S
ERVER
I
RON
LINK BALANCER
Highlights
t Efficient load balancing over multiple Internet links to
increase bandwidth utilization
t Reduce cost for Internet service by increasing link utilization
with redundancy
t Eliminate the need for complex BGP routing in
Enterprise network
t High-availability link load balancing with transparent failover t Static and dynamic metrics to intelligently load balance
for optimal link utilization
t Real-time measurement of in-band service response time
and available capacity
t Increase Internet access capacity by aggregating multiple
low-cost links
t IntelliNAT
™
for securing Enterprise network and delivering consistent application performance
t Transparent Application Support for any IP application
M a x i m i z i n g E n t e r p r i s e I n t e r n e t A c c e s s
ServerIron
™Link Balancer to Optimize
ISP Link Usage and Lower Cost
Internet access is at the heart of every Enterprise business operation. Foundry Networks® ServerIron® Link Balancer
maximizes Internet connectivity and availability while reducing the total cost. The Link Balancer uses intelligent Layer 4-7 switching to efficiently load balance Enterprise Internet traffic between all available ISP links without the complexities and limitations of the BGP routing protocol. Additionally, the Link Balancer optimizes utilization of ISP links by using metrics like link health, service response time, proximity, and cost of bandwidth that are tied directly to business productivity and profitability.
Many Enterprises purchase redundant ISP links for Internet connectivity to support their mission-critical business needs. Today, to simultaneously utilize all the links, Enterprises need to use complex BGP routing protocol and hire resources to manage it. They are faced with two poor choices of keeping the bandwidth on redundant links idle, or investing significantly in BGP expertise and management. With the simple-to-use ServerIron Link Balancer, Enterprises can maximize their return on Internet access costs while significantly boosting the performance of their applications.
Built on Foundry’s proven IronCore™architecture, ServerIron
enables Internet traffic switching based on Layer 2 through Layer 7 definitions, and delivers industry-leading performance for Internet traffic management functions.
Link Balancer Applications
ServerIron Link Balancer supports the following key applications in the Enterprise network:
1. Link Load Balancing –Distribute IP-based services and transparently load balance traffic across multiple ISP links while continuously monitoring link health, response time and utilization in real time. This application enhances overall reliability and availability of Internet access while optimizing utilization on all available links. Enterprise users will experience immediate improvements in productivity with no added cost.
2. Link Aggregation – Get increased bandwidth for Internet access by aggregating multiple low-cost links with intelligent load balancing. Avoid paying steep prices for high-capacity links and minimize the risk of downtime. Increase service reliability and reduce cost by purchasing and aggregating bandwidth from multiple Internet Service Providers (ISPs).
3. Enterprise Network Security – With the superior performance and advanced security features, the ServerIron, when deployed with the Link Balancer, acts the first line of defense to Firewalls and Enterprise applications against DoS attacks. The ServerIron Link Balancer provides IronShield™
protection to critical business applications from unauthorized and malicious users.
ISP1
ISP3
ISP2
ROUTER #1 ROUTER #2 ROUTER #3 SERVERIRONENTERPRISE
NETWORK
INTERNET
Always-On Internet Connectivity
ServerIron Link Balancer ensures uninterrupted Internet connectivity by providing intelligent load balancing with continuous link health monitoring. In the event of a link outage or degradation, the Link Balancer provides detection and rapid fail-over for traffic to the other available ISP links. The Link Balancer detects failures and performance degradations on ISP links before the Enterprise hosts, and takes corrective action by switching over to links best able to serve the traffic.
Two ServerIrons deployed in high-availability configuration provide 24x7 Internet connectivity to Enterprise clients even during catastrophic failures. In the event that one device fails,the standby device transparently takes over without disrupting traffic flows. The ServerIron’s extensive link health check capability monitors end-to-end Layer 2, Layer 3, Layer 4, and Layer 7 connectivity,and determines the links’ability to quickly respond to client requests. Health checks also ensure fast detection of link problems and eliminate lengthy manual troubleshooting during outages.
Maximum Scalability
The Link Balancer combines the feature rich link load balancing with the high-performance ServerIron architecture to meet the Internet connectivity needs of most Enterprise customers. It can support line-rate link balancing for up to six T3 or two OC3 links.
Easy to Set Up and Manage
ServerIron Link Balancer is simple to configure and manage using the Command Line Interface (CLI) or the built-in Web interface. The CLI uses well-known Cisco-like commands allowing network administration staff to easily configure all Foundry products. In addition, ServerIron’s support for Simple Network Management Protocol (SNMP) allows device management using applications such as HP OpenView, available on major server platforms including Sun Solaris, HP-UX, and Windows NT.
