Port mirroring traffic is seen on uplinks of ESXi hosts in maintenance mode
search cancel

Port mirroring traffic is seen on uplinks of ESXi hosts in maintenance mode

book

Article ID: 399732

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Port mirroring sessions defined on the DVS of the cluster: source vms and target vm are both running on that cluster.

The mirroring traffic is supposed to be seen only on the target VM where the endpoint of mirroring traffic is terminated. But  those session traffic is detected on the uplinks of all the ESXi hosts, even when the host is in maintenance mode.

The encapsulated remote mirroring (L3) source with GRE encapsulation type is configured for port mirroring. 

 

 

Environment

8.0.3 Build 24022510

DVS Version: 7.0.3

Cause

From the packet captures on physical Nics of ESXi hosts, these encapsulated port mirroring packets were found to be received from uplink switches as its captured in UplinkRcvKernel as shown below 

Resolution

This issue needs to be checked with the Switch vendor to which these ESXi hosts are connected as the packets are seem to be entering ESXi hosts from uplink switches