Ëæ×ÅÍøÂçµÄ·¢Õ¹£¬¶ÔÍøÂçµÄ¸ß¿ÉÓÃÐÔµÄÒªÇóÈÕÒæÌá¸ß¡£µ±ÍøÂç³öÏÖÒ쳣ʱ£¬±ØÒª¶ÔÍøÂç½Úµã»òÕßÉ豸µÄ¶Ë¿Ú½øÐÐÁËÊý¾ÝÁ÷Á¿·ÖÎöÒÔ±ãÍøÂç¿ÉÄܼ±¾ç¸´ÔÕý³££¬µ«Í¬Ê±ÓÖÒªÇó²»Ó°ÏìÉ豸Êý¾ÝÁ÷Á¿µÄÕý³£×ª·¢¡£
¾µÏñÊǽ«Ö¸¶¨¶Ë¿ÚµÄ±¨Îĸ´Ôìµ½ÁíÒ»¸öÏνÓÓÐÍøÂç¼à²âÉ豸µÄ¶Ë¿ÚµÄÖ°ÄÜ£¬ÊµÏÖÁ˶ԿÉÒɵÄÍøÂç½Úµã»òÕßÉ豸¶Ë¿Ú½øÐÐÊý¾ÝÁ÷Á¿·ÖÎö£¬Í¬Ê±ÓÖ²»Ó°Ïì±»¼à¿ØÉ豸µÄÊý¾Ýת·¢¡£¾µÏñÖ°ÄÜÖØÒªÀûÓÃÔÚÍøÂç¼à¿ØºÍ¹ÊÕÏÅŲéÁ½ÖÖ³¡¾°ÖУ¬ÊµÏÖÁË¼à¿ØÍøÂçÐÅÏ¢°²È«ºÍ½â¾öÍøÂç¹ÊÕϵÄÖ÷ÕÅ¡£
Ô´¶Ë¿ÚÒ²³ÆÎª±»¼à¿Ø¿Ú£¬Ô´¶Ë¿ÚÉϵÄÊý¾ÝÁ÷»á±»¸´ÔìÒ»·Ýµ½Ö÷ÕŶ˿ڣ¬ÓÃÓÚÍøÂç·ÖÎö»ò¹ÊÕÏÅųý¡£
Ö÷ÕŶ˿ÚÒ²³ÆÎªÎª¼à¿Ø¿Ú£¬Óë¼à¿ØÉ豸ÏàÏνӵĶ˿ڣ¬½«½Ó¹Üµ½µÄÔ´¶Ë¿Ú±¨ÎÄת·¢µ½¼à¿ØÉ豸¡£
»á»°ÊÇÒ»¸öÂß¼ÉϵĸÅÏ룬һ¸öÆëÈ«µÄ»á»°ÓÉÔ´¶Ë¿ÚºÍÖ÷ÕŶ˿Ú×é³É¡£
SPAN£¨Switch Port Analyzer£¬»¥»»Ê½¶Ë¿Ú·ÖÎöÆ÷£©Ò²³ÆÎª±¾µØ¶Ë¿Ú¾µÏñ»òÕß±¾µØ¾µÏñ¡£Ö¸Í³Ò»¸ö¾µÏñ»á»°µÄÔ´¶Ë¿ÚÓëÖ÷ÕŶ˿ÚÔÚͳһ̨É豸ÉϵľµÏñ¡£
RSPAN£¨Remote Switch Port Analyzer£¬Ô¶³Ì¶Ë¿Ú¾µÏñ£©ÊÇSPANµÄÀ©´ó£¬Ô´¶Ë¿ÚºÍÖ¸±ê¶Ë¿Ú´¦ÓÚ·ÖÆçµÄÉ豸¡£
ERSPAN£¨Encapsulated Remote Switch Port Analyzer£¬·â×°Ô¶³Ì¶Ë¿Ú¾µÏñ£©ÊÇRSPANµÄÀ©´ó£¬ÊµÏÖÁËÓâÔ½»¥»»»ò·ÓÉÍøÂçµÄ¶ą̀É豸µÄÔ¶³Ì¼à¿Ø²½Öè¡£
Ô¶³Ì¾µÏñVLANÊÇÒ»ÖÖÌØÊâµÄVLAN£¬¸ÃVLANÖ»´«Êä¾µÏñ±¨ÎÄ£¬²»ºÏÕý³£µÄÒµÎñÊý¾Ý½øÐд«Êä¡£
Ô´É豸´ó½«¾µÏñ±¨ÎÄ·¢Ë͵½ÖÐÑëÉ豸»òÕßÖ÷ÕÅÉ豸µÄ¶Ë¿Ú³ÆÎªÊä³ö¶Ë¿Ú¡£
Ô´É豸ÊÇÔ¶³Ì¾µÏñ½Çɫ֮һ£¬Ö¸Ô´¶Ë¿ÚµØµãµÄÉ豸£¬Õƹܽ«Ô´¶Ë¿ÚµÄ±¨Îĸ´ÔìÒ»·Ýµ½Ô´É豸µÄÊä³ö¶Ë¿Ú£¬´«Ê䏸ÖÐÑëÉ豸»òÖ÷ÕÅÉ豸¡£
Ö÷ÕÅÉ豸Զ³Ì¾µÏñ½Çɫ֮һ£¬Ö¸Ô¶³Ì¾µÏñÖ÷ÕŶ˿ڵصãµÄÉ豸£¬Õƹܽ«ÖÐÑëÉ豸»òÕßÔ´É豸½Ó¹Üµ½µÄ¾µÏñ±¨ÎÄת·¢¸ø¼à¿ØÉ豸¡£
ÖÐÑëÉ豸ÊÇÔ¶³Ì¾µÏñ½Çɫ֮һ£¬Ö¸´¦ÓÚÔ´É豸ºÍÖ÷ÕÅÉ豸֮¼äµÄÉ豸£¬Õƹܽ«¾µÏñ±¨ÎÄ´«Ê䏸ÏÂÒ»¸öÖÐÑëÉ豸»òÖ÷ÕÅÉ豸¡£ÈôÊÇÔ´É豸ÓëÖ÷ÕÅÉ豸ֱ½ÓÏàÁ¬£¬Ôò²»´æÔÚÖÐÑëÉ豸¡£
¾µÏñÊý¾ÝÁ÷Ö¸±»¾µÏñµÄÊý¾Ý±¨ÎÄ¡£¾µÏñ»á»°µÄÊý¾ÝÁ÷Ô̺¬ÒÔÏÂÈýÖÖ·½ÏòµÄÊý¾ÝÁ÷£º
l ÊäÈëÊý¾ÝÁ÷
ËùÓÐÔ´¶Ë¿ÚÉϽӹܵ½µÄ±¨Îͼ½«±»¸´ÔìÒ»·Ýµ½Ö÷ÕŶ˿ڡ£ÔÚÒ»¸ö¾µÏñ»á»°ÖУ¬Äܹ»¼à¿ØÒ»¸ö»ò¶à¸öÔ´¶Ë¿ÚµÄÊäÈ뱨ÎÄ¡£
l Êä³öÊý¾ÝÁ÷
ËùÓдÓÔ´¶Ë¿Ú·¢Ë͵ı¨Îͼ½«¸´ÔìÒ»·Ýµ½Ö÷ÕŶ˿ڡ£ÔÚÒ»¸ö¾µÏñ»á»°ÖУ¬Äܹ»¼à¿ØÒ»¸ö»ò¶à¸öÔ´¶Ë¿ÚµÄÊä³ö±¨ÎÄ¡£
l Ë«ÏòÊý¾ÝÁ÷
ͬʱÔ̺¬ÊäÈëÊý¾ÝÁ÷ºÍÊä³öÊý¾ÝÁ÷¡£ÔÚÒ»¸ö¾µÏñ»á»°ÖУ¬¿É¼à¿ØÒ»¸ö»ò¶à¸öÔ´¶Ë¿ÚµÄÊäÈëºÍÊä³ö·½ÏòµÄÊý¾ÝÁ÷¡£
Èçͼ1-1Ëùʾ£¬Í¨¹ýÔÚDeviceAÉÏÅäÖÃÁËSPAN£¬É豸½«Port 1Éϵı¨Îĸ´ÔìÒ»·Ýµ½Port 10£¬ÏνÓÔÚPort 10ÉϵÄÍøÂç·ÖÎöÉ豸¹ÌȻδÓëPort1Ö±½ÓÏàÁ¬£¬µ«ÊÇÄܹ»½Ó¹Üͨ¹ýPort1ÉϵÄËùÓб¨ÎÄ£¬´Ó¶øÊµÏÖÁË¼à¿ØPort 1½Ó¿Ú´«ÊäµÄÊý¾ÝÁ÷µÄÖ÷ÕÅ¡£¾ßÌ幤×÷¹ý³ÌÈçÏ£º
(1) É豸¼ø±ðÓëÏóÕ÷³ö´ÓÔ´¶Ë¿ÚPort 1½ø³öµÄ±¨ÎÄ¡£
(2) É豸²éÕÒPort 1ËùÊôµÄ¾µÏñ»á»°¡£
(3) É豸²éÕҸþµÏñ»á»°¶ÔÓ¦µÄÖ÷ÕŶ˿ÚPort 10¡£
(4) É豸¸´ÔìÒ»·Ý½ø³öPort 1µÄ±¨ÎÄ·¢ËÍÖÁPort 10¡£
(5) Port 10½«±¨ÎÄ·¢ËÍÖÁÍøÂç·ÖÎöÉ豸¡£
ͼ1-1 SPAN¹¤×÷µÀÀíͼ

Èçͼ1-2Ëùʾ£¬RSPANµÄµÀÀíÊÇÔÚÔ´É豸¡¢ÖÐÑëÉ豸ºÍÖ÷ÕÅÉ豸´´½¨Ò»¸öÔ¶³Ì¾µÏñVLAN£¬ÇÒËùÓвμӾµÏñ»á»°µÄ¶Ë¿Ú¶¼²ÎÓë¸ÃÔ¶³Ì¾µÏñVLAN¡£Ô¶³Ì¾µÏñVLANÖÐͨ¹ý¹ã²¥£¬Ê¹µÃÔ´É豸½«¾µÏñ±¨ÎÄת·¢µ½Ö÷ÕÅÉ豸£¬Ö÷ÕÅÉ豸ÔÙ½«¾µÏñ±¨ÎÄת·¢µ½ÍøÂç·ÖÎöÉ豸¡£¾ßÌ幤×÷¹ý³ÌÈçÏ£º
