Ä¿¡¡Â¼

1 ¾µÏñ... 1

1.1 Ö°ÄܽéÉÜ... 1

1.1.1 ¾µÏñÖ°ÄܸÅÊö... 1

1.1.2 ¸ù»ù¸ÅÏë... 1

1.1.3 ¹¤×÷µÀÀí... 2

1.2 ÅäÖÃÏ޶ȺÍÁìµ¼... 5

1.3 ÅäÖù¤×÷¸ÅÀÀ... 5

1.4 ÅäÖÃSPAN.. 6

1.4.1 Ö°Äܼò½é... 6

1.4.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 6

1.4.3 ÅäÖò½Öè... 6

1.5 ÅäÖÃRSPAN.. 7

1.5.1 Ö°Äܼò½é... 7

1.5.2 ÅäÖÃÏÞ¶Å×ëÁìµ¼... 7

1.5.3 ÅäÖò½Öè... 7

1.6 ÅäÖÃERSPAN.. 8

1.6.1 ÅäÖù¤×÷¼ò½é... 8

1.6.2 ÅäÖÃERSPAN¸ù»ùÖ°ÄÜ... 8

1.6.3 ÅäÖÃERSPANµÄ²ÉÑùÖ°ÄÜ... 9

1.6.4 ÅäÖÃERSPANµÄÊôÐÔ... 9

1.7 ¼à¶½ÓëÊØ»¤... 10

1.8 µäÐÍÅäÖþÙÀý... 10

1.8.1 SPANÅäÖþÙÀý... 10

1.8.2 »ùÓÚRSPANʵÏÖµÄÒ»¶Ô¶à¾µÏñÖ°ÄÜÅäÖþÙÀý... 13

1.8.3 ERSPAN¸ù»ùÖ°ÄÜÅäÖþÙÀý... 16

 


1 ¾µÏñ

1.1?? Ö°ÄܽéÉÜ

1.1.1? ¾µÏñÖ°ÄܸÅÊö

Ëæ×ÅÍøÂçµÄ·¢Õ¹£¬¶ÔÍøÂçµÄ¸ß¿ÉÓÃÐÔµÄÒªÇóÈÕÒæÌá¸ß¡£µ±ÍøÂç³öÏÖÒ쳣ʱ£¬±ØÒª¶ÔÍøÂç½Úµã»òÕßÉ豸µÄ¶Ë¿Ú½øÐÐÁËÊý¾ÝÁ÷Á¿·ÖÎöÒÔ±ãÍøÂç¿ÉÄܼ±¾ç¸´Ô­Õý³££¬µ«Í¬Ê±ÓÖÒªÇó²»Ó°ÏìÉ豸Êý¾ÝÁ÷Á¿µÄÕý³£×ª·¢¡£

¾µÏñÊǽ«Ö¸¶¨¶Ë¿ÚµÄ±¨Îĸ´Ôìµ½ÁíÒ»¸öÏνÓÓÐÍøÂç¼à²âÉ豸µÄ¶Ë¿ÚµÄÖ°ÄÜ£¬ÊµÏÖÁ˶ԿÉÒɵÄÍøÂç½Úµã»òÕßÉ豸¶Ë¿Ú½øÐÐÊý¾ÝÁ÷Á¿·ÖÎö£¬Í¬Ê±ÓÖ²»Ó°Ïì±»¼à¿ØÉ豸µÄÊý¾Ýת·¢¡£¾µÏñÖ°ÄÜÖØÒªÀûÓÃÔÚÍøÂç¼à¿ØºÍ¹ÊÕÏÅŲéÁ½ÖÖ³¡¾°ÖУ¬ÊµÏÖÁË¼à¿ØÍøÂçÐÅÏ¢°²È«ºÍ½â¾öÍøÂç¹ÊÕϵÄÖ÷ÕÅ¡£

1.1.2? ¸ù»ù¸ÅÏë

1.    Ô´¶Ë¿Ú

Ô´¶Ë¿ÚÒ²³ÆÎª±»¼à¿Ø¿Ú£¬Ô´¶Ë¿ÚÉϵÄÊý¾ÝÁ÷»á±»¸´ÔìÒ»·Ýµ½Ö÷ÕŶ˿Ú£¬ÓÃÓÚÍøÂç·ÖÎö»ò¹ÊÕÏÅųý¡£

2.    Ö÷ÕŶ˿Ú

Ö÷ÕŶ˿ÚÒ²³ÆÎªÎª¼à¿Ø¿Ú£¬Óë¼à¿ØÉ豸ÏàÏνӵĶ˿Ú£¬½«½Ó¹Üµ½µÄÔ´¶Ë¿Ú±¨ÎÄת·¢µ½¼à¿ØÉ豸¡£

3.    »á»°

»á»°ÊÇÒ»¸öÂß¼­ÉϵĸÅÏ룬һ¸öÆëÈ«µÄ»á»°ÓÉÔ´¶Ë¿ÚºÍÖ÷ÕŶ˿Ú×é³É¡£

4.    SPAN

SPAN£¨Switch Port Analyzer£¬»¥»»Ê½¶Ë¿Ú·ÖÎöÆ÷£©Ò²³ÆÎª±¾µØ¶Ë¿Ú¾µÏñ»òÕß±¾µØ¾µÏñ¡£Ö¸Í³Ò»¸ö¾µÏñ»á»°µÄÔ´¶Ë¿ÚÓëÖ÷ÕŶ˿ÚÔÚͳһ̨É豸ÉϵľµÏñ¡£

5.    RSPAN

RSPAN£¨Remote Switch Port Analyzer£¬Ô¶³Ì¶Ë¿Ú¾µÏñ£©ÊÇSPANµÄÀ©´ó£¬Ô´¶Ë¿ÚºÍÖ¸±ê¶Ë¿Ú´¦ÓÚ·ÖÆçµÄÉ豸¡£

6.    ERSPAN

ERSPAN£¨Encapsulated Remote Switch Port Analyzer£¬·â×°Ô¶³Ì¶Ë¿Ú¾µÏñ£©ÊÇRSPANµÄÀ©´ó£¬ÊµÏÖÁËÓâÔ½»¥»»»ò·ÓÉÍøÂçµÄ¶ą̀É豸µÄÔ¶³Ì¼à¿Ø²½Öè¡£

7.    Ô¶³Ì¾µÏñVLAN

Ô¶³Ì¾µÏñVLANÊÇÒ»ÖÖÌØÊâµÄVLAN£¬¸ÃVLANÖ»´«Êä¾µÏñ±¨ÎÄ£¬²»ºÏÕý³£µÄÒµÎñÊý¾Ý½øÐд«Êä¡£

8.    Êä³ö¶Ë¿Ú

Ô´É豸´ó½«¾µÏñ±¨ÎÄ·¢Ë͵½ÖÐÑëÉ豸»òÕßÖ÷ÕÅÉ豸µÄ¶Ë¿Ú³ÆÎªÊä³ö¶Ë¿Ú¡£

9.    Ô´É豸

Ô´É豸ÊÇÔ¶³Ì¾µÏñ½Çɫ֮һ£¬Ö¸Ô´¶Ë¿ÚµØµãµÄÉ豸£¬Õƹܽ«Ô´¶Ë¿ÚµÄ±¨Îĸ´ÔìÒ»·Ýµ½Ô´É豸µÄÊä³ö¶Ë¿Ú£¬´«Ê䏸ÖÐÑëÉ豸»òÖ÷ÕÅÉ豸¡£

10. ?Ö÷ÕÅÉ豸

Ö÷ÕÅÉ豸Զ³Ì¾µÏñ½Çɫ֮һ£¬Ö¸Ô¶³Ì¾µÏñÖ÷ÕŶ˿ڵصãµÄÉ豸£¬Õƹܽ«ÖÐÑëÉ豸»òÕßÔ´É豸½Ó¹Üµ½µÄ¾µÏñ±¨ÎÄת·¢¸ø¼à¿ØÉ豸¡£

11. ?ÖÐÑëÉ豸

ÖÐÑëÉ豸ÊÇÔ¶³Ì¾µÏñ½Çɫ֮һ£¬Ö¸´¦ÓÚÔ´É豸ºÍÖ÷ÕÅÉ豸֮¼äµÄÉ豸£¬Õƹܽ«¾µÏñ±¨ÎÄ´«Ê䏸ÏÂÒ»¸öÖÐÑëÉ豸»òÖ÷ÕÅÉ豸¡£ÈôÊÇÔ´É豸ÓëÖ÷ÕÅÉ豸ֱ½ÓÏàÁ¬£¬Ôò²»´æÔÚÖÐÑëÉ豸¡£

