Mylinking ™ Umuyoboro wa Packet Broker (NPB): Kumurika Inguni Zijimye Zumuyoboro wawe

Muri iki gihe kigoye, cyihuta cyane, kandi gikunze guhishirwa urusobe rwibidukikije, kugera kumurongo wuzuye nibyingenzi mumutekano, kugenzura imikorere, no kubahiriza.Umuyoboro wa Packet Brokers (NPBs)Byahindutse biva mubikoresho byoroshye bya TAP bihinduka muburyo buhanitse, bwubwenge bukenewe mugucunga umwuzure wamakuru yumuhanda no kugenzura ibikoresho nibikoresho byumutekano bikora neza. Dore ibisobanuro birambuye kubyingenzi byingenzi basaba nibisubizo:

Ikibazo Cyibanze NPBs Gukemura:
Imiyoboro igezweho itanga ubwinshi bwimodoka. Guhuza umutekano wingenzi nibikoresho byo kugenzura (IDS / IPS, NPM / APM, DLP, forensics) guhuza imiyoboro (binyuze ku byambu bya SPAN cyangwa TAP) ntibikora kandi akenshi ntibishoboka kubera:

1. Ibikoresho birenga: Ibikoresho byuzuyemo traffic idafite aho ihuriye, guta udupaki no kubura iterabwoba.

2. Kudakora neza kw'ibikoresho: Ibikoresho byangiza umutungo utunganya ibintu bibiri cyangwa bitari ngombwa.

3. Topologiya igoye: Imiyoboro yatanzwe (Data Centre, Igicu, Ibiro by'Amashami) ituma igenzura ryibanze rigoye.

4. Encryption Ahantu hatabona: Ibikoresho ntibishobora kugenzura ibanga ryabitswe (SSL / TLS) nta kubanga.

5. Ibikoresho bya SPAN bigarukira: ibyambu bya SPAN bitwara ibintu byahinduwe kandi akenshi ntibishobora gutwara umurongo wuzuye.

Igisubizo cya NPB: Ubwunzi bwumuhanda wubwenge
NPBs yicaye hagati yicyambu TAPs / SPAN nicyuma cyo kugenzura / ibikoresho byumutekano. Bakora nkubwenge "abapolisi bo mumuhanda," bakora:

1. Guteranya: Huza traffic kuva kumirongo myinshi (physique, virtual) mubiryo byahujwe.

2. Kurungurura: Hitamo imbere gusa traffic traffic kubikoresho byihariye bishingiye kubipimo (IP / MAC, VLAN, protocole, icyambu, porogaramu).

3. Kuringaniza imizigo: Gukwirakwiza urujya n'uruza rwinshi mu bihe byinshi byigikoresho kimwe (urugero, ibyuma bifata ibyuma bya IDS) kugirango bipime kandi bihangane.

4. Kwigana: Kuraho kopi imwe yipaki yafashwe kumurongo urenze.

5. Gukata paki: Gabanya paki (gukuramo umushahara) mugihe uzigama imitwe, kugabanya umurongo wibikoresho bikenera metadata gusa.

6. SSL / TLS Kurangiza: Kurangiza amasomo ahishe (ukoresheje urufunguzo), werekane urujya n'uruza rwanditse kubikoresho byo kugenzura, hanyuma wongere uhishe.

7. Kwigana / Kugwiza: Kohereza inzira imwe yimodoka kubikoresho byinshi icyarimwe.

8.

ML-NPB-3440L 3D

Shakisha hano kugirango umenye byinshi kuriyi moderi:

Mylinking ™ Umuyoboro wa Packet Broker (NPB) ML-NPB-3440L

16 * 10/100 / 1000M RJ45, 16 * 1/10GE SFP +, 1 * 40G QSFP na 1 * 40G / 100G QSFP28, Max 320Gbps

Ibisobanuro birambuye Ibisobanuro & Ibisubizo:

1. Kongera igenzura ry'umutekano (IDS / IPS, NGFW, Iterabwoba Intel):

En Scenario: Ibikoresho byumutekano birengerwa numubare munini wimodoka y'iburasirazuba-Iburengerazuba muri data center, guta udupaki no kubura iterabwoba ryuruhande. Imodoka ihishe neza ihisha imitwaro mibi.

