Cisco brings up to 800G firewalling to Nexus switches
In a data center rack, traffic no longer necessarily has to leave the switch and take a detour to reach a firewall. With NX-OS 10.6(3s)F, Cisco enables the new DPU security mode: stateful firewalling on Layer 4 runs directly on the DPUs, the specialized data processing units in Nexus switches, with up to 800G throughput and without hairpinning.
The feature is available for Cisco's Nexus 9000 smart switches, including the N9348Y2C6D-SE1U and N9324C-SE1U models. According to heise online, these devices previously lacked DPU-based firewalling. HPE has offered a comparable feature in its CX-10000 series for some time; there, the AMD Pensando Policy and Services Manager is used to manage policies. Cisco, by contrast, relies on its own management through Hypershield, even though Cisco's DPUs also come from AMD.
There are several ways to forward traffic to the DPU: Layer 2 microsegmentation via a service VLAN, a Receive-Only VLAN assignment, Enhanced Proxy-ARP, or the redirection of a VLAN or VRF, meaning a separate routing instance. The switches can also inspect traffic between VRFs and support security controls in EVPN/VXLAN overlay networks. Hypershield is now available for the first time as an on-premises controller, allowing policies to be managed locally.
Cisco is adding high-availability features for Layer 2 and Layer 3. They are intended to secure packet forwarding if an individual switch or DPU fails. Because the paths inside the device between the NPU, or Network Processing Unit, and DPU are becoming more complex, a Packet Tracer displays the path taken by a packet.
So, what does this mean in practice? Operators can run stateful firewalling directly on the switches' DPUs with up to 800G throughput, without sending traffic through a separate firewall. Access is expensive, however: in addition to the DCN-Premier license for the switches, an additional Hypershield license is required for policy management. The feature has been released; the licenses mentioned are required to use it.
Comentários
A carregar a conversa…
Inicie sessão para escrever um comentário. Iniciar sessão