12. ?¾µÏñÊý¾ÝÁ÷

¾µÏñÊý¾ÝÁ÷Ö¸±»¾µÏñµÄÊý¾Ý±¨ÎÄ¡£¾µÏñ»á»°µÄÊý¾ÝÁ÷Ô̺¬ÒÔÏÂÈýÖÖ·½ÏòµÄÊý¾ÝÁ÷£º

l  ÊäÈëÊý¾ÝÁ÷

ËùÓÐÔ´¶Ë¿ÚÉϽӹܵ½µÄ±¨Îͼ½«±»¸´ÔìÒ»·Ýµ½Ö÷ÕŶ˿Ú¡£ÔÚÒ»¸ö¾µÏñ»á»°ÖУ¬Äܹ»¼à¿ØÒ»¸ö»ò¶à¸öÔ´¶Ë¿ÚµÄÊäÈ뱨ÎÄ¡£

l  Êä³öÊý¾ÝÁ÷

ËùÓдÓÔ´¶Ë¿Ú·¢Ë͵ı¨Îͼ½«¸´ÔìÒ»·Ýµ½Ö÷ÕŶ˿Ú¡£ÔÚÒ»¸ö¾µÏñ»á»°ÖУ¬Äܹ»¼à¿ØÒ»¸ö»ò¶à¸öÔ´¶Ë¿ÚµÄÊä³ö±¨ÎÄ¡£

l  Ë«ÏòÊý¾ÝÁ÷

ͬʱÔ̺¬ÊäÈëÊý¾ÝÁ÷ºÍÊä³öÊý¾ÝÁ÷¡£ÔÚÒ»¸ö¾µÏñ»á»°ÖУ¬¿É¼à¿ØÒ»¸ö»ò¶à¸öÔ´¶Ë¿ÚµÄÊäÈëºÍÊä³ö·½ÏòµÄÊý¾ÝÁ÷¡£

1.1.3? ¹¤×÷µÀÀí

1.    SPAN¹¤×÷µÀÀí

Èçͼ1-1Ëùʾ£¬Í¨¹ýÔÚDeviceAÉÏÅäÖÃÁËSPAN£¬É豸½«Port 1Éϵı¨Îĸ´ÔìÒ»·Ýµ½Port 10£¬ÏνÓÔÚPort 10ÉϵÄÍøÂç·ÖÎöÉ豸¹ÌȻδÓëPort1Ö±½ÓÏàÁ¬£¬µ«ÊÇÄܹ»½Ó¹Üͨ¹ýPort1ÉϵÄËùÓб¨ÎÄ£¬´Ó¶øÊµÏÖÁË¼à¿ØPort 1½Ó¿Ú´«ÊäµÄÊý¾ÝÁ÷µÄÖ÷ÕÅ¡£¾ßÌ幤×÷¹ý³ÌÈçÏ£º

(1)   É豸¼ø±ðÓëÏóÕ÷³ö´ÓÔ´¶Ë¿ÚPort 1½ø³öµÄ±¨ÎÄ¡£

(2)   É豸²éÕÒPort 1ËùÊôµÄ¾µÏñ»á»°¡£

(3)   É豸²éÕҸþµÏñ»á»°¶ÔÓ¦µÄÖ÷ÕŶ˿ÚPort 10¡£

(4)   É豸¸´ÔìÒ»·Ý½ø³öPort 1µÄ±¨ÎÄ·¢ËÍÖÁPort 10¡£

(5)   Port 10½«±¨ÎÄ·¢ËÍÖÁÍøÂç·ÖÎöÉ豸¡£

ͼ1-1     SPAN¹¤×÷µÀÀíͼ

image011

 

2.    RSPAN¹¤×÷µÀÀí

Èçͼ1-2Ëùʾ£¬RSPANµÄµÀÀíÊÇÔÚÔ´É豸¡¢ÖÐÑëÉ豸ºÍÖ÷ÕÅÉ豸´´½¨Ò»¸öÔ¶³Ì¾µÏñVLAN£¬ÇÒËùÓвμӾµÏñ»á»°µÄ¶Ë¿Ú¶¼²ÎÓë¸ÃÔ¶³Ì¾µÏñVLAN¡£Ô¶³Ì¾µÏñVLANÖÐͨ¹ý¹ã²¥£¬Ê¹µÃÔ´É豸½«¾µÏñ±¨ÎÄת·¢µ½Ö÷ÕÅÉ豸£¬Ö÷ÕÅÉ豸ÔÙ½«¾µÏñ±¨ÎÄת·¢µ½ÍøÂç·ÖÎöÉ豸¡£¾ßÌ幤×÷¹ý³ÌÈçÏ£º

(1)   Ô´É豸¡¢ÖÐÑëÉ豸ºÍÖ÷ÕÅÉ豸É豸ÖвμӾµÏñ»á»°µÄ¶Ë¿Ú¾ù²ÎÓëµ½Ô¶³Ì¾µÏñVLANÖС£

(2)   Ô´É豸½«Ô´¶Ë¿ÚÖеľµÏñ±¨ÎÄ·â×°Ô¶³Ì¾µÏñVLANµÄID£¬²¢¸´ÔìÒ»·Ýµ½Êä³ö¶Ë¿Ú¡£

*     ×¢Ã÷

Èçͼ1-3¶ÔÓÚÒ»¶Ô¶à¾µÏñ£¬±ØÒªÔÚÔ´É豸µÄÊä³ö¶Ë¿ÚÉÏ¿ªÆôΪMAC»Ø»·Ö°ÄÜʹÆä³ÉΪ×Ô»·¿Ú£¬²¢½«×Ô»·¿Ú¼°ÓëÖÐÑëÉ豸ÏνӵĽӿڣ¨Í¼1-3ÖеÄPort1ºÍPort2£©²ÎÓëÔ¶³Ì¾µÏñVLAN¡£Ô´¶Ë¿Ú½«±¨ÎľµÏñ´«Êäµ½×Ô»·¿Ú£¬¾µÏñ±¨ÎÄÔö³¤Ô¶³Ì¾µÏñVLANµÄID¡£ÓÉÓÚ×Ô»·¿ÚÊôÓÚÔ¶³Ì¾µÏñVLANÇÒ¸ÃVLAN²»Èݽø½¨MACµØÖ·£¬Òò¶ø·´É仨À´µÄ±¨ÎÄÔÚÔ¶³Ì¾µÏñVLANÄڹ㲥£¬ËÁÒâ²ÎÓëÔ¶³Ì¾µÏñVLANµÄ½Ó¿Ú¾ù¿ÉÄܽӹܵ½¾µÏñ±¨ÎÄ£¬´Ó¶øÊµÏÖÒ»¶Ô¶à¾µÏñ¡£

 

(3)   Êä³ö¶Ë¿Úͨ¹ýÔ¶³Ì¾µÏñVLAN½«¾µÏñ±¨ÎÄÊä³öµ½ÖÐÑëÉ豸»òÕßÖ÷ÕÅÉ豸¡£

(4)   ÖÐÑëÉ豸ÔÚÔ¶³Ì¾µÏñVLANÖй㲥¾µÏñ±¨ÎÄ£¬½«¾µÏñ±¨ÎÄ͸´«µ½ÏÂÒ»¸öÖÐÑëÉ豸»òÕßÖ÷ÕÅÉ豸¡£

*     ×¢Ã÷

ÈôÊÇÔ´É豸ÓëÖ÷ÕÅÉ豸ֱ½ÓÏνÓ£¬ÔòÊä³ö¶Ë¿Ú½«¾µÏñ±¨ÎÄÊä³öµ½Ö÷ÕÅÉ豸¡£

 

(5)   Ö÷ÕÅÉ豸½Ó¹Üµ½±¨Îĺó£¬Í¨¹ý±¨ÎÄЯ´øµÄVLAN IDÅжϸñ¨ÎÄÊÇ·ñΪ¾µÏñ±¨ÎÄ£¬µ±±¨ÎÄЯ´øµÄVLAN IDÓëÔ¶³Ì¾µÏñVLAN IDÒ»ÖÂʱ£¬ÔòÅжϸñ¨ÎÄΪ¾µÏñ±¨ÎÄ£¬²¢½«¸Ã±¨ÎÄͨ¹ýÖ÷ÕŶ˿Úת·¢¸øÍøÂç·ÖÎöÒÇ¡£

