Sie sind auf Seite 1von 6

White Paper

Nortel Networks
Alteon Switched Firewall

A Nortel Networks positioning paper


Executive summary
The Internet has become a vital resource for business of all sizes. E-mail is now a
mission-critical resource; sharing applications and data online with customers, partners,
and suppliers is becoming the standard way of conducting business.
However, opening access to a corporate network — especially to servers in the data center
— generates significant security concerns. A firewall is the most common way to implement
perimeter protection for corporate information assets. While traditional firewalls do
a great job of securing entry to a network or data center, today’s solutions introduce
performance bottlenecks. Until now, an enterprise or service provider had to chose between
implementing the highest levels of security with maintaining the performance required for
data center operations.
To address the challenges of security, performance, and management within data centers,
Nortel Networks has developed a next-generation security architecture called the Nortel
Open Security Architecture (OSA). OSA is a new paradigm for ultra-high-throughput
security with unmatched scalability and flexibility. It combines the performance of wire-
speed switching with the sophistication found in best-of-class security software solutions.
The first product released using this new architecture is the Nortel Networks Alteon
Switched Firewall. The Alteon Switched Firewall, integrating Check Point FireWall-1 Next
Generation, is specifically designed to provide a total solution that allows you to ensure
high levels of security without giving up the data center performance that is truly critical to
business success. The Alteon Switched Firewall optimizes capital investment by providing
what we call “high-performance security” at a significantly lower cost than traditional
solutions that require multiple firewalls. All this comes in a highly flexible solution that
is easy to integrate into existing data centers.

2 Alteon Switched Firewall System White Paper


Introduction The Alteon The second generation of firewalls
Firewalls come in various sizes and Switched Firewall consisted of appliances that were created
capabilities, filling many specific network to solve server-based firewall shortcomings.
Evolution of security These so-called appliances represented a
requirements depending on their point hardware technology
of use. For example, data centers require new architecture — a combination of a
Firewalls have been used for many years
firewalls with tremendous throughput dedicated hardware device paired with a
to protect access to networks. Firewall
capacity, often well in excess of 1,000 more secure operating system. The firewall
architecture has changed over time to
Mbps. Broadband subscribers, on the appliance has one function only, and that
meet new requirements for security
other hand, connect at speeds of one is to function as a perimeter security
and performance. The first generation
Mbps or less. Nortel Networks has the device. Processing power is not shared
of firewalls, some of the earliest forms
right firewall solution to suit these various with any other application. Increasingly,
of protection in the new Internet
customer needs. For high-performance, firewall appliances have become the
environment, involved deploying firewall
high-throughput firewalls used in dominant solution for securing networks
software on a general-purpose operating
enterprise and service provider data centers, and data centers. Despite their popularity,
system running on a workstation
the Alteon Switched Firewall integrating appliances still present a scalability and
or server. The firewall function often
Check Point FireWall-1 is the choice. manageability challenge. As traffic grows,
was one of many applications running on
the firewall appliance becomes a bottleneck
To date, implementing perimeter the device. As traffic volume grew and the
within the data path. The addition of
protection security within a data center sophistication of Internet users improved,
other firewall appliances, load-balanced
has required tradeoffs among high security, problems with this firewall architecture
by a Web switch, allows for scaling and
flexibility, and high performance. The emerged, such as security holes in
management of traffic distribution and
most secure solutions impose a bottleneck general-purpose operating systems and
sessions across multiple firewalls; however,
within the data path. For high-speed data poor performance under moderate traffic
at a certain point this solution becomes
centers, the only solution until today was demands. It was time for an evolution to
untenable from throughput, management
to implement multiple firewalls operating the second generation in firewalls.
and cost perspectives. It is now time for
in parallel, load-balanced by a Web
the next evolution in firewall architecture.
switch. Although this solution scales
to gigabit speeds, it requires spending Figure 1: Contrast between traditional firewall architecture
significant capital and often introduces and the Alteon Switched Firewall.
an added level of complexity to data
Traditional Firewall Appliances Alteon Switched Firewall
center management. Today, the economics Scale Using Switches for Firewall Simplifies Configuration and
Load Balancing Management
of enterprise and service provider IT
Alteon Web Switches for Alteon Switched Firewall
infrastructures require simpler, more firewall load balancing
cost effective solutions that scale to new
performance levels.
Traditional
The solution? The Nortel Open Security Firewall
Appliance
Architecture (OSA). OSA is a new paradigm
for ultra-high-throughput security with
Alteon Web Switches for Alteon Web Switches for
unmatched scalability and flexibility. It server load balancing server load balancing
combines the performance of wire-speed
switching with the sophistication found
in best-of-class security software solutions.
The Alteon Switched Firewall is the first
product designed following the principles
of the Open Security Architecture.

