DPI not functioning
I am having issues with DPI not detecting anything. What OSI model does your DPI sniff at? I am now using an Ubuntu controller not in standalone mode anymore.
Here is the network diagram:
The last message I got from TP Link support was they recommended two things:
1. It is recommended to check off all Facebook-related.
2. There is only one VLAN interface on the gateway, but the clients should not be on this subnet. So the DPI data cannot be detected. That's why it's not in effect.
Even though I set up TWO DPI filter, one for Facebook and another for TikTok. TikTok only has one, but even when I put all the facebook application into the filter it does nothing.
Point 2, I am not even sure what that even means.
So my question is, is DPI sniffing at layer 2? The only thing I can think of is that, I am not using the ER8411 as a RoaS. I am routing between the ER8411 and my L3 switch (DX010). So any VLAN information is going to be dropped at the interface..
Anyone want to chime in?
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
yep your support team have given me that guide like 5x.
and I just tried to do restrict Google and moved the ER8411 back to VLAN1 still nothing
- Copy Link
- Report Inappropriate Content
just tested DPI QoS Class modifier too.
I put all my steaming services, youtube, hulu...etc in to Class 2.
Went to Insight->QoS Data and kept hitting the refresh and Class 2 sat on 0 all the time while playing something on Youtube.
- Copy Link
- Report Inappropriate Content
@MR.S Question for you:
When you build your restriction.
This part:
Do you have multiple choice? Because you have all your VLAN interfaces on the router?
or
you have only one choice?
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
This might be the case why nothing is working for me
The DPI TP Link might be only inspecting at layer 2 & 3 in the OSI model
Since my network is a multilayer and not router on a stick model the DPI and IPS/IDS will not work
They need to make their inspection software to work on a higher layer
- Copy Link
- Report Inappropriate Content
Have you tried connecting a PC directly to the ER8411 to test it? then it should work, just for testing
- Copy Link
- Report Inappropriate Content
Hi @mbze430
Please change your original post and edit #11.
If you post the email conversation again and violate email confidentiality, you will get a perm ban and a deletion of all the posts and replies.
If you have objections, please read the email confidentiality. If you don't agree, we may stop providing email service.
And, add one disclaimer, it is not censoring your freedom of speech. You can paraphrase the conversation you had with the chat/email. But you cannot paste the original contents. I bet you understand this basic email rule and courtesy.
- Copy Link
- Report Inappropriate Content
Hi @MR.S
MR.S wrote
Have you tried connecting a PC directly to the ER8411 to test it? then it should work, just for testing
DPI works but not for him. Basically, it does not work for him or his environment.
He's using routing and when you use the routing instead of placing them in the VLAN INT, it, DPI, won't work.
So, that's the reason. He's right in his first post which I did not read carefully. L3, that's how far it goes.
He's looking for something like L4 and L5 DPI. I am not sure if that's possible for other vendors.
- Copy Link
- Report Inappropriate Content
I just heard back from their support and their "senior" engineer have confirm that IDS/IPS and DPI will not work in a multilayer topology. And yes there are lots of other vendors out there that does it. Netscout, Cisco, Solarwind, Fortinet etc...
Also, TP Link needs to be more transparent about IDS/IPS and DPI only works in a RoaS topology. IF they don't plan to make their security work in a wider range of network topology.
- Copy Link
- Report Inappropriate Content
Hi @mbze430
mbze430 wrote
I just heard back from their support and their "senior" engineer have confirm that IDS/IPS and DPI will not work in a multilayer topology. And yes there are lots of other vendors out there that does it. Netscout, Cisco, Solarwind, Fortinet etc...
Also, TP Link needs to be more transparent about IDS/IPS and DPI only works in a RoaS topology. IF they don't plan to make their security work in a wider range of network topology.
If the email contents are not deleted or edited, I will delete this thread. This is a reminder.
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 1940
Replies: 23
Voters 0
No one has voted for it yet.