Whitepaper
Radware and Enterasys Networks
Layer 4-7 Switching for Enterprises and Data Centers
Page 1 of 6 • Whitepaper
Introduction The aim of this whitepaper is to outline how the combination of Radware Intelligent Application Switching (IAS) together with the Enterasys Matrix family of switches can provide enterprises and data centers alike with a high-capacity solution that guarantees high availability, QoS for mission-critical applications, protection against malicious attacks and performance optimization of network servers for local as well as global networks. Enterprise Solution The Challenge Day-to-day enterprise operations rely heavily on the availability and reliability of the organization’s communication infrastructure. Downtime of mission-critical applications can have severe financial implications both in terms of employee productivity, as well as loss of revenue due to the inability to access content and applications. This creates the need for a solution that will guarantee continuous operation of these applications, while identifying not only resource failures, but also degradation of services. It must also handle traffic bursts quickly and efficiently, and be completely transparent to the user. The Solution As can be seen in Figure 1, enterprise servers are connected to high-capacity Matrix E1 switches. Radware’s Web Service Director (WSD) aggregates traffic arriving to and from these switches at multi-Gigabit rates. Deployment of WSD provides real-time Layer 4-7 content switching at multi-Gigabit speeds, redirecting traffic to the best available server for optimal performance. An advanced health monitoring mechanism quickly and effectively identifies failures, as well as degradation of services, thereby guaranteeing non-stop reliability and high availability of all services. The solution provides bandwidth management capabilities enabling management of server farm bandwidth allocation by IP address, application and content. These bandwidth management capabilities ensure optimal service levels by guaranteeing mission-critical applications and prioritizing traffic of all enterprise operations. Protecting enterprise networks from malicious attacks and illegal access to their computer systems is obtained with WSD’s security modules: Application Security and DoS Shield. Application Security provides real-time protection from over 1,000 known attack signatures, providing an additional layer of security for your valuable resources. DoS Shield, on the other hand, provides fully configurable and unmatched protection, at multi-Gigabit speed, from harmful Denial of Service (DoS) attacks. Together, these modules provide the fastest and most effective application-level protection available and safeguard the integrity of your applications. The Matrix E1 switches are ideal for workgroup environments that require both high-bandwidth connections and high port density. Supporting 10/100, Gigabit and 10-Gigabit Ethernet, these high-performance switches can handle the requirements of bandwidth-intensive enterprise applications such as videoconferencing, distance learning and enterprise resource planning.
Page 2 of 6 • Whitepaper
WSD
WSD
Matrix E1
Matrix E1
Matrix E1
Web/Application Servers
Mail Servers
Database Servers
Figure 1. Enterprise solution Benefits • High availability for IP-based transactions, guaranteeing continuous operation of mission-critical applications. • A performance optimized solution via wire-speed forwarding and redirection of service requests to the best-performing server. • Low-entry-cost solution enabling transparent scalability with incremental investment as server connectivity needs grow. • Quality of Service through the enforcement of business policies on network traffic according to client, application flow and content. • Real-time protection from over 1,000 malicious attack signatures. • Fully configurable, multi-Gigabit speed protection from Denial of Service (DoS) attacks. • Return on investment after preventing the first five minutes of downtime.
Page 3 of 6 • Whitepaper
Data Centers/Collocation Solution The Challenge Many organizations are now outsourcing various applications and IT functions. As a result, key applications are often hosted by a collocation company, hosting company or Application Service Provider. The following solution provides the availability, performance and transparent scalability required for the uninterrupted delivery of those key applications. The Solution In this configuration, high-capacity, high-port-density and reliability requirements of data centers are met through the use of Matrix N3 switches. The Matrix N3 modular chassis supports high-density 100/1000Base-X and 10-Gigabit Ethernet connectivity modules, enabling incremental investment as server connectivity demand grows. Distributed Forwarding Engine (DFE) modules provide high availability through stateful failover capabilities as well as support of Virtual Router Redundancy Protocol (VRRP). As in the Enterprise solution, deployment of WSD provides real-time Layer 4-7 content switching at multi-Gigabit speeds. An advanced health monitoring mechanism quickly and effectively identifies failures, as well as degradation of services, thereby guaranteeing non-stop reliability and high availability of all services.
WSD
WSD
Matrix N3
Matrix N3
Servers
Servers
Figure 2. Data center / Collocation solution Benefits • High availability for full application fault tolerance. • Performance optimization by redirecting each request to the best-performing server. • Advanced QoS guarantees application responsiveness during peak traffic periods according to client, applications and content. • Real-time protection from over 1,000 malicious attack signatures. • Fully configurable, multi-Gigabit speed protection from Denial of Service (DoS) attacks. • Wire-speed traffic prioritization and rate limiting based on ports, servers, VLANs, and application flows.
Page 4 of 6 • Whitepaper
• Hosting services with full load balancing and high-availability capabilities for 5002,000 customers over the same infrastructure.
Disaster Recovery and Business Continuity for Data Centers The Challenge Organizations recognize the need to establish a reliable backup network service, and this issue has been given more precedence since the September 11th disasters. Positioning the backup service at a distant physical location is necessary to protect it since whatever disaster befalls the primary network must not be able to reach the secondary network. Carriers can provide data centers at dispersed locations to be used as backup networks for the client. However, customers need to be ensured that when a site goes offline, service is maintained. This means that entire infrastructures must be duplicated, information must be constantly mirrored, availability of each site must be monitored, failover and traffic redirection must occur, integrity of each site’s security must be maintained and it must all be transparent to end users. Most importantly, it must be able to be deployed under the most adverse conditions. The challenge, therefore, is to provide the means whereby a backup location can be provided for the customer as effortlessly as possible, while taking into account these restrictions. The Solution As in the previous example, deployment of Matrix N3 switches meet the high-capacity, high-port-density and reliability requirements of each data center. WSD units in each data center frequently exchange information on the available capacity in each site and the proximity (in terms of latency and hops) of each data center to different users subnets. Based on this information, WSD transparently redirects user requests to the best available site for optimal performance. These unique global capabilities allow for the simultaneous usage of both data centers, ensuring that even under the most severe conditions, users will get the best available service. QoS and security services supported both on the Matrix network switch as well as on WSD units provide end-to-end enforcement of bandwidth management policies, security and the highest site-wide performance.
WSD
WSD
WSD
WSD
Matrix N3
Matrix N3
Matrix N3
Matrix N3
Servers
Servers
Servers
Servers
Figure 3. Business continuity for data centers
Page 5 of 6 • Whitepaper
Benefits • Seamless integration of a customer’s backup site, ensuring full availability, disaster recovery and continued service for the customer’s clients. • Local and global high availability for full application fault tolerance and application response times. • Performance optimization by redirecting each request to the best-performing site. • Quality of Service by enforcing the business policy on the networked traffic according to client, applications and content. • Real-time protection from over 1,000 malicious attack signatures. • Fully configurable, multi-Gigabit speed protection from Denial of Service (DoS) attacks.
Matrix is a trademark or registered trademark of Enterasys Networks. All other products or services mentioned are identified by the trademarks or service marks of their respective companies or organizations. NOTE: Enterasys Networks reserves the right to change specifications without notice. Please contact your representative to confirm current specifications. All contents are copyright © 2004 Enterasys Networks, Inc. All rights reserved. Lit. #9013652 5/04
Page 6 of 6 • Whitepaper