Enterprise network managers are looking to virtualize more data center resources, but they hesitate when it comes to security. They want the resource sharing and hardware consolidation that virtualization offers but aren’t willing to risk compromising security.
So, to meet security demands they set up racks and racks of appliances and network gear (such as load balancers) to handle firewall, antivirus, antispam, IDS, IPS, content filtering and other security tasks. As network traffic grows and strains the performance of the systems, IT meets the rising demand by adding more appliances, load balancers, switches and cabling, as well as redundant hardware to ensure the necessary reliability.
The resulting appliance sprawl results in a chaotic architecture that is increasingly difficult and expensive to manage and maintain, and a security nightmare waiting to happen.
The critical requirements for enterprise security are superior application performance, ultra-low latency, massive scalability, ultra-high reliability, and low total cost of ownership. While best-of-breed appliance platforms have become the solution of choice, they fail to deliver massive scalability. Sprawling networks of hardware, cables and traffic-control gear provide an enterprise-sized security solution, but at the cost of complexity.
They also fail to meet performance requirements in the form of low latency and high reliability, and total cost of ownership goes through the roof. Unified threat management devices “unify” security applications by bringing together acquired technologies into a single solution, but users must sacrifice best-of-breed choice in exchange for ease of management, a risk that large enterprises are unwilling to accept.
So, what is the alternative to appliance sprawl and low-end unified boxes? An ideal solution would deliver key operational, technical and economic benefits, including:
* Consolidation of appliance computing resources and the network gear required to connect them.
* Real virtualization capabilities that dramatically improve resource utilization.
* True “linear scalability,” enabling efficient growth for existing applications as well as the ability to add new ones.
* Support for multiple, best-in-class third-party applications for all major security areas, including firewall, intrusion detection and prevention and content gateways.
* Simplification of the architecture supporting multiple security services.
* Material long-term capital and operational savings.
To address these desired benefits, security technologies are now being integrated into platforms that enable the consolidation and virtualization of racks of appliances and multiple third-party applications, such as firewall, IDS/IPS, antivirus/antispam, content checking and URL filtering. This approach makes it possible to streamline security processes; consolidate switches, load balancers and security appliances; and virtualize the delivery of multiple best-of-breed security applications.
An integrated security platform can be highly scalable, combining specialized application processing and IP network blades with a high-throughput backplane and a hardened operating system. These components create a sophisticated yet simplified solution that consolidates the appliances, switches, load balancers, taps and port mirrors in traditional networks while virtualizing the delivery of security applications. Consolidation reduces capital expenditures and delivers operational savings.
The hardware
One of the primary functions of an integrated security platform is highly scalable network processing at 10-gigabit plus speeds. Thus, such platforms must allow for the scaling of IP forwarding capability by supporting additional network blades as needed. Moreover, these blades must also serve as switching and load-balancing centers that route and evenly distribute network flows to application processors.
Security application processing is provided by a second type of blade, which provides single-blade, multicore processing capabilities that replicate the computing power of special-purpose security appliances. The processing power of multiple application blades can also be grouped to create a “virtual application processor” that enhances performance and redundancy.
This virtual application processor scales linearly; thus two blades acting as one virtual application processor have twice the computing performance as one blade. Moreover, traffic flows are balanced between application blades within a virtual application processor to deliver maximum computing efficiency. These blades are also hot-swappable and quickly adopt the configuration of any failed blade within the virtual application processor. Application processors also have priority failover capability, can be configured to back up each other and can even switch applications based on enterprise priorities.
The final processing capability in integrated security platforms is performed by the control processing blade, which monitors and manages the system’s overall functioning and health. These blades constantly manage and monitor all elements of the platform for failures and perform the appropriate system-level self-healing functionality for ultra-high reliability.
Integrated security platforms deliver the industry’s most advanced high-availability features with no single point of failure. The platform architecture provides multiple redundant data paths, dual control path switch fabrics, multiple power supplies and feeds, and redundant network and control processing modules.
The sophisticated, open operating-system software running these platforms offers the ability to logically sequence flows from one security application to another. This allows managers to get the benefits of security “service chaining” (such as traffic flows to firewall first and then an intrusion prevention device) without having to build the appliance, switching and load balancing infrastructure to enable it; instead, it’s all done via software.
Moreover, it’s done in a way that allows managers to choose best-in-class third-party security applications that facilitate implementation of their companies’ security policies. Additionally, the security platform operating system provides the virtualization capability that lets security applications have no physical representation on applications blades. Instead, the operating system creates an abstraction that allows applications to run on a “virtual application processor” that is a collection of blades.
Conclusion
As IT management looks to cut costs and ease the management burden of increasingly complex networks while complying with stringent security policies, it will increasingly need to consider the integrated security platforms. These platforms deliver unprecedented levels of network consolidation and scalability, are simple to install, integrate and operate, and deliver on virtualization’s promise of improved infrastructure and asset utilization.
Together, the consolidation, virtualization and service chaining capabilities of these platforms reduce appliance sprawl; efficiently utilize computing and networking resources; and deliver high availability, reliability and uncompromising performance.
Freeze is the chief marketing officer for Crossbeam Systems. He can be contacted at jfreeze@crossbeamsys.com.




