1- Yintoni i-Define Heartbeat Packet?
Iipakethi zokubetha kwentliziyo yeMylinking™ Network Tap Bypass Tshintsha okuhlala kukho kwi-Ethernet Layer 2 izakhelo. Xa kufakwa imo yokuvala i-transparent Layer 2 (efana ne-IPS / FW), iifreyimu zeLayer 2 Ethernet zidla ngokugqithiswa, zivalwe okanye zilahlwe. Kwangaxeshanye, iMylinking™ Network Tap Bypass Switch ixhasa ifomati yomyalezo wokubetha kwentliziyo ukuze ihlangabezane nemeko yokuba ezinye izixhobo ezikhethekileyo zokhuseleko azinakukwazi ukudlulisa izakhelo eziqhelekileyo zeLayer 2 Ethernet.
Kwaye iMylinking™ Network Tap Bypass Switch ikwaxhasa ukufunyanwa kwepakethe yokubetha kwentliziyo esekwe kwithegi yeVLAN, iLayer 3 kunye neLayer 4 yeentlobo zemiyalezo yesiko. Ngokusekwe kolu matshini, umsebenzisi unokuphumeza umsebenzi wovavanyo lokhuseleko lwenkonzo yesixhobo sokhuseleko soqhagamshelo ukuze sisebenze ngakumbi ukuqinisekisa ukuba iinkonzo zokhuseleko ezihambelanayo zisebenza ngokufanelekileyo.
I-Mylinking™ Network Tap Bypass Switch inokuxhasa imonitha ukuthumela iipakethi zokubetha kwentliziyo kumacala omabini. Ngokomzekelo, iipakethi ze-TCP kunye ne-UDP zohlobo lwe-heartbeat zenziwe ngokwezifiso kwi-"Strategy Traffic Traction Protector", ngokweenkcukacha zesixhobo se-serial. Ungaqwalasela ukuthunyelwa kweepakethi zokubetha kwentliziyo ye-TCP kwi-uplink monitor A izibuko kunye nokuthunyelwa kweepakethe ze-UDP zokubetha kwentliziyo kwi-downlink monitor B port ukulungiselela indlela yogqithiso lomyalezo wesixhobo sothotho sokhuseleko. Lo msebenzi unokuqinisekisa ngokusebenzayo ngakumbi umtya. Xhuma izixhobo zokhuseleko ekusebenzeni okuqhelekileyo.
I-Mylinking™ Network Inline Bypass Switch iphandiwe kwaye iphuhliswe ukuba isetyenziselwe ukuhanjiswa okubhetyebhetye kweentlobo ngeentlobo zezixhobo zokhuseleko ngelixa ibonelela ngokuthembeka okuphezulu kwenethiwekhi.
I-2-Network Inline Bypass Tshintsha iiNkalo eziPhezulu kunye neeTekhnoloji
I-Mylinking™ "SpecFlow" iModi yoKhuselo kunye neTekhnoloji yeModi yoKhuselo "iFullLink".
I-Mylinking™ iFast Bypass yokuTshintsha iTekhnoloji yoKhuseleko
ITekhnoloji yeMylinking™ “LinkSafeSwitch”
I-Mylinking™ “i-WebService” ye-Dynamic Strategy Forwarding/Issue Technology
ITekhnoloji yokuFumana iTekhnoloji yeMylinking ™ yokuBetha kwentliziyo ekrelekrele
ITekhnoloji yeTekhnoloji yeMylinking ™ yokuBetha kwentliziyo echazwayo
I-Mylinking™ iTekhnoloji yokuNxulumanisa iMithetho emininzi yokuLawulwa
I-Mylinking™ iTekhnoloji yoSasazo lweZithuthi ezikrelekrele
I-Mylinking™ iTekhnoloji yokuHlalanisa uMlayisho oDynamic
ITekhnoloji yoLawulo lweRemote ye-Mylinking™(HTTP/WEB, TELNET/SSH, “EasyConfig/AdvanceConfig” Iimpawu)
I-3-Network Inline Bypass Switch Application (njengoko kulandelayo)
3.1 UMngcipheko weSixhobo soKhuseleko olukwi-Inline (IPS / FW)
Oku kulandelayo yi-IPS eqhelekileyo (i-Intrusion Prevention System), i-FW (Firewall) imodi yokuthunyelwa, i-IPS / FW isetyenziswe ngokulandelelana kwisixhobo sothungelwano (i-routers, switch, njl.) umgaqo-nkqubo wokhuseleko ohambelanayo wokumisela ukukhululwa okanye ukuvimba i-traffic ehambelanayo, ukufezekisa umphumo wokukhusela ukhuseleko.
