Mylinking™ Network Packet Broker pamwe neInline Bypass Switch ML-BYPASS-M2000

Module yeBypass: 8*10G SFP+ & 4*100GE, Module yeMonitor: 16*10GE SFP+ & 4*100GE, Max 2.4Tbps

Tsananguro pfupi:

Nekukura kuri kuita internet nekukurumidza, njodzi yekuchengetedzeka kwemashoko enetwork iri kuramba ichikura, saka maapplication akasiyana-siyana ekudzivirira ruzivo ari kushandiswa zvakanyanya. Ingave iri michina yekudzora kupinda (firewall) yechinyakare kana rudzi rutsva rwenzira dzekudzivirira dzakanyanya dzakadai sesystem yekudzivirira kupinda (IPS), Unified threat management platform (UTM), Anti-denial service attack system (Anti-DDoS), Anti-spamGateway, Unified DPI Traffic Identification and Control System, pamwe nemidziyo yakawanda yekuchengetedza yakaiswa mumatanho e network key nodes, kushandiswa kwemutemo wekuchengetedza data unoenderana kuti uzive nekugadzirisa traffic yepamutemo / isiri pamutemo. Panguva imwe chete, zvisinei, network yekombuta ichaita kuti network inonoka zvikuru kana kuti network ikanganisika kana paine kutadza, kugadzirisa, kusimudzira, kutsiva michina nezvimwewo munzvimbo ye network yekugadzira yakavimbika zvikuru, vashandisi havagone kuzvitsungirira.


Ruzivo rweChigadzirwa

Matagi eChigadzirwa

1-Ongororo

Nekukura kuri kuita internet nekukurumidza, njodzi yekuchengetedzeka kwemashoko enetwork iri kuramba ichikura, saka maapplication akasiyana-siyana ekudzivirira ruzivo ari kushandiswa zvakanyanya. Ingave iri michina yekudzora ruzivo yechinyakare (firewall) kana rudzi rutsva rwenzira dzekudzivirira dzakanyanya senge system yekudzivirira kupinda (IPS), Unified threat management platform (UTM), Anti-denial service attack system (Anti-DDoS), Anti-spam Gateway, Unified DPI Traffic Identification and Control System, uye zvishandiso zvakawanda zvekuchengetedza zviri kuiswa mumatanho e network key nodes, kushandiswa kwemutemo wekuchengetedza data unoenderana kuti uone uye ugadzirise traffic yepamutemo / isiri pamutemo. Panguva imwe chete, zvisinei, network yemakomputa ichakonzera kunonoka kukuru kwenetwork kana kutokanganisa network kana paine kutadza, kugadzirisa, kusimudzira, kutsiva michina nezvimwewo munzvimbo ye network yekugadzira yakavimbika, vashandisi havagone kuzvitsungirira.

ML-BYPASS-M2000 Mylinking™ Network Packet Broker pamwe neInline Bypass Switch zvakatsvakurudzwa uye zvakagadzirwa kuti zvishandiswe pakuisa mhando dzakasiyana dzemidziyo yekuchengetedza serial ukuwo zvichipa kuvimbika kwakanyanya kune network.

Nekushandisa Mylinking™ Network Packet Broker pamwe neInline Bypass Switch:

●Vashandisi vanogona kuisa/kubvisa zvishandiso zvekuchengetedza pasina kukanganisa kana kukanganisa network iripo;

● Ine basa rekuongorora hutano rakangwara kuti riongorore mashandiro emidziyo yekuchengetedza yakabatana panguva chaiyo. Kana mudziyo wekuchengetedza wakabatana ukatadza kushanda zvakanaka, mudziviriri anongoerekana adarika kuti arambe achitaurirana netiweki.

●Tekinoroji yekudzivirira traffic inogona kushandiswa kuisa michina yekuchengetedza traffic, michina yekuongorora inovakirwa pa encryption, nezvimwewo. Inoshanda zvinobudirira kudzivirira traffic access kune mamwe marudzi etraffic, ichibvisa mutoro wekugadzirisa traffic wemidziyo iri mu-line.

● Tekinoroji yekudzivirira traffic inoenzanisa mutoro inogona kushandiswa kuisa zvishandiso zvakachengeteka zviri mumutsara mumapoka kuti zvizadzise zvinodiwa zvekuchengetedzwa kwemukati pasi penzvimbo dzine bandwidth yakanyanya kumanikidzwa.

●Ine hunyanzvi hweSSL proxy, ichizadzisa zvinodiwa zvekutarisa nekuongorora zvemidziyo yekudzivirira kuchengetedzwa kwezvinyorwa zvisina kunyorwa.

● Ine hunyanzvi hwekugadzirisa traffic hwakadai sekukopa traffic, kuunganidzwa, kusefa, uye kunyora mazita, pamwe nehunyanzvi hwepamusoro hwekugadzirisa traffic hwakadai sekuparadzanisa, kufukidza, kuziva application layer protocol, uye kugadzira traffic.

KUPANDA-M2000

2-Mylinking™ Network Packet Broker pamwe neInline Bypass Switch Advanced Features uye Technologies

Mylinking™ “SpecFlow” Protection Mode uye tekinoroji ye “FullLink” Protection Mode

Mylinking™ Fast Bypass Switching Protection Technology

Tekinoroji yeMylinking™ "LinkSafeSwitch"

Mylinking™ “WebService” Kutumira/Kuburitsa Mutemo Unochinja-chinja Tekinoroji

Tekinoroji yeMylinking™ Intelligent Heartbeat Packet yeKuona

Kubatanidza Kwangu™   Mapaketi Ekurova Kwemwoyo Anotsanangurwa Tekinoroji

Kubatanidza Kwangu™   Tekinoroji yeKuenzanisa Mutoro weZvibatanidza Zvakawanda

Kubatanidza Kwangu™   Tekinoroji Yekuparadzira Migwagwa Yakangwara

Kubatanidza Kwangu™   Tekinoroji Yekuenzanisa Mutoro Inochinja

Kubatanidza Kwangu™   Tekinoroji Yekutarisira Kure (HTTP/WEB, TELNET/SSH, “EasyConfig/AdvanceConfig” Hunhu)

3-Mylinking™ Network Packet Broker pamwe neInline Bypass Switch Configuration Guide

Nzvimbo yeBYPASS-M2000

Sezvakaratidzwa mudhayagiramu iri pamusoro apa, chikamu chose chine nzvimbo ina dze modular:

Nzvimbo dzeSLOT1, SLOT2, SLOT3, uye SLOT4 module dzinogona kugamuchira ma BYPASS protection port modules kana MONITOR port modules ane mitengo yakasiyana uye nhamba dzeport. Nekutsiva mamodules akasiyana, zvinokwanisika kutsigira BYPASS protection kune akawanda ma 10G/40G/100G links, pamwe nekuisa Inline Bypass monitoring equipment kune akawanda ma 10G/40G/100G links.

Cherechedza: BYPASS module neMONITOR module zvese zvinotsigira kuchinjana kwemagetsi.