Solution NPB Igisubizo:Guteranya traffic kuva kumurongo ukomeye wa DC.

* Koresha filteri ya granulaire kugirango wohereze gusa ibice byumuhanda bikekwa (urugero, ibyambu bitari bisanzwe, subnets zihariye) kuri IDS.

* Fata impuzandengo hejuru ya cluster ya sensor ya IDS.

* Kora ibanga rya SSL / TLS hanyuma wohereze urujya n'uruza rwanditse kuri IDS / Iterabwoba rya Intel kugirango ugenzure byimbitse.

* Kugabanya ibinyabiziga biva munzira zirenze urugero.Igisubizo:Igipimo cyo hejuru cyo gutahura iterabwoba, kugabanya ibibi, gukoresha neza IDS umutungo.

2. Kunoza gukurikirana imikorere (NPM / APM):

Scenario: Ibikoresho byo gukurikirana imikorere y'urusobe birwanira guhuza amakuru kuva amajana n'amajana yatatanye (WAN, ibiro by'ishami, igicu). Gufata paki yuzuye kuri APM birahenze cyane kandi byihuta cyane.

Solution NPB Igisubizo:

* Gukusanya ibinyabiziga biva muri TAPs / SPANs bitatanye ku mwenda wa NPB.

* Shungura traffic kugirango wohereze gusa porogaramu yihariye (urugero, VoIP, SaaS ikomeye) kubikoresho bya APM.

* Koresha udupaki dukata kubikoresho bya NPM bikenera cyane cyane amakuru yo gutembera / kugurisha igihe (imitwe), kugabanya cyane gukoresha umurongo wa interineti.

* Kwigana ibikorwa byingenzi byerekana ibipimo byombi kuri NPM na APM.Igisubizo:Ibikorwa byuzuye, bifitanye isano no kureba, kugabanya ibikoresho byigikoresho, kugabanya umurongo mwinshi hejuru.

3. Kugaragara kw'igicu (rusange / Private / Hybrid):

En Scenario: Kubura TAP kavukire kavukire mubicu rusange (AWS, Azure, GCP). Ingorane zo gufata no kuyobora imashini yimashini / kontineri yimodoka kubikoresho byumutekano no gukurikirana.

Solution NPB Igisubizo:

* Kohereza NPBs (vNPBs) mubidukikije.

* vNPBs kanda traffic traffic (urugero, ukoresheje ERSPAN, Mirroring VPC).

* Akayunguruzo, guteranya, hamwe nuburemere buringaniye Iburasirazuba-Iburengerazuba na Amajyaruguru-Amajyepfo traffic traffic.

* Hindura neza umuhanda ujyanye no gusubira kumwanya wa NPBs cyangwa ibikoresho byo kugenzura bishingiye ku bicu.

* Kwinjiza hamwe na serivise-igaragara ya serivise.Igisubizo:Guhagarara kumutekano uhoraho no kugenzura imikorere murwego rwibidukikije, gutsinda ibicu bigaragara.

4. Gukumira Data Gukumira (DLP) & Kubahiriza:

En Scenario: Ibikoresho bya DLP bigomba kugenzura urujya n'uruza rw'amakuru yihariye (PII, PCI) ariko rwuzuyemo traffic traffic idafite akamaro. Kubahiriza bisaba gukurikirana amakuru yihariye atemba.

Solution NPB Igisubizo:

* Shungura traffic kugirango wohereze gusa ibicuruzwa bisohoka (urugero, bigenewe interineti cyangwa abafatanyabikorwa runaka) kuri moteri ya DLP.

* Koresha igenzura ryimbitse (DPI) kuri NPB kugirango umenye imigendekere ikubiyemo ubwoko bwamakuru yagenwe kandi ubishyire imbere kubikoresho bya DLP.

