Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ashik_Sheik
Contributor II

Cisco ERSPAN - To FortiGate (IDS) Interface

Hello,

 

The design is to get ERSPAN traffic from Cisco to FortiGate Interface to act like IDS. How to achieve this and what configuration needs to enable on FortiGate. Is GRE mandatory?

 

Regards,

 

Ashu

Ashu 

 

1 REPLY 1
rarumugam
Staff
Staff

Hello Ashu,

 

As I understand, you would like FortiGate to operate as an IDS appliance( i.e. without actually processing the packets). Correct me, If I am wrong.

 

You could put the FortiGate in one-arm sniffer mode and it would serve the purpose. Below is the link to configure it on the FortiGate,

 

https://docs.fortinet.com/document/fortigate/6.0.0/handbook/430641/one-armed-sniffer

 

Regards,

Ram.

Rambharathi Arumugam