Feature Overview
Network Insight (aNI) enables collection of traffic between VMs and between SKE resources (services) to discover their access relationships, and auto sync of newly-created VMs and SKE resources. From a business perspective, it provides a clear topology view to give a visual representation of such access and access details. Micro-segmentation policies are also automatically recommended based on the access relationships between VMs. With all these capabilities, aNI helps users clearly see business access relationships and greatly simplifies policy configuration, minimizing access permissions and reducing business risk exposure.
Working Principles
Deploy aNI VMs to collect network traffic on SCP for analysis of access relationships between VMs and containers. Based on the analysis results, visualized topologies and access policy recommendations are generated. aNI VMs can connect to HCI or SCP, enabling unified network visualization management across different platforms.
Applicable Scenarios
• Network topology visualization: Administrators need a clear and intuitive view of the network topology of business systems in the cloud environment, such as access relationships between web servers and databases. aNI provides a quick way to view the overall access topology and identify network dependencies between business systems.
• Micro-segmentation policy optimization: Enterprises often need to implement fine-grained network isolation, for example, allowing only the financial system to access specific database ports. Based on historical traffic, aNI can recommend micro-segmentation policies, reducing manual configuration effort.
• Access risk monitoring: O&M personnel need to monitor abnormal access behaviors in the cloud environment, such as access to critical services from unknown IP addresses or legitimate access blocked by firewalls. aNI enables realtime monitoring of access risks and supports timely responses.
Related Concepts
• aNI VM: A VM for access relationship analysis. It is a critical component for collecting and analyzing network access relationships. You need to select the appropriate VM specification (small, medium, or large) based on the scale of the cloud environment.
• Micro-segmentation policy: A fine-grained network access control policy generated based on business access relationships. Only necessary business traffic is allowed to reduce risk exposure.
• Internal IP address: An IP address within the network of an enterprise or organization, distinct from public IP addresses. Users can define internal IP ranges for access relationship analysis.
• Mistakenly-denied access alert: An alert triggered when legitimate business traffic is blocked due to distributed firewall policies, helping administrators promptly adjust the policies.