メイン コンテンツに進む
  • すばやく簡単にご注文が可能
  • 注文内容の表示、配送状況をトラック
  • 会員限定の特典や割引のご利用
  • 製品リストの作成とアクセスが可能
  • 「Company Administration(会社情報の管理)」では、お使いのDell EMCのサイトや製品、製品レベルでのコンタクト先に関する情報を管理できます。

Dell EMC SmartFabric OS10 User Guide Release 10.5.0

PDF

Remote port monitoring on VLT

In a network, devices you configure with peer VLT nodes are considered as a single device. You can apply remote port monitoring (RPM) on the VLT devices in a network.

In a failover case, the monitored traffic reaches the packet analyzer connected to the top-of-rack (ToR) through the VLT interconnect link.

NOTE
  • In VLT devices configured with RPM, when the VLT link is down, the monitored packets might drop for some time. The time is equivalent to the VLT failover recovery time, the delay restore.
  • ERPM does not work on VLT devices.

RPM on VLT scenarios

Consider a simple VLT setup where two VLT devices are connected using VLTi and a top-of-rack switch is connected to both the VLT peers using VLT LAGs in a ring topology. In this setup, the following table describes the possible scenarios when you use RPM to mirror traffic.

NOTE Ports that connect to the VLT domain, but not part of the VLT-LAG, are called orphan ports.
Table 1. RPM on VLT scenariosRPM on VLT scenarios
Scenario Recommendation
Mirror an orphan port or VLT LAG or VLTi member port to a VLT LAG. The packet analyzer connects to the ToR switch.

The recommended configuration on the peer VLT device:

  1. Create an RPM VLAN.
    !
    interface vlan 100
    no shutdown
    remote-span
    !
  2. Create an L2 ACL for the RPM VLAN - RPM session and attach it to VLTi LAG interface.
    !
    mac access-list rpm
    seq 10 permit any any capture session 10 vlan 100
    !
    
    interface ethernet 1/1/1
    no shutdown
    switchport access vlan 1
    mac access-group rpm in
    !
  3. Create a flow-based RPM session on the peer VLT device to monitor the VLTi LAG interface as the source.
    !
    monitor session 10 type rpm-source
    destination remote-vlan 100
    flow-based enable
    source interface ethernet1/1/1 (ICL lag member)
    !
Mirror a VLAN with VLTi LAG as a member to any orphan port on the same VLT device. The packet analyzer connects to the local VLT device through the orphan port.

The recommended configuration on the VLT device:

  1. Create an L2 ACL for the local session and attach it to the VLTi LAG interface.
    !
    mac access-list local
    seq 10 permit any any capture session 10
    !
    
    interface ethernet 1/1/1
    no shutdown
    switchport access vlan 1
    mac access-group local in
    !
  2. Create a flow-based local session on the VLT device to monitor the VLTi LAG interface member (Ethernet 1/1/1) as source.
    !
    monitor session 10 type
    destination interface ethernet 1/1/10 flow-based enable
    source interface ethernet1/1/1
    no shut
    !
Mirror a VLAN with a VLTi LAG as the member to the VLT LAG on the same VLT device. The packet analyzer connects to the ToR switch.
Mirror a VLT LAG of the ToR, or any port in the ToR to any orphan port in the VLT device. Configure VLT nodes as intermediate devices. The packet analyzer connects to the ToR switch.
Mirror a VLT LAG to any orphan port on the same VLT device. The packet analyzer connects to the local VLT device through the orphan port. If the packet analyzer directly connects to the VLT peer where the source session is configured, use local port monitoring instead of RPM.
Mirror an orphan port in the primary VLT device to any orphan port on a secondary VLT device through the VLTi. The packet analyzer connects to the secondary VLT device through the orphan port. In this case, the mirroring packets duplicate.
Mirror a VLT LAG of the primary VLT device to any orphan port on a secondary VLT device through the VLTi. The packet analyzer connects to the secondary VLT device through the orphan port.
Mirror a member port of the VLTi LAG or VLT LAG to any orphan port in the same device. The packet analyzer connects to the local VLT device through the orphan port. If the packet analyzer is directly connected to the VLT peer in which the source session is configured, use local port monitoring instead of RPM.
Mirror a member port of VLTi LAG to the VLT LAG on the same VLT device. The packet analyzer connects to the ToR switch.
Mirror a VLT LAG or VLT member port as part of the source VLAN and destination VLAN. The packet analyzer connects to the ToR switch.

このコンテンツを評価する

正確
有益
分かりやすい
この記事は役に立ちましたか?
0/3000 characters
  1~5個の星の数で評価してください。
  1~5個の星の数で評価してください。
  1~5個の星の数で評価してください。
  この記事は役に立ちましたか?
  コメントでは、以下の特殊文字は利用できません: <>()\