Ukuba unomlawuli, akukho ngxaki: indlela yokugcina lula inethiwekhi yakho engenazingcingo

Kwi-2019, inkampani yokubonisana i-Miercom yenza uvavanyo oluzimeleyo lwezobuchwepheshe lwabalawuli be-Wi-Fi 6 yechungechunge lwe-Cisco Catalyst 9800. Kulo cwaningo, ibhentshi yokuvavanya yahlanganiswa kubalawuli be-Cisco Wi-Fi 6 kunye neendawo zokufikelela, kunye nesisombululo sobugcisa. ihlolwe kwezi ndidi zilandelayo:

  • ukufumaneka;
  • UKhuseleko;
  • Ukuzenzekela.

Iziphumo zophando ziboniswe ngezantsi. Ukusukela ngo-2019, ukusebenza kwabalawuli be-Cisco Catalyst 9800 kuphuculwe kakhulu - la manqaku abonakaliswe kweli nqaku.

Unokufunda malunga nezinye iingenelo ze-Wi-Fi 6 iteknoloji, imizekelo yokuphunyezwa kunye neendawo zokusetyenziswa apha.

Isishwankathelo sesisombululo

Wi-Fi 6 abalawuli Cisco Catalyst 9800 series

I-Cisco Catalyst 9800 Series Controllers Wireless, esekelwe kwinkqubo yokusebenza ye-IOS-XE (ekwasetyenziselwa ukutshintsha kweCisco kunye nee-routers), ziyafumaneka kwiinketho ezahlukeneyo.

Ukuba unomlawuli, akukho ngxaki: indlela yokugcina lula inethiwekhi yakho engenazingcingo

Imodeli endala yomlawuli we-9800-80 isekela i-wireless network throughput ukuya kwi-80 Gbps. Umlawuli omnye we-9800-80 uxhasa ukufikelela kwiindawo ze-6000 zokufikelela kunye nokufika kwi-64 yabathengi abangenazintambo.

Imodeli ephakathi, umlawuli we-9800-40, isekela ukuya kwi-40 Gbps throughput, ukuya kwii-2000 zokufikelela kwiindawo kunye nokufika kwi-32 yabathengi abangenazintambo.

Ukongeza kwezi modeli, uhlalutyo lokukhuphisana lukwabandakanya isilawuli esingenazingcingo se-9800-CL (i-CL imele i-Cloud). I-9800-CL iqhuba kwiindawo ezibonakalayo kwi-VMWare ESXI kunye ne-KVM hypervisors, kwaye ukusebenza kwayo kuxhomekeke kwizibonelelo ze-hardware ezizinikeleyo kumatshini we-controller virtual. Ekuqwalaselweni kwayo okuphezulu, umlawuli we-Cisco 9800-CL, njengemodeli endala ye-9800-80, isekela ukukhawuleza ukuya kwii-6000 zokufikelela kwiindawo kunye nokufika kwi-64 yabathengi abangenazintambo.

Xa kuqhutywa uphando kunye nabalawuli, Cisco Aironet AP 4800 amanqaku ukufikelela series zisetyenzisiwe, ukuxhasa umsebenzi kwi-frequencies 2,4 kunye 5 GHz kunye nekhono dynamically ukutshintshela kwimowudi ezimbini 5-GHz.

ibhentshi yovavanyo

Njengenxalenye yovavanyo, i-stand yahlanganiswa ukusuka kubalawuli be-Cisco Catalyst 9800-CL abangenazintambo abasebenza kwi-cluster kunye ne-Cisco Aironet AP 4800 amanqaku okufikelela kwiichungechunge.

Iilaptops ezivela kuDell kunye neApple, kunye ne-Apple iPhone smartphone, zasetyenziswa njengezixhobo zabathengi.

Ukuba unomlawuli, akukho ngxaki: indlela yokugcina lula inethiwekhi yakho engenazingcingo

Ufikelelo uvavanyo

Ubukho buchazwa njengokukwazi kwabasebenzisi ukufikelela nokusebenzisa inkqubo okanye inkonzo. Ukufumaneka okuphezulu kuthetha ukufikelela rhoqo kwinkqubo okanye inkonzo, ngaphandle kweziganeko ezithile.

Ukufumaneka okuphezulu kwavavanywa kwiimeko ezine, iimeko ezintathu zokuqala ziqikelelwa okanye iziganeko ezicwangcisiweyo ezinokuthi zenzeke ngexesha okanye emva kweeyure zokusebenza. Imeko yesihlanu kukungaphumeleli kweklasi, okuyisiganeko esingalindelekanga.

ОписаниС сцСнариСв:

  • Ukulungiswa kwempazamo - i-micro-update yenkqubo (i-bugfix okanye i-patch yokhuseleko), evumela ukuba ulungise iphutha elithile okanye ubuthathaka ngaphandle kokuhlaziywa okupheleleyo kwesofthiwe yenkqubo;
  • Uhlaziyo olusebenzayo - ukongeza okanye ukwandisa ukusebenza kwangoku kwenkqubo ngokufaka uhlaziyo olusebenzayo;
  • Uhlaziyo olupheleleyo - hlaziya umfanekiso wesoftware yesilawuli;
  • Ukongeza indawo yokufikelela - ukongeza imodeli entsha yokufikelela kwinethiwekhi engenazintambo ngaphandle kwesidingo sokuhlaziya okanye ukuhlaziya isofthiwe yokulawula i-wireless;
  • Ukusilela-ukusilela kwesilawuli esingenazingcingo.

Ukulungisa iimpazamo kunye nobuthathaka

Ngokuqhelekileyo, kunye nezisombululo ezininzi ezikhuphisanayo, ukudibanisa kufuna uhlaziyo olupheleleyo lwesoftware yenkqubo yokulawula engenazingcingo, enokubangela ukwehla okungacwangciswanga. Kwimeko yesisombululo seCisco, i-patching yenziwa ngaphandle kokumisa imveliso. Iipetshi zinokufakelwa nakweliphi na icandelo ngelixa iziseko zoncedo ezingenazingcingo ziqhubeka nokusebenza.

Inkqubo ngokwayo ilula kakhulu. Ifayile ye-patch ikopishwe kwifolda ye-bootstrap kwenye yabalawuli be-wireless Cisco, kwaye umsebenzi uqinisekisiwe nge-GUI okanye umgca womyalelo. Ukongeza, unokuhlehlisa kwaye ususe ukulungiswa nge-GUI okanye umgca womyalelo, ngaphandle kokuphazamisa ukusebenza kwenkqubo.