(1) Ô´É豸¡¢ÖÐÑëÉ豸ºÍÖ÷ÕÅÉ豸É豸ÖвμӾµÏñ»á»°µÄ¶Ë¿Ú¾ù²ÎÓëµ½Ô¶³Ì¾µÏñVLANÖС£
(2) Ô´É豸½«Ô´¶Ë¿ÚÖеľµÏñ±¨ÎÄ·â×°Ô¶³Ì¾µÏñVLANµÄID£¬²¢¸´ÔìÒ»·Ýµ½Êä³ö¶Ë¿Ú¡£
×¢Ã÷
Èçͼ1-3¶ÔÓÚÒ»¶Ô¶à¾µÏñ£¬±ØÒªÔÚÔ´É豸µÄÊä³ö¶Ë¿ÚÉÏ¿ªÆôΪMAC»Ø»·Ö°ÄÜʹÆä³ÉΪ×Ô»·¿Ú£¬²¢½«×Ô»·¿Ú¼°ÓëÖÐÑëÉ豸ÏνӵĽӿڣ¨Í¼1-3ÖеÄPort1ºÍPort2£©²ÎÓëÔ¶³Ì¾µÏñVLAN¡£Ô´¶Ë¿Ú½«±¨ÎľµÏñ´«Êäµ½×Ô»·¿Ú£¬¾µÏñ±¨ÎÄÔö³¤Ô¶³Ì¾µÏñVLANµÄID¡£ÓÉÓÚ×Ô»·¿ÚÊôÓÚÔ¶³Ì¾µÏñVLANÇÒ¸ÃVLAN²»Èݽø½¨MACµØÖ·£¬Òò¶ø·´É仨À´µÄ±¨ÎÄÔÚÔ¶³Ì¾µÏñVLANÄڹ㲥£¬ËÁÒâ²ÎÓëÔ¶³Ì¾µÏñVLANµÄ½Ó¿Ú¾ù¿ÉÄܽӹܵ½¾µÏñ±¨ÎÄ£¬´Ó¶øÊµÏÖÒ»¶Ô¶à¾µÏñ¡£
(3) Êä³ö¶Ë¿Úͨ¹ýÔ¶³Ì¾µÏñVLAN½«¾µÏñ±¨ÎÄÊä³öµ½ÖÐÑëÉ豸»òÕßÖ÷ÕÅÉ豸¡£
(4) ÖÐÑëÉ豸ÔÚÔ¶³Ì¾µÏñVLANÖй㲥¾µÏñ±¨ÎÄ£¬½«¾µÏñ±¨ÎÄ͸´«µ½ÏÂÒ»¸öÖÐÑëÉ豸»òÕßÖ÷ÕÅÉ豸¡£
×¢Ã÷
ÈôÊÇÔ´É豸ÓëÖ÷ÕÅÉ豸ֱ½ÓÏνӣ¬ÔòÊä³ö¶Ë¿Ú½«¾µÏñ±¨ÎÄÊä³öµ½Ö÷ÕÅÉ豸¡£
(5) Ö÷ÕÅÉ豸½Ó¹Üµ½±¨Îĺó£¬Í¨¹ý±¨ÎÄЯ´øµÄVLAN IDÅжϸñ¨ÎÄÊÇ·ñΪ¾µÏñ±¨ÎÄ£¬µ±±¨ÎÄЯ´øµÄVLAN IDÓëÔ¶³Ì¾µÏñVLAN IDÒ»ÖÂʱ£¬ÔòÅжϸñ¨ÎÄΪ¾µÏñ±¨ÎÄ£¬²¢½«¸Ã±¨ÎÄͨ¹ýÖ÷ÕŶ˿Úת·¢¸øÍøÂç·ÖÎöÒÇ¡£
ͼ1-2 RSPAN¹¤×÷µÀÀíͼ

ͼ1-3 »ùÓÚRSPANʵÏÖµÄÒ»¶Ô¶à¾µÏñµÀÀíͼ

ÔÚRSPANÖУ¬¾µÏñ±¨ÎÄÖ»ÄÜÔÚ¶þ²ãÄÚ´«Ê䣬ÎÞ·¨¿ç·ÓÉÍø¶Îת·¢£¬¶øERSPAN½«¾µÏñ±¨ÎÄͨ¹ýGRE£¨Generic Routing Encapsulation£¬Í¨Ó÷ÓɺÍ̸·â×°£©Ëí··â×°³ÉIP±¨Îĺó£¬ÔÙ½«¾µÏñ±¨ÎÄת·¢µ½Ô¶¶Ë¾µÏñÉ豸µÄÖ÷ÕŶ˿ڣ¬ÊµÏÖÁ˾µÏñ±¨ÎĵĿç·ÓÉÍø¶ÎµÄ´«Êä¡£
Èçͼ1-4Ëùʾ£¬ERSPANµÄ¾ßÌ幤×÷¹ý³ÌÈçÏ¡£
(1) Ô´É豸½«½øÈëÔ´¶Ë¿ÚµÄ±¨Îĸ´ÔìÒ»·Ý²¢½øÐзâ×°¡£
¡ð ·â×°µÄGRE±¨ÎĵÄÔ´IP¡¢Ö÷ÕÅIP¡£
¡ð ÉèÖÃGRE±¨ÎĵÄTTLºÍDSCPÖµ¡£
¡ð ·â×°IPv6±¨ÎĵÄhop-limitºÍtraffic-classÖµ¡£
×¢Ã÷
¾µÏñ±¨Îľ¹ýERSPAN·â×°ºóµÄ±¨ÎÄÍ·²¿ÌåʽÈçͼ1-5Ëùʾ¡£
(2) ͨ¹ýGREËí·£¬½«¾µÏñ±¨ÎÄת·¢ÖÁÖ÷ÕÅÉ豸¡£
(3) Ö÷ÕÅÉ豸½«¾µÏñ±¨ÎĽøÐÐGREÄ£¿é½â·â×°£¬°þÀëERSPAN·â×°Í·²¿ºó½«¾µÏñ±¨ÎÄת·¢µ½Ö÷ÕŶ˿ڡ£
(4) Ö÷ÕŶ˿ڽ«¾µÏñ±¨ÎÄת·¢µ½ÍøÂç·ÖÎöÉ豸¡£
°ÑÎÈ
½øÐÐGRE·â×°ºóµÄIP±¨ÎıØÐëÊÇ¿ÉÄÜÔÚÍøÂçÖÐÕý³£Â·Óɵ½Ö÷ÕžµÏñÉ豸µÄ£¬Òò¶øÖ÷ÕÅIPͨ³£ÊÇ·ÓɵÄÏÂÒ»ÌøIP¡£¼´Ô´É豸µÄÊä³ö¶Ë¿ÚÊÇÆäÒª·â×°µÄÖ÷ÕÅIPµØÖ·µØµãµÄÈý²ãͨ·µÄÏÂÒ»Ìø³ö¿Ú£¬ËùÒÔ¾µÏñÊä³ö¿Ú±ØÐëÊÇ·ÓɿɴïµÄ½Ó¿Ú£¬¿ÉËùÒÔSVI½Ó¿Ú£¬Èý²ã¾ÛºÏ½Ó¿Ú»òÕßÈý²ãÒÔÌ«Íø½Ó¿Ú¡£
ͼ1-4 ERSPAN¹¤×÷µÀÀíͼ

ͼ1-5 ERSPAN·â×°±¨ÎÄÌåʽͼ
![]()
Á÷µÄ¾µÏñÊÇÔڶ˿ھµÏñµÄ»ù´¡ÉÏ£¬½«Ô´¶Ë¿ÚÓëACL¹ØÁª£¬Æ¾¾ÝACL¹æ¶¨¶Ô±¨ÎĽøÐйýÂË£¬´ïµ½Ö»¾µÏñÖ¸¶¨±¨ÎĵÄÖ÷ÕÅ¡£Ô´¶Ë¿ÚÖ»ÓÐÆ¥Åäµ½ACLÖÐpermit aceµÄ±¨ÎÄÄÜÁ¦±»¾µÏñµ½Ö÷ÕŶ˿ڡ£Ò»¸öÔ´¶Ë¿ÚÖ»ÄܹØÁªÒ»¸öACL¡£¿É¹ØÁªµÄACLÓг߶ÈACL¡¢À©´óACL¡¢MAC ACLºÍ×Ô½ç˵ACL¡£
l Ô´¶Ë¿ÚÓµÓÐÒÔϸöÐÔ£º
¡ð Ô´¶Ë¿ÚÓëÊä³ö¶Ë¿Ú²»ÄÜΪͳһ¶Ë¿Ú¡£
¡ð Ô´¶Ë¿Ú¿ÉËùÒÔ¶þ²ãÒÔÌ«Íø½Ó¿Ú£¬Èý²ãÒÔÌ«Íø½Ó¿Ú¡¢¶þ²ã¾ÛºÏ¿Ú»òÈý²ã¾ÛºÏ¿Ú¡£
¡ð Ö§³Ö½«Ô´É豸ÉϵĶà¸öÔ´¶Ë¿ÚÊý¾ÝÁ÷¾µÏñµ½Ö¸¶¨µÄÊä³ö¶Ë¿Ú¡£
¡ð µ±¾µÏñÔ´¶Ë¿ÚΪÈý²ãÒÔÌ«Íø½Ó¿Ú»òÈý²ã¾ÛºÏ¿Úʱ£¬¼à¿ØµÄ±¨ÎÄÔ̺¬¶þ²ã±¨ÎĺÍÈý²ã±¨ÎÄ¡£