 

3.1-Rondedzero yeMagadzirirwo eModule

Muenzaniso weChigadzirwa

InoshandaPzviyero

Chassis
ML-BYPASS-M2000-CHS/AC 2U standard 19-inch rackmount; simba rekushandisa zvakanyanya 300W; modular BYPASS protector main unit; 4 module slots; 1*RS232 Console interface, 1*10/100/1000M RJ45 interface ine network management yekunze; dual power supply AC-220V;
NT-BYPASS-M2000-CHS/DC 2U standard 19-inch rackmount; simba rekushandisa zvakanyanya 300W; modular BYPASS protector main unit; 4 module slots; 1*RS232 Console interface, 1*10/100/1000M RJ45 interface ine network management yekunze; dual power supply DC-48V;
NZVARAModule
INL-I8XM8X(LM/SM) Inotsigira dziviriro yekubatanidza serial ye 10GE (inoenderana ne 1G), ine ma interfaces e 8*10GE; inotsigira ma ports e 8*10G SFP+ ekutarisa (kunze kwema optical modules).
INL-I4HM2H (LM/SM) Inotsigira dziviriro ye 2-way 100GE (40GE inoenderana) yekubatanidza serial, ine huwandu hwe4*100GE interfaces; inotsigira 2*100GE QSFP28 monitoring ports (kunze kwema optical modules).
Module yeMONITOR
Muvhuro-M16X 16*10GE SFP+ maports ekutarisa (kunze kwemamodule e optical);
Muvhuro-M16X-CN98 Maport ekutarisa e16*10GE SFP+ (module ye optical haina kubatanidzwa); ine injini yepamusoro, inotsigira mabasa ekugadzirisa traffic akadai se bypass SSL decryption, SSL proxy, uye traffic drauplication;
Muvhuro-M4H 4 * 100GE QSFP28 monitoring ports (ma modules e optical haana kubatanidzwa);
Muvhuro-M4H-CN98 4*100GE QSFP28 monitoring ports (ma optical modules haana kubatanidzwa); ine engine yepamusoro, inotsigira mabasa epamusoro ekugadzirisa traffic akadai se bypass SSL decryption, SSL proxy, uye traffic drauplication;

 

3.2-Mitemo Yekusarudza Module

Zvichibva pane zvakasiyana-siyana zvinodzivirirwa uye zvinodiwa zvekutarisa kuiswa kwemidziyo, unogona kusarudza magadzirirwo akasiyana emamodule kuti aenderane nezvinodiwa zvako chaizvo; ndapota tevera mitemo iyi paunenge uchisarudza:

1) Kubatanidzwa kwechassis chinhu chakakosha uye chinofanira kusarudzwa usati wasarudza mamwe mamodule. Ndapota sarudzawo nzira yakakodzera yekupa magetsi (AC/DC) zvichienderana nezvaunoda.

2) Chigadziko ichi chinotsigira nzvimbo dzinosvika mana dzemamodule; haugone kusarudza mamodule akawanda kupfuura nhamba yenzvimbo dzekugadzirisa. Zvichienderana nekusanganiswa kwemhando dzakasiyana dzemamodule, chigadziko ichi chinogona kutsigira dziviriro yeserial kune anosvika gumi nematanhatu e10GE/GE links kana masere e100GE/40GE links.

4-Unyanzvi hwekugadzirisa motokari 

4.1-Kutumirwa Mukati

1

Dziviriro Yakanangana Yemumugwagwa
InotsigiraMutsetse(yakatevedzana)nzira yekudzivirira yemhando dzakasiyana dzetraffic mune chero ipi zvayomukatichinobatanidza.Totumira mamwe marudzi etraffic anotsanangurwa nemushandisi pamukatilink kuneMutsetse Skuchengetedzwamudziyokuti zvishandiswe, uye zvimwe zvinofamba zvinotumirwa zvakananga pasina kuyerera nepakatiMutsetse Skuchengetedzwamudziyo. Panguva imwe,itinoita real-time monitoring pamamiriro ekushanda kweMutsetse SkuchengetedzwamudziyoKana mamiriro ekugadzirisa traffic asina kunaka aonekwa,itichabviswa panzira yekutumira traffic otomatiki kuitira kuti network service irambe iripo.

1

Dziviriro Yese Yemumugwagwa Mukati
InotsigiraMutsetse(yakatevedzana)nzira yekudzivirira yemhando dzese dzetraffic mune chero ipi zvayomukatichinobatanidza.Tokutumira traffic yese iri mumukatilink kuneMutsetse Skuchengetedzwamudziyoyekugadzirisa, uye kutarisa mashandiro eInline Securitymudziyopanguva chaiyo. Kana mamiriro ekugadzirisa traffic asina kujairika awanikwa,itichabviswa panzira yekutumira traffic otomatiki kuitira kuti network service irambe iripo.

tsananguro yechigadzirwa

Kurema Kwemutoro
Iine kugona kwakangwara kwekuenzanisa mutoro wemotokari. Kana mashandiro ekugadzirisa eimwe cheteMutsetse Skuchengetedzwamudziyohazvina kukwana kugadzirisa dambudziko irimukatitraffic yekutaurirana kwelink, inogona kugoveramukatibatanidza traffic kune N Monitor interfaces nekugadzira boka rekuenzanisa mutoro. Zvichienderana neMAC, ruzivo rweIP, nhamba yechiteshi, protocol nedzimwe ruzivo,itinoita sarudzo yeHash algorithm yekuyera mutoro, kuitira kutimukatitraffic yekubatanidza inogoverwa zvakaenzana kune akawandamukatikuchengetedzekachishandisos yekugadzirisa cluster, izvo zvinovandudza mashandiro ekugadzirisa ese emukatikuchengetedzekachishandisos. Kuti zvienderane nezvinodiwa zvebandwidth yakakwira uye mamiriro ekushandiswa kwetraffic yakakura.

2

Kuonekwa kwePaketi yekurova kwemoyo

InotsigiraTxuyeRxmapaketi ekuona kurova kwemoyo kuburikidza neuplink uye downlink yezvakabatanamukatizvishandiso zvekuchengetedza, uye inoonazvishandiso zviri mukatimamiriro ekushanda uye kana maitiro ekugadzirisa traffic ari akajairika. Kurova kwemoyo kwemativi maviripaketinzira yekuona inogona kuratidza zviri nani mamiriro ekushanda aripo iye zvino emukatikuchengetedzekamudziyo, uye zvinobudirira kuona kuti network inoshanda zvakanaka.

Inogona kugadzirisa maparamita ekurova kwemoyo echero chinhumukatimudziyo wekuchengetedza, wakaita sekurova kwemoyoTxnguva yepakati, nguva yepamusoro yekurova kwemoyo kuedzazve, nguva yekurova kwemoyoTxgwara, nezvimwewo. Inogona kuona nekutonga mamiriro ekutadza kwemukatizvishandiso zvekuchengetedza nenguva, uye zvinoita kuti pave nekukurumidza kushandura ma links ekudzivirira.

Mapaketi ekuona kurova kwemoyo anenge ari ma frame eEthernet layer 2. Kana nzira yeLayer 2 bridge yaonekwa pachena (yakadai seIPS/FW) yaiswa, ma frame eEthernet layer 2 anotumirwa nguva dzose pasina kuvhara kana kudonhedza. Panguva imwe chete, inogona zvakare kutsigira ma Ethernet layer 2, layer 3 uye layer 4 heartbeat detection packets kuti ienderane nemamwe ma special.mukatiZvishandiso zvekuchengetedza hazviwanzogone kutumira mafuremu eEthernet layer 2 akajairika.