Key Features
t Out-Bound Link Balancing– ServerIron provides out-bound
load balancing for any type of IP application traffic,and handles link balancing on up to six T3 or two OC3 links.Traffic belonging to a connection is routed to the same link based on session information to achieve reliable and persistent service. IntelliNAT (Intelligent Network Address Translation) is used to secure internal network while ensuring the return packets are routed back through the same ISP link for consistent connection performance.
t In-Bound Link Balancing– Incoming traffic into an
Enterprise network is load balanced to multiple ISP links. Using passive DNS intercept in combination with intelligent load balancing algorithms, the ServerIron re-directs in-coming traffic over all available links to achieve optimal utilization.
t Link Balancing Methods– To meet the diverse demands of
Foundry’s Enterprise customers, the ServerIron Link Balancer supports a comprehensive set of user-configurable static and dynamic link metrics for intelligent load balancing. By fine-tuning the metrics, network administrators can optimize performance and cost of Internet service to meet the needs of specific deployment.
t Pro-Active Measurement of Link Performance –
The ServerIron Link Balancer uses a pro-active approach to measuring link performance for effective load balancing of traffic. In-band measurement of end-to-end service response time during connection setup is combined with pro-active out-of- band measures to pick the links that deliver the best overall performance.
t High Availability– Foundry’s ServerIron devices are
designed to support mission-critical business applications. To provide a high-level of redundancy and fault tolerance to the Link Balancer, two ServerIron devices can be deployed in high-availability configuration with session synchronization and transparent failover for total Internet access reliability.
t Real-Time Synchronization– Session information and link
performance measures are synchronized in real-time between the two ServerIron devices configured for high availability to maintain consistently high load balancing performance in the event of failover to the standby device. Stateful connection failover and instantaneous availability of link performance information allows Enterprise users to be fully transparent to network failures.
t Robust Security– With Enterprise network and application
infrastructure at the core of the business, the loss of productivity and profits from external Denial of Service (DoS) attacks is devastating.The ServerIron Link Balancer provides industry’s best defense against DoS attacks. Using IntelliNAT on outgoing traffic, the ServerIron provides an additional layer of protection by keeping internal IP addresses private and inaccessible to external hosts.
t Backup Links– The ServerIron Link Balancer supports
backup links that are used for load balancing traffic only when all other ISP links fail.Transition to the backup links is automatic, instantaneous and fully transparent to network hosts.This feature allows the use of highly reliable low-capacity links for uninterrupted connectivity during catastrophic failures.
Link Health Checks
t Link Connectivity– The Link Balancer continuously
monitors connectivity to the routers, ISP nodes and nodes in the Internet to determine the availability of links in real-time. Loss of connectivity is detected instantaneously, and all the sessions are transparently switched to other available links. By monitoring link connectivity beyond the next hop, the Link Balancer ensures that mission-critical traffic is reliably serviced end-to-end.
t Link Utilization– When utilization on links reaches a
specific threshold, the Link Balancer re-directs new traffic flows to other less utilized links.The threshold for marking the links as fully utilized and removing them from the available pool is user-configurable. Link utilization is continuously monitored to add the links back to the available pool once utilization drops below the threshold.
t Proximity and Link Response Time– Using sophisticated
monitoring of in-band traffic flows, and out-of-band hop count and response time, the Link Balancer has an accurate view of end-to-end service response time on all the ISP links.These measures are used to avoid utilizing links that are likely to adversely impact application performance.
Load Balancing Methods
t Round Robin– Assigns traffic flows sequentially among the
multiple available ISP links. Round robin treats all links as equal regardless of the capacity, cost and preferences.This method is suitable for networks with multiple ISP links with equal capacity and similar traffic flows.
t Weighted Round Robin– Assigns traffic flows sequentially to
the ISP links based on link weight. Links with greater weight are assigned proportionately more connections.This method is
appropriate for Enterprises purchasing access to ISP links with dissimilar capacity and performance capabilities. It ensures adequate distribution on multiple links and avoids link overload.
t Link Cost– Allows managers to assign cost of bandwidth ($
per kilobit/sec) to each link.The Link Balancer uses weighted cost to load balance traffic and ensures that the cheaper links are preferred. Using this method, the Enterprises can minimize the cost of their Internet access without compromising
application performance.Various link cost models are supported including pre-paid, variable, and tiered.
t Service Response Time– The Link Balancer is designed to
meet the needs of diverse users and applications in an Enterprise. Using response time and hop count measures, the Link Balancer directs traffic over links that provide best performance for specific applications and users. Pro-active out-of-band service response time measures are used on unutilized or under-utilized links to maintain real-time network performance information.
t Link Usage Limits– In this method, the Link Balancer
limits link utilization to user-defined logical limits that may differ from physical capacity.When link utilization reaches the logical limit, traffic is directed to other under-utilized links. This method helps lower ISP cost for Enterprises using variable or tiered pricing for ISP access with higher marginal cost for exceeding pre-set bandwidth limits.
t Proximity– The Link Balancer uses out-of-band messages to
measure round trip time, hop count, and completion rate to determine proximity of hosts in the Internet serving specific Enterprise applications and users.These measures are then used to efficiently load balance traffic between links able to provide best performance.
