Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
en:dpi:faq:start [2024/05/29 08:15] – elena.krasnobryzh | en:dpi:faq:start [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== FAQ ====== | ||
- | {{indexmenu_n> | ||
- | |||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | -[[en: | ||
- | |||
- | |||
- | -Can one use the own list rather than the one loaded from clouds?\\ Can one make DPI to use our list of restricted resources only?\\ **Answer:** Yes. The cloud service is implemented for your convenience, | ||
- | -Do you pass STP transparently? | ||
- | -Does the filtering by Federal Supervision Agency for Information Technologies and Communications and Department of Justice lists work in case VAS Experts DPI processes the outbound traffic only?\\ Can your system operate passing not the whole traffic but only that one bound to IP addresses from restricted resources list?\\ **Answer:** Asymmetric connection is supported but it is not advised. The reasons are:\\ - most of options become unavailable (for example, analytics requires both inbound and outbound streams for protocol analysis and so on);\\ - sending the traffic according to PKH scheme (i.e. only IPs from a list) creates an additional trouble. Our SW does not support the router' | ||
- | -What is the license price for dna& | ||
- | -Can one use two ports of four-ports card 02:00.0 Ethernet controller: Intel Corporation I350 Gigabit Network Connection (rev 01) for asymmetric filtering? | ||
- | -The source code for libzero and DNA drivers for Intel network interfaces are available for download on ntop.org. Can you briefly describe what functionality is restricted in these drivers compared to commercial ones (http:// | ||
- | -Does your solution allow the following connection scheme: a server has one 10G network interface. The VAS Experts DPI traffic passes through this interface by means of two VLAN representing input and output?\\ **Answer:** No. The future support is not scheduled. | ||
- | -Can your system arrange BGP link to a border in order to export prefixes that require their traffic to be sent to the VAS Experts DPI?\\ **Answer:** No. The future support is not scheduled. | ||
- | -Are the url2dic and ip2bin utilities source codes available? Can we get them for FreeBSD 9 x64?\\ **Answer:** Source codes for utilities are not available and we do not plan to provide them in a future. FreeBSD allows to run native Linux applications: | ||
- | -Is the request https:// | ||
- | -What is the aggregation logic when working by your list and external one?\\ **Answer:** own lists are used as separate ones. They are added to cloud ones (if the service is on). | ||
- | -Can DPI pass the tagged traffic and implement filtering policy on certain VLANs?\\ **Answer:** Yes. The VAS Experts DPI processes tagged traffic - VLAN, QinQ, MPLS.\\ Currently there is no option to indicate the VLAN to block the traffic on. This functionality can be implemented in future versions. | ||
- | -All the tagged traffic passing through DPI is filtered and there is no need to create any VLANs on DPI server itself. Is it right?\\ **Answer:** Yes. | ||
- | -The process fastdpi_1gb по top shows the load about 140% (4 core CPU) even on non connected server. Is it OK? ' | ||
- | -We connected the internal local area network for tests. Ping's time remains the same. Should it be some delay?\\ **Answer:** The equipment delay is no higher than 30 us if the equipments meets our recommendations. Ping measurements start from 1 ms. In order to detect such small delays one needs specific software and hardware. We use nanosecond timers (supported by modern network cards) in our test bench. | ||
- | -Is it possible to increase maximum number of fdpi_ctrl connections ? We have got such errors during sync billing services: ctrl : too many connections=4, | ||
- | -For local_passthrough=1 how DPI will process the traffic of local ASN? Where is the traffic counted? How will SSG handle traffic priority by protocols, will it take into account the traffic going to these ASNs in the general flow or not ?\\ Traffic will pass through SCAT, but it will not be processed at all, netflow data will be discounted? | ||
- | -In mirror schema in_dev=dna1: | ||
- | -How can I get IP list for BGP /32 route ?\\ **Answer:** to anonnce IP for BGP routes you have make script like:\\ bin2ip / | ||
- | -When is licence expired? < | ||
- | | ||
- | | ||
- | -How to save licences information?< | ||
- | / | ||
- | / | ||
- | / | ||
- | </ | ||