Kwixesha lonxibelelwano olukhulu kunye notshintsho lwedijithali, iziseko zenethiwekhi yeshishini zijongene nokwanda okungakaze kubonwe ngaphambili kwezoyikiso ze-cyber—ukusuka ekuhlaselweni yi-DDoS kunye nokungenelela okunobungozi ukuya ekukhutshweni kwedatha kunye nobuthathaka bethrafikhi efihliweyo. Ukukhusela imisebenzi ebalulekileyo yeshishini, imibutho isebenzisa i-ecosystem exineneyo yezisombululo ze-Inline Security kwiindawo eziphambili zenethiwekhi, kubandakanya ii-firewalls (FW), iinkqubo zokuthintela ukungena (IPS), amaqonga e-anti-DDoS, ii-firewalls zesicelo sewebhu (WAF), kunye nezixhobo zolawulo lwezoyikiso ezihlangeneyo (UTM). Kwangaxeshanye, ukuBekwa kweliso kwiNethiwekhi kuye kwaba yinto engaxoxiswana ngayo yokugcina ukubonakala kwethrafikhi, ukusombulula iingxaki, kunye nokuqinisekisa ukuthotyelwa kwemithetho. Nangona kunjalo, ukuthunyelwa kwesiqhelo kwezisombululo ze-Network Packet Broker (NPB) ezizimeleyo kunye ne-Inline Bypass Switch kudala iindawo ezibalulekileyo zokusebenza: amanqaku okusilela (SPOF) kwiindlela zokhuseleko ezingaphakathi, ukucima kwenethiwekhi okungacwangciswanga ngexesha lokugcinwa/ukuphuculwa kwesixhobo, ukucutshungulwa kwethrafikhi okungasebenzi kakuhle, ukungakwazi ukujonga ithrafikhi ye-SSL/TLS efihliweyo, kunye nemiqobo yokusebenza kwiindawo eziphezulu ze-bandwidth 10/40/100GE.
I-Mylinking ijongana nale mingeni kushishino lonke nge-ML-NPB-M2000—isisombululo esidibeneyo esiguqukayo esidibanisa amandla okucwangcisa ithrafikhi akrelekrele esizukulwana esilandelayo seNetwork Packet Broker (NPB) kunye nokunyamezela iimpazamo kunye nokukhuselwa kwexesha lokungasebenzi kwe-Inline Bypass Switch ekumgangatho ophezulu, iNetwork Bypass Tap, kunye neSmart Bypass Switch. Yenzelwe ukuthembeka nokusebenza kwinqanaba leshishini, i-ML-NPB-M2000 inika amandla okucubungula apheleleyo e-2.4Tbps, uyilo oluguquguqukayo olunokutshintshwa, iimodyuli ze-810G SFP+ / 4100GE Bypass, iimodyuli ze-1610GE SFP+ / 4100GE Monitor, kunye neempawu eziphambili zokucubungula ithrafikhi kubandakanya i-SSL proxy/decryption, i-traffic drag, i-DPI deep packet inspection, kunye ne-dynamic policy forwarding. Njenge-Inline Bypass Tap kunye ne-NPB, ichaza ngokutsha uKhuseleko lweNethiwekhi kunye nokubeka esweni ngokudibanisa ukuthunyelwa kokhuseleko olusebenzayo nolusengqiqweni, isuse ii-SPOF, iqinisekise ukuba akukho xesha lokungasebenzi kwenethiwekhi, kwaye ivula ukubonakala kwethrafikhi ngexesha langempela kumashishini anamhlanje, amaziko edatha, kunye namaqonga efu.
Olu lwazi lubanzi lobuchwephesha luhlola ubuchwepheshe obuphambili be-ML-NPB-M2000, ukuguquguquka kwemodyuli, amandla okucubungula ithrafikhi ngobuchule, iinkcukacha zobugcisa, iimeko zokusetyenziswa kwehlabathi lokwenyani, kunye neenzuzo zokhuphiswano—ukuyibeka njengesisombululo esiqinisekileyo se-enterprise Network Packet Broker (NPB), i-Inline Bypass Switch, kunye neemfuno zokhuseleko/ukubeka esweni inethiwekhi.
1. Ukhuseleko lweNethiwekhi yeNdalo kunye nokuBeka esweni: Amanqaku eNtlungu angasonjululwanga kwiShishini
Ngaphambi kokuba sijonge ubuchule obuphambili be-ML-NPB-M2000, kubalulekile ukubala imida yokusetyenziswa kweNetwork Security kunye neNetwork Monitoring—iziphene ezidityaniswe neNetwork Packet Broker (NPB) kunye ne-Inline Bypass Switch ezidityaniswe ngenjongo yokuzisombulula. Ezi ndawo zibuhlungu zihlupha imibutho yazo zonke iintlobo, zichaphazela ukuqhubeka kweshishini, ukusebenza kakuhle, kunye nembuyekezo kutyalo-mali (ROI) lweziseko zokhuseleko kunye nokubeka iliso, kwaye zigxile ekungadibanini phakathi kwe-NPB ezimeleyo kunye nezisombululo ze-inline bypass:
1.1 Amanqaku Okusilela Ngamnye (i-SPOF) kwiiTsheyini zoKhuseleko ezikwi-Inline
Ukusasazwa kwezixhobo ze-Inline Security ngokulandelelana (FW/IPS/Anti-DDoS) kudala ii-SPOF eziqhekekayo: ukusilela kwesixhobo esinye (ukulayisha ngaphezulu, ukuqhekeka, ukonakala kwe-firmware) okanye ukugcinwa rhoqo kumisa lonke ikhonkco lenethiwekhi, okukhokelela kwixesha lokungasebenzi elibizayo elingacwangciswanga. Izisombululo ze-Inline Bypass Tap zemveli azinabo ubulumko bokudibanisa nezixhobo zokujonga ithrafikhi, nto leyo edala ukhuseleko lwempazamo efihliweyo kunye nokubonakala.
1.2 Ukuphazamiseka kweNethiwekhi Okungenakuphepheka Ngexesha Lokulungiswa Nokuphuculwa
Ukuphucula i-firmware, ukutshintsha i-hardware, okanye ukuhlaziya imigaqo-nkqubo yokhuseleko yezixhobo zokhuseleko ezikwi-intanethi kufuna ukunqanyulwa kwenethiwekhi ngesandla kunye nee-pass jumpers ezibonakalayo. Oku kucima okucwangcisiweyo kuphazamisa usetyenziso olubalulekileyo lweshishini kwaye kutshabalalisa ukuthembeka kwenethiwekhi—ingxaki engamkelekanga kwiindawo zeshishini kunye neziko ledatha ezingama-24/7.
1.3 Ukungasebenzi kakuhle kweTrafikhi kunye neMisantsa yokuBonakala
Izisombululo ze-Standalone Network Packet Broker (NPB) zihlala zingenalo ukhuseleko oluqinileyo lwempazamo emgceni, ngelixa izixhobo zeSmart Bypass Switch zemveli zibonelela ngezakhono zokucubungula ithrafikhi ezilinganiselweyo (umz., ukuphindaphinda/ukucoca okusisiseko). Oku kuphumela ekusasazweni kwethrafikhi okungasebenzi kakuhle, ukubanjwa kweepakethi ezingafunekiyo, iindawo ezingabonakaliyo ekubekweni kweliso eliyimfihlo kwethrafikhi, kunye nokungakwazi ukulungisa ukuhlolwa kwethrafikhi ngokweemfuno ezithile zezixhobo zokhuseleko—ukuchitha izixhobo zokucubungula kunye nokunciphisa ukuchaneka kokubeka esweni.
1.4 Imida Yokubeka Esweni Itrafikhi Efihliweyo
Ukubethela i-SSL/TLS kusemgangathweni wokudluliselwa kwedatha ngokukhuselekileyo, kodwa kudala indawo ebalulekileyo yokungafihlisi kwizixhobo zoLawulo lweNethiwekhi kunye noKhuseleko oluPhakathi. Izisombululo zemveli azinazo izakhono zomgunyathi/zokususa ukubethela ze-SSL, nto leyo eshiya imibutho ingakwazi ukuhlola ithrafikhi ebethelweyo ukuze ibone imisebenzi enobungozi ngaphandle kokuphazamisa ukhuseleko oluvela ekupheleni ukuya ekupheleni.
1.5 Iingxaki Zokusebenza Kwiindawo EzineBandwidth Ephezulu
Iikhonkco ze-10/40/100GE eziphezulu ze-bandwidth zivelisa imithamo emikhulu yethrafikhi egqitha izixhobo zokhuseleko/zokubeka esweni esinye. Izisombululo ezizimeleyo azinazo izakhono zokulinganisela umthwalo eziguquguqukayo zokusasaza ithrafikhi kwizixhobo ezidibeneyo, nto leyo ekhokelela ekwandeni kokulibaziseka, ukulahleka kwepakethi, kunye nokusebenza kwesicelo okuwohlokileyo.
1.6 Ukusasazwa kweZixhobo ezininzi okuntsonkothileyo kunye noLawulo oluSiloed
Ukusebenzisa izixhobo ezahlukeneyo ze-NPB, i-Inline Bypass Switch, kunye nokucubungula ithrafikhi kufuna iintambo zomzimba ezintsonkothileyo, uqwalaselo lwesandla, kunye nolawulo oluvaliweyo. Oku kwandisa iindleko zokusebenza kwamaqela e-IT, kulibazisa ukusombulula iingxaki, kwaye kudala ukungangqinelani ekuthotyelweni komgaqo-nkqubo wethrafikhi kuyo yonke inethiwekhi.
1.7 Ukubonakala Okulinganiselweyo Kwezithuthi kunye Nokufumaneka Kweempazamo
Izisombululo zokubeka esweni zemveli zibonelela ngeenkcukacha-manani ezisisiseko zendlela, ngaphandle kokuhlolwa kwepakethe enzulu (DPI) okanye uhlalutyo lwempazamo ebonakalayo. Oku kushiya imibutho ingakwazi ukufumanisa ngokukhawuleza unobangela oyintloko weengxaki zenethiwekhi, ukwaphulwa kokhuseleko, okanye imiba yokusebenza—ukwandisa amaxesha okusombulula iingxaki kunye nokwandisa umngcipheko weshishini.