Uhlaziyo olusebenzayo

Uhlaziyo lwesoftware olusebenzayo luyasetyenziswa ukunika amandla amanqaku amatsha. Enye yezi mpucuko kukuhlaziya utyikityo lwedatha yesicelo. Le phakheji ifakwe kubalawuli beCisco njengovavanyo. Njengakwiziqendu, uhlaziyo lwefitsha luyasetyenziswa, lufakwe, okanye lususwe ngaphandle kokuphazamiseka okanye ukuphazamiseka kwenkqubo.

Uhlaziyo olupheleleyo

Okwangoku, uhlaziyo olupheleleyo lomfanekiso wesoftware yomlawuli lwenziwa ngendlela efanayo nohlaziyo olusebenzayo, oko kukuthi, ngaphandle kwexesha lokuphumla. Nangona kunjalo, eli nqaku lifumaneka kuphela kuqwalaselo lweqela xa kukho ngaphezu komlawuli omnye. Uhlaziyo olupheleleyo lwenziwa ngokulandelelanayo: okokuqala kumlawuli omnye, ngoko okwesibini.

Ukongeza imodeli entsha yendawo yokufikelela

Ukuqhagamshela iindawo ezintsha zokufikelela, ezingazange zisetyenziswe ngaphambili kunye nomfanekiso wesofthiwe yomlawuli osetyenzisiweyo, kwinethiwekhi engenazintambo ngumsebenzi oqhelekileyo, ngokukodwa kwiinethiwekhi ezinkulu (ii-airport, iihotele, iifektri). Rhoqo kwizisombululo zabakhuphisanayo, lo msebenzi ufuna ukuhlaziya inkqubo yesoftware okanye ukuqalisa ngokutsha abalawuli.

Xa udibanisa iindawo ezintsha zokufikelela kwi-Wi-Fi 6 kwiqela le-Cisco Catalyst 9800 abalawuli beechungechunge, akukho ngxaki zibonwayo. Ukudibanisa amanqaku amatsha kumlawuli wenziwa ngaphandle kokuhlaziya isofthiwe yomlawuli, kwaye le nkqubo ayifuni ukuqaliswa kwakhona, ngoko ke ayichaphazeli inethiwekhi engenazintambo nangayiphi na indlela.

Ukusilela komlawuli

Indawo yokuvavanya isebenzisa abalawuli ababini be-Wi-Fi 6 (I-Active/StandBy) kwaye indawo yokufikelela inonxibelelwano oluthe ngqo kubo bobabini abalawuli.

Omnye umlawuli ongenazingcingo uyasebenza, kwaye omnye, ngokulandelelana, ugcina i-backup. Ukuba umlawuli osebenzayo akaphumeleli, umlawuli wogcino uthatha indawo kwaye isimo saso sitshintsha sisebenze. Le nkqubo yenzeka ngaphandle kokuphazamiseka kwindawo yofikelelo kunye ne-Wi-Fi kubaxhasi.

Khu seleko

Eli candelo lixoxa ngemiba yokhuseleko, engumba ocinezela kakhulu kwiinethiwekhi ezingenazingcingo. Ukhuseleko lwesisombululo luvavanywa ngokusekelwe kwezi mpawu zilandelayo:

  • Ukuqwalaselwa kwesicelo;
  • Ukulandela umkhondo;
  • Анализ Π·Π°ΡˆΠΈΡ„Ρ€ΠΎΠ²Π°Π½Π½ΠΎΠ³ΠΎ Ρ‚Ρ€Π°Ρ„ΠΈΠΊΠ°;
  • Ukubona ukungena kunye nokuthintela;
  • Ukuqinisekiswa kuthetha;
  • Izixhobo zokukhusela isixhobo somthengi.

Ukuqatshelwa kwesicelo

Phakathi kweemveliso ezahlukeneyo kwimarike ye-Wi-Fi yeshishini kunye nezoshishino, kukho umahluko kwindlela iimveliso ezichonga ngayo i-traffic ngokusebenzisa isicelo. Iimveliso ezivela kubavelisi abohlukeneyo zinokuchonga amanani ahlukeneyo osetyenziso. Nangona kunjalo, uninzi lwezicelo ezidwelisa izisombululo ezikhuphisanayo kangangoko kunokwenzeka ukuze zichongwe, enyanisweni, ziiwebhusayithi, kwaye ayizizo izicelo ezizodwa.

Kukho enye into enomdla yokuqatshelwa kwesicelo: izisombululo ziyahluka kakhulu ekuchongeni ukuchaneka.

Ukuqwalasela zonke iimvavanyo ezenziweyo, sinokuchaza ngokufanelekileyo ukuba isisombululo se-Wi-Fi-6 seCisco senza ukuqatshelwa kwesicelo ngokuchanekileyo: iJabber, iNetflix, iDropbox, i-YouTube kunye nezinye izicelo ezithandwayo, kunye neenkonzo zewebhu, zachongwa ngokuchanekileyo. Izisombululo zeCisco zinokuntywila nzulu kwiipakethi zedatha zisebenzisa iDPI (I-Deep Packet Inspection).

Ukulandelela ukuhamba kwetrafiki

Olunye uvavanyo lwenziwe ukujonga ukuba inkqubo inokulandelela ngokuchanekileyo kwaye inike ingxelo yokuhamba kwedatha (njengokuhamba kweefayile ezinkulu). Ukuvavanya oku, ifayile ye-megabyte eyi-6,5 ithunyelwe ngenethiwekhi kusetyenziswa iProtocol Transfer Protocol (FTP).

Isisombululo seCisco sasifikelele ngokupheleleyo kulo msebenzi kwaye sakwazi ukulandelela le trafiki ngokubonga kwi-NetFlow kunye nobuchule bayo be-hardware. Itrafikhi yabhaqwa yaza yachongwa ngoko nangoko ngesixa esichanekileyo sedatha edluliselweyo.

Uhlalutyo lwendlela entsonkothileyo

I-traffic data yomsebenzisi iya iguqulelwa ngokufihlakeleyo. Oku kwenziwa ukuze kukhuselwe ukuba ingalandelwa okanye ibanjwe ngabahlaseli. Kodwa kwangaxeshanye, abahlaseli bayanda ukusebenzisa i-encryption ukufihla i-malware yabo kwaye baqhube ezinye izinto ezithandabuzekayo ezifana ne-Man-in-the-Middle (MiTM) okanye uhlaselo lwe-keylogging.

Uninzi lwamashishini ahlola ezinye zetrafikhi yawo efihliweyo ngokuqala ngokuyicoca kusetyenziswa iindonga zomlilo okanye iinkqubo zokuthintela ukungena. Kodwa le nkqubo ithatha ixesha elininzi kwaye ayizuzi intsebenzo yenethiwekhi ngokubanzi. Ukongeza, yakuba ikhutshiwe, le datha iba sesichengeni sokujonga amehlo.

