9.3 Switched Port Analyzer: Local SPAN, Remote SPAN (RSPAN), and Encapsulated RSPAN (ERSPAN)

Key Takeaways

  • Port mirroring duplicates traffic from source ports, VLANs, or EtherChannels and directs it to an analyzer port, overcoming Layer 2 MAC switching isolation that prevents promiscuous sniffing on access switches.

  • Local SPAN mirrors traffic within a single physical switch; destination ports disable normal Layer 2 switching, MAC learning, and Spanning Tree Protocol (STP), and strip 802.1Q tags unless configured with encapsulation replicate.

  • Remote SPAN (RSPAN) extends port mirroring across a Layer 2 switched network by flooding mirrored traffic over a dedicated RSPAN VLAN with MAC learning disabled, requiring manual trunk pruning to avoid link saturation.

  • Encapsulated Remote SPAN (ERSPAN) encapsulates mirrored Ethernet frames into Generic Routing Encapsulation (GRE) with IP protocol 47 and protocol type 0x88BE, allowing mirrored traffic to be routed across Layer 3 enterprise networks and WANs.

  • In all SPAN implementations, destination port oversubscription occurs silently when aggregate monitored ingress/egress bandwidth exceeds destination port capacity, dropping excess mirrored frames without impacting production data forwarding.

Last updated: October 2026

Switched Port Analyzer: Local SPAN, Remote SPAN (RSPAN), and Encapsulated RSPAN (ERSPAN)

In traditional shared-media Ethernet networks operating with legacy hubs, all connected stations occupied a common collision domain. Network analyzers and intrusion detection systems (IDS) attached to any access port could operate their Network Interface Cards (NICs) in promiscuous mode to observe all traffic traversing the local broadcast domain. Modern enterprise networks, however, operate on switched architectures where switches inspect source MAC addresses, populate Content Addressable Memory (CAM) tables, and forward unicast frames strictly to the specific physical switchport associated with the destination MAC address.

While switched architectures eliminate collisions and enhance security, they isolate network ports, preventing diagnostic packet analyzers, sniffers (e.g., Wireshark), and security appliances from capturing conversations between third-party endpoints. To restore non-intrusive monitoring visibility, network operating systems implement port mirroring via the Switched Port Analyzer (SPAN) technology family.


Port Mirroring Fundamentals

Port mirroring intercepts frames traversing designated switch interfaces, VLANs, or port-channels, duplicates the frames in hardware via the switch's Application-Specific Integrated Circuit (ASIC) fabric, and transmits the replica frames out a designated monitoring interface connected to an analyzer.

Port mirroring architectures encompass three operational models tailored to network scale and topology:

  1. Local SPAN: Source interfaces and destination analysis ports reside on the same physical switch or switch stack.
  2. Remote SPAN (RSPAN): Source interfaces and destination analysis ports reside on different switches interconnected via a Layer 2 switched campus network.
  3. Encapsulated Remote SPAN (ERSPAN): Source and destination endpoints reside across an arbitrary routed Layer 3 IP network, encapsulating mirrored frames within Generic Routing Encapsulation (GRE) tunnels.

Local SPAN Architecture and Operational Mechanics

Local SPAN mirrors traffic entirely within a single autonomous switch or unified virtual switch stack.

       +---------------------------------------------+
       |             Local Switch (ASIC)             |
       |                                             |
       |  Source Port Gi0/1        Source Port Gi0/2 |
       |     [Server A]               [Server B]     |
       |          \                      /           |
       |           \ (Ingress / Egress) /            |
       |            +--------+---------+             |
       |                     | (Hardware Duplicate)  |
       |                     v                       |
       |           Destination Port Gi0/24           |
       |             [Packet Analyzer]               |
       +---------------------------------------------+

Source Sessions

A SPAN source refers to any network entity whose traffic is monitored. Valid SPAN sources include:

  • Physical Switchports: FastEthernet, GigabitEthernet, 10-GigabitEthernet, etc.
  • Port-Channels (EtherChannels): Monitors aggregate traffic traversing all bundled physical links.
  • VLANs (VSPAN): Monitors all active access and trunk ports assigned to the specified VLAN.

For any monitored source, engineers configure the directional scope of traffic capture:

  • Ingress (rx): Monitors only packets received by the source interface prior to switch fabric buffering or modification.
  • Egress (tx): Monitors only packets transmitted out the source interface after routing, QoS scheduling, and ACL processing.
  • Bidirectional (both): Monitors both received and transmitted frames simultaneously (the default setting).