Zvichienderana nemaitiro ari pamusoro apa, vashandisi vanogona kuona mhedzisiro yekuongorora hutano hwemidziyo yekuchengetedza yakabatana, kuitira kuti ive nechokwadi chekuti mabasa ekuchengetedza anoshanda zvakanaka.

1

Kuchinja kweBypass
Inotsigira nzira yakaderera zvikuru yekupfuurakushandurakunonoka (<8ms), uye vashandisi havanyatsonzwi kukanganiswa kwenetwork kana mudziyo uchiita bypasskushanduraPanguva imwe chete, tekinoroji yekuchinja Link inoshandiswa nemudziyo inogona kuve nechokwadi chekuti mamiriro ekubatanidza kwe primary link haakanganiswe panguva yepasspass.kushanduraTekinoroji iyi ichaita kuti nzira yekupinda mudenga ienderane nezvinodiwakushandurayakachengeteka zvakanyanya, uye haizokonzere kuti protocol ye layer 2 / Layer 3 topology ye protected links iverengezve uye iungane, kuitira kuderedza kukanganisa kune network yemushandisi panguva yekushandura.

4

Kuvharirwa Kwemotokari
Kana mudziyo wekuchengetedza ukaona kubatana kwesesheni kusiri pamutemo kana kusina kujairika mutraffic uye uchida kuivhara nenguva, mudziyo unogona kuvharira chero mapaketi akatarwa mutraffic iri kumusoro/pasi.mukatichinongedzo chakavakirwa pamamiriro efirita anoenderana netuple kuti ive nechokwadi chekuti masevhisi enetwork anoshanda zvakachengeteka.

5

Girazi reMotokari
Pamusoro pekuchengetedzwa kwetraffic ye inline link uye Inline Security device (yakadai seIPS, WAF), chero traffic inotaridzwa neSPAN inogonawo kuburitswa kune SPAN security monitoring system (yakadai seIDS, APT), kuitira kuti isangane nezvinodiwa zveSPAN monitoring yetraffic data kana traffic testing uye certification.

6

Chiremba cheSSL
Kuburikidza nebasa reSSL proxy, packet yekutanga yakavharirwa inobviswa crypt yotumirwa ku inline security protection system, uye data rakabviswa crypt rinodzoserwa uye rodzoserwa ku original link, kuitira kuti data rakabviswa crypt ku inline security protection system rirege kukanganisa kutapurirana kwedata rakavharirwa pane original link yemushandisi, uye kuita kuti data rakavharirwa rionekwe uye riongororwe ne analysis system.

4.2-Kuendeswa kweSPAN

7

Kudzokororwa kweTraffic yeNetwork
InotsigiraMutsetse(yakatevedzana)nzira yekudzivirira yemhando dzakasiyana dzetraffic mune chero ipi zvayomukatichinobatanidza.Totumira mamwe marudzi etraffic anotsanangurwa nemushandisi pamukatilink kuneMutsetse Skuchengetedzwamudziyokuti zvishandiswe, uye zvimwe zvinofamba zvinotumirwa zvakananga pasina kuyerera nepakatiMutsetse Skuchengetedzwamudziyo. Panguva imwe,itinoita real-time monitoring pamamiriro ekushanda kweMutsetse SkuchengetedzwamudziyoKana mamiriro ekugadzirisa traffic asina kunaka aonekwa,itichabviswa panzira yekutumira traffic otomatiki kuitira kuti network service irambe iripo.

8

Kuunganidzwa kweTraffic yeNetiweki
Traffic yekutanga yekupinda uye traffic yakagadziriswa kare inogona kukopwa kuchiratidzo cheN chiteshi zvichienderana nechiratidzo chimwe chete chechiteshi kana kukopwa kuchiratidzo cheM chiteshi mushure mekuunganidzwa kwechiratidzo cheN chiteshi paGE, 10GE, 40G uye 100G line speed forwarding, izvo zvinogadzirisa zvakakwana zvinodiwa zvekuisa zvishandiso zvinopfuura zviviri zve multi-port literacy bypass mu network panguva imwe chete.

9

Kugovera/Kutumira Data
Yakarongedza methata inouya nemazvo uye yakarasa kana kutumira masevhisi akasiyana edata kune akawanda ma interface outputs zvichienderana nemitemo yakatarwa nemushandisi.

10

Kusefa Data rePaketi
Ruzivo rwekupindamotokariinogona kupatsanurwa nemazvo, uye masevhisi akasiyana edata anogona kuve mitemo yepamutemo kana yepamutemo, uye ma interface outputs akawanda anogona kuraswa kana kutumirwa. Inotsigira musanganiswa unochinjika zvichienderana nerudzi rweEthernet, vlan tag, IP five-tuple,TCPchitupa, hunhu hwepaketi nezvimwe zvinhu kuti zvienderane nezvinodiwa zvekuisa michina yakasiyana-siyana yekuchengetedza network, ongororo yeprotocol, ongororo yezviratidzo, uye kumwe kutarisa traffic.

35

Kurema Kwemutoro
Kuenzanisa mutoro weHash algorithm yesarudzo kunogona kuitwa zvichienderana nehunhu hwemukati nekunze kweL2-L4 kuve nechokwadi chekuti session integrity yekufamba kwedata kwakagamuchirwa neSPANmudziyo wekutarisa. Kana mamiriro ekubatanidza achichinja, nhengo dzeboka rechiteshi chekuburitsa zvinhu dzinogona kubuda (link DOWN) kana kubatana (link UP) nenzira inochinjika, uye boka rekuburitsa zvinhu rinogona kugovera otomatiki traffic kuti ive nechokwadi chekuti traffic inobuda yechiteshi ichi inochinjika.

tsananguro yechigadzirwa (7)
tsananguro yechigadzirwa (8)
tsananguro yechigadzirwa (9)

VLAN Yakanyorwa

VLAN Isina Matagi

VLAN Yakatsiviwa

Yakatsigira kuenzaniswa kwechero key field mumabyte ekutanga zana nemakumi maviri nemasere epakeji. Mushandisi anogona kugadzirisa kukosha kwe offset uye kureba kwekey field uye zviri mukati, uye kusarudza mutemo wekubuda kwetraffic zvichienderana nemagadzirirwo emushandisi.

15

Kudhinda Nguva
Inotsigirwa ku batanidza sevha yeNTP kuti ugadzirise nguva uye nyora meseji mupaketi nenzira yechiratidzo chenguva chine chiratidzo chenguva pamagumo efuremu, nekururama kwemasekondi mashoma.

16

Kubvisa Tunnel Encapsulation
Yakatsigira VxLAN, VLAN, GRE, GTP, MPLS, IPIP header yakabviswa mupaketi yedata yekutanga ndokutumirwa.

wps_doc_20

Kucheka Data/Packet
Inotsigirachikamu chepaketiKutora data rekutanga zvichibva pane traffic input interface uye output interface (64, 96, 128, 160, 192, 224, 256, 288, 320, 384, 512, 640, 768, 896, 960 bytes hazvidiwi), uye traffic output policy inogona kushandiswa zvichienderana ne user configuration.

wps_doc_22

Kuziva Protocol yeTunneling
Inotsigirwa inoona otomatiki mapuroteni akasiyana-siyana ekugadzira tunnel akadai seGTP / GRE / VxLAN / PPTP / L2TP / PPPOE / IPIP. Zvichienderana nemagadzirirwo emushandisi, nzira yekuburitsa traffic inogona kushandiswa zvichienderana nechikamu chemukati kana chekunze chetunnel.

