Data sources
- Authentication / Session
- NAT / DNS / URL
- Network and security equipment
- Export mirror flow
• Product positioning
The data, such as authentication, session, DNS, NAT, URL and network traffic, enter the collection and processing chain for use in search, statistics, alarms and traceability after structured storage.
Value of products
Focusing access, session, authentication and traffic leads on retention, query, analysis and alarm
• Product interface and deployment
The platform receives mirror traffic, session logs and certified logs, forming multi-dimensional views of users, accounts, source addresses, target addresses, domain names, application protocols, operators and place of belonging.



View traffic, speed and timing by user, account, agreement, target, region, operator, interface and group.
Combining DPI, encryption traffic features, application of fingerprints and threat intelligence to identify VPNs, proxy and offshore communication leads.
Retains records such as URL, DNS, NAT sessions, authentication and virtual identity to support queries by five-digit and account number association.
The alerts are issued and sent on time, simultaneously and with communication features and can be forwarded to the enterprise ' s micro-mail, nails, mailboxes or third party platforms.
:: Functional characteristics
The key capabilities of the product in connection, management, strategy, operation and transport are used to help you quickly understand its value and orientation.
Collects accreditation, session, NAT, DNS, URL, equipment and application logs.
Queries and export results according to time, user, IP, destination, protocol etc.
Flow and connectivity trends are viewed from user, application, target, geographic and operator dimensions.
Supports the location of events by linking user authentication, IP, sessions to access logs.
Identification of cross-border applications, agency agreements, offshore IPs and unusual communication modes when deployment conditions are met.
Configures the time delay, simultaneous or event rules and exports alarms via a control table or an interface.
04 Deployment path
The underlying conditions are checked before access and validation is progressively achieved to reduce the operational risks associated with one-time switching.
Identify compliance targets, data sources, fields, retention cycles and query scenarios.
Planning equipment logs, authentication data and mirror traffic collection location and bandwidth.
Design single machines or distributed storage by data volume and establish query and alarm rules.
Authentication of identification, retrieval, export, alarm and disposal processes using typical events.
05. Applied scene
Web projects with logs, access back-to-back, NATSHEL_CROSS_BORDER_TRAFFIC or unusual outreach management needs.
Centralize user access and network access leads to support network operations and security analysis.
Collect equipment, security and access logs to support queries, reports and audits.
Distributive storage, flow analysis and event traceability for larger log volumes.
VPN, proxy and unusual outreach leads are identified when export flows are visible.
Description of deployment
The log retention range, fields, storage cycle and performance are accounted for by data source, flow and hardware configuration. Cross-border testing is primarily capable of identifying, recording, analysing and alerting, and does not amount to a full interception or compliance conclusion; identifiable objects and accuracy depend on encryption, deployment location, feature library, model version and field validation.
Product information
Download product presentations, white papers and operations manuals to gain a better understanding of system architecture, functionality configuration and usage.
Cases
A representative case is first looked at, and more project titles are used to understand the accumulation of services in the relevant scenes.
Product Updates
Practices around online conduct audits, NAT traceability and other assurance compliance practices.
Next
Tell us about the use of scenes, user size and current network patterns, first to determine how products match the existing network, then to discuss models, interfaces and scope.