Monday, November 23, 2009
How Oracle, Cisco to Challenge IBM, HP in Enterprise Data Centers ?
News Analysis: Oracle and Cisco Systems are working on entirely separate, but similar tracks in long-term efforts to become full-service systems providers on par with IBM and Hewlett-Packard. Oracle, a 32-year-old vendor of database and enterprise application software, will get a lot closer to that goal if it gets final regulatory clearance to close its $7.4 billion acquisition of server and storage manufacturer Sun Microsystems. Meanwhile, networking equipment vendor Cisco Systems, at 25, is focusing on its Unified Computing System initiative to expand its presence and influence in corporate data centers.
Botnets: who's behind them and why?
Thursday, October 16, 2008
Wednesday, April 9, 2008
Cisco, Juniper face-off on software
Network World, 06/12/00
SANTA CLARA - Speeds and feeds are not all that matters when building reliable routers for the Internet core.
Indeed, the software component of these high-speed devices may play an even larger role in ensuring that packets and sessions are not dropped. That's why Cisco is building more resiliency and redundancy into its next generation IOS software. That's also why Juniper Networks plays up the reliability of its Junos operating system.
And perhaps that's why these two rivals try to point out the deficiencies of each others' software offerings. Although Cisco has been around a lot longer than Juniper, both companies are courting the same customers in the service provider market, where Cisco is a relative newcomer.
"Juniper continues to eat away at Cisco's leading market share - which is still in the 70% range - and this trend should continue," market researcher Current Analysis stated in a recent report.
"Our broader strength is our six major releases in 18 months," says Scott Kriens, Juniper CEO, commenting on Junos. "We can deliver innovation faster than anyone else. It's that accumulated breadth that is our competitive advantage."
Eighteen months pales in comparison to 15 years, which is how long Cisco has been developing and selling IOS.
"We are the market share leader from a control plane perspective," says Martin McNealis, marketing manager in Cisco's IOS Technologies division, referring to the Multi-protocol Label Switching, VPN, voice and multicast features of the Cisco software. "We're not hearing service providers hammer the table saying we need to have [certain features] because [Juniper] has it."
It's neither Juniper nor Junos that's prompting Cisco to build more resiliency, availability and redundancy into the next major release of IOS. IOS will feature "more intelligent" handling of outages and service upgrades, McNealis says.
"We're now looking to deliver a bulletproof architecture," McNealis says. "Now that we're a systems company, we have to accept that there will be hardware and software failures."
Cisco is building stateful redundancy into IOS whereby information on the state of routes, sessions or packets can be replicated within a router chassis. Currently, Cisco offers redundancy between two distinct routers via the Hot Standby Routing Protocol in IOS.
Juniper refers to this version of IOS as IOS NG, with NG standing for "Next Generation." IOS NG is Cisco's attempt to be more competitive with Junos by having a more modular architecture and being tailored specifically for service providers, Kriens says.
Juniper's definition of modular means separate processes - such as routing protocols, management and security - each run in protected memory. Currently, IOS is "monolithic," Kriens says, meaning all processes run together and are interdependent.
"It's kind of comparing Windows with DOS," Kriens says, noting the modular nature of Windows vs. the monolithic nature of DOS.
Perhaps it's best to compare an operating system that was built from the ground up to perform routing vs. one that has its roots in a general purpose operating system such as Berkeley Sockets - the precursor to Unix - but has been modified to do routing, says Cisco's McNealis. IOS is the former while Junos is the latter.
"IOS was always tailored for infrastructure," McNealis says. "It's very network-centric. It's control plane and data plane optimization vs. a general-purpose operating system. You do make some compromises when it has to be that portable."
Juniper selected Berkeley Sockets as the source code for Junos because it was readily available in the public domain, Kriens says. But JUNOS represents 4 years and 300 to 400 man years of development on top of that Berkeley Sockets source code, he says.
"Any resemblance [to Berkeley Sockets] would be so remote as to be irrelevant," Kriens says.
Cisco, Juniper face-off on software
Network World, 06/12/00
SANTA CLARA - Speeds and feeds are not all that matters when building reliable routers for the Internet core.
Indeed, the software component of these high-speed devices may play an even larger role in ensuring that packets and sessions are not dropped. That's why Cisco is building more resiliency and redundancy into its next generation IOS software. That's also why Juniper Networks plays up the reliability of its Junos operating system.
Sunday, February 17, 2008
Cisco Nexus 7000 Series Switches
A More Scalable and Flexible Data Center
Build a flexible, scalable framework for your new data center network with Cisco Nexus Switches.
The Cisco Nexus 7000 Series is a modular data center-class switching system designed for 10 Gigabit Ethernet networks. The Cisco Nexus architecture scales beyond 15 terabits per second, with future availability of 40Gb and 100 Gb Ethernet and unified fabric I/O modules. This new platform is designed for exceptional scalability, continuous systems operation, and transport flexibility.
The Cisco Nexus 7000 Platform is powered by Cisco NX-OS, a state-of-the-art operating system. The Cisco Nexus 7000 Series is purpose-built for the data center and has many unique features and capabilities designed specifically for the most mission-critical place in the network, the data center.
Monday, October 22, 2007
Cisco Cable High Speed Data (HSD) Solutions
Cable operators have enjoyed great success offering Internet access. Cisco has the real-world experience, proven products, and advanced technologies to help you supply cable high-speed data (HSD) services, based on DOCSIS standards, for homes and businesses.
Cisco HSD solutions (Figure 1) blend broadband cable RF technology with Cisco’s highly scalable, secure, and flexible IP core technology. The Cisco portfolio includes industry-leading, DOCSIS-compliant CMTSs, leading-edge business and home CPE, and advanced IP backbone and edge products. Along with residential HSD products, Cisco offers tested business service solutions, including VPNs, Metro Ethernet, and virtual LANs, that can generate higher margins and higher revenue.
Cisco works with you to integrate its broad array of products into a single, highly productive HSD solution tailored to your needs.
How the DOCSIS-Based Solution Works
Your high-speed data backbone can be used for interconnection between different regional networks, as well as to external networks. High-speed trunks using DWDM and SONET/SDH technologies support Ethernet interfaces used by both routers and switches. The statistically multiplexed links can, in turn, use Dynamic Packet Transport (DPT), Resilient Packet Rings (RPRs), or other Ethernet transport standards such as 10 Gigabit Ethernet links.
Next-generation technology incorporates Modular CMTS architectures (M-CMTS) based on DOCSIS 3.0 downstream channel-bonding techniques that more effectively use bandwidth. Your customers can receive 100 Mbps services and beyond via your existing cable plant. You can add this new technology on a node-by-node basis, responding to competition as it arises. Our solutions let you take advantage of DOCSIS 3.0 channel bonding without a major infrastructure upgrade and also allow you to support DOCSIS 1.x, 2.0, and 3.0 simultaneously.
Figure 1 Cisco Cable DOCSIS-Based High-Speed Data Solutions
Click on a product name for more information
Wednesday, October 17, 2007
Juniper unveils giant router
Juniper Networks Monday announced a eight-slot core router for service providers that boasts bandwidth of 1.6Tbps, more