Skip to content

SPAN

SPAN settings are only for Sophos NDR.

The appliance captures network packets via Switched Port Analyzer (SPAN) ports.

You can change your SPAN settings on the Settings page. Changes only take effect after a restart of your VM. See Restart and shutdown.

SPAN ports

By default, Sophos NDR has SPAN Port 1 (ens160) turned on and SPAN Port 2 turned off. This allows normal SPAN traffic to be monitored on the SPAN Port 1 network interface.

SPAN default setting.

You might have multiple switches that are able to send SPAN traffic to the appliance. To collect this traffic, turn on SPAN Port 2.

If you need a second SPAN port, you must allocate at least 8 vCPUs to the virtual machine.

SPAN port 2.

To find out more about setting up Sophos switches for SPAN, see the Configure your switches section of Sophos NDR.

Encapsulated Remote SPAN traffic

Encapsulated Remote Switched Port Analyzer (ERSPAN) enables monitoring of traffic from multiple sources distributed over multiple switches. This traffic is then delivered to the ERSPAN destination switch via IP.

The Sophos appliance can collect encapsulated SPAN traffic. It supports the VXLAN and GRE tunnel protocols.

Follow the instructions for VXLAN or GRE.

To turn on VXLAN, do as follows:

  1. Select Enable ERSPAN next to the SPAN port.
  2. In Tunnel Protocol, select vxlan.
  3. In IP Address, enter the IP address of the VTEP interface.
  4. In VXLAN ID, enter the ID. This must match the VXLAN encapsulated source configuration.
  5. In VXLAN Port, enter the default VXLAN port. This must match the VXLAN encapsulated source configuration.
  6. Click Save.

VXLAN configuration.

To turn on GRE, do as follows:

  1. Select Enable ERSPAN next to the SPAN port.
  2. In Tunnel Protocol, select gre.
  3. In IP Address, enter the IP address of the GRE target interface.
  4. In GRE Port, enter the default GRE port. This must match the GRE encapsulated source configuration.
  5. Click Save.

    GRE configuration.

It's common to see SPAN and VXLAN encapsulated SPAN ports in the same configuration. Using VXLAN and GRE on the same Sophos appliance is rare.