Xa isixhobo se-Intrusion Detection System (IDS) sisetyenziswa, i-mirroring port kwi-switch kwiziko lolwazi lweqela loontanga alanelanga (umzekelo, i-mirroring port enye kuphela ivunyelwe, kwaye i-mirroring port ithathe ezinye izixhobo).
Ngeli xesha, xa singongezi amazibuko amaninzi ezibuko, sinokusebenzisa uphindaphindo lwenethiwekhi, udityaniso kunye nesixhobo sokudlulisa ukuhambisa inani elifanayo ledatha yesipili kwisixhobo sethu.
Yintoni iNetwork TAP?
Mhlawumbi uqale weva igama TAP tshintsha. I-TAP (iNdawo yokuFikelela kwiSitena), eyaziwa ngokuba yiNPB (i-Network Packet Broker), okanye iTap Aggregator?
Umsebenzi ongundoqo we-TAP kukuseka phakathi kwezibuko lezibuko kuthungelwano lwemveliso kunye neqela lesixhobo sokuhlalutya. I-TAP iqokelela i-mirrored okanye i-traffic eyahlukanisiweyo ukusuka kwisixhobo esinye okanye ezininzi zenethiwekhi yemveliso kwaye isasaza i-traffic kwisixhobo esinye okanye ezininzi zokuhlalutya idatha.
I-Common Network ye-TAP yokusasazwa kwenethiwekhi iimeko
I-Network Tap ineelebhile ezicacileyo, ezifana nezi:
I-Hardware eZimeleyo
I-TAP yinto eyahlukileyo ye-hardware engachaphazeli umthwalo kwizixhobo zenethiwekhi ezikhoyo, enye yeenzuzo ngaphezu kwesibuko sezibuko.
Network Transparent
Emva kokuba i-TAP iqhagamshelwe kwinethiwekhi, zonke ezinye izixhobo kwinethiwekhi azichaphazeleki. Kubo, i-TAP iyabonakala njengomoya, kwaye izixhobo zokubeka esweni eziqhagamshelwe kwi-TAP ziselubala kuthungelwano luphela.
I-TAP ifana nje nePort Mirroring kwiswitshi. Ngoko kutheni kusetyenziswe i-TAP eyahlukileyo? Makhe sijonge ezinye zeeyantlukwano phakathi kwe-Network TAP kunye ne-Network Port Mirroring ngokulandelelana.
Umahluko 1: I-TAP yothungelwano kulula ukuyiqwalasela kunezibuko zesibuko
Isibuko sezibuko kufuneka siqwalaselwe kwiswitshi. Ukuba iliso lifuna ukulungiswa, iswitshi kufuneka iphinde iqwalaselwe BONKE. Nangona kunjalo, i-TAP idinga ukulungiswa kuphela apho icele khona, engenampembelelo kwizixhobo ezikhoyo zenethiwekhi.
Umahluko 2: I-TAP yenethiwekhi ayichaphazeli ukusebenza kwenethiwekhi ngokunxulumene nesibuko sesibuko
Isibuko sePort kwiswitshi siwohloka ukusebenza kokutshintsha kwaye kuchaphazela amandla okutshintsha. Ngokukodwa, ukuba iswitshi iqhagamshelwe kuthungelwano kuthotho njenge-inline, isakhono sokudlulisa inethiwekhi yonke sichaphazeleka kakhulu. I-TAP yi-hardware ezimeleyo kwaye ayiphazamisi ukusebenza kwesixhobo ngenxa yokujonga isipili. Ngoko ke, ayinayo impembelelo kumthwalo wezixhobo zenethiwekhi ezikhoyo, ezineenzuzo ezinkulu ngaphezu kwesibuko sesibuko.
Umahluko 3: Uthungelwano lwe-TAP lubonelela ngenkqubo yetrafikhi egcweleyo ngakumbi kunesibuko sesipili sokuphindaphinda
Isibuko sesibuko asikwazi ukuqinisekisa ukuba zonke iitrafikhi zinokufumaneka ngenxa yokuba isibuko sokutshintsha ngokwaso siyakuhluza iipakethi ezithile zempazamo okanye iipakethi ezincinci kakhulu. Nangona kunjalo, i-TAP iqinisekisa ingqibelelo yedatha kuba "yimpinda" epheleleyo kumaleko womzimba.
Umahluko 4: Ulibaziseko lokuthunyelwa kwe-TAP luncinci kunolo lwe-Port Mirroring
Kwezinye iinguqu eziphantsi, i-port mirroring inokwazisa i-latency xa ikopisha i-traffic kwizibuko ze-mirroring, kunye naxa ukopisha i-10 / 100m izibuko kwizibuko ze-Giga Ethernet.
Nangona oku kubhalwe ngokubanzi, sikholelwa ukuba uhlalutyo ezimbini zokugqibela azinayo inkxaso yobugcisa obuqinileyo.
Ke, kweyiphi imeko jikelele, kufuneka sisebenzise i-TAP yokusasazwa kwetrafikhi yenethiwekhi? Ngokulula, ukuba unezi mfuno zilandelayo, ke iNethiwekhi ye-TAP lolona khetho lwakho lulungileyo.
Network TAP Technologies
Mamela oku kungasentla, yiva ukuba i-TAP network shunt sisixhobo somlingo ngokwenene, imarike yangoku ye-TAP shunt isebenzisa ulwakhiwo olusisiseko lweendidi ezithathu:
FPGA
- Ukwenza okuphezulu
- Kunzima ukuphuhlisa
- Iindleko eziphezulu
MIPS
-Ibhetyebhetye kwaye ifanelekile
- Ubunzima bophuhliso oluphakathi
- Abathengisi abaphambili be-RMI kunye neCavium bayeka uphuhliso kwaye bahluleka kamva
I-ASIC
- Ukwenza okuphezulu
- Ulwandiso lophuhliso lomsebenzi lunzima, ikakhulu ngenxa yokulinganiselwa kwetshiphu ngokwayo
-I-interface kunye neenkcukacha zilinganiselwe yi-chip ngokwayo, ekhokelela ekusebenzeni kakubi kokwandisa
Ke ngoko, uxinaniso oluphezulu kunye nesantya esiphezulu seNethiwekhi ye-TAP ebonwa kwintengiso inegumbi elininzi lokuphucula ukuguquguquka ekusebenziseni okusebenzayo. I-TAP network shunters isetyenziselwa ukuguqulwa kweprotocol, ukuqokelelwa kwedatha, ukuthungatha idatha, ukubonwa kwedatha, kunye nokucoca i-traffic. Iintlobo eziphambili zezibuko eziqhelekileyo ziquka i-100G, i-40G, i-10G, i-2.5G ye-POS, i-GE, njl. Ngenxa yokuhoxiswa ngokuthe ngcembe kweemveliso ze-SDH, i-Network TAP shunters yangoku isetyenziswa kakhulu kwi-network ye-Ethernet yonke indawo.
Ixesha lokuposa: May-25-2022