Admin and Operator users can use the traffic loopback feature to analyze loopback traffic and find bottlenecks in the Network Security appliance.
Loopback traffic consists of packets that are sent in through an interface and sent out through the peer interface of the appliance's port. The loopback functionality allows the flow of traffic to skip specific levels or checks in the appliance. By skipping a level in the appliance, you can localize the cause for packets dropping in the appliance.
For example, if the traffic flow is bottle-necked and you think that the front-end level of the appliance is the cause, configure a loopback to skip it. If the bottleneck is still not cleared, you can analyze the flow by skipping the inline engine or bott engine check in the appliance to locate the bottleneck.
Three loopback functions are available. You can enable one at a time.
Interface Loopback
The Network Security appliance sends the traffic to the peer interface and bypasses both the front-end and inline engine levels. You can enable interface loopback on one or more interfaces.
Frontend Loopback
The Network Security appliance sends the incoming traffic to the peer interface by skipping the inline engine level. This applies to all traffic coming into the appliance.
Inline Engine Loopback
The Network Security appliance sends the traffic to the peer interface by skipping the SigMatch check in the BOTT engine (part of the inline engine). All the other checks configured in the inline engine are performed and this flow includes all the traffic coming into the appliance.
Tip
See the tips about these loopback functions by hovering over the
ibuttons.
Interface loopback bypasses the front-end and inline engine levels.
Front-end loopback bypasses the inline engine level.
Inline engine loopback bypasses the SigMatch check in the BOTT engine.
Refer to the steps below to enable and disable the traffic loopback functionality.
Traffic Loopback | Steps |
|---|---|
Interface Loopback | |
Front-End Loopback | |
Inline Engine Loopback |