ͼ1-2     RSPAN¹¤×÷µÀÀíͼ

image013

 

ͼ1-3     »ùÓÚRSPANʵÏÖµÄÒ»¶Ô¶à¾µÏñµÀÀíͼ

image015

 

3.    ERSPAN¹¤×÷µÀÀí

ÔÚRSPANÖУ¬¾µÏñ±¨ÎÄÖ»ÄÜÔÚ¶þ²ãÄÚ´«Ê䣬ÎÞ·¨¿ç·ÓÉÍø¶Îת·¢£¬¶øERSPAN½«¾µÏñ±¨ÎÄͨ¹ýGRE£¨Generic Routing Encapsulation£¬Í¨Ó÷ÓɺÍ̸·â×°£©Ëí··â×°³ÉIP±¨Îĺó£¬ÔÙ½«¾µÏñ±¨ÎÄת·¢µ½Ô¶¶Ë¾µÏñÉ豸µÄÖ÷ÕŶ˿Ú£¬ÊµÏÖÁ˾µÏñ±¨ÎĵĿç·ÓÉÍø¶ÎµÄ´«Êä¡£

Èçͼ1-4Ëùʾ£¬ERSPANµÄ¾ßÌ幤×÷¹ý³ÌÈçÏ¡£

(1)   Ô´É豸½«½øÈëÔ´¶Ë¿ÚµÄ±¨Îĸ´ÔìÒ»·Ý²¢½øÐзâ×°¡£

¡ð         ·â×°µÄGRE±¨ÎĵÄÔ´IP¡¢Ö÷ÕÅIP¡£

¡ð         ÉèÖÃGRE±¨ÎĵÄTTLºÍDSCPÖµ¡£

¡ð         ·â×°IPv6±¨ÎĵÄhop-limitºÍtraffic-classÖµ¡£

*     ×¢Ã÷

¾µÏñ±¨Îľ­¹ýERSPAN·â×°ºóµÄ±¨ÎÄÍ·²¿ÌåʽÈçͼ1-5Ëùʾ¡£

 

(2)   ͨ¹ýGREËí·£¬½«¾µÏñ±¨ÎÄת·¢ÖÁÖ÷ÕÅÉ豸¡£

(3)   Ö÷ÕÅÉ豸½«¾µÏñ±¨ÎĽøÐÐGREÄ£¿é½â·â×°£¬°þÀëERSPAN·â×°Í·²¿ºó½«¾µÏñ±¨ÎÄת·¢µ½Ö÷ÕŶ˿Ú¡£

(4)   Ö÷ÕŶ˿ڽ«¾µÏñ±¨ÎÄת·¢µ½ÍøÂç·ÖÎöÉ豸¡£

*    °ÑÎÈ

½øÐÐGRE·â×°ºóµÄIP±¨ÎıØÐëÊÇ¿ÉÄÜÔÚÍøÂçÖÐÕý³£Â·Óɵ½Ö÷ÕžµÏñÉ豸µÄ£¬Òò¶øÖ÷ÕÅIPͨ³£ÊÇ·ÓɵÄÏÂÒ»ÌøIP¡£¼´Ô´É豸µÄÊä³ö¶Ë¿ÚÊÇÆäÒª·â×°µÄÖ÷ÕÅIPµØÖ·µØµãµÄÈý²ãͨ·µÄÏÂÒ»Ìø³ö¿Ú£¬ËùÒÔ¾µÏñÊä³ö¿Ú±ØÐëÊÇ·ÓɿɴïµÄ½Ó¿Ú£¬¿ÉËùÒÔSVI½Ó¿Ú£¬Èý²ã¾ÛºÏ½Ó¿Ú»òÕßÈý²ãÒÔÌ«Íø½Ó¿Ú¡£

 

ͼ1-4     ERSPAN¹¤×÷µÀÀíͼ

image017

 

ͼ1-5     ERSPAN·â×°±¨ÎÄÌåʽͼ

image019

 

4.    Á÷¾µÏñµÄ¹¤×÷µÀÀí

Á÷µÄ¾µÏñÊÇÔڶ˿ھµÏñµÄ»ù´¡ÉÏ£¬½«Ô´¶Ë¿ÚÓëACL¹ØÁª£¬Æ¾¾ÝACL¹æ¶¨¶Ô±¨ÎĽøÐйýÂË£¬´ïµ½Ö»¾µÏñÖ¸¶¨±¨ÎĵÄÖ÷ÕÅ¡£Ô´¶Ë¿ÚÖ»ÓÐÆ¥Åäµ½ACLÖÐpermit aceµÄ±¨ÎÄÄÜÁ¦±»¾µÏñµ½Ö÷ÕŶ˿Ú¡£Ò»¸öÔ´¶Ë¿ÚÖ»ÄܹØÁªÒ»¸öACL¡£¿É¹ØÁªµÄACLÓг߶ÈACL¡¢À©´óACL¡¢MAC ACLºÍ×Ô½ç˵ACL¡£

1.2?? ÅäÖÃÏ޶ȺÍÁìµ¼

l  Ô´¶Ë¿ÚÓµÓÐÒÔϸöÐÔ£º

¡ð         Ô´¶Ë¿ÚÓëÊä³ö¶Ë¿Ú²»ÄÜΪͳһ¶Ë¿Ú¡£

¡ð         Ô´¶Ë¿Ú¿ÉËùÒÔ¶þ²ãÒÔÌ«Íø½Ó¿Ú£¬Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ¿Ú»òÈý²ã¾ÛºÏ¿Ú¡£

¡ð         Ö§³Ö½«Ô´É豸ÉϵĶà¸öÔ´¶Ë¿ÚÊý¾ÝÁ÷¾µÏñµ½Ö¸¶¨µÄÊä³ö¶Ë¿Ú¡£

¡ð         µ±¾µÏñÔ´¶Ë¿ÚΪÈý²ãÒÔÌ«Íø½Ó¿Ú»òÈý²ã¾ÛºÏ¿Úʱ£¬¼à¿ØµÄ±¨ÎÄÔ̺¬¶þ²ã±¨ÎĺÍÈý²ã±¨ÎÄ¡£

¡ð         ÔÚË«Ïò¼à¿Ø¶à¸ö¶Ë¿ÚµÄÇé¿öÏ£¬Ò»·Ý±¨ÎÄÓÉÒ»¸ö¶Ë¿Ú½øÈ룬´ÓÁí±íÒ»¸ö¶Ë¿ÚÊä³ö£¬Ö»ÓÐÓÐ¼à¿Øµ½Ò»·Ý±¨Îļ´ÊÓΪ±¨Îı»¾µÏñ³É¹¦¡£

¡ð         µ±¶Ë¿ÚÆôÓÃSTP²¢´¦ÓÚBLOCK״̬ʱ£¬¸Ã¶Ë¿ÚµÄÊäÈë»òÊä³öµÄ±¨ÎÄÒ²¿ÉÄܱ»¼à¿Øµ½¡£

¡ð         Ô´¶Ë¿ÚºÍÖ÷ÕŶ˿ÚÄܹ»ÊôÓÚͳһVLAN£¬Ò²Äܹ»ÊôÓÚ·ÖÆçVLAN¡£

¡ð         ÈôÊǽ«Ô´¶Ë¿Ú²ÎÓë¾ÛºÏ¿Ú£¬Ôò¸ÃÔ´¶Ë¿Ú½«Í˳ö¾µÏñ»á»°£¬½ö×÷Ϊ¾ÛºÏ¿ÚµÄ³ÉÔ±¿Ú£¬²»ÔÙ×÷Ϊ¾µÏñ»á»°µÄÔ´¶Ë¿Ú¡£

l  Ö÷ÕŶ˿ÚÓµÓÐÒÔϸöÐÔ£º

¡ð         Ö÷ÕŶ˿ڲ»ÄÜͬʱ×÷ΪԴ¶Ë¿Ú¡£

¡ð         Ö÷ÕŶ˿ڿÉËùÒÔÒÔÌ«Íø½Ó¿Ú»ò¾ÛºÏ½Ó¿Ú¡£

l  ÒѾ­ÅäÖõĻỰID²»ÄÜ×÷ΪÆäËû¾µÏñ»á»°µÄID¡£

l  ȱʡÇé¿öÏ£¬¾µÏñÖ÷ÕÅ¿ÚûÓпªÆôswitchÖ°ÄÜ£¬Ö÷Õſڲ»²Î¼ÓÊý¾Ýת·¢£¬Ö»½Ó¹Ü¾µÏñ±¨ÎÄ¡£ÈôÊDZØÒªÖ÷ÕſڲμÓÊý¾Ýת·¢£¬Ôò±ØÒª¿ªÆôswitchÖ°ÄÜ£¬²»È»¶ÔÓÚÁ÷¾­¸Ã¶Ë¿ÚµÄÊý¾Ý±¨ÎĽ«±»Åׯú¡£