Ezi ndawo zibuhlungu azizongxaki zobugcisa nje kuphela; zichaphazela ngokuthe ngqo amandla ombutho okugcina inethiwekhi ekhuselekileyo, ethembekileyo, nebonakalayo. I-Mylinking ML-NPB-M2000 isombulula nganye kwezi ngxaki ngokudibanisa ukusebenza kweNetwork Packet Broker (NPB) kunye ne-Inline Bypass Switch kwiqonga elinye, elikrelekrele, nelinokwandiswa—ukususa ii-silos, ukuvula ukusebenza kwe-zero-downtime, kunye nokubonelela ngoKhuseleko lweNethiwekhi olupheleleyo kunye nokubeka esweni.
2. I-Mylinking ML-NPB-M2000: I-NPB edibeneyo + i-Inline Bypass Switch – Utshintsho lweParadigm kuKhuseleko lweNethiwekhi kunye nokuBeka esweni
I-Mylinking ML-NPB-M2000 sisisombululo sokuqala seshishini esikumgangatho ophezulu sokudibanisa ngokungenamthungo amandla okucwangcisa ithrafikhi ye-Network Packet Broker (NPB) kunye nokunyamezela iimpazamo ze-Smart Bypass Switch, i-Network Bypass Tap, kunye ne-Inline Bypass Tap. Yenzelwe ukusasazwa okuguquguqukayo kwezixhobo ze-serial Inline Security kunye ne-Network Monitoring eqinileyo, yenzelwe ukujongana neendawo eziphambili zokusetyenziswa kwendabuko ngelixa inikezela ukusebenza okungapheliyo, ukwandiswa, kunye nokuthembeka.
Eyona nto iphambili kuyo, i-ML-NPB-M2000 sisixhobo se-rackmount esisemgangathweni se-2U esidibanisa ukhuseleko lwe-Inline Bypass Switch kunye ne-NPB traffic processing ephucukileyo—kuquka i-SSL proxy/decryption, i-traffic dragment, i-DPI, i-dynamic load balancing, kunye nokubonakala kwe-traffic ngexesha langempela. Iintsika zayo eziphambili zoyilo zihambelana neemfuno ezifunwa kakhulu zeshishini kunye neziko ledatha:
○ Ukudibanisa: Idibanisa i-NPB, i-Inline Bypass Switch, i-Network Bypass Tap, kunye nokucutshungulwa kwetrafikhi kwiqonga elinye, isusa ukuthunyelwa kwe-siloed kunye nobunzima bokusebenza.
○ Ukusebenza kweZero-Downtime: Ukuchonga ukubetha kwentliziyo okukrelekrele kunye nokutshintsha ngokukhawuleza kwe-bypass kuqinisekisa unxibelelwano lwenethiwekhi olungaphazanyiswa, nokuba izixhobo zokhuseleko ezikwi-intanethi okanye i-ML-NPB-M2000 ngokwayo ifumana ingxaki.
○ Ukulinganiswa kweModular: Izithuba zemodyuli ezi-4 ezishushu ezitshintshanayo zixhasa umxube weemodyuli zeBypass kunye neMonitor, ezivumela ukumiselwa ngokwezifiso kweekhonkco ze-10/40/100GE kunye nokuziqhelanisa neemfuno zenethiwekhi eziguqukayo ngaphandle kokutshintshwa ngokupheleleyo kwehardware.
○ Ukucubungula iTrafikhi okuPhambili: I-Native SSL proxy/decryption, i-DPI yeeprotokholi zesicelo ezingaphezu kwe-1800, ukususwa kwethrafikhi, ukufihla, kunye nokubumba—ukuvula ukubonakala okupheleleyo kwithrafikhi efihliweyo nengafihliweyo.
○ Iindlela zokusasazwa kabini: Ixhasa ukuthunyelwa kwe-Inline (serial) yokukhusela isixhobo sokhuseleko kunye nokuthunyelwa kwe-SPAN (switched port analyzer) yokubeka iliso kwiNethiwekhi engashukumiyo—inikezela ngokuguquguquka kuzo zonke ii-node zesitshixo senethiwekhi (ii-gateways ze-intanethi, ii-core switches, iifama zeseva yeziko ledatha).
○ Ukuthembeka komgangatho weShishini: Umbane ombini we-AC/DC, ukunyamezelana kokusingqongileyo okusemgangathweni wemizi-mveliso, kunye neendlela zokulawula ezingafunekiyo ziqinisekisa ukusebenza iiyure ezingama-24/7 kwiindawo ezinobungozi zedatha nakwiindawo zoshishino.
I-ML-NPB-M2000 ayisiyo nje iNetwork Packet Broker (NPB) okanye i-Inline Bypass Switch—sisiziko sokulungelelanisa nokukhusela ithrafikhi esichaza ngokutsha indlela imibutho esebenzisa ngayo izisombululo ze-Inline Security kunye ne-Network Monitoring. Ngokudibanisa le misebenzi ibalulekileyo, inciphisa iindleko zokusebenza, isuse ii-SPOF, kwaye inika ukubonakala kwethrafikhi kunye nolawulo olufunekayo kwishishini ledijithali lanamhlanje.
3. Iiteknoloji eziphambili kunye neempawu ezichazayo
Ukusebenza nokuthembeka okuphambili kwishishini leMylinking ML-NPB-M2000 kuvela kwipotifoliyo yeetekhnoloji ezizimeleyo neziqinisekisiweyo kushishino—nganye ilungiselelwe ukujongana nemingeni eyahlukileyo yoKhuseleko lweNethiwekhi kunye nokuBekwa kweliso kwiNethiwekhi kwiindawo ezine-bandwidth ephezulu. Ezi tekhnoloji zenza i-ML-NPB-M2000 ibe yiNetwork Packet Broker (NPB) edibeneyo ephucukileyo kunye neSmart Bypass Switch kwimarike, inika ukunyamezela iimpazamo, ubukrelekrele bendlela, kunye nolawulo olungenamthungo. Zonke iimpawu eziphambili zenzelwe ukusebenza ngaxeshanye, ukuqinisekisa isiseko senethiwekhi esidibeneyo, esikhuselekileyo, nesibonakalayo.
3.1 Iindlela zoKhuseleko zeSpecFlow™ kunye neFullLink™
I-ML-NPB-M2000 ineendlela ezimbini zokukhusela ezinokucwangciswa zokusetyenziswa kwe-Inline Security, ezihambelana neemfuno ezahlukeneyo zokhuseleko lwentlangano kunye nokulungiswa kwethrafikhi:
○ Imo yoKhuselo yeSpecFlow™: Ivumela ukhuseleko olukhethiweyo lwethrafikhi ngokuchonga nokuthumela ngqo iintlobo ezithile zethrafikhi (umz., i-RDP, i-SSH, ithrafikhi yedatha, ithrafikhi ye-SSL/TLS efihliweyo) kwizixhobo zokhuseleko ezikwi-inline ngokusebenzisa i-L2-L4 layer header identification (iithegi ze-VLAN, iidilesi ze-MAC/IP, iiports ze-transport layer). Ithrafikhi engadibaniyo ithunyelwa ngqo kwikhonkco lenethiwekhi, inciphisa umthwalo wokucubungula kwizixhobo zokhuseleko kwaye inciphise ukubambezeleka.
○ Imo yoKhuseleko yeFullLink™: Kwiimeko ezifuna ukuhlolwa kokhuseleko olupheleleyo, le ndlela idlulisela lonke ithrafikhi yenethiwekhi ngokusebenzisa izixhobo ze-Inline Security ezilandelelanayo—iqinisekisa ukuthotyelwa ngokupheleleyo kwemigaqo-nkqubo yokhuseleko lweshishini ngelixa igcina unyamezelo lweempazamo ze-Inline Bypass Switch kunye nokukhuselwa kwexesha lokungasebenzi.
Zombini iindlela zidibana ngokungenamthungo nobuchule bokucubungula ithrafikhi ye-ML-NPB-M2000's NPB, nto leyo evumela ukuhluzwa kwethrafikhi kunye nokunyanzeliswa komgaqo-nkqubo kuzo zombini iindlela zokusasazwa kwe-Inline kunye ne-SPAN.
3.2 Ukuchonga iPakethi yeNtliziyo eNgqondileyo neQinisekayo
Isiseko sokunyamezela iimpazamo ze-ML-NPB-M2000 (ubuchule obuphambili beSmart Bypass Switch) kukubona iipakethi zentliziyo ngendlela ekrelekrele—iteknoloji yokujonga ethambileyo ejikelezayo esusa amabala angabonakaliyo ekuhlolweni kwempilo yesixhobo sokhuseleko esisemgceni. I-ML-NPB-M2000 ithumela iipakethi zentliziyo ezinokwenziwa ngokwezifiso kwiindawo eziphezulu/ezantsi zezixhobo ze-Inline Security ezixhunyiweyo kwaye iqinisekisa ukubuya kwazo ukuvavanya imeko yokusebenza ngexesha langempela, kunye neempawu eziphambili eziquka:
○ Iiparameter zentliziyo ezichazwe ngokupheleleyo: Abalawuli banokwenza ngokwezifiso amaxesha okudlulisa ukubetha kwentliziyo, inani eliphezulu lokuzama kwakhona, kunye nemiyalelo yokudlulisa ukuze ihambelane neempawu ze-latency kunye nokuthembeka kwezixhobo zabo zokhuseleko.
○ Ukuchonga iimpazamo kwicala ngalinye: Indlela yokubetha kwentliziyo ye-Tx/Rx ibonisa ngokuchanekileyo indlela epheleleyo yokucubungula ithrafikhi yezixhobo zokhuseleko ezikwi-inline, iqinisekisa ukuba akukho ziphumo zingalunganga okanye ezimbi ekufumaneni iimpazamo.
○ Ukudlula ngokuzenzekelayo kwangoko: Ukuba iipakethi zentliziyo azibuyi (ezibonisa ukusilela kwesixhobo, ukugqithisa kakhulu, okanye ukuqhawuka), i-ML-NPB-M2000 idlula isixhobo esinengxaki ngaphakathi kwe-<8ms—ibuyisela ithrafikhi ngqo phakathi kwezixhobo zenethiwekhi ukuqinisekisa ukuba akukho xesha lokungasebenzi kwenethiwekhi.
○ Ukubuyisela ngokuzenzekelayo okungenamthungo: Xa isixhobo sokhuseleko esinempazamo siqala ukusebenza ngendlela eqhelekileyo, inkqubo yokufumanisa ukubetha kwentliziyo ibangela ukunxibelelana kwakhona okungenamthungo kwikhonkco lokhuseleko—akukho mfuneko yokungenelela ngesandla.
