Hardware Acceleration for High-density Datacenter Monitoring



Similar documents
High-Density Network Flow Monitoring

Hardware acceleration enhancing network security

Low Cost 100GbE Data Center Interconnect

HANIC 100G: Hardware accelerator for 100 Gbps network traffic monitoring

SCAMPI Programmable hardware for network monitoring. Masaryk University

Extreme Load Test of Hardware-accelerated Adapter against DDoS Attacks

Why 25GE is the Best Choice for Data Centers

High-Density Network Flow Monitoring

Mellanox Academy Online Training (E-learning)

The Future of Computing Cisco Unified Computing System. Markus Kunstmann Channels Systems Engineer

Emerging storage and HPC technologies to accelerate big data analytics Jerome Gaysse JG Consulting

PCI Express Impact on Storage Architectures and Future Data Centers. Ron Emerick, Oracle Corporation

Monitoring of Tunneled IPv6 Traffic Using Packet Decapsulation and IPFIX

Infrastructure for active and passive measurements at 10Gbps and beyond

COUNTERSNIPE

Bricata Next Generation Intrusion Prevention System A New, Evolved Breed of Threat Mitigation

HUBER+SUHNER AG Phil Ward

Software Defined Monitoring of Application Protocols

Next Generation Operating Systems

High speed pattern streaming system based on AXIe s PCIe connectivity and synchronization mechanism

Wireshark in a Multi-Core Environment Using Hardware Acceleration Presenter: Pete Sanders, Napatech Inc. Sharkfest 2009 Stanford University

Next Steps Toward 10 Gigabit Ethernet Top-of-Rack Networking

100 GBE AND BEYOND. Greg Hankins NANOG52. Diagram courtesy of the CFP MSA. NANOG /06/14

Latest Trends in Data Center Optics

Network Computing. Solution Brief. Simplifing Converged Networks. Secure Wireless Connectivity. Preventing DDoS Attacks with Firewalls

10 Gbit Hardware Packet Filtering Using Commodity Network Adapters. Luca Deri Joseph Gasparakis

FlowMon. Complete solution for network monitoring and security. INVEA-TECH

Optics Technology Trends in Data Centers

enabling Ultra-High Bandwidth Scalable SSDs with HLnand

The Future of Cloud Networking. Idris T. Vasi

Bus Interconnect Evolution in embedded computing

Accelerating High-Speed Networking with Intel I/O Acceleration Technology

UCS M-Series Modular Servers

Seeking Opportunities for Hardware Acceleration in Big Data Analytics

CloudEngine Series Data Center Switches. Cloud Fabric Data Center Network Solution

PCI Express IO Virtualization Overview

The Ethernet Roadmap Applications, servers, optics, and switches

Data Center Architecture Overview

Bivio 7000 Series Network Appliance Platforms

QLogic 16Gb Gen 5 Fibre Channel in IBM System x Deployments

What s New in Mike Bailey LabVIEW Technical Evangelist. uk.ni.com

Cloud-Based Apps Drive the Need for Frequency-Flexible Clock Generators in Converged Data Center Networks

Designing a Card for 100 Gb/s Network Monitoring

Oracle Virtual Networking Overview and Frequently Asked Questions March 26, 2013

Boosting Data Transfer with TCP Offload Engine Technology

Architecture of distributed network processors: specifics of application in information security systems

How To Switch A Layer 1 Matrix Switch On A Network On A Cloud (Network) On A Microsoft Network (Network On A Server) On An Openflow (Network-1) On The Network (Netscout) On Your Network (

Direct Attach Cable with Micro Coaxial Wire for Data Center

PCIe Over Cable Provides Greater Performance for Less Cost for High Performance Computing (HPC) Clusters. from One Stop Systems (OSS)

F5 Intelligent DNS Scale. Philippe Bogaerts Senior Field Systems Engineer mailto: Mob.:

Intel Ethernet Switch Load Balancing System Design Using Advanced Features in Intel Ethernet Switch Family

Accelerating I/O- Intensive Applications in IT Infrastructure with Innodisk FlexiArray Flash Appliance. Alex Ho, Product Manager Innodisk Corporation

Pluggable Optics for the Data Center

100 GIGABIT ETHERNET TECHNOLOGY OVERVIEW & OUTLOOK. Joerg Ammon <jammon@brocade.com> Netnod spring meeting 2012

Optimizing Infrastructure Support For Storage Area Networks

How To Create A Network Monitoring System (Flowmon) In Avea-Tech (For Free)

From Ethernet Ubiquity to Ethernet Convergence: The Emergence of the Converged Network Interface Controller

Data Center and Cloud Computing Market Landscape and Challenges

Observer Analysis Advantages

Scaling from Datacenter to Client

TÓPICOS AVANÇADOS EM REDES ADVANCED TOPICS IN NETWORKS

Solving I/O Bottlenecks to Enable Superior Cloud Efficiency

Distributed Monitoring Pervasive Visibility & Monitoring, Selective Drill-Down

Resource Efficient Computing for Warehouse-scale Datacenters

Uncompromising Integrity. Making 100Gb/s deployments as easy as 10Gb/s

Connecting the Clouds

Evaluation Report: Emulex OCe GbE and OCe GbE Adapter Comparison with Intel X710 10GbE and XL710 40GbE Adapters

Performance Beyond PCI Express: Moving Storage to The Memory Bus A Technical Whitepaper