l  ÓÉÓÚÆäËûÔ­Òò£¨Èç¶Ë¿Ú°²È«£©£¬´ÓÔ´¶Ë¿ÚÊäÈëµÄ±¨ÎÄ¿ÉÄܱ»Åׯú£¬µ«Õâ²»Ó°Ïì¾µÏñÖ°ÄÜ£¬¸Ã±¨ÎÄÒÀÈ»»á±»¾µÏñµ½Ö÷ÕŶ˿Ú¡£¶øÓÉÓÚÆäËûÔ­Òò£¬´ÓÆäËû¶Ë¿Ú·¢Ë͵½Ô´¶Ë¿ÚµÄ±¨ÎÄ¿ÉÄܱ»Åׯú£¬Òò¶ø¸Ã±¨ÎÄÒ²²»»á·¢Ë͵½Ö÷ÕŶ˿Ú¡£

l  ÈôÊÇ´ÓÔ´¶Ë¿ÚÊä³öµÄ±¨ÎĵÄÌåʽ²úÉúŤתʱ£¬ÀýÈçÔ´¶Ë¿ÚÊä³ö¾­¹ý·ÓÉÖ®ºóµÄ±¨ÎÄ£¬±¨ÎĵÄÔ´MAC¡¢Ö÷ÕÅMAC¡¢VLAN IDÒÔ¼°TTL²úÉú±ä¶¯Ê±£¬Ôò¾µÏñµ½Ö÷ÕŶ˿ڵı¨ÎĵÄÌåʽҲ»áËæÖ®²úÉú±ä¶¯¡£

l  Äܹ»Í¨¹ýÔÚÔ´¶Ë¿ÚÅäÖÃACL´ïµ½¾µÏñÖ¸¶¨µÄÊý¾ÝÁ÷µÄÖ÷ÕÅ£¬Ö§³Ö³ß¶ÈACL¡¢À©´óACL¡¢MAC ACLºÍ×Ô½ç˵ACL¡£

1.3?? ÅäÖù¤×÷¸ÅÀÀ

¾µÏñÅäÖù¤×÷ÈçÏ£º

l  ÅäÖÃSPAN

l  ÅäÖÃRSPAN

l  ÅäÖÃERSPAN

a      ÅäÖÃERSPAN¸ù»ùÖ°ÄÜ

b      £¨¿ÉÑ¡£©ÅäÖÃERSPANµÄ²ÉÑùÖ°ÄÜ

c      £¨¿ÉÑ¡£©ÅäÖÃERSPANµÄÊôÐÔ

1.4?? ÅäÖÃSPAN

1.4.1? Ö°Äܼò½é

SPANͨ¹ý½«Ö¸¶¨¶Ë¿Ú»òÖ¸¶¨VLANµÄ±¨Îĸ´Ôìµ½ÓëÊý¾Ý¼à²âÉ豸ÏàÁ¬µÄ¶Ë¿Ú£¬Äܹ»ÀûÓÃÊý¾Ý¼à²âÉ豸·ÖÎöÕâЩ¸´Ôì¹ýÀ´µÄ±¨ÎÄ£¬ÒÔ½øÐÐÍøÂç¼à¿ØºÍ¹ÊÕÏÅųý¡£

1.4.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ÅäÖþµÏñÔ´¶Ë¿Úʱ£¬Äܹ»Í¬Ê±ÅäÖÃÖ¸¶¨²¿ÃÅVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿ÚÉϵÄÖ¸¶¨Á÷×÷Ϊ¾µÏñµÄÊý¾ÝÔ´Ö°ÄÜ¡£

l  ÅäÖþµÏñÔ´¶Ë¿Úʱ£¬Ö¸¶¨Ä³¸öVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´Ö°ÄÜÓëÖ¸¶¨²¿ÃÅVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿ÚÉϵÄÖ¸¶¨Á÷×÷Ϊ¾µÏñµÄÊý¾ÝÔ´Ö°ÄÜ»¥³â¡£

l  ÅäÖþµÏñÔ´¶Ë¿Úʱ£¬Ö¸¶¨²¿ÃÅVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´ºó£¬Í¬Ê±»¹±ØÒªÅäÖÃÖ¸¶¨½Ó¿Ú×÷ΪԴ¶Ë¿Ú¡£

l  ÈôÊÇŤתÁËÔ´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄVLANÅäÖã¬ÅäÖý«¶ÙʱÉúЧ¡£

l  ÈôÊǽûÓÃÁËÔ´¶Ë¿Ú»òÖ÷ÕŶ˿Ú£¬¾µÏñÖ°Äܽ«Ê§Ð§¡£

l  ÈôÊÇVLAN»òVLANÁбí×÷Ϊ¾µÏñԴʱ£¬Òª±£ÕÏÖ÷ÕÅ¿ÚÓÐ×ã¹»´óµÄ¿í´ø¿ÉÄܽӹÜÕû¸öVLANµÄ¾µÏñÊý¾Ý¡£

l  ÈôÊÇÔÚÒѾ­ÉúЧµÄÖ¸¶¨VLANΪԴ¿ÚµÄ¾µÏñ»á»°ÖУ¬Ôö³¤»òɾ³ýVLANÔ´¿Ú£¬±ØÒª³ÁÐÂÀûÓÃÕû¸ö¾µÏñ»á»°£¬Òò¶øÒÑÓеľµÏñÁ÷Á¿¿ÉÄÜ»á³öÏÖÉÙÁ¿¶ª°ü¡£

1.4.3? ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ÅäÖþµÏñÔ´¶Ë¿Ú¡£ÇëÖÁÉÙÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡£

monitor session session-number source interface interface-type interface-number [ { both | rx | tx } [ acl acl-name | acl acl-number ]

¡ð         £¨¿ÉÑ¡£©ÅäÖÃÖ¸¶¨²¿ÃÅVLAN²»ÄÜ×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡£

monitor session session-number filter vlan vlan-id-list rx

±¾ºÅÁî±ØÒªÓëmonitor session source interfaceºÅÁî»òmonitor session source interface aclºÅÁîͬʱÅäÖÃʹÓá£

¡ð         ÅäÖÃÖ¸¶¨Ä³Ð©VLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡£

monitor session session-number source vlan vlan-id-list rx

ÐÔ×ÓÄÜÓëÖ¸¶¨²¿ÃÅVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´Ö°ÄÜ»¥³â¡£

ȱʡÇé¿öÏ£¬Î´ÅäÖþµÏñ»á»°µÄÔ´¶Ë¿Ú¡£

(4)   ÅäÖþµÏñÖ÷ÕŶ˿Ú¡£

monitor session session-number destination interface interface-type interface-number switch

ȱʡÇé¿öÏ£¬Î´ÅäÖþµÏñÖ÷ÕŶ˿Ú¡£

1.5?? ÅäÖÃRSPAN

1.5.1? Ö°Äܼò½é

ͨ¹ýÅäÖÃRSPANÖ°ÄÜ£¬¿ÉÄÜ¿çÉ豸¼à¿ØÊý¾Ý±¨ÎÄÒÔ½øÐÐÍøÂç¼à¿ØºÍ¹ÊÕÏÅųý¡£

1.5.2? ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ËùÓвμӾµÏñµÄ±¨ÎľùÒª²ÎÓëÔ¶³ÌVLANÖС£

l  Ô¶³Ì¾µÏñVLAN±ØÐëÔÚÿ̨É豸Öж¼Òª½øÐÐÅäÖã¬ÇÒVLAN ID±ØÐëÒ»Ö£¬²¢ÇÒËùÓвμӻỰµÄ¶Ë¿Ú¶¼Òª²ÎÓë¸ÃVLANÖС£ÇëÔ¤·À½«Í¨³£¶Ë¿Ú²ÎÓëÔ¶³Ì¾µÏñVLAN¡£