19

Kutumira Packet Kunokosha
Inotsigira tsananguro yekuisa data package zvichienderana nekukosha kwebasa pachiteshi chinouya, uye mapakeji anonyanya kukosha anotumirwa zvakanyanya panosvika pakabuda. Mushure mekunge mapakeji anonyanya kukosha atumirwa, mamwe mapakeji epakati neasina kukosha anotumirwa. Dzivisa alarm yehurongwa hwekuongorora inokonzerwa nekushaikwa kwemapakeji edata akakosha.

21

Alarms Isina Kunaka
Inotsigira alarm yekutarisa nguva chaiyo uye marekodhi ealarm enhoroondo emafambiro einterface zvichienderana nehurongwa hwe threshold. Inotsigira maalarms ekutarisa nguva chaiyo uye marekodhi ealarm enhoroondo zvichienderana nehutano hwehardware yemudziyo (CPU, memory, tembiricha, fan, magetsi, nezvimwewo).

20

Nzvimbo Yekuchengetedza Inopisa
Inotsigira input interface 1+1 primary/standby configuration, output interface 1+1 primary/standby configuration, uye load balancing group N+1 primary/standby configuration kuti ive yakavimbika zvikuru mukufamba kwetraffic kubva pakupinda kuenda pakubuda.

22

Kuyerwa kweTraffic Microburst
Inogona kuona nguva, nguva uye mwero wekubuda kwetraffic micro-burst munguva chaiyo, uye inopa kuchengetedza zvinyorwa zvekuyera kwenhoroondo, izvo zvinopa nzira dzinoverengeka uye dzinoonekwa uye hwaro hwekugadzirisa matambudziko ekushanda nekugadzirisa uye kuona kurasikirwa kwepaketi.

23

Dziviriro yeKutenderera kweInterface
Inotsigira kuonekwa nekuchengetedzwa kwezviitiko zvekubatanidza kumusoro/kudzika kwechero interface, kuitira kudzivirira kurasikirwa kwekupinda nekubuda kwetraffic kunokonzerwa nekubatanidza kazhinji kumusoro/kudzika kweinterfaces, uye kuvandudza kugadzikana kwekuunganidza nekutumirwa kwetraffic.

18

Kuburitswa kweTunnel Encapsulation
Inotsigira ERSPAN2, GRE, VXLAN, NVGRE type tunnel encapsulation yechero traffic yakaunganidzwa uye output kuti ienderane nezvinodiwa zvekushandisa pakutumira traffic yakaunganidzwa kune remote analysis system.

24

Kugumiswa kweTunnel Packet
Inotsigira basa rekugumisa meseji yemugero. Basa iri rinobvumira kugadzirisa ma IP address/mask nema MAC addresses pachiteshi chekupinda kwetraffic. Rinogonesa kutapurirana zvakananga kwetraffic inoda kuunganidzwa mu user network kuburikidza nenzira dze tunnel encapsulation dzakadai seGRE, GTP, uye VXLAN kuenda kuchiteshi chekuunganidza chemudziyo.

6

Kubvisa Kuvharidzira kweSpan SSL
Kurodha pasi chitupa cheSSL chinoenderana kunotsigirwa. Mushure mekudzima data rakavharidzirwa reHTTPS kune traffic yakatarwa, richatumirwa kumasystem ekutarisa nekuongorora kumashure sezvinodiwa. Kutsigirwa kweTLS1.0, TLS1.2 uye SSL3.0

25

Kubvisa Data/Packet
Kutsigirwa kwehuwandu hwezviverengero zveport-based kana policy-level kuenzanisa data rakawanda rekuunganidza uye kudzokorora kwepaketi redata rimwe chete panguva yakatarwa. Vashandisi vanogona kusarudza ma identifier akasiyana epaketi (dst.ip, src.port, dst.port, tcp.seq, tcp.ack, dst.mac, src.mac, vlan.id)

26

Kuvhara Zuva Rakarongwa
Yakatsigira granularity yakavakirwa pamutemo wekutsiva chero nzvimbo yakakosha mudata raw kuitira kuzadzisa chinangwa chekudzivirira ruzivo rwakakosha. Zvichienderana nemagadzirirwo emushandisi, mutemo wekubuda kwetraffic unogona kushandiswa.

27

Kuzivikanwa kweApp Layer Protocol
Inotsigira kuzivikanwa, kuburitswa uye kuraswa kweApplication Layer Protocols zvichibva paDNS/URL matching mode. Raibhurari yeDPI inogona kubatanidzwa kuti ione, ibudise uye ibvise mhando dzemaapplication protocol anosvika 1800 (akadai seaudio nevhidhiyo, mutambo, instant messaging, database, email, P2P, nezvimwewo), uye raibhurari yeDPI inogona kuvandudzwa uye kugadziriswa. Kana paine zvinodiwa zvakakosha, kuvandudzwa kwechipiri kunogona kuitwawo.

28

Paketi Yakatsanangurwa Nemushandisi Kubvisa Makapisi
Inotsigira basa rekuzvitsanangurira ma packet, iro rinogona kubvisa minda ye encapsulation nezviri mukati chero kupi zvako kwema bytes zana nemakumi maviri nemasere ekutanga epacket uye kuiburitsa.

29

Kuumba Migwagwa
Panguva imwe chete, tekinoroji yekugadzira traffic inoshandiswa mu output interface kuburitsa data rinoyerera zvakanaka kuenda ku analysis tool, iyo inogadzirisa zvakanyanya dambudziko rekurasikirwa kwepacket rinokonzerwa ne micro-burst uye inodzivirira alarm isina kujairika inokonzerwa nekurasikirwa kwetraffic mu analysis system.

30

Kufananidza Mazwi Akakosha Paketi
Mushure mekunge chero zviri muchikamu chemutoro wepaketi zvaenzaniswa uye zvabatwa, paketi yakabatana kana kuyerera kwechikamu kunotumirwa uye kunoburitswa kana kuraswa kuti kusangane nezvinodiwa zvekugadzirisa data retraffic rakati.

31

Kubvisa Tunnel Encapsulation
Inotsigira kubuda kweVXLAN, MPLS, GRE, SRV6, FABRICPATCH, GENEVE nedzimwe misoro yemapaketi mupaketi yedata yekutanga mushure mekubviswa.

32

Kuburitsa Kubatanidza Kwenguva Refu
Zvichienderana nezvinodiwa nemushandisi, chero kuyerera kwechikamu kunogona kutumirwa uye kuburitswa zvichienderana nehuwandu hwemabyte anotumirwa uye huwandu hwemapaketi anotumirwa, uye kuyerera kwechikamu chinotevera kunogona kuraswa, kuitira kuti zvienderane nezvinodiwa nesystem yekuongorora kumashure mune zvimwe zviitiko, izvo zvinongoda kuwana chikamu chetraffic yechikamu, kuderedza kumanikidzwa kwekuongorora traffic uye kuvandudza mashandiro esystem yekuongorora.

