Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
en:dpi:faq:start [2021/07/22 17:25] – ↷ Links adapted because of a move operation lexx26 | en:dpi:faq:start [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== 7 FAQ ====== | ||
- | {{indexmenu_n> | ||
- | < | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | < | ||
- | -Can one use the own list rather than the one loaded from clouds?\\ Can one make DPI to use our list of restricted resources only?\\ **Answer:** Yes. The cloud service is implemented for your convenience, | ||
- | -Do you pass STP transparently? | ||
- | -Does the filtering by Federal Supervision Agency for Information Technologies and Communications and Department of Justice lists work in case VAS Experts DPI processes the outbound traffic only?\\ Can your system operate passing not the whole traffic but only that one bound to IP addresses from restricted resources list?\\ **Answer:** Asymmetric connection is supported but it is not advised. The reasons are:\\ - most of options become unavailable (for example, analytics requires both inbound and outbound streams for protocol analysis and so on);\\ - sending the traffic according to PKH scheme (i.e. only IPs from a list) creates an additional trouble. Our SW does not support the router' | ||
- | -Is the license going to be free in future?\\ Does the free license cover the full functionality or the filtering only?\\ **Answer:** The free license covers filtering only. It is issued for 12 months and can be prolonged. We plan to prolong free of charge now, as we do not consider filtering as a business. We plan to make money on additional options. The income sharing is considered as well.\\ Free evaluation period of 3 months is available for other options.\\ So you are welcome to inform us if you wish to try some options. You provide us the access and we install licenses remotely. These licenses are limited by their term for evaluation. | ||
- | -What is the license price for dna& | ||
- | -Can one use two ports of four-ports card 02:00.0 Ethernet controller: Intel Corporation I350 Gigabit Network Connection (rev 01) for asymmetric filtering? | ||
- | -The source code for libzero and DNA drivers for Intel network interfaces are available for download on ntop.org. Can you briefly describe what functionality is restricted in these drivers compared to commercial ones (http:// | ||
- | -Does your solution allow the following connection scheme: a server has one 10G network interface. The VAS Experts DPI traffic passes through this interface by means of two VLAN representing input and output?\\ **Answer:** No. The future support is not scheduled. | ||
- | -Can your system arrange BGP link to a border in order to export prefixes that require their traffic to be sent to the VAS Experts DPI?\\ **Answer:** No. The future support is not scheduled. | ||
- | -Are the url2dic and ip2bin utilities source codes available? Can we get them for FreeBSD 9 x64?\\ **Answer:** Source codes for utilities are not available and we do not plan to provide them in a future. FreeBSD allows to run native Linux applications: | ||
- | -Is the request https:// | ||
- | -What is the aggregation logic when working by your list and external one?\\ **Answer:** own lists are used as separate ones. They are added to cloud ones (if the service is on). | ||
- | -Can DPI pass the tagged traffic and implement filtering policy on certain VLANs?\\ **Answer:** Yes. The VAS Experts DPI processes tagged traffic - VLAN, QinQ, MPLS.\\ Currently there is no option to indicate the VLAN to block the traffic on. This functionality can be implemented in future versions. | ||
- | -All the tagged traffic passing through DPI is filtered and there is no need to create any VLANs on DPI server itself. Is it right?\\ **Answer:** Yes. | ||
- | -The process fastdpi_1gb по top shows the load about 140% (4 core CPU) even on non connected server. Is it OK? ' | ||
- | -We connected the internal local area network for tests. Ping's time remains the same. Should it be some delay?\\ **Answer:** The equipment delay is no higher than 30 us if the equipments meets our recommendations. Ping measurements start from 1 ms. In order to detect such small delays one needs specific software and hardware. We use nanosecond timers (supported by modern network cards) in our test bench. | ||
- | -Is it possible to increase maximum number of fdpi_ctrl connections ? We have got such errors during sync billing services: ctrl : too many connections=4, | ||
- | -For local_passthrough=1 how DPI will process the traffic of local ASN? Where is the traffic counted? Как будет СКАТ обрабатывать приоритет трафика по протоколам, | ||
- | -In mirror schema in_dev=dna1: | ||
- | -How can I get IP list for BGP /32 route ?\\ **Answer:** to anonnce IP for BGP routes you have make script like:\\ bin2ip / | ||
- | -when is licence expired? < | ||
- | | ||
- | | ||
- | -how to save licences information?< | ||
- | / | ||
- | / | ||
- | / | ||
- | </ | ||
- | |||
- | ~~DISCUSSION|Please help us to improve our documentation. Let us know if you found an error or something is unclear..~~ |