l  ½¨Òé²»Òª½«ÓëÖÐÑëÉ豸ÏàÁ¬µÄ¶Ë¿Ú»òÓëÖ÷ÕÅÉ豸ÏàÁ¬µÄ¶Ë¿ÚÅäÖÃΪ¾µÏñÔ´¶Ë¿Ú£¬²»È»¿ÉÄÜÒýÆðÍøÂçÄÚµÄÁ÷Á¿»ìÂÒ¡£

l  ΪÁËʵÏÖÒ»¶Ô¶à¾µÏñ£¬±ØÒªÔÚÔ´É豸ÉϰÎȡһ¸ö½Ó¿ÚÅäÖÃΪMAC»Ø»·¿Ú£¬½«Êä³ö¶Ë¿Úͨ¹ýMAC»Ø»·¿ÚµÄ¡°×Ô»·¡±Ö°ÄÜ£¬Í¨¹ýʵÏÖ½«¾µÏñ±¨ÎÄÊä³öµ½¶à¸öÖÐÑëÉ豸»òÕß¶à¸öÖ÷ÕÅÉ豸µÄÖ°ÄÜ¡£

l  MAC»Ø»·¿ÚÎÞ·¨×÷ΪÕý³£µÄ¶Ë¿Úת·¢Á÷Á¿¡£½¨Ò齫´¦ÓÚDOWN״̬µÄ¶Ë¿ÚÅäÖÃΪMAC»Ø»·¿Ú£¬ÇÒ²»ÒªÔڸö˿ÚÉÏÔö³¤ÆäËûÅäÖá£

1.5.3? ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ½øÈëVLANÅäÖÃģʽ¡£

vlan vlan-id

(4)   ÅäÖÃÔ¶³ÌVLAN¡£

remote-span

ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ¶³ÌVLAN¡£

(5)   Í˳öVLANÅäÖÃģʽ¡£

exit

(6)   ÅäÖÃÔ¶³Ì¾µÏñµÄÔ´É豸¡£

monitor session session-number remote-source

ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ¶³Ì¾µÏñ»á»°ÖеÄÔ´É豸¡£

(7)   £¨¿ÉÑ¡£©ÔÚÔ´É豸ÉÏÅäÖÃMAC×Ô»·Ö°ÄÜ¡£

a      ½øÈë¶þ²ãÒÔÌ«Íø½Ó¿Ú»òÈý²ãÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£

interface interface-type interface-number

b      ´ò¿ª½Ó¿ÚMAC×Ô»·Ö°ÄÜ¡£

mac-loopback

ȱʡÇé¿öÏ£¬½Ó¿ÚMAC×Ô»·Ö°ÄÜ´¦ÓڹعØ×´Ì¬¡£

(8)   Í˳ö¶þ²ãÒÔÌ«Íø½Ó¿Ú»òÈý²ãÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£

exit

(9)   ÅäÖÃÔ´É豸ÉϵÄÔ´¶Ë¿Ú¡£

monitor session session-number source interface interface-type interface-number [ { both | rx | tx } [ acl { acl-name | acl-number } ]

ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ´É豸ÉϵľµÏñ»á»°Ô´¶Ë¿Ú¡£

(10) ÅäÖÃÔ¶³Ì¾µÏñµÄÖ÷ÕÅÉ豸¡£

monitor session session-number remote-destination

ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ¶³Ì¾µÏñµÄ»á»°Ö÷ÕÅÉ豸¡£

(11) ÅäÖÃÔ´É豸ÉϵÄÊä³ö¶Ë¿Ú»òÕßÖ÷ÕÅÉ豸ÉϵÄÖ÷ÕŶ˿Ú¡£

monitor session session-number destination remote vlan remote-vlan-id interface interface-type interface-number switch

ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ¶³Ì¾µÏñÔ´É豸µÄÊä³ö¶Ë¿Ú»òÔ¶³Ì¾µÏñÖ÷ÕÅÉ豸µÄÖ÷ÕŶ˿Ú¡£

1.6?? ÅäÖÃERSPAN

1.6.1? ÅäÖù¤×÷¼ò½é

ERSPANÅäÖù¤×÷ÈçÏ£º

(1)   ÅäÖÃERSPAN¸ù»ùÖ°ÄÜ

(2)   £¨¿ÉÑ¡£©ÅäÖÃERSPANµÄ²ÉÑùÖ°ÄÜ

(3)   £¨¿ÉÑ¡£©ÅäÖÃERSPANµÄÊôÐÔ

1.6.2? ÅäÖÃERSPAN¸ù»ùÖ°ÄÜ

1.    Ö°Äܼò½é

ÅäÖÃERSPANºóÍøÂç·ÖÎöÒÇÄܹ»Í¨¹ýÔ¶³Ì¾µÏñ¼à¿ØÍøÂçÉ豸µÄÊý¾ÝÁ÷¡£É豸֮¼ä¾ùÄÜÕý³£»¥»»Êý¾Ý¡£

2.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ÅäÖÃERSPAN»á»°¡£

monitor session session-number erspan-source

ȱʡÇé¿öÏ£¬Î´ÅäÖÃERSPAN»á»°¡£

(4)   ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡£

source interface { interface-type interface-numbere | all } [ both | rx [ acl { acl-name | acl-number } ] | tx ]

ȱʡÇé¿öÏ£¬Î´ÅäÖþµÏñÔ´¶Ë¿Ú£¬µ±ÅäÖÃÔ´¶Ë¿Úʱ¾µÏñÊý¾ÝµÄ·½ÏòȱʡΪ˫ÏòÊý¾ÝÁ÷¡£

(5)   ÅäÖ÷â×°Ô´IPµØÖ·¡£

original { ip | ipv6 } address ip-address

ȱʡÇé¿öÏ£¬Î´ÅäÖÃGRE·â×°µÄÖ¸¶¨Ô´IPµØÖ·¡£

(6)   ÅäÖ÷â×°Ö÷ÕÅIPµØÖ·¡£

destination { ip | ipv6 } address ip-address

ȱʡÇé¿öÏ£¬Î´ÅäÖ÷â×°µÄÀàÐͼ°Ö¸¶¨Ö÷ÕÅIPµØÖ·¡£

1.6.3? ÅäÖÃERSPANµÄ²ÉÑùÖ°ÄÜ

1.    ÅäÖÃÏÞ¶Å×ëÁìµ¼

l  ERSPANµÄ²ÉÑùÖ°ÄÜÖ»ÓÐÔڻỰ»òÕß¾µÏñÔ´¶Ë¿ÚÅäÖÃÁ˲ÉÑùÖ°ÄÜʱ²ÅÉúЧ¡£

l  ¶ÔÓÚERSPANÅäÖÃÁ÷²ÉÑùµÄ²ÉÑù±Èʱ£¬²ÉÑù±È»áÒÔ×î¿¿½üµÄ2µÄn´Î·½ÉúЧ¡£ÈçÅäÖõIJÉÑù±ÈΪ100£¬ÔòÏÖʵÉúЧµÄ²ÉÑù±ÈΪ128¡£

l  ²ÉÑù±ÈÏÖʵÉúЧµÄÁìÓòΪ2^0~2^14£¬¼´1~16384¡£

2.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ÅäÖÃERSPAN»á»°¡£

monitor session session-umber erspan-source

(4)   ÅäÖÃÔ´¶Ë¿Ú¡£

source interface interface-type interface-number { [ rx | tx | both ] }

ȱʡÇé¿öÏ£¬Î´ÅäÖþµÏñÔ´¶Ë¿Ú£¬µ±ÅäÖÃÔ´¶Ë¿Úʱ¾µÏñ·½ÏòȱʡΪboth·½Ïò¡£

(5)   ÅäÖ÷â×°Ô´IPµØÖ·¡£

original { ip | ipv6 } address ip-address

ȱʡÇé¿öÏ£¬Î´ÅäÖÃGRE·â×°µÄÖ¸¶¨Ô´IPµØÖ·¡£

(6)   ÅäÖ÷â×°Ö÷ÕÅIPµØÖ·¡£

destination { ip | ipv6 } address ip-address

ȱʡÇé¿öÏ£¬Î´ÅäÖ÷â×°µÄÀàÐͼ°Ö¸¶¨Ö÷ÕÅIPµØÖ·¡£

(7)   ÅäÖûùÓÚÁ÷µÄERSPAN²ÉÑùÖ°ÄÜ¡£

source interface { interface-type interface-number | all }rx acl { acl-name | acl-number } [ sample ]

