Solution Partner:
|
Cavium Networks is a worldwide
leader in security, network services and embedded processor
solutions. Cavium Networks' award-winning NITROX and MIPS64-based
OCTEON families of processors and accelerator boards offer
flexible, scalable and highly integrated solutions delivering
50Mbps to 10Gbps performance. The company's products are integrated
into a wide range of networking equipment that include routers,
gateways, network appliances, content switches, wireless LAN
access/aggregation points, servers and storage networking
devices.
Cavium Networks is headquartered in the heart of Silicon Valley
in Mountain View, CA with development centers in Marlboro,
MA and Hyderabad, India. For enquiries, please email
|
Download
Case Study
|
The Customer and its
Business Challenges
The Customer: A global provider of network
security solutions.
The Business Challenges: The lines between
networking equipment segments and security equipment segments are
blurring fast. The reason is simple: Enterprise IT managers in highly-regulated
verticals like banking and finance, defense and security, with flourishing
branch offices increasingly need to optimize their TCO. Consolidating
security optimization and routing into the same box at the network
gateway as well as for the whole infrastructure is one cost-effective
solution.
Time to market (TTM) is however critical as
integrated networking security hybrids mature. Major network equipment
providers have entered the security space to offer integrated or
route-managed security with other LAN/WAN connectivity functionalities.
To meet this TTM challenge and retain a foothold
in the fast-collapsing networking and security pie, the Customer
had to avoid developing networking features from scratch. They didn't
want their resources and expertise on leading edge security solutions
diluted and dispersed for catching up to more established networking
solutions. At the same time, they were looking for comprehensive
networking features that were future-proof and would be applicable
to multiple hardware range to optimize performance scalability and
costs.
Product Development
Requirements
The Customer decided on a strategic product
roadmap to develop a full range of new generation network security
gateways based on key criteria of:
- Including a comprehensive set of pre-integrated networking
protocols
- Quick and seamless integration with their proprietary
UTM software
- Ported over a range of 3 products, including the latest
high-performing multi-core MIPS64 architecture to separate
forwarding treatments and enhance performance, as well as
an X86 platform
|
The Solution
The Customer chose to use 6WINDGate SDS software suite
and the Cavium Networks' OCTEON CN38XX Multi-core MIPS64 processors.
The solution synergy between the two essentially facilitated fast
product design and development:
- 6WINDGate software integrates with OCTEON SDK and
runs on the OCTEON evaluation boards
- Cavium Networks' provided fast path hardware acceleration
and software correspond to the well-defined APIs of 6WINDGate
|
As a result, the Customer is able to reduce overall development
cycle by gaining on:
- A complete set of field-proven IP features pre-integrated
and validated on a scalable and optimized processor architecture
- The ability to develop several product lines founded
on the same software and processor, due to OCTEON's superior
scalability
- An open software architecture incorporating XML-based
management system for fast software integration and configuration
with the Customer's UTM software
- The capacity to scale up on performance as well as
service evolution by integrating Ethernet and interfaces
for WLAN or xDSL, as well as additional security applications
|

Networking
features delivered with the 6WINDGate SDS for the Customer:
(For full list of supported RFCs, refer to http://www.6wind.com/RFC.html) |
IP Protocols (Kernels)
- IPv4 & IPv6 stacks
- Unicast & Multicast forwarding
- IPv4 to IPv6 tunnelling
- IPv4 & IPv6 IPsec
- IPv4 & IPv6 Stateful Firewall
- IPv4 & IPv6 QoS
- NAT
- VNB framework
|
Connectivity
- PPP, Multi-link PPP, PPPoE,
- CHDLC, VLAN
- GRE, 6in6, 4in4
- L2TP, DHCPv6-v4, DNS proxy
- RADIUS Client
|
IPv4 to IPv6 Transition
- ISATAP, DSTM, 6to4, 6in4,
- NAP-PT
|
|
|
Security
- IKE Key Management, X509 v3,
Pre-shared Keys,
- Dynamic VPN, OCF - HW IPsec,
- EAP/802.1X
|
Routing
- Static (v4-v6)
- RIP, RIPng
- OSPFv2 & v3
- BGP-4, BGP-4+, IS-IS
- ECMP (v4-v6)
- VRRP
- PIMv4-SM, PIMv6-SM
|
Management
- XMS (eXtensible Management System Framework)
- CLI, WEBGate
- XML Conf
- SNMPv3
- telnet, NTP, ssh, ... with IPv4 & IPv6
transport
|
|
|
|