Uma unesilawuli, akunankinga: ungayigcina kanjani kalula inethiwekhi yakho engenantambo

Ngo-2019, inkampani yokubonisana i-Miercom yenza ukuhlola okuzimele kwezobuchwepheshe kwabalawuli be-Wi-Fi 6 bochungechunge lwe-Cisco Catalyst 9800. Kulolu cwaningo, ibhentshi lokuhlola lahlanganiswa kusuka kubalawuli be-Cisco Wi-Fi 6 kanye nezindawo zokufinyelela, futhi isisombululo sezobuchwepheshe zihlolwe ezigabeni ezilandelayo:

  • Ukutholakala;
  • Ukuphepha;
  • Okuzenzakalelayo.

Imiphumela yocwaningo ikhonjiswe ngezansi. Kusukela ngo-2019, ukusebenza kwezilawuli zochungechunge lweCisco Catalyst 9800 kuye kwathuthukiswa kakhulu - lawa maphuzu aphinde aboniswe kulesi sihloko.

Ungafunda mayelana nezinye izinzuzo zobuchwepheshe be-Wi-Fi 6, izibonelo zokuqalisa kanye nezindawo zohlelo lokusebenza lapha.

Uhlolojikelele lwesixazululo

Izilawuli ze-Wi-Fi 6 Cisco Catalyst 9800 uchungechunge

I-Cisco Catalyst 9800 Series Wireless Controllers, esekelwe ohlelweni lokusebenza lwe-IOS-XE (ebuye isetshenziselwe ukushintshwa kwe-Cisco namarutha), iyatholakala ngezinketho ezihlukahlukene.

Uma unesilawuli, akunankinga: ungayigcina kanjani kalula inethiwekhi yakho engenantambo

Imodeli endala yesilawuli se-9800-80 isekela inethiwekhi engenantambo efinyelela ku-80 Gbps. Isilawuli esisodwa se-9800-80 sisekela izindawo zokufinyelela ezingafika ku-6000 kanye namaklayenti angenantambo afika kwangu-64.

Imodeli yebanga eliphakathi, isilawuli se-9800-40, isekela okokufaka kokudlulela kokufika ku-40 Gbps, amaphuzu okufinyelela afika kwangu-2000 kanye namaklayenti angenantambo afika kwangu-32.

Ngokungeziwe kulawa mamodeli, ukuhlaziywa kokuncintisana kuphinde kwafaka isilawuli esingenantambo se-9800-CL (CL imele Cloud). I-9800-CL isebenza ezindaweni ezibonakalayo ku-VMWare ESXI ne-KVM hypervisors, futhi ukusebenza kwayo kuncike ezinsizeni zehadiwe ezizinikele zomshini obonakalayo wesilawuli. Ekucushweni kwaso okuphezulu, isilawuli se-Cisco 9800-CL, njengemodeli endala engu-9800-80, sisekela amaphoyinti okufinyelela ku-6000 kanye namaklayenti angenantambo afika kwangu-64.

Lapho kwenziwa ucwaningo ngezilawuli, kwasetshenziswa izindawo zokufinyelela zochungechunge lwe-Cisco Aironet AP 4800, okusekela ukusebenza kumafrikhwensi angu-2,4 no-5 GHz ngekhono lokushintshela kumodi ekabili engu-5-GHz.

Isitendi sokuhlola

Njengengxenye yokuhlola, isitendi sahlanganiswa kusukela kuzilawuli ezimbili ezingenazintambo ze-Cisco Catalyst 9800-CL ezisebenza kuqoqo kanye nezindawo zokufinyelela zochungechunge lwe-Cisco Aironet AP 4800.

Amakhompyutha aphathekayo avela ku-Dell kanye ne-Apple, kanye ne-Apple iPhone smartphone, asetshenziswa njengamadivayisi eklayenti.

Uma unesilawuli, akunankinga: ungayigcina kanjani kalula inethiwekhi yakho engenantambo

Ukuhlola Ukufinyeleleka

Ukutholakala kuchazwa njengekhono labasebenzisi lokufinyelela nokusebenzisa isistimu noma isevisi. Ukutholakala okuphezulu kusho ukufinyelela okuqhubekayo ohlelweni noma isevisi, ngaphandle kwemicimbi ethile.

Ukutholakala okuphezulu kwahlolwa ezimeni ezine, izimo ezintathu zokuqala kube izehlakalo ezibikezelwayo noma ezihleliwe ezingase zenzeke phakathi noma ngemva kwamahora ebhizinisi. Isimo sesihlanu siwukwehluleka kwakudala, okuyisenzakalo esingalindelekile.

Incazelo yezimo:

  • Ukulungiswa kwephutha - i-micro-update yesistimu (i-bugfix noma isichibi sokuphepha), esikuvumela ukuthi ulungise iphutha elithile noma ubungozi ngaphandle kokubuyekezwa okuphelele kwesofthiwe yesistimu;
  • Ukuvuselelwa okusebenzayo - ukwengeza noma ukwandisa ukusebenza kwamanje kwesistimu ngokufaka izibuyekezo zokusebenza;
  • Isibuyekezo esigcwele - buyekeza isithombe sesofthiwe yesilawuli;
  • Ukwengeza indawo yokufinyelela - ukwengeza imodeli yephoyinti lokufinyelela elisha kunethiwekhi engenantambo ngaphandle kwesidingo sokumisa kabusha noma ukuvuselela isofthiwe yesilawuli esingenantambo;
  • Ukwehluleka—ukwehluleka kwesilawuli esingenantambo.

Ukulungisa iziphazamisi kanye nokuba sengozini

Ngokuvamile, ngezixazululo eziningi ezincintisanayo, ukuchibiyela kudinga isibuyekezo esiphelele sesofthiwe yesistimu yesilawuli esingenantambo, okungaholela ekuphumuleni okungahleliwe. Endabeni yesisombululo seCisco, ukubopha kwenziwa ngaphandle kokumisa umkhiqizo. Amapeshi angafakwa kunoma yiziphi izingxenye ngenkathi ingqalasizinda engenazintambo iqhubeka nokusebenza.

Inqubo ngokwayo ilula kakhulu. Ifayela le-patch likopishelwe kufolda ye-bootstrap kwesinye sezilawuli ezingenazintambo ze-Cisco, futhi ukusebenza kuqinisekiswa nge-GUI noma umugqa womyalo. Ngaphezu kwalokho, ungakwazi futhi ukuhlehlisa futhi ususe ukulungisa nge-GUI noma umugqa womyalo, futhi ngaphandle kokuphazamisa ukusebenza kwesistimu.