Cisco Catalyst 9800 Series abalawuli ukusombulula ngempumelelo ingxaki yokuhlalutya i-encrypted traffic ngezinye iindlela. Isisombululo sibizwa ngokuba yi-Encrypted Traffic Analytics (ETA). I-ETA yitekhnoloji okwangoku engenazo ii-analogues kwizisombululo ezikhuphisanayo kwaye ibona i-malware kwitrafikhi efihliweyo ngaphandle kwesidingo sokuyisusa. I-ETA luphawu olungundoqo lwe-IOS-XE oluquka i-NetFlow ephuculweyo kwaye isebenzisa iindlela zokuziphatha eziphucukileyo ukuchonga iipatheni ezikhohlakeleyo zendlela ezifihlwe kwitrafikhi efihliweyo.

Ukuba unomlawuli, akukho ngxaki: indlela yokugcina lula inethiwekhi yakho engenazingcingo

I-ETA ayikhiphi imiyalezo, kodwa iqokelela iiprofayili zemetadata zokuqukuqela kwetrafikhi efihliweyo - ubungakanani bepakethi, ixesha eliphakathi kweepakethi, nokunye okuninzi. Imethadatha ithunyelwa ngaphandle kwiirekhodi zeNetFlow v9 kwiCisco Stealthwatch.

Umsebenzi ophambili weStealthwatch kukubeka iliso rhoqo kwitrafikhi, kunye nokwenza isiseko somsebenzi wenethiwekhi eqhelekileyo. Isebenzisa imetadata yomjelo efihliweyo ethunyelwe kuyo yi-ETA, iStealthwatch isebenzisa umatshini wokufunda ngoomatshini abaninzi ukuchonga ukungahambi kakuhle kwendlela yokuziphatha enokubonisa iziganeko ezirhanelekayo.

Kulo nyaka uphelileyo, uCisco ubandakanye iMiercom ukuba ivavanye ngokuzimeleyo isisombululo sayo seCisco Encrypted Traffic Analytics. Ngexesha lovavanyo, i-Miercom yathumela ngokwahlukeneyo izoyikiso ezaziwayo nezingaziwayo (iintsholongwane, iiTrojani, i-ransomware) kwitrafikhi efihliweyo kunye ne-encrypted kwi-ETA enkulu kunye neenethiwekhi ezingezizo ze-ETA ukuchonga izoyikiso.

Ukuvavanya, ikhowudi enobungozi yasungulwa kuzo zombini iinethiwekhi. Kuzo zombini ezi meko, ngokuthe ngcembe kwafunyanwa umsebenzi okrokrisayo. Inethiwekhi ye-ETA iqale yafumanisa izoyikiso ze-36% ngokukhawuleza kunenethiwekhi engeyiyo ye-ETA. Ngexesha elifanayo, njengoko umsebenzi uqhubela phambili, imveliso yokufumanisa kwinethiwekhi ye-ETA yaqala ukwanda. Ngenxa yoko, emva kweeyure ezininzi zomsebenzi, isibini kwisithathu sezoyikiso ezisebenzayo zafunyanwa ngempumelelo kwinethiwekhi ye-ETA, ephindwe kabini kune-non-ETA network.

Ukusebenza kwe-ETA kudityaniswe kakuhle neStealthwatch. Izoyikiso zibekwe ngokobungqongqo kwaye ziboniswe ngolwazi oluneenkcukacha, kunye neendlela zokulungisa xa ziqinisekisiwe. Isiphelo - i-ETA iyasebenza!

Ukubona ukungena kunye nokuthintela

Ngoku iCisco inesinye isixhobo sokhuseleko esisebenzayo-iCisco Advanced Wireless Intrusion Prevention System (aWIP): isixhobo sokubona nokuthintela izoyikiso kuthungelwano olungenazingcingo. Isisombululo se-aWIPS sisebenza kwinqanaba labalawuli, iindawo zokufikelela kunye nesoftware yolawulo lweCisco DNA Centre. Ukufunyanwa kwesoyikiso, ukulumkisa, kunye nokuthintela kudibanisa uhlalutyo lwetrafikhi yenethiwekhi, isixhobo sothungelwano kunye nolwazi lwe-topology yenethiwekhi, ubuchule obusekwe kwisiginitsha, kunye nokufumanisa okungaqhelekanga ukuhambisa izisongelo ezichanekileyo nezinokuthintelwa ngaphandle kwamacingo.

Ukudibanisa ngokupheleleyo i-aWIPS kwisiseko senethiwekhi yakho, unokuqhubeka nokubeka iliso kwitrafikhi engenazingcingo kuzo zombini iinethiwekhi ezineentambo kunye nezingenazingcingo kwaye uyisebenzise ukuhlalutya ngokuzenzekelayo uhlaselo olunokuthi lubekho oluvela kwimithombo emininzi ukubonelela ngobona lwazi lubanzi kunye nothintelo olunokwenzeka.

Ukuqinisekiswa kuthetha

Okwangoku, ukongeza kwizixhobo zokuqinisekisa zakudala, iCisco Catalyst 9800 izisombululo zechungechunge zixhasa iWPA3. I-WPA3 yinguqulelo yamva nje ye-WPA, eyisethi yemigaqo kunye nobuchwepheshe obubonelela ngoqinisekiso kunye noguqulelo oluntsonkothileyo lweenethiwekhi ze-Wi-Fi.

I-WPA3 isebenzisa i-Simltaneous Authentication of Equals (SAE) ukubonelela ngokhuseleko oluluqilima kubasebenzisi ngokuchasene neenzame zokuqikelela igama eliyimfihlo liqela lesithathu. Xa umxhasi edibanisa kwindawo yokufikelela, yenza utshintshiselwano lwe-SAE. Ukuba uphumelele, ngamnye kubo uya kudala isitshixo esinamandla e-cryptographically apho iqhosha leseshoni liya kuphuma khona, kwaye ke baya kungena kwimeko yokuqinisekisa. Umxhasi kunye nendawo yofikelelo banokungena kwi-handshake states ngexesha ngalinye iqhosha leseshoni lifuna ukwenziwa. Indlela isebenzisa imfihlo eya phambili, apho umhlaseli angakwazi ukukrazula isitshixo esinye, kodwa kungekhona zonke ezinye izitshixo.