¡ð ÔÚË«Ïò¼à¿Ø¶à¸ö¶Ë¿ÚµÄÇé¿öÏ£¬Ò»·Ý±¨ÎÄÓÉÒ»¸ö¶Ë¿Ú½øÈ룬´ÓÁí±íÒ»¸ö¶Ë¿ÚÊä³ö£¬Ö»ÓÐÓÐ¼à¿Øµ½Ò»·Ý±¨Îļ´ÊÓΪ±¨Îı»¾µÏñ³É¹¦¡£
¡ð µ±¶Ë¿ÚÆôÓÃSTP²¢´¦ÓÚBLOCK״̬ʱ£¬¸Ã¶Ë¿ÚµÄÊäÈë»òÊä³öµÄ±¨ÎÄÒ²¿ÉÄܱ»¼à¿Øµ½¡£
¡ð Ô´¶Ë¿ÚºÍÖ÷ÕŶ˿ÚÄܹ»ÊôÓÚͳһVLAN£¬Ò²Äܹ»ÊôÓÚ·ÖÆçVLAN¡£
¡ð ÈôÊǽ«Ô´¶Ë¿Ú²ÎÓë¾ÛºÏ¿Ú£¬Ôò¸ÃÔ´¶Ë¿Ú½«Í˳ö¾µÏñ»á»°£¬½ö×÷Ϊ¾ÛºÏ¿ÚµÄ³ÉÔ±¿Ú£¬²»ÔÙ×÷Ϊ¾µÏñ»á»°µÄÔ´¶Ë¿Ú¡£
l Ö÷ÕŶ˿ÚÓµÓÐÒÔϸöÐÔ£º
¡ð Ö÷ÕŶ˿ڲ»ÄÜͬʱ×÷ΪԴ¶Ë¿Ú¡£
¡ð Ö÷ÕŶ˿ڿÉËùÒÔÒÔÌ«Íø½Ó¿Ú»ò¾ÛºÏ½Ó¿Ú¡£
l ÒѾÅäÖõĻỰID²»ÄÜ×÷ΪÆäËû¾µÏñ»á»°µÄID¡£
l ȱʡÇé¿öÏ£¬¾µÏñÖ÷ÕÅ¿ÚûÓпªÆôswitchÖ°ÄÜ£¬Ö÷Õſڲ»²Î¼ÓÊý¾Ýת·¢£¬Ö»½Ó¹Ü¾µÏñ±¨ÎÄ¡£ÈôÊDZØÒªÖ÷ÕſڲμÓÊý¾Ýת·¢£¬Ôò±ØÒª¿ªÆôswitchÖ°ÄÜ£¬²»È»¶ÔÓÚÁ÷¾¸Ã¶Ë¿ÚµÄÊý¾Ý±¨ÎĽ«±»Åׯú¡£
l ÓÉÓÚÆäËûÔÒò£¨Èç¶Ë¿Ú°²È«£©£¬´ÓÔ´¶Ë¿ÚÊäÈëµÄ±¨ÎÄ¿ÉÄܱ»Åׯú£¬µ«Õâ²»Ó°Ïì¾µÏñÖ°ÄÜ£¬¸Ã±¨ÎÄÒÀÈ»»á±»¾µÏñµ½Ö÷ÕŶ˿ڡ£¶øÓÉÓÚÆäËûÔÒò£¬´ÓÆäËû¶Ë¿Ú·¢Ë͵½Ô´¶Ë¿ÚµÄ±¨ÎÄ¿ÉÄܱ»Åׯú£¬Òò¶ø¸Ã±¨ÎÄÒ²²»»á·¢Ë͵½Ö÷ÕŶ˿ڡ£
l ÈôÊÇ´ÓÔ´¶Ë¿ÚÊä³öµÄ±¨ÎĵÄÌåʽ²úÉúŤתʱ£¬ÀýÈçÔ´¶Ë¿ÚÊä³ö¾¹ý·ÓÉÖ®ºóµÄ±¨ÎÄ£¬±¨ÎĵÄÔ´MAC¡¢Ö÷ÕÅMAC¡¢VLAN IDÒÔ¼°TTL²úÉú±ä¶¯Ê±£¬Ôò¾µÏñµ½Ö÷ÕŶ˿ڵı¨ÎĵÄÌåʽҲ»áËæÖ®²úÉú±ä¶¯¡£
l Äܹ»Í¨¹ýÔÚÔ´¶Ë¿ÚÅäÖÃACL´ïµ½¾µÏñÖ¸¶¨µÄÊý¾ÝÁ÷µÄÖ÷ÕÅ£¬Ö§³Ö³ß¶ÈACL¡¢À©´óACL¡¢MAC ACLºÍ×Ô½ç˵ACL¡£
l ÅäÖÃSPAN
b
£¨¿ÉÑ¡£©ÅäÖÃERSPANµÄ²ÉÑùÖ°ÄÜ
c
£¨¿ÉÑ¡£©ÅäÖÃERSPANµÄÊôÐÔ
SPANͨ¹ý½«Ö¸¶¨¶Ë¿Ú»òÖ¸¶¨VLANµÄ±¨Îĸ´Ôìµ½ÓëÊý¾Ý¼à²âÉ豸ÏàÁ¬µÄ¶Ë¿Ú£¬Äܹ»ÀûÓÃÊý¾Ý¼à²âÉ豸·ÖÎöÕâЩ¸´Ôì¹ýÀ´µÄ±¨ÎÄ£¬ÒÔ½øÐÐÍøÂç¼à¿ØºÍ¹ÊÕÏÅųý¡£
l ÅäÖþµÏñÔ´¶Ë¿Úʱ£¬Äܹ»Í¬Ê±ÅäÖÃÖ¸¶¨²¿ÃÅVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿ÚÉϵÄÖ¸¶¨Á÷×÷Ϊ¾µÏñµÄÊý¾ÝÔ´Ö°ÄÜ¡£
l ÅäÖþµÏñÔ´¶Ë¿Úʱ£¬Ö¸¶¨Ä³¸öVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´Ö°ÄÜÓëÖ¸¶¨²¿ÃÅVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿ÚÉϵÄÖ¸¶¨Á÷×÷Ϊ¾µÏñµÄÊý¾ÝÔ´Ö°ÄÜ»¥³â¡£
l ÅäÖþµÏñÔ´¶Ë¿Úʱ£¬Ö¸¶¨²¿ÃÅVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´ºó£¬Í¬Ê±»¹±ØÒªÅäÖÃÖ¸¶¨½Ó¿Ú×÷ΪԴ¶Ë¿Ú¡£
l ÈôÊÇŤתÁËÔ´¶Ë¿Ú»òÖ÷ÕŶ˿ڵÄVLANÅäÖã¬ÅäÖý«¶ÙʱÉúЧ¡£
l ÈôÊǽûÓÃÁËÔ´¶Ë¿Ú»òÖ÷ÕŶ˿ڣ¬¾µÏñÖ°Äܽ«Ê§Ð§¡£
l ÈôÊÇVLAN»òVLANÁбí×÷Ϊ¾µÏñԴʱ£¬Òª±£ÕÏÖ÷ÕÅ¿ÚÓÐ×ã¹»´óµÄ¿í´ø¿ÉÄܽӹÜÕû¸öVLANµÄ¾µÏñÊý¾Ý¡£
l ÈôÊÇÔÚÒѾÉúЧµÄÖ¸¶¨VLANΪԴ¿ÚµÄ¾µÏñ»á»°ÖУ¬Ôö³¤»òɾ³ýVLANÔ´¿Ú£¬±ØÒª³ÁÐÂÀûÓÃÕû¸ö¾µÏñ»á»°£¬Òò¶øÒÑÓеľµÏñÁ÷Á¿¿ÉÄÜ»á³öÏÖÉÙÁ¿¶ª°ü¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ÅäÖþµÏñÔ´¶Ë¿Ú¡£ÇëÖÁÉÙÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡£
monitor session session-number source interface interface-type interface-number [ { both | rx | tx } [ acl acl-name | acl acl-number ]
¡ð £¨¿ÉÑ¡£©ÅäÖÃÖ¸¶¨²¿ÃÅVLAN²»ÄÜ×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡£
monitor
session session-number filter vlan vlan-id-list rx