Isibuyekezo esisebenzayo

Ukubuyekezwa kwesofthiwe esebenzayo kusetshenziselwa ukunika amandla imisebenzi emisha. Okunye kwalokhu kuthuthukiswa ukubuyekeza isizindalwazi sesiginesha yohlelo lokusebenza. Le phakheji ifakwe kuzilawuli ze-Cisco njengokuhlola. Njengamapeshi, izibuyekezo zesici ziyasetshenziswa, zifakwe, noma zisuswe ngaphandle kokuphelelwa yisikhathi noma ukuphazamiseka kwesistimu.

Isibuyekezo esigcwele

Okwamanje, ukubuyekezwa okugcwele kwesithombe sesofthiwe yesilawuli kwenziwa ngendlela efanayo nesibuyekezo sokusebenza, okungukuthi, ngaphandle kwesikhathi sokuphumula. Nokho, lesi sici sitholakala kuphela ekucushweni kweqoqo uma kukhona isilawuli esingaphezu kwesisodwa. Ukubuyekeza okuphelele kwenziwa ngokulandelana: okokuqala kwisilawuli esisodwa, bese kuba kwesibili.

Ingeza imodeli yephoyinti lokufinyelela elisha

Ukuxhuma izindawo ezintsha zokufinyelela, ezingakaze zisetshenziswe ngaphambilini nesithombe sesofthiwe yesilawuli esisetshenzisiwe, kunethiwekhi engenazintambo kuwumsebenzi ovamile, ikakhulukazi kumanethiwekhi amakhulu (izikhumulo zezindiza, amahhotela, izimboni). Imvamisa ezixazululweni zesiqhudelani, lokhu kusebenza kudinga ukubuyekeza isoftware yesistimu noma ukuqalisa kabusha izilawuli.

Lapho uxhuma izindawo ezintsha zokufinyelela ze-Wi-Fi 6 kuqoqo lezilawuli zochungechunge lwe-Cisco Catalyst 9800, azikho izinkinga ezinjalo ezibonwayo. Ukuxhuma amaphuzu amasha kusilawuli kwenziwa ngaphandle kokubuyekeza isofthiwe yesilawuli, futhi le nqubo ayidingi ukuqalisa kabusha, ngaleyo ndlela ingaphazamisi inethiwekhi engenantambo nganoma iyiphi indlela.

Ukuhluleka kwesilawuli

Indawo yokuhlola isebenzisa izilawuli ezimbili ze-Wi-Fi 6 (I-Active/StandBy) futhi indawo yokufinyelela inokuxhumana okuqondile kuzo zombili izilawuli.

Isilawuli esisodwa esingenantambo siyasebenza, kanti esinye, ngokulandelana, siyisipele. Uma isilawuli esisebenzayo sihluleka, isilawuli esiyisipele siyathatha futhi isimo saso sishintshe sisebenze. Le nqubo yenzeka ngaphandle kokuphazamiseka endaweni yokufinyelela kanye ne-Wi-Fi yamaklayenti.

Ukuphepha

Lesi sigaba sidingida izici zokuphepha, okuwudaba olucindezela kakhulu kumanethiwekhi angenantambo. Ukuphepha kwesixazululo kuhlolwa ngokusekelwe ezicini ezilandelayo:

  • Ukuqashelwa kwesicelo;
  • Ukulandelela ukugeleza;
  • Ukuhlaziywa kwethrafikhi ebethelwe;
  • Ukutholwa nokuvimbela ukungena;
  • Ukufakazela ubuqiniso kusho;
  • Amathuluzi okuvikela idivayisi yeklayenti.

Ukuqashelwa kohlelo lokusebenza

Phakathi kwemikhiqizo ehlukahlukene emakethe ye-Wi-Fi yebhizinisi nezimboni, kunomehluko endleleni imikhiqizo ehlonza ngayo ithrafikhi ngokufaka isicelo. Imikhiqizo evela kubakhiqizi abahlukene ingase ihlonze izinombolo ezihlukene zezinhlelo zokusebenza. Kodwa-ke, izinhlelo zokusebenza eziningi ezifakwa ohlwini lwezixazululo ezincintisanayo ngangokunokwenzeka ukuze zihlonzwe, empeleni, zingamawebhusayithi, futhi azizona izinhlelo zokusebenza ezihlukile.

Kunesinye isici esijabulisayo sokuqashelwa kohlelo lokusebenza: izixazululo ziyahlukahluka kakhulu ekunembeni kokuhlonza.

Ngokucabangela zonke izivivinyo ezenziwe, singasho ngokuzibophezela ukuthi isisombululo se-Cisco Wi-Fi-6 senza ukuqashelwa kwesicelo ngokunembe kakhulu: I-Jabber, i-Netflix, i-Dropbox, i-YouTube nezinye izinhlelo zokusebenza ezidumile, kanye nezinsizakalo zewebhu, zihlonzwe ngokunembile. Izixazululo zeCisco zingangena futhi zijule emaphaketheni edatha zisebenzisa i-DPI (Deep Packet Inspection).

Ukulandelela ukugeleza kwethrafikhi

Olunye uvivinyo lwenziwa ukuze kubonakale ukuthi isistimu ingakwazi yini ukulandelela ngokunembile futhi ibike ukuhamba kwedatha (njengokunyakaza kwamafayela amakhulu). Ukuhlola lokhu, ifayela elingu-6,5 megabyte lithunyelwe ngenethiwekhi kusetshenziswa i-File Transfer Protocol (FTP).

Isixazululo se-Cisco sasifike ngokugcwele emsebenzini futhi sakwazi ukulandelela lokhu kubonga kwethrafikhi ku-NetFlow namandla ayo e-hardware. Ithrafikhi yatholwa futhi yahlonzwa ngokushesha ngenani eliqondile ledatha edlulisiwe.

Ukuhlaziywa kwethrafikhi ebethelwe

Ithrafikhi yedatha yomsebenzisi ilokhu ibethelwa ngokwandayo. Lokhu kwenzelwa ukuyivikela ekulandeleni noma ekubanjweni abahlaseli. Kepha ngasikhathi sinye, abaduni baya ngokuya besebenzisa ukubethela ukufihla uhlelo lwabo olungayilungele ikhompuyutha futhi benze eminye imisebenzi engabazekayo efana neMan-in-the-Middle (MiTM) noma ukuhlasela kwe-keylogging.

Amabhizinisi amaningi ahlola enye yethrafikhi yawo ebethelwe ngokuqala ngokuyisusa kusetshenziswa izindonga zomlilo noma amasistimu okuvimbela ukungena. Kodwa le nqubo ithatha isikhathi esiningi futhi ayizuzisi ukusebenza kwenethiwekhi iyonke. Ngaphezu kwalokho, uma isisusiwe, le datha iba sengozini yokubonwa ngamehlo.

Abalawuli beCisco Catalyst 9800 Series baxazulula ngempumelelo inkinga yokuhlaziya ithrafikhi ebethelwe ngezinye izindlela. Isixazululo sibizwa nge-Encrypted Traffic Analytics (ETA). I-ETA iwubuchwepheshe okwamanje obungenazo ama-analogue ezixazululweni ezincintisanayo futhi obuthola uhlelo olungayilungele ikhompuyutha kuthrafikhi ebethelwe ngaphandle kwesidingo sokuyisusa. I-ETA iyisici esiyinhloko se-IOS-XE esihlanganisa i-NetFlow Ethuthukisiwe futhi isebenzisa ama-algorithms okuziphatha athuthukisiwe ukuhlonza amaphethini ethrafikhi anonya acashe kuthrafikhi ebethelwe.

Uma unesilawuli, akunankinga: ungayigcina kanjani kalula inethiwekhi yakho engenantambo

I-ETA ayikhiphi imilayezo, kodwa iqoqa amaphrofayela emethadatha okugeleza kwethrafikhi ebethelwe - usayizi wephakethe, izikhawu zesikhathi phakathi kwamaphakethe, nokunye okuningi. Imethadatha ibe isithunyelwa kumarekhodi e-NetFlow v9 ku-Cisco Stealthwatch.

Umsebenzi obalulekile we-Stealthwatch wukuqapha njalo ithrafikhi, kanye nokudala isisekelo somsebenzi wenethiwekhi evamile. Isebenzisa imethadatha yokusakaza ebethelwe ethunyelwe kuyo yi-ETA, i-Stealthwatch isebenzisa umshini wokufunda onezendlalelo eziningi ukuze ikhombe okudidayo kwethrafikhi okungase kubonise izehlakalo ezisolisayo.

Ngonyaka odlule, i-Cisco ihlanganyele ne-Miercom ukuze ihlole ngokuzimela isisombululo sayo se-Cisco Encrypted Traffic Analytics. Phakathi nalokhu kuhlola, i-Miercom yathumela ngokuhlukana izinsongo ezaziwayo nezingaziwa (amagciwane, ama-Trojan, i-ransomware) kuthrafikhi ebethelwe futhi engabetheliwe kuwo wonke amanethiwekhi amakhulu e-ETA nangewona e-ETA ukuze kutholakale izinsongo.

Ukuze kuhlolwe, ikhodi enonya yethulwe kuwo womabili amanethiwekhi. Kuzo zombili izimo, kancane kancane kwatholakala umsebenzi osolisayo. Inethiwekhi ye-ETA ekuqaleni ithole izinsongo ezisheshayo ezingama-36% kunenethiwekhi engeyona ye-ETA. Ngesikhathi esifanayo, njengoba umsebenzi uqhubeka, ukukhiqizwa kokutholwa kunethiwekhi ye-ETA kwaqala ukwanda. Ngenxa yalokho, ngemva kwamahora ambalwa okusebenza, izingxenye ezimbili kwezintathu zezinsongo ezisebenzayo zitholwe ngempumelelo kunethiwekhi ye-ETA, ephindwe kabili kunenethiwekhi engeyona ye-ETA.

Ukusebenza kwe-ETA kuhlanganiswe kahle ne-Stealthwatch. Izinsongo zibalwa ngobunzima futhi ziboniswa ngolwazi oluningiliziwe, kanye nezinketho zokulungisa uma sekuqinisekisiwe. Isiphetho - I-ETA iyasebenza!

Ukutholwa nokuvimbela ukungena

I-Cisco manje inelinye ithuluzi lokuvikela elisebenzayo - i-Cisco Advanced Wireless Intrusion Prevention System (aWIP): indlela yokuthola nokuvimbela izinsongo kumanethiwekhi angenantambo. Isixazululo se-aWIPS sisebenza ezingeni lezilawuli, izindawo zokufinyelela kanye nesofthiwe yokuphatha ye-Cisco DNA Center. Ukutholwa kosongo, ukuxwayisa, nokuvimbela kuhlanganisa ukuhlaziywa kwethrafikhi yenethiwekhi, idivayisi yenethiwekhi nolwazi lwe-topology yenethiwekhi, amasu asekelwe kusiginesha, nokutholwa okudidayo ukuze kulethwe izinsongo ezingenazintambo ezinembile kakhulu nezingavinjelwa.

Ukuhlanganisa ngokugcwele i-aWIPS nengqalasizinda yenethiwekhi yakho, ungakwazi ngokuqhubekayo ukuqapha ithrafikhi engenantambo kuwo womabili amanethiwekhi anezintambo nangenawaya futhi ukusebenzisele ukuhlaziya ngokuzenzakalelayo ukuhlasela okungase kube khona okuvela emithonjeni eminingi ukuze unikeze ukutholwa nokuvimbela okuphelele kakhulu ngangokunokwenzeka.

Ukufakazela ubuqiniso kusho

Okwamanje, ngaphezu kwamathuluzi okufakazela ubuqiniso akudala, izixazululo zochungechunge lweCisco Catalyst 9800 zisekela i-WPA3. I-WPA3 inguqulo yakamuva ye-WPA, okuyisethi yezivumelwano nobuchwepheshe obunikeza ubuqiniso nokubethela kwamanethiwekhi e-Wi-Fi.

I-WPA3 isebenzisa i-Simultaneous Authentication of Equals (SAE) ukuze inikeze isivikelo esiqine kakhulu sabasebenzisi ngokumelene nemizamo yokuqagela iphasiwedi yezinkampani zangaphandle. Uma iklayenti lixhuma endaweni yokufinyelela, lenza ukushintshaniswa kwe-SAE. Uma kuphumelele, ngamunye wabo uzodala ukhiye oqinile we-cryptographically lapho kuzothathwa khona ukhiye weseshini, bese bengena esimweni sokuqinisekisa. Iklayenti nendawo yokufinyelela ingafaka izimo zokuxhawula isikhathi ngasinye lapho ukhiye weseshini udinga ukukhiqizwa. Indlela isebenzisa imfihlo eya phambili, lapho umhlaseli ekwazi ukuchoboza ukhiye owodwa, kodwa hhayi bonke abanye okhiye.

