SPAN-aggregation and packet brokers. Packets deduplication

4404
SPAN-aggregation and packet brokers. Packets deduplication

One may ask: is it real to be so stupid implementing TAPs and brokers that packets are duplicated? Yes, of course, and it doesn't indicate architects' stupidity. E.g. we need the datacenter traffic analysis. So, it is necessary to mirror datacenter uplinks (no matter Internet or corporate) to have an incoming/outgoing traffic visibility, and aggregation/service layer links according to the datacenter network design. Inbound/outbound packet has no duplicates if it is going to some segment connected via dedicated physical lines, no router/firewall on a stick etc.

name='more'>
Let's assume some network part on the picture 1. TAPs mirror traffic to aggregators and then it is sent to information security systems. Users' connections path to servers is going through at least 2 TAPs copying traffic to the aggregator. As a result security sensors receive much more traffic for analysis.
  
Alt text
Обращаем внимание, что все материалы в этом блоге представляют личное мнение их авторов. Редакция SecurityLab.ru не несет ответственности за точность, полноту и достоверность опубликованных данных. Вся информация предоставлена «как есть» и может не соответствовать официальной позиции компании.
SIEM
27Авг
Security Vision // бесплатный вебинар
SIEM собирает события. Но помогает ли она видеть реальные угрозы?
27 августа Security Vision на бесплатном вебинаре покажет, как выделять критичные активы, контролировать качество данных, выявлять аномалии и реагировать на инциденты в едином окне.
Регистрируйтесь
18+. Реклама. Рекламодатель ООО «Интеллектуальная безопасность», ИНН 7719435412

Андрей Дугин

Практическая информационная безопасность и защита информации | Information Security and Cyber Defense in Deed

Рекламодатель
«Позитив Текнолоджиз»
ИНН: 7718668887
ptsecurity.com↗
Реклама «Позитив Текнолоджиз»