2014-03-12 12:09 AM
Hello Everyone,
We are installing the All-In-One Netwitness virtual appliance suite and I'd like the Decoder to be able to be vmotioned to/from any one of three ESX 5.5 hosts. The span port will be a L3 Mirror port created on our VDS (Virtual Distributed Switch) and this basically encapsulates all mirror/span traffic from selected VMWare guests into GRE packets which are routed to our Decoder (Not a high volume TAP environment). This allows the Decoder to be Vmotioned from Host to Host however at the moment the traffic arrives encapsulated in GRE. What would be the best way to remove the GRE headers on the Decoder before the traffic actually enters the Decoder for processing?
Many thanks
2020-03-30 08:34 AM
I know this is an old question but it came up when I searched for ERSPAN. I'm hoping a NetWitness 11.4 Decoder will process the data inside a GRE tunnel. Can anyone confirm or deny this feature?
2020-03-31 08:46 AM
This may help you Virtual Host Setup: Step 4. Configure Host-Specific Parameters
Virtual taps encapsulate the captured traffic in a GRE tunnel. Depending on the type you choose, either of these scenarios may apply:
2020-03-31 11:49 AM
Thanks! With the help of support I have also found the VlanGRE parser that is used to decapsulate the GRE traffic. My only question now is if this parser supports the GRE protocol types from RFC1701 only or if the ERSPAN protocol types 0x88BE and 0x22EB are also supported. See https://tools.ietf.org/html/rfc1701 and https://tools.ietf.org/html/draft-foschiano-erspan-03