±¾ºÅÁî±ØÒªÓëmonitor session source interfaceºÅÁî»òmonitor session source interface aclºÅÁîͬʱÅäÖÃʹÓá£
¡ð ÅäÖÃÖ¸¶¨Ä³Ð©VLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡£
monitor session session-number source vlan vlan-id-list rx
ÐÔ×ÓÄÜÓëÖ¸¶¨²¿ÃÅVLAN×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡¢ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´Ö°ÄÜ»¥³â¡£
ȱʡÇé¿öÏ£¬Î´ÅäÖþµÏñ»á»°µÄÔ´¶Ë¿Ú¡£
(4) ÅäÖþµÏñÖ÷ÕŶ˿ڡ£
monitor session session-number destination interface interface-type interface-number switch
ȱʡÇé¿öÏ£¬Î´ÅäÖþµÏñÖ÷ÕŶ˿ڡ£
ͨ¹ýÅäÖÃRSPANÖ°ÄÜ£¬¿ÉÄÜ¿çÉ豸¼à¿ØÊý¾Ý±¨ÎÄÒÔ½øÐÐÍøÂç¼à¿ØºÍ¹ÊÕÏÅųý¡£
l ËùÓвμӾµÏñµÄ±¨ÎľùÒª²ÎÓëÔ¶³ÌVLANÖС£
l Ô¶³Ì¾µÏñVLAN±ØÐëÔÚÿ̨É豸Öж¼Òª½øÐÐÅäÖã¬ÇÒVLAN ID±ØÐëÒ»Ö£¬²¢ÇÒËùÓвμӻỰµÄ¶Ë¿Ú¶¼Òª²ÎÓë¸ÃVLANÖС£ÇëÔ¤·À½«Í¨³£¶Ë¿Ú²ÎÓëÔ¶³Ì¾µÏñVLAN¡£
l ½¨Òé²»Òª½«ÓëÖÐÑëÉ豸ÏàÁ¬µÄ¶Ë¿Ú»òÓëÖ÷ÕÅÉ豸ÏàÁ¬µÄ¶Ë¿ÚÅäÖÃΪ¾µÏñÔ´¶Ë¿Ú£¬²»È»¿ÉÄÜÒýÆðÍøÂçÄÚµÄÁ÷Á¿»ìÂÒ¡£
l ΪÁËʵÏÖÒ»¶Ô¶à¾µÏñ£¬±ØÒªÔÚÔ´É豸ÉϰÎȡһ¸ö½Ó¿ÚÅäÖÃΪMAC»Ø»·¿Ú£¬½«Êä³ö¶Ë¿Úͨ¹ýMAC»Ø»·¿ÚµÄ¡°×Ô»·¡±Ö°ÄÜ£¬Í¨¹ýʵÏÖ½«¾µÏñ±¨ÎÄÊä³öµ½¶à¸öÖÐÑëÉ豸»òÕß¶à¸öÖ÷ÕÅÉ豸µÄÖ°ÄÜ¡£
l MAC»Ø»·¿ÚÎÞ·¨×÷ΪÕý³£µÄ¶Ë¿Úת·¢Á÷Á¿¡£½¨Ò齫´¦ÓÚDOWN״̬µÄ¶Ë¿ÚÅäÖÃΪMAC»Ø»·¿Ú£¬ÇÒ²»ÒªÔڸö˿ÚÉÏÔö³¤ÆäËûÅäÖá£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ½øÈëVLANÅäÖÃģʽ¡£
vlan vlan-id
(4) ÅäÖÃÔ¶³ÌVLAN¡£
remote-span
ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ¶³ÌVLAN¡£
(5) Í˳öVLANÅäÖÃģʽ¡£
exit
(6) ÅäÖÃÔ¶³Ì¾µÏñµÄÔ´É豸¡£
monitor session session-number remote-source
ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ¶³Ì¾µÏñ»á»°ÖеÄÔ´É豸¡£
(7) £¨¿ÉÑ¡£©ÔÚÔ´É豸ÉÏÅäÖÃMAC×Ô»·Ö°ÄÜ¡£
a ½øÈë¶þ²ãÒÔÌ«Íø½Ó¿Ú»òÈý²ãÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£
interface interface-type interface-number
b ´ò¿ª½Ó¿ÚMAC×Ô»·Ö°ÄÜ¡£
mac-loopback
ȱʡÇé¿öÏ£¬½Ó¿ÚMAC×Ô»·Ö°ÄÜ´¦ÓڹعØ×´Ì¬¡£
(8) Í˳ö¶þ²ãÒÔÌ«Íø½Ó¿Ú»òÈý²ãÒÔÌ«Íø½Ó¿ÚÅäÖÃģʽ¡£
exit
(9) ÅäÖÃÔ´É豸ÉϵÄÔ´¶Ë¿Ú¡£
monitor session session-number
source interface interface-type interface-number [ { both | rx | tx } [ acl { acl-name | acl-number } ]
ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ´É豸ÉϵľµÏñ»á»°Ô´¶Ë¿Ú¡£
(10) ÅäÖÃÔ¶³Ì¾µÏñµÄÖ÷ÕÅÉ豸¡£
monitor session session-number remote-destination
ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ¶³Ì¾µÏñµÄ»á»°Ö÷ÕÅÉ豸¡£
(11) ÅäÖÃÔ´É豸ÉϵÄÊä³ö¶Ë¿Ú»òÕßÖ÷ÕÅÉ豸ÉϵÄÖ÷ÕŶ˿ڡ£
monitor session session-number destination remote vlan remote-vlan-id interface interface-type interface-number switch
ȱʡÇé¿öÏ£¬Î´ÅäÖÃÔ¶³Ì¾µÏñÔ´É豸µÄÊä³ö¶Ë¿Ú»òÔ¶³Ì¾µÏñÖ÷ÕÅÉ豸µÄÖ÷ÕŶ˿ڡ£
ERSPANÅäÖù¤×÷ÈçÏ£º
(2)
£¨¿ÉÑ¡£©ÅäÖÃERSPANµÄ²ÉÑùÖ°ÄÜ
