Traffic Monitoring
- Traffic Monitoring
- Creating a Traffic Monitoring Session
- Editing an Existing Traffic Monitoring Session
- Activating or Deactivating a Traffic Monitoring Session
- Deleting a Traffic Monitoring Session
Traffic Monitoring
Traffic monitoring copies traffic, from one or more source ports, and sends it to a dedicated destination port for analysis by a network analyzer. This feature is also known as Switched Port Analyzer (SPAN).
For FC port channels on Cisco UCS 6200 Fabric Interconnects, you can monitor only egress traffic.
For FC port channels on Cisco UCS 6300 Fabric Interconnects, you can monitor only ingress traffic.
Traffic Monitoring Session Types
When you create a traffic monitoring session, you can choose either an Ethernet or Fibre Channel destination port to receive the traffic. The type of destination port determines the type of session, which in turn determines the types of available traffic sources. For an Ethernet traffic monitoring session, the destination port must be an unconfigured physical port. For a Fibre Channel traffic monitoring session, the destination port must be a Fibre Channel uplink port.
Note |
For Cisco UCS 6300 Fabric Interconnects, the destination port must also be an unconfigured physical Ethernet port. For Cisco UCS 6332 and Cisco UCS 6332-16UP Fabric Interconnects, you cannot choose Fibre Channel destination ports, but can use unconfigured ethernet ports as a destination for FC traffic monitoring sessions. |
Traffic Monitoring Across Ethernet
An Ethernet traffic monitoring session can monitor any of the following traffic source and destination ports:
Source Ports |
Destination Ports |
---|---|
Traffic Monitoring for UCS 6300 Interconnects
Traffic Monitoring for UCS 6200 Interconnects
Traffic Monitoring Across Fibre Channel
You can monitor Fibre Channel traffic using either a Fibre Channel traffic analyzer or an Ethernet traffic analyzer. When Fibre Channel traffic is monitored with an Ethernet traffic monitoring session, the destination traffic is FCoE. The Cisco UCS 6300 Fabric Interconnect supports FC SPAN only on the ingress side. You cannot configure a Fibre Channel port on a Cisco Cisco UCS 6248 Fabric Interconnect as a source port.
A Fibre Channel traffic monitoring session can monitor any of the following traffic source and destination ports:
Source Ports |
Destination Ports |
---|---|
|
|
Guidelines and Recommendations for Traffic Monitoring
When configuring or activating traffic monitoring, consider the following guidelines:
Traffic Monitoring Sessions
A traffic monitoring session is disabled by default when created. To begin monitoring traffic, you must activate the session.
-
Create a unique traffic monitoring session on any fabric interconnect within the Cisco UCS pod.
-
Create each monitoring session with a unique name and unique source.
-
Add all vNICs from the service profile of a server to monitor traffic from a server.
-
Locate all traffic sources within the same switch as the destination port.
-
Do not add the same source in multiple traffic monitoring sessions.
-
Do not configure a port as a destination port and a source port.
-
Do not configure a member port, of a port channel, individually as a source. If you configure the port channel as a source, all member ports are source ports.
Maximum Supported Active Traffic Monitoring Sessions
Note |
Traffic monitoring can impose a significant load on your system resources. To minimize the load, select sources that carry as little unwanted traffic as possible and disable traffic monitoring when it is not needed. |
vNIC
Because a traffic monitoring destination is a single physical port, a traffic monitoring session can monitor only a single fabric. To monitor uninterrupted vNIC traffic across a fabric failover, create two sessions, one per fabric, and connect two analyzers. Add the vNIC as the traffic source using the exact same name for both sessions. If you change the port profile of a virtual machine, you must reconfigure the monitoring session. All associated vNICs used as source ports are removed from monitoring.
vHBA
You can use a vHBA as a source for either an Ethernet or Fibre Channel monitoring session, but it cannot be a source for both simultaneously. When a VHBA is set as the SPAN source, the SPAN destination only receives VN-tagged frames. It does not receive direct FC frames.