Oko kukuthi, i-SAE iyilwe ngendlela yokuba umhlaseli onqanda i-traffic unomzamo omnye kuphela wokuqikelela igama eligqithisiweyo ngaphambi kokuba idatha ebanjiweyo ingabi namsebenzi. Ukucwangcisa ukubuyiswa kwephasiwedi ende, uya kufuna ukufikelela ngokomzimba kwindawo yokufikelela.

Ukhuseleko lwesixhobo somthengi

I-Cisco Catalyst 9800 Series izisombululo ezingenazintambo okwangoku zibonelela ngeyona nto iphambili yokukhusela abathengi ngeCisco Umbrella WLAN, inkonzo yokhuseleko lwenethiwekhi esekelwe kwifu esebenza kwinqanaba le-DNS kunye nokufumanisa ngokuzenzekelayo zombini izisongelo ezaziwayo kunye nezivelayo.

I-Cisco Umbrella WLAN ibonelela ngezixhobo zabathengi ngoqhagamshelwano olukhuselekileyo kwi-Intanethi. Oku kuphunyezwa ngokucoca umxholo, oko kukuthi, ngokuthintela ukufikelela kwizibonelelo kwi-Intanethi ngokuhambelana nomgaqo-nkqubo weshishini. Ke, izixhobo zabaxumi kwi-Intanethi zikhuselwe kwi-malware, i-ransomware, kunye ne-phishing. Ukunyanzeliswa komgaqo-nkqubo kusekelwe kwiindidi zomxholo ezihlaziywa ngokuqhubekayo ezingama-60.

Ukuzenzekelayo

Uthungelwano lwanamhlanje olungenazingcingo lubhetyebhetye ngakumbi kwaye luntsonkothile, ngoko ke iindlela zemveli zokuqwalasela nokubuyisela ulwazi kubalawuli abangenazingcingo azanelanga. Abalawuli benethiwekhi kunye neengcali zokhuseleko lolwazi zifuna izixhobo zokuzenzekelayo kunye nohlalutyo, ukukhuthaza abathengisi abangenazintambo ukuba banikele ngezixhobo ezinjalo.

Ukusombulula ezi ngxaki, i-Cisco Catalyst 9800 abalawuli abangenazintambo ezingenazintambo, kunye ne-API yendabuko, inikezela ngenkxaso ye-RESTCONF / NETCONF yoqwalaselo lwenethiwekhi yeprotocol kunye neYANG (Kusesinye esinye isiZukulwana esilandelayo) ulwimi lokulinganisa idatha.

I-NETCONF yi-protocol esekwe kwi-XML ezinokuthi izicelo zisebenzise ukubuza ulwazi kunye nokutshintsha ukucwangciswa kwezixhobo zenethiwekhi ezifana nabalawuli abangenazintambo.

Ukongeza kwezi ndlela, i-Cisco Catalyst 9800 Series Controllers inikezela ngokukwazi ukubamba, ukufumana, kunye nokuhlalutya idatha yokuhamba kolwazi usebenzisa i-NetFlow kunye ne-sFlow protocol.

Ukhuseleko kunye nemodeli yetrafikhi, ukukwazi ukulandelela ukuhamba okuthe ngqo sisixhobo esibalulekileyo. Ukusombulula le ngxaki, iprotocol ye-sFlow yaphunyezwa, ekuvumela ukuba ubambe iipakethi ezimbini kwikhulu ngalinye. Nangona kunjalo, ngamanye amaxesha oku kusenokunganeli ukuhlalutya kunye nokufunda ngokwaneleyo kunye nokuvavanya ukuhamba. Ngoko ke, enye indlela yi-NetFlow, ephunyezwe yiCisco, evumela ukuba i-100% iqokelele kwaye ithumele ngaphandle zonke iipakethi kwi-flow ecacisiweyo yohlalutyo olulandelayo.

Enye into, nangona kunjalo, ekhoyo kuphela ekuphunyezweni kwe-hardware yabalawuli, ekuvumela ukuba wenze ngokuzenzekelayo ukusebenza kwenethiwekhi engenazintambo kwi-Cisco Catalyst 9800 abalawuli beechungechunge, inkxaso eyakhelwe-ngaphakathi yolwimi lwePython njenge-add-on yokusebenzisa. izikripthi ngqo kwisilawuli esingenazingcingo ngokwaso.

Ekugqibeleni, iCisco Catalyst 9800 Series Controllers ixhasa i-SNMP version 1, 2, kunye ne-3 yeprotocol eqinisekisiweyo yokubeka iliso kunye nemisebenzi yokulawula.

Ngaloo ndlela, ngokubhekiselele kwi-automation, i-Cisco Catalyst 9800 Series solutions ihlangabezana ngokupheleleyo neemfuno zoshishino zanamhlanje, ezinikezela zombini ezintsha kunye neyodwa, kunye nezixhobo ezivavanywe ixesha lokusebenza ngokuzenzekelayo kunye nohlalutyo kwiinethiwekhi ezingenazintambo zaluphi na ubukhulu kunye nobunzima.

isiphelo

Kwizisombululo ezisekelwe kwiCisco Catalyst 9800 Series Controllers, iCisco ibonise iziphumo ezigqwesileyo kwiindidi zokufumaneka okuphezulu, ukhuseleko kunye nokuzenzekelayo.

Isisombululo sihlangabezana ngokupheleleyo nazo zonke iimfuno eziphezulu zokufumaneka ezifana ne-sub-second failover ngexesha leziganeko ezingacwangciswanga kunye ne-zero downtime kwiziganeko ezicwangcisiweyo.

I-Cisco Catalyst 9800 Series Controllers inikezela ngokhuseleko olubanzi olubonelela ngokuhlolwa kwepakethe enzulu yokuqaphela isicelo kunye nokulawula, ukubonakala okupheleleyo kwiinkqubo zedatha, kunye nokuchongwa kwezisongelo ezifihliweyo kwi-traffic encrypted, kunye nokuqinisekiswa okuphambili kunye neendlela zokukhusela izixhobo zabaxhasi.

Ukuzenzekela kunye nokuhlalutya, i-Cisco Catalyst 9800 Series inikeza amandla anamandla usebenzisa imodeli esemgangathweni eyaziwayo: i-YANG, i-NETCONF, i-RESTCONF, i-APIs yendabuko, kunye nemibhalo ye-Python eyakhelwe ngaphakathi.

Ngaloo ndlela, iCisco iphinda iqinisekise isimo sayo njengomvelisi ohamba phambili wehlabathi wezisombululo zothungelwano, ukuhambisana namaxesha kunye nokuthathela ingqalelo yonke imingeni yeshishini lanamhlanje.