○ Iintlobo zeepakethi zentliziyo ezinokwenziwa ngokwezifiso: Ixhasa iipakethi zentliziyo zeLayer 2, 3, kunye ne-4, ezilungelelaniswa nezixhobo zokhuseleko ezikhethekileyo ezingaphakathi ezingakwaziyo ukudlulisa iifreyimu ze-Ethernet zeLayer 2 eziqhelekileyo (umz., i-IPS/FW ecacileyo ye-bridge-mode).
Le teknoloji iqinisekisa ukuba i-ML-NPB-M2000 isebenza njengomlindi ophaphileyo wekhonkco lokhuseleko olungaphakathi, isusa ii-SPOF kwaye iqinisekisa unxibelelwano oluqhubekayo lwenethiwekhi—into ebalulekileyo kwiindawo zoshishino kunye neziko ledatha ezingama-24/7.
3.3 Ukutshintsha i-Fast Bypass kunye neTekhnoloji yeLinkSafeSwitch™
Ukuncedisa ukufunyanwa kwentliziyo ngendlela ekrelekrele, i-ML-NPB-M2000 idibanisa uKhuseleko lokuTshintshela i-Fast Bypass kunye neTekhnoloji ye-LinkSafeSwitch™—iimpawu ezikhawulezisiweyo zehardware ezichaza amandla ayo e-Inline Bypass Tap kunye ne-Network Bypass Tap:
○ Utshintsho lwe-Sub-8ms bypass latency: I-ML-NPB-M2000 ibonelela ngokulibaziseka okuphantsi kokutshintsha kwe-bypass okukhokelayo kushishino, iqinisekisa ukuba abasebenzisi abafumani mpembelelo ebonakalayo kwinethiwekhi ngexesha leziganeko zempazamo.
○ Ukugcinwa kwemeko yekhonkco: Iteknoloji yeLinkSafeSwitch™ iqinisekisa ukuba imeko yekhonkco lenethiwekhi ephambili ayitshintshi ngexesha lokutshintsha kwe-bypass, ithintela iiprotokholi ze-topology zeLayer 2/3 ekubeni ziphinde zisebenze kwaye zihlangane—inciphisa ukuphazamiseka kwenethiwekhi.
○ Umsebenzi wokuvula ngokungaphumeleliNokuba i-ML-NPB-M2000 ngokwayo ifumana ingxaki kwi-hardware okanye kwisoftware, iyazigqitha ngokuzenzekelayo umaleko wayo wokucubungula, igcina unxibelelwano oluthe ngqo phakathi kwezixhobo zenethiwekhi. Oku kususa i-ML-NPB-M2000 njenge-SPOF enokubakho— inzuzo ebalulekileyo kunezisombululo ze-Inline Bypass Switch ezizimeleyo.
3.4 Iteknoloji yokudlulisa/yokukhupha umgaqo-nkqubo weWebService™
Into ebalulekileyo eyahlulahlulayo ukusebenza kwe-ML-NPB-M2000's Network Packet Broker (NPB) yiWebService™ Dynamic Policy Forwarding/Issue Technology—evumela ukuhlanganiswa kwexesha langempela nezixhobo zoKhuseleko oluQokelelweyo kunye nokubeka esweni zeqela lesithathu (umz., amaqonga e-Anti-DDoS, iinkqubo ze-SIEM). Olu phawu luguqula i-ML-NPB-M2000 ibe yindawo yolawulo lwethrafikhi ephakathi, enezakhono eziphambili:
○ Uhlaziyo lomgaqo-nkqubo olutshintshatshintshayo ngexesha langempelaIzixhobo zokhuseleko zomntu wesithathu zinokuthumela imithetho yokufanisa ithrafikhi kwi-ML-NPB-M2000 nge-WebService API eqhelekileyo, ehlaziya i-traffic traction yayo ngokukhawulezileyo—akukho mfuneko yokuseta ngesandla.
○ Ukudluliselwa kwenye indawo kwethrafikhi ngendlela enobungozi xa kufunekaUmzekelo, ukuba isixhobo se-Anti-DDoS sibona uhlaselo kwi-IP/segment yeseva ethile, sibangela i-ML-NPB-M2000 ukuba ithumele kuphela ithrafikhi enobuthi kwisixhobo se-Anti-DDoS ukuze sicoceke—okushiya ithrafikhi eqhelekileyo ingachaphazeleki kwaye inciphise ukubambezeleka.
○ Ukuxhomekeka okuphantsi kwinethiwekhiNgokungafaniyo nezisombululo zendabuko zokutsala ithrafikhi (umz., ukufakwa kwendlela ye-BGP), ukuthunyelwa kwemigaqo-nkqubo okuguquguqukayo akufuni tshintsho kwi-topology yenethiwekhi esisiseko—okwenza kube lula ukuyisebenzisa, ukuyigcina, kunye nokulinganisa.
○ Ukudlulisela phambili isantya sentambo esikhawulezileyo se-ASIC: I-ML-NPB-M2000 isebenzisa ukuthunyelwa kwetshiphusi ye-ASIC ecocekileyo ukuya kuthi ga kwi-100Gbps yethrafikhi yesantya sentambo, ngaphandle kokuthintela—nokuba kusetyenzwa amakhulu emithetho yemigaqo-nkqubo eguqukayo.
I-3.5 SSL Proxy kunye ne-Decryption – Ukuvula Ukubonakala Kwetrafikhi Okufihliweyo
Enye yezona ngxaki zibalulekileyo zokubeka iliso kwiNethiwekhi kunye noKhuseleko oluPhakathi kwiinethiwekhi zanamhlanje yi-encrypted SSL/TLS traffic. I-ML-NPB-M2000 ijongana nale nto nge-native SSL Proxy kunye ne-SPAN SSL Decryption capabilities—ukususa iindawo ezingabonakaliyo ze-traffic ezifihliweyo ngaphandle kokuphazamisa ukhuseleko oluvela ekupheleni ukuya ekupheleni:
○ Iproksi ye-SSL ecacileyo: Isusa iipakethi ezifihliweyo zokuqala, ithumela umbhalo ocacileyo kwizixhobo zokhuseleko/zokubeka esweni ezingaphakathi ukuze zihlolwe, ize iphinde ibethele idatha kwaye iyithumele kwikhonkco lenethiwekhi yokuqala—iqinisekisa ukuhanjiswa kwedatha ekhuselekileyo ngelixa ivumela ukuhlolwa kwetrafikhi ngokupheleleyo.
○ Inkxaso ebanzi yokubethela: Ixhasa i-TLS1.0, i-TLS1.2, kunye ne-SSL3.0, iyahambelana nazo zonke iiprotokholi zokubethela zeshishini ezisemgangathweni.
○ Ukususwa kwe-crypt ngokusekelwe kwisatifikethi: Ilayisha izatifikethi ze-SSL ezenziwe ngokwezifiso zokususa ukubethela kwiintlobo ezithile zetrafikhi, iqinisekisa ukuthotyelwa kwemigaqo yobumfihlo bedatha (umz., i-GDPR, i-CCPA).
○ Ukususa ukubethela kwe-SSL nge-Bypass: Kwi-SPAN deployments, isusa i-HTTPS encrypted traffic kwiinkqubo zokubeka esweni/uhlalutyo lwangasemva—ivula ukubonakala kwimisebenzi enobungozi efihliweyo kwi-encrypted traffic.
Olu buchule lutshintsha umdlalo kwimibutho efuna ukulinganisela ukuhanjiswa kwedatha okukhuselekileyo okufihliweyo kunye nokubeka iliso kwiNethiwekhi okuqinileyo kunye noKhuseleko oluPhakathi.
3.6 Ukulinganisela Umthwalo Oguquguqukayo Weekhonkco Ezininzi
Kwiindawo ze-bandwidth ephezulu ye-10/40/100GE apho isixhobo esinye soKhuseleko oluPhakathi okanye sokubeka esweni singenako ukusingatha ithrafikhi ephezulu, iiteknoloji ze-ML-NPB-M2000's Multi-link Load Balancing kunye ne-Intelligent Traffic Distribution zivumela ukuthunyelwa kwezixhobo ezidibeneyo—ukuvula i-linear scalability yokucubungula amandla:
○ Ukusasazwa kwetrafikhi okusekelwe kwiHash: Isasaza ithrafikhi kwizixhobo zokhuseleko/zokubeka esweni ezidityanisiweyo ngokusekelwe kwiimpawu zomaleko we-L2-L4 (iithegi ze-VLAN, iidilesi ze-MAC/IP, iinombolo zezibuko, ulwazi lweprotocol)—iqinisekisa ukuthembeka kweseshoni kunye nokuphepha ukuphinda ucwangcise iipakethi.
○ Uhlengahlengiso lomthwalo oguqukayo: Ukubeka esweni umthwalo wesixhobo ngasinye ngexesha langempela, kunye nokusasazwa kwezithuthi ngokuzenzekelayo ukuthintela ukuxinana kakhulu kunye nokuphucula ukusetyenziswa kwezixhobo.
○ Inkxaso yokudibanisa abantu abaninzi: Ivumela ukuhlanganiswa kwezixhobo zokhuseleko ezikwi-intanethi ukuya kuthi ga kwi-1610GE okanye kwi-8100GE, ukuhlangabezana neemfuno zenethiwekhi eziphambili ze-bandwidth ephezulu, ii-intanethi zamasango, kunye neefama zeseva yeziko ledatha.
○ Ubulungu beqela le-Dynamic port: Amaqela ezibuko zokulinganisela umthwalo azivumelanisa ngokuzenzekelayo notshintsho lwemeko yekhonkco (qhagamshela PHEZULU/PHANTSI), esasaza kwakhona ithrafikhi ukuqinisekisa ukuqhubekeka kokucubungula—akukho kungenelela ngesandla okufunekayo.
3.7 Ubuchwepheshe obupheleleyo boLawulo olukude
I-ML-NPB-M2000 yenzelwe ukulawula kude ngaphandle komthungo—ibalulekile kwiinethiwekhi ezinkulu zamashishini, amaziko edatha asasazeke ngokwendawo, kunye namaqonga efu. NjengoMthengisi wePakethi yeNethiwekhi (NPB) oqeqeshiweyo kunye neSmart Bypass Switch, ixhasa uluhlu olupheleleyo lweeprotokholi zolawulo olusemgangathweni zoshishino kunye nezixhobo, kunye nolawulo lokufikelela olusekelwe kwindima (RBAC) ukuqinisekisa ukhuseleko lolawulo:
○ Ulawulo lwemizobo: I-HTTP/WEB GUI yokujonga ngexesha langempela ngendlela eqondakalayo, uqwalaselo, ukusombulula iingxaki, kunye nokubona ithrafikhi.
○ Ulawulo lomgca womyalelo: TELNET/SSH CLI ene-EasyConfig (ukuseta okusisiseko kwabalawuli abangengabo abenza ubugcisa) kunye neendlela ze-AdvanceConfig (ukuseta okuncinci kobugcisa kwiinjineli zenethiwekhi).
○ Ukuhlanganiswa kolawulo lwenethiwekhi: I-SNMP V1/V2C yokudibanisa neenkqubo zolawulo lwenethiwekhi yeshishini (i-NMS) kunye ne-SYSLOG yokuqokelela kunye nokuhlaziya iilog ezidityanisiweyo.
○ Uqinisekiso olukhuselekileyo: Ukuqinisekiswa okusekelwe kwigama eligqithisiweyo, i-AAA, kunye nogunyaziso oluphakathi lwe-TACACS+/RADIUS—ukuqinisekisa ukuba ngabasebenzi abagunyazisiweyo kuphela abanokufikelela kwaye balungiselele isixhobo.
○ Ulawulo olungaphandle kwebhendi: I-interface yolawulo ye-1*10/100/1000M RJ45 ezinikeleyo iqinisekisa ukufikelela kude nokuba iplani yedatha ifumana impazamo.
○ Uqwalaselo lwendawo: I-RS232 Console interface (115200,8,N,1) yokulungiselela uqwalaselo kunye nokusombulula iingxaki kwindawo.
Olu luhlu olubanzi lolawulo lunciphisa umthwalo wokusebenza kumaqela e-IT, lwenza kube lula ukuseta kunye nokusombulula iimpazamo, kwaye luqinisekisa ukunyanzeliswa kwemigaqo-nkqubo rhoqo kuyo yonke inethiwekhi.
4. Ukuguquguquka koCwangciso lweModular - Okunokwenziwa ngokwezifiso kuzo zonke iimfuno zenethiwekhi
Uphawu olucacileyo lweMylinking ML-NPB-M2000 luyilo lwayo oluguquguqukayo, olunokutshintshwa ngobushushu—uphawu lokukwazi kwayo ukuguquguquka njengeNetwork Packet Broker (NPB) edibeneyo kunye neInline Bypass Switch. Esi sixhobo sine-chassis eyimfuneko (eneendlela zamandla ze-AC/DC) kunye neendawo ezine ze-module ezixhasa naluphi na udibaniso lweemodyuli zeBypass kunye neMonitor—ezenza imibutho ilungelelanise iML-NPB-M2000 nesantya sayo sekhonkco se-10/40/100GE, ukhuseleko lwe-Inline Security, kunye neemfuno ze-Network Monitoring. Zonke iimodyuli zixhasa ukutshintsha ngobushushu, okuvumela ukugcinwa kunye nokuphuculwa ngaphandle kwexesha lokungasebenzi kwenethiwekhi—okuqinisa ngakumbi umgaqo woyilo lwe-ML-NPB-M2000 we-zero-downtime.
4.1 Iinkcukacha zeChassis (ML-NPB-M2000)
Itshasi sisiseko se-ML-NPB-M2000, ebonelela ngeziseko zophuhliso ezibonakalayo, zombane, nezolawulo zokudibanisa iimodyuli. Kukho iimodeli ezimbini zetshasi ezikhoyo, ezahluka kuphela kumbane (AC/DC) ukuze zilungelelaniswe neendawo ezahlukeneyo zamandla eshishini kunye neziko ledatha:
| Imodeli yeChassis | Iinkcukacha zobuGcisa eziPhambili |
|---|---|
| I-ML-NPB-M2000-CHS/AC | I-rackmount ye-2U eyi-19-intshi; Izithuba zemodyuli ezi-4 ezinokutshintshelwa ngobushushu; 1Ikhonsoli ye-RS232, 110/100/1000M RJ45 mgmt; amandla amabini e-AC-220V; ukusetyenziswa kwamandla okuphezulu kwe-300W; ubukhulu be-444mm88mm670mm |
| I-ML-NPB-M2000-CHS/DC | I-rackmount ye-2U eyi-19-intshi; Izithuba zemodyuli ezi-4 ezinokutshintshelwa ngobushushu; 1Ikhonsoli ye-RS232, 110/100/1000M RJ45 mgmt; amandla e-DC-48V amabini; ukusetyenziswa kwamandla okuphezulu kwe-300W; ubukhulu be-444mm88mm670mm |
4.2 Iimodyuli ze-Bypass – Ukhuseleko olusemgceni
Iimodyuli ze-Bypass zingundoqo kwi-ML-NPB-M2000's Inline Bypass Switch, Network Bypass Tap, kunye ne-Inline Bypass Tap, zibonelela ngokhuseleko olulandelelanayo kwiikhonkco ze-10/40/100GE kwaye zidibana ngokuthe ngqo nokuchongwa kwentliziyo okukrelekrele kwesixhobo kunye nokutshintsha ngokukhawuleza kwe-bypass. Zonke iimodyuli ze-Bypass zixhasa ukuhambelana kwe-1G/10GE (INL-I8XM8X) okanye i-40GE/100GE (INL-I4HM2H), okuqinisekisa ukuhambelana ngasemva nangaphambili neziseko zenethiwekhi ezikhoyo:
| Imodeli yeModyuli yeDrap | Iinkcukacha zobuGcisa eziPhambili |
|---|---|
| INL-I8XM8X (LM/SM) | Ukhuseleko lwe-serial lwe-link ye-10GE (ehambelana ne-1G) yeendlela ezi-4; 8Ii-interface ze-10GE; 8Iiports zokubeka esweni ze-10G SFP+ (akukho modyuli ze-optical); inkxaso ye-single/multimode |
| INL-I4HM2H (LM/SM) | Ukhuseleko lwe-serial lwe-link ye-100GE (ehambelana ne-40GE) yeendlela ezimbini; 4Ii-interface ze-100GE; 2Iiports zokubeka esweni ze-100GE QSFP28 (akukho modyuli ze-optical); inkxaso ye-single/multimode |
4.3 Iimodyuli zokuJonga – Ukucwangciswa nokuBekwa esweni kweTrafikhi yeNPB ePhambili
Iimodyuli zeMonitor zinika amandla ukusebenza kwe-ML-NPB-M2000's Network Packet Broker (NPB), zibonelela ngokucubungula okusisiseko nokuphambili kwethrafikhi yokuthunyelwa kwe-SPAN kunye nokuBekwa kweliso kwiNethiwekhi. Kukho amanqanaba amabini eemodyuli zeMonitor: iimodyuli ezisemgangathweni (ukucubungula okusisiseko kwethrafikhi) kunye neemodyuli ze-engine function eziphambili (i-SSL proxy/decryption, i-traffic drag, i-DPI). Zonke iimodyuli zeMonitor azibandakanyi iimodyuli ze-optical, ezivumela imibutho ukuba isebenzise ii-transceivers zayo ezikhoyo ukuze isebenzise iindleko kakuhle:
| Imodeli yeModyuli yoMlindo | Iinkcukacha zobuGcisa eziPhambili |
|---|---|
| MON-M16X | Iiports zokubeka esweni ze-16*10GE SFP+ (akukho modyuli ze-optical); ukucutshungulwa kwetrafikhi esisiseko (ukuphindaphinda/ukuhlanganisa/ukucoca) |
| MON-M16X-CN98 | Iiports zokubeka esweni ze-16*10GE SFP+ (akukho modyuli ze-optical); injini yomsebenzi ephucukileyo (i-SSL proxy/decryption, i-traffic draduplication, i-DPI) |
| UMVULO-UM4H | Iiports zokubeka esweni ze-4*100GE QSFP28 (akukho modyuli ze-optical); ukucutshungulwa kwetrafikhi esisiseko (ukuphindaphinda/ukuhlanganisa/ukucoca) |
| UMvulo-M4H-CN98 | Iiports zokubeka esweni ze-4*100GE QSFP28 (akukho modyuli ze-optical); injini yomsebenzi ephucukileyo (i-SSL proxy/decryption, i-traffic draduplication, i-DPI) |
4.4 Imithetho yoCwangciso lweModyuli ebalulekileyo
Ukuqinisekisa ukusebenza kakuhle, ukuhambelana, kunye nokukhula, i-ML-NPB-M2000 ilandela iseti yemithetho yoqwalaselo lwemodyuli ecacileyo, elula ukuyisebenzisa—eyenzelwe ukwandisa ukuguquguquka ngelixa kuthintelwa iimpazamo zoqwalaselo:
○ Itshasi kuqala: Itshasi ye-ML-NPB-M2000 (AC/DC) yinxalenye eyimfuneko; zonke iimodyuli zeBypass/Monitor zezesibini kwaye kufuneka zikhethwe emva kwetshasi.
○ Ukuguquguquka kwesloti okungenamkhawulo: Izithuba zeemodyuli ezi-4 zixhasa naluphi na udibaniso lweemodyuli zeBypass kunye neMonitor (umz., i-4 Bypass, i-4 Monitor, i-2 Bypass + i-2 Monitor)—akukho slot locking kwiintlobo ezithile zeemodyuli.
○ Inkxaso yekhonkco enoxinano olukhulu: Ngokusekelwe kwiindidi zemodyuli, esi sixhobo sixhasa ukhuseleko olulandelelanayo ukuya kuthi ga kwi-161G/10GE optical links okanye i-840G/100GE optical links—ukuhlangabezana neemfuno zenethiwekhi ze-high-bandwidth zoshishino kunye neziko ledatha.
○ Ukubeka esweni uxinano oluphezulu: Esi sixhobo sixhasa ukuya kuthi ga kwi-641G/10GE monitoring interfaces okanye i-1640G/100GE monitoring interfaces—evumela ukubekwa kweliso okukhulu kunye nokufakwa kwezixhobo zokhuseleko.
○ Ukutshintshana okushushu kuyasebenza: Zonke iimodyuli zeBypass kunye neMonitor zixhasa ukutshintshiselana kwe-hot-swap—okuvumela ukutshintshwa kwemodyuli, ukuphuculwa, okanye ukulungiswa ngaphandle kwexesha lokungasebenzi kwenethiwekhi okanye utshintsho loqwalaselo.
Olu tshintsho lwemodyuli lwenza i-ML-NPB-M2000 ibe lutyalo-mali oluya kuqinisekisa ikamva—imibutho inokuphucula isantya sayo sonxibelelwano, ukhuseleko lokhuseleko, okanye amandla okubeka esweni ngokutshintshiselana nje ngeemodyuli (ukungatshintshi yonke itshasi), ukunciphisa iindleko zizonke zobunini (i-TCO) kunye nokuziqhelanisa neemfuno zenethiwekhi eziguqukayo kwiminyaka ezayo.
