Hello,
I am new at this, sorry in advanced if I am missing something. So I am trying to figure out this issue of remote analyzer. We have an IDS device which is connected to another 4600 in our comp room. Our core switch is located in another room. I was reading that I could do RSPAN on the ports that I want to mirror to the 4600 in our comp room. So the topology is as shown below
Core4600 ---(fiber link)-- Edge4600--IDS device (I have only connected the ports to 4600 which they want to use to monitor traffic)
This is how I set up the analyzer on my core4600
root@4600-core# show forwarding-options analyzer
Firewall-External-Monitor {
input {
ingress {
interface ge-0/0/14.0;
}
egress {
interface ge-0/0/14.0;
}
}
output {
vlan {
Remote-Analyzer-External;
}
}
}
Firewall-Internal-Monitor {
input {
ingress {
interface ge-0/0/10.0;
}
egress {
interface ge-0/0/10.0;
}
}
output {
vlan {
Remote-Analyzer-Internal;
}
}
}
On the edge Ex4600, this is what I have configured
root@edgeex4600# show forwarding-options analyzer
Firewall-External {
input {
ingress {
vlan Remote-Analyzer-External;
}
}
output {
interface ge-0/2/6.0;
}
}
Firewall-Internal {
input {
ingress {
vlan Remote-Analyzer-Internal;
}
}
output {
interface ge-0/2/0.0;
}
}
Here is the uplink configuration between the switches
Core EX4600
root@4600-core# show interfaces xe-1/2/7
description Uplink-To-4600-Edge-1;
unit 0 {
family ethernet-switching {
interface-mode trunk;
vlan {
members [ Test1 Test2 Test3 Test4 Remote-Analyzer-Internal Remote-Analyzer-External ];
}
}
}
Edge4600
root@edge4600-1# show interfaces xe-0/0/0
description Uplink-To-4600-core;
unit 0 {
family ethernet-switching {
interface-mode trunk;
vlan {
members [ Test1 Test2 Test3 Test4 Remote-Analyzer-Internal Remote-Analyzer-External ];
}
}
}
The analyzers both show up on both the switches, I can't confirm if its running. Is my config correct? Please let me know if I am missing anything here.