Destination Port Behavior and Constraints

The destination port in a SPAN session connects directly to the monitoring tool (packet analyzer, IDS, or probe). Because the destination port functions strictly as an egress telemetry tap, the switch fundamentally alters its Layer 2 operational behavior:

  1. Disables Layer 2 Switching and MAC Learning: The switch never learns MAC addresses from frames arriving on a SPAN destination port, nor does it insert destination port entries into its CAM table.
  2. Spanning Tree Protocol (STP) Deactivation: STP is completely disabled on a SPAN destination port. The port neither transmits nor processes Spanning Tree Bridge Protocol Data Units (BPDUs). If an unmanaged bridge or loop is accidentally connected to a SPAN destination port, standard STP loop prevention will not protect the network.
  3. Ingress Traffic Blocking: By default, a SPAN destination port drops all inbound traffic received from the analyzer. The attached monitoring device can passively capture traffic, but it cannot inject packets into the switch fabric. (Ingress forwarding can be enabled using the optional ingress keyword to allow interactive analyzer communication).
  4. VLAN Tag Stripping: By default, when monitoring an 802.1Q trunk port, the switch strips all 802.1Q tags before transmitting frames out the destination port. To preserve original VLAN tags for protocol analyzers analyzing multi-VLAN trunk traffic, administrators must explicitly append the encapsulation replicate parameter.
  5. Oversubscription and Packet Dropping: SPAN never impedes or throttles production traffic. If two 1-Gbps source interfaces are monitored bidirectionally (both) and directed to a single 1-Gbps destination port, the aggregate mirrored traffic can peak at 4 Gbps. When oversubscription occurs, the switch ASIC's SPAN replication engine silently drops excess mirrored frames. Production traffic forwarding remains completely unaffected.

Remote SPAN (RSPAN) Architecture

When the packet analyzer cannot be physically attached to the switch hosting the monitored source ports, Remote SPAN (RSPAN) bridges the gap across a Layer 2 enterprise campus.

+------------------------+                        +------------------------+
|    SOURCE SWITCH A     |                        |  DESTINATION SWITCH B  |
| Source Port: Gi0/1     |                        | Destination: Gi0/24    |
| (Copies to RSPAN VLAN) |                        | (Pulls from RSPAN VLAN)|
+------------------------+                        +------------------------+
            \                                                 /
             \========= Trunk Link (RSPAN VLAN 900) =========/

The Dedicated RSPAN VLAN

RSPAN achieves cross-switch frame transport by dedicating a unique, specialized VLAN—termed the RSPAN VLAN—exclusively to mirrored traffic.

  • Configuration Requirement: The VLAN must be explicitly designated as an RSPAN VLAN under global VLAN configuration mode (vlan <id>, followed by remote-span).
  • Flooding Behavior: Because RSPAN destination ports can reside anywhere in the campus Layer 2 domain, normal MAC learning is disabled on the RSPAN VLAN. Mirrored frames injected into the RSPAN VLAN are flooded across all trunk ports that permit the RSPAN VLAN.
  • Spanning Tree Participation: Unlike SPAN destination ports, STP remains active on the RSPAN VLAN across inter-switch trunks. This ensures that flooded RSPAN frames follow standard Spanning Tree active forwarding paths and do not create Layer 2 broadcast storms.

RSPAN Operational Hazards and Pruning

Because RSPAN floods frames across all trunk links carrying the RSPAN VLAN, an unconstrained RSPAN session can severely congest inter-switch uplinks. If a busy 10-Gbps server port is mirrored into an RSPAN VLAN spanning a multi-switch campus, trunk links carry gigabits of duplicate broadcast traffic.

To prevent link exhaustion, engineers must enforce manual trunk pruning:

  • The RSPAN VLAN must be explicitly removed from trunk links that do not lead to the switch hosting the destination analysis port using switchport trunk allowed vlan remove <rspan-vlan-id>.
  • Note: Cisco documents that when VTP and VTP pruning are enabled, RSPAN traffic is pruned on trunks for RSPAN VLAN IDs below 1005. Extended-range RSPAN VLANs, or networks without VTP pruning, need manual trunk pruning.