(3) £¨¿ÉÑ¡£©ÅäÖÃERSPANµÄÊôÐÔ
ÅäÖÃERSPANºóÍøÂç·ÖÎöÒÇÄܹ»Í¨¹ýÔ¶³Ì¾µÏñ¼à¿ØÍøÂçÉ豸µÄÊý¾ÝÁ÷¡£É豸֮¼ä¾ùÄÜÕý³£»¥»»Êý¾Ý¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ÅäÖÃERSPAN»á»°¡£
monitor session
session-number erspan-source
ȱʡÇé¿öÏ£¬Î´ÅäÖÃERSPAN»á»°¡£
(4) ÅäÖÃÖ¸¶¨½Ó¿Ú×÷Ϊ¾µÏñµÄÊý¾ÝÔ´¡£
source interface { interface-type interface-numbere | all } [ both | rx [ acl { acl-name | acl-number } ] | tx ]
ȱʡÇé¿öÏ£¬Î´ÅäÖþµÏñÔ´¶Ë¿Ú£¬µ±ÅäÖÃÔ´¶Ë¿Úʱ¾µÏñÊý¾ÝµÄ·½ÏòȱʡΪ˫ÏòÊý¾ÝÁ÷¡£
(5) ÅäÖ÷â×°Ô´IPµØÖ·¡£
original { ip | ipv6 } address ip-address
ȱʡÇé¿öÏ£¬Î´ÅäÖÃGRE·â×°µÄÖ¸¶¨Ô´IPµØÖ·¡£
(6) ÅäÖ÷â×°Ö÷ÕÅIPµØÖ·¡£
destination { ip | ipv6 } address ip-address
ȱʡÇé¿öÏ£¬Î´ÅäÖ÷â×°µÄÀàÐͼ°Ö¸¶¨Ö÷ÕÅIPµØÖ·¡£
l ERSPANµÄ²ÉÑùÖ°ÄÜÖ»ÓÐÔڻỰ»òÕß¾µÏñÔ´¶Ë¿ÚÅäÖÃÁ˲ÉÑùÖ°ÄÜʱ²ÅÉúЧ¡£
l ¶ÔÓÚERSPANÅäÖÃÁ÷²ÉÑùµÄ²ÉÑù±Èʱ£¬²ÉÑù±È»áÒÔ×î¿¿½üµÄ2µÄn´Î·½ÉúЧ¡£ÈçÅäÖõIJÉÑù±ÈΪ100£¬ÔòÏÖʵÉúЧµÄ²ÉÑù±ÈΪ128¡£
l ²ÉÑù±ÈÏÖʵÉúЧµÄÁìÓòΪ2^0~2^14£¬¼´1~16384¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ÅäÖÃERSPAN»á»°¡£
monitor session
session-umber erspan-source
(4) ÅäÖÃÔ´¶Ë¿Ú¡£
source interface interface-type interface-number { [ rx | tx | both ] }
ȱʡÇé¿öÏ£¬Î´ÅäÖþµÏñÔ´¶Ë¿Ú£¬µ±ÅäÖÃÔ´¶Ë¿Úʱ¾µÏñ·½ÏòȱʡΪboth·½Ïò¡£
(5) ÅäÖ÷â×°Ô´IPµØÖ·¡£
original { ip | ipv6 } address ip-address
ȱʡÇé¿öÏ£¬Î´ÅäÖÃGRE·â×°µÄÖ¸¶¨Ô´IPµØÖ·¡£
(6) ÅäÖ÷â×°Ö÷ÕÅIPµØÖ·¡£
destination { ip | ipv6 } address ip-address
ȱʡÇé¿öÏ£¬Î´ÅäÖ÷â×°µÄÀàÐͼ°Ö¸¶¨Ö÷ÕÅIPµØÖ·¡£
(7) ÅäÖûùÓÚÁ÷µÄERSPAN²ÉÑùÖ°ÄÜ¡£
source interface { interface-type interface-number | all }rx acl { acl-name | acl-number } [ sample ]
ȱʡÇé¿öÏ£¬Î´ÅäÖûùÓÚÁ÷µÄERSPAN²ÉÑùÖ°ÄÜ¡£
(8) £¨¿ÉÑ¡£©ÅäÖõIJÉÑùƵÂÊ¡£
sampling-rate rate
ȱʡÇé¿öÏ£¬²ÉÑùƵÂÊÊÇ1:1£¬°µÊ¾Ã¿¸ö±¨Îͼ½øÐвÉÑù¡£
(1) ½øÈëÌØÈ¨Ä£Ê½¡£
enable
(2) ½øÈëÈ«¾ÖÅäÖÃģʽ¡£
configure terminal
(3) ÅäÖÃERSPAN»á»°¡£
monitor session
session-number erspan-source
(4) ÅäÖÃERSPAN»á»°µÄÊôÐÔ¡£ÒÔÏÂÅäÖþùΪ¿ÉÑ¡£¬ÇëÆ¾¾ÝÏÖʵÐèÒªÖÁÉÙÑ¡ÔñÆäÖÐÒ»Ïî½øÐÐÅäÖá£
¡ð ·â×°IP TTL
ip ttl ttl-value
ȱʡÇé¿öÏ£¬·â×°IP±¨ÎĵÄTTLֵΪ64¡£
¡ð ·â×°IP DSCP
ip dscp dscp-value
ȱʡÇé¿öÏ£¬·â×°IP±¨ÎĵÄDSCPֵΪ0¡£
¡ð
·â×°IPv6 hop-limitÖµ¡£
ipv6
hop-limit value
ȱʡÇé¿öÏ£¬·â×°IPv6±¨ÎĵÄhop-limitֵΪ64¡£
¡ð ·â×°ipv6 traffic-classÖµ¡£
ipv6
traffic-class value
ȱʡÇé¿öÏ£¬·â×°IPv6±¨ÎĵÄtraffic-classֵΪ0¡£
traffic-classµÄ¿ÉÅäÖÃÁìÓòΪ0~255£¬µ«ÏÖʵֻÓÐǰ6±ÈÌØ·â×°ÉúЧ£¬¼´Ö»ÓÐDSCP£¨0-63£©·â×°ÉúЧ£¬ºó2±ÈÌØ²¹0¡£
¡ð ÅäÖÃERSPANÓëVRFÁª¶¯¡£
vrf vrf-name
ȱʡÇé¿öÏ£¬Î´ÅäÖÃERSPANÓëVRFÁª¶¯Ö°ÄÜ¡£
ÅäÖøÃÖ°ÄÜʱVRF±ØÐëÒѾ´æÔÚ¡£
(5) £¨¿ÉÑ¡£©¹Ø¹ØERSPAN»á»°¡£
shutdown
