Configure Rspan Vmware
Configure Rspan Vmware
Published: 2024-02-20
The Remote Switched Port Analyzer (RSPAN) enables you to monitor traffic on one switch through a device
on another switch and then send the monitored traffic to one or more destinations.
Before you begin
RSPAN requires that you configure an RSPAN VLAN on your physical switches. If you cannot configure an
RSPAN VLAN, consider configuring ERSPAN as an alternative. For more information, see How Mirroring
Works .
• You must have experience with basic VMware ESX and ESXi administration through the VMware
vSphere Web Client.
• You must have an uplink port (HW NIC) attached to the switch (preferably one that is not designated
for general network traffic).
• Direct access to the iDRAC console is preferred.
For information about configuring the VMware vSphere server, see the Working with Port Mirroring section
in the ESXi and vCenter documentation for your version of VMware.
For information about configuring VMware with an ExtraHop sensor, see Deploy the ExtraHop sensor with
VMware .
The following steps outline the key procedures that are required to configure RSPAN with VMware for an
ExtraHop sensor. Note that procedures in these steps might vary between versions of VMware.
Note: While these steps are required for RSPAN configuration, most deployments have completed
the first four steps prior to installing the sensor. If you have an existing Virtual Distributed
Switch, start with step 5.
1. Create a virtual distributed switch (VDS)
2. Add port groups to the VDS
3. Add a host to the VDS
4. Add uplink ports to the VDS
5. Configure an RSPAN port mirror on the VDS
©
2024ExtraHop Networks, Inc. All rights reserved.
3. In the left panel, click Distributed Switches.
4. Above the list of switches, click the Create a new distributed switch icon.
a) Set the Number of uplinks to two or more if your SPAN traffic is on a dedicated NIC
(recommended). Otherwise, set this value to 1.
b) Click the Network I/O Control drop-down list and select one of the following options.
Disabled
If your SPAN traffic on a dedicated NIC. (Recommended)
2. Right-click the VDS and then select New Distributed Port Group.
3. In the New Distributed Port Group window, type a name for the port group and click Next.
5. In the list of available hosts, select the checkbox next to the host and click OK.
11. After you have assigned each adapter to a Destination Port Group (in the far right column), click Next.
12. On the Validate Changes screen, verify that the status has passed and click Next.
14. Click the Assign Port Group icon and assign a network adapter for management and a network adapter
for monitoring, and click Next.
15. Verify your settings and click Finish.
16. View the progress bar in the right panel and wait for the system to add the host.
The following figure shows an example configuration.
3. From the list, select the distributed switch you want to add an uplink port to.
4. Click Manage the physical network adapters .
5. Click Add .
6. From the list, select a network adapter and then select the uplink port from the drop-down menu that
you want to assign to the network adapter.
7. Click OK.
1. Click on Networking.
2. Select your VDS and ensure that the Settings tab is selected.
3. Click Port mirroring.
6. In the Name field, type a name to identify the port mirroring session.
7. From the Status drop-down, select Enabled.
8. Click Next.
9. Click the plus icon to add the source VLAN IDs that you want to monitor, and then click Next.
10. Specify the destination port where you want to send mirrored traffic. This port is the virtual port on the
VDS that corresponds to the monitoring interface on your virtual Discover appliance.
11. Verify the summary information and then click Finish to add the port mirror.