Net Optics Director Pro Combines Deep Packet Inspection And Load Balancing
Mike Fratto and Editor
March 03, 2010
Anyone who need to view network traffic for application, network or security monitoring knows the difficulty in getting traffic from the wire to the analyzer. Physical and network interfaces have to match exactly, or IT is forced to use switch-span ports that can place additional load on the switch fabric and limit the output speed. Net Optics announced a new inline tap that supports 40Gbps pass through traffic, a Gigabit Zero Delay TAP and a Director Pro with hardware based deep packet inspection and dynamic load balancing. Director Pro starts at $19,500.
The two new taps are, in a way, incremental improvements to existing passive tap products. The 40Gbps tap is, as far as we can tell, the first 40Gbps passive, full duplex network tap on the market, but we are sure there will be more to follow. Net Optics Zero Delay tap preserves the electrical connectivity to connected device ports, ensuring that if there is a power failure to a Zero Delay tap, the connected devices won't detect the electrical failure and have to renegotiate the physical link.
The bigger news, however, is Director Pro is a new hardware platform that adds additional processing power for performing deep packet inspection (DPI) and load balancing. Existing Director products are not field upgradeable to Director Pro, but both Directory and Director PRO use the same hardware interface modules.
The DPI function allows IT administrators to set-up filtering rules based on patterns that can match anywhere in the packet. Other intelligent tap products like Gigamon's Gigavue has had DPI pattern matching for quite some time. DPI is used to direct matching packets to specific output ports. Net Optics Director and Director Pro can direct packets to specific ports based on a variety of parameters like IP addresses and port numbers, but with DPI, IT administrators can direct only HTTP traffic, regardless of the TCP port being used, to a specific port based on the discovery of an HTTP header. For example, an IDS might be tuned to look for malicious traffic in the HTML responses like SQL Injection or Cross Site Scripting from a client to a server, and you want that traffic to be processed by the IDS. Other HTTP traffic such as images and videos don't need to be processed and won't be sent to the IDS. Or you might want to direct HTTP files like images and videos to be an anti-malware product. Using DPI, setting up those rules allows you reduce load on analysis devices.
Director Pro also allows dynamic load balancing, which can spread traffic flows among a number of different output ports. As network speeds increase beyond 10Gbps, analysis products have a hard time keeping up. Just like load balancing incoming HTTP connections among multiple servers lightens the load per server, load balancing captured traffic among multiple analysis products--multiple IDSes, for example--lightens the load per IDS.