Encapsulated Remote SPAN (ERSPAN) Architecture

While RSPAN solves multi-switch monitoring within a shared Layer 2 broadcast domain, it cannot traverse routed Layer 3 boundaries. Enterprise data centers, hybrid clouds, and campus networks with Layer 3 routed access layers require a routed port mirroring solution.

Encapsulated Remote SPAN (ERSPAN) overcomes Layer 2 boundaries by packaging mirrored frames into standard Layer 3 routable IP datagrams using Generic Routing Encapsulation (GRE).

[Monitored Host]
       |
+--------------+                                           +--------------------+
| SOURCE NODE  |====== Layer 3 Routed IP Network =========>|  DESTINATION NODE  |
| ERSPAN Src   |       (GRE Encapsulation: Protocol 47)    |  ERSPAN Dst        |
+--------------+                                           +--------------------+
                                                                      |
                                                              [Packet Analyzer]

ERSPAN Header and Encapsulation Mechanics

When an ERSPAN source session intercepts a frame, the switch hardware constructs a multi-layered encapsulation wrapper:

  1. Original Mirrored Frame: The entire original Ethernet frame, including its payload and original Layer 2/VLAN headers, is preserved intact.
  2. ERSPAN Header: A specialized metadata header inserted immediately ahead of the original frame. It contains:
    • ERSPAN ID (Session ID): A 10-bit identifier (values 1–1023) identifying the unique monitoring session.
    • Timestamp: High-precision hardware timestamp recording when the frame was captured.
    • Original VLAN ID, Cos, and Direction: Metadata recording ingress/egress state and original 802.1p Class of Service markings.
  3. GRE Header (IP Protocol 47): The packet is encapsulated in a GRE tunnel header. The GRE Protocol Type field is set to:
    • 0x88BE for ERSPAN Type II (standard enterprise deployment).
    • 0x22EB for ERSPAN Type III (adds richer platform metadata and higher-resolution timestamps).
  4. Outer IPv4 Header: An outer IP header with:
    • Source IP: Typically a loopback interface on the source switch.
    • Destination IP: The IP address of the destination switch or an ERSPAN-capable packet capture server (e.g., a server running Wireshark or an intrusion detection appliance configured to terminate ERSPAN).
    • DSCP / IP Precedence: Configurable IP QoS markings to prioritize or deprioritize mirrored traffic across WAN and campus backbones.

Because ERSPAN traffic is formatted as standard unicast IP/GRE packets, it routes across intermediate routers, firewalls, and WAN links without requiring any special configuration on transit nodes.


Architecture Comparison: SPAN vs. RSPAN vs. ERSPAN

Architecture CharacteristicLocal SPANRemote SPAN (RSPAN)Encapsulated RSPAN (ERSPAN)
Operational ScopeSingle autonomous switch or switch stackMultiple switches across Layer 2 broadcast domainEnterprise-wide across routed Layer 3 IP networks
Transport MediumInternal switch backplane / ASIC fabricDedicated RSPAN VLAN over 802.1Q trunksGRE encapsulation (IP Protocol 47)
Encapsulation ProtocolNone (Raw native frames)Standard 802.1Q tagged frameGRE Type II (0x88BE) or Type III (0x22EB)
Encapsulation Overhead0 bytes4 bytes (802.1Q tag)42 to 50 bytes (IP + GRE + ERSPAN headers)
Layer 3 RoutableNoNo (Confined to Layer 2 domain)Yes (Routable across campus, WAN, or cloud)
MAC Address LearningDisabled on destination portDisabled across the entire RSPAN VLANStandard unicast IP routing for outer header
Spanning Tree ImpactSTP disabled on destination portSTP active across RSPAN VLAN topologyUnaffected; operates as standard Layer 3 IP traffic
Destination NodeLocal switchport connected to analyzerSwitchport on remote switch in RSPAN VLANRemote switch or software-based IP capture server

Configuration and Verification

1. Local SPAN Configuration

! Configure Local SPAN session 1
Switch(config)# monitor session 1 source interface GigabitEthernet0/1 both
Switch(config)# monitor session 1 source interface GigabitEthernet0/2 rx
Switch(config)# monitor session 1 destination interface GigabitEthernet0/24 encapsulation replicate

2. Remote SPAN (RSPAN) Configuration

! On ALL participating switches: Define the dedicated RSPAN VLAN
Switch(config)# vlan 900
Switch(config-vlan)# name RSPAN_MONITORING
Switch(config-vlan)# remote-span

