Kumaha Cara Nyebarkeun Inline Bypass Tap pikeun Nyegah Overload atanapi Kacilakaan Alat Kasalametan?

The Bypass TAP (ogé disebut switch bypass) nyadiakeun palabuhan aksés anu gagal-aman pikeun alat kaamanan aktip anu dipasang sapertos IPS sareng firewall generasi saterusna (NGFWS). Saklar bypass disebarkeun antara alat jaringan sareng di payuneun alat kaamanan jaringan pikeun nyayogikeun titik isolasi anu dipercaya antara jaringan sareng lapisan kaamanan. Aranjeunna nyayogikeun dukungan lengkep pikeun jaringan sareng alat kaamanan pikeun ngahindarkeun résiko gangguan jaringan.

Solusi 1 1 Patalina Bypass Network Ketok (Bypass Switch) - Bebas

Aplikasi:

Ketok Jaringan Bypass (Bypass Switch) nyambung ka dua alat jaringan ngaliwatan palabuhan Link sareng nyambung ka server pihak katilu ngaliwatan palabuhan Alat.

Pemicu Ketok Jaringan Bypass (Bypass Switch) disetel ka Ping, anu ngirimkeun pamundut Ping berturut-turut ka server. Sakali server lirén ngaréspon kana ping, Ketok Jaringan Bypass (Bypass Switch) asup kana modeu bypass.

Nalika server mimiti ngaréspon deui, Ketok Jaringan Bypass (Bypass Switch) balik deui ka modeu throughput.

Aplikasi ieu ngan tiasa dianggo ngaliwatan ICMP (Ping). Henteu aya pakét denyut jantung anu dianggo pikeun ngawas sambungan antara server sareng Ketok Jaringan Bypass (Bypass Switch).

2

Solusi 2 Network Packet Broker + Bypass Network Tap(Bypass Switch)

Network Packet Broker(NPB) + Bypass Network Tap(Bypass Switch) -- Status normal

Aplikasi:

Ketok Jaringan Bypass (Bypass Switch) nyambung ka dua alat jaringan ngaliwatan palabuhan Link sareng ka Broker Paket Jaringan (NPB) ngalangkungan palabuhan Alat. Server pihak katilu nyambung ka Network Packet Broker (NPB) nganggo kabel tambaga 2 x 1G. Network Packet Broker (NPB) ngirimkeun pakét denyut jantung ka server ngalangkungan port #1 sareng hoyong nampi deui dina port #2.

Pemicu pikeun Bypass Network Tap (Bypass Switch) disetel ka REST, sareng Network Packet Broker (NPB) ngajalankeun aplikasi bypass.

Lalu lintas dina modeu throughput:

Alat 1 ↔ Saklar Bypass/Ketok ↔ NPB ↔ Server ↔ NPB ↔ Saklar Bypass/Ketok ↔ Alat 2

3

Network Packet Broker(NPB) + Bypass Network Tap(Bypass Switch) -- Software Bypass

Katerangan Software Bypass:

Upami Network Packet Broker(NPB) henteu ngadeteksi pakét denyut jantung, éta bakal ngaktifkeun bypass parangkat lunak.

Konfigurasi Network Packet Broker (NPB) sacara otomatis dirobih pikeun ngirim lalu lintas asup deui ka Bypass Network Tap (Bypass Switch), ku kituna ngalebetkeun deui lalu lintas kana tautan langsung kalayan leungitna pakét minimal.

The Bypass Network Tap(Bypass Switch) henteu kedah ngabales pisan sabab sadaya bypass dilakukeun ku Network Packet Broker (NPB).

Lalulintas dina Software Bypass:

Alat 1 ↔ Switch Bypass/Ketok ↔ NPB ↔ Switch Bypass/Ketok ↔ Alat 2

1

Network Packet Broker(NPB) + Bypass Network Tap(Bypass Switch) -- Hardware bypass

Katerangan Hardware Bypass:

Upami Network Packet Broker(NPB) gagal atanapi sambungan antara Network Packet Broker(NPB) sareng Bypass Network Tap(Bypass Switch) dipegatkeun, Bypass Network Tap(Bypass Switch) pindah ka modeu bypass pikeun ngajaga real- link waktos jalan.

Nalika Ketok Jaringan Bypass (Bypass Switch) asup kana modeu bypass, Network Packet Broker (NPB) sareng server éksternal diliwat sareng henteu nampi lalu lintas dugi ka Bypass Network Tap (Bypass Switch) ngalih deui ka modeu throughput.

Modeu bypass dipicu nalika Ketok Jaringan Bypass (Bypass Switch) teu nyambung deui kana catu daya.

Lalu lintas off-line hardware:

Alat 1 ↔ Bypass Switch/Ketok ↔ Alat 2

4

Solusi 3 Dua Ketok Jaringan Bypass (Saklar Bypass) pikeun tiap tautan

Pitunjuk Konfigurasi:

Dina setelan ieu, 1 tautan tambaga tina 2 alat anu nyambung ka server anu dipikanyaho diliwat ku dua Ketok Jaringan Bypass (Saklar Bypass). Kauntungannana ieu ngaliwatan solusi 1 bypass nyaeta nalika sambungan pakét calo jaringan (NPB) kaganggu, server masih bagian tina link live.

5

2 * Bypass Network Taps (Bypass Switch) per link - Software Bypass

Katerangan Software Bypass:

Upami Network Packet Broker(NPB) henteu ngadeteksi pakét denyut jantung, éta bakal ngaktifkeun bypass parangkat lunak. Ketok Jaringan Bypass (Bypass Switch) henteu kedah diréaksikeun pisan sabab sadayana jalan-jalan dilakukeun ku Network Packet Broker (NPB).

Lalu lintas dina software bypass:

Alat 1 ↔ Saklar Bypass/Ketok 1 ↔ Broker Paket Jaringan(NPB) ↔ Saklar Bypass/Ketok 2 ↔ Alat 2

6

 

2 * Bypass Network Taps (Bypass Switch) per link - Hardware Bypass

Katerangan Hardware Bypass:

Upami Network Packet Broker(NPB) gagal atanapi sambungan antara Bypass Network Tap(Bypass Switch) sareng Network Packet Broker(NPB) dipegatkeun, duanana Bypass Network Taps(Bypass Switches) dialihkeun ka modeu bypass pikeun ngajaga. link aktip.

Kontras jeung setelan "1 Bypass per link", server masih kaasup kana link live.

Lalu lintas off-line hardware:

Alat 1 ↔ Switch Bypass/Ketok 1 ↔Server ↔ Switch Bypass/Ketok 2 ↔ Alat 2

7

Solusi 4 Dua Ketok Jaringan Bypass (Saklar Bypass) dikonpigurasi pikeun tiap tautan dina dua situs

Parentah setelan:

Pilihan: Dua Network Packet Brokers (NPBs) tiasa dianggo pikeun nyambungkeun dua situs anu béda dina torowongan GRE tinimbang hiji Network Packet Broker (NPB). Upami server anu nyambungkeun dua situs gagal, éta bakal ngalangkungan server sareng lalu lintas anu tiasa disebarkeun ngaliwatan torowongan GRE Network Packet Broker (NPB) (sapertos dina Gambar di handap).

8

9


waktos pos: Mar-06-2023