What’s New
This page provides a brief description and links to additional information about new features in the recent Orchestrator release.
管弦乐队9.2.0
在编队9.2.0中引入了以下功能:
链接聚合Control Protocol (LACP)
LACP提供了控制链接聚合的谈判机制。链接聚合将来自多个接口的数据结合到提供单个高速链接的通道组中。配置链接聚合还为组中的接口增加了故障转移冗余。看链接聚合.
多播组过滤
现在,用户可以允许列表的多播组,因此EdgeOS仅处理与定义列表匹配的组。看Multicast.
Secure Logging
管弦乐队now allows you to configure the port number and protocol of remote log receivers and upload client certificates for remote log receivers.
OSPF and BGP Route Map Enhancements
现在,OSPF和BGP路线地图的几种增强功能可以为OSPF路由提供社区过滤,作为BGP邻居配置的覆盖,LE/GE前缀匹配。
双向转发检测(BFD)
BFD is a networking protocol that detects faults between devices. In addition to supporting single- and multi-hop configurations and asynchronous mode, BFD can be configured for up to 20 segments with a maximum of 100 simultaneous sessions across all segments. The EdgeConnect appliance supports BFD for both BGP and OSPF. SeeBFD选项卡.
AVC Attributes
There are now additional static attributes under the Address Map parameter that can be used as match criteria. These attributes are secondary parameters to the address map, and are evaluated for a policy match only when the configured address map parameter matches with the flow. This release includes support for MS Instance, MS Category, and Proxy attributes.
Firewall Protection Profiles
Users can now add firewall protection profiles in the Configuration menu. Protection profiles allow users to define firewall thresholds around specific threats and security objectives of an environment where the firewall will be used, map the profile to a segment or zone of the firewall, and quickly add/edit the profile as a template. SeeFirewall Protection Profiles.
IPSec Suite B
现在,IPSEC隧道建立和数据交换有一组更强大的安全算法。
笔记:在编队9.2.0中,此功能不完全支持。将来的版本将提供全部支持。
入侵预防系统(IPS)
除了现有的入侵检测系统(IDS)外,它指定了使用匹配规则进行检查的流量,IPS还通过匹配签名然后执行配置的操作(警报,阻止或允许)来保护流量。看入侵检测/预防系统(IDS/IPS).
Radius Snooping
EdgeConnect现在根据RADIUS身份验证期间收集的用户和设备信息提供身份和上下文感知的微分割。用户可以根据基于用户的匹配标准编写策略,用于交通转向,选择防火墙区和其他策略。
一键在GCP上部署
在创建了带有管弦乐器所需权限的Google Cloud Platform帐户之后,用户现在可以在GCP中快速部署一个或多个新的EdgeConnect Virtual(EC-V)设备,通过提供一些基本的配置和部署详细信息。看Cloud Hubs in GCP.
Configuration Limits for EC Appliances
Various configuration limits were defined for EC-model appliances.
警报通知表优化
This release includes scalability enhancements to alarm notification handling to support a larger number of appliances.
性能增强
This release adds a number of performance enhancements to significantly reduce orchestration times for most use cases.