Okusho ukuthi, i-SAE yakhelwe ngendlela yokuthi umhlaseli ovimba ithrafikhi enomzamo owodwa kuphela wokuqagela iphasiwedi ngaphambi kokuthi idatha ebanjiwe ingabi namsebenzi. Ukuze uhlele ukutholwa kwephasiwedi ende, uzodinga ukufinyelela ngokomzimba endaweni yokufinyelela.

Ukuvikelwa kwedivayisi yeklayenti

Izixazululo ezingenantambo ze-Cisco Catalyst 9800 Series okwamanje zinikeza isici esiyinhloko sokuvikela ikhasimende nge-Cisco Umbrella WLAN, isevisi yenethiwekhi esekelwe emafini esebenza ezingeni le-DNS ngokutholwa okuzenzakalelayo kwakho kokubili izinsongo ezaziwayo nezivelayo.

I-Cisco Umbrella WLAN inikeza amadivaysi eklayenti ngoxhumano oluphephile ku-inthanethi. Lokhu kufezwa ngokuhlunga okuqukethwe, okungukuthi, ngokuvimba ukufinyelela ezinsizeni ku-inthanethi ngokuvumelana nenqubomgomo yebhizinisi. Ngakho, amadivayisi amaklayenti aku-inthanethi avikelekile kuhlelo olungayilungele ikhompuyutha, i-ransomware, kanye nobugebengu bokweba imininingwane ebucayi. Ukugcinwa kwenqubomgomo kusekelwe ezigabeni zokuqukethwe ezibuyekezwa njalo ezingama-60.

Ukuzenzakalela

Amanethiwekhi anamuhla angenawaya avumelana nezimo kakhulu futhi ayinkimbinkimbi, ngakho-ke izindlela zendabuko zokumisa nokuthola ulwazi kuzilawuli ezingenazintambo azanele. Abalawuli benethiwekhi nezingcweti zokuphepha kolwazi badinga amathuluzi okuzenzakalela kanye nezibalo, okukhuthaza abathengisi abangenazintambo ukuthi banikeze amathuluzi anjalo.

Ukuze kuxazululwe lezi zinkinga, izilawuli ezingenantambo ze-Cisco Catalyst 9800, kanye ne-API evamile, zinikeza ukusekelwa kwephrothokholi yokucushwa kwenethiwekhi ye-RESTCONF / NETCONF ngolimi lokumodela lwedatha ye-YANG (Yet Another Next Generation).

I-NETCONF iyiphrothokholi esekwe ku-XML izinhlelo zokusebenza ezingase ziyisebenzise ukubuza ulwazi futhi ziguqule ukucushwa kwamadivayisi enethiwekhi njengezilawuli ezingenantambo.

Ngaphezu kwalezi zindlela, i-Cisco Catalyst 9800 Series Controllers inikeza ikhono lokuthwebula, ukubuyisa, nokuhlaziya idatha yokugeleza kolwazi kusetshenziswa izivumelwano ze-NetFlow ne-sFlow.

Ngokuvikeleka nokumodela kwethrafikhi, ikhono lokulandelela ukugeleza okuthile liyithuluzi elibalulekile. Ukuxazulula le nkinga, i-protocol ye-sFlow yasetshenziswa, evumela ukuthi uthwebule amaphakethe amabili kulelo nalelo khulu. Nokho, ngezinye izikhathi lokhu kungase kungenele ukuhlaziya nokutadisha ngokwanele nokuhlola ukugeleza. Ngakho-ke, enye i-NetFlow, esetshenziswa yi-Cisco, ekuvumela ukuthi uqoqe futhi ukhiphe wonke amaphakethe ngokugeleza okucacisiwe ukuze kuhlaziywe okulandelayo.

Esinye isici, noma kunjalo, esitholakala kuphela ekusetshenzisweni kwe-hardware yabalawuli, okukuvumela ukuthi wenze ngokuzenzakalelayo ukusebenza kwenethiwekhi engenantambo kubalawuli bechungechunge lweCisco Catalyst 9800, ukusekelwa okwakhelwe ngaphakathi kolimi lwePython njengesengezo sokusebenzisa. ibhala ngokuqondile kusilawuli esingenantambo ngokwaso.

Ekugcineni, abalawuli beCisco Catalyst 9800 Series basekela i-SNMP version 1, 2, kanye ne-3 protocol eqinisekisiwe yokuqapha nokuphatha imisebenzi.

Ngakho-ke, ngokuzenzakalelayo, izixazululo ze-Cisco Catalyst 9800 Series zihlangabezana ngokugcwele nezidingo zebhizinisi zanamuhla, ezinikeza kokubili okusha nokuyingqayizivele, kanye namathuluzi ahlolwe isikhathi okusebenza okuzenzakalelayo nokuhlaziya kumanethiwekhi angenawaya anoma yisiphi isayizi nobunzima.

isiphetho

Kuzixazululo ezisekelwe ku-Cisco Catalyst 9800 Series Controllers, i-Cisco ibonise imiphumela emihle kakhulu ezigabeni zokutholakala okuphezulu, ukuphepha kanye ne-automation.

Isixazululo sihlangabezana ngokugcwele nazo zonke izidingo zokutholakala okuphezulu okufana ne-failover yesekhondi elincane phakathi nemicimbi engahleliwe kanye nesikhathi sokuphumula esiyiziro semicimbi ehleliwe.

I-Cisco Catalyst 9800 Series Controllers ihlinzeka ngokuphepha okuphelele okuhlinzeka ngokuhlolwa kwephakethe okujulile kokuqashelwa nokulawula uhlelo lokusebenza, ukubonakala okuphelele ekugelezeni kwedatha, nokuhlonza izinsongo ezifihliwe kuthrafikhi ebethelwe, kanye nezindlela zokuqinisekisa ezithuthukisiwe zokuphepha zamadivayisi weklayenti.

Ngokuzenzakalela nokuhlaziya, i-Cisco Catalyst 9800 Series inikezela ngamakhono anamandla kusetshenziswa amamodeli ajwayelekile adumile: i-YANG, i-NETCONF, i-RESTCONF, ama-API endabuko, nemibhalo ye-Python eyakhelwe ngaphakathi.

Ngakho-ke, i-Cisco iphinda iqinisekisa isimo sayo njengomkhiqizi ohamba phambili emhlabeni wezixazululo zokuxhumana, ehambisana nezikhathi futhi ecabangela zonke izinselele zebhizinisi lesimanje.

Ukuze uthole ulwazi olwengeziwe mayelana nomndeni wokushintsha kwe-Catalyst, vakashela isayithi I-Cisco.