ȱʡÇé¿öÏ£¬Î´ÅäÖûùÓÚÁ÷µÄERSPAN²ÉÑùÖ°ÄÜ¡£

(8)   £¨¿ÉÑ¡£©ÅäÖõIJÉÑùƵÂÊ¡£

sampling-rate rate

ȱʡÇé¿öÏ£¬²ÉÑùƵÂÊÊÇ1:1£¬°µÊ¾Ã¿¸ö±¨Îͼ½øÐвÉÑù¡£

1.6.4? ÅäÖÃERSPANµÄÊôÐÔ

1.    ÅäÖò½Öè

(1)   ½øÈëÌØÈ¨Ä£Ê½¡£

enable

(2)   ½øÈëÈ«¾ÖÅäÖÃģʽ¡£

configure terminal

(3)   ÅäÖÃERSPAN»á»°¡£

monitor session session-number erspan-source

(4)   ÅäÖÃERSPAN»á»°µÄÊôÐÔ¡£ÒÔÏÂÅäÖþùΪ¿ÉÑ¡£¬ÇëÆ¾¾ÝÏÖʵÐèÒªÖÁÉÙÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£

¡ð         ·â×°IP TTL

ip ttl ttl-value

ȱʡÇé¿öÏ£¬·â×°IP±¨ÎĵÄTTLֵΪ64¡£

¡ð         ·â×°IP DSCP

ip dscp dscp-value

ȱʡÇé¿öÏ£¬·â×°IP±¨ÎĵÄDSCPֵΪ0¡£

¡ð         ·â×°IPv6 hop-limitÖµ¡£

ipv6 hop-limit value

ȱʡÇé¿öÏ£¬·â×°IPv6±¨ÎĵÄhop-limitֵΪ64¡£

¡ð         ·â×°ipv6 traffic-classÖµ¡£

ipv6 traffic-class value

ȱʡÇé¿öÏ£¬·â×°IPv6±¨ÎĵÄtraffic-classֵΪ0¡£

traffic-classµÄ¿ÉÅäÖÃÁìÓòΪ0~255£¬µ«ÏÖʵֻÓÐǰ6±ÈÌØ·â×°ÉúЧ£¬¼´Ö»ÓÐDSCP£¨0-63£©·â×°ÉúЧ£¬ºó2±ÈÌØ²¹0¡£

¡ð         ÅäÖÃERSPANÓëVRFÁª¶¯¡£

vrf vrf-name

ȱʡÇé¿öÏ£¬Î´ÅäÖÃERSPANÓëVRFÁª¶¯Ö°ÄÜ¡£

ÅäÖøÃÖ°ÄÜʱVRF±ØÐëÒѾ­´æÔÚ¡£

(5)   £¨¿ÉÑ¡£©¹Ø¹ØERSPAN»á»°¡£

shutdown

ȱʡÇé¿öÏ£¬»á»°Ö°ÄÜ´¦ÓÚ¿ªÆô״̬¡£

1.7?? ¼à¶½ÓëÊØ»¤

Äܹ»Í¨¹ýshowºÅÁîÐв鿴ְÄÜÅäÖúóµÄÔËÐÐÇé¿öÒÔÑéÖ¤ÅäÖóÉЧ¡£

Äܹ»Í¨¹ýdebugºÅÁîÐÐÁоÙÊä³öµÄ¸÷Ààµ÷ÊÔÐÅÏ¢¡£

±í1-1     SPAN-RSPAN¼à¶½ÓëÊØ»¤

×÷ÓÃ

ºÅÁî

²é¿´¾µÏñ»á»°ÐÅÏ¢

show monitor [ session session-number ]

´ò¿ª¾µÏñ»á»°µÄµ÷ÊÔ¿ª¹Ø

debug span

 

1.8?? µäÐÍÅäÖþÙÀý

1.8.1? SPANÅäÖþÙÀý

1.    ×éÍøÐèÒª

Èçͼ1-6Ëùʾ£¬Í¨¹ýÊʵ±µÄÅäÖã¬ÍøÂç·ÖÎöÒÇ¿ÉÄÜ¼à¿ØDeviceAת·¢¸øDeviceBµÄËùº±¼û¾ÝÁ÷£¬¼à¿ØÀ´×ÔDeviceBµÄÌØ¶¨Êý¾ÝÁ÷£¨ÈçÀ´×ÔPC1ºÍPC2µÄÊý¾ÝÁ÷£©¡£

2.    ×éÍøÍ¼

ͼ1-6     SPAN×éÍøÍ¼

image021

 

3.    ÅäÖÃÖØµã

l  ÅäÖÃDeviceAµÄGigabitEthernet 0/1ºÍGigabitEthernet 0/2ÊôÓÚVLAN 1¡£´´½¨SVI 1£¬²¢ÅäÖÃSVI 1µØÖ·Îª10.10.10.10/24¡£

l  ÅäÖÃDeviceBµÄGigabitEthernet 0/1ÊôÓÚVLAN 1¡£´´½¨SVI 1£¬²¢ÅäÖÃSVI 1µØÖ·Îª10.10.10.20/24¡£

l  ÅäÖÃPC1¡¢PC2µÄµØÖ·±ðÀëΪ10.10.10.1/24ºÍ10.10.10.2/24¡£

l  ÅäÖÃDeviceAµÄ±¾µØ¾µÏñ£¬Ö¸¶¨¶Ë¿ÚGigabitEthernet 0/1ºÍGigabitEthernet 0/2±ðÀëΪ¾µÏñµÄÔ´¶Ë¿ÚºÍÖ÷ÕŶ˿Ú¡£¼à¿ØDeviceAת·¢¸øDeviceBµÄËùº±¼û¾ÝÁ÷£¬¼à¿ØÀ´×ÔDeviceBµÄÌØ¶¨Êý¾ÝÁ÷¡£

4.    ÅäÖò½Öè

# ÅäÖÃDeviceAµÄGigabitEthernet 0/1ºÍGigabitEthernet 0/2ÊôÓÚVLAN 1¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# vlan 1

DeviceA(config-vlan)# exit

# ÔÚDeviceAÉÏ´´½¨SVI 1£¬²¢ÅäÖÃSVI 1µØÖ·Îª10.10.10.10/24¡£

DeviceA(config)# interface vlan 1

DeviceA(config-if-VLAN 1)# ip address 10.10.10.10 255.255.255.0

DeviceA(config-if-VLAN 1)# exit

# ÅäÖÃDeviceBµÄGigabitEthernet 0/1ÊôÓÚVLAN 1¡£

DeviceB# configure

DeviceB(config)# vlan 1

DeviceB(config-vlan)# exit

# ÔÚDeviceBÉÏ´´½¨SVI 1£¬²¢ÅäÖÃSVI 1µØÖ·Îª10.10.10.20/24¡£

DeviceB (config)# interface vlan 1

DeviceB(config-if-VLAN 1)# ip address 10.10.10.20 255.255.255.0

DeviceB(config-if-VLAN 1)# exit

# ÔÚDeviceAÉÏÅäÖÃACL£¬Æ¥ÅäÔ´µØÖ·Îª10.10.10.20µÄ±¨ÎÄ¡£

DeviceA(config)# access-list 100 permit ip host 10.10.10.20 any

# ÔÚDeviceAÉÏÅäÖö˿ÚGigabitEthernet 0/1Ϊ¾µÏñµÄÔ´¶Ë¿Ú£¬¼à¿ØDeviceAת·¢¸øDeviceBµÄËùº±¼û¾ÝÁ÷£¬¼à¿ØÀ´×ÔDeviceBµÄÌØ¶¨Êý¾ÝÁ÷¡£

DeviceA(config)# monitor session 1 source interface gigabitethernet 0/1 tx

DeviceA(config)# monitor session 1 source interface gigabitethernet 0/1 rx acl 100

# ÔÚDeviceAÉÏÅäÖÃGigabitEthernet 0/2Ϊ¾µÏñµÄÖ÷ÕŶ˿Ú¡£

DeviceA(config)# monitor session 1 destination interface gigabitethernet 0/2

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ͨ¹ýshow monitorºÅÁî²é¿´¾µÏñÊÇ·ñÕýÈ·ÅäÖá£

DeviceA# show monitor

sess-num: 1

span-type: LOCAL_SPAN

src-intf:

¡¡GigabitEthernet 0/1¡¡¡¡¡¡¡¡ frame-type TX Only

src-intf:

¡¡GigabitEthernet 0/1¡¡¡¡¡¡¡¡ frame-type RX Only

rx acl id 100

dest-intf:

