
1- Yintoni iDefine Heartbeat Packet?
Iipakethi zentliziyo zeMylinking™ Network Tap Bypass Switch ezizenzekelayo kwi-Ethernet Layer 2 frames. Xa kusetyenziswa imo ye-Layer 2 bridging (efana ne-IPS / FW), iifreyimu ze-Layer 2 Ethernet zihlala zithunyelwa, zivaliwe okanye zilahlwe. Kwangaxeshanye, iMylinking™ Network Tap Bypass Switch ixhasa ifomathi yemiyalezo yentliziyo eyenzelwe wena ukuhlangabezana nemeko yokuba ezinye izixhobo zokhuseleko ezikhethekileyo azikwazi ukuthumela iifreyimu ze-Ethernet eziqhelekileyo zeLayer 2.
Kwaye iMylinking™ Network Tap Bypass Switch ikwaxhasa ukufunyanwa kwepakethi yokubetha kwentliziyo ngokusekelwe kwithegi yeVLAN, uhlobo lweLayer 3 kunye nohlobo lwemiyalezo eyenzelwe wena yeLayer 4. Ngokusekelwe kule ndlela, umsebenzisi unokuphumeza umsebenzi wovavanyo lokhuseleko lwenkonzo yesixhobo sokhuseleko loqhagamshelo ukuze sisebenze ngakumbi ukuqinisekisa ukuba iinkonzo zokhuseleko ezifanelekileyo zisebenza ngokufanelekileyo.
I-Mylinking™ Network Tap Bypass Switch inokuxhasa imonitha ukuthumela iipakethi ezahlukeneyo zokubetha kwentliziyo kuzo zombini iindlela. Umzekelo, iipakethi zokubetha kwentliziyo zohlobo lwe-TCP kunye nohlobo lwe-UDP zenziwe ngokwezifiso kwi-"Strategy Traffic Traffic Protector", ngokweenkcukacha zesixhobo se-serial. Ungacwangcisa ukuthunyelwa kweepakethi zokubetha kwentliziyo ze-TCP kwi-uplink monitor A port kunye nokuthunyelwa kweepakethi zokubetha kwentliziyo ze-UDP kwi-downlink monitor B port ukuze kulungiselelwe indlela yokudlulisela imiyalezo yesixhobo sokhuseleko se-serial. Lo msebenzi unokuqinisekisa ngakumbi umtya. Qhagamshela izixhobo zokhuseleko ekusebenzeni okuqhelekileyo.

I-Mylinking™ Network Inline Bypass Switch iphandwe kwaye yenzelwe ukusetyenziswa ngendlela eguquguqukayo kwiintlobo ngeentlobo zezixhobo zokhuseleko ezilandelelanayo ngelixa inika ukuthembeka okuphezulu kwenethiwekhi.
Iimpawu eziphambili kunye neeTekhnoloji ze-Inline Bypass Switch ze-2-Network
Imo yoKhuselo yeMylinking™ “SpecFlow” kunye neTekhnoloji yeMo yoKhuselo ye-“FullLink”
Iteknoloji yoKhuseleko lokuTshintsha iMylinking™ ekhawulezayo
Iteknoloji ye-Mylinking™ “LinkSafeSwitch”
I-Mylinking™ “Inkonzo yeWebhu” Isicwangciso esiguqukayo sokudlulisela/ukukhupha iTekhnoloji
Iteknoloji yokuHlola imiyalezo yeNtliziyo eNgqondi yeMylinking™
Itekhnoloji yemiyalezo yeNtliziyo ecacileyo yeMylinking™
Iteknoloji yokulinganisela umthwalo weMylinking™ Multi-link
Iteknoloji yoSasazo lweeNdlela eziBukrelekrele zeMylinking™
Iteknoloji yokulinganisela umthwalo weMylinking™ Dynamic
Iteknoloji yoLawulo olukude lweMylinking™ (HTTP/WEB, TELNET/SSH, uphawu lwe-“EasyConfig/AdvanceConfig”)
Isicelo sokutshintsha i-Inline Bypass yenethiwekhi ezi-3 (njengoko kulandelayo)
3.1 Umngcipheko weZixhobo zoKhuseleko ezikwi-Inline (IPS / FW)
Oku kulandelayo yi-IPS (Intrusion Prevention System) eqhelekileyo, imo yokusasazwa kwe-FW (Firewall), i-IPS / FW isasazwa ngokulandelelana kwizixhobo zenethiwekhi (ii-routers, iiswitshi, njl.njl.) phakathi kwetrafikhi ngokusebenzisa ukwenziwa kokuhlolwa kokhuseleko, ngokwemigaqo-nkqubo yokhuseleko ehambelanayo yokumisela ukukhululwa okanye ukuvalwa kwetrafikhi ehambelanayo, ukufezekisa isiphumo sokhuselo lokhuseleko.