33

Kuongorora Nhamba dzeTraffic
Inotsigira nhamba dzezvikamu zvechero traffic yeinterface yekupinda, uye inogona kuratidza saizi yayo yetraffic, saizi/chikamu cheIP address, saizi/chikamu chetraffic TOPN yechikamu cheapplication protocol, saizi/chikamu chetraffic TOPN yezita reapplication protocol uye ruzivo rwetraffic session muchimiro chemachati munguva chaiyo, uye inopa kutumira kwemhedzisiro yenhamba kumafaira emunharaunda. Saka, vashandisi vanogona kunzwisisa zvakajeka chimiro chetraffic yakaunganidzwa, uye kupa hwaro hwekutsigira data zvakananga hwekugadzirisa maitiro etraffic uye kuchinja zvinodiwa zvebhizinesi.

34

Kuonekwa Kwemotokari - Kuongorora Ruzivo Rwekutanga
Module yekuongorora yekuona traffic inogona kuratidza ruzivo rwekutanga rwe data retraffic rakatorwa, senge kuverengwa kwemapaketi, kugoverwa kwemapaketi eunicast/multicast/broadcast, nhamba yekubatanidza session, kugoverwa kwemapaketi eprotocol, uye saizi yetraffic yakatorwa.

34

Kuonekwa Kwemotokari - Kuongorora Kwakadzama kweDPI
Module yeDPI yekuongorora zvakadzama yekushanda kwekuona traffic inogona kuongorora zvakadzama data retraffic rakabatwa kubva pamaonero akasiyana-siyana, uye kuratidza huwandu hwakadzama muchimiro chemagrafu nematafura.

34

Kuonekwa Kwemotokari - Kuongorora Kuenzana Kwemotokari
● Kuongorora huwandu hweprotocol yeTransport layer: senge TCP, UDP, ICMP, IGMP, ARP nedzimwe nhamba dzepaketi uye nhamba dzetraffic uye kuratidzwa kwechati yepie
● Kuongorora huwandu hwetraffic yeIP: zvakaita sehuwandu hwetraffic hunogadzirwa nekero dzakasiyana dzeIP, IP-based traffic ranking TOP N uye bar chart display
● Kuongorora huwandu hwekushandiswa kweDPI: zvakaita seHTTP, QQ, FTP nedzimwe nzira dzekushandisa, huwandu hwemabyte, kugoverwa kwenhamba dzemafambiro ekutaurirana uye kuratidzwa kwechati yepie

34

Kuonekwa Kwemotokari - Kuongorora Nguva Yemotokari
Zvichienderana nemamiriro akasiyana ekusefa, akadai se IP, port, transport layer protocol, application layer protocol nezvimwe zvakatsanangurwa, data re traffic capture target capture rinogona kuongororwa uye kuratidzwa zvichienderana nenguva yesampuli, uye saizi ye traffic uye trend zvinogona kubvunzwa nekufambisa time slider uye statistical granularity scaling, uye kururama kunogona kusvika 1 millisecond.

34

Kuonekwa Kwemotokari - Kuongorora Tafura Yekuyerera
Zvichienderana nemamiriro akasiyana efirita, akadai se flow ID, IP, port, transport layer protocol, application layer protocol nezvimwe zvakatsanangurwa, data retraffic rakatorwa panguva ino rinogona kuongororwa nekuverengwa zvichienderana ne session flow mode, kureva, kuratidzwa kwakadzama kweruzivo rwe session flow, kusanganisira ruzivo rwe five-tuple rwe flow yega yega, rudzi rwe carrier application, nhamba uye bytes ye packet transmission, uye data rinobatana. Uye ine ranking display zvichibva paruzivo rwuri pamusoro. Zvichienderana neruzivo urwu, vashandisi vanogona nyore nyore kusarudza mhando dzetraffic dzavanofarira, izvo zvinopa hwaro hwakananga hwevashandisi kuti vagadzire ma traffic forwarding policies.

34

Kuonekwa Kwemotokari - Kuongorora Mapaketi
Zvichibva pane zvakasiyana-siyana zvekusefa, zvakaita sepacket ID, IP, port, transport layer protocol, application layer protocol nezvimwe zvakatsanangurwa, data re target traffic rinogona kupihwa pamwe ne presentation ye per-packet level analysis presentation, kusanganisira:
● Kuongororwa kwenguva yekuunganidza mapaketi
● Kuongorora ruzivo rwemakey packet, senge sip, dip, smac, dmac, protocol, flag, TTL, urefu hwemeseji, zviitiko zvikuru
● Kuongorora nzira yekutumirwa kwepaketi uye kuratidzwa kwemifananidzo, zvakaita se: nguva dzekutumira, kunonoka kwekutumira, rudzi rwekutumira (routing, switching, firewall, load balancing, NAT)
● Pfupiso yeruzivo rwepaketi uye kuratidzwa kwakadzama kwechimiro
● Kuongorora huwandu hwemapaketi akaunganidzwa kakawanda

34

Kuonekwa Kwemotokari - Kuongorora Mhosva Kwakarurama
Module yekuongorora kukanganisa yebasa rekuona traffic inogona kupa nzvimbo dzakasiyana dzekuongorora zvikanganiso zvekuona kune data retraffic rakatorwa, kusanganisira:
● Ongororo isina kujairika, yakadai se: mhedzisiro yekuongorora network service, mhedzisiro yekuongorora zviitiko zvisina kujairika, maitiro enetwork zvichibva pakuongorora maitiro (senge nhamba yemidziyo yekufambisa, midziyo yeNAT, midziyo yefirewall, midziyo yekuenzanisa mutoro inopfuudzwa nepaketi yekutumira)
● Kuongorora kukundikana padanho retafura yekuyerera, senge mhando dzezviitiko zvisina kujairika (kubatana kwakarambwa/kubatana kusingapinduri/kubatana kusina kutumira data/kubatana kwakavhurika hafu/nzira yechikamu isingasvikwe, nezvimwewo), ● Kuongorora kukundikana kwepaketi, senge: rudzi rwechiitiko chisina kujairika (packet checksum error /TTL 0/ unreachable error /FCS checksum error, nezvimwewo), tsananguro yakadzama yeruzivo rusina kujairika, uye ruzivo rwekuyerera kwedata kwakabatana.
● Kuongorora zvikanganiso zvekuchengetedza, zvakaita se: rudzi rwechiitiko chisina kujairika (DDOS attack/firewall blocking /ARP attack/UDP flood/SYN FLOOD, nezvimwewo), tsananguro yakadzama yeruzivo rusina kujairika, uye ruzivo rwekufamba kwedata kwakabatana narwo
● Kuongorora kukanganisa kwenetiweki, zvakaita se: rudzi rwechiitiko chisina kujairika (switching loop/routing loop/path unreachable/link interruption, nezvimwewo), tsananguro yakadzama yeruzivo rusina kujairika, uye ruzivo rwekufamba kwedata kwakabatana narwo

5-Mylinking™ Network Packet Broker pamwe neInline Bypass Switch Specifications

ML-NZVARA-M2000 Mylinking™ Network Packet Broker pamwe neInline Bypass Switch

Maitiro Ekushanda

Nzvimbo yenetiweki

Nzvimbo yemodule

Nzvimbo 4 dzeBYPASS kana MONITOR module

Huwandu hwezvinobatanidza zviri mukati

Inotsigira dziviriro yezvinongedzo zve optical zvinosvika gumi nematanhatu zve 1G/10G kana zvisongedzo zve optical zvinosvika 8 zve 40G/100G.

