Solution Brief Intel Xeon Processors Lanner Intel Network Builders: Lanner and Intel Building the Best Network Security Platforms Internet usage continues to rapidly expand and evolve, and with it network infrastructure is changing and evolving. The use of general-purpose processors to provide network functionality has changed the face of the networking market and dramatically reduced costs for enterprises and telecom service providers. For the most part, these general-purpose servers have kept pace with Internet application usage. Network traffic, however, has increased dramatically with new applications that have extensive data plane requirements. Traffic has multiplied to a point where specialized technology is needed to keep up. High-volume networking functions such as firewalls, unified threat management (UTM) servers, anti-virus, and load balancers are essential in the protection and performance optimization of the Internet. These networking and security devices have specific highcapacity requirements, including encryption/decryption and compression, which are not easily satisfied by commodity processors. Lanner Electronics provides system integrators, service providers, and application developers with a range of computer systems and acceleration cards designed to satisfy networking and security needs. Their high-performing FW-8896 uses the latest in Intel processors, memory, interfaces, and software optimization techniques. Challenge The traffic from high bandwidth connections received by cloud and other data centers must be monitored for security threats, and modified for bandwidth optimization in real time at up gigabit line rates. Security devices include firewalls, UTMs, intrusion detection/protection systems (IDS/IPS), and virtual private network endpoints (VPN). Bandwidth optimization devices include WAN optimizers, load balancers, and application delivery platforms.
To date, this has functionality has resided in high-performance, single function hardware appliances. The market is moving to hosting multiple applications on a single, virtualized server. In order to accomplish that hardware shift with these high performance applications, network equipment providers need the most modern, highest performance platforms in order to keep pace with Internet growth and to compete effectively. These platforms require optimized networking paths and specialized accelerators for encryption/decryption, compression, deep packet inspection (DPI), and other security and optimization processes. The use of industry standard processors helps reduce the cost of hardware design, development, manufacture, and support. To succeed in this market, vendors have to spend a significant percent of their engineering budget on hardware development, which slows their innovation on software secret sauce that makes their systems competitive. It also block innovative start-up companies from entering the market unless they can raise significant amounts of capital for these developments. Further, deployed networking systems must be highly reliable, since all traffic flows through them in most cases. They must have five nines or better reliability, be field maintainable, and remotely managed. Significant effort and experience is needed to accomplish these goals. Solution For almost three decades, Lanner has supplied high-tech companies worldwide with high-performance computing and networking platforms. Major network equipment manufacturers (NEM), system integrators, application developers, and service providers use Lanner technology to solve the most difficult networking and security problems. Lanner customizes a range of platforms for each customer s needs down to the shape and color of the chassis. Customers can choose and customize platforms with multiple levels of performance to meet the needs of their SMB, enterprise, carrier, and cloud customers. To provide a hardware foundation for next-generation Internet security applications, Lanner teamed with Intel to develop the FW-8896. This flexible network security platform offers the latest Intel CPU, memory, storage, acceleration modules, and network interfaces. Up to 64 network interfaces can be included, with 10 Gbps and 40 Gbps copper and fiber connections. Acceleration modules from Intel and other suppliers deal with specialized processing associated with networking and security. Network processing units (NPUs), for example, are included that developers can use to rapidly perform such functions as DPI, IDS/IPS, and cryptography, offloading the main CPU for other functions. IPsec/ SSL, the key protocols used in VPNs and secure web access, use multiple cryptographic techniques and are supported by accelerators from Intel. Intel s advanced hardware and software technology and robust roadmap are critical to Lanner. The FW-8896 utilizes Intel Xeon E5-2600 v3 processors with 16 cores. A number of Intel technologies contribute to the FW-8896 s performance: Intel Data Plane Development Kit (Intel DPDK) The Intel DPDK software library is used to route network packets around the Linux OS kernel and virtual switch (vswitch). Coupled with network drivers and an optimized run-time environment, tenfold network performance can be achieved compared to a classical virtual environment. Intel QuickAssist offers easy integration for built-in accelerators. It employs a hardware-assisted security engine for implementing major security processes. This hardware-assisted security engine works to reserve processor cycles for application processing, and that in turn not only relieves CPU burden but also improves overall system performance. Intel Virtualization Technologies reduces virtualization overhead and improves data throughput. Intel Cache Monitoring technologies to monitor last level cache (LLC) offer better utilization of cache space. 2