¡¡GigabitEthernet 0/2

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

ip access-list extended 100

?10 permit ip host 10.10.10.20 any

!

interface VLAN 1

?ip address 10.10.10.10 255.255.255.0

!

monitor session 1 destination interface GigabitEthernet 0/2

monitor session 1 source interface GigabitEthernet 0/1 tx

monitor session 1 source interface GigabitEthernet 0/1 rx acl 100

!

end

l  DeviceBµÄÅäÖÃÎļþ

hostname DeviceB

!

interface VLAN 1

?ip address 10.10.10.20 255.255.255.0

!

end

1.8.2? »ùÓÚRSPANʵÏÖµÄÒ»¶Ô¶à¾µÏñÖ°ÄÜÅäÖþÙÀý

*    ÖÒ¸æ

µ±²¿ÊðÒ»¶Ô¶à¶Ë¿Ú¾µÏñʱ£¬±ØÐëʹÓÃswitchport trunk allowed vlan remove vlan-listºÅÁî²Ã¼ôµô¸÷¾µÏñÉ豸ÉÏtrunkÀàÐ͵ĽӿÚÖй㲥µÄVLAN£¬²»È»trunk½Ó¿Ú¿ÉÄܻᱻ¹ã²¥µÄÁ÷Á¿Õ¼Âúµ¼ÖÂÒµÎñÖжÏ¡£

 

1.    ×éÍøÐèÒª

Èçͼ1-7Ëùʾ£¬ÍøÂç·ÖÎöÒÇÄܹ»Í¨¹ýÔ¶³Ì¾µÏñÖ°ÄÜ£¬Êµ´Ë¿ÌÖ÷ÕÅÉ豸DeviceBºÍDeviceCÉÏ¼à¿ØÔ´É豸DeviceAÉϵÄË«ÏòÊý¾ÝÁ÷¡£ÇÒÉ豸֮¼ä¾ùÄÜÕý³£»¥»»Êý¾Ý¡£

2.    ×éÍøÍ¼

ͼ1-7     »ùÓÚRSPANʵÏÖµÄÒ»¶Ô¶à¾µÏñÖ°ÄÜÍøÍ¼

image023

 

3.    ÅäÖÃÖØµã

l  ÅäÖÃDeviceAΪԴÉ豸£¬ÅäÖÃÔ¶³Ì¾µÏñVLAN£¬ÅäÖö˿ÚGigabitEthernet 0/1ΪԴ¶Ë¿Ú£¬ÓëÖ÷ÕÅÉ豸ÏàÁ¬µÄ¶Ë¿ÚGigabitEthernet 0/3ºÍGigabitEthernet 0/4ΪÊä³ö¶Ë¿Ú£¬ÅäÖÃGigabitEthernet 0/2½Ó¿ÚΪMAC»Ø»·¿Ú£¬ÓÃÓÚʵÏÖÒ»¶Ô¶à¾µÏñµÄ¡°·´É䡱ְÄÜ¡£ÅäÖÃÊä³ö¶Ë¿Ú¿É»¥»»Ö°ÄÜ¡£

l  DeviceBºÍDeviceCÅäÖÃΪÖ÷ÕÅÉ豸£¬ÅäÖÃÔ¶³Ì¾µÏñVLAN£¬ÓëÔ´É豸ÏàÁ¬µÄ¶Ë¿ÚGigabitEthernet 0/1×÷ΪԴ¶Ë¿Ú£¬ÅäÖÃTrunk¶Ë¿Ú£¬ÓëÍøÂç·ÖÎöÒÇÏàÁ¬µÄ¶Ë¿ÚGigabitEthernet 0/2ÅäÖÃΪ¾µÏñÖ÷ÕŶ˿Ú£¬²¢ÅäÖþµÏñÖ÷ÕŶ˿ڿɻ¥»»Ö°ÄÜ¡£

4.    ÅäÖò½Öè

# ÅäÖÃDeviceAΪԴÉ豸¡£

(1)   ÅäÖÃÔ¶³ÌVLAN¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# vlan 7

DeviceA(config-vlan)# remote-span

DeviceA(config-vlan)# exit

(2)   ÅäÖÃÔ´¶Ë¿Ú¡£

DeviceA(config)# monitor session 1 remote-source

DeviceA(config)# monitor session 1 source interface gigabitethernet 0/1 both

(3)   ÅäÖÃÊä³ö¶Ë¿Ú¡£

DeviceA(config)# monitor session 1 destination remote vlan 7 interface gigabitethernet 0/2 switch

(4)   ÅäÖûػ·¿Ú¡£

DeviceA(config)# interface gigabitethernet 0/2

DeviceA(config-if)# mac-loopback

DeviceA(config-if)# switchport access vlan 7

DeviceA(config-if)# exit

DeviceA(config)# interface range gigabitethernet 0/3-4

DeviceA(config-if-range)# switchport mode trunk

# ÅäÖÃDeviceBΪÖ÷ÕÅÉ豸¡£

(1)   ÅäÖÃÔ¶³ÌVLAN¡£

DeviceB> enable

DeviceB# configure

DeviceB(config)# vlan 7

DeviceB(config-vlan)# remote-span

DeviceB(config-vlan)# exit

(2)   ÅäÖÃÖ÷ÕŶ˿Ú¡£

DeviceB(config)# monitor session 1 remote-destination

DeviceB(config)# monitor session 1 destination remote vlan 7 interface gigabitethernet 0/2 switch

DeviceB(config)# interface gigabitethernet 0/1

DeviceB(config-if)# switchport mode trunk

# ÅäÖÃDeviceCΪÖ÷ÕÅÉ豸¡£

(1)   ÅäÖÃÔ¶³ÌVLAN¡£

DeviceC> enable

DeviceC# configure

DeviceC(config)# vlan 7

DeviceC(config-vlan)# remote-span

DeviceC(config-vlan)# exit

(2)   ÅäÖÃÖ÷ÕŶ˿Ú¡£

DeviceC(config)# monitor session 1 remote-destination

DeviceC(config)# monitor session 1 destination remote vlan 7 interface gigabitethernet 0/2 switch

DeviceC(config)# interface gigabitethernet 0/1

DeviceC(config-if)# switchport mode trunk

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ÔÚDeviceAÉÏͨ¹ýshow monitorºÅÁî²é¿´¾µÏñÔ´É豸ÅäÖÃÁ˾Ö¡£

DeviceA# show monitor

sess-num: 1

span-type: SOURCE_SPAN

src-intf:

GigabitEthernet 0/1¡¡¡¡¡¡frame-type Both

dest-intf:

GigabitEthernet¡¡0/2

Remote vlan 7

mtp_switch on

# ÔÚDeviceBºÍDeviceCÖÐͨ¹ýshow monitorºÅÁî²é¿´¾µÏñÖ÷ÕÅÉ豸ÅäÖÃÁ˾Ö¡£ÒÔDeviceBΪÀý×¢Ã÷¡£

DeviceB# show monitor

sess-num: 1

span-type: DEST_SPAN

dest-intf:

GigabitEthernet¡¡0/2

Remote vlan 7

mtp_switch on

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

vlan 7

!

?remote-span

!

interface GigabitEthernet 0/2

?mac-loopback

?switchport access vlan 7

!

interface GigabitEthernet 0/3

switchport mode trunk

interface GigabitEthernet 0/4

switchport mode trunk

!

monitor session 1 remote-source

monitor session 1 source interface GigabitEthernet 0/1 both

monitor session 1 destination remote vlan 7 interface GigabitEthernet0/2 switch

!

end

l  DeviceBµÄÅäÖÃÎļþ

hostname DeviceB

!

vlan 7

?remote-span

!

interface GigabitEthernet 0/1

?switchport mode trunk

!

monitor session 1 remote-destination

monitor session 1 destination remote vlan 7 interface GigabitEthernet0/2 switch

!

end

l  DeviceCµÄÅäÖÃÎļþ

hostname Device

!

vlan 7

?remote-span

!

interface GigabitEthernet 0/1

?switchport mode trunk

?!

monitor session 1 remote-destination

monitor session 1 destination remote vlan 7 interface GigabitEthernet 0/2 switch

!