ȱʡÇé¿öÏ£¬»á»°Ö°ÄÜ´¦ÓÚ¿ªÆô״̬¡£
Äܹ»Í¨¹ýshowºÅÁîÐв鿴ְÄÜÅäÖúóµÄÔËÐÐÇé¿öÒÔÑéÖ¤ÅäÖóÉЧ¡£
Äܹ»Í¨¹ýdebugºÅÁîÐÐÁоÙÊä³öµÄ¸÷Ààµ÷ÊÔÐÅÏ¢¡£
±í1-1 SPAN-RSPAN¼à¶½ÓëÊØ»¤
|
×÷ÓÃ |
ºÅÁî |
|
²é¿´¾µÏñ»á»°ÐÅÏ¢ |
show monitor [ session session-number ] |
|
´ò¿ª¾µÏñ»á»°µÄµ÷ÊÔ¿ª¹Ø |
debug span |
Èçͼ1-6Ëùʾ£¬Í¨¹ýÊʵ±µÄÅäÖã¬ÍøÂç·ÖÎöÒÇ¿ÉÄÜ¼à¿ØDeviceAת·¢¸øDeviceBµÄËùº±¼û¾ÝÁ÷£¬¼à¿ØÀ´×ÔDeviceBµÄÌØ¶¨Êý¾ÝÁ÷£¨ÈçÀ´×ÔPC1ºÍPC2µÄÊý¾ÝÁ÷£©¡£
ͼ1-6 SPAN×éÍøÍ¼

l ÅäÖÃDeviceAµÄGigabitEthernet 0/1ºÍGigabitEthernet 0/2ÊôÓÚVLAN 1¡£´´½¨SVI 1£¬²¢ÅäÖÃSVI
1µØÖ·Îª10.10.10.10/24¡£
l ÅäÖÃDeviceBµÄGigabitEthernet 0/1ÊôÓÚVLAN 1¡£´´½¨SVI 1£¬²¢ÅäÖÃSVI 1µØÖ·Îª10.10.10.20/24¡£
l ÅäÖÃPC1¡¢PC2µÄµØÖ·±ðÀëΪ10.10.10.1/24ºÍ10.10.10.2/24¡£
l ÅäÖÃDeviceAµÄ±¾µØ¾µÏñ£¬Ö¸¶¨¶Ë¿ÚGigabitEthernet 0/1ºÍGigabitEthernet 0/2±ðÀëΪ¾µÏñµÄÔ´¶Ë¿ÚºÍÖ÷ÕŶ˿ڡ£¼à¿ØDeviceAת·¢¸øDeviceBµÄËùº±¼û¾ÝÁ÷£¬¼à¿ØÀ´×ÔDeviceBµÄÌØ¶¨Êý¾ÝÁ÷¡£
# ÅäÖÃDeviceAµÄGigabitEthernet 0/1ºÍGigabitEthernet 0/2ÊôÓÚVLAN 1¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# vlan 1
DeviceA(config-vlan)# exit
# ÔÚDeviceAÉÏ´´½¨SVI 1£¬²¢ÅäÖÃSVI 1µØÖ·Îª10.10.10.10/24¡£
DeviceA(config)# interface vlan 1
DeviceA(config-if-VLAN 1)# ip address 10.10.10.10 255.255.255.0
DeviceA(config-if-VLAN 1)# exit
# ÅäÖÃDeviceBµÄGigabitEthernet 0/1ÊôÓÚVLAN 1¡£
DeviceB# configure
DeviceB(config)# vlan 1
DeviceB(config-vlan)# exit
# ÔÚDeviceBÉÏ´´½¨SVI 1£¬²¢ÅäÖÃSVI 1µØÖ·Îª10.10.10.20/24¡£
DeviceB (config)# interface vlan 1
DeviceB(config-if-VLAN 1)# ip address 10.10.10.20 255.255.255.0
DeviceB(config-if-VLAN 1)# exit
# ÔÚDeviceAÉÏÅäÖÃACL£¬Æ¥ÅäÔ´µØÖ·Îª10.10.10.20µÄ±¨ÎÄ¡£
DeviceA(config)# access-list 100 permit ip host 10.10.10.20 any
# ÔÚDeviceAÉÏÅäÖö˿ÚGigabitEthernet 0/1Ϊ¾µÏñµÄÔ´¶Ë¿Ú£¬¼à¿ØDeviceAת·¢¸øDeviceBµÄËùº±¼û¾ÝÁ÷£¬¼à¿ØÀ´×ÔDeviceBµÄÌØ¶¨Êý¾ÝÁ÷¡£
DeviceA(config)# monitor session 1 source interface gigabitethernet 0/1 tx
DeviceA(config)# monitor session 1 source interface gigabitethernet 0/1 rx acl 100
# ÔÚDeviceAÉÏÅäÖÃGigabitEthernet 0/2Ϊ¾µÏñµÄÖ÷ÕŶ˿ڡ£
DeviceA(config)# monitor session 1 destination interface gigabitethernet 0/2
# ͨ¹ýshow monitorºÅÁî²é¿´¾µÏñÊÇ·ñÕýÈ·ÅäÖá£
DeviceA# show monitor
sess-num: 1
span-type: LOCAL_SPAN
src-intf:
¡¡GigabitEthernet 0/1¡¡¡¡¡¡¡¡ frame-type TX Only
src-intf:
¡¡GigabitEthernet 0/1¡¡¡¡¡¡¡¡ frame-type RX Only
rx acl id 100
dest-intf:
¡¡GigabitEthernet 0/2
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
ip access-list extended 100
?10 permit ip host 10.10.10.20 any
!