Benefits Software developers or equipment companies who offer products built around the Lanner FW-8896 platform achieve significant benefits over those who design, develop, manufacture, and maintain their own systems: Figure 1 - Lanner FW-8896 Chassis Intel Ethernet Controller XL710 supports 10Gbps and 40Gbps Ethernet interfaces. Intel Communications Chipset 8900 Series accelerates cryptography and data compression. Key Features Latest Intel technology Lanner, as a member of the Intel Network Builders ecosystem and associate member of the Intel Intelligent Systems Alliance, has access to Intel s roadmap, early product information and advance samples. This allows them to offer the latest Intel technology as soon as it goes mainstream. Flexible selection of accelerators through the use of Intel QuickAssist technology, Lanner can offer a selection of accelerators that further speed up processing associated with security and bandwidth optimization. High reliability and maintainability Lanner platforms offer redundant power supplies, hot-swappable fans, and watchdog and power-off LAN bypass to deliver a highly reliable and maintainable platform. Reduced/targeted engineering engineering talent can now be dedicated to development of software that distinguishes a provider s product from their competitors. Large teams of engineers are no longer necessary for the continuous development of computing platforms. Better, more reliable products security OEM equipment providers benefit from Lanner s large client base, which allows Lanner to amortize advanced system designs across multiple customers. New platforms perform better out of the box, and are more maintainable. Customizable range of platforms multiple, compatible platforms of different sizes are available. Optimized for network performance Lanner platforms are specifically optimized for high network performance, allowing them to handle up to 64 network interfaces operating at up to 40Gbps each. 3 Figure 2 - Sample Network Processing Units (NPU)
More competitive products Lanner offers the most powerful computing and acceleration platforms. In addition, providers may offer a range of products that match the price/ performance needs of their customers. Flexibility the multiple accelerators available from Lanner allow providers to offer further options for their product s configuration. Conclusion Security and optimization are key requirements in the rapidly expanding Internet. The very high volume of network traffic mandates the use of specialized computing platforms to handle firewalling, IDS/IPS, anti-virus, and other security functions. Bandwidth optimization likewise requires computing systems that are able to compress/decompress data at high rates. Lanner has built the FW-8896 using Intel s latest technologies to meet these needs. The FW-8896 handles extreme bandwidth requirements with a combination of accelerators, interfaces, and Intel innovations. NEMs, system integrators, application developers, and service providers base their products and solutions on Lanner platforms with confidence that they are building the best solution possible. 4
For more information about solutions from Lanner visit, lannerinc.com. Solution Provided By: For more information about Intel solutions for communications infrastructure, visit www.intel.com/go/commsinfrastructure. INFORMATION IN THIS DOCUMENT IS PROVIDED IN CONNECTION WITH INTEL PRODUCTS. NO LICENSE, EXPRESS OR IMPLIED, BY ESTOPPEL OR OTHERWISE, TO ANY INTELLECTUAL PROPERTY RIGHTS IS GRANTED BY THIS DOCUMENT. EXCEPT AS PROVIDED IN INTEL S TERMS AND CONDITIONS OF SALE FOR SUCH PRODUCTS, INTEL ASSUMES NO LIABILITY WHATSOEVER, AND INTEL DISCLAIMS ANY EXPRESS OR IMPLIED WAR- RANTY, RELATING TO SALE AND/OR USE OF INTEL PRODUCTS INCLUDING LIABILITY OR WARRANTIES RELATING TO FITNESS FOR A PARTICULAR PURPOSE, MERCHANTABILITY, OR INFRINGEMENT OF ANY PATENT, COPYRIGHT OR OTHER INTELLECTUAL PROPERTY RIGHT. UNLESS OTHERWISE AGREED IN WRITING BY INTEL, THE INTEL PRODUCTS ARE NOT DESIGNED NOR INTENDED FOR ANY APPLICATION IN WHICH THE FAILURE OF THE INTEL PRODUCT COULD CREATE A SITUATION WHERE PERSONAL INJURY OR DEATH MAY OCCUR. Intel may make changes to specifications and product descriptions at any time, without notice. Designers must not rely on the absence or characteristics of any features or instructions marked reserved or undefined. Intel reserves these for future definition and shall have no responsibility whatsoever for conflicts or incompatibilities arising from future changes to them. The information here is subject to change without notice. Do not finalize a design with this information. The products described in this document may contain design defects or errors known as errata which may cause the product to deviate from published specifications. Current characterized errata are available on request. Contact your local Intel sales office or your distributor to obtain the latest specifications and before placing your product order. Copies of documents which have an order number and are referenced in this document, or other Intel literature, may be obtained by calling 1-800-548-4725, or by visiting Intel s Web site at www.intel.com. Copyright 2014 Intel Corporation. All rights reserved. Intel, the Intel logo, and Xeon are trademarks of Intel Corporation in the U.S. and other countries. * Other names and brands may be claimed as the property of others. Printed in USA XXXX/XXX/XXX/XX/XX Please Recycle XXXXXX-001US 5