Source: www.habr.com

Engeza amazwana

Ngo-2019, inkampani yokubonisana i-Miercom yenza ukuhlola okuzimele kwezobuchwepheshe kwabalawuli be-Wi-Fi 6 bochungechunge lwe-Cisco Catalyst 9800. Kulolu cwaningo, ibhentshi lokuhlola lahlanganiswa kusuka kubalawuli be-Cisco Wi-Fi 6 kanye nezindawo zokufinyelela, futhi isisombululo sezobuchwepheshe zihlolwe ezigabeni ezilandelayo:

  • Ukutholakala;
  • Ukuphepha;
  • Okuzenzakalelayo.

Imiphumela yocwaningo ikhonjiswe ngezansi. Kusukela ngo-2019, ukusebenza kwezilawuli zochungechunge lweCisco Catalyst 9800 kuye kwathuthukiswa kakhulu - lawa maphuzu aphinde aboniswe kulesi sihloko.

Ungafunda mayelana nezinye izinzuzo zobuchwepheshe be-Wi-Fi 6, izibonelo zokuqalisa kanye nezindawo zohlelo lokusebenza lapha.

Uhlolojikelele lwesixazululo

Izilawuli ze-Wi-Fi 6 Cisco Catalyst 9800 uchungechunge

I-Cisco Catalyst 9800 Series Wireless Controllers, esekelwe ohlelweni lokusebenza lwe-IOS-XE (ebuye isetshenziselwe ukushintshwa kwe-Cisco namarutha), iyatholakala ngezinketho ezihlukahlukene.

Uma unesilawuli, akunankinga: ungayigcina kanjani kalula inethiwekhi yakho engenantambo

Imodeli endala yesilawuli se-9800-80 isekela inethiwekhi engenantambo efinyelela ku-80 Gbps. Isilawuli esisodwa se-9800-80 sisekela izindawo zokufinyelela ezingafika ku-6000 kanye namaklayenti angenantambo afika kwangu-64.

Imodeli yebanga eliphakathi, isilawuli se-9800-40, isekela okokufaka kokudlulela kokufika ku-40 Gbps, amaphuzu okufinyelela afika kwangu-2000 kanye namaklayenti angenantambo afika kwangu-32.

Ngokungeziwe kulawa mamodeli, ukuhlaziywa kokuncintisana kuphinde kwafaka isilawuli esingenantambo se-9800-CL (CL imele Cloud). I-9800-CL isebenza ezindaweni ezibonakalayo ku-VMWare ESXI ne-KVM hypervisors, futhi ukusebenza kwayo kuncike ezinsizeni zehadiwe ezizinikele zomshini obonakalayo wesilawuli. Ekucushweni kwaso okuphezulu, isilawuli se-Cisco 9800-CL, njengemodeli endala engu-9800-80, sisekela amaphoyinti okufinyelela ku-6000 kanye namaklayenti angenantambo afika kwangu-64.

Lapho kwenziwa ucwaningo ngezilawuli, kwasetshenziswa izindawo zokufinyelela zochungechunge lwe-Cisco Aironet AP 4800, okusekela ukusebenza kumafrikhwensi angu-2,4 no-5 GHz ngekhono lokushintshela kumodi ekabili engu-5-GHz.

Isitendi sokuhlola

Njengengxenye yokuhlola, isitendi sahlanganiswa kusukela kuzilawuli ezimbili ezingenazintambo ze-Cisco Catalyst 9800-CL ezisebenza kuqoqo kanye nezindawo zokufinyelela zochungechunge lwe-Cisco Aironet AP 4800.

Amakhompyutha aphathekayo avela ku-Dell kanye ne-Apple, kanye ne-Apple iPhone smartphone, asetshenziswa njengamadivayisi eklayenti.

Uma unesilawuli, akunankinga: ungayigcina kanjani kalula inethiwekhi yakho engenantambo

Ukuhlola Ukufinyeleleka

Ukutholakala kuchazwa njengekhono labasebenzisi lokufinyelela nokusebenzisa isistimu noma isevisi. Ukutholakala okuphezulu kusho ukufinyelela okuqhubekayo ohlelweni noma isevisi, ngaphandle kwemicimbi ethile.

Ukutholakala okuphezulu kwahlolwa ezimeni ezine, izimo ezintathu zokuqala kube izehlakalo ezibikezelwayo noma ezihleliwe ezingase zenzeke phakathi noma ngemva kwamahora ebhizinisi. Isimo sesihlanu siwukwehluleka kwakudala, okuyisenzakalo esingalindelekile.

Incazelo yezimo:

  • Ukulungiswa kwephutha - i-micro-update yesistimu (i-bugfix noma isichibi sokuphepha), esikuvumela ukuthi ulungise iphutha elithile noma ubungozi ngaphandle kokubuyekezwa okuphelele kwesofthiwe yesistimu;
  • Ukuvuselelwa okusebenzayo - ukwengeza noma ukwandisa ukusebenza kwamanje kwesistimu ngokufaka izibuyekezo zokusebenza;
  • Isibuyekezo esigcwele - buyekeza isithombe sesofthiwe yesilawuli;
  • Ukwengeza indawo yokufinyelela - ukwengeza imodeli yephoyinti lokufinyelela elisha kunethiwekhi engenantambo ngaphandle kwesidingo sokumisa kabusha noma ukuvuselela isofthiwe yesilawuli esingenantambo;
  • Ukwehluleka—ukwehluleka kwesilawuli esingenantambo.

Ukulungisa iziphazamisi kanye nokuba sengozini

Ngokuvamile, ngezixazululo eziningi ezincintisanayo, ukuchibiyela kudinga isibuyekezo esiphelele sesofthiwe yesistimu yesilawuli esingenantambo, okungaholela ekuphumuleni okungahleliwe. Endabeni yesisombululo seCisco, ukubopha kwenziwa ngaphandle kokumisa umkhiqizo. Amapeshi angafakwa kunoma yiziphi izingxenye ngenkathi ingqalasizinda engenazintambo iqhubeka nokusebenza.

Inqubo ngokwayo ilula kakhulu. Ifayela le-patch likopishelwe kufolda ye-bootstrap kwesinye sezilawuli ezingenazintambo ze-Cisco, futhi ukusebenza kuqinisekiswa nge-GUI noma umugqa womyalo. Ngaphezu kwalokho, ungakwazi futhi ukuhlehlisa futhi ususe ukulungisa nge-GUI noma umugqa womyalo, futhi ngaphandle kokuphazamisa ukusebenza kwesistimu.

