<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Captured traffic inconsistently VLAN-tagged in ExtremeSwitching (VSP/Fabric Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/captured-traffic-inconsistently-vlan-tagged/m-p/100809#M2520</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I set up traffic monitoring on VOSS and EXOS switches, but the network analysis guys are complaining that captured traffic is asymetrically tagged, and this messes up with their software.&lt;/P&gt;&lt;P&gt;On the EXOS switch, traffic is captured on selected ports:&lt;BR /&gt;create mirror &amp;lt;name&amp;gt;&lt;BR /&gt;configure mirror &amp;lt;name&amp;gt; to port &amp;lt;dst-port&amp;gt;&lt;BR /&gt;configure mirror &amp;lt;name&amp;gt; add port &amp;lt;ports&amp;gt;&lt;BR /&gt;enable mirror &amp;lt;name&amp;gt;&lt;/P&gt;&lt;P&gt;On the VOSS switch, traffic from/to selected IP addresses is captured:&lt;BR /&gt;filter acl 1 type inVlan&lt;BR /&gt;filter acl set 1 global-action monitor-dst-port &amp;lt;dst-port&amp;gt;&lt;BR /&gt;filter acl vlan 1 &amp;lt;vlan&amp;gt;&lt;BR /&gt;filter acl ace 1 1&lt;BR /&gt;filter acl ace action 1 1 permit&lt;BR /&gt;filter acl ace ethernet 1 1 ether-type eq ip&lt;BR /&gt;filter acl ace ip 1 1 dst-ip eq &amp;lt;ip1&amp;gt;&lt;BR /&gt;filter acl ace 1 1 enable&lt;BR /&gt;filter acl ace 1 2&lt;BR /&gt;filter acl ace action 1 2 permit&lt;BR /&gt;filter acl ace ethernet 1 2 ether-type eq ip&lt;BR /&gt;filter acl ace ip 1 2 src-ip eq &amp;lt;ip1&amp;gt;&lt;BR /&gt;filter acl ace 1 2 enable&lt;BR /&gt;[two more ACEs for &amp;lt;ip2&amp;gt;]&lt;/P&gt;&lt;P&gt;On EXOS, we use NAC to move devices to the VLAN they belong to, just in case this matters and could mess up with traffic capture.&lt;BR /&gt;On VOSS, we couldn't use port-based capture because we're capturing VM traffic.&amp;nbsp;Some traffic will be captured on UNI ports connected to the VM infrastructure or router/firewall, and some on NNI port to another VOSS switch.&lt;/P&gt;&lt;P&gt;In both cases, network analysis guys complain there's a VLAN tag on inbound traffic but not on outbound, or the other way I'm not sure.&lt;BR /&gt;Is this a known issue ?&lt;BR /&gt;Can we make the captured traffic consistent VLAN-wise ?&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jul 2024 13:18:18 GMT</pubDate>
    <dc:creator>nmelay</dc:creator>
    <dc:date>2024-07-03T13:18:18Z</dc:date>
    <item>
      <title>Captured traffic inconsistently VLAN-tagged</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/captured-traffic-inconsistently-vlan-tagged/m-p/100809#M2520</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I set up traffic monitoring on VOSS and EXOS switches, but the network analysis guys are complaining that captured traffic is asymetrically tagged, and this messes up with their software.&lt;/P&gt;&lt;P&gt;On the EXOS switch, traffic is captured on selected ports:&lt;BR /&gt;create mirror &amp;lt;name&amp;gt;&lt;BR /&gt;configure mirror &amp;lt;name&amp;gt; to port &amp;lt;dst-port&amp;gt;&lt;BR /&gt;configure mirror &amp;lt;name&amp;gt; add port &amp;lt;ports&amp;gt;&lt;BR /&gt;enable mirror &amp;lt;name&amp;gt;&lt;/P&gt;&lt;P&gt;On the VOSS switch, traffic from/to selected IP addresses is captured:&lt;BR /&gt;filter acl 1 type inVlan&lt;BR /&gt;filter acl set 1 global-action monitor-dst-port &amp;lt;dst-port&amp;gt;&lt;BR /&gt;filter acl vlan 1 &amp;lt;vlan&amp;gt;&lt;BR /&gt;filter acl ace 1 1&lt;BR /&gt;filter acl ace action 1 1 permit&lt;BR /&gt;filter acl ace ethernet 1 1 ether-type eq ip&lt;BR /&gt;filter acl ace ip 1 1 dst-ip eq &amp;lt;ip1&amp;gt;&lt;BR /&gt;filter acl ace 1 1 enable&lt;BR /&gt;filter acl ace 1 2&lt;BR /&gt;filter acl ace action 1 2 permit&lt;BR /&gt;filter acl ace ethernet 1 2 ether-type eq ip&lt;BR /&gt;filter acl ace ip 1 2 src-ip eq &amp;lt;ip1&amp;gt;&lt;BR /&gt;filter acl ace 1 2 enable&lt;BR /&gt;[two more ACEs for &amp;lt;ip2&amp;gt;]&lt;/P&gt;&lt;P&gt;On EXOS, we use NAC to move devices to the VLAN they belong to, just in case this matters and could mess up with traffic capture.&lt;BR /&gt;On VOSS, we couldn't use port-based capture because we're capturing VM traffic.&amp;nbsp;Some traffic will be captured on UNI ports connected to the VM infrastructure or router/firewall, and some on NNI port to another VOSS switch.&lt;/P&gt;&lt;P&gt;In both cases, network analysis guys complain there's a VLAN tag on inbound traffic but not on outbound, or the other way I'm not sure.&lt;BR /&gt;Is this a known issue ?&lt;BR /&gt;Can we make the captured traffic consistent VLAN-wise ?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jul 2024 13:18:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-vsp-fabric/captured-traffic-inconsistently-vlan-tagged/m-p/100809#M2520</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2024-07-03T13:18:18Z</dc:date>
    </item>
  </channel>
</rss>

