Foundry switches put security at edge

Opinion
Jul 6, 20062 mins

* Foundry's latest security switches

Foundry Networks last week introduced products that combine the company’s security technology with LAN switching.

The SecureIronLS LAN switches are part of the larger SecureIron family. Previous models were billed as traffic managers that performed Layer 2-7 switching and security for portions of your network. The new models offer security combined with high-density 10/100Mbps and Gigabit Ethernet ports for direct connections to servers and certain users.

Foundry says the SecureIronLS switches can do wire-speed network-layer security, protection against denial-of-service and distributed denial-of-service attacks at multi-gigabit rates, application-level deep-packet inspection, granular user and application usage control and Layer 2/3 LAN switching. Next month, Web-based authentication and device verification and identity-based service access control will be added. Anomaly detection and threat prevention are planned for December.

Foundry is selling the new switches as “a security value-added alternative to traditional LAN switches in the distribution layer as an internal firewall, or at the edge as personal firewall with direct desktop and server connectivity.” The company says the switches can be used for admission, access and usage control for all traffic coming to and from the edge of your network.

The devices come in several models. One is a 24-port 10/100Mbps Ethernet model with four ports of Gigabit Ethernet for $15,000. Another has 16 ports of 100/1000Mbps Ethernet and two Gigabit fiber ports for $25,000. And a third has 32 ports of 100/1000Mbps Ethernet and two 10 Gigabit Ethernet ports for $35,000. For full details, see my colleague Phil Hochmuth’s story.

It’s interesting to see Foundry take this step of embedding security at this level into LAN switches, at a time when so much is being said about the security architectures of other switch companies, particularly that of Cisco.