官术网_书友最值得收藏!

The management and data plane

There are two main planes that make up a firewall, the data plane and the management plane, which are physical or logical boards that perform specific functions. All platforms have a management plane. Larger platforms like the PA-5200 come with 2 to 3 data planes and the largest platforms have replaceable hardware blades (line cards) that have up to 3 data plane equivalents per line card and can hold up to 10 line cards. The smaller platforms like the PA-220 only have the one hardware board that virtually splits up responsibilities among its CPU cores.

The management plane is where all administrative tasks happen. It serves the web interfaces used by the system to allow configuration, provide URL filtering block pages, and serve the client VPN portal. It performs cloud lookups for URL filtering and DNS security, and downloads and installs content updates onto the data plane. It also performs the logic part of routing and communicates with dynamic routing peers and neighbors. Authentication, User-ID, logging, and many other supporting functions that are not directly related to processing packets.

The data plane is responsible for processing flows and performs all the security features associated with the next-generation firewall. It scans sessions for patterns and heuristics. It maintains IPSec VPN connections and has hardware offloading to provide wire-speed throughputs. Due to its architecture and the use of interconnected specialty chips, all types of scanning can happen in parallel as each chip processes packets simultaneously and reports its findings.

A switch fabric enables communication between planes so the data plane can send lookup requests to the management plane, and the management plane can send configuration updates and content updates.

Another important feature is the ability to identify users and apply different security policies based on identity or group membership.

主站蜘蛛池模板: 永定县| 应城市| 汨罗市| 耿马| 卢龙县| 郁南县| 西平县| 临澧县| 青川县| 尉犁县| 青铜峡市| 平塘县| 福州市| 长子县| 化州市| 积石山| 奉新县| 聂拉木县| 和龙市| 玉门市| 石门县| 喀喇沁旗| 会理县| 河西区| 肇庆市| 宝兴县| 阿拉善盟| 班玛县| 沈阳市| 贞丰县| 五台县| 全州县| 乐业县| 威远县| 阿图什市| 和平区| 阿鲁科尔沁旗| 上思县| 察哈| 额济纳旗| 龙井市|