sFlow Monitoring for Layer 2 Bridge Domain Traffic
sFlow monitoring for Layer 2 bridge domain traffic provides visibility into ingress and egress Layer 2 forwarded traffic using sFlow sampling.
sFlow monitoring for Layer 2 (L2) bridge domain traffic extends traffic visibility beyond traditional Layer 3 forwarding by enabling packet sampling for L2-forwarded packets. With this capability, Junos OS Evolved supports ingress and egress sFlow monitoring for traffic switched within a bridge domain and for traffic that traverses Layer 2 and Layer 3 boundaries through an Integrated Routing and Bridging (IRB) interface. This feature applies to both enterprise-style (EP) and service-provider-style (SP) Layer 2 configurations.
sFlow continues to sample packets at physical interfaces. Exported sFlow records include bridge-domain-aware context, such as VLAN information and Layer 2 forwarding behavior. This approach provides clear visibility into switched traffic without requiring changes to existing sFlow configuration or collectors.
Benefits of sFlow Monitoring for Layer 2 Bridge Domain traffic
- Provides enhanced visibility into Layer 2 switched traffic that does not involve Layer 3 forwarding.
- Enables ingress and egress traffic monitoring for accurate analysis of traffic flows across bridge domains.
- Supports hybrid forwarding scenarios, including traffic traversing bridge domains and IRB interfaces.
- Delivers consistent traffic monitoring for enterprise and service-provider Layer 2 deployments.
- Maintains compatibility with existing sFlow collectors and operational workflows.
Limitations
- sFlow samples packets only on physical interfaces, it does not sample traffic directly on IRB interfaces.
- For dual-tagged (Q-in-Q) packets, sFlow reports only the outer VLAN tag.
- sFlow includes extended routing information only when packets traverse a Layer 3 forwarding interface.