SPAN是什么
SPAN是一种高效,高性能的流量监控系统,它在横向交换时将网络流量复制到一个或者多个监控接口,SPAN用于解决连接问题,计算网络利用率和性能等
SPAN类型
- RSPAN:
- 所有交换机都需要同一个网络
- 在中间通过二层互联
- ERSPAN(cisco特有)
- 在两个交换机三层可以通就可以
- 把流量封装在GRE的隧道
配置
SPAN的配置
拓扑图: 电脑 - (G0/2)SW1(G0/0) ——(G0/0) SW2(G0/1) ——(G0/1)SW3
SW1
hostname SW1
!
vlan 10
vlan 150
!
interface GigabitEthernet0/0
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet0/2
switchport access vlan 150
switchport mode access
!
interface Vlan10
ip address 10.1.1.11 255.255.255.0
SW2
hostname SW2
!
vlan 10
!
interface GigabitEthernet0/0
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet0/1
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface Vlan10
ip address 10.1.1.12 255.255.255.0
SW3
hostname SW3
!
vlan 10
!
interface GigabitEthernet0/0
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet0/1
switchport access vlan 20
switchport mode access
!
interface Vlan10
ip address 10.1.1.13 255.255.255.0
interface Vlan20
ip address 20.1.1.23 255.255.255.0
把SW1上面配置
monitor session 1 source interfac G0/0 //收集G0/0的流量
monitor session 1 destination interfac G0/2 //发送给G0/2的流量
interfac(接口的流量)/remote(远端的流量)/vlan(vlan的流量)
后面还可以加上流量方向 both rx tx
如果需要修改,推荐首先删除monitor session 1
在指对vlan进行SPAN的时候,如果两个设备在一个vlan下面可以使用RX,如果使用both那么所有的流量都会收到两遍
高级选项
抓取trunk流量,需要Dot1Q封装
monitor session 1 source vlan Gi1/0/2
monitor session 1 destination vlan Gi1/0/23 encapsulation replicate
抓VLAN流量,并且通过Dot1Q来区分VLAN
monitor session 1 source vlan 10,20,30 rx
monitor session 1 destination interface Gi1/0/1 encapsulation dot1q
使用ingress注入数据
monitor session 1 source vlan 10,20,30 rx
monitor session 1 destination interface Gi1/0/1 encapsulation dot1q in
关于接口状态
Gig1/0/1 is up,line protocol is down (monitoring)
删除SPAN
no monitor session 1
RSPAN的配置
配置vlan 500 为rspan
SW1
vlan 500
remote-span
SW2
vlan 500
remote-span
SW3
vlan 500
remote-span
SW3
monitor session 1 source interface G0/1
monitor session 1 destination remote vlan 500
SW1
monitor session 1 destination interface G0/2
monitor session 1 source remote vlan 500
ERSPAN的配置
电脑 -——(g2)R1(g3)——(g2) R2(g3) ——(g2) R3(g3) ——(g2) R4
R1
hostname R1
!
interface GigabitEthernet1
ip address 150.1.7.201 255.255.255.0
!
interface GigabitEthernet2
ip address 172.16.1.1 255.255.255.0
!
interface GigabitEthernet3
ip address 12.1.1.1 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 12.1.1.2
R2
hostname R2
!
interface GigabitEthernet1
ip address 150.1.7.202 255.255.255.0
!
interface GigabitEthernet2
ip address 12.1.1.2 255.255.255.0
!
interface GigabitEthernet3
ip address 23.1.1.2 255.255.255.0
!
ip route 34.1.1.0 255.255.255.0 23.1.1.3
R3
hostname R3
!
interface GigabitEthernet1
ip address 150.1.7.203 255.255.255.0
!
interface GigabitEthernet2
ip address 23.1.1.3 255.255.255.0
!
interface GigabitEthernet3
ip address 34.1.1.3 255.255.255.0
!
ip route 12.1.1.0 255.255.255.0 23.1.1.2
R4
hostname R4
!
interface GigabitEthernet1
ip address 150.1.7.204 255.255.255.0
!
interface GigabitEthernet2
ip address 34.1.1.4 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 34.1.1.3
配置RSPAN,监控R3 G3口 rx 方向的流量,送到12.1.1.1
R3
monitor session 1 type erspan-source
source interface Gi3 rx
no shutdown
destination
erspan-id 101
ip address 12.1.1.1
origin ip address 23.1.1.3 //源地址
R1
monitor session 2 type erspan-destination
destination interface Gi2
no shutdown
source
erspan-id 101
ip address 12.1.1.1
在中间有GRE的封装,但是协议号也不一样