H3C SecPath Security Products FAQ(V7)-6W101

HomeSupportQuick StartsFAQH3C SecPath Security Products FAQ(V7)-6W101
11-DPI FAQ
Title Size Download
11-DPI FAQ 15.28 KB

DPI FAQ

Q.     How do I understand DPI will try its best to detect packets after the memory threshold is reached?

A.     Memory resources will be requested when DPI processes packets. However, the time memory resources are requested is not determined and depends on the order of a packet in the flow and the packet payload. Memory resources are not requested for each packet. New memory resources will be requested for each flow (DPI is flow based). After the memory threshold is reached, the software will not request new memory resources from the system. However, DPI has a small memory pool that can supports the processing of a small number of flows. Old sessions will be deleted to make room for new sessions. After the memory threshold is reached, most new traffic will not be detected by DPI due to memory request failure. DPI will try its best to use existing resources to detect packets.

Q.     I can sends viruses through email and bypass detection of DPI. Why?

A.     DPI supports only limited encoding methods (Base64, QP, and URL encoding). For compressed packets, DPI supports only the gzip compression. DPI cannot decrypt packets, so it cannot identify encrypted packets. Emails use 7-bit encoding and cannot be detected by DPI.

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Intelligent Storage
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
  • Technical Blogs
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网