Interaction With Other Features - OmniSwitch os6900 Network Configuration Manual

Table of Contents

Advertisement

Interaction With Other Features

Interaction With Other Features
This section contains important information about how Application Fingerprinting (AFP) functionality
interacts with other OmniSwitch features. Refer to the specific chapter for each feature to get more
detailed information about how to configure and use the feature.
General
IPv4 and IPv6 packets are sampled on AFP ports. The entire packet is scanned, not just the payload.
Fragmented, encrypted, control or protocol packets (for example, ICMP, LLDP, BPDU) are not
supported.
AFP is applied after other OmniSwitch features, such as Universal Network Profile (UNP), Edge
Virtual Bridging (EVB), Learned Port Security (LPS), QoS, DHCP, and other protocols.
QoS
AFP shares QoS system resources with other OmniSwitch applications. As a result, AFP functionality
is subject to available QoS system resources, especially when the QoS and/or UNP modes are running
on AFP ports.
A QoS policy list is used by the AFP QoS and UNP modes to specify the name of an application group
of signatures to apply to AFP port traffic.
>
When using the QoS mode, the policy list must be configured as an AFP list (appfp) when the list is
created. With UNP mode the policy list is not configured as an AFP list, since it associated with a
UNP.
>
The QoS appfp-group policy condition is used to specify the name of the AFP application group to
apply. If this condition is not used in a policy list rule, then no QoS is applied to the AFP port traffic.
sFLOW
AFP uses the OmniSwitch SFLOW mechanism to sample the IPv4 and IPv6 packets.
The packet sampling rate is approximately 50K packets per second per NI module. This rate may
change based on the level of use of switch resources by other applications.
The sFLOW mechanism runs two seconds for each port (one port at a time), so if there are two AFP
ports in an NI, each port is serviced for half of its testing duration, whether or not the port receives any
number of packets.
Do not run AFP and other SFLOW services on the same port.
page 28-10
OmniSwitch AOS Release 7 Network Configuration Guide
Configuring Application Fingerprinting
June 2013

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents