Home > Networking Tips > Routing and Switching > Cisco's RSPAN
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

ROUTING AND SWITCHING

Cisco's RSPAN


Tom Lancaster
02.08.2005
Rating: -3.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Traffic-collecting devices such as IDS probes and protocol analyzers have often frustrated network administrators because they never seem to be where you need them. This is particularly true in remote offices, where these devices are permanently fixed. While it's easy to "span" or "mirror" the port you need to do the probe, all too often, the port you need is on a different switch, in a closet far away. Inevitably, valuable time is wasted dispatching someone to move the probe into the right closet, and configure that switch appropriately.

While it's true that in most of these remote-office cases, the traffic you want to capture passes through the core of your network, from an architectural purist's perspective, that's the last place you want to be spanning ports. Recall that cores are high-speed, low-drag; things like filtering, PBR, and spanning can cause serious performance problems and belong much closer to the end-points.

A much better solution is RSPAN, which is like the regular span, except that it uses a special VLAN on trunks between switches to carry the traffic you want to see. Of course, you've always been able to front-panel-connect a span port to a VLAN and trunk it all over your campus, but the RSPAN feature solves an otherwise tricky problem: it disables MAC address learning so all traffic is flooded. Another problem is that it's possible that QoS schemes in intermediate switches could even change the order of the packets, confusing your analyzer or IDS/IPS.

The downside though, is that due to the nature of the VLAN trunking mechanisms RSPAN uses, don't expect to get your layer 2 control traffic to your probe or things like collisions. And if you do use RSPAN, it's probably wise to rate limit this traffic so that you don't accidentally use up all your bandwidth and starve production data. Whether you intentionally affect it, or just let the switches give it "best effort", keep in mind that the timestamps in your trace files will all be different than when they were originally transmitted.

You can find implementation details for RSPAN features on www.cisco.com.


Tom Lancaster, CCIE# 8829 CNX# 1105, is a consultant with 15 years experience in the networking industry, and co-author of several books on networking, most recently, CCSPTM: Secure PIX and Secure VPN Study Guide published by Sybex.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Hardware
Unified wireless network still a work in progress for vendors
3Com acquisition confirms HP-Cisco battle for China
Juniper to CIOs: Invest in internal cloud computing networks
802.11n wireless APs bring IP video to sprawling Illinois high school
802.11n upgrade: College ditches legacy network for new vendor
Network device management overload: Engineers managing too many boxes
What is network infrastructure and what is a hybrid network?
What preventative maintenance procedures for network devices exist?
Can wireless adapters operate as client access points to make SoftAPs?
Is there VLAN software recommend for Realtek NICs?
Network Hardware Research

Routing and Switching
How to test LAN switch energy efficiency
Testing LAN switch power consumption: A best practices guide
Dynamic IP routing and routing protocols
Monitor your network traffic with MRTG
How routers work: An overview for networking pros
Secure Cisco routers against IOS flaw attack
Network summarization -- Supernetting and wildcard masks
Routing: Five common, easily avoided errors
Router Expert: Building a WLAN proxy server, implementing ASR
Router Expert: Building a WLAN proxy server, implementing WPAD

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
core router  (SearchNetworking.com)
fiber jumper  (SearchNetworking.com)
flow routing  (SearchNetworking.com)
foreign agent  (SearchNetworking.com)
foreign network  (SearchNetworking.com)
hardware load-balancing device  (SearchNetworking.com)
logical router  (SearchNetworking.com)
mrouter  (SearchNetworking.com)
patch cord  (SearchNetworking.com)
port interface card (PIC)  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts