Nortel Alteon Switched Firewalls 6000 Series |
 |
Switched Firewall 6000 Series
The Nortel Switched Firewall 6000 series performs accelerated deep-packet inspection -- resulting in up to 90% of all packets being safely forwarded with inspection by the switched accelerator rather than the core firewall logic. This kind of performance is critical in any application or services deployment that has periods of heavy demand
Key Features:
- Intelligent security with high performance -
- Throughput of 7 Gbps
- Session connections per second of 20,000 to 100,000
- Concurrent sessions of 2,000,000
- Plug-and-play deployment and expansion with a single-system-image that is easy to manage and maintain.
- Multi-layer packet inspection for extra protection from advanced hackers and attackers.
- Switch-based acceleration that off-loads CPU processing and minimizes impact on next-generation multimedia, SIP, and VoIP services.
- Device load-balancing for advanced support of IDS security devices such as Nortel Threat Protection System.
- Active-active configurations for high availability environments where 99.999% application and service availability is a must.
Features & Benefits
Features
Threat Protection
Nortel's Threat Protection System uses intrusion detection and real-time threat intelligence to analyze and detect network threats. An intelligent, automatic update to Nortel Switched Firewall blocks threats before they harm the network.
Layer 2 through Layer 7 Content Filtering
The accelerated switched firewall blocks attacks and unauthorized traffic before there is any chance for performance degradation or network outage. Up to 224 filtering rules can be configured to allow or deny traffic based on application type, protocol type and IP source/destination addresses.
Accelerated Performance
The accelerated switched firewall performs deep-packet inspection with up to 90% of all packets being safely forwarded with hardware-based inspection as prescribed by the core firewall logic. Throughput is 5.0 Gbps for the 6416 and 7.0 Gbps for the 6616. This enables the system to use the core firewall resources to inspect and connect a much higher number of concurrent sessions and to deal with a higher number of connection requests per second -- critical in any web-services deployment.
VLAN Tagging
Support for up to 242 unique firewall policies and enforcement for IEEE 802.1q VLANs. Ideal for multi-tenant and multi-department deployments.
Network Address Translation
The accelerated switched firewall performs Network Address Translation (NAT) to preserve and hide organizational IP addresses. With this accelerated-NAT function performed in the switch hardware, the core firewall system devotes its resources to session connections and complex security concerns.
Layer 2 Layer 3 Mode Deployment
The Switched Firewall 6000 series supports flexible deployment in both Layer 2 and Layer 3 mode. Customers easily deploy the 6000 series into existing topologies in Layer 2 mode. No address or routing changes are required. Network segments can then be migrated port-by-port to Layer 3 mode if desired.
Benefits
Low Total Cost of Ownership
- Cost-effective solution that can grow to meet future demand.
- Up to six Directors can be supported by a single Switched Firewall Accelerator
- A Single System Image controls all configuration data, including physical interfaces, VLANs, IP interfaces, routing protocols, and administrative settings.
- Existing Check Point customers may re-use their existing license to easily move their firewall onto any Nortel Switched Firewall.
Enhanced Performance Supporting Productivity
The Nortel Switched Firewall is optimized to support VoIP and SIP services. High packet throughput to minimize delay, VoIP and SIP application awareness, and virtually jitter-free performance are fundamental to its design and function.
Carrier-class Availability for Assured Customer Connection
High Availability in the Switched Firewall System enables automatic fail-over to other Switched Firewall Directors in the security cluster. This eliminates single points of failure in the network. In-service hitless upgrades ensure ongoing performance and availability.
Nortel Alteon Whitepapers
|