Monitor yekutarisa interface

Inotsigira nzvimbo dzekutarisa dzinosvika 64*1G/10GE kana nzvimbo dzekutarisa dzinosvika 16*40G/100G.

Interface yekutarisira yekunze kwebhendi

Chiteshi cheEthernet che1*10/100/1000M;

Maitiro ekutumira

Kuiswa kwemukati

Tsigiro

Kuendeswa kweSPAN

Tsigiro

Mabasa eSisitimu

Maitiro ekuisa mukati memutsara

Dziviriro chaiyo yekubatana kwemvura

Tsigiro

Dziviriro yemhando dzese dzerukova

Tsigiro

Kuenzanisa mutoro

Tsigiro

Kuonekwa kwekurova kwemoyo

Tsigiro

Kuchinja kweBYPASS

Tsigiro

Kuvharirwa kwemotokari

Tsigiro

Kuenzanisa traffic

Tsigiro

Chiremba cheSSL

Tsigiro

Maitiro ekutumira SPAN

Kugadziriswa kwetraffic yekutanga

Kuunganidzwa/kugoverwa kwemigwagwa

Tsigiro

Kuenzanisa mutoro

Tsigiro

Kusefa kwetraffic kunoenderana neIP/protocol/port 5-tuple identifier

Tsigiro

Kugadzira/kuchinja/kubvisa ma tagging eVLAN

Tsigiro

Kuisa chisimbiso chenguva

Tsigiro

Kubvisa gomba rakavharirwa mugero

Tsigiro

Kuchekwa kweData

Tsigiro

Kuzivikanwa kweProtocol yeTunneling

Tsigiro

Kukosha kwekutumira mapaketi

Tsigiro

Yambiro isina kujairika

Tsigiro

Interface inopisa yekumira

Tsigiro

Kuyerwa kwe micro-burst

Tsigiro

Dziviriro yekufamba-famba kweinterface

Tsigiro

Kuburitswa kweTunnel Encapsulation

Tsigiro

Kugumiswa kwepakeji yemugero

Tsigiro

Kugadziriswa kwetraffic yepamusoro

Kubvisa Kuvharwa kweSSL

Tsigiro

Kubviswa kwedata

Tsigiro

Kuvhara data

Tsigiro

Kuzivikanwa kweprotocol yechikamu chekushandisa

Tsigiro

Kubvisa kapisiyumu yakagadzirwa

Tsigiro

Kuumbwa kwekuyerera

Tsigiro

Kufananidza mazwi akakosha

Tsigiro

Kubvisa gomba rakavharirwa mugero

Tsigiro

Kuburitsa zvinhu kwenguva refu zvekubatanidza

Tsigiro

Kucherechedzwa kwechikamu chekuyerera

Tsigiro

Kuongorora uye kutarisa

Kutarisa panguva chaiyo

Tsigiro

Mubvunzo wezvekutenderera kwemotokari kare

Tsigiro

Kubatwa kwemotokari

Tsigiro

Kuonekwa kwekuona kwetraffic

Kuongorora Kwechokwadi

Inotsigira kuratidzwa kwehuwandu hwe ...

Kuongorora Kwakadzama kweDPI

Inotsigira kuongororwa kwehuwandu hwemaprotocol ekutakura, huwandu hweunicast, nhepfenyuro uye multicast, huwandu hweIP traffic, uye huwandu hweDPI applications. Inotsigira kuongororwa uye kuratidzwa kwedata content zvichienderana nenguva yesampuli uye huwandu hwedata. Inotsigira kuongororwa kwedata uye nhamba zvichibva pamisangano.

Kuongorora Mhosva Kwakarurama

Inotsigira kuongorora kukanganisa uye nzvimbo uchishandisa data retraffic kubva pamaonero akasiyana-siyana, anosanganisira: kuongorora maitiro ekutumira ma packet, kuongorora kukanganisa kwe data stream-level, kuongorora kukanganisa kwe data packet-level, kuongorora kukanganisa kwakabatana ne security, uye kuongorora kukanganisa kwakabatana ne network.

Kugona kugadzira

2.4Tbsp

Gadzirisa

Kutarisira Network yeCONSOLE

Tsigiro

Kutarisira Network yeIP/WEB

Tsigiro

Kutarisira network yeSNMP

Tsigiro

Kutarisira network yeTELNET/SSH

Tsigiro

Nzira yeSYSLOG

Tsigiro

Kusimbiswa kwemvumo yeRADIUS kana TADACS+ pakati

Tsigiro

Basa rekusimbisa mushandisi

Zita rekushandisa uye password yekusimbisa

Magetsi

Rated simba remagetsi magetsi

AC-220V/DC-48V [Sarudzo]

Rated simba frequency

AC-50HZ

Rated input current

AC-3A / DC-10A

Simba rinoshanda rakaongororwa

300W yepamusoro

Zvakatipoteredza

Tembiricha yekushanda

0-50

Tembiricha yekuchengetedza

-20-70℃

Hunyoro hwekushanda

10% -95%, isingapindi mvura

Kugadziriswa kweMushandisi

Kugadziriswa kweConsole

RS232 interface, 115200, 8, N, 1

Kusimbiswa kwepassword

Srutsigiro

Saizi yeRaki

Nzvimbo yeraki (U)

2U 444mm*88mm*670mm

 

6-Mylinking™ Network Packet Broker pamwe neInline Bypass Switch Application

6.1IyoRisk ofMutsetse SkuchengetedzwaEzvishandiso (IPS / FW)

Inotevera ndiyo nzira yakajairika yeIPS (Intrusion Prevention System), FW (Firewall) deployment mode, IPS / FW inoiswa muzvikamu zvakatevedzana kune network midziyo (routers, switches, nezvimwewo) pakati petraffic kuburikidza nekuita security checks, zvichienderana nemutemo wekuchengetedza unoenderana kuti uone kuburitswa kana kuvharwa kwetraffic inoenderana, kuti uwane simba rekudzivirira kuchengetedza.

36

Inotevera ndiyo nzira yakajairika yeIPS (Intrusion Prevention System), FW (Firewall) deployment mode, IPS / FW inoiswa muzvikamu zvakatevedzana kune network midziyo (routers, switches, nezvimwewo) pakati petraffic kuburikidza nekuita security checks, zvichienderana nemutemo wekuchengetedza unoenderana kuti uone kuburitswa kana kuvharwa kwetraffic inoenderana, kuti uwane simba rekudzivirira kuchengetedza.