Kwangaxeshanye, sinokubona i-IPS / FW njengokusasazwa kwezixhobo ngokulandelelana, ngokuqhelekileyo zisasazwa kwindawo ephambili yenethiwekhi yeshishini ukuze kuphunyezwe ukhuseleko lwe-serial, ukuthembeka kwezixhobo zayo eziqhagamshelweyo kuchaphazela ngokuthe ngqo ukufumaneka kwenethiwekhi yeshishini iyonke. Nje ukuba izixhobo ze-serial zigqithise kakhulu, ziqhekeke, uhlaziyo lwesoftware, uhlaziyo lomgaqo-nkqubo, njl.njl., ukufumaneka kwenethiwekhi yeshishini lonke kuya kuchaphazeleka kakhulu. Kweli nqanaba, kuphela ngokusika kwenethiwekhi, i-jumper ye-bypass ebonakalayo inokwenza inethiwekhi ibuyiselwe, nto leyo echaphazela kakhulu ukuthembeka kwenethiwekhi. I-IPS / FW kunye nezinye izixhobo ze-serial kwelinye icala ziphucula ukusasazwa kokhuseleko lwenethiwekhi yeshishini, kwelinye icala zinciphisa ukuthembeka kwenethiwekhi yeshishini, nto leyo enyusa umngcipheko wokuba inethiwekhi ayifumaneki.
3.2 Ukhuseleko lwezixhobo ze-Inline Link Series

I-Mylinking™ "Network Inline Bypass" isetyenziswa kuthotho phakathi kwezixhobo zenethiwekhi (ii-routers, iiswitshi, njl.njl.), kwaye ukuhamba kwedatha phakathi kwezixhobo zenethiwekhi akusakhokeleli ngqo kwi-IPS / FW, "Network Inline Bypass" ukuya kwi-IPS / FW, xa i-IPS / FW ngenxa yokugqithiswa kakhulu, ukuphahlazeka, uhlaziyo lwesoftware, uhlaziyo lomgaqo-nkqubo kunye nezinye iimeko zokungaphumeleli, i-"Network Inline Bypass" ngokusebenzisa ukufunyanwa komyalezo wentliziyo ekrelekrele Umsebenzi wokufunyanwa ngexesha elifanelekileyo, kwaye ngaloo ndlela utsibe isixhobo esinesiphene, ngaphandle kokuphazamisa isiseko senethiwekhi, izixhobo zenethiwekhi ezikhawulezayo eziqhagamshelwe ngqo ukukhusela inethiwekhi eqhelekileyo yonxibelelwano; xa ukusilela kwe-IPS / FW kubuya, kodwa nakwiipakethi zentliziyo ekrelekrele Ukufumanisa ukufunyanwa ngexesha elifanelekileyo komsebenzi, ikhonkco lokuqala lokubuyisela ukhuseleko lokuhlolwa kokhuseleko lwenethiwekhi yeshishini.
I-Mylinking™ “Network Inline Bypass” inomsebenzi onamandla wokufumanisa imiyalezo yokubetha kwentliziyo, umsebenzisi angenza ngokwezifiso ixesha lokubetha kwentliziyo kunye nenani eliphezulu lokuzama kwakhona, ngomyalezo wentliziyo olungiselelweyo kwi-IPS / FW wovavanyo lwempilo, njengokuthumela umyalezo wokujonga ukubetha kwentliziyo kwi-upstream / downstream port ye-IPS / FW, aze emva koko afumane kwi-upstream / downstream port ye-IPS / FW, aze agwebe ukuba i-IPS / FW isebenza ngokuqhelekileyo ngokuthumela nokufumana umyalezo wokubetha kwentliziyo.
3.3 Ukhuseleko lweNkqubo ye-“SpecFlow” yoMgca wokuHamba okuLungileyo

