- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
ERSPAN Tap port on decoder from multiple ESX Hosts
Hello Everyone,
We are installing the All-In-One Netwitness virtual appliance suite and I'd like the Decoder to be able to be vmotioned to/from any one of three ESX 5.5 hosts. The span port will be a L3 Mirror port created on our VDS (Virtual Distributed Switch) and this basically encapsulates all mirror/span traffic from selected VMWare guests into GRE packets which are routed to our Decoder (Not a high volume TAP environment). This allows the Decoder to be Vmotioned from Host to Host however at the moment the traffic arrives encapsulated in GRE. What would be the best way to remove the GRE headers on the Decoder before the traffic actually enters the Decoder for processing?
Many thanks
- Tags:
- Community Thread
- Discussion
- Forum Thread
- NetWitness
- NW
- NWP
- RSA NetWitness
- RSA NetWitness Platform
- tap
- Virtual
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I know this is an old question but it came up when I searched for ERSPAN. I'm hoping a NetWitness 11.4 Decoder will process the data inside a GRE tunnel. Can anyone confirm or deny this feature?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
This may help you Virtual Host Setup: Step 4. Configure Host-Specific Parameters
Virtual taps encapsulate the captured traffic in a GRE tunnel. Depending on the type you choose, either of these scenarios may apply:
- An external host is required to terminate the tunnel, and the external host directs the traffic to the Decoder interface.
- The tunnel send traffic directly to the Decoder interface, where NetWitness Platform handles the de-encapsulation of the traffic.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks! With the help of support I have also found the VlanGRE parser that is used to decapsulate the GRE traffic. My only question now is if this parser supports the GRE protocol types from RFC1701 only or if the ERSPAN protocol types 0x88BE and 0x22EB are also supported. See https://tools.ietf.org/html/rfc1701 and https://tools.ietf.org/html/draft-foschiano-erspan-03
