Use ERSPAN to collect IoT device traffic data from switches and send it through GRE tunnels
to a firewall.
| Where Can I Use This? | What Do I Need? |
|
|
One of the following subscriptions:
Device Security subscription for an advanced
Device Security product (Enterprise,
OT, or Medical)
Device Security X subscription
|
Unless device traffic is visible to a firewall,
the firewall cannot include it in the logs it forwards to
Device Security.
When you need to collect data for devices whose traffic doesn't
pass through a firewall, mirror their traffic on network switches
and use Encapsulated Remote Switched Port Analyzer (ERSPAN) to send
it to the firewall through a
Generic Routing Encapsulation (GRE) tunnel.
After the firewall decapsulates the traffic,
it inspects it similar to traffic received on a TAP port. The firewall
then creates enhanced application logs (EALs) and traffic, threat,
WildFire, URL, data, GTP (when GTP is enabled), SCTP (when SCTP
is enabled), tunnel, auth, and decryption logs. It forwards them to
the logging service where
Device Security can access and analyze the
device data.
You can use this feature for any deployments where traffic from remote switches
needs to be inspected. Device Security is just one use case.
This
feature requires switches that support ERSPAN such as Catalyst 6500,
7600, Nexus, and ASR 1000 platforms.