<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Mirroring on X590 - V400. Troubles with 802.1BR (0x893F) encapsulation in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mirroring-on-x590-v400-troubles-with-802-1br-0x893f/m-p/90849#M21292</link>
    <description>&lt;P&gt;Recently we replaced our Enterasys S4 with a couple of X590 and associated V400 edge switches&lt;BR /&gt;We are now facing problems regarding mirroring the traffic of our VLANs and checking the results on our network analyzer where we also NEED to run tcpdump&lt;BR /&gt;&lt;BR /&gt;Here is what I did step by step&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Step 1&lt;/STRONG&gt;&lt;BR /&gt;Let's say I want to monitor what happens on my VLAN 100 and send everything to my analyzer located on port 103:31: &lt;STRONG&gt;IMPORTANT!&lt;/STRONG&gt; This analyzer &lt;STRONG&gt;MUST&lt;/STRONG&gt; have an IP address in the same VLAN 100 in order to be accessible.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;mirrored port is 1:1 on the X590&lt;/LI&gt;	&lt;LI&gt;monitor port is 103:31 on a V400 (belonging to VLAN 100)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;In order to keep VLAN 100 on the monitor port I found a solution using the &lt;STRONG&gt;remote-tag &lt;/STRONG&gt;keyword (otherwise VLAN is removed)&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;create mirror "PUBLIC_MIRROR"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;configure mirror PUBLIC_MIRROR to port 103:31 &lt;/EM&gt;&lt;EM&gt;&lt;STRONG&gt;remote-tag 100&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;configure mirror PUBLIC_MIRROR add vlan Internet-V port 1:1 ingress&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;enable mirror PUBLIC_MIRROR&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;This way everything works: my Analyzer with tcpdump can see the traffic of the mirrored port (which resides on X590)&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Step 2&lt;/STRONG&gt;&lt;BR /&gt;Now I want to add another port into the mirror, THIS TIME located on a V400, let's say 103:1&lt;BR /&gt;&lt;EM&gt;configure mirror PUBLIC_MIRROR add vlan Internet-V port 103:1 ingress&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Now tcpdump on the analyzer start seeing all traffic originated in 103:1 encapsulated with 802.1BR (0x893f), which it is not able to decode&lt;BR /&gt;I understand that the 802.1BR tagging is used to handle traffic between X590 and V400, but it makes the traffic in the mirror unreadable.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Step 3&lt;/STRONG&gt;&lt;BR /&gt;Other tests&lt;BR /&gt;1) Connect the Network Analyzer on the X590 instead of V400. No change&lt;BR /&gt;2) Connect the Network Analyzer on a remote switch, using "Remote Mirroring" as described in EXOS User Guide, CLI Reference anche KB like&lt;BR /&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000074211&amp;amp;q=how%20to%20configure%20remote%20mirror&lt;BR /&gt;&lt;BR /&gt;No joy, the 802.1BR encapsulation is sent also to the remote switch&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;The problem&lt;/STRONG&gt;&lt;BR /&gt;This is just to explain the concept: now imagine I have to monitor the whole VLAN 100 with 96 ports on the V400 switches: I'm not able to see anything.&lt;BR /&gt;I'm only able to decode traffic which originates on the X590 switches which is unaffected by 802.1BR&amp;nbsp; (that is all my trunks to remote switches)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;How can I handle this situation?&lt;BR /&gt;Remember the fundamental facts&lt;BR /&gt;1) The analyzer MUST have an IP address on the monitored VLAN&lt;BR /&gt;2) TCPDUMP must be used&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 07 Feb 2021 22:51:00 GMT</pubDate>
    <dc:creator>DB2001</dc:creator>
    <dc:date>2021-02-07T22:51:00Z</dc:date>
    <item>
      <title>Mirroring on X590 - V400. Troubles with 802.1BR (0x893F) encapsulation</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mirroring-on-x590-v400-troubles-with-802-1br-0x893f/m-p/90849#M21292</link>
      <description>&lt;P&gt;Recently we replaced our Enterasys S4 with a couple of X590 and associated V400 edge switches&lt;BR /&gt;We are now facing problems regarding mirroring the traffic of our VLANs and checking the results on our network analyzer where we also NEED to run tcpdump&lt;BR /&gt;&lt;BR /&gt;Here is what I did step by step&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Step 1&lt;/STRONG&gt;&lt;BR /&gt;Let's say I want to monitor what happens on my VLAN 100 and send everything to my analyzer located on port 103:31: &lt;STRONG&gt;IMPORTANT!&lt;/STRONG&gt; This analyzer &lt;STRONG&gt;MUST&lt;/STRONG&gt; have an IP address in the same VLAN 100 in order to be accessible.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;mirrored port is 1:1 on the X590&lt;/LI&gt;	&lt;LI&gt;monitor port is 103:31 on a V400 (belonging to VLAN 100)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;In order to keep VLAN 100 on the monitor port I found a solution using the &lt;STRONG&gt;remote-tag &lt;/STRONG&gt;keyword (otherwise VLAN is removed)&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;create mirror "PUBLIC_MIRROR"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;configure mirror PUBLIC_MIRROR to port 103:31 &lt;/EM&gt;&lt;EM&gt;&lt;STRONG&gt;remote-tag 100&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;configure mirror PUBLIC_MIRROR add vlan Internet-V port 1:1 ingress&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;enable mirror PUBLIC_MIRROR&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;This way everything works: my Analyzer with tcpdump can see the traffic of the mirrored port (which resides on X590)&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Step 2&lt;/STRONG&gt;&lt;BR /&gt;Now I want to add another port into the mirror, THIS TIME located on a V400, let's say 103:1&lt;BR /&gt;&lt;EM&gt;configure mirror PUBLIC_MIRROR add vlan Internet-V port 103:1 ingress&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Now tcpdump on the analyzer start seeing all traffic originated in 103:1 encapsulated with 802.1BR (0x893f), which it is not able to decode&lt;BR /&gt;I understand that the 802.1BR tagging is used to handle traffic between X590 and V400, but it makes the traffic in the mirror unreadable.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Step 3&lt;/STRONG&gt;&lt;BR /&gt;Other tests&lt;BR /&gt;1) Connect the Network Analyzer on the X590 instead of V400. No change&lt;BR /&gt;2) Connect the Network Analyzer on a remote switch, using "Remote Mirroring" as described in EXOS User Guide, CLI Reference anche KB like&lt;BR /&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000074211&amp;amp;q=how%20to%20configure%20remote%20mirror&lt;BR /&gt;&lt;BR /&gt;No joy, the 802.1BR encapsulation is sent also to the remote switch&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;The problem&lt;/STRONG&gt;&lt;BR /&gt;This is just to explain the concept: now imagine I have to monitor the whole VLAN 100 with 96 ports on the V400 switches: I'm not able to see anything.&lt;BR /&gt;I'm only able to decode traffic which originates on the X590 switches which is unaffected by 802.1BR&amp;nbsp; (that is all my trunks to remote switches)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;How can I handle this situation?&lt;BR /&gt;Remember the fundamental facts&lt;BR /&gt;1) The analyzer MUST have an IP address on the monitored VLAN&lt;BR /&gt;2) TCPDUMP must be used&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 22:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/mirroring-on-x590-v400-troubles-with-802-1br-0x893f/m-p/90849#M21292</guid>
      <dc:creator>DB2001</dc:creator>
      <dc:date>2021-02-07T22:51:00Z</dc:date>
    </item>
  </channel>
</rss>

