Re: ERSPAN / GRE - weird log
Stuart H <[email protected]> Tue, 5 Nov 2019 18:44:08 +0000
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <[email protected]> |
I added support for ERSPAN type II and III and have it working fine using VMware ERSPAN. You’re definitely using Zeek 3.0+ right? From: <[email protected]> on behalf of "Ralph R. Rye" <[email protected]> Date: Monday, 4 November 2019 at 15:08 To: "[email protected]" <[email protected]> Subject: [Zeek] ERSPAN / GRE - weird log Hoping to see if someone has gotten Zeek to work with ERSPAN span sessions. I am doing ERSPAN from a Cisco Nexus switch to a VMware host. I can see the traffic at the host and do tcpdump captures without any problems. When attempting to use Zeek (3.0 or 2.6.3) all I get is entries in the weird log for the ERSPAN traffic. I noticed someone previously posting about it may be a GRE type issue, and that it appears someone modified a source file to get things to work. Here is the frame/packet header info from the ERSPAN traffic from the Nexus 9k. As you can see it is type 0x88be [cid:[email protected]] I have used Zeek quite a bit in the past with regular SPAN sessions and TAPs, but having the capability to use ERSPAN would be a great benefit of being able to pull in traffic from many sections of the network without having to worry about the physical device requirements of regular SPAN and TAPS. I utilize ERSPAN quite a bit with tshark/wireshark for being able to capture just the traffic I care about in a datacenter. -Ralph _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
image001.png
(image/png, 44.5 KB) - not displayed