Upcoming software from Foundry Networks could help customers better manage firewalls and Web servers in the event of unexpected or seasonal surges in Web traffic. The software will also stop common denial-of-service attacks at a Foundry load-balancing switch before the attack can affect Web servers or firewalls.
Set to be unveiled at NetWorld+Interop 2001 in Atlanta this week, the latest version of Foundry's ServerIron IronWare switch software can be applied to Foundry's chassis-based ServerIron 400 and 800 boxes, which are aimed at large-scale Web server farms or consolidated enterprise data centers. The ServerIron supports up to 24 Gigabit Ethernet ports and 128G bit/sec of capacity, while the ServerIron 800 maxes out at 56 Gigabit ports and 256G bit/sec of capacity.
A company's Web server administrator could use the Symmetric Server Load Balancing (SSLB) feature in the software to double a the load-balancing capacity in a server farm while making failover between switches more reliable. This is done by having both switches actively balance traffic among multiple servers. ServerIron boxes configured in this "active/active" method can handle a failure in milliseconds instead of seconds. Today, many customers deploy one load-balancing switch and an inactive back-up switch for fail-over protection.
An IronWare feature called Active Square firewall load balancing now lets load balancers share active session information and pass incoming and outgoing traffic through different firewalls. This can double the throughput of firewall packet inspection in a network, the company says.
The IronWare release will also include security features, such as SYN Guard, for cutting off DoS attacks at the switch, instead of a firewall. Also included is a connection rate-limiting feature for capping the number of sessions a firewall or Web server can accept to avoid device overload and failure - such as increased e-commerce traffic at Christmas or spiking traffic to an accounting server during a businesses' end-of-quarter finance closings.
SYN Guard expands on the SYN Defense feature of previous IronWare versions, which let a ServerIron monitor synchronization (SYN) packets from an incoming client request. SYN packets are sent by a networked device to initiate a TCP/IP transaction with another machine. A commonly used DoS tactic is to deluge a Web server with SYN request packets that the server cannot answer.
A ServerIron using SYN Defense can identify SYN packets sent from a client that are not followed up by an acknowledgement packet from the sender - necessary for a TCP/IP handshake to occur. The switch would then tell the server to drop the requests.
SYN Guard goes further by acting as a proxy for a Web server, requiring that the entire TCP/IP handshake occur between the switch and a client before letting the connection be processed by the server. The switch monitors for unfulfilled SYN packets, Foundry says, ensuring that a server is shielded from SYN flood attacks - even distributed denial-of-service attacks, which could have overwhelmed sites using SYN Defense.
Foundry's ServerIron switches compete with products such as Cisco's Content Service Switch product line and Nortel's line of Alteon Web switches, as well as products from CacheFlow, Extreme Networks, Infolibria and Top Layer. The IronWare software for the ServerIron 400 and 800 switches is available now as a free download for IronWare users with an active support contract.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. How to improve employee productivity in small and medium businesses
Email Archiving 101—Customer Case Study
The state of Middleware
Delivering the Power of Choice with Microsoft Dynamics CRM
Solve Exchange Mailbox Storage Issues Once and for All
Taking On Demand CRM Integration to the Next Level
IT Service Management Needs and Adoption Trends: An Analysis of a Global Survey of IT Executives
Strategies for Eliminating .PST Files
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #98: The Future of Datacentre IP 18/12/2008 10:33:00
CW Live speaks withLin Nease, Director of Emerging Business for HP ProCurve, to discuss the future of networks, including the effect of IP-based storage on datacentres, new capacity requirements generated by the use of 10Gb Ethernet, and how an efficient network design can slash energy and cooling costs, and help enterprises build a "green" image. - +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport.
IT industry veteran advises caution on outsourcing selection in light of Satyam problems 2009-01-09 21:45:00+11
F-Secure Warns About a Worm Affecting Corporate Networks 2009-01-08 16:42:00+11
Research software developer appoints Susan Dart to new Business Development Director role 2009-01-08 09:08:00+11
Research software developer appoints Susan Dart to new Business Development Director role 2009-01-08 09:08:00+11
Anyware Introduce Two Powerful PCI TV Tuner Cards with S5 Power Up and Windows Media Center Remote 2009-01-07 17:30:00+11
Discover the advantages of an open architecture multi-vendor network solution
View this webcast and discover the drivers for changing network design practices, why many organisations are changing their approach to network architecture and how enterprises should be moving forward with open architecture multi-vendor network solutions. Register now and learn how your business can maximize the business value of the enterprise network.