Kwangaxeshanye, sinokujonga i-IPS / FW njengokuthunyelwa kweserial kwezixhobo, ngokuqhelekileyo zibekwe kwindawo ephambili yothungelwano lweshishini ukuphumeza ukhuseleko lwe-serial, ukuthembeka kwezixhobo zayo eziqhagamshelweyo kuchaphazela ngqo ukufumaneka kwenethiwekhi yeshishini ngokubanzi. Nje ukuba izixhobo ze-serial zigcwele, ukuphazamiseka, uhlaziyo lwesoftware, uhlaziyo lomgaqo-nkqubo, njl. njl., ukufumaneka kwenethiwekhi yeshishini lonke kuya kuchaphazeleka kakhulu. Kweli nqanaba, thina kuphela ngokusikwa kwenethiwekhi, i-jumper ye-bypass ebonakalayo inokwenza inethiwekhi ibuyiselwe, ichaphazela kakhulu ukuthembeka kwenethiwekhi. I-IPS / FW kunye nezinye izixhobo ze-serial kwelinye icala ziphucula ukuthunyelwa kokhuseleko lwenethiwekhi yeshishini, kwelinye icala kunciphisa ukuthembeka kothungelwano lwamashishini, ukwandisa umngcipheko womnatha awufumaneki.
3.2 I-Inline Link Series yoKhuselo lweZixhobo
I-Mylinking™ "I-Network Inline Bypass" ibekwe kuthotho phakathi kwezixhobo zenethiwekhi (iirutha, iiswitshi, njl. njl.), kunye nokuhamba kwedatha phakathi kwezixhobo zenethiwekhi akusakhokeleli ngqo kwi-IPS / FW, "I-Network Inline Bypass" ukuya kwi-IPS / FW, xa IPS / FW ngenxa yokugcwala, ukungqubana, uhlaziyo lwesoftware, uhlaziyo lomgaqo-nkqubo kunye nezinye iimeko zokusilela, “iNetwork Inline Bypass” ngokubhaqwa komyalezo wokubetha kwentliziyo ukufunyanwa kwangexesha, kwaye ngaloo ndlela utsibe isixhobo esingalunganga, ngaphandle kokuphazamisa isiseko sothungelwano, izixhobo zenethiwekhi ezikhawulezayo eziqhagamshelwe ngokuthe ngqo ukukhusela unxibelelwano oluqhelekileyo lonxibelelwano; xa IPS / FW ukusilela ukubuyiswa, kodwa ngokusebenzisa iipakethi ezikrelekrele ukubetha kwentliziyo Ukufunyanwa ukubhaqwa kwangethuba umsebenzi, ikhonkco yokuqala ukubuyisela ukhuseleko iitshekhi wokhuseleko womnatha ishishini.
I-Mylinking™ "I-Network Inline Bypass" inomsebenzi onamandla wokuqonda ukubetha kwentliziyo, umsebenzisi unokwenza ngokwezifiso ukubetha kwentliziyo kunye nenani eliphezulu lokuzama kwakhona, ngomyalezo oqhelekileyo wokubetha kwentliziyo kwi-IPS / FW yovavanyo lwezempilo, njengokuthumela ukubetha kwentliziyo. umyalezo ukuya phezulu / ezantsi izibuko IPS / FW, kwaye emva koko ufumane ukusuka phezulu / ezantsi izibuko IPS / FW, kwaye ugwebe ukuba IPS / FW iyasebenza ngokwesiqhelo ngokuthumela nokufumana umyalezo wokubetha kwentliziyo.