IronShield
™Security
t IntelliNAT– ServerIron’s IntelliNAT feature allows
Enterprise customers to use non-routable private addresses on internal hosts to enhance security and conserve address space. The Link Balancer performs IntelliNAT on outgoing traffic and shields the Enterprise network and applications from external attacks. Incoming packets without matching reverse traffic flow information are disallowed from reaching inside the Enterprise network. IntelliNAT also ensures that return traffic is routed over the same ISP link as the original traffic, therefore maintaining application transaction persistence and delivering consistently superior performance.
t DoS Protection– ServerIron Link Balancer protects Enterprise
network and applications against multiple forms of Denial of Service (DoS) attacks,such as TCP SYN attacks,by monitoring and tracking session flows. Only valid connection requests are allowed into the internal network.This capability combined with the ServerIronXL’s ability to support over 1 million concurrent connections protects against the hijacking of internal network resources by unauthorized and malicious users, and ensures high-performance connectivity for genuine traffic.
t High Performance Access Control Lists (ACLs) and Extended ACLs– By using ACLs, network administrators can restrict access to specific applications from a given address or subnet. Filters can be easily set to deny access to servers by any particular port or VIP address. For example, a network administrator can deny FTP traffic to a particular address. Conversely, filters can be set to allow access by a subset of users or subnets.
t Cisco-syntax ACLs– ServerIron supports Cisco-syntax
ACLs, which network administrators can easily cut/copy/ paste from their existing Cisco products to drop them right into the ServerIron configuration for the ultimate in portability and security.
High Availability Services
t Backup Links– The ServerIron Link Balancer allows
reserving links for backup.These links are brought into the pool of available links for load balancing only if all the original links fail.These backup links may be highly reliable but low-capacity links that may be used for uninterrupted connectivity during catastrophic failures.
t Active/Standby– To provide an added layer of fault tolerance
and reliability, two ServerIron switches may be deployed in Active-Standby high-availability mode.When deployed in this mode, a failure of the Active device or its physical links will result in a quick and transparent failover of traffic flows to the Standby device. Configuration common to the two ServerIrons is synchronized to avoid manual replication and potential human errors. Additionally, the active ServerIron synchronizes real-time link performance and proximity measures to allow failover without the added measurement delay.
t Quality of Service– Network administrators can prioritize
traffic based on ports, MAC,VLAN, and 802.1p attributes, as well as by service port and application type; for example, ServerIron can grant priority to HTTP traffic over FTP.
t Redundant Power Supplies– ServerIronXL supports an
optional built-in redundant power supply to provide high level of protection against power failures.
Easy Link Management
t Mix and Match Links– ServerIron increases Internet access
flexibility and investment protection for existing ISP links by allowing uninterrupted traffic distribution to different links based on user-defined performance metrics with dynamic measures.
t SNMP Reporting– ServerIron reports SNMP traps and
events to the specified trap receiver and can send those management messages to up to six different Syslog servers.