SPAN Ports Support Matrix
Note |
For Cisco UCS 6200 and 6324 FIs, you can only set the source mode to transmit for two sources per Cisco UCS domain. |
Ethernet Span Port Sources
Source Ethernet SPAN ports are supported in the following configurations:
Source Type |
Source Mode | ||
---|---|---|---|
on Cisco UCS 6200 FI |
on Cisco UCS 6324 FI |
on Cisco UCS 6332 FI |
|
Ethernet Uplink |
Receive, Transmit, Both |
Receive, Transmit, Both |
Receive, Transmit, Both |
Ethernet Port-Channel |
Receive |
Receive |
Receive, Transmit, Both |
FCoE Uplink |
Receive, Transmit, Both |
Receive, Transmit, Both |
Receive, Transmit, Both |
FCoE Port-Channel |
Receive |
Receive |
Receive, Transmit, Both |
Appliance Port |
Receive, Transmit, Both |
Receive, Transmit, Both |
Receive, Transmit, Both |
FCoE Storage |
Receive, Transmit, Both |
Receive, Transmit, Both |
Receive, Transmit, Both |
Unified Ports |
Receive, Transmit, Both |
Receive, Transmit, Both |
Receive, Transmit, Both |
VLAN |
Receive |
Receive |
Receive |
Static vNIC |
Receive, Transmit, Both |
Receive, Transmit, Both |
Receive, Transmit, Both |
vHBA |
Receive, Transmit, Both |
Receive, Transmit, Both |
Receive, Transmit, Both |
Ethernet Span Port Destinations
Destination Ethernet SPAN ports are supported in the following configurations:
Session Type |
Admin Speed |
||
---|---|---|---|
on Cisco UCS 6200 FI |
on Cisco UCS 6324 FI |
on Cisco UCS 6332 FI |
|
Ethernet SPAN Ports |
Ethernet Unconfigured at 1 Gbps, 10 Gbps |
Ethernet Unconfigured at 1 Gbps, 10 Gbps |
Ethernet Unconfigured at 1Gbps, 10 Gbps, 40 Gbps |
FC Span Port Sources
Source FC SPAN ports are supported in the following configurations:
Source Type |
Source Mode | ||
---|---|---|---|
on Cisco UCS 6200 FI |
on Cisco UCS 6324 FI |
on Cisco UCS 6332 FI |
|
FC Uplink |
Transmit |
Not Supported |
Receive |
FC Port-Channel |
Transmit |
Not Supported |
Receive |
FC Storage |
Transmit |
Not Supported |
Receive |
VSAN |
Not Supported |
Not Supported |
Receive |
vHBA |
Receive, Transmit, Both |
Not Supported |
Receive, Transmit, Both |
FC Span Port Destinations
Destination FC SPAN ports are supported in the following configurations:
Session Type |
Admin Speed |
||
---|---|---|---|
on Cisco UCS 6200 FI |
on Cisco UCS 6324 FI |
on Cisco UCS 6332 FI |
|
FC SPAN Ports |
FC Uplink at 1 Gbps, 2 Gbps, 4 Gbps, 8 Gbps, Auto |
Not Supported |
FC Unconfigured at 1 Gbps, 2 Gbps, 4 Gbps, 8 Gbps, 16 Gbps, Auto |
FC SPAN Ports |
FC Monitor at 1 Gbps, 2 Gbps, 4 Gbps, 8 Gbps, Auto |
Not Supported |
FC Monitor at 1 Gbps, 2 Gbps, 4 Gbps, 8 Gbps, 16 Gbps, Auto |
Creating a Traffic Monitoring Session
Before creating a traffic monitoring session in Cisco UCS Central, ensure that port configuration is set to Global on the Policy Resolution Control page for the Cisco UCS.
Editing an Existing Traffic Monitoring Session
Activating or Deactivating a Traffic Monitoring Session
Existing traffic monitoring sessions can be activated or deactivated.
Step 1 | Click the Browse Tables icon and choose Fabric Interconnects. |
Step 2 | Choose the fabric interconnect where you want to update traffic monitoring. |
Step 3 | On the fabric interconnect page, click Traffic Monitoring. |
Step 4 | Click on the traffic monitoring session that you want to edit. |
Step 5 | Click the Edit icon. |
Step 6 | Modify the Admin State: |
Step 7 | Click Save. |
Deleting a Traffic Monitoring Session
Step 1 | Click the Browse Tables icon and choose Fabric Interconnects. |
Step 2 | Choose the fabric interconnect where you want to update traffic monitoring. |
Step 3 | On the fabric interconnect page, click Traffic Monitoring. |
Step 4 | Click on the traffic monitoring session that you want to delete. |
Step 5 | Click the Delete icon. |