This knowledge base has moved to the documentation site. Please visit the knowledge base here for the most up to date content. This site is no longer maintained.

Configure ERSPAN to a Cumulus Linux Switch



This article applies to the following issues:

  • A SPAN destination is not available.
  • The interface type or types prevent using a laptop as a SPAN destination.

Note: This data has to be processed by the control plane, which impacts the CPU of the destination switch.


  • Cumulus Linux, all versions


Normal ERSPAN setup rules apply; see the Network Troubleshooting chapter for details.

  1. Create rules for SPAN source; for example:
    cumulus@switch:~$ cat /etc/cumulus/acl/policy.d/span.rules
    -A FORWARD --in-interface swp50 -j ERSPAN --src-ip --dst-ip
    -A FORWARD --out-interface swp50 -j ERSPAN --src-ip --dst-ip
  2. Install the rules:
    cumulus@switch:~$ sudo cl-acltool -i
  3. Verify the SPAN rules were installed:
    cumulus@switch:~$ cl-acltool -L all | grep SPAN
    41229 4368K ERSPAN all -- swp50 any anywhere anywhere ERSPAN src-ip: dst-ip:
    17540 1126K ERSPAN all -- any swp50 anywhere anywhere ERSPAN src-ip: dst-ip:

Note: The destination switch does not expect the ERSPAN packets, so it generates ICMP destination unreachable packets as a result. These packets are included in any capture you take.

To remove these packets, add an ACL like the following to the destination switch:

cumulus@switch:~$ cat /etc/cumulus/acl/policy.d/span.rules
-A OUTPUT --out-interface swp3 -p icmp --icmp-type destination-unreachable -j DROP



  • Avatar
    Rodney Olesak

    To see the ERSPAN traffic at the destination IP using Wireshark, when selecting the interface to listen to, enter the following for protocol/filter:

    ip proto 0x2f

    Once you start the capture, you will see the traffic from the device, without the GRE tunnel on you local wireshark.

This support portal has moved

Cumulus Networks is now part of the NVIDIA Networking Business Unit! The NVIDIA Cumulus Global Support Services (GSS) team has merged its operations with the NVIDIA Mellanox support services team.

You can access NVIDIA Cumulus support content from the Mellanox support portal.

You open and update new cases on the Mellanox support portal. Any previous cases that have been closed have been migrated to the Mellanox support portal.

Cases that are still open on the Cumulus portal will continue to be managed on the Cumulus portal. Once these cases close, they will be moved to the Mellanox support portal.

Powered by Zendesk