6.2 Dziviriro yeMidziyo yeInline Link Series

Kuchengetedzwa Kwemumugwagwa Kudzivirirwa Kwemotokari

Mylinking™ Network Packet Broker pamwe neInline Bypass Switch zvinoiswa munhevedzano pakati pemidziyo yenetwork (routers, switches, nezvimwewo), uye kufamba kwedata pakati pemidziyo yenetwork hakuchatungamiri zvakananga kuIPS / FW, "Smart Inline Bypass Switch" kuenda kuIPS / FW, apo IPS / FW nekuda kwekuwanda, kuparara, software updates, policy updates nezvimwe zvinhu zvekukundikana, "Smart Inline Bypass Switch" kuburikidza ne intelligent heartbeat message detection Function ye timetime discovery, uye nokudaro skip the error device, pasina kukanganisa preference yenetwork, rapid network midziyo yakabatana zvakananga kuchengetedza normal communication network; apo IPS / FW failure recovery, asiwo kuburikidza ne intelligent heartbeat packets Kuona kuonekwa kwebasa nenguva, link yekutanga yekudzoreredza kuchengetedzeka kwe enterprise network security checks.

Mylinking™ Network Packet Broker pamwe neInline Bypass Switch ine simba rakangwara rekuona meseji yemoyo, mushandisi anogona kugadzirisa nguva yemoyo uye huwandu hwakanyanya hwekuyedza, kuburikidza nemeseji yemoyo yakagadzirwa paIPS / FW yekuyedzwa kwehutano, senge kutumira meseji yekutarisa moyo kuchiteshi chepamusoro / pasi peIPS / FW, uye wobva wagamuchira kubva kuchiteshi chepamusoro / pasi peIPS / FW, uye kutonga kana IPS / FW iri kushanda zvakanaka nekutumira nekugamuchira meseji yemoyo.

6.3 "SpecFlow" Mutemo weKuyerera MukatiKuchengetedzwaDziviriro yeNhevedzano

Dziviriro Yakanangana Yemumugwagwa

Kana mudziyo wekuchengetedza network uchingoda chete kugadzirisa traffic chaiyo mu series security protection, kuburikidza neMylinking™ Network Packet Broker pamwe neInline Bypass Switch traffic per-processing function, kuburikidza nemutemo wekutarisa traffic kuti ubatanidze mudziyo wekuchengetedza inline "Concerned" traffic inodzoserwa zvakananga kune network link, uye "chikamu chetraffic chine chekuita" chiri kubata mudziyo wekuchengetedza in-line kuti uite security checks. Izvi hazvingogumiri pakuchengetedza security detection function yemuchina wekuchengetedza, asiwo zvinoderedza kufamba kusina kunaka kwemuchina wekuchengetedza kuti ubate pressure; panguva imwe chete, "Smart Inline Bypass Switch" inogona kuona mashandiro emuchina wekuchengetedza munguva chaiyo. Mudziyo wekuchengetedza unoshanda zvisina kujairika unopfuura data traffic zvakananga kudzivirira kukanganisa network service.

Mylinking™ Network Packet Broker pamwe neInline Bypass Switch inogona kuona traffic zvichibva pane L2-L4 layer header identifier, senge VLAN tag, source/destination MAC address, source IP address, IP packet type, transport layer protocol port, protocol header key tag, nezvimwewo. Mamiriro akasiyana-siyana ekufananidza anogona kutsanangurwa nenzira inochinjika kuti atsanangure mhando dzetraffic dzinofarirwa nemudziyo wekuchengetedza uye dzinogona kushandiswa zvakanyanya pakuisa zvishandiso zvekuongorora zvekuchengetedza (RDP, SSH, database auditing, nezvimwewo).

6.4Load yakaenzanaKuchengetedzwa KwakabatanaDziviriro yeNhevedzano

Dziviriro yeInline Security Series yakaringana

Mylinking™ Network Packet Broker pamwe neInline Bypass Switch inoiswa munhevedzano pakati pemidziyo yenetwork (routers, switches, nezvimwewo). Kana mashandiro ekugadzirisa eIPS / FW imwe chete asingakwani kugadzirisa traffic yenetwork link peak, basa rekuchengetedza traffic load, "bundling" ye IPS / FW cluster processing network link traffic yakawanda, rinogona kuderedza zvinobudirira IPS / FW processing pressure imwe chete, kuvandudza mashandiro ekugadzirisa ese kuti asangane nebandwidth yakakwira yenzvimbo yedeployment.

Mylinking™ Network Packet Broker pamwe neInline Bypass Switch ine basa rakasimba rekuenzanisa mutoro, zvichienderana ne frame VLAN tag, MAC information, IP information, port number, protocol uye rumwe ruzivo pamusoro pekugoverwa kweHash load balancing kwetraffic kuve nechokwadi chekuti IPS / FW yega yega yakagamuchira data flow Session integrity.

6.5Nhepfenyuro dzakawandaMidziyo iri mukati FyakadereraTkupatsanuranaPkudzivirira(ChinjoZvepanyamaKubatana kweSerial kuZvine musoroKubatana Kwakafanana)

Mune mamwe malink akakosha (akadai seInternet outlets, server area exchange link) nzvimbo inowanzo kuve nekuda kwezvinodiwa zvekuchengetedza uye kuiswa kwemidziyo yakawanda yekuongorora kuchengetedza iri mu-line (yakadai sefirewall, anti-DDOS attack equipment, WEB application firewall, intrusion prevention Equipment, nezvimwewo), michina yakawanda yekuona kuchengetedza panguva imwe chete mumutsara pane link kuti iwedzere link yepoindi imwe chete yekukundikana, zvichideredza kuvimbika kwenetwork. Uye mukushandiswa kwemidziyo yekuchengetedza yataurwa pamusoro apa, kuvandudzwa kwemidziyo, kutsiva michina nezvimwe, zvichaita kuti network ikanganiswe kwenguva yakareba uye chirongwa chikuru chidzivise kuita mapurojekiti akadaro.

Nekushandisa Mylinking™ Network Packet Broker pamwe neInline Bypass Switch nenzira yakabatana, nzira yekuisa zvishandiso zvakawanda zvekuchengetedza zvakabatana mumutsara pane imwe link inogona kuchinjwa kubva ku "Physical Serial Connection Mode" kuenda ku "Physical Parallel Connection asi Logical Serial Connection Mode". Izvi zvinoderedza zvinokonzeresa kukundikana kwechinhu chimwe chete pane imwe link uye zvinovandudza kuvimbika kwe link. Panguva imwe chete, Mylinking™ Network Packet Broker pamwe neInline Bypass Switch zvinogona kutungamira traffic traffic pazvinodiwa, zvichiita kuti traffic security processing effect ive yakafanana nepakutanga serial connection mode.