Networking Virtualization Using FPGAs

Truffle Broadband Bonding Network Appliance

How To Understand Cloud Computing

Networking Goes Open-Source. Michael Zimmerman VP Marketing, Tilera

FC SAN Vision, Trends and Futures. LB-systems

Findings in High-Speed OrthoMosaic

Convergence-A new keyword for IT infrastructure transformation

Going Linux on Massive Multicore

Realizing the next step in storage/converged architectures

Intel Xeon Processor E5-2600

DOMINO Broadband Bonding Network

Solid State Storage in Massive Data Environments Erik Eyberg

PCI Express Impact on Storage Architectures and Future Data Centers. Ron Emerick, Oracle Corporation

Computer Organization & Architecture Lecture #19

Scalable Network Monitoring with SDN-Based Ethernet Fabrics

Lab Testing Summary Report

Reliable high throughput data connections with low-cost & diverse transport technologies

White Paper. S2C Inc Technology Drive, Suite 620 San Jose, CA 95110, USA Tel: Fax:

Router Architectures

Post-production Video Editing Solution Guide with Microsoft SMB 3 File Serving AssuredSAN 4000

Accelerating Real Time Big Data Applications. PRESENTATION TITLE GOES HERE Bob Hansen

Transcription:

Hardware Acceleration for High-density Datacenter Monitoring Datacenter IaaS Workshop 2014 Denis Matoušek matousek@invea.com

Company Introduction Czech university spin-off company Tight cooperation with CESNET, a Czech NREN operator Established in 2007 40+ employees Key focus Hardware acceleration and FPGA Solutions Flow Monitoring and Network Behavior Analysis Lawful Interception and Data Retention

Motivation I High-speed links in data centers 40G Ethernet 100G Ethernet: Bleeding-edge technology Very high load: new packet every 6.72ns Transition from 10GE challenge (10 10G high-density mode) Many variants (IEEE standards, CFP MSA specifications, SFF specifications) Even newer technologies are emerging 25G/50G Ethernet: 25G Ethernet Consortium Dedicated and flexible hardware needed!

Motivation II Network attacks Which types of attacks are effective to be mitigated on high-speed links? (D)DoS attacks: filtering out the traffic based on previous traffic analysis Black listing: dropping traffic from known malicious sources It is necessary to process the traffic at wire-speed!

Campus network monitoring and security workshop INVEA-TECH 2014 Platforms I Commodity hardware Cheap and flexible Limited I/O performance Dedicated hardware High I/O performance Expensive, limited flexibility Commodity hardware + Hardware acceleration Multi-core CPUs + FPGA network interface card High I/O performance Reasonable price Flexible

Price Platforms II Commodity hardware Commodity hardware + Hardware acceleration Max. price Dedicated hardware Flexibility I/O performance Min. performance

INVEA-TECH Solutions Hardware-acceleration in FPGA chip Flexibility and high performance One hardware for multiple applications (traffic recording, IDS/IPS, SDM ) HW/SW codesign HANIC-80G HANIC-100G

Network Technologies High-speed HANIC-80G HANIC-100G High-speed 40G Ethernet 100G Ethernet High-density 10G Ethernet 25G / 50G Ethernet No change in hardware is needed!

Deployment of 100GE Evolution of optical modules: CFP CFP2 CFP4 / QSFP28 Smaller & cheaper Allowing even multiple 100G interfaces on one adapter HANIC-100G is the world s first 100G FPGA adapter available 100GBASE-xR4, -SR10 PCI Express Gen 3 x16

High Density The nature of 40G and 100G Ethernet technologies allows to use one link as multiple independent 10G links SM (single mode) vs. PSM (parallel SM) FPGA provides flexibility that allows to support many Ethernet standards 40G + 10G + even 1G! Optical break out cable 40G 4 10G

network links Use Case: 8 10G with One Card 10G 10G 10G 10G 10G 10G 10G 10G optical module + break out cable traffic preprocessing in hardware HANIC-80G PCI Express bus DMA channels control host server optical module + break out cable physical links/paths traffic/data control paths

network links Use Case: 2 40G with One Card 40G optical module traffic preprocessing in hardware PCI Express bus host server 40G HANIC-80G DMA channels control optical module Exactly the same hardware!!! physical links/paths traffic/data control paths

Flexibility FPGA chip is able to be programmed even after deployment: HANIC-80G example: 2 40G vs. 8 10G Ethernet only by loading different firmware! HANIC-100G example: it provides architecture to support new technologies (CFP4/QSFP28 optical modules, 25G/50G Ethernet) Firmwares can be simply upgraded with new features and bug fixes

Network Traffic Processing High-speed network interfaces traffic preprocessing in FPGA chip high-speed transfer to host computer packet processing on multicore CPUs All advantages of processing on commodity servers are preserved! PCI Express Gen 3 Network interface(s) FPGA Host server HANIC-100G: PCIe bifurcation

Usability High-performance requires special processing on both HW and SW side Device drivers provide transparent user interface Standard application interface (PCAP) Optimized for throughput Special techniques for 100GE (PCIe bifurcation)

Standard tools Easy integration with standard tools: Tcpdump traffic recording Wireshark traffic analysis Snort IDS/IPS FlowMon traffic analysis

Summary Benefits of INVEA-TECH FPGA solutions: Flexibility and scalability of FPGA technology High performance: wire-speed traffic processing HW/SW codesign: performance vs. time-to-market Broad support of network technologies: 1G, 10G, 40G & 100G Ethernet Future: 25G, 50G Ethernet High density multiple 10G links on one adapter multiple adapters in one rack-mountable server We enable you to use your standard tools with the only difference they run faster!

Reference

High-Speed Networks Technology Partner Denis Matoušek matousek@invea.com +420 511 205 264 INVEA-TECH a.s. U Vodárny 2965/2 616 00 Brno, Czech Republic www.invea.com