Ukufumana ulwazi oluthe kratya malunga nosapho lokutshintsha kweCatalyst, ndwendwela indawo ICisco.

umthombo: www.habr.com

Yongeza izimvo

Kwi-2019, inkampani yokubonisana i-Miercom yenza uvavanyo oluzimeleyo lwezobuchwepheshe lwabalawuli be-Wi-Fi 6 yechungechunge lwe-Cisco Catalyst 9800. Kulo cwaningo, ibhentshi yokuvavanya yahlanganiswa kubalawuli be-Cisco Wi-Fi 6 kunye neendawo zokufikelela, kunye nesisombululo sobugcisa. ihlolwe kwezi ndidi zilandelayo:

  • ukufumaneka;
  • UKhuseleko;
  • Ukuzenzekela.

Iziphumo zophando ziboniswe ngezantsi. Ukusukela ngo-2019, ukusebenza kwabalawuli be-Cisco Catalyst 9800 kuphuculwe kakhulu - la manqaku abonakaliswe kweli nqaku.

Unokufunda malunga nezinye iingenelo ze-Wi-Fi 6 iteknoloji, imizekelo yokuphunyezwa kunye neendawo zokusetyenziswa apha.

Isishwankathelo sesisombululo

Wi-Fi 6 abalawuli Cisco Catalyst 9800 series

I-Cisco Catalyst 9800 Series Controllers Wireless, esekelwe kwinkqubo yokusebenza ye-IOS-XE (ekwasetyenziselwa ukutshintsha kweCisco kunye nee-routers), ziyafumaneka kwiinketho ezahlukeneyo.

Ukuba unomlawuli, akukho ngxaki: indlela yokugcina lula inethiwekhi yakho engenazingcingo

Imodeli endala yomlawuli we-9800-80 isekela i-wireless network throughput ukuya kwi-80 Gbps. Umlawuli omnye we-9800-80 uxhasa ukufikelela kwiindawo ze-6000 zokufikelela kunye nokufika kwi-64 yabathengi abangenazintambo.

Imodeli ephakathi, umlawuli we-9800-40, isekela ukuya kwi-40 Gbps throughput, ukuya kwii-2000 zokufikelela kwiindawo kunye nokufika kwi-32 yabathengi abangenazintambo.

Ukongeza kwezi modeli, uhlalutyo lokukhuphisana lukwabandakanya isilawuli esingenazingcingo se-9800-CL (i-CL imele i-Cloud). I-9800-CL iqhuba kwiindawo ezibonakalayo kwi-VMWare ESXI kunye ne-KVM hypervisors, kwaye ukusebenza kwayo kuxhomekeke kwizibonelelo ze-hardware ezizinikeleyo kumatshini we-controller virtual. Ekuqwalaselweni kwayo okuphezulu, umlawuli we-Cisco 9800-CL, njengemodeli endala ye-9800-80, isekela ukukhawuleza ukuya kwii-6000 zokufikelela kwiindawo kunye nokufika kwi-64 yabathengi abangenazintambo.

Xa kuqhutywa uphando kunye nabalawuli, Cisco Aironet AP 4800 amanqaku ukufikelela series zisetyenzisiwe, ukuxhasa umsebenzi kwi-frequencies 2,4 kunye 5 GHz kunye nekhono dynamically ukutshintshela kwimowudi ezimbini 5-GHz.

ibhentshi yovavanyo

Njengenxalenye yovavanyo, i-stand yahlanganiswa ukusuka kubalawuli be-Cisco Catalyst 9800-CL abangenazintambo abasebenza kwi-cluster kunye ne-Cisco Aironet AP 4800 amanqaku okufikelela kwiichungechunge.

Iilaptops ezivela kuDell kunye neApple, kunye ne-Apple iPhone smartphone, zasetyenziswa njengezixhobo zabathengi.

Ukuba unomlawuli, akukho ngxaki: indlela yokugcina lula inethiwekhi yakho engenazingcingo

Ufikelelo uvavanyo

Ubukho buchazwa njengokukwazi kwabasebenzisi ukufikelela nokusebenzisa inkqubo okanye inkonzo. Ukufumaneka okuphezulu kuthetha ukufikelela rhoqo kwinkqubo okanye inkonzo, ngaphandle kweziganeko ezithile.

Ukufumaneka okuphezulu kwavavanywa kwiimeko ezine, iimeko ezintathu zokuqala ziqikelelwa okanye iziganeko ezicwangcisiweyo ezinokuthi zenzeke ngexesha okanye emva kweeyure zokusebenza. Imeko yesihlanu kukungaphumeleli kweklasi, okuyisiganeko esingalindelekanga.

ОписаниС сцСнариСв:

  • Ukulungiswa kwempazamo - i-micro-update yenkqubo (i-bugfix okanye i-patch yokhuseleko), evumela ukuba ulungise iphutha elithile okanye ubuthathaka ngaphandle kokuhlaziywa okupheleleyo kwesofthiwe yenkqubo;
  • Uhlaziyo olusebenzayo - ukongeza okanye ukwandisa ukusebenza kwangoku kwenkqubo ngokufaka uhlaziyo olusebenzayo;
  • Uhlaziyo olupheleleyo - hlaziya umfanekiso wesoftware yesilawuli;
  • Ukongeza indawo yokufikelela - ukongeza imodeli entsha yokufikelela kwinethiwekhi engenazintambo ngaphandle kwesidingo sokuhlaziya okanye ukuhlaziya isofthiwe yokulawula i-wireless;
  • Ukusilela-ukusilela kwesilawuli esingenazingcingo.

Ukulungisa iimpazamo kunye nobuthathaka

Ngokuqhelekileyo, kunye nezisombululo ezininzi ezikhuphisanayo, ukudibanisa kufuna uhlaziyo olupheleleyo lwesoftware yenkqubo yokulawula engenazingcingo, enokubangela ukwehla okungacwangciswanga. Kwimeko yesisombululo seCisco, i-patching yenziwa ngaphandle kokumisa imveliso. Iipetshi zinokufakelwa nakweliphi na icandelo ngelixa iziseko zoncedo ezingenazingcingo ziqhubeka nokusebenza.

Inkqubo ngokwayo ilula kakhulu. Ifayile ye-patch ikopishwe kwifolda ye-bootstrap kwenye yabalawuli be-wireless Cisco, kwaye umsebenzi uqinisekisiwe nge-GUI okanye umgca womyalelo. Ukongeza, unokuhlehlisa kwaye ususe ukulungiswa nge-GUI okanye umgca womyalelo, ngaphandle kokuphazamisa ukusebenza kwenkqubo.

Uhlaziyo olusebenzayo

Uhlaziyo lwesoftware olusebenzayo luyasetyenziswa ukunika amandla amanqaku amatsha. Enye yezi mpucuko kukuhlaziya utyikityo lwedatha yesicelo. Le phakheji ifakwe kubalawuli beCisco njengovavanyo. Njengakwiziqendu, uhlaziyo lwefitsha luyasetyenziswa, lufakwe, okanye lususwe ngaphandle kokuphazamiseka okanye ukuphazamiseka kwenkqubo.

Uhlaziyo olupheleleyo

Okwangoku, uhlaziyo olupheleleyo lomfanekiso wesoftware yomlawuli lwenziwa ngendlela efanayo nohlaziyo olusebenzayo, oko kukuthi, ngaphandle kwexesha lokuphumla. Nangona kunjalo, eli nqaku lifumaneka kuphela kuqwalaselo lweqela xa kukho ngaphezu komlawuli omnye. Uhlaziyo olupheleleyo lwenziwa ngokulandelelanayo: okokuqala kumlawuli omnye, ngoko okwesibini.

Ukongeza imodeli entsha yendawo yokufikelela

Ukuqhagamshela iindawo ezintsha zokufikelela, ezingazange zisetyenziswe ngaphambili kunye nomfanekiso wesofthiwe yomlawuli osetyenzisiweyo, kwinethiwekhi engenazintambo ngumsebenzi oqhelekileyo, ngokukodwa kwiinethiwekhi ezinkulu (ii-airport, iihotele, iifektri). Rhoqo kwizisombululo zabakhuphisanayo, lo msebenzi ufuna ukuhlaziya inkqubo yesoftware okanye ukuqalisa ngokutsha abalawuli.

Xa udibanisa iindawo ezintsha zokufikelela kwi-Wi-Fi 6 kwiqela le-Cisco Catalyst 9800 abalawuli beechungechunge, akukho ngxaki zibonwayo. Ukudibanisa amanqaku amatsha kumlawuli wenziwa ngaphandle kokuhlaziya isofthiwe yomlawuli, kwaye le nkqubo ayifuni ukuqaliswa kwakhona, ngoko ke ayichaphazeli inethiwekhi engenazintambo nangayiphi na indlela.

Ukusilela komlawuli

Indawo yokuvavanya isebenzisa abalawuli ababini be-Wi-Fi 6 (I-Active/StandBy) kwaye indawo yokufikelela inonxibelelwano oluthe ngqo kubo bobabini abalawuli.

Omnye umlawuli ongenazingcingo uyasebenza, kwaye omnye, ngokulandelelana, ugcina i-backup. Ukuba umlawuli osebenzayo akaphumeleli, umlawuli wogcino uthatha indawo kwaye isimo saso sitshintsha sisebenze. Le nkqubo yenzeka ngaphandle kokuphazamiseka kwindawo yofikelelo kunye ne-Wi-Fi kubaxhasi.

Khu seleko

Eli candelo lixoxa ngemiba yokhuseleko, engumba ocinezela kakhulu kwiinethiwekhi ezingenazingcingo. Ukhuseleko lwesisombululo luvavanywa ngokusekelwe kwezi mpawu zilandelayo:

  • Ukuqwalaselwa kwesicelo;
  • Ukulandela umkhondo;
  • Анализ Π·Π°ΡˆΠΈΡ„Ρ€ΠΎΠ²Π°Π½Π½ΠΎΠ³ΠΎ Ρ‚Ρ€Π°Ρ„ΠΈΠΊΠ°;
  • Ukubona ukungena kunye nokuthintela;
  • Ukuqinisekiswa kuthetha;
  • Izixhobo zokukhusela isixhobo somthengi.

Ukuqatshelwa kwesicelo

Phakathi kweemveliso ezahlukeneyo kwimarike ye-Wi-Fi yeshishini kunye nezoshishino, kukho umahluko kwindlela iimveliso ezichonga ngayo i-traffic ngokusebenzisa isicelo. Iimveliso ezivela kubavelisi abohlukeneyo zinokuchonga amanani ahlukeneyo osetyenziso. Nangona kunjalo, uninzi lwezicelo ezidwelisa izisombululo ezikhuphisanayo kangangoko kunokwenzeka ukuze zichongwe, enyanisweni, ziiwebhusayithi, kwaye ayizizo izicelo ezizodwa.

Kukho enye into enomdla yokuqatshelwa kwesicelo: izisombululo ziyahluka kakhulu ekuchongeni ukuchaneka.

Ukuqwalasela zonke iimvavanyo ezenziweyo, sinokuchaza ngokufanelekileyo ukuba isisombululo se-Wi-Fi-6 seCisco senza ukuqatshelwa kwesicelo ngokuchanekileyo: iJabber, iNetflix, iDropbox, i-YouTube kunye nezinye izicelo ezithandwayo, kunye neenkonzo zewebhu, zachongwa ngokuchanekileyo. Izisombululo zeCisco zinokuntywila nzulu kwiipakethi zedatha zisebenzisa iDPI (I-Deep Packet Inspection).

Ukulandelela ukuhamba kwetrafiki

Olunye uvavanyo lwenziwe ukujonga ukuba inkqubo inokulandelela ngokuchanekileyo kwaye inike ingxelo yokuhamba kwedatha (njengokuhamba kweefayile ezinkulu). Ukuvavanya oku, ifayile ye-megabyte eyi-6,5 ithunyelwe ngenethiwekhi kusetyenziswa iProtocol Transfer Protocol (FTP).

Isisombululo seCisco sasifikelele ngokupheleleyo kulo msebenzi kwaye sakwazi ukulandelela le trafiki ngokubonga kwi-NetFlow kunye nobuchule bayo be-hardware. Itrafikhi yabhaqwa yaza yachongwa ngoko nangoko ngesixa esichanekileyo sedatha edluliselweyo.

Uhlalutyo lwendlela entsonkothileyo

I-traffic data yomsebenzisi iya iguqulelwa ngokufihlakeleyo. Oku kwenziwa ukuze kukhuselwe ukuba ingalandelwa okanye ibanjwe ngabahlaseli. Kodwa kwangaxeshanye, abahlaseli bayanda ukusebenzisa i-encryption ukufihla i-malware yabo kwaye baqhube ezinye izinto ezithandabuzekayo ezifana ne-Man-in-the-Middle (MiTM) okanye uhlaselo lwe-keylogging.

Uninzi lwamashishini ahlola ezinye zetrafikhi yawo efihliweyo ngokuqala ngokuyicoca kusetyenziswa iindonga zomlilo okanye iinkqubo zokuthintela ukungena. Kodwa le nkqubo ithatha ixesha elininzi kwaye ayizuzi intsebenzo yenethiwekhi ngokubanzi. Ukongeza, yakuba ikhutshiwe, le datha iba sesichengeni sokujonga amehlo.

Cisco Catalyst 9800 Series abalawuli ukusombulula ngempumelelo ingxaki yokuhlalutya i-encrypted traffic ngezinye iindlela. Isisombululo sibizwa ngokuba yi-Encrypted Traffic Analytics (ETA). I-ETA yitekhnoloji okwangoku engenazo ii-analogues kwizisombululo ezikhuphisanayo kwaye ibona i-malware kwitrafikhi efihliweyo ngaphandle kwesidingo sokuyisusa. I-ETA luphawu olungundoqo lwe-IOS-XE oluquka i-NetFlow ephuculweyo kwaye isebenzisa iindlela zokuziphatha eziphucukileyo ukuchonga iipatheni ezikhohlakeleyo zendlela ezifihlwe kwitrafikhi efihliweyo.

Ukuba unomlawuli, akukho ngxaki: indlela yokugcina lula inethiwekhi yakho engenazingcingo

I-ETA ayikhiphi imiyalezo, kodwa iqokelela iiprofayili zemetadata zokuqukuqela kwetrafikhi efihliweyo - ubungakanani bepakethi, ixesha eliphakathi kweepakethi, nokunye okuninzi. Imethadatha ithunyelwa ngaphandle kwiirekhodi zeNetFlow v9 kwiCisco Stealthwatch.

Umsebenzi ophambili weStealthwatch kukubeka iliso rhoqo kwitrafikhi, kunye nokwenza isiseko somsebenzi wenethiwekhi eqhelekileyo. Isebenzisa imetadata yomjelo efihliweyo ethunyelwe kuyo yi-ETA, iStealthwatch isebenzisa umatshini wokufunda ngoomatshini abaninzi ukuchonga ukungahambi kakuhle kwendlela yokuziphatha enokubonisa iziganeko ezirhanelekayo.

Kulo nyaka uphelileyo, uCisco ubandakanye iMiercom ukuba ivavanye ngokuzimeleyo isisombululo sayo seCisco Encrypted Traffic Analytics. Ngexesha lovavanyo, i-Miercom yathumela ngokwahlukeneyo izoyikiso ezaziwayo nezingaziwayo (iintsholongwane, iiTrojani, i-ransomware) kwitrafikhi efihliweyo kunye ne-encrypted kwi-ETA enkulu kunye neenethiwekhi ezingezizo ze-ETA ukuchonga izoyikiso.

Ukuvavanya, ikhowudi enobungozi yasungulwa kuzo zombini iinethiwekhi. Kuzo zombini ezi meko, ngokuthe ngcembe kwafunyanwa umsebenzi okrokrisayo. Inethiwekhi ye-ETA iqale yafumanisa izoyikiso ze-36% ngokukhawuleza kunenethiwekhi engeyiyo ye-ETA. Ngexesha elifanayo, njengoko umsebenzi uqhubela phambili, imveliso yokufumanisa kwinethiwekhi ye-ETA yaqala ukwanda. Ngenxa yoko, emva kweeyure ezininzi zomsebenzi, isibini kwisithathu sezoyikiso ezisebenzayo zafunyanwa ngempumelelo kwinethiwekhi ye-ETA, ephindwe kabini kune-non-ETA network.

Ukusebenza kwe-ETA kudityaniswe kakuhle neStealthwatch. Izoyikiso zibekwe ngokobungqongqo kwaye ziboniswe ngolwazi oluneenkcukacha, kunye neendlela zokulungisa xa ziqinisekisiwe. Isiphelo - i-ETA iyasebenza!

Ukubona ukungena kunye nokuthintela

Ngoku iCisco inesinye isixhobo sokhuseleko esisebenzayo-iCisco Advanced Wireless Intrusion Prevention System (aWIP): isixhobo sokubona nokuthintela izoyikiso kuthungelwano olungenazingcingo. Isisombululo se-aWIPS sisebenza kwinqanaba labalawuli, iindawo zokufikelela kunye nesoftware yolawulo lweCisco DNA Centre. Ukufunyanwa kwesoyikiso, ukulumkisa, kunye nokuthintela kudibanisa uhlalutyo lwetrafikhi yenethiwekhi, isixhobo sothungelwano kunye nolwazi lwe-topology yenethiwekhi, ubuchule obusekwe kwisiginitsha, kunye nokufumanisa okungaqhelekanga ukuhambisa izisongelo ezichanekileyo nezinokuthintelwa ngaphandle kwamacingo.

Ukudibanisa ngokupheleleyo i-aWIPS kwisiseko senethiwekhi yakho, unokuqhubeka nokubeka iliso kwitrafikhi engenazingcingo kuzo zombini iinethiwekhi ezineentambo kunye nezingenazingcingo kwaye uyisebenzise ukuhlalutya ngokuzenzekelayo uhlaselo olunokuthi lubekho oluvela kwimithombo emininzi ukubonelela ngobona lwazi lubanzi kunye nothintelo olunokwenzeka.

Ukuqinisekiswa kuthetha

Okwangoku, ukongeza kwizixhobo zokuqinisekisa zakudala, iCisco Catalyst 9800 izisombululo zechungechunge zixhasa iWPA3. I-WPA3 yinguqulelo yamva nje ye-WPA, eyisethi yemigaqo kunye nobuchwepheshe obubonelela ngoqinisekiso kunye noguqulelo oluntsonkothileyo lweenethiwekhi ze-Wi-Fi.

I-WPA3 isebenzisa i-Simltaneous Authentication of Equals (SAE) ukubonelela ngokhuseleko oluluqilima kubasebenzisi ngokuchasene neenzame zokuqikelela igama eliyimfihlo liqela lesithathu. Xa umxhasi edibanisa kwindawo yokufikelela, yenza utshintshiselwano lwe-SAE. Ukuba uphumelele, ngamnye kubo uya kudala isitshixo esinamandla e-cryptographically apho iqhosha leseshoni liya kuphuma khona, kwaye ke baya kungena kwimeko yokuqinisekisa. Umxhasi kunye nendawo yofikelelo banokungena kwi-handshake states ngexesha ngalinye iqhosha leseshoni lifuna ukwenziwa. Indlela isebenzisa imfihlo eya phambili, apho umhlaseli angakwazi ukukrazula isitshixo esinye, kodwa kungekhona zonke ezinye izitshixo.

Oko kukuthi, i-SAE iyilwe ngendlela yokuba umhlaseli onqanda i-traffic unomzamo omnye kuphela wokuqikelela igama eligqithisiweyo ngaphambi kokuba idatha ebanjiweyo ingabi namsebenzi. Ukucwangcisa ukubuyiswa kwephasiwedi ende, uya kufuna ukufikelela ngokomzimba kwindawo yokufikelela.

Ukhuseleko lwesixhobo somthengi

I-Cisco Catalyst 9800 Series izisombululo ezingenazintambo okwangoku zibonelela ngeyona nto iphambili yokukhusela abathengi ngeCisco Umbrella WLAN, inkonzo yokhuseleko lwenethiwekhi esekelwe kwifu esebenza kwinqanaba le-DNS kunye nokufumanisa ngokuzenzekelayo zombini izisongelo ezaziwayo kunye nezivelayo.

I-Cisco Umbrella WLAN ibonelela ngezixhobo zabathengi ngoqhagamshelwano olukhuselekileyo kwi-Intanethi. Oku kuphunyezwa ngokucoca umxholo, oko kukuthi, ngokuthintela ukufikelela kwizibonelelo kwi-Intanethi ngokuhambelana nomgaqo-nkqubo weshishini. Ke, izixhobo zabaxumi kwi-Intanethi zikhuselwe kwi-malware, i-ransomware, kunye ne-phishing. Ukunyanzeliswa komgaqo-nkqubo kusekelwe kwiindidi zomxholo ezihlaziywa ngokuqhubekayo ezingama-60.

Ukuzenzekelayo

Uthungelwano lwanamhlanje olungenazingcingo lubhetyebhetye ngakumbi kwaye luntsonkothile, ngoko ke iindlela zemveli zokuqwalasela nokubuyisela ulwazi kubalawuli abangenazingcingo azanelanga. Abalawuli benethiwekhi kunye neengcali zokhuseleko lolwazi zifuna izixhobo zokuzenzekelayo kunye nohlalutyo, ukukhuthaza abathengisi abangenazintambo ukuba banikele ngezixhobo ezinjalo.

Ukusombulula ezi ngxaki, i-Cisco Catalyst 9800 abalawuli abangenazintambo ezingenazintambo, kunye ne-API yendabuko, inikezela ngenkxaso ye-RESTCONF / NETCONF yoqwalaselo lwenethiwekhi yeprotocol kunye neYANG (Kusesinye esinye isiZukulwana esilandelayo) ulwimi lokulinganisa idatha.

I-NETCONF yi-protocol esekwe kwi-XML ezinokuthi izicelo zisebenzise ukubuza ulwazi kunye nokutshintsha ukucwangciswa kwezixhobo zenethiwekhi ezifana nabalawuli abangenazintambo.

Ukongeza kwezi ndlela, i-Cisco Catalyst 9800 Series Controllers inikezela ngokukwazi ukubamba, ukufumana, kunye nokuhlalutya idatha yokuhamba kolwazi usebenzisa i-NetFlow kunye ne-sFlow protocol.

Ukhuseleko kunye nemodeli yetrafikhi, ukukwazi ukulandelela ukuhamba okuthe ngqo sisixhobo esibalulekileyo. Ukusombulula le ngxaki, iprotocol ye-sFlow yaphunyezwa, ekuvumela ukuba ubambe iipakethi ezimbini kwikhulu ngalinye. Nangona kunjalo, ngamanye amaxesha oku kusenokunganeli ukuhlalutya kunye nokufunda ngokwaneleyo kunye nokuvavanya ukuhamba. Ngoko ke, enye indlela yi-NetFlow, ephunyezwe yiCisco, evumela ukuba i-100% iqokelele kwaye ithumele ngaphandle zonke iipakethi kwi-flow ecacisiweyo yohlalutyo olulandelayo.

Enye into, nangona kunjalo, ekhoyo kuphela ekuphunyezweni kwe-hardware yabalawuli, ekuvumela ukuba wenze ngokuzenzekelayo ukusebenza kwenethiwekhi engenazintambo kwi-Cisco Catalyst 9800 abalawuli beechungechunge, inkxaso eyakhelwe-ngaphakathi yolwimi lwePython njenge-add-on yokusebenzisa. izikripthi ngqo kwisilawuli esingenazingcingo ngokwaso.

Ekugqibeleni, iCisco Catalyst 9800 Series Controllers ixhasa i-SNMP version 1, 2, kunye ne-3 yeprotocol eqinisekisiweyo yokubeka iliso kunye nemisebenzi yokulawula.

Ngaloo ndlela, ngokubhekiselele kwi-automation, i-Cisco Catalyst 9800 Series solutions ihlangabezana ngokupheleleyo neemfuno zoshishino zanamhlanje, ezinikezela zombini ezintsha kunye neyodwa, kunye nezixhobo ezivavanywe ixesha lokusebenza ngokuzenzekelayo kunye nohlalutyo kwiinethiwekhi ezingenazintambo zaluphi na ubukhulu kunye nobunzima.

isiphelo

Kwizisombululo ezisekelwe kwiCisco Catalyst 9800 Series Controllers, iCisco ibonise iziphumo ezigqwesileyo kwiindidi zokufumaneka okuphezulu, ukhuseleko kunye nokuzenzekelayo.

Isisombululo sihlangabezana ngokupheleleyo nazo zonke iimfuno eziphezulu zokufumaneka ezifana ne-sub-second failover ngexesha leziganeko ezingacwangciswanga kunye ne-zero downtime kwiziganeko ezicwangcisiweyo.

I-Cisco Catalyst 9800 Series Controllers inikezela ngokhuseleko olubanzi olubonelela ngokuhlolwa kwepakethe enzulu yokuqaphela isicelo kunye nokulawula, ukubonakala okupheleleyo kwiinkqubo zedatha, kunye nokuchongwa kwezisongelo ezifihliweyo kwi-traffic encrypted, kunye nokuqinisekiswa okuphambili kunye neendlela zokukhusela izixhobo zabaxhasi.

Ukuzenzekela kunye nokuhlalutya, i-Cisco Catalyst 9800 Series inikeza amandla anamandla usebenzisa imodeli esemgangathweni eyaziwayo: i-YANG, i-NETCONF, i-RESTCONF, i-APIs yendabuko, kunye nemibhalo ye-Python eyakhelwe ngaphakathi.

Ngaloo ndlela, iCisco iphinda iqinisekise isimo sayo njengomvelisi ohamba phambili wehlabathi wezisombululo zothungelwano, ukuhambisana namaxesha kunye nokuthathela ingqalelo yonke imingeni yeshishini lanamhlanje.

Ukufumana ulwazi oluthe kratya malunga nosapho lokutshintsha kweCatalyst, ndwendwela indawo ICisco.

umthombo: www.habr.com

Yongeza izimvo