Zvishandiso zvinopfuura chimwe chete zveInline Security panguva imwe chete mudhayagiramu yekuiswa kweseji:

37

Mylinking™ Network Packet Broker pamwe neInline Bypass Switch Deployment Diagram:

(Chinja Pysical Serial Connection kuita Logical Parallel Connection)

Kushandiswa kweInline Bypass Security

6.6Zvichibva paneDMutemo we synamic weTraffic InlineSkuchengetedzwaDkubatwaPkudzivirira

Mylinking™ Network Packet Broker pamwe neInline Bypass Switch, imwe nzira yepamusoro yekushandisa yakavakirwa pamutemo wekuchengetedza traffic traction, kushandiswa kwenzira iyi sezvakaratidzwa pazasi:

Mutemo Unochinja-chinja weDziviriro Yekuona Kuchengetedzwa Kwemumugwagwa

Tora michina yekuongorora kuchengetedzwa ye "Anti-DDoS attack protection and detection", semuenzaniso, kuburikidza nekushandiswa kwe "Smart Bypass Switch" uye anti-DDOS protection equipment wozobatanidzwa ku "Smart Bypass Switch", mu "Smart Bypass Switch" yenguva dzose kusvika pahuwandu hwakazara hwe traffic wire-speed forwarding panguva imwe chete iyo flow mirror output kuenda ku "Anti-DDOS attack protection device", kana yaonekwa kune server IP (kana IP network segment) mushure mekurwiswa, "Anti-DDOS attack protection device" ichagadzira mitemo inoenderana ne traffic flow uye ichaitumira ku "Smart Bypass Switch" kuburikidza ne dynamic policy delivery interface. "Bypass Switch" inogona kugadzirisa "traffic traction dynamic" mushure mekugamuchira dynamic policy rule pool "uye pakarepo" rule yakarova attack server traffic "traction to the" anti-DDoS attack protection and detection equipment "yekugadzirisa, kuti ishande mushure mekurwiswa uye yozopinzwazve mu network.

Chirongwa chekushandisa chakavakirwa pa "Smart Bypass Switch" chiri nyore kushandisa pane chirongwa chekare cheBGP route injection kana chimwe chirongwa chetrack traction, uye nharaunda hainyanyi kutsamira pane network uye kuvimbika kwacho kwakanyanya.

"Smart Bypass Switch" ine hunhu hunotevera hunotsigira dziviriro yekuchengetedzwa kwekuchengetedza kwemaitiro anochinja-chinja:

1. "Smart Bypass Switch" kupa kunze kwemitemo yakavakirwa paWEBSERIVCE interface, zviri nyore kubatanidzwa nemidziyo yekuchengetedza yevamwe.

2. "Smart Bypass Switch" zvichibva pa "hardware pure ASIC chip" inotumira mafaira kusvika pa100Gbps wire-speed packets pasina kuvharira switch forwarding, uye "traffic traction dynamic rule library" zvisinei nenhamba.

3. "Smart Bypass Switch" yakavakirwa mukati me "Smart Bypass Switch", kunyangwe kana chidziviriro chacho chikatadza, chinogonawo kunzvenga serial link yekutanga nekukasika, hachikanganisi link yekutanga yekutaurirana kwakajairika.

6.7Kuenzanisa Kwemotokari Mumutsetseyekuchengetedzwa kwekunze kwebhendi (Inline + SPAN)

Mylinking™ Network Packet Broker pamwe neInline Bypass Switch zvinowanzoiswa muIT network yemutengi kana cloud platform network kuti dziviriro yeWAF/IPS devices ne original link. Vashandisi vanogonawo kunge vaine zvimwe zvinodiwa pakuedza, kusimbisa, kana kuisa bypass monitoring devices, zvichiita kuti pave neruzivo rwetraffic pane iyi link.

Saka, uchishandisa basa rekutarisa traffic reMylinking™ Network Packet Broker pamwe neInline Bypass Switch, traffic yeinline serial link inogona kuratidzwa kubva pamonitor port, sezvakaratidzwa mumufananidzo unotevera:

Kushandiswa kweInline plus SPAN

Dhayagiramu iri pazasi inoratidza mamiriro ekushandiswa kwenguva refu kwetraffic ye inline link uye traffic ye switch mirrored port. Izvi zvinobvumira kuchengetedzwa kwetraffic ye inline link pasina kukanganiswa ne switch mirrored port traffic. Sisitimu yekuongorora IDS inogona kuwana panguva imwe chete traffic ye inline link uye traffic ye switch mirrored port traffic. Nzira yekuendesa inoratidzwa mudhayagiramu iri pazasi:

Kushandiswa kweInline plus SPAN-1

6.8Kubvisa Data/PacketKushandiswa

Kubviswa kweData Packet

Sezvakaratidzwa muchimiro chekuiswa kweapplication pamusoro apa, kuti kuve nechokwadi chekuti data rekutanga raunganidzwa zvakanaka pamwe chete nelink yese, mamwe mapaketi edata akafanana anogona kuunganidzwa kakawanda mukati menzira imwe chete. Izvi zvinotungamira kuwedzera kwekunyepedzera kwenhema uye kudzoserwa kwedata mu backend system, zvichiwedzera mashandiro ehurongwa hwekuongorora uye zvichikanganisa kururama uye kushanda kwekuongorora. Zvichibva pamhinduro, chekutanga, mapaketi edata akafanana anotorwa muma node akasiyana ekutora. Paketi imwe chete yedata inotumirwa ku backend NPM network performance analysis system uye APM application performance analysis system, nokudaro ichichengetedza mashandiro ehurongwa hwekuongorora uye kuvandudza kushanda uye kururama kwekuongorora.

6.9Data/PaketiVLAN TaggingKushandiswa

Kuisa Mazita Paketi yeData

Munzvimbo yenetwork inoratidzwa mudhayagiramu iri pamusoro, mhinduro inoshandiswa kuisa label data raw kubva kumidziyo yakasiyana yenetwork uye ma link nodes. Kana traffic isina kujairika kana mapaketi edata akaitika munetwork, michina yekuongorora backend inogona kuwana nekukurumidza uye nemazvo kwakabva data risingajairiki nekutsvaga data zvichibva pane labels dzedata.

6.10 Kufamba KwenetiwekiPurogiramu YakabatanaKushandiswa

Purogiramu Yakabatana Yetraffic

Munzvimbo yenetwork inoratidzwa padhayagiramu iri pamusoro, data re 10GE, 25GE, 40GE uye 100GE source link rinoiswa zvizere muMylinking™ Network Packet Broker pamwe neInline Bypass Switch uchishandisa optical splitting kana port mirror. Zvadaro, filtering uye traffic splitting zvinoshandiswa kuburitsa data reservice traffic yakasiyana kune akasiyana backend out-of-band network monitoring uye security system devices. Kana network packet anomalies kana traffic changes zvisingawanzoitiki zvinoda kupindira nemaoko, kutora uye kuongorora mapaketi epakutanga panguva chaiyo kunogona kuitwa nekukasika kuti vabatsire vashandisi kuongorora nekukurumidza uye kuwana dambudziko.

6.11NetworkKuongorora Kuonekwa Kwedata RemotaKushandiswa

Kuongorora Kuonekwa Kwedata Remumugwagwa weNetwork

Inogona kuratidza chero data rakawanikwa uye rakatorwa nenzira ine mativi akawanda uye ine maonero akawanda kuburikidza ne graphic uye text interactive interface iri nyore kushandisa, kusanganisira chimiro che traffic composition, application protocol distribution, traffic distribution ye network nodes dzese, nzira yekutumira data, kuona zviitiko zvisina kujairika, nzvimbo chaiyo ye network element/link faults, mamiriro ekutaurirana kwemashoko, traffic development trend nezvimwe zvinhu zvekutarisa nekuongorora, kuitira kuti pave nepuratifomu yakazara, inoonekwa uye inodzoreka yekuunganidza data uye yekuchengetedza network dzemabhizinesi.


  • Yakapfuura:
  • Zvinotevera:

  • Nyora meseji yako pano woitumira kwatiri