5. Amandla okucubungula iiTrafikhi ngoBukrelekrele: Iindlela zokusasazwa ezikwi-Inline kunye ne-SPAN
Eyona nto inamandla kwiMylinking ML-NPB-M2000 yinkxaso yayo yendlela yokuhambisa ezimbini: Ukuthunyelwa kwe-Inline (serial) yokukhusela isixhobo se-Inline Security kunye nokunyamezela iimpazamo (ukusebenzisa amandla ayo e-Inline Bypass Switch, i-Network Bypass Tap, kunye ne-Smart Bypass Switch) kunye nokuthunyelwa kwe-SPAN (passive) yokubeka iliso kwiNethiwekhi kunye nokuqhubekeka kwethrafikhi (ukusebenzisa ukusebenza kwayo kwe-Network Packet Broker (NPB). Ezi ndlela zimbini zisebenza ngokuzimeleyo okanye ngaxeshanye (Inline + SPAN), okuvumela i-ML-NPB-M2000 ukuba ijongane nayo yonke imfuno yoKhuseleko lweNethiwekhi kunye nokubeka iliso kuzo zonke iindawo zenethiwekhi eziphambili—ukusuka kwiingcango ze-intanethi kunye notshintsho oluphambili ukuya kwiifama zeseva yeziko ledatha kunye neekhonkco zeqonga lefu.
5.1 Indlela Yokusasazwa Kwi-Inline – Ukhuseleko Lokhuseleko Kwi-Inline Lwe-Zero-Downtime
Ukufakwa kwe-inline yindlela ephambili yokukhusela isixhobo se-Inline Security, apho i-ML-NPB-M2000 isetyenziswa kuthotho phakathi kwezixhobo zenethiwekhi (ii-routers, ii-switches) kunye nezixhobo zokhuseleko ze-inline (FW/IPS/Anti-DDoS/WAF). Kule ndlela, isebenza njenge-Smart Bypass Switch kunye ne-Inline Bypass Tap, inika ukunyamezela iimpazamo, ukusebenza kwe-zero-downtime, kunye nokutsalwa kwethrafikhi ekhethiweyo—ngexesha idibanisa amandla okucubungula ithrafikhi ye-NPB. Iimpawu eziphambili zokufakwa kwe-Inline ziquka:
○ Ukhuseleko oluKhethekileyo/Lonke iTrafikhi eLungileyo: Iindlela zeSpecFlow™/FullLink™ zokuhlola ukhuseleko olujoliswe kulo okanye olupheleleyo (ukuchonga ithrafikhi ye-L2-L4).
○ Ukulinganisela Umthwalo Okrelekrele: Sabalalisa ithrafikhi kwizixhobo zokhuseleko ezidityanisiweyo ukuze kulawulwe ithrafikhi ephezulu ye-bandwidth (ukuthembeka kweseshoni kugciniwe).
○ <8ms Ukutshintsha i-Bypass ekhawulezayo: Ukudlula ngokuzenzekelayo kwezixhobo zokhuseleko ezineziphene kunye nefuthe elincinci kwinethiwekhi (iTekhnoloji yeLinkSafeSwitch™).
○ Ukuchonga Ukubetha Kwentliziyo Ngamacala Ahlukeneyo: Ukubeka esweni impilo ngexesha langempela kwezixhobo zokhuseleko ezikwi-intanethi ezineeparamitha ezinokwenziwa ngokwezifiso.
○ Ukuthintela iimoto: Vimbela iipakethi ezingekho mthethweni/ezingaqhelekanga ngokusekelwe kwiimeko zesihluzi ezihambelanayo ezi-5-tuple—ukuqinisekisa ukhuseleko lwenethiwekhi.
○ Ukujonga iiModeli zeTrafikhi: Jonga ithrafikhi edibeneyo emgceni ukuya kwizixhobo zokubeka esweni ezingaphandle kwebhendi (IDS/NPM/APM) ukuze kubekwe esweni inethiwekhi ngendlela engasebenziyo—akukho mpembelelo ekuqhubekeni kokhuseleko olungaphakathi.
○ I-Proxy ye-SSL ecacileyo: Susa i-trafikhi efihliweyo ukuze kuhlolwe ukhuseleko, uze uphinde uyi-encrypt ukuze idluliselwe—ukuvula ukubonakala kwe-trafikhi efihliweyo.
5.2 Indlela yoSetyenziso lwe-SPAN – Ukucutshungulwa kweTrafikhi ye-NPB ePhambili yoBeko-liso lweNethiwekhi
Ukufakwa kwe-SPAN yindlela engasebenziyo yokubeka iliso kwiNethiwekhi, apho i-ML-NPB-M2000 isetyenziselwa ukuhlanganisa, ukucubungula, nokusasaza ithrafikhi ukusuka kwiichweba ze-SPAN zenethiwekhi ukuya kwizixhobo zokubeka iliso/uhlalutyo (i-IDS, i-NPM, i-APM, i-SIEM). Kule ndlela, isebenza njenge-Network Packet Broker (NPB) epheleleyo, enikezela ngezakhono ezisisiseko neziphambili zokucubungula ithrafikhi—ukuvula ukubonakala kwethrafikhi okuncinci, ukunciphisa ukubanjwa kwepakethi okungafunekiyo, kunye nokwenza ngcono ukusebenza kwesixhobo sokubeka iliso. Amandla okucubungula i-SPAN e-ML-NPB-M2000 awanakuthelekiswa nanto kushishino, kunye neempawu ezingaphezulu kwama-30 eziphambili ezahlulwe zibe kukucubungula ithrafikhi okusisiseko kunye nokucubungula ithrafikhi okuphambili:
5.2.1 Inkqubo Esisiseko Yezithuthi (i-SPAN)
Amandla e-NPB asisiseko okwenza ngcono ukusasazwa kwethrafikhi kunye nokuBekwa esweni kweNethiwekhi okusisiseko:
○ Ukuphindaphinda/Ukuqokelelana/Ukusasazwa kweTrafikhi: 1:N replication, N:M aggregation, kunye nokusasazwa ngokuchanekileyo kwetrafikhi kwizixhobo zokubeka esweni—ukususa ukubanjwa kweepakethe okungafunekiyo.
○ Ukucoca iiTrafikhi ezi-5-Tuple: Ukucoca ithrafikhi ye-granular ngokusekelwe kwi-IP/protocol/port 5-tuple, uhlobo lwe-Ethernet, i-VLAN tag, kunye neempawu zepakethe (imithetho yoluhlu olumhlophe/uluhlu olumnyama).
○ Ulawulo lwe-VLAN: Ukuthega, ukuguqula, kunye nokucima i-VLAN—okuvumela ukwahlulwahlulwa kwetrafikhi kunye nokwenziwa kwendawo.
○ Ukubeka ixesha ngokuchaneka kweNanosecond: Ukunyathelisa ixesha kweepakethi nge-NTP (ukuchaneka kwe-nanosecond) ukusombulula iingxaki kunye nokuhambelana kwelog.
○ Ukuhluba iTunnel Encapsulation: Strip VXLAN, GRE, GTP, MPLS, IPIP, kunye ne-SRV6 tunnel headers—ivula ukubonakala kwitrafikhi eneetunnel.
○ Ukusikwa kwePakethi: Ukusikwa kweepakethi ngokwezifiso (ii-byte ezingama-64–960) ukunciphisa ukudluliselwa kwedatha okungeyomfuneko kwizixhobo zokubeka esweni—ukunciphisa ukusetyenziswa kwe-bandwidth.
○ Ukuchongwa kweProtocol yoThungelwano: Ukuchongwa ngokuzenzekelayo kwe-GTP/GRE/VXLAN/PPTP/L2TP/PPPOE/IPIP—okuvumela ukuthunyelwa kwethrafikhi okusekelwe kumgaqo-nkqubo.
○ Ukuthunyelwa kwePakethi Okuphambili: Chaza ukubaluleka kwetrafikhi ngokusekelwe kukubaluleka kwenkonzo—ukuqinisekisa ukuba iipakethi eziphambili zithunyelwa kuqala ukuze kuthintelwe ukujonga ii-alamu zezixhobo.
5.2.2 Ukulungiswa kweTrafikhi okuPhambili (i-SPAN)
Amandla e-NPB akumgangatho weshishini okusombulula imingeni enzima yokuJonga iNethiwekhi kunye nokhuseleko (afumaneka kuphela kwiimodyuli ze-CN98 advanced function engine Monitor):
○ Ukususwa kwe-SSL: Susa ukubethela ithrafikhi ye-HTTPS/SSL/TLS ukuze ijongwe/ihlalutywe (inkxaso ye-TLS1.0/TLS1.2/SSL3.0).
○ Ukususwa kweTrafikhi: Ukunikezelwa kweepakethi eziphindwe kabini ngePort/policy—ukunciphisa izixhobo zokubeka esweni ii-alamu zobuxoki kunye nomthwalo wokucubungula.
○ Ukufihla idatha: Ukufihla amasimi edatha ayimfihlo ngokusekelwe kumgaqo-nkqubo (umz., iinombolo zekhadi letyala, ulwazi lomntu)—ukuqinisekisa ukuthotyelwa kwemigaqo yobumfihlo bedatha.
○ Uhlolo lweDPI Deep Packet: Chonga iiprotokholi zomaleko wesicelo ezingaphezu kwe-1800 (iaudio/ividiyo, imidlalo, i-IM, isiseko sedatha, i-imeyile, i-P2P) ngelayibrari yeempawu ze-DPI enokuhlaziywa—ukuvula ukubonakala kwethrafikhi kwinqanaba lesicelo.
○ Ukususa iicapsules kwiPakethi yakho: Hluba amasimi e-encapsulation alungiselelwe wena kwiibhayithi zokuqala ezili-128 zeepakethi—ukuziqhelanisa neeprotokholi zenethiwekhi ezizimeleyo.
○ Ukubunjwa kweTrafikhi: Ukuphuma kwethrafikhi ngendlela etyibilikayo kwizixhobo zokubeka esweni ngokusebenzisa iteknoloji yokubumba—ukususa ukulahleka kwepakethi kwimibhobho yethrafikhi.
○ Ukuthelekiswa kwamagama angundoqo epakethi: Thelekisa umxholo wentsimi yomthwalo womvuzo kwaye udlulisele phambili/ulahlele iipakethi/iiseshoni ezinxulumene noko—okuvumela ukufunyanwa kwengozi ekujoliswe kuyo.
