You can now use Intelligent Traffic Offload subscription on CN-Series as a Kubernetes
CNF mode to unlock more performance and protect mobile networks leveraging GTP
Security.
You can now configure software cut-through based offload on the CN-Series firewall.
With the software cut-through based Intelligent Traffic Offload (ITO) service, the
CN-Series firewall eliminates the tradeoff between network performance, security,
and cost. For each new flow on the network, the ITO service determines whether or
not the flow can benefit from security inspection. The ITO service routs the first
few packets of the flow to the firewall for inspection, which determines whether to
inspect or offload the rest of the packets in the flow.
The software cut-through based offload supports the GTP-U tunnel protocol. Within a
GTP-U With GTPU inner session software coordinated Universal Time-through, after the
GTPU inner session completes the Layer 7 inspection, the GTPU packet will follow the
existing software cut-through datapath, bypass the unnecessary operations, take
advantage of a FIB/MAC cache, and run to completion. In CN-Series, only the
CN-Series as a Kubernetes CNF mode of deployment supports software
cut-through based ITO.