3.3 “SpecFlow” Policy Flow Inline Traction Series Protection
Xa isixhobo sothungelwano sokhuseleko sidinga kuphela ukujongana netrafikhi ethile kuthotho lokhuseleko lokhuseleko, ngeMylinking™ ” Network Inline Bypass ” traffic per-processing function, ngokusebenzisa isicwangciso sokuhlola itrafikhi ukuqhagamshela isixhobo sokhuseleko ngqo kwikhonkco lothungelwano, kwaye” icandelo lezithuthi ezichaphazelekayo “kukutsalela kwisixhobo sokhuseleko esise-intanethi ukwenza uhlolo lokhuseleko. Oku akuyi kugcina kuphela ukusetyenziswa okuqhelekileyo komsebenzi wokukhangela ukhuseleko lwesixhobo sokukhusela, kodwa nokunciphisa ukuhamba okungahambi kakuhle kwezixhobo zokukhusela ukujongana noxinzelelo; ngelo xesha, i "Network Inline Bypass" inokubona imeko yokusebenza yesixhobo sokhuseleko ngexesha langempela. Isixhobo sokhuseleko sisebenza ngendlela engaqhelekanga sidlula ngokuthe ngqo ukugcwala kwedatha ukunqanda ukuphazamiseka kwenkonzo yenethiwekhi.
3.4 Layisha iBalanced Series Protection
I-Mylinking™ “I-Network Inline Bypass ” ibekwe kuthotho phakathi kwezixhobo zenethiwekhi (iirutha, iiswitshi, njl. njl.). Xa ukusebenza kwe-IPS / FW enye kunganelanga ukujongana nencopho yonxibelelwano lwetrafikhi, Umsebenzi wokulinganisa umthwalo wetrafikhi womkhuseli, "ukuhlanganisana" kweqela le-IPS / FW leqela lokucwangcisa ikhonkco lonxibelelwano lwenethiwekhi, kunokunciphisa ngokufanelekileyo i-IPS enye / Uxinzelelo lwe-FW processing, ukuphucula ukusebenza ngokubanzi kokusebenza ukuhlangabezana ne-bandwidth ephezulu yendawo yokuthunyelwa kweBango.
I-Mylinking™ "I-Network Inline Bypass" inomsebenzi onamandla wokulinganisa umthwalo, ngokuhambelana nethegi ye-VLAN yesakhelo, ulwazi lwe-MAC, ulwazi lwe-IP, inombolo yesibuko, iprotocol kunye nolunye ulwazi kwi-Hash load balancing distribution of traffic ukuqinisekisa ukuba i-IPS / FW nganye ifunyenwe. ukuhamba kwedatha Ingqibelelo yeseshoni.
3.5 IsiXhobo esiSetyenziswayo seMilayini yoKhuseleko lokuHamba okuHamba (Tshintsha uQhagamshelwano lothotho ukuya kuQhagamshelwano oluFanayo)
Kwezinye iziqhagamshelo ezingundoqo (ezifana ne-intanethi, i-server yendawo yekhonkco yokutshintshiselana) indawo ihlala ibangelwa kwiimfuno zeempawu zokhuseleko kunye nokuthunyelwa kwezixhobo ezininzi zokuvavanya ukhuseleko kwi-line (ezifana ne-firewall, izixhobo zokuhlaselwa kwe-DDOS, i-WEB application firewall. , Izixhobo zokuthintela ukungena, njl.), izixhobo ezininzi zokufumanisa ukhuseleko ngexesha elifanayo kwi-series kwikhonkco ukunyusa ikhonkco lenqaku elilodwa lokungaphumeleli, ukunciphisa ukuthembeka okupheleleyo kwenethiwekhi. Kwaye kwizixhobo zokhuseleko ezikhankanywe ngasentla kwi-intanethi, ukuphuculwa kwezixhobo, ukutshintshwa kwezixhobo kunye neminye imisebenzi, kuya kubangela uthungelwano ixesha elide lokuphazamiseka kwenkonzo kunye neprojekthi enkulu yokusika isenzo ukugqiba ukuphunyezwa ngempumelelo kweeprojekthi ezinjalo.