○ Uqhagamshelo Oluhlala Ixesha Elide Luyakhutshwa: Lahla ithrafikhi yoqhagamshelo ehlala ixesha elide emva kokubanjwa kokuqala—ukunciphisa umthwalo wokucubungula izixhobo zokubeka esweni.
○ Isiphumo sokuVala iTunnel: Faka ithrafikhi eqokelelweyo kwiitonela ze-ERSPAN2/GRE/VXLAN/NVGRE—ukuhambisa ithrafikhi kwiinkqubo zokujonga/zohlalutyo ezikude.
○ Ukupheliswa kwePakethi yeTunnel: Lungiselela iidilesi ze-IP/MAC zeeports zokungenisa ithrafikhi ukuze zifumane ithrafikhi eneetoneli (GRE/GTP/VXLAN) ngokuthe ngqo—ukwenza kube lula ukuqokelelwa kwethrafikhi ekude.
5.3 Ukusasazwa kwe-Inline + SPAN Hybrid – Ukhuseleko oluManyeneyo kunye nokuBeka esweni
Amandla okwenyani e-ML-NPB-M2000 avuliwe kwi-Inline + SPAN hybrid deployment, apho ibonelela ngokhuseleko lwe-Inline Security (imo ye-Inline) kunye ne-inline passive Network Monitoring (imo ye-SPAN) ngexesha elinye. Kule mo, isixhobo sibonisa i-inline link traffic kwizixhobo zokubeka iliso ngaphandle kwebhendi ngelixa sikhusela izixhobo zokhuseleko ezikwi-inline kwi-disappency—sinikezela ngesisombululo esidibeneyo soKhuseleko lweNethiwekhi kunye nokubeka iliso ngaphandle kwe-silos, akukho hardware eyongezelelweyo, kwaye akukho mpembelelo yokusebenza kwenethiwekhi. Le mo ye-hybrid yeyona ndlela ifanelekileyo yokubeka i-key nodes ezibalulekileyo zenethiwekhi (umz., ii-intanethi, ii-data center core switches), apho zombini ukhuseleko oluqhubekayo kunye nokubonakala kwethrafikhi ngexesha langempela kungaxoxiswana.
5.4 Uhlalutyo Olupheleleyo Lokubonakala Kweemoto kunye Neempazamo
Inxalenye ephambili yokusebenza kwe-ML-NPB-M2000's Network Packet Broker (NPB) yimodyuli yayo edibeneyo yokubonakala kwethrafikhi kunye nohlalutyo lweempazamo—ujongano lwemizobo olusebenziseka lula olubonelela ngokuBekwa kweliso kweNethiwekhi okunemilinganiselo emininzi, ngexesha langempela kunye nokubekwa kwempazamo ngokuchanekileyo. Le modyuli iguqula idatha yethrafikhi engacwangciswanga ibe yingqiqo enokwenzeka, enezakhono ezintathu eziphambili zokuhlalutya:
○ Uhlalutyo oluSisiseko lweTrafikhi: Izibalo-manani ezishwankathelweyo (ukubalwa kwepakethi, ukusasazwa kwe-unicast/multicast/ukusasazwa, ukubalwa kweeseshoni, ukusasazwa kweprotocol) kunye neetshathi zendlela yethrafikhi ngexesha langempela.
○ Uhlalutyo olunzulu lwe-DPI: Umlinganiselo weprotocol yomaleko wothutho, udidi lwetrafikhi ye-IP, usasazo lweprotocol yesicelo se-DPI, kunye nohlalutyo lwetrafikhi olusekelwe kumgca wexesha (ukuchaneka kwe-1ms) kunye nezilayidi zexesha ezisebenzisanayo.
○ Uhlalutyo lweZiphene oluchanekileyo: Ukubekwa kwindawo yempazamo enamaleko amaninzi kuquka ukujonga okungaqhelekanga, uhlalutyo lwempazamo kwinqanaba letafile yokuhamba (ukungavumi konxibelelwano/ukungaphenduli), uhlalutyo lwempazamo kwinqanaba lepakethi (iimpazamo ze-checksum/TTL 0), uhlalutyo lwempazamo yokhuseleko (uhlaselo lwe-DDoS/ARP/ukuvimba i-firewall), kunye nohlalutyo lwempazamo yenethiwekhi (ukutshintsha/ukuhambisa iilophu/ukuphazamiseka kwekhonkco).
○ Uhlalutyo lwezibalo zeTrafikhi: Uhlu lwe-TOPN lwexesha langempela lweedilesi ze-IP, iiprotokholi zesicelo, kunye neeseshoni zethrafikhi—kunye nokuboniswa kwetshathi kunye nokuthunyelwa kwefayile zasekuhlaleni ukuze kuthotyelwe imithetho kunye nengxelo.
Le modyuli yokubonakala kwetrafikhi isusa isidingo sezixhobo zokubeka esweni ezizimeleyo, inciphisa ubunzima bokusebenza kwaye ivumela amaqela e-IT ukuba aqaphele ngokukhawuleza, asombulule iingxaki, kwaye asombulule iimpazamo zenethiwekhi kunye nokhuseleko—ukunciphisa ixesha lokungasebenzi kunye nomngcipheko weshishini.
6. Iinkcukacha zoBugcisa eziBanzi ze-ML-NPB-M2000
I-Mylinking ML-NPB-M2000 yenzelwe ukuhlangabezana neemfuno zobugcisa ezingqongqo zenethiwekhi yeshishini, iziko ledatha, kunye neqonga lefu—inikezela ngokusebenza okungagungqiyo, ukuthembeka, kunye nokukhula njenge-Network Packet Broker (NPB) edibeneyo kunye ne-Inline Bypass Switch. Apha ngezantsi kukho uhlalutyo olupheleleyo lweenkcukacha zobugcisa bayo bezinga leshishini, ezicwangciswe ngokwecandelo elisebenzayo ukuze kube lula ukubhekisela kulo:
6.1 Iinkcukacha zeNethiwekhi ePhambili kunye neNxibelelwano
| Ipharamitha | Inkcazo |
|---|---|
| Uhlengahlengiso lweMveliso | I-Mylinking ML-NPB-M2000 Network Packet Broker (NPB) + Iswitshi ye-Inline Bypass |
| Ifomu Factor | I-rackmount eqhelekileyo ye-2U eyi-19-intshi (444mm)88mm670mm) |
| IiSlots zeModyuli | Izithuba ezi-4 ezishushu nezitshintshanayo (umxube we-Bypass/Monitor) |
| Iikhonkco eziKhuselekileyo kakhulu | 16Iikhonkco ze-optical ze-1G/10GE okanye ezi-8Iikhonkco ze-optical ze-40G/100GE |
| Ujongano oluPhezulu lokujonga | 641G/10GE okanye 1640G/100GE |
| Iindlela zoLawulo | 1Ikhonsoli ye-RS232 (115200,8,N,1); 110/100/1000M RJ45 ngaphandle kwebhendi mgmt |
| Ubuchule bokucubungula | 2.4Tbps full-duplex (ukudlulisela phambili ngesantya sentambo esikhawulezileyo se-ASIC) |
| Utshintsho lwe-Bypass | <8ms (ekhokela ishishini) |
6.2 Imisebenzi yokusasazwa kunye neNkqubo
| Udidi lomsebenzi | Iimpawu ezixhaswayo |
|---|---|
| Iindlela zokusasazwa | I-Inline (serial), i-SPAN (passive), i-Inline + i-SPAN hybrid |
| Imisebenzi yeModi ePhakathi | Ukhuseleko lweSpecFlow™/FullLink™, ukulinganisela umthwalo, ukufumanisa ukubetha kwentliziyo, ukudlula ngokukhawuleza, ukuvimba/ukuhombisa ithrafikhi, iproksi ye-SSL |
| Imisebenzi esisiseko yeModi ye-SPAN | Ukuphindaphinda/ukuhlanganisa/ukusasazwa kwetrafikhi, ukucoca nge-5-tuple, ulawulo lwe-VLAN, ukubethela ixesha, ukususa imisele, ukusika iipakethe |
| Imisebenzi ePhambili yeMowudi ye-SPAN | Ukususwa kwe-SSL, ukususwa kwetrafikhi, ukufihla idatha, i-DPI (iiprotokholi ezingaphezu kwe-1800), ukubunjwa kwetrafikhi, ukufanisa amagama angundoqo, ukukhutshelwa konxibelelwano oluhlala ixesha elide |
| Ukubonakala kweTrafikhi | Uhlalutyo olusisiseko, uhlalutyo olunzulu lwe-DPI, uhlalutyo oluchanekileyo lwempazamo, uhlalutyo lwezibalo (ukuboniswa kwetshathi/ukuthunyelwa kwamanye amazwe) |
| Iimpawu zokuthembeka | Ukutshintshana kweModule ngokushushu, ukudlula okungekho mthethweni, i-interface hot backup (1+1), ukhuseleko lokuxinana kwe-interface, umlinganiselo we-traffic microburst |
6.3 Ulawulo kunye noQinisekiso
| Udidi loLawulo | IiProtocols/Izixhobo ezixhaswayo |
|---|---|
| Ulawulo Olukude | I-HTTP/WEB GUI, i-TELNET/SSH CLI (EasyConfig/AdvanceConfig), i-SNMP V1/V2C, i-SYSLOG |
| Uqinisekiso | Ugunyaziso olusekwe kumagama ayimfihlo, i-AAA, i-TACACS+/RADIUS |
| Ukurekhoda kunye nokuNika ingxelo | Ukubeka iliso kwi-alamu ngexesha langempela, iirekhodi ze-alamu zembali, ukuthunyelwa ngaphandle kwezibalo zethrafikhi |
6.4 Iinkcukacha zoMbane kunye nokusingqongileyo (kwizinga lezeMveliso)
| Udidi | Inkcazo |
|---|---|
| Ukunikezwa Amandla | I-AC-220V okanye i-DC-48V (amandla amabini, ayinyanzelekanga) |
| Ubuninzi bamandla | I-AC-50Hz |
| Igalelo langoku | I-AC-3A / DC-10A |
| Ukusetyenziswa kwamandla aphezulu | 300W |
| Ubushushu bokusebenza | 0℃ – 50℃ (32°F – 122°F) |
| Ubushushu bokugcina | -20℃ – 70℃ (-4°F – 158°F) |
| Ukufuma okusebenzayo | 10% – 95% (ayifumi) |
| Umswakama wokugcina | 5% – 95% (ayifumi) |
Ezi nkcukacha ziqinisekisa i-ML-NPB-M2000 njenge-NPB edibeneyo kunye ne-Inline Bypass Switch esebenza kakuhle, ekumgangatho wezoshishino—eyenzelwe ukusebenza iiyure ezingama-24/7 kwiindawo ezifuna kakhulu amashishini, iziko ledatha, kunye neqonga lamafu.