Alteon Switched Firewall System White Paper 3


The third-generation switched firewall Figure 2: Alteon Switched Firewall accelerates session packets.
architecture takes the best of second-gen- Traditional Firewall Solution Alteon Switched Firewall System
eration appliances and adds the scalability, Secure Data Center Secure Data Center

manageability, and performance of


switching – meeting key requirements
of the high performance IT data centers
(see Figure 1). The OSA-based Alteon
Security
Switched Firewall is the first of this new Revolution
90% of all packets Switched
generation of firewall architecture. The are accelerated Firewall System

Alteon Switched Firewall System provides


multi-gigabit firewall performance for
Un-Secure Internet Un-Secure Internet
data centers that require this level of
throughput and state-of-the-art filtering
in order to secure and safeguard servers.
Using the innovative OSA architecture,
the Alteon Switched Firewall System
overcomes the traditional performance • Nortel Networks Alteon appliance boosted by the acceleration of these
degradation that occurs with deep packet platform subsequent packets in a session because
inspection. This switch-accelerated firewall • Nortel Networks Single System Image these packets are processed by the
solution not only increases throughput (SSI) automatic configuration capability wirespeed switching fabric.
performance to multi-gigabit speeds, Based on typical session composition,
• Nortel Networks patent-pending
but also improves the flexibility and users will find that nine of every ten
interface technology, the Nortel
manageability of the firewall function. packets are accelerated — for a throughput
Appliance Acceleration Protocol (NAAP)
Firewall policies are controlled from a improvement of nearly ten times that of
dedicated appliance while high performance • Check Point Software Technologies’
traditional firewall appliances — while
comes from the addition of wirespeed FireWall-1 Next Generation security
still maintaining full security (see Figure 2).
Layer 4-7 switching technology. application and SecureXL performance
architecture Each component of the Alteon Switched
Alteon Switched Firewall has a specialized function.
Traditional firewall appliance architectures
Firewall Architecture integrate the policy control and forwarding
The Alteon Switched Firewall Director,
Following the principles of OSA, running FireWall-1, performs policy
functions of an in-line data processing
the Alteon Switched Firewall is a multi- checking for every new connection
device. Scalability is achieved through
component solution that is managed request, manages the connection table,
the use of multiple firewalls load-balanced
as a single system. It combines the traffic and specifies the rules for handling
by a Web switch. In contrast, the Alteon
management functionality of Web subsequent packets in a session. While
Switched Firewall separates the control
switching with the firewall function a session is active, policy checking for
and forwarding functions. A dedicated
of one or more dedicated appliances, packets is managed by the Alteon
firewall appliance — the Alteon Switched
providing unmatched levels of network Switched Firewall Accelerator at blazing
Firewall Director — runs Check Point’s
manageability and performance. The speeds. As traffic and the number of
Firewall-1 Next Generation application.
cornerstones of this new architecture are: policies grow, additional Alteon Switched
The Alteon Switched Firewall Director
Firewall Directors can be paired with a
• Nortel Networks Alteon Web handles the control functions of policy
single Alteon Switched Firewall Accelerator.
Switching technology management, session acceptance, session
management, etc. However, once the
first packet in a session passes through
the inspection engine, rule checking
and packet forwarding are offloaded to a
high-speed switch, the Alteon Switched
Firewall Accelerator. Throughput is