interface VLAN 1
?ip address 10.10.10.10 255.255.255.0
!
monitor session 1 destination interface GigabitEthernet 0/2
monitor session 1 source interface GigabitEthernet 0/1 tx
monitor session 1 source interface GigabitEthernet 0/1 rx acl 100
!
end
l DeviceBµÄÅäÖÃÎļþ
hostname DeviceB
!
interface VLAN 1
?ip address 10.10.10.20 255.255.255.0
!
end
ÖÒ¸æ
µ±²¿ÊðÒ»¶Ô¶à¶Ë¿Ú¾µÏñʱ£¬±ØÐëʹÓÃswitchport trunk allowed vlan remove vlan-listºÅÁî²Ã¼ôµô¸÷¾µÏñÉ豸ÉÏtrunkÀàÐ͵ĽӿÚÖй㲥µÄVLAN£¬²»È»trunk½Ó¿Ú¿ÉÄܻᱻ¹ã²¥µÄÁ÷Á¿Õ¼Âúµ¼ÖÂÒµÎñÖжϡ£
Èçͼ1-7Ëùʾ£¬ÍøÂç·ÖÎöÒÇÄܹ»Í¨¹ýÔ¶³Ì¾µÏñÖ°ÄÜ£¬Êµ´Ë¿ÌÖ÷ÕÅÉ豸DeviceBºÍDeviceCÉÏ¼à¿ØÔ´É豸DeviceAÉϵÄË«ÏòÊý¾ÝÁ÷¡£ÇÒÉ豸֮¼ä¾ùÄÜÕý³£»¥»»Êý¾Ý¡£
ͼ1-7 »ùÓÚRSPANʵÏÖµÄÒ»¶Ô¶à¾µÏñÖ°ÄÜÍøÍ¼

l ÅäÖÃDeviceAΪԴÉ豸£¬ÅäÖÃÔ¶³Ì¾µÏñVLAN£¬ÅäÖö˿ÚGigabitEthernet 0/1ΪԴ¶Ë¿Ú£¬ÓëÖ÷ÕÅÉ豸ÏàÁ¬µÄ¶Ë¿ÚGigabitEthernet 0/3ºÍGigabitEthernet 0/4ΪÊä³ö¶Ë¿Ú£¬ÅäÖÃGigabitEthernet 0/2½Ó¿ÚΪMAC»Ø»·¿Ú£¬ÓÃÓÚʵÏÖÒ»¶Ô¶à¾µÏñµÄ¡°·´É䡱ְÄÜ¡£ÅäÖÃÊä³ö¶Ë¿Ú¿É»¥»»Ö°ÄÜ¡£
l DeviceBºÍDeviceCÅäÖÃΪÖ÷ÕÅÉ豸£¬ÅäÖÃÔ¶³Ì¾µÏñVLAN£¬ÓëÔ´É豸ÏàÁ¬µÄ¶Ë¿ÚGigabitEthernet 0/1×÷ΪԴ¶Ë¿Ú£¬ÅäÖÃTrunk¶Ë¿Ú£¬ÓëÍøÂç·ÖÎöÒÇÏàÁ¬µÄ¶Ë¿ÚGigabitEthernet 0/2ÅäÖÃΪ¾µÏñÖ÷ÕŶ˿ڣ¬²¢ÅäÖþµÏñÖ÷ÕŶ˿ڿɻ¥»»Ö°ÄÜ¡£
# ÅäÖÃDeviceAΪԴÉ豸¡£
(1) ÅäÖÃÔ¶³ÌVLAN¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# vlan 7
DeviceA(config-vlan)# remote-span
DeviceA(config-vlan)# exit
(2) ÅäÖÃÔ´¶Ë¿Ú¡£
DeviceA(config)# monitor session 1 remote-source
DeviceA(config)# monitor session 1 source interface gigabitethernet 0/1 both
(3) ÅäÖÃÊä³ö¶Ë¿Ú¡£
DeviceA(config)# monitor session 1 destination remote vlan 7 interface gigabitethernet 0/2 switch
(4) ÅäÖûػ·¿Ú¡£
DeviceA(config)# interface gigabitethernet 0/2
DeviceA(config-if)# mac-loopback
DeviceA(config-if)# switchport access vlan 7
DeviceA(config-if)# exit
DeviceA(config)# interface range gigabitethernet 0/3-4
DeviceA(config-if-range)#
switchport mode trunk
# ÅäÖÃDeviceBΪÖ÷ÕÅÉ豸¡£
(1) ÅäÖÃÔ¶³ÌVLAN¡£
DeviceB> enable
DeviceB# configure
DeviceB(config)# vlan 7
DeviceB(config-vlan)# remote-span
DeviceB(config-vlan)# exit
(2) ÅäÖÃÖ÷ÕŶ˿ڡ£
DeviceB(config)# monitor session 1 remote-destination
DeviceB(config)# monitor session 1 destination remote vlan 7 interface gigabitethernet 0/2 switch
DeviceB(config)# interface gigabitethernet 0/1
DeviceB(config-if)# switchport mode trunk
# ÅäÖÃDeviceCΪÖ÷ÕÅÉ豸¡£
(1) ÅäÖÃÔ¶³ÌVLAN¡£
DeviceC> enable
DeviceC# configure
DeviceC(config)# vlan 7
DeviceC(config-vlan)# remote-span
DeviceC(config-vlan)# exit
(2) ÅäÖÃÖ÷ÕŶ˿ڡ£
DeviceC(config)# monitor session 1 remote-destination
DeviceC(config)# monitor session 1 destination remote vlan 7 interface gigabitethernet 0/2 switch
DeviceC(config)# interface gigabitethernet 0/1
DeviceC(config-if)# switchport mode trunk
# ÔÚDeviceAÉÏͨ¹ýshow monitorºÅÁî²é¿´¾µÏñÔ´É豸ÅäÖÃÁ˾֡£
DeviceA# show monitor
sess-num: 1
span-type: SOURCE_SPAN
src-intf:
GigabitEthernet 0/1¡¡¡¡¡¡frame-type Both
dest-intf:
GigabitEthernet¡¡0/2
Remote vlan 7
mtp_switch on
# ÔÚDeviceBºÍDeviceCÖÐͨ¹ýshow monitorºÅÁî²é¿´¾µÏñÖ÷ÕÅÉ豸ÅäÖÃÁ˾֡£ÒÔDeviceBΪÀý×¢Ã÷¡£
DeviceB# show monitor
sess-num: 1
span-type: DEST_SPAN
dest-intf:
GigabitEthernet¡¡0/2
Remote vlan 7
mtp_switch on
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
vlan 7
!
?remote-span
!
interface GigabitEthernet 0/2
?mac-loopback
?switchport access vlan 7
!
interface GigabitEthernet 0/3
switchport mode trunk
interface GigabitEthernet 0/4
switchport mode trunk
!
monitor session 1 remote-source
monitor session 1 source interface GigabitEthernet 0/1 both
monitor session 1 destination remote vlan 7 interface GigabitEthernet0/2 switch
!
end
l DeviceBµÄÅäÖÃÎļþ
hostname DeviceB
!
vlan 7
?remote-span
!
interface GigabitEthernet 0/1
?switchport mode trunk
!
monitor session 1 remote-destination
monitor session 1 destination remote vlan 7 interface GigabitEthernet0/2 switch
!
end
l DeviceCµÄÅäÖÃÎļþ
hostname Device
!
vlan 7
?remote-span
!
interface GigabitEthernet 0/1
?switchport mode trunk
?!
monitor session 1 remote-destination
monitor session 1 destination remote vlan 7 interface GigabitEthernet 0/2 switch
!
