On Wed, 11 Aug 2010, Phil Mayers wrote: > FWIW we seldom (In fact I'm not sure ever!) use an actual 6500 as an > erspan receiver; we use "gulp" on a Unix box, or the wireshark ERSPAN > decoder, depending on the requirements. Yes, I usually tcpdump it to a pcap file and analyse it with wireshark. -- Mikael Abrahamsson email: swmike at swm.pp.se