7. Iimeko zeSicelo seShishini lokwenyani
Iindlela ezimbini zokusasazwa kweMylinking ML-NPB-M2000, ukuguquguquka kwemodyuli, kunye nobuchule bokucubungula ithrafikhi obuphambili buyenza ifaneleke kuzo zonke iindawo zenethiwekhi yeshishini—ukusuka kwiingcango ze-intanethi kunye notshintsho oluphambili ukuya kwiifama zeseva yeziko ledatha, amakhonkco eqonga lefu, kunye nonxibelelwano lweofisi yesebe. Apha ngezantsi kukho iimeko ezili-10 eziphambili zesicelo apho iML-NPB-M2000 inikezela ngexabiso elikhulu, ijongana nemingeni ethile yoKhuseleko lweNethiwekhi kunye nokuBekwa kweliso kweNethiwekhi kwaye isebenzisa amandla ayo apheleleyo njengeNetwork Packet Broker (NPB), iSmart Bypass Switch, iNetwork Bypass Tap, kunye neInline Bypass Tap:
7.1 Ukhuseleko lweSixhobo soKhuseleko lwe-Inline Link Series
○ Umngeni: Ukusilela okanye ukulungiswa kwesixhobo sokhuseleko esikwi-intanethi enye (FW/IPS) kubangela ukungasebenzi kwenethiwekhi.
○ Isisombululo: Sebenzisa i-ML-NPB-M2000 kwimo ye-Inline phakathi kwezixhobo zenethiwekhi kunye nezixhobo zokhuseleko—ukuchonga ukubetha kwentliziyo okukrelekrele kunye nokutshintsha kwe-<8ms bypass ukuqinisekisa ukuba akukho xesha lokungasebenzi ukuba isixhobo sokhuseleko asiphumeleli okanye sikhutshwa ngaphandle kwe-intanethi ukuze silungiswe.
○ Inzuzo ephambili: Unxibelelwano lwenethiwekhi olungenaziphazamiso kunye nokhuseleko oluhlala iiyure ezingama-24 ngosuku, iintsuku ezisixhenxe ngeveki.
7.2 Ukhuseleko loKhuseleko oluQhubekekileyo lweSpecFlow™
○ Umngeni: Lonke ithrafikhi inyanzeliswa zizixhobo zokhuseleko, ichitha izixhobo zokucubungula kwaye inyusa ukubambezeleka.
○ Isisombululo: Sebenzisa imo yeSpecFlow™ ukuhambisa iintlobo ezithile zetrafikhi (umz., idatabase/SSH/trafikhi efihliweyo) kwizixhobo zokhuseleko—trafikhi enganxulumananga ithunyelwa ngqo.
○ Inzuzo ephambili: Umthwalo wezixhobo zokhuseleko onciphileyo, ukubambezeleka okuphantsi, kunye nokuhlolwa kokhuseleko okujoliswe kuko.
7.3 Ukhuseleko loKhuseleko oluLungelelanisiweyo loMthwalo (iBandwidth ephezulu)
○ Umngeni: Isixhobo esinye sokhuseleko asinakukwazi ukusingatha ithrafikhi ephezulu ye-10/40/100GE, nto leyo ekhokelela ekulahlekelweni yi-latency/ipakethi.
○ Isisombululo: Sebenzisa i-ML-NPB-M2000's dynamic load balancing ukuze iqokelele izixhobo zokhuseleko ezininzi—Ukusasazwa kwetrafikhi okusekelwe kwiHash kuqinisekisa ukuthembeka kweseshoni kunye nokusetyenziswa kwezixhobo ezifanelekileyo.
○ Inzuzo ephambili: Ubungakanani bokukwazi ukucwangcisa ukhuseleko kunye nenkxaso yethrafikhi ephezulu ye-bandwidth.
7.4 Utshintsho loQhagamshelwano lwePhysical-to-Logical
○ UmngeniIzixhobo ezininzi zokhuseleko ezibonakalayo zenza ii-SPOF ezininzi kunye nokubambezeleka okubalulekileyo.
○ Isisombululo: I-ML-NPB-M2000 iguqula ukuthunyelwa kwe-serial ebonakalayo ibe yi-physical parallel + logical serial—zonke izixhobo zokhuseleko ziqhagamshela kwi-ML-NPB-M2000, etsala ithrafikhi kwisixhobo ngasinye xa kuyimfuneko.
○ Inzuzo ephambili: Isusa ii-SPOF ezininzi, inciphisa ukubambezeleka, kwaye ivumela ukugcinwa kwezixhobo zokhuseleko nganye nganye ngaphandle kwexesha lokungasebenzi kwenethiwekhi.
7.5 Ulawulo lweTrafikhi oluSekelwe kwiMigaqo-nkqubo eDynamic (Anti-DDoS)
○ Umngeni: Indlela yokulawula ithrafikhi ye-Anti-DDoS (BGP) yendabuko iyinkimbinkimbi kwaye ifuna utshintsho kwi-topology yenethiwekhi.
○ Isisombululo: Hlanganisa i-ML-NPB-M2000 nezixhobo ze-Anti-DDoS ngokusebenzisa i-WebService™ dynamic policy forwarding—i-traffic enonya ithunyelwa kwizixhobo ze-Anti-DDoS ngexesha langempela, kungekho tshintsho kwinethiwekhi.
○ Inzuzo ephambili: Impendulo yosongelo ngexesha langempela, ukuxhomekeka okuphantsi kwenethiwekhi, kunye nokubambezeleka okuncinci kwitrafikhi eqhelekileyo.
7.6 Ukubeka iliso kuKhuseleko oluPhandle kweBand olungaphakathi + olungaphandle kwe-SPAN
○ Umngeni: Imfuneko yokhuseleko olukwi-intanethi ngaxeshanye kunye nokubeka iliso kwinethiwekhi ngaphandle kwezixhobo ezongezelelweyo.
○ Isisombululo: Ukufakwa kweHybrid Inline + SPAN—ML-NPB-M2000 ikhusela izixhobo zokhuseleko ezikwi-intanethi ngelixa ilinganisa ithrafikhi kwizixhobo zokujonga ezingaphandle kwebhendi (IDS/NPM/APM).
○ Inzuzo ephambili: Ukhuseleko oludibeneyo kunye nokubeka iliso, akukho zi-silos, akukho zindleko zongezelelweyo zehardware.
7.7 Ukususwa kweTrafikhi ukuze kujongwe ukuSebenzisa izixhobo
○ Umngeni: Iipakethi eziphindwe kabini zibangela izixhobo zokubeka esweni ii-alamu zobuxoki kunye nomthwalo wokucubungula owandisiweyo.
○ Isisombululo: Sebenzisa i-ML-NPB-M2000's port/policy-based traffic draplication ukususa iipakethi eziphindwe kabini ngaphambi kokuba zifikelele kwizixhobo zokubeka esweni.
○ Inzuzo ephambili: Ukunciphisa ii-alamu zobuxoki, umthwalo wezixhobo zokubeka esweni ophantsi, kunye nokuchaneka kohlalutyo okuphuculweyo.
7.8 Ukuthegiwa kwe-VLAN kwe-Traffic Anomaly Localization
○ Umngeni: Ayikwazi ukufumana ngokukhawuleza umthombo weengxaki zenethiwekhi/ukwaphulwa kokhuseleko.
○ IsisombululoSebenzisa i-ML-NPB-M2000's VLAN tagging ukuze ulebhelise ithrafikhi evela kwii-network nodes ezahlukeneyo—izixhobo ze-backend zinokulandela izinto ezingaqhelekanga kumthombo ochanekileyo ngee-VLAN tags.
○ Inzuzo ephambili: Ukukhawuleza kokufumana iimpazamo, ukunciphisa ixesha lokusombulula iingxaki, kunye nokuphuculwa kokubonakala kwenethiwekhi.
7.9 UkuCwangciswa kweTrafikhi yeNethiwekhi eManyeneyo (Iziko leDatha)
○ Umngeni: I-Disparate 10/40/100GE link traffic kunzima ukuyihlanganisa nokuyisasaza kwizixhobo zokubeka esweni/zokhuseleko.
○ Isisombululo: Sebenzisa i-ML-NPB-M2000 njengomcwangcisi wethrafikhi ophakathi—hlanganisa zonke iithrafikhi zekhonkco, zihluze/zinqumle, uze uzisasaze kwizixhobo ezifanelekileyo.
○ Inzuzo ephambili: Ulawulo lwendlela oluphakathi, ubunzima bokusebenza obuncitshisiweyo, kunye nokusetyenziswa kwezixhobo ngendlela efanelekileyo.
7.10 Uhlalutyo olupheleleyo lokubonakala kweTrafikhi kwiNethiwekhi
○ Umngeni: Ukungabikho kokubonakala kwetrafikhi ngexesha langempela, ubukhulu becala kunye nokukwazi ukuhlalutya iimpazamo.
○ Isisombululo: Sebenzisa imodyuli yokubonakala kwethrafikhi edibeneyo ye-ML-NPB-M2000—uhlalutyo olunzulu olusisiseko/i-DPI kunye nohlalutyo oluchanekileyo lwempazamo unikeze ulwazi olusebenzisekayo nge-interface yemizobo esebenziseka lula.
○ Inzuzo ephambili: Ukubeka iliso kwinethiwekhi ngexesha langempela, ukusombulula iimpazamo ngokukhawuleza, kunye nezibalo zethrafikhi ezilungele ukuthobela imithetho.
8. Iingenelo zoKhuphiswano zeMylinking ML-NPB-M2000
Kwimarike exineneyo yezisombululo zeNetwork Packet Broker (NPB) ezizimeleyo kunye ne-Inline Bypass Switch, iMylinking ML-NPB-M2000 ivelele njengeqonga eliphambili elihlanganisiweyo loKhuseleko lweNethiwekhi kunye nokubeka iliso kwishishini, iziko ledatha, kunye neenethiwekhi zamafu. Indibaniselwano yayo eyahlukileyo yokudibanisa, ukusebenza, ukuguquguquka, kunye nobukrelekrele inika umda wokhuphiswano ongenakulinganiswa nasisombululo esizimeleyo—okwenza ukuba ibe lolona khetho luphezulu kwimibutho ebeka phambili ukuthembeka kwenethiwekhi, ukhuseleko, kunye nokubonakala. Apha ngezantsi kukho izibonelelo ezili-10 eziphambili zokhuphiswano ezichaza i-ML-NPB-M2000:
8.1 Udibaniso olungazange lubonwe ngaphambili: I-NPB + I-Inline Bypass Switch kwi-One Platform
I-ML-NPB-M2000 sisisombululo sokuqala seshishini esikumgangatho ophezulu ukuhlanganisa ukucutshungulwa kwetrafikhi yeNetwork Packet Broker (NPB) nge-Inline Bypass Switch fault tolerance—ukususa ukuthunyelwa kwe-siloed, ukunciphisa iintambo ezibonakalayo, kunye nokunciphisa ubunzima bokusebenza. Akukho sisombululo sinikezela ngolu nqanaba lokudibanisa, okwenza i-ML-NPB-M2000 ibe yindawo enye yoKhuseleko lweNethiwekhi kunye nokuBekwa kweliso kweNethiwekhi.