end

7.    ³£¼ûÃýÎó

l  Ô´É豸¡¢ÖÐÑëÉ豸¡¢Ö÷ÕÅÉ豸¾ùÒªÅäÖÃÔ¶³ÌVLANÇÒVID±ØÐëÒ»Ö¡£

l  ´ø¿í´óµÄ¶Ë¿Ú±»¾µÏñµ½´ø¿íÓ׵Ķ˿ڿÉÄÜ»áÔì³É¶ª°ü¡£

1.8.3? ERSPAN¸ù»ùÖ°ÄÜÅäÖþÙÀý

1.    ×éÍøÐèÒª

Èçͼ1-8ÖÐËùʾ¡£Íø¹Üµ«Ô¸Í¨¹ýÍøÂç·ÖÎöÒǶÔDeviceAºÍDeviceCµÄÁ÷Á¿½øÐÐ¼à¿Ø¡£ÆäÖжÔÓÚDeviceA£¬¼à¿ØË«ÏòÊý¾ÝÁ÷£»¶ÔÓÚDeviceC£¬½ö¼à¿Ø²¿ÃÅ·¢Ë͵½DeviceµÄ±¨ÎÄ¡£ÎªÁ˺ÏÀíÀûÓÃ×ÊÔ´£¬¶Ô¼à¿Ø±¨ÎĽøÐвÉÑù£¬²ÉÑùÂÊΪ1000¡£

2.    ×éÍøÍ¼

ͼ1-8     ERSPANÅäÖþÙÀý×éÍøÍ¼

image025

 

3.    ÅäÖÃÖØµã

l  ÅäÖø÷É豸֮¼äÈý²ã·Óɿɴï¡£

l  ÅäÖÃDeviceBΪԴÉ豸¡£GigabitEthernet 0/1£¬GigabitEthernet 0/2¾ùΪԴ¶Ë¿Ú£¬¼à¿ØGigabitEthernet 0/1µÄË«ÏòÊý¾Ý±¨ÎÄ£¬¶ÔÓÚGigabitEthernet 0/2µÄ±¨ÎÄ£¬½ö¾µÏñÖ÷ÕÅIPΪ2.1.1.1µÄ±¨ÎÄ£¬GigabitEthernet 0/3Ϊ¾µÏñ±¨Îijö¿Ú¡£

l  ÅäÖþµÏñ±¨ÎĵIJÉÑùÂÊΪ1000¡£

4.    ÅäÖò½Öè

# ÅäÖÃDeviceBµÄµØÖ·¡£

DeviceB> enable

DeviceB# configure terminal

DeviceB(config)# interface gigabitethernet 0/1

DeviceB(config-if-GigabitEthernet 0/1)# ip address 1.1.1.1 255.255.255.0

DeviceB(config-if-GigabitEthernet 0/1)# exit

DeviceB(config)# interface gigabitethernet 0/2

DeviceB(config-if-GigabitEthernet 0/1)# ip address 2.1.1.1 255.255.255.0

DeviceB(config-if-GigabitEthernet 0/1)# exit

DeviceB(config)# interface gigabitethernet 0/3

DeviceB(config-if-GigabitEthernet 0/1)# ip address 13.1.1.1 255.255.255.0

DeviceB(config-if-GigabitEthernet 0/1)# exit

# ÅäÖÃDeviceAµÄµØÖ·¡£

DeviceA> enable

DeviceA# configure terminal

DeviceA(config)# interface gigabitethernet 0/1

DeviceA(config-if-GigabitEthernet 0/1)# ip address 1.1.1.2 255.255.255.0

DeviceA(config-if-GigabitEthernet 0/1)# exit

# ÅäÖÃDeviceCµØÖ·¡£

DeviceC> enable

DeviceC# configure terminal

DeviceC(config)# interface gigabitethernet 0/1

DeviceC(config-if-GigabitEthernet 0/1)# ip address 2.1.1.2 255.255.255.0

DeviceC(config-if-GigabitEthernet 0/1)# exit

# ÔÚDeviceBÉÏÅäÖÃACL¡£

DeviceB(config)#access-list 1 permit host 1.1.1.1

# ´´½¨ERSPAN Session 1£¬ÉèÖÃΪԴÉ豸£¬²¢ÉèÖö˿ÚGigabitEthernet 0/1ΪԴ¶Ë¿Ú£¬¾µÏñË«ÏòÊý¾ÝÁ÷£¬¶Ë¿ÚGigabitEthernet 0/2ҲΪԴ¶Ë¿Ú£¬½ö½øÐÐÖ÷ÕŵØÖ·Îª1.1.1.1µÄ±¨ÎÄ¡£

DeviceB(config)# monitor session 1 erspan-source

DeviceB(config-mon-erspan-src)# source interface gigabitethernet 0/1 both

DeviceB(config-mon-erspan-src)# source interface gigabitethernet 0/2 rx acl acl1

DeviceB(config-mon-erspan-src)# origin ip address 10.1.1.2

DeviceB(config-mon-erspan-src)# destination ip address 3.1.1.2

# ¿ªÆô¾µÏñ±¨ÎÄѡȡְÄܲ¢ÅäÖòÉÑùÂÊΪ1000¡£

DeviceB(config-mon-erspan-src)# sample enable

DeviceB(config-mon-erspan-src)# sample rate 1000

5.    ÑéÖ¤ÅäÖÃÁ˾Ö

# ÑéÖ¤DeviceBÓëDeviceAÖ®¼äÈý²ã¿Éͨ¡£

DeviceB# ping 1.1.1.2

Sending 5, 100-byte ICMP Echoes to 1.1.1.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 2/3/8 ms.

# ÑéÖ¤DeviceBÓëDeviceCÖ®¼äÈý²ã¿Éͨ¡£

DeviceB# ping 2.1.1.2

Sending 5, 100-byte ICMP Echoes to 2.1.1.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 2/3/8 ms.

# ÑéÖ¤DeviceBÓëÍøÂç·ÖÎöÒÇÖ®¼äÈý²ã¿Éͨ¡£

DeviceB# ping 3.1.1.2

Sending 5, 100-byte ICMP Echoes to 3.1.1.2, timeout is 2 seconds:

¡¡< press Ctrl+C to break >

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 2/3/8 ms.

# ͨ¹ýshow access-listsºÅÁî²é¿´ACLÅäÖóɹ¦¡£

DeviceB# show access-lists

 

ip access-list standard 1

?10 permit host 1.1.1.1

# ͨ¹ýshow monitorºÅÁî²é¿´ÅäÖÃÁ˾Ö£¬ERSPAN»á»°´¦ÓÚActive״̬¡£

DeviceB# show monitor

sess-num: 1

span-type: ERSPAN_SOURCE

src-intf:

¡¡GigabitEthernet 0/1¡¡¡¡¡¡¡¡ frame-type: Both¡¡¡¡¡¡¡¡TX status: Active¡¡ RX status: Active¡¡

src-intf:

¡¡GigabitEthernet 0/2¡¡¡¡¡¡¡¡ frame-type: RX Only¡¡¡¡ Rx acl id: 1¡¡¡¡¡¡

status: Active

original ip address: 2.1.1.2

destination ip address: 3.1.1.2

ip ttl: 64

ip dscp: 0

sample rate: 1000

vrf: default

6.    ÅäÖÃÎļþ

l  DeviceAµÄÅäÖÃÎļþ

hostname DeviceA

!

interface GigabitEthernet 0/1

?ip address 1.1.1.2 255.255.255.0

!

end

l  DeviceCµÄÅäÖÃÎļþ

hostname DeviceC

!

interface GigabitEthernet 0/1

?ip address 2.1.1.2 255.255.255.0

!

end

l  DeviceBµÄÅäÖÃÎļþ

hostname DeviceB

!

ip access-list standard 1

?10 permit host 1.1.1.1

!

interface GigabitEthernet 0/1

?ip address 1.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/2

?ip address 2.1.1.1 255.255.255.0

!

interface GigabitEthernet 0/3

?ip address 3.1.1.1 255.255.255.0

!

monitor session 1 erspan-source

?source interface gigabitEthernet 0/1 both

?source interface gigabitEthernet 0/2 rx acl acl1

?origin ip address 10.1.1.2

?destination ip address 3.1.1.2

?sample enable

?sample rate 1000

!

end

7.    ³£¼ûÃýÎó

l  ÅäÖÃERSPAN¾µÏñµÄ»á»°IDÒѾ­±»ÅäÖÃÁËRSPAN»òLOCAL SPAN¡£

l  ´ÓÔ´É豸µ½Ö÷ÕÅÉ豸µÄÈý²ã·ÓÉÎÞ·¨»¥Í¨¡£

¡¾ÍøÕ¾µØÍ¼¡¿