer I deal with.

There are two (that I know of) potential options to add ERSPAN end point capability to a linux server, these may or may not - I never got to a testing phase as I don't have a switch that can do ERSPAN available to me - work.

  • Gulp - http://staff.washington.edu/corey/gulp/
  • RCDCap - http://sourceforge.net/projects/rcdcap/

 

Comment
Antoine B.

People who like this

1 Show 0 · Share
10 |2000000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Toggle Comment visibility. Current Visibility: Viewable by all users

Up to 10 attachments (including images) can be used with a maximum of 50.0 MiB each and 250.0 MiB total.

avatar image

Answer by Ulf T. · May 21, 2015 at 08:46 AM

As always - looking at virtual TAPs is a viable option, though not cost neutral.

They usually have the capbilities to direct themselves to other ports and enclosures and specifically designed to do so, something that isn't always the case with the various SPAN capabilites that initially was a bolt on solution to get insight into switches and now how become a troublesome legacy solution.

Comment

People who like this

0 Show 0 · Share
10 |2000000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Toggle Comment visibility. Current Visibility: Viewable by all users

Up to 10 attachments (including images) can be used with a maximum of 50.0 MiB each and 250.0 MiB total.

How to get started

First steps in the forum
Read Community User Guide
Best practices of using forum

NAM 2019 SP5 is available


Check the RHEL support added in the latest NAM service pack.

Learn more

LIVE WEBINAR

"Performance Clinic - Monitoring as a Self Service with Dynatrace"


JANUARY 15, 3:00 PM GMT / 10:00 AM ET

Register here

Follow this Question

Answers Answers and Comments

2 People are following this question.

avatar image avatar image

Forum Tags

esm siebel Dynatrace Managed license nam probe wan citrix dna rest api configuration mq alerting NAM 2018 dashboard dcrumadvisory reports css nam universal decode database mobileapp RUM ads sap nam console scripting nam server sequence transactions nam 2019 upgrade
  • Forums
  • Public Forums
    • Community Connect
    • Dynatrace
      • Dynatrace Open Q&A
    • Application Monitoring & UEM
      • AppMon & UEM Open Q&A
    • Network Application Monitoring
      • NAM Open Q&A