Xa isixhobo senethiwekhi yokhuseleko sifuna kuphela ukujongana nokhuseleko oluthile lwethrafikhi, ngokusebenzisa umsebenzi we-Mylinking™ "Network Inline Bypass" traffic per-processing, ngokusebenzisa icebo lokuhlola ithrafikhi ukuze kuqhagamshelwe isixhobo sokhuseleko "Ithrafikhi echaphazelekayo" ithunyelwa ngqo kwikhonkco lenethiwekhi, kwaye "icandelo lethrafikhi elichaphazelekayo" lixhomekeke kwisixhobo sokhuseleko esikwi-intanethi ukuze kwenziwe uhlolo lokhuseleko. Oku akuyi kugcina kuphela ukusetyenziswa okuqhelekileyo komsebenzi wokuchonga ukhuseleko lwesixhobo sokhuseleko, kodwa kuya kunciphisa ukuhamba okungafanelekanga kwezixhobo zokhuseleko ukujongana noxinzelelo; kwangaxeshanye, "i-Network Inline Bypass" inokubona imeko yokusebenza kwesixhobo sokhuseleko ngexesha langempela. Isixhobo sokhuseleko sisebenza ngokungaqhelekanga sidlula ngokuthe ngqo ithrafikhi yedatha ukuze kuthintelwe ukuphazamiseka kwenkonzo yenethiwekhi.
3.4 Ukhuseleko loLuhlu olulinganiselayo lomthwalo

I-Mylinking™ “Network Inline Bypass” isetyenziswa kuthotho phakathi kwezixhobo zenethiwekhi (ii-routers, iiswitshi, njl.njl.). Xa ukusebenza okukodwa kokucubungula i-IPS / FW kunganelanga ukujongana nethrafikhi ye-network link peak, umsebenzi wokulinganisela umthwalo wethrafikhi womkhuseli, “ukuhlanganisa” ithrafikhi ye-network link ye-IPS / FW cluster processing, inokunciphisa ngempumelelo uxinzelelo lokucubungula i-IPS / FW enye, iphucule ukusebenza ngokubanzi kokucubungula ukuhlangabezana ne-bandwidth ephezulu yendawo yokusasazwa.
I-Mylinking™ “Network Inline Bypass” inomsebenzi onamandla wokulinganisela umthwalo, ngokwethegi yesakhelo se-VLAN, ulwazi lwe-MAC, ulwazi lwe-IP, inombolo yezibuko, iprotocol kunye nolunye ulwazi malunga nokusasazwa kwe-Hash load balancing yethrafikhi ukuqinisekisa ukuba i-IPS / FW nganye ifumene ukuthembeka kweSeshini yokuhamba kwedatha.
3.5 Ukhuseleko lokuHamba kweZixhobo eziPhakathi kweZixhobo ezininzi (Tshintsha uQhagamshelo lweSerial ukuya kuQhagamshelo oluPhakathi)
Kwezinye iikhonkco eziphambili (ezifana neendawo ze-intanethi, ikhonkco lokutshintshiselana kwendawo yeseva) indawo idla ngokuba ngenxa yeemfuno zeempawu zokhuseleko kunye nokuthunyelwa kwezixhobo ezininzi zokuvavanya ukhuseleko ezikwi-intanethi (ezifana ne-firewall, izixhobo zokuhlasela ze-DDOS, i-firewall yesicelo se-WEB, izixhobo zokuthintela ukungena, njl.njl.), izixhobo ezininzi zokuchonga ukhuseleko ngaxeshanye kuthotho kwikhonkco ukwandisa ikhonkco lenqaku elinye lokusilela, ukunciphisa ukuthembeka ngokubanzi kwenethiwekhi. Kwaye kwizixhobo zokhuseleko ezikhankanyiweyo apha ngasentla ezifakwe kwi-intanethi, ukuphuculwa kwezixhobo, ukutshintshwa kwezixhobo kunye neminye imisebenzi, kuya kubangela ukuphazamiseka kwenethiwekhi ixesha elide kunye nesenzo esikhulu sokunqunyulwa kweprojekthi ukugqiba ukuphunyezwa ngempumelelo kweeprojekthi ezinjalo.
Ngokusebenzisa i-"Network Inline Bypass" ngendlela edibeneyo, indlela yokusetyenziswa kwezixhobo ezininzi zokhuseleko ezidityaniswe kuthotho kwikhonkco elinye inokutshintshwa ukusuka kwi-"physical concatenation mode" ukuya kwi-"physical concatenation, logical concatenation mode". Ikhonkco kwikhonkco lenqaku elinye lokungaphumeleli ukuphucula ukuthembeka kwekhonkco, ngelixa i-"Network Inline Bypass" kwikhonkco ijikeleza kwi-demand traction, ukufezekisa ukuhamba okufanayo ne-original mode ye-processing effect ekhuselekileyo.
Izixhobo zokhuseleko ezingaphezu kwesinye ngexesha elinye kumzobo wokusasazwa kochungechunge:

