Intelligent Traffic Offloading Flashcards
What is Intelligent Traffic Offloading (ITO)?
a VM-Series firewall Security subscription that, when configured with the NVIDIA BlueField-2 DPU, increases capacity throughput for the VM-Series firewall
The VM-Series firewall and the BlueField-2 DPU must be installed on which system, platform and kernel?
- system = Ubuntu 18.04
- kernel version = 4.15.0-20
- platform = x86 physical host
What is the only supported interface mode?
virtual wire
should be also L3 since PAN-OS 11.2
How many firewalls and BlueField-2 DPUs can you deploy per host?
only 1
How does ITO work?
- ITO service routes the first few packets of a flow to the firewall for inspection to determine whether the rest of the packets in the flow should be inspected or offloaded. The decision is based on policy or whether the flow can be inspected (for example, encrypted traffic can’t be inspected)
- By only inspecting flows that can benefit from security inspection, the overall load on the firewall is greatly reduced and VM-Series firewall performance increases without sacrificing security
What is the top sessions per second threshold for ITO?
7,000; when reached traffic still flows through the VM-Series firewall and is inspected
or the offload session table is ful
What is the minumum number of vCPUs for ITO?
18