Chii chinonzi Bypass basa reNetwork Security Device?

Chii chinonzi Bypass?

Iyo Network Security Equipment inowanzoshandiswa pakati pematanho maviri kana anopfuura, senge pakati pemukati network nekunze network. The Network Security Equipment kubudikidza nomumbure packet ongororo, kuona kana pane kutyisidzira, pashure kugadziridzwa maererano mamwe routing mitemo mberi packet kubuda, uye kana network kuchengeteka midziyo malfunctioned, Somuenzaniso, pashure simba kukundikana kana tsaona. , zvikamu zvetiweki zvakabatana kune mudziyo zvakabviswa kubva kune mumwe nemumwe. Muchiitiko ichi, kana imwe neimwe network inoda kubatanidzwa, ipapo Bypass inofanira kuonekwa.

Basa reBypass, sezvinoreva zita, rinogonesa ma network maviri kubatanidza pasina kupfuura nehurongwa hwetiweki yekuchengetedza mudziyo kuburikidza neimwe nzira inokonzeresa (simba kutadza kana kuparara). Naizvozvo, kana network yekuchengetedza mudziyo ikatadza, network yakabatana neiyo Bypass mudziyo inogona kutaurirana. Ehe, mudziyo wetiweki haugadziri mapaketi pane network.

pasina kukanganisa network

Nzira yekuisa sei iyo Bypass Application Mode?

Bypass yakakamurwa kuita control or trigger modes, ari anotevera
1. Yakakonzerwa nemagetsi. Mune iyi modhi, iyo Bypass basa inogonesa kana mudziyo wadzima. Kana mudziyo ukabatidzwa, basa reBypass richadzimwa nekukasira.
2. Inodzorwa neGPIO. Mushure mekupinda muOS, unogona kushandisa GPIO kushanda chaiyo madoko kudzora Bypass switch.
3. Kudzorwa neWatchdog. Uku ndiko kuwedzera kwemaitiro 2. Unogona kushandisa Watchdog kudzora kugonesa uye kudzima chirongwa cheGPIO Bypass kudzora mamiriro eBypass. Nenzira iyi, kana chikuva ichiputsika, iyo Bypass inogona kuvhurwa neWatchdog.
Mumashandisirwo anoshanda, idzi nhatu dzinogara dziripo panguva imwe chete, kunyanya maviri modes 1 uye 2. Iyo yakawanda yekushandisa nzira ndeye: kana mudziyo wakadzimwa, iyo Bypass inogoneswa. Mushure mekunge mudziyo wabatidzwa, iyo Bypass inogoneswa neBIOS. Mushure mekunge BIOS yatora mudziyo, iyo Bypass ichiri kugoneswa. Dzima Bypass kuti application ishande. Munguva yese yekutanga maitiro, pane kanenge pasina network kubviswa.

Kuona kurova kwemoyo

Chii chinonzi Principle yeBypass kuita?

1. Hardware Level
Payero yehardware, relays inonyanya kushandiswa kuwana Bypass. Aya mareyi akabatanidzwa kune masaini tambo dzeBypass network ports. Mufananidzo unotevera unoratidza maitiro ekushanda kweiyo relay uchishandisa imwe chiratidzo tambo.
Tora mutsara wemagetsi semuenzaniso. Panyaya yekutadza kwemagetsi, switch mune relay inosvetukira kunharaunda ye1, ndiko kuti, Rx paRJ45 interface yeLAN1 ichabatana zvakananga kuRJ45 Tx yeLAN2, uye kana mudziyo uchinge wabatidzwa, switch inozoita. batanidza ku 2. Nenzira iyi, kana kutaurirana kwetiweki pakati peLAN1 neLAN2 kuchidiwa, Unoda kuita izvozvo kuburikidza nechikumbiro pachigadzirwa.
2. Software Level
Muchikamu cheBypass, GPIO uye Watchdog dzinotaurwa kudzora uye kukonzeresa Bypass. Muchokwadi, mbiri idzi nzira mbiri dzinoshanda iyo GPIO, uye ipapo GPIO inodzora relay pane Hardware kuita kusvetukira kunoenderana. Kunyanya, kana iyo inoenderana GPIO yakaiswa padanho repamusoro, relay inosvetuka kuenda kunzvimbo 1 zvinoenderana, nepo kana mukombe weGPIO ukaiswa padanho rakaderera, relay inosvetuka kuenda pachinzvimbo 2 zvinoenderana.

YeWatchdog Bypass, inowedzerwa chaizvo Watchdog control Bypass pahwaro hweGPIO kutonga pamusoro. Mushure mekunge watchdog yatanga kushanda, isa chiito chekupfuura paBIOS. Iyo sisitimu inomutsa iyo watchdog basa. Mushure mekunge iyo watchdog yatanga kushanda, iyo inoenderana netiweki port bypass inogoneswa uye mudziyo unopinda mu bypass state. Kutaura zvazviri, Bypass inodzorwawo neGPIO, asi munyaya iyi, kunyorwa kwemazinga akaderera kuGPIO kunoitwa neWatchdog, uye hapana purogiramu yakawedzerwa inodiwa kunyora GPIO.

Iyo Hardware Bypass basa ibasa rinosungirwa retiweki kuchengetedza zvigadzirwa. Kana mudziyo uchinge wadzimwa kana kupunzika, zviteshi zvemukati nekunze zvinobatanidzwa kuti zvigadzire tambo yetiweki. Nenzira iyi, data traffic inogona kupfuudza zvakananga kuburikidza nemudziyo pasina kukanganiswa nemamiriro azvino echishandiso.

Kuwanikwa Kwepamusoro (HA) Kushandisa:

Mylinking™ inopa maviri ekuwanikwa kwepamusoro (HA) mhinduro, Active/Standby uye Active/Active. Iyo Active Standby (kana inoshanda / passive) kuendesa kune ebetsero maturusi kupa failover kubva yekutanga kuenda kune backup zvishandiso. Uye iyo Inoshanda / Inoshanda Yakaiswa kune yakawandisa malink kuti ipe failover kana chero Active mudziyo watadza.

HA1

Mylinking™ Bypass TAP inotsigira maturusi maviri akawandisa inline, anogona kuiswa muActive/Standby mhinduro. Imwe inoshanda seyekutanga kana "Active" mudziyo. Iyo Standby kana "Passive" mudziyo uchiri kugamuchira chaiyo-nguva traffic kuburikidza neBypass nhevedzano asi haina kutorwa sechinhu chiri mukati. Izvi zvinopa "Hot Standby" redundancy. Kana chishandiso chikatadza kushanda uye iyo Bypass TAP ikamira kugashira kurova kwemoyo, mudziyo wekumira unotora otomatiki semudziyo wekutanga uye wouya online nekukurumidza.

HA2

Ndezvipi Zvakanakira iwe zvaunogona kuwana zvichibva pane yedu Bypass?

1-Govera traffic pamberi uye mushure meiyo inline chishandiso (senge WAF, NGFW, kana IPS) kune kunze-kwe-bhendi chishandiso.
2-Kubata akawanda inline maturusi panguva imwe chete inorerutsa chengetedzo stack uye inoderedza network kuoma.
3-Inopa kusefa, kuunganidza, uye kuyera kuyera kune inline link
4-Deredzai njodzi yenguva isina kurongeka
5-Kukundikana, kuwanikwa kwakanyanya [HA]


Nguva yekutumira: Zvita-23-2021