Umzobo woTshintsho lwe-Inline Bypass Deployment Deployment:

3.6 Ngokusekelwe kwiQhinga eliDynamic loKhuselo loKhuseleko lokuQondwa koKhuseleko lokuHamba kweNdlela
“I-Network Inline Bypass” Enye imeko yesicelo esiphambili isekelwe kwisicwangciso esitshintshayo sezicelo zokukhusela ukufunyanwa kokhuseleko lokubanjwa kwethrafikhi, ukusasazwa kwendlela njengoko kubonisiwe ngezantsi:

Thatha izixhobo zovavanyo lokhuseleko ze-"Anti-DDoS attack protection and detection", umzekelo, ngokusebenzisa izixhobo zokukhusela ze-"Network Inline Bypass" kunye nezixhobo zokukhusela ze-anti-DDOS uze uqhagamshele kwi-"Network Inline Bypass", kwi-"Traction protector" eqhelekileyo ukuya kwinani elipheleleyo lokudluliselwa kwesantya sethrafikhi ngaxeshanye isiphumo sesibuko sokuhamba ukuya kwisixhobo sokukhusela uhlaselo lwe-anti-DDOS, xa sele sifunyenwe kwi-server IP (okanye icandelo lenethiwekhi ye-IP) emva kohlaselo, isixhobo sokukhusela uhlaselo lwe-anti-DDOS siya kuvelisa imithetho yokufanisa ukuhamba kwethrafikhi ekujoliswe kuyo kwaye siyithumele kwi-"Network Inline Bypass" ngokusebenzisa i-interface yokuhambisa umgaqo-nkqubo onamandla. I-"Network Inline Bypass" inokuhlaziya "i-traffic traction dynamic" emva kokufumana imithetho yomgaqo-nkqubo onamandla. Umgaqo-nkqubo "kwaye ngoko nangoko" ubethe i-attack server traffic "traction to the" anti-DDoS attack protection and detection "equipment for processing, ukuze isebenze emva kohlaselo kwaye ibuyiselwe kwinethiwekhi.
Inkqubo yesicelo esekelwe kwi-"Network Inline Bypass" kulula ukuyisebenzisa kune-BGP route injection yesiqhelo okanye enye inkqubo yokutsalwa kwetrafikhi, kwaye okusingqongileyo akuxhomekekanga kakhulu kwinethiwekhi kwaye ukuthembeka kuphezulu.
I-“Network Inline Bypass” ineempawu ezilandelayo zokuxhasa ukhuseleko lokufunyanwa kokhuseleko lwemigaqo-nkqubo eguquguqukayo:
1, "I-Network Inline Bypass" ukubonelela ngaphandle kwemithetho esekwe kwi-interface ye-WEBSERIVCE, ukuhlanganiswa okulula nezixhobo zokhuseleko zomntu wesithathu.
2, "I-Network Inline Bypass" isekelwe kwi-hardware pure ASIC chip edlulisela iipakethi ze-wire-speed ze-10Gbps ngaphandle kokuthintela ukudluliselwa kweswitshi, kunye "nelayibrari yemithetho ye-traction dynamic rule" nokuba inani lithini.
3, "I-Network Inline Bypass" umsebenzi wobuchwephesha owakhelwe ngaphakathi we-BYPASS, nokuba isikhuselo ngokwaso asiphumeleli, sinokudlula ikhonkco lokuqala le-serial ngoko nangoko, asichaphazeli ikhonkco lokuqala lonxibelelwano oluqhelekileyo.
Ixesha lokuthumela: Disemba-23-2021