Load Balancing
Methods
- Round Robin
- Weighted Round Robin - Link Cost
- Link Bandwidth - Bandwidth Usage Limits - Service Response Time - Host Proximity
Layer 2 Switching
Capabilities
- 32,000 MAC addresses - 802.1d Spanning Tree Protocol - 802.1p prioritization
- Policy-based VLANs - Port-based VLANs - Layer 3 protocol VLANs
- Layer 3 protocol and subnet VLANs - 802.1q VLAN tagging
Protocol Support
- TCP - UDP - SSL - FTP - Telnet - SMTP - HTTP - SOAP - IMAP4 - LDAP - NNTP - POP3 - DNS - BootP - TFTP - SNMP - IPSec - RADIUS - VoIPStandards Compliance
- 802.3, 10BaseT- 802.3u 100BaseTX, 100BaseFX - 802.3z 1000BaseSX
- 802.3z 1000BaseLX - 802.3x Flow Control - 802.1q VLAN Tagging - 802.1d Bridging
- 802.3 Ethernet Like MIB - Repeater MIB
- Ethernet Interface MIB - SNMP V1
- SNMP MIB II
Network Management
- Integrated Command Line Interface - SSH - Web-based GUI - Telnet - SNMP - RMON
- IronView Network Manager (INM) - HP OpenView
Warranty
-1 year hardware - 90 days software
- Upgrades to higher levels available
Mounting Options
- 19" Universal EIA (telco) Rack - Tabletop
Technical and Physical Specifications
Platform ServerIronXL
Concurrent sessions 1,000,000 Switching capacity 4.4 Gbps Number of Virtual IP addresses Unlimited
Number of ISP links Up to six T3 links or two OC3 links Number of 10/100 ports 16 or 24
Number of Gigabit ports Up to 2 Total number of ports 26 maximum
Layer 3 switching capabilities Supports links on different subnets
Physical dimensions 2.75" h x 17.5" w x 16.75" d (6.7 cm x 44.5 cm x 42.2 cm)
Weight 18–22 lbs (8–10 kg)
Ordering Information
Part Number Description
ServerIronXL Base Platform
FCSLB16 16-port 10/100Base-TX (RJ45) ServerIron XL with one expansion slot FCSLB24 24-port 10/100Base-TX (RJ45) ServerIron XL with one expansion slot
FCSLB16-I (International Orders Only) 16-port 10/100Base-TX (RJ45) ServerIron XL with one expansion slot FCSLB24-I (International Orders Only) 24-port 10/100Base-TX (RJ45) ServerIron XL with one expansion slot FCSLB16DC 16-port 10/100Base-TX (RJ45) ServerIron XL with one expansion slot and –48VDC power supply FCSLB24AC 24-port 10/100Base-TX (RJ45) ServerIron XL with one expansion slot and –48VDC power supply
ServerIronXL System Options
U1GC 1-port 1000Base-T (RJ45) copper Gigabit uplink U2GC 2-port 1000Base-T (RJ45) copper Gigabit uplink
RPS Redundant auto-switching 90-240v AC power supply for ServerIron XL 16/24 port only
RPS-I (International Orders Only) Redundant auto-switching 90-240v AC power supply for ServerIron XL 16/24 port only
RPSDC-FC -48VDC power supply for ServerIron XL 16/24 only and is a factory configuration only F2100F 2-port 100Base-FX MMF (SC) uplink
F1GE 1-port 1000Base-SX (SC) Gigabit uplink for 50 or 62.5 um MMF F2GE 2-port 1000Base-SX (SC) Gigabit uplink for 50 or 62.5 um MMF FLX1GE 1-port 1000Base-LX (SC) Gigabit uplink for 9 or 10 um SMF FLX2GE 2-port 1000Base-LX (SC) Gigabit uplink for 9 or 10 um SMF
FLXSXGE 2-port Gigabit uplink with 1-port 1000Base-SX (SC) and 1-port 1000Base-LX (SC) for 50 or 62.5 um MMF and 9 or 10 um SMF
FLHA1G 1-port 1000Base-LogHaul (SC) series A Gigabit uplink for 70 km maximum reach with 9 or 10 um SMF and minimum 10 db attenuation
FLHA2G 2-port 1000Base-LogHaul (SC) series A Gigabit uplink for 70 km maximum reach with 9 or 10 um SMF and minimum 10dB attenuation
FLHB1G 1-port 1000Base-LongHaul (SC) series B Gigabit uplink for 150 km maximum reach with 9 or 10 um SMF and minimum 10dB attenuation
FLHB2G 2-port 1000Base-LongHaul (SC) series B Gigabit uplink for 150 km maximum reach with 9 or 10 um SMF and minimum 10 dB attenuation
ServerIronXL GBIC Options
LHA 1-port 1000Base-LongHaul (SC) series A Gigabit uplink for 70 km maximum reach with 9 or 10 um SMF and minimum 10dB attenuation – specify SX or LHx upgrade quantities
LHB 1-port 1000Base-LongHaul (SC) series B Gigabit uplink for 150 km maximum reach with 9 or 10 um SMF and minimum 10dB attenuation – specify SX or LHx upgrade quantities
DS-017/Rev.1/10-03
Foundry Networks, Inc. Corporate Headquarters 2100 Gold Street P.O. Box 649100
San Jose, CA 95164-9100
U.S. and Canada Toll-free: (888) TURBOLAN (887-2652) Direct: (408) 586-1700
Fax: (408) 586-1900 [email protected]
http://www.foundrynetworks.com
© 2003 Foundry Networks, BigIron, NetIron, FastIron, ServerIron, IronWare, Jetscope, IronView and the “Iron” marks or trademarks are registered trademarks of Foundry Networks, Inc. in the United States of America and other countries
Although Foundry has attempted to provide accurate information in these materials, Foundry assumes no legal responsibility for the accuracy or completeness of the information. Please note that Foundry’s product information does not constitute or contain any guarantee, warranty or legally binding representation, unless expressly identified as such in a duly signed writing.