Cisco Systems' Encapsulated Remote Switch Port Analyzer (ERSPAN)
draft-foschiano-erspan-03

Document Type Expired Internet-Draft (individual)
Last updated 2017-08-26 (latest revision 2017-02-22)
Stream ISE
Intended RFC status Informational
Formats
Expired & archived
plain text pdf html bibtex
Stream ISE state In ISE Review
Awaiting Reviews
Consensus Boilerplate Unknown
Document shepherd No shepherd assigned
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at
https://www.ietf.org/archive/id/draft-foschiano-erspan-03.txt

Abstract

This document describes an IP-based packet capture format that can be used to transport exact copies of packets to a network probe to analyze and characterize the operational load and protocol distribution of a network as well as to detect anomalies such as network-based worms or viruses. This replication and transport mechanism operates over one or multiple switch or router ports whose traffic can be mirrored and forwarded to a destination device in charge of traffic analysis and reporting.

Authors

Marco Foschiano (mfoschiano@gmail.com)
Kalyan Ghosh (kghosh@cisco.com)
Munish Mehta (mmehta@cisco.com)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)