Is it possible to have more than one switch in the 'config target-port' section of the configuration or are you limited to one switch....? Also, I'm assuming you can only have one RSPAN or ERSPAN block of config...
Sorry.... still new to Fortinet CLI after working in the other networking worlds equipment whom I would rather not even mention...
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello Spartan_67,
In the 'config target-port' section of the configuration, you can specify multiple switches by listing them with the 'edit' command for each switch. You are not limited to configuring just one switch in this section.
The FortiSwitch unit can send a copy of any ingress or egress packet on a port to egress on another port of the same FortiSwitch unit. The original traffic is unaffected. This process is known as port-based mirroring and is typically used for external analysis and capture.
Using remote SPAN (RSPAN) or encapsulated RSPAN (ERSPAN) allows you to send the collected packets across layer-2 domains for analysis. You can have one RSPAN session or one ERSPAN session.
In RSPAN mode, traffic is encapsulated in VLAN 4092 and sent toward the FortiGate device, where it can be captured using packet capture. The FortiSwitch unit assigns the uplink port and the dst port. The switching functionality is enabled on the dst interface when mirroring.
In ERSPAN mode, traffic is encapsulated in Ethernet, IPv4, and generic routing encapsulation (GRE) headers. By focusing on traffic to and from specified ports and traffic to a specified MAC or IP address, ERSPAN reduces the amount of traffic being mirrored. The ERSPAN traffic is sent to a specified IP address, which is the device acting as an ERSPAN collector. The collector must be reachable by the FortiSwitch unit using IPv4 ICMP ping (NOTE: A firewall policy might be required on the FortiGate device.). If the collector IP address is not specified, the traffic is not mirrored.
NOTE: ERSPAN cannot be used with SPAN or RSPAN.
Please refer to the below documents for more information:
https://docs.fortinet.com/document/fortiswitch/7.6.0/fortilink-guide/173278/configuring-fortiswitch-...
https://docs.fortinet.com/document/fortigate/7.2.3/cli-reference/250620/config-switch-controller-tra...
If you have found a solution, please like and accept it to make it easily accessible to others.
Hello Spartan_67,
In the 'config target-port' section of the configuration, you can specify multiple switches by listing them with the 'edit' command for each switch. You are not limited to configuring just one switch in this section.
The FortiSwitch unit can send a copy of any ingress or egress packet on a port to egress on another port of the same FortiSwitch unit. The original traffic is unaffected. This process is known as port-based mirroring and is typically used for external analysis and capture.
Using remote SPAN (RSPAN) or encapsulated RSPAN (ERSPAN) allows you to send the collected packets across layer-2 domains for analysis. You can have one RSPAN session or one ERSPAN session.
In RSPAN mode, traffic is encapsulated in VLAN 4092 and sent toward the FortiGate device, where it can be captured using packet capture. The FortiSwitch unit assigns the uplink port and the dst port. The switching functionality is enabled on the dst interface when mirroring.
In ERSPAN mode, traffic is encapsulated in Ethernet, IPv4, and generic routing encapsulation (GRE) headers. By focusing on traffic to and from specified ports and traffic to a specified MAC or IP address, ERSPAN reduces the amount of traffic being mirrored. The ERSPAN traffic is sent to a specified IP address, which is the device acting as an ERSPAN collector. The collector must be reachable by the FortiSwitch unit using IPv4 ICMP ping (NOTE: A firewall policy might be required on the FortiGate device.). If the collector IP address is not specified, the traffic is not mirrored.
NOTE: ERSPAN cannot be used with SPAN or RSPAN.
Please refer to the below documents for more information:
https://docs.fortinet.com/document/fortiswitch/7.6.0/fortilink-guide/173278/configuring-fortiswitch-...
https://docs.fortinet.com/document/fortigate/7.2.3/cli-reference/250620/config-switch-controller-tra...
If you have found a solution, please like and accept it to make it easily accessible to others.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.