8.2 Umthamo wokucubungula ohamba phambili kwi-2.4Tbps
Ngomthamo wokucubungula we-ASIC okhawulezileyo we-2.4Tbps kunye nenkxaso yeekhonkco ze-10/40/100GE, i-ML-NPB-M2000 ihambelana neemfuno zokusebenza zeziko ledatha elinobubanzi obuphezulu kunye neenethiwekhi eziphambili zeshishini—ezihambisa ukuthunyelwa kwe-wire-speed ngaphandle kokuthintela, nokuba kusetyenzwa imithetho enzima yendlela.
8.3 Uyilo oluQhelekileyo noluTshintshisayo oluSetyenziswayo
Iisloti zemodyuli ezine ezitshintshatshintshayo ezisetyenziswa kwihlabathi liphela zixhasa naluphi na udibaniso lweemodyuli zeBypass kunye neMonitor—ezivumela uqwalaselo olwenziwe ngokwezifiso kuzo zonke iimfuno zenethiwekhi kunye nokugcinwa/ukuphuculwa ngaphandle kwexesha lokungasebenzi kwenethiwekhi. Olu guqulelo lwemodyuli lwenza i-ML-NPB-M2000 ingabi naxesha elizayo, ngaphandle kokuphelelwa lixesha kwehardware njengoko iimfuno zenethiwekhi zitshintsha.
8.4 Iindlela zokuSebenza kabini (Inline/SPAN) + Hybrid Inline + SPAN
Inkxaso yeendlela zokusasazwa kwe-Inline, SPAN, kunye ne-hybrid Inline + SPAN zibonelela ngokuguquguquka okungenakuthelekiswa nanto—zilungelelanisa zonke iindawo zesitshixo senethiwekhi kunye nemeko yokusetyenziswa, ukusuka kukhuseleko lokhuseleko olungaphakathi ukuya ekujongeni ngaphandle. Akukho NPB ezimeleyo okanye i-Inline Bypass Switch enika olu nqanaba lokuguquguquka kokusasazwa.
8.5 I-Native SSL Proxy/Decryption – Ukususa iiNdawo eziFihlileyo zeTrafikhi
I-Native SSL proxy kunye nobuchule bokuguqulela ulwazi (TLS1.0/TLS1.2/SSL3.0) zivula ukubonakala kwitrafikhi efihliweyo— uphawu olubalulekileyo olungekhoyo kwizisombululo ezininzi ze-NPB ezizimeleyo kunye ne-bypass. Oku kuqinisekisa ukuba imibutho inokuhlola itrafikhi efihliweyo ukuze ibone imisebenzi enobungozi ngaphandle kokuphazamisa ukhuseleko oluvela ekupheleni ukuya ekupheleni.
Ukutshintsha i-Sub-8ms Fast Bypass kunye nokusebenza kwe-Fail-Open
Utshintsho oluhamba phambili kwi-<8ms bypass switching latency kunye nokusebenza okuvulayo okungaphumeleli kuqinisekisa ukuba akukho xesha lokungasebenzi kwenethiwekhi—nokuba izixhobo zokhuseleko ezikwi-intanethi okanye i-ML-NPB-M2000 ngokwayo ifumana impazamo. Olu nyamezelo lwempazamo alunakuthelekiswa nezisombululo ze-NPB ezizimeleyo, ezingenazo izakhono zendalo zokudlula.
I-8.7 DPI yeeProtocols zeSicelo ezingaphezu kwe-1800 (iThala leeNcwadi eliHlaziyiweyo)
Ukuhlolwa kwepakethi enzulu ye-DPI edibeneyo kwiiprotokholi zomaleko wesicelo ezingaphezu kwe-1800 (enelayibrari yeempawu ezinokuphuculwa) ibonelela ngokubonakala kwethrafikhi kwinqanaba lesicelo- okuvumela ukuhlolwa kokhuseleko okujoliswe kuko kunye nokuBekwa esweni kweNethiwekhi kwiinethiwekhi zanamhlanje ezisebenzisa izicelo ezininzi.
8.8 Ukubonakala Okubanzi Kweemoto kunye noHlalutyo Oluchanekileyo Lweempazamo
Imodyuli edibeneyo nelula ukuyisebenzisa inika uhlalutyo olunzulu lwesiseko/i-DPI olunemilinganiselo emininzi kunye neenkcukacha ezichanekileyo zokufumana iimpazamo—isusa isidingo sezixhobo zokubeka esweni ezizimeleyo kunye nokunciphisa iindleko zokusebenza.
8.9 Udibaniso olungenamthungo lweQela lesithathu (uMgaqo-nkqubo oDynamic weWebService™)
Ukuthunyelwa kwemigaqo-nkqubo yeWebService™ enamandla kwenza kube lula ukuhlanganiswa ngexesha langempela nazo zonke izixhobo zoKhuseleko oluQhelekileyo kunye nokubeka esweni (FW/IPS/Anti-DDoS/SIEM)—okwenza i-ML-NPB-M2000 ibe yinto engabonakaliyo kwaye ihambelana nee-security stacks ezikhoyo (ukuthunyelwa kweyona ndlela ilungileyo).
8.10 Ukuthembeka phakathi kweShishini kunye nokunyamezelana phakathi kweShishini kunye noBume beNdalo
Umbane ombane ombini we-AC/DC, ukutshintshana kwe-hot module, i-interface hot backup, kunye nokunyamezela ubushushu/umswakama kwizinga lemizi-mveliso kuqinisekisa ukusebenza iiyure ezingama-24/7 kwiindawo ezinobungozi zedatha nakwiindawo zoshishino—okubonelela ngokuthembeka okufunekayo kwiziseko zophuhliso zenethiwekhi ezibalulekileyo.
Ngoko ke, kwixesha apho ixesha lokungasebenzi kwenethiwekhi libiza amashishini amawaka (okanye izigidi) zeedola ngomzuzu, kwaye izoyikiso ze-cyber zikhula ngokuphucuka ngakumbi ngemini, i-Mylinking ML-NPB-M2000 ingaphezulu nje kweNetwork Packet Broker (NPB) okanye i-Inline Bypass Switch—lutyalo-mali olucwangcisiweyo kuKhuseleko lweNethiwekhi, ukuthembeka, kunye nokubonakala. Ngokudibanisa ukucutshungulwa kwetrafikhi ye-NPB kunye nokunyamezela iimpazamo zeSmart Bypass Switch, iNetwork Bypass Tap, kunye ne-Inline Bypass Tap, isombulula iindawo eziphambili zokusetyenziswa kwemveli okuzimeleyo: ukususa ii-SPOF, ukuqinisekisa ukuba akukho xesha lokungasebenzi kwenethiwekhi, ukuvula ukubonakala kwetrafikhi okufihliweyo, kunye nokubonelela ngokuBekwa kweliso kweNethiwekhi ngexesha langempela kwishishini lanamhlanje, iziko ledatha, kunye neenethiwekhi zamafu.
Ngomthamo wayo wokucubungula we-2.4Tbps, uyilo oluguquguqukayo olutshintshatshintshayo, iindlela ezimbini zokusasazwa kwe-Inline/SPAN, i-native SSL proxy/decryption, ukuhlolwa kwepakethi enzulu ye-DPI, kunye nokubonakala kwethrafikhi epheleleyo, i-ML-NPB-M2000 sisisombululo esipheleleyo soKhuseleko lweNethiwekhi kunye nokubeka iliso kwimibutho efuna ukusebenza okungapheliyo, ukwandiswa, kunye nokuthembeka. Yenzelwe ukuhlangabezana neemfuno zeshishini ledijithali lanamhlanje—apho ukufumaneka kwenethiwekhi iiyure ezingama-24 ngosuku, ukhuseleko oluqinileyo, kunye nokubonakala kwethrafikhi ngokupheleleyo kungaxoxiswana ngako.
Thatha iNyathelo Elilandelayo ngeMylinking ML-NPB-M2000
Ukulungele ukutshintsha ukusasazwa kwakho koKhuseleko lweNethiwekhi kunye nokuBekwa kweliso kwiNethiwekhi, ukususa ii-silos, kunye nokuqinisekisa ukuba akukho xesha lokungasebenzi kwenethiwekhi?
○ Jonga iphepha lemveliso yeMylinking ML-NPB-M2000:https://www.mylinking.com/mylinking-network-packet-broker-plus-inline-bypass-switch-ml-npb-m2000-product/
○ Nxibelelana neqela lobuchwephesha leMylinking: Yenza ngokwezifiso uqwalaselo lwemodyuli oluhambelana nesantya sakho soqhagamshelwano se-10/40/100GE, uKhuseleko oluPhakathi, kunye neemfuno zokubeka iliso kwiNethiwekhi.
○ Cela idemo ephilayo: Jonga amandla e-ML-NPB-M2000 e-NPB + Inline Bypass Switch asebenzayo—kuquka i-zero-downtime bypass, i-SSL decryption, i-DPI, kunye nokubonakala kwethrafikhi—kwimeko ethile yenethiwekhi yakho.
○ Fumana ikowuteshini: Funda indlela i-ML-NPB-M2000 enciphisa ngayo iindleko zakho zizonke zobunini (i-TCO) ngokuphelisa i-NPB ezimeleyo kunye ne-pass hardware, ukunciphisa iindleko zokusebenza, kunye nokubonelela ngesisombululo senethiwekhi esikhuselekileyo kwixesha elizayo.
Nge-Mylinking ML-NPB-M2000, ungathumela i-Network Security and monitoring stack eqinileyo, enokulinganiswa, nedibeneyo—ngaphandle kokubeka emngciphekweni ukuthembeka kwenethiwekhi, ukusebenza, okanye ukubonakala kwayo.
Ixesha leposi: Matshi-26-2026