Alteon Switched Firewall System White Paper 4


The Nortel Appliance Acceleration Multiple Switched Firewall Directors The acceleration capabilities of
Protocol (NAAP) controls and manages can be teamed with one Switched Firewall the Nortel Networks Open Security
the interface between the devices. NAAP Accelerator. NAAP creates a Single Architecture can be extended to other
is a communication protocol that simplifies System Image as the first Alteon Switched security technologies, such as intrusion
management and centrally enforces Firewall Director is configured. detection systems, virus scanning, content
security between the Switched Firewall Adding additional Directors is a simple filtering and virtual private networks.
Accelerator and Switched Firewall plug-and-play operation as the device is Nortel Networks higher-end switching
Directors, providing integrated automatically recognized and the system platform rides the switching performance
communication and acceleration of image created. curve and scales to incredible performance.
the interface function. The Alteon Switched Firewall is the first
Benefits of the Alteon
This breakthrough hardware acceleration product released using this innovative
Switched Firewall
architecture — the sharing of the OSA architecture. The result is a firewall
Nortel Networks’ revolutionary Alteon
connection tables and separation of that delivers in excess of 3 Gbps through-
Switched Firewall system enables service
the control and forwarding planes — put and supports up to 32,000 new
providers to deploy current and future
represents a paradigm shift that is similar connections every second with over
high-margin managed security services
to the movement from routing to Layer 3 500,000 concurrent connections —
over a cost-effective and flexible infra-
switching. Extracting the forwarding performance that is unmatched
structure. With its innovative architecture
function out of the software and processing in the industry.
and plug-and-play provisioning of firewall
it on a specially-purposed ASIC was the
resources, the Alteon Switched Firewall
basis of the LAN routing-to-Layer 3
allows service providers to reduce capital
switching market paradigm shift. Nortel
expenditures due to the Nortel Networks
Networks is accelerating perimeter security
Open Security Architecture’s “pay as your
in a similar fashion with the Open
traffic grows” flexiblity.
Security Architecture and the Alteon
Switched Firewall. Not only does the The Alteon Switched Firewall provides
specialized forwarding function improve the best price/throughput ratio on the
firewall throughput performance, but market, making it the best choice for
additional acceleration comes from performance-hungry networks.
the automatic offload of CPU-intensive Operation costs are minimized because
network address translation (NAT) to administrators no longer must configure
the Alteon Switched Firewall Accelerator. each firewall as added. The first firewall
NAT has always been a CPU drain for can be provisioned in minutes using a
firewalls. By offloading this function GUI-based configuration wizard. The
to the exceptionally powerful processing Single System Image replication and
on the Alteon Switched Firewall management wizard capabilities of the
Accelerator, the firewall appliance (Alteon Alteon Switched Firewall System makes
Switched Firewall Director) is not wasting adding new Alteon Switched Firewall
valuable CPU resources performing Directors a plug-and-play operation.
NAT functions.

5 Alteon Switched Firewall System White Paper


For more information, contact your Nortel Networks representative or call 1-800-4-NORTEL
(1-800-466-7835), or 1-506-674-5470 outside of North America.

www.nortelnetworks.com
United States Europe, Middle East, and Africa
Nortel Networks Nortel Networks EMEA, S.A.
4401 Great America Parkway Les Cyclades-Immeuble Naxos
Santa Clara, CA 95054 25 Allee Pierre Ziller
1-877-655-2ASK Valbonne, 06560 France
Canada 00-800-8008-9009**
Nortel Networks 44(0)-20-8920-4618
8200 Dixie Road, Suite 100 Asia Pacific
Brampton, Ontario Nortel Networks
L6T 5P6 Canada 27/F City Plaza One
1-800-466-7835 1111 King’s Road
Caribbean and Latin America Quarry Bay
Nortel Networks CALA Inc Hong Kong
1500 Concord Terrace 852-2100 2888
Sunrise, FL 33323-2815
954-851-8000 **Number accessible from most European Countries

Copyright © 2001 Nortel Networks. All Rights Reserved.


*Nortel Networks, the Nortel Networks logo, and the Globemark, are trademarks of Nortel Networks. All other trademarks are the property of their
respective owners. Information in this document is subject to change without notice. Nortel Networks assumes no responsibility for any errors or
omissions that may appear in this document.
94013.25/01-02

Das könnte Ihnen auch gefallen