! On Source Switch A: Direct monitored traffic into RSPAN VLAN 900
Switch-A(config)# monitor session 1 source interface GigabitEthernet0/1 both
Switch-A(config)# monitor session 1 destination remote vlan 900

! On Destination Switch B: Pull traffic from RSPAN VLAN 900 to analyzer port
Switch-B(config)# monitor session 1 source remote vlan 900
Switch-B(config)# monitor session 1 destination interface GigabitEthernet0/24

3. Encapsulated Remote SPAN (ERSPAN) Configuration

! On Source Router/Switch: Configure ERSPAN Source Session
Switch-Src(config)# monitor session 1 type erspan-source
Switch-Src(config-mon-erspan-src)# source interface GigabitEthernet0/1 both
Switch-Src(config-mon-erspan-src)# destination
Switch-Src(config-mon-erspan-src-dst)# erspan-id 101
Switch-Src(config-mon-erspan-src-dst)# ip address 10.100.1.50
Switch-Src(config-mon-erspan-src-dst)# origin ip address 10.10.1.1
Switch-Src(config-mon-erspan-src-dst)# exit
Switch-Src(config-mon-erspan-src)# no shutdown

! On Destination Router/Switch: Configure ERSPAN Destination Session
Switch-Dst(config)# monitor session 1 type erspan-destination
Switch-Dst(config-mon-erspan-dst)# destination interface GigabitEthernet0/24
Switch-Dst(config-mon-erspan-dst)# source
Switch-Dst(config-mon-erspan-dst-src)# erspan-id 101
Switch-Dst(config-mon-erspan-dst-src)# ip address 10.100.1.50
Switch-Dst(config-mon-erspan-dst-src)# exit
Switch-Dst(config-mon-erspan-dst)# no shutdown

ERSPAN sessions are created in the shutdown state, so no shutdown is required on both the source and destination sessions.

Verification Commands

  • show monitor session <number>: Displays session state (active/inactive), monitored source ports/VLANs, direction, and destination interface.
  • show monitor session all: Summarizes all configured SPAN, RSPAN, and ERSPAN sessions across the device.
  • show vlan remote-span: Lists all VLANs currently designated with the remote-span property.
Switch# show monitor session 1
Session 1
---------
Type                   : Local Session
Source Ports           : 
    RX Only            : Gi0/2
    TX Only            : None
    Both               : Gi0/1
Source VLANs           : 
    RX Only            : None
    TX Only            : None
    Both               : None
Destination Ports      : Gi0/24
    Encapsulation      : Replicate
    Ingress            : Disabled
Test Your Knowledge

What operational state does a Cisco switch enforce on an interface designated as a Local SPAN destination port?

A

The interface operates in full-duplex promiscuous mode and actively injects mirrored traffic into the default VLAN

B

The interface participates in Spanning Tree Protocol (STP) using Bridge Assurance to prevent bridging loops

C

The interface acts as an 802.1Q trunk that automatically tags all mirrored frames with VLAN 1

D

The interface disables Layer 2 MAC learning and Spanning Tree Protocol, and discards inbound traffic by default

Test Your Knowledge

Why must network engineers manually prune the dedicated RSPAN VLAN from trunk links that do not lead directly to the switch hosting the monitoring analyzer?

A

Because Spanning Tree Protocol is disabled on the RSPAN VLAN, causing immediate broadcast storms on unpruned trunks

B

Because MAC learning is disabled on the RSPAN VLAN, mirrored traffic floods out every trunk that carries that VLAN

C

Because dynamic VTP pruning automatically converts unpruned RSPAN trunks into routed Layer 3 sub-interfaces

D

Because RSPAN traffic overwrites native VLAN tags, corrupting the management plane of adjacent transit switches

Test Your Knowledge

An enterprise needs to mirror traffic from a branch office access switch across an MPLS VPN WAN to a centralized security operations center. Which technology and encapsulation protocol enable this capability?

A

Encapsulated Remote SPAN (ERSPAN) utilizing GRE IP protocol 47

B

Local SPAN utilizing 802.1Q VLAN trunking protocol 1

C

Remote SPAN (RSPAN) utilizing standard Ethernet multicasting

D

Switched Port Analyzer utilizing IPsec ESP protocol 50

Sections you finish are checked off in the contents.