Ngokuhambisa "i-Network Inline Bypass" ngendlela edibeneyo, indlela yokuthunyelwa kwezixhobo ezininzi zokhuseleko ezidityaniswe kuluhlu kwikhonkco elifanayo linokutshintshwa ukusuka "kwindlela yokudibanisa ngokomzimba" ukuya "kwindlela yokudibanisa ngokomzimba, imo yokudibanisa enengqiqo" Ikhonkco kwikhonkco. kwindawo enye yokungaphumeleli ekuphuculeni ukuthembeka kwekhonkco, ngelixa "i-Network Inline Bypass" kwi-link flowing on demand traction, ukufezekisa ukuhamba okufanayo kunye neyokuqala. Imowudi yesiphumo esikhuselekileyo sokucubungula.
Ngaphezulu kwesixhobo esinye sokhuseleko ngexesha elinye kwidayagram yokusasazwa kothotho:
ISazobe sokusasazwa kweNethiwekhi ye-Bypass:
3.6 Ngokusekelwe kwiQhinga eliDynamic loKhuseleko loKhuseleko lweTraffic Traffic Traction
"I-Network Inline Bypass" Enye imeko yesicelo esiphezulu isekelwe kwiqhinga eliguqukayo le-traffic traction yokhuseleko lwezicelo zokukhusela ukhuseleko, ukuthunyelwa kwendlela njengoko kuboniswe ngezantsi:
Thatha "i-Anti-DDoS yokukhusela uhlaselo kunye nokubhaqwa" izixhobo zovavanyo zokhuseleko, umzekelo, ngokubekwa kwangaphambili kwe "Network Inline Bypass" emva koko izixhobo zokukhusela iDDOS emva koko ziqhagamshelwe kwi "Network Inline Bypass", kwindawo eqhelekileyo ” Umkhuseli wokutsalwa “kwisixa esipheleleyo sokuhanjiswa kwesantya socingo lwetrafikhi ngaxeshanye isibuko sokuphuma sisiya kwisixhobo sokhuselo sokuhlasela se-anti-DDOS “, xa sifunyenwe kwiseva ye-IP (okanye i-IP icandelo lomnatha) emva kohlaselo,” isixhobo sokukhusela i-anti-DDOS ” siya kuvelisa imigaqo ehambelana nokuhamba kwetrafikhi ekujoliswe kuyo kwaye iyithumele “kwi-Network Inline Bypass” ngojongano lomgaqo-nkqubo onamandla. I "Network Inline Bypass" inokuhlaziya "i-traffic traction dynamic" emva kokufumana imigaqo-nkqubo eguquguqukayo yomgaqo-nkqubo Umgaqo "kwaye ngokukhawuleza" umgaqo ubethe i-traffic server yokuhlaselwa "ukutsalwa kwe-" anti-DDoS ukhuseleko lohlaselo kunye nokufumanisa "izixhobo zokusebenza, ukuya". isebenze emva kokuhamba kohlaselo kwaye iphinde ifakwe kwinethiwekhi.
Inkqubo yesicelo esekelwe kwi " Network Inline Bypass " kulula ukuyiphumeza kunesitofu sendlela ye-BGP yendabuko okanye enye i-traffic scheme ye-traffic, kunye nokusingqongileyo kuxhomekeke kancinci kwinethiwekhi kunye nokuthembeka okuphezulu.
"I-Network Inline Bypass" inezi mpawu zilandelayo zokuxhasa ukhuseleko lomgaqo-nkqubo oguquguqukayo wokhuseleko:
I-1, "I-Network Inline Bypass" ukubonelela ngaphandle kwemithetho esekelwe kwi-WEBSERIVCE interface, ukudibanisa lula kunye nezixhobo zokhuseleko lomntu wesithathu.
I-2, "I-Network Inline Bypass" esekelwe kwi-hardware ecocekileyo ye-ASIC chip idlulisa ukuya kwi-10Gbps iipakethi ze-wire-speed ngaphandle kokuthintela ukuhanjiswa kotshintshi, kunye "nelayibrari ye-traffic traction dynamic rule" kungakhathaliseki ukuba inani.
3, ” I-Network Inline Bypass ” eyakhelwe-ngaphakathi umsebenzi we-BYPASS wobuchwephesha, nokuba umkhuseli ngokwawo ukusilela, unokuphinda adlule ikhonkco loqobo lothotho ngoko nangoko, alichaphazeli ikhonkco lokuqala lonxibelelwano oluqhelekileyo.
Ixesha lokuposa: Dec-23-2021