Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

sFlow Monitoring for Layer 2 Bridge Domain Traffic

sFlow monitoring for Layer 2 bridge domain traffic provides visibility into ingress and egress Layer 2 forwarded traffic using sFlow sampling.

sFlow monitoring for Layer 2 (L2) bridge domain traffic extends traffic visibility beyond traditional Layer 3 forwarding by enabling packet sampling for L2-forwarded packets. With this capability, Junos OS Evolved supports ingress and egress sFlow monitoring for traffic switched within a bridge domain and for traffic that traverses Layer 2 and Layer 3 boundaries through an Integrated Routing and Bridging (IRB) interface. This feature applies to both enterprise-style (EP) and service-provider-style (SP) Layer 2 configurations.

sFlow continues to sample packets at physical interfaces. Exported sFlow records include bridge-domain-aware context, such as VLAN information and Layer 2 forwarding behavior. This approach provides clear visibility into switched traffic without requiring changes to existing sFlow configuration or collectors.

Benefits of sFlow Monitoring for Layer 2 Bridge Domain traffic

  • Provides enhanced visibility into Layer 2 switched traffic that does not involve Layer 3 forwarding.
  • Enables ingress and egress traffic monitoring for accurate analysis of traffic flows across bridge domains.
  • Supports hybrid forwarding scenarios, including traffic traversing bridge domains and IRB interfaces.
  • Delivers consistent traffic monitoring for enterprise and service-provider Layer 2 deployments.
  • Maintains compatibility with existing sFlow collectors and operational workflows.

Limitations

  • sFlow samples packets only on physical interfaces, it does not sample traffic directly on IRB interfaces.
  • For dual-tagged (Q-in-Q) packets, sFlow reports only the outer VLAN tag.
  • sFlow includes extended routing information only when packets traverse a Layer 3 forwarding interface.