end
l Ô´É豸¡¢ÖÐÑëÉ豸¡¢Ö÷ÕÅÉ豸¾ùÒªÅäÖÃÔ¶³ÌVLANÇÒVID±ØÐëÒ»Ö¡£
l ´ø¿í´óµÄ¶Ë¿Ú±»¾µÏñµ½´ø¿íÓ׵Ķ˿ڿÉÄÜ»áÔì³É¶ª°ü¡£
Èçͼ1-8ÖÐËùʾ¡£Íø¹Üµ«Ô¸Í¨¹ýÍøÂç·ÖÎöÒǶÔDeviceAºÍDeviceCµÄÁ÷Á¿½øÐÐ¼à¿Ø¡£ÆäÖжÔÓÚDeviceA£¬¼à¿ØË«ÏòÊý¾ÝÁ÷£»¶ÔÓÚDeviceC£¬½ö¼à¿Ø²¿ÃÅ·¢Ë͵½DeviceµÄ±¨ÎÄ¡£ÎªÁ˺ÏÀíÀûÓÃ×ÊÔ´£¬¶Ô¼à¿Ø±¨ÎĽøÐвÉÑù£¬²ÉÑùÂÊΪ1000¡£
ͼ1-8 ERSPANÅäÖþÙÀý×éÍøÍ¼

l ÅäÖø÷É豸֮¼äÈý²ã·Óɿɴ
l ÅäÖÃDeviceBΪԴÉ豸¡£GigabitEthernet 0/1£¬GigabitEthernet 0/2¾ùΪԴ¶Ë¿Ú£¬¼à¿ØGigabitEthernet 0/1µÄË«ÏòÊý¾Ý±¨ÎÄ£¬¶ÔÓÚGigabitEthernet 0/2µÄ±¨ÎÄ£¬½ö¾µÏñÖ÷ÕÅIPΪ2.1.1.1µÄ±¨ÎÄ£¬GigabitEthernet 0/3Ϊ¾µÏñ±¨Îijö¿Ú¡£
l ÅäÖþµÏñ±¨ÎĵIJÉÑùÂÊΪ1000¡£
# ÅäÖÃDeviceBµÄµØÖ·¡£
DeviceB> enable
DeviceB# configure terminal
DeviceB(config)# interface gigabitethernet 0/1
DeviceB(config-if-GigabitEthernet 0/1)# ip address 1.1.1.1 255.255.255.0
DeviceB(config-if-GigabitEthernet 0/1)# exit
DeviceB(config)# interface gigabitethernet 0/2
DeviceB(config-if-GigabitEthernet 0/1)# ip address 2.1.1.1 255.255.255.0
DeviceB(config-if-GigabitEthernet 0/1)# exit
DeviceB(config)# interface gigabitethernet 0/3
DeviceB(config-if-GigabitEthernet 0/1)# ip address 13.1.1.1 255.255.255.0
DeviceB(config-if-GigabitEthernet 0/1)# exit
# ÅäÖÃDeviceAµÄµØÖ·¡£
DeviceA> enable
DeviceA# configure terminal
DeviceA(config)# interface gigabitethernet 0/1
DeviceA(config-if-GigabitEthernet 0/1)# ip address 1.1.1.2 255.255.255.0
DeviceA(config-if-GigabitEthernet 0/1)# exit
# ÅäÖÃDeviceCµØÖ·¡£
DeviceC> enable
DeviceC# configure terminal
DeviceC(config)# interface gigabitethernet 0/1
DeviceC(config-if-GigabitEthernet 0/1)# ip address 2.1.1.2 255.255.255.0
DeviceC(config-if-GigabitEthernet 0/1)# exit
# ÔÚDeviceBÉÏÅäÖÃACL¡£
DeviceB(config)#access-list 1 permit host 1.1.1.1
# ´´½¨ERSPAN Session 1£¬ÉèÖÃΪԴÉ豸£¬²¢ÉèÖö˿ÚGigabitEthernet 0/1ΪԴ¶Ë¿Ú£¬¾µÏñË«ÏòÊý¾ÝÁ÷£¬¶Ë¿ÚGigabitEthernet 0/2ҲΪԴ¶Ë¿Ú£¬½ö½øÐÐÖ÷ÕŵØÖ·Îª1.1.1.1µÄ±¨ÎÄ¡£
DeviceB(config)# monitor session 1 erspan-source
DeviceB(config-mon-erspan-src)# source interface gigabitethernet 0/1 both
DeviceB(config-mon-erspan-src)# source interface gigabitethernet 0/2 rx acl acl1
DeviceB(config-mon-erspan-src)#
origin ip address
DeviceB(config-mon-erspan-src)# destination ip address 3.1.1.2
# ¿ªÆô¾µÏñ±¨ÎÄѡȡְÄܲ¢ÅäÖòÉÑùÂÊΪ1000¡£
DeviceB(config-mon-erspan-src)# sample enable
DeviceB(config-mon-erspan-src)# sample rate 1000
# ÑéÖ¤DeviceBÓëDeviceAÖ®¼äÈý²ã¿Éͨ¡£
DeviceB# ping 1.1.1.2
Sending 5, 100-byte ICMP Echoes to 1.1.1.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/3/8 ms.
# ÑéÖ¤DeviceBÓëDeviceCÖ®¼äÈý²ã¿Éͨ¡£
DeviceB# ping 2.1.1.2
Sending 5, 100-byte ICMP Echoes to 2.1.1.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/3/8 ms.
# ÑéÖ¤DeviceBÓëÍøÂç·ÖÎöÒÇÖ®¼äÈý²ã¿Éͨ¡£
DeviceB# ping 3.1.1.2
Sending 5, 100-byte ICMP Echoes to 3.1.1.2, timeout is 2 seconds:
¡¡< press Ctrl+C to break >
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/3/8 ms.
# ͨ¹ýshow access-listsºÅÁî²é¿´ACLÅäÖóɹ¦¡£
DeviceB# show access-lists
ip access-list standard 1
?10 permit host 1.1.1.1
# ͨ¹ýshow monitorºÅÁî²é¿´ÅäÖÃÁ˾֣¬ERSPAN»á»°´¦ÓÚActive״̬¡£
DeviceB# show monitor
sess-num: 1
span-type: ERSPAN_SOURCE
src-intf:
¡¡GigabitEthernet 0/1¡¡¡¡¡¡¡¡ frame-type: Both¡¡¡¡¡¡¡¡TX status: Active¡¡ RX status: Active¡¡
src-intf:
¡¡GigabitEthernet 0/2¡¡¡¡¡¡¡¡ frame-type: RX Only¡¡¡¡ Rx acl id: 1¡¡¡¡¡¡
status: Active
original ip address: 2.1.1.2
destination ip address: 3.1.1.2
ip ttl: 64
ip dscp: 0
sample rate: 1000
vrf: default
l DeviceAµÄÅäÖÃÎļþ
hostname DeviceA
!
interface GigabitEthernet 0/1
?ip address 1.1.1.2 255.255.255.0
!
end
l DeviceCµÄÅäÖÃÎļþ
hostname DeviceC
!
interface GigabitEthernet 0/1
?ip address 2.1.1.2 255.255.255.0
!
end
l DeviceBµÄÅäÖÃÎļþ
hostname DeviceB
!
ip access-list standard 1
?10 permit host 1.1.1.1
!
interface GigabitEthernet 0/1
?ip address 1.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/2
?ip address 2.1.1.1 255.255.255.0
!
interface GigabitEthernet 0/3
?ip address 3.1.1.1 255.255.255.0
!
monitor session 1 erspan-source
?source interface gigabitEthernet 0/1 both
?source interface gigabitEthernet 0/2 rx acl acl1
?origin ip address 10.1.1.2
?destination ip address 3.1.1.2
?sample enable
?sample rate 1000
!
end
l ÅäÖÃERSPAN¾µÏñµÄ»á»°IDÒѾ±»ÅäÖÃÁËRSPAN»òLOCAL SPAN¡£