* Menyesha amakuru yoroheje (urugero, nimero yikarita yinguzanyo) mubipakimberekohereza mubikoresho bike byo kugenzura kugirango byinjizwe.Igisubizo:Igikorwa cyiza cya DLP, cyagabanije ibyiza, kugabanya igenzura ryubahirizwa, kuzamura amakuru yihariye.

5. Urubuga rwa Forensics & Gukemura ibibazo:

Scenario: Gusuzuma ikibazo cyimikorere igoye cyangwa kurenga bisaba gufata paki yuzuye (PCAP) uhereye kumanota menshi mugihe. Gukurura gufata intoki biratinda; kubika ibintu byose ntibishoboka.

Solution NPB Igisubizo:

* NPBs irashobora guhagarika traffic ubudahwema (ku gipimo cyumurongo).

* Shyiramo imbarutso (urugero, imiterere yihariye yibibazo, umuvuduko wumuhanda, kumenyesha iterabwoba) kuri NPB kugirango uhite ufata traffic ijyanye nibikoresho bifatanye.

* Mbere yo gushungura traffic yoherejwe mubikoresho byo gufata kugirango ubike ibikenewe gusa.

* Ongera uhindure urujya n'uruza rw'ibikoresho byo gufata bitagize ingaruka ku bikoresho byo gukora.Igisubizo:Byihuse-igihe-cyo-gukemura (MTTR) kubura / kurenga, gufata ibyemezo byubucamanza, kugabanya ububiko.

Mylinking ™ Umuyoboro wa Packet Broker Igisubizo Cyuzuye

Ibitekerezo byo Gushyira mu bikorwa & Ibisubizo:

Ubunini: Hitamo NPBs hamwe nubucucike bwicyambu gihagije nibisohoka (1/10/25/40 / 100GbE +) kugirango ukemure ibinyabiziga bigezweho nibizaza. Moderi ya chassis akenshi itanga ubunini bwiza. Virtual NPBs igipimo cyoroshye mubicu.

Kwihangana: Shyira mubikorwa NPBs zirenze urugero (HA jours) n'inzira zirenze kubikoresho. Menya neza guhuza leta muburyo bwa HA. Koresha NPB umutwaro uringaniza ibikoresho.

Ubuyobozi & Automation: Ubuyobozi bukomatanyije ni ngombwa. Reba APIs (RESTful, NETCONF / YANG) kugirango uhuze hamwe na orchestre platform (Ansible, Puppet, Chef) na SIEM / SOAR sisitemu yo guhindura politiki yingirakamaro ishingiye kubimenyesha.

Umutekano: Kurinda imiyoboro ya NPB. Kugenzura uburyo bworoshye. Niba ufunguye traffic, menya neza politiki yingenzi yo kuyobora hamwe numuyoboro wizewe wo kwimura urufunguzo. Tekereza guhisha amakuru yihariye.

Kwishyira hamwe kw'ibikoresho: Menya neza ko NPB ishyigikira igikoresho gikenewe cyo guhuza (interineti igaragara / igaragara, protocole). Kugenzura guhuza n'ibikoresho byihariye bisabwa.

Noneho,Umuyoboro wa Packet Brokersntibikiri ibintu by'akataraboneka; nibintu remezo byingenzi kugirango tugere kumurongo ugaragara mubikorwa bigezweho. Mugukusanya ubushishozi, gushungura, kuringaniza imizigo, no gutunganya traffic, NPBs iha imbaraga umutekano nibikoresho byo kugenzura kugirango bikore neza kandi neza. Basenya silos igaragara, batsinde imbogamizi zubunini no kugenzura, kandi amaherezo batanga ibisobanuro bikenewe kugirango umutekano urusheho umutekano, kwemeza imikorere myiza, kubahiriza inshingano zubahirizwa, no gukemura vuba ibibazo. Gushyira mubikorwa ingamba zikomeye za NPB nintambwe yingenzi yo kubaka urusobe rugaragara, rufite umutekano, kandi rukomeye.


Igihe cyo kohereza: Nyakanga-07-2025