Intelligent Traffic Offloading Flashcards

1
Q

What is Intelligent Traffic Offloading (ITO)?

A

a VM-Series firewall Security subscription that, when configured with the NVIDIA BlueField-2 DPU, increases capacity throughput for the VM-Series firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The VM-Series firewall and the BlueField-2 DPU must be installed on which system, platform and kernel?

A
  • system = Ubuntu 18.04
  • kernel version = 4.15.0-20
  • platform = x86 physical host
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the only supported interface mode?

A

virtual wire

should be also L3 since PAN-OS 11.2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How many firewalls and BlueField-2 DPUs can you deploy per host?

A

only 1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How does ITO work?

A
  1. ITO service routes the first few packets of a flow to the firewall for inspection to determine whether the rest of the packets in the flow should be inspected or offloaded. The decision is based on policy or whether the flow can be inspected (for example, encrypted traffic can’t be inspected)
  2. By only inspecting flows that can benefit from security inspection, the overall load on the firewall is greatly reduced and VM-Series firewall performance increases without sacrificing security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the top sessions per second threshold for ITO?

A

7,000; when reached traffic still flows through the VM-Series firewall and is inspected

or the offload session table is ful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the minumum number of vCPUs for ITO?

A

18

How well did you know this?
1
Not at all
2
3
4
5
Perfectly