Isibuyekezo esisebenzayo

Ukubuyekezwa kwesofthiwe esebenzayo kusetshenziselwa ukunika amandla imisebenzi emisha. Okunye kwalokhu kuthuthukiswa ukubuyekeza isizindalwazi sesiginesha yohlelo lokusebenza. Le phakheji ifakwe kuzilawuli ze-Cisco njengokuhlola. Njengamapeshi, izibuyekezo zesici ziyasetshenziswa, zifakwe, noma zisuswe ngaphandle kokuphelelwa yisikhathi noma ukuphazamiseka kwesistimu.

Isibuyekezo esigcwele

Okwamanje, ukubuyekezwa okugcwele kwesithombe sesofthiwe yesilawuli kwenziwa ngendlela efanayo nesibuyekezo sokusebenza, okungukuthi, ngaphandle kwesikhathi sokuphumula. Nokho, lesi sici sitholakala kuphela ekucushweni kweqoqo uma kukhona isilawuli esingaphezu kwesisodwa. Ukubuyekeza okuphelele kwenziwa ngokulandelana: okokuqala kwisilawuli esisodwa, bese kuba kwesibili.

Ingeza imodeli yephoyinti lokufinyelela elisha

Ukuxhuma izindawo ezintsha zokufinyelela, ezingakaze zisetshenziswe ngaphambilini nesithombe sesofthiwe yesilawuli esisetshenzisiwe, kunethiwekhi engenazintambo kuwumsebenzi ovamile, ikakhulukazi kumanethiwekhi amakhulu (izikhumulo zezindiza, amahhotela, izimboni). Imvamisa ezixazululweni zesiqhudelani, lokhu kusebenza kudinga ukubuyekeza isoftware yesistimu noma ukuqalisa kabusha izilawuli.

Lapho uxhuma izindawo ezintsha zokufinyelela ze-Wi-Fi 6 kuqoqo lezilawuli zochungechunge lwe-Cisco Catalyst 9800, azikho izinkinga ezinjalo ezibonwayo. Ukuxhuma amaphuzu amasha kusilawuli kwenziwa ngaphandle kokubuyekeza isofthiwe yesilawuli, futhi le nqubo ayidingi ukuqalisa kabusha, ngaleyo ndlela ingaphazamisi inethiwekhi engenantambo nganoma iyiphi indlela.

Ukuhluleka kwesilawuli

Indawo yokuhlola isebenzisa izilawuli ezimbili ze-Wi-Fi 6 (I-Active/StandBy) futhi indawo yokufinyelela inokuxhumana okuqondile kuzo zombili izilawuli.

Isilawuli esisodwa esingenantambo siyasebenza, kanti esinye, ngokulandelana, siyisipele. Uma isilawuli esisebenzayo sihluleka, isilawuli esiyisipele siyathatha futhi isimo saso sishintshe sisebenze. Le nqubo yenzeka ngaphandle kokuphazamiseka endaweni yokufinyelela kanye ne-Wi-Fi yamaklayenti.

Ukuphepha

Lesi sigaba sidingida izici zokuphepha, okuwudaba olucindezela kakhulu kumanethiwekhi angenantambo. Ukuphepha kwesixazululo kuhlolwa ngokusekelwe ezicini ezilandelayo:

  • Ukuqashelwa kwesicelo;
  • Ukulandelela ukugeleza;
  • Ukuhlaziywa kwethrafikhi ebethelwe;
  • Ukutholwa nokuvimbela ukungena;
  • Ukufakazela ubuqiniso kusho;
  • Amathuluzi okuvikela idivayisi yeklayenti.

Ukuqashelwa kohlelo lokusebenza

Phakathi kwemikhiqizo ehlukahlukene emakethe ye-Wi-Fi yebhizinisi nezimboni, kunomehluko endleleni imikhiqizo ehlonza ngayo ithrafikhi ngokufaka isicelo. Imikhiqizo evela kubakhiqizi abahlukene ingase ihlonze izinombolo ezihlukene zezinhlelo zokusebenza. Kodwa-ke, izinhlelo zokusebenza eziningi ezifakwa ohlwini lwezixazululo ezincintisanayo ngangokunokwenzeka ukuze zihlonzwe, empeleni, zingamawebhusayithi, futhi azizona izinhlelo zokusebenza ezihlukile.

Kunesinye isici esijabulisayo sokuqashelwa kohlelo lokusebenza: izixazululo ziyahlukahluka kakhulu ekunembeni kokuhlonza.

Ngokucabangela zonke izivivinyo ezenziwe, singasho ngokuzibophezela ukuthi isisombululo se-Cisco Wi-Fi-6 senza ukuqashelwa kwesicelo ngokunembe kakhulu: I-Jabber, i-Netflix, i-Dropbox, i-YouTube nezinye izinhlelo zokusebenza ezidumile, kanye nezinsizakalo zewebhu, zihlonzwe ngokunembile. Izixazululo zeCisco zingangena futhi zijule emaphaketheni edatha zisebenzisa i-DPI (Deep Packet Inspection).

Ukulandelela ukugeleza kwethrafikhi

Olunye uvivinyo lwenziwa ukuze kubonakale ukuthi isistimu ingakwazi yini ukulandelela ngokunembile futhi ibike ukuhamba kwedatha (njengokunyakaza kwamafayela amakhulu). Ukuhlola lokhu, ifayela elingu-6,5 megabyte lithunyelwe ngenethiwekhi kusetshenziswa i-File Transfer Protocol (FTP).

Isixazululo se-Cisco sasifike ngokugcwele emsebenzini futhi sakwazi ukulandelela lokhu kubonga kwethrafikhi ku-NetFlow namandla ayo e-hardware. Ithrafikhi yatholwa futhi yahlonzwa ngokushesha ngenani eliqondile ledatha edlulisiwe.

Ukuhlaziywa kwethrafikhi ebethelwe

Ithrafikhi yedatha yomsebenzisi ilokhu ibethelwa ngokwandayo. Lokhu kwenzelwa ukuyivikela ekulandeleni noma ekubanjweni abahlaseli. Kepha ngasikhathi sinye, abaduni baya ngokuya besebenzisa ukubethela ukufihla uhlelo lwabo olungayilungele ikhompuyutha futhi benze eminye imisebenzi engabazekayo efana neMan-in-the-Middle (MiTM) noma ukuhlasela kwe-keylogging.

Amabhizinisi amaningi ahlola enye yethrafikhi yawo ebethelwe ngokuqala ngokuyisusa kusetshenziswa izindonga zomlilo noma amasistimu okuvimbela ukungena. Kodwa le nqubo ithatha isikhathi esiningi futhi ayizuzisi ukusebenza kwenethiwekhi iyonke. Ngaphezu kwalokho, uma isisusiwe, le datha iba sengozini yokubonwa ngamehlo.

Abalawuli beCisco Catalyst 9800 Series baxazulula ngempumelelo inkinga yokuhlaziya ithrafikhi ebethelwe ngezinye izindlela. Isixazululo sibizwa nge-Encrypted Traffic Analytics (ETA). I-ETA iwubuchwepheshe okwamanje obungenazo ama-analogue ezixazululweni ezincintisanayo futhi obuthola uhlelo olungayilungele ikhompuyutha kuthrafikhi ebethelwe ngaphandle kwesidingo sokuyisusa. I-ETA iyisici esiyinhloko se-IOS-XE esihlanganisa i-NetFlow Ethuthukisiwe futhi isebenzisa ama-algorithms okuziphatha athuthukisiwe ukuhlonza amaphethini ethrafikhi anonya acashe kuthrafikhi ebethelwe.

Uma unesilawuli, akunankinga: ungayigcina kanjani kalula inethiwekhi yakho engenantambo

I-ETA ayikhiphi imilayezo, kodwa iqoqa amaphrofayela emethadatha okugeleza kwethrafikhi ebethelwe - usayizi wephakethe, izikhawu zesikhathi phakathi kwamaphakethe, nokunye okuningi. Imethadatha ibe isithunyelwa kumarekhodi e-NetFlow v9 ku-Cisco Stealthwatch.

Umsebenzi obalulekile we-Stealthwatch wukuqapha njalo ithrafikhi, kanye nokudala isisekelo somsebenzi wenethiwekhi evamile. Isebenzisa imethadatha yokusakaza ebethelwe ethunyelwe kuyo yi-ETA, i-Stealthwatch isebenzisa umshini wokufunda onezendlalelo eziningi ukuze ikhombe okudidayo kwethrafikhi okungase kubonise izehlakalo ezisolisayo.

Ngonyaka odlule, i-Cisco ihlanganyele ne-Miercom ukuze ihlole ngokuzimela isisombululo sayo se-Cisco Encrypted Traffic Analytics. Phakathi nalokhu kuhlola, i-Miercom yathumela ngokuhlukana izinsongo ezaziwayo nezingaziwa (amagciwane, ama-Trojan, i-ransomware) kuthrafikhi ebethelwe futhi engabetheliwe kuwo wonke amanethiwekhi amakhulu e-ETA nangewona e-ETA ukuze kutholakale izinsongo.

Ukuze kuhlolwe, ikhodi enonya yethulwe kuwo womabili amanethiwekhi. Kuzo zombili izimo, kancane kancane kwatholakala umsebenzi osolisayo. Inethiwekhi ye-ETA ekuqaleni ithole izinsongo ezisheshayo ezingama-36% kunenethiwekhi engeyona ye-ETA. Ngesikhathi esifanayo, njengoba umsebenzi uqhubeka, ukukhiqizwa kokutholwa kunethiwekhi ye-ETA kwaqala ukwanda. Ngenxa yalokho, ngemva kwamahora ambalwa okusebenza, izingxenye ezimbili kwezintathu zezinsongo ezisebenzayo zitholwe ngempumelelo kunethiwekhi ye-ETA, ephindwe kabili kunenethiwekhi engeyona ye-ETA.

Ukusebenza kwe-ETA kuhlanganiswe kahle ne-Stealthwatch. Izinsongo zibalwa ngobunzima futhi ziboniswa ngolwazi oluningiliziwe, kanye nezinketho zokulungisa uma sekuqinisekisiwe. Isiphetho - I-ETA iyasebenza!

Ukutholwa nokuvimbela ukungena

I-Cisco manje inelinye ithuluzi lokuvikela elisebenzayo - i-Cisco Advanced Wireless Intrusion Prevention System (aWIP): indlela yokuthola nokuvimbela izinsongo kumanethiwekhi angenantambo. Isixazululo se-aWIPS sisebenza ezingeni lezilawuli, izindawo zokufinyelela kanye nesofthiwe yokuphatha ye-Cisco DNA Center. Ukutholwa kosongo, ukuxwayisa, nokuvimbela kuhlanganisa ukuhlaziywa kwethrafikhi yenethiwekhi, idivayisi yenethiwekhi nolwazi lwe-topology yenethiwekhi, amasu asekelwe kusiginesha, nokutholwa okudidayo ukuze kulethwe izinsongo ezingenazintambo ezinembile kakhulu nezingavinjelwa.

Ukuhlanganisa ngokugcwele i-aWIPS nengqalasizinda yenethiwekhi yakho, ungakwazi ngokuqhubekayo ukuqapha ithrafikhi engenantambo kuwo womabili amanethiwekhi anezintambo nangenawaya futhi ukusebenzisele ukuhlaziya ngokuzenzakalelayo ukuhlasela okungase kube khona okuvela emithonjeni eminingi ukuze unikeze ukutholwa nokuvimbela okuphelele kakhulu ngangokunokwenzeka.

Ukufakazela ubuqiniso kusho

Okwamanje, ngaphezu kwamathuluzi okufakazela ubuqiniso akudala, izixazululo zochungechunge lweCisco Catalyst 9800 zisekela i-WPA3. I-WPA3 inguqulo yakamuva ye-WPA, okuyisethi yezivumelwano nobuchwepheshe obunikeza ubuqiniso nokubethela kwamanethiwekhi e-Wi-Fi.

I-WPA3 isebenzisa i-Simultaneous Authentication of Equals (SAE) ukuze inikeze isivikelo esiqine kakhulu sabasebenzisi ngokumelene nemizamo yokuqagela iphasiwedi yezinkampani zangaphandle. Uma iklayenti lixhuma endaweni yokufinyelela, lenza ukushintshaniswa kwe-SAE. Uma kuphumelele, ngamunye wabo uzodala ukhiye oqinile we-cryptographically lapho kuzothathwa khona ukhiye weseshini, bese bengena esimweni sokuqinisekisa. Iklayenti nendawo yokufinyelela ingafaka izimo zokuxhawula isikhathi ngasinye lapho ukhiye weseshini udinga ukukhiqizwa. Indlela isebenzisa imfihlo eya phambili, lapho umhlaseli ekwazi ukuchoboza ukhiye owodwa, kodwa hhayi bonke abanye okhiye.

Okusho ukuthi, i-SAE yakhelwe ngendlela yokuthi umhlaseli ovimba ithrafikhi enomzamo owodwa kuphela wokuqagela iphasiwedi ngaphambi kokuthi idatha ebanjiwe ingabi namsebenzi. Ukuze uhlele ukutholwa kwephasiwedi ende, uzodinga ukufinyelela ngokomzimba endaweni yokufinyelela.

Ukuvikelwa kwedivayisi yeklayenti

Izixazululo ezingenantambo ze-Cisco Catalyst 9800 Series okwamanje zinikeza isici esiyinhloko sokuvikela ikhasimende nge-Cisco Umbrella WLAN, isevisi yenethiwekhi esekelwe emafini esebenza ezingeni le-DNS ngokutholwa okuzenzakalelayo kwakho kokubili izinsongo ezaziwayo nezivelayo.

I-Cisco Umbrella WLAN inikeza amadivaysi eklayenti ngoxhumano oluphephile ku-inthanethi. Lokhu kufezwa ngokuhlunga okuqukethwe, okungukuthi, ngokuvimba ukufinyelela ezinsizeni ku-inthanethi ngokuvumelana nenqubomgomo yebhizinisi. Ngakho, amadivayisi amaklayenti aku-inthanethi avikelekile kuhlelo olungayilungele ikhompuyutha, i-ransomware, kanye nobugebengu bokweba imininingwane ebucayi. Ukugcinwa kwenqubomgomo kusekelwe ezigabeni zokuqukethwe ezibuyekezwa njalo ezingama-60.

Ukuzenzakalela

Amanethiwekhi anamuhla angenawaya avumelana nezimo kakhulu futhi ayinkimbinkimbi, ngakho-ke izindlela zendabuko zokumisa nokuthola ulwazi kuzilawuli ezingenazintambo azanele. Abalawuli benethiwekhi nezingcweti zokuphepha kolwazi badinga amathuluzi okuzenzakalela kanye nezibalo, okukhuthaza abathengisi abangenazintambo ukuthi banikeze amathuluzi anjalo.

Ukuze kuxazululwe lezi zinkinga, izilawuli ezingenantambo ze-Cisco Catalyst 9800, kanye ne-API evamile, zinikeza ukusekelwa kwephrothokholi yokucushwa kwenethiwekhi ye-RESTCONF / NETCONF ngolimi lokumodela lwedatha ye-YANG (Yet Another Next Generation).

I-NETCONF iyiphrothokholi esekwe ku-XML izinhlelo zokusebenza ezingase ziyisebenzise ukubuza ulwazi futhi ziguqule ukucushwa kwamadivayisi enethiwekhi njengezilawuli ezingenantambo.

Ngaphezu kwalezi zindlela, i-Cisco Catalyst 9800 Series Controllers inikeza ikhono lokuthwebula, ukubuyisa, nokuhlaziya idatha yokugeleza kolwazi kusetshenziswa izivumelwano ze-NetFlow ne-sFlow.

Ngokuvikeleka nokumodela kwethrafikhi, ikhono lokulandelela ukugeleza okuthile liyithuluzi elibalulekile. Ukuxazulula le nkinga, i-protocol ye-sFlow yasetshenziswa, evumela ukuthi uthwebule amaphakethe amabili kulelo nalelo khulu. Nokho, ngezinye izikhathi lokhu kungase kungenele ukuhlaziya nokutadisha ngokwanele nokuhlola ukugeleza. Ngakho-ke, enye i-NetFlow, esetshenziswa yi-Cisco, ekuvumela ukuthi uqoqe futhi ukhiphe wonke amaphakethe ngokugeleza okucacisiwe ukuze kuhlaziywe okulandelayo.

Esinye isici, noma kunjalo, esitholakala kuphela ekusetshenzisweni kwe-hardware yabalawuli, okukuvumela ukuthi wenze ngokuzenzakalelayo ukusebenza kwenethiwekhi engenantambo kubalawuli bechungechunge lweCisco Catalyst 9800, ukusekelwa okwakhelwe ngaphakathi kolimi lwePython njengesengezo sokusebenzisa. ibhala ngokuqondile kusilawuli esingenantambo ngokwaso.

Ekugcineni, abalawuli beCisco Catalyst 9800 Series basekela i-SNMP version 1, 2, kanye ne-3 protocol eqinisekisiwe yokuqapha nokuphatha imisebenzi.

Ngakho-ke, ngokuzenzakalelayo, izixazululo ze-Cisco Catalyst 9800 Series zihlangabezana ngokugcwele nezidingo zebhizinisi zanamuhla, ezinikeza kokubili okusha nokuyingqayizivele, kanye namathuluzi ahlolwe isikhathi okusebenza okuzenzakalelayo nokuhlaziya kumanethiwekhi angenawaya anoma yisiphi isayizi nobunzima.

isiphetho

Kuzixazululo ezisekelwe ku-Cisco Catalyst 9800 Series Controllers, i-Cisco ibonise imiphumela emihle kakhulu ezigabeni zokutholakala okuphezulu, ukuphepha kanye ne-automation.

Isixazululo sihlangabezana ngokugcwele nazo zonke izidingo zokutholakala okuphezulu okufana ne-failover yesekhondi elincane phakathi nemicimbi engahleliwe kanye nesikhathi sokuphumula esiyiziro semicimbi ehleliwe.

I-Cisco Catalyst 9800 Series Controllers ihlinzeka ngokuphepha okuphelele okuhlinzeka ngokuhlolwa kwephakethe okujulile kokuqashelwa nokulawula uhlelo lokusebenza, ukubonakala okuphelele ekugelezeni kwedatha, nokuhlonza izinsongo ezifihliwe kuthrafikhi ebethelwe, kanye nezindlela zokuqinisekisa ezithuthukisiwe zokuphepha zamadivayisi weklayenti.

Ngokuzenzakalela nokuhlaziya, i-Cisco Catalyst 9800 Series inikezela ngamakhono anamandla kusetshenziswa amamodeli ajwayelekile adumile: i-YANG, i-NETCONF, i-RESTCONF, ama-API endabuko, nemibhalo ye-Python eyakhelwe ngaphakathi.

Ngakho-ke, i-Cisco iphinda iqinisekisa isimo sayo njengomkhiqizi ohamba phambili emhlabeni wezixazululo zokuxhumana, ehambisana nezikhathi futhi ecabangela zonke izinselele zebhizinisi lesimanje.

Ukuze uthole ulwazi olwengeziwe mayelana nomndeni wokushintsha kwe-Catalyst, vakashela isayithi I-Cisco.

Source: www.habr.com

Engeza amazwana