Pagini

Nexus 9000 - ACI power!


The following tables compare hardware capabilities of the Cisco Nexus 9000 Series switches. For more product details, refer to the product data sheets or consult your Cisco representative. Here!

vineri, 17 mai 2019

NBAR2 Auto-learn

Marvelous technology.

A follow-up post for NBAR technology, a thing that you don't want to miss...

NBAR2 Auto-learn improves classification of traffic not otherwise recognized by NBAR2 protocols.

For generic HTTP or SSL traffic, NBAR2 can identify the hostname from packet header fields.
For unknown traffic, it can track top-occurring server-side ports and sockets.
These mechanisms facilitate creating custom protocols to better classify the otherwise generic or unknown traffic.

Follow the link for more specifications.

Further, read.

Deploying QoS for Application PerformanceOptimization.

marți, 14 mai 2019

Flexible Netflow also uses NBAR as a 'match' for applications

As a continuation of the previous post, with some comments.
This seems like a bargain.
But very useful info when you need to fingerprint your apps traversin your network.
Below is a sample of using Flexible Netflow with NBAR(match application name).

!
flow record rm_1
match application name
match ipv4 source address
match ipv4 destination address
collect interface input
collect interface output
collect counter packets
!
flow monitor mm_1
record rm_1
!
interface gi0/0
ip address 192.168.1.1 255.255.255.0
ip flow monitor mm_1 input
!
end

Application Performance: The Good, the Bad and the Expense

Still relevant, so shuffle through the info to understand how to fingerprint your apps inside your organization. Check this out..

The Good, the Bad and the Expense!

Secure SD-WAN for the Cloud-First Enterprise without Compromise

Going Cloud Security all the way!

Check out the link here!

"Executive summary

 As applications continue to migrate to the cloud, changing traffic patterns drive the need for a new Wide Area Network (WAN) approach and security model. When all applications resided in enterprise data centers, life was simpler for IT; all traffic from the branch was backhauled to the data center over MPLS circuits, with the entire stack of security services enforced at data center egress points, requiring only fundamental security services at the branch. Now, applications reside everywhere and may be hosted in the data center, in public and private clouds, or delivered by myriad Software-as-a-Service (SaaS) providers. To further complicate the security model and the IT challenge, users now access applications from anywhere, from any device and across diverse WAN transports, including the internet. This increases the attack surface, significantly increasing the need for more advanced security services to protect the branch from threats. While enterprises could deploy next-generation firewalls at every branch, that model is untenable. The hardware is too expensive, and managing dedicated security appliances at hundreds or thousands of branch locations requires far too many IT resources. In addition, branch locations need advanced security controls, like sandboxing, intrusion prevention (IPS) and Data Loss Prevention, as well as SSL inspection,  to protect against advanced threats. To address the security and cost challenges, centrally orchestrated cloud-hosted security services, such as those available from Zscaler™, have emerged and are experiencing hyper-growth. The Zscaler Cloud Security Platform combined with the application-aware, business-driven Silver Peak® Unity EdgeConnect™ SD-WAN edge platform provides a powerful solution that secures the enterprise from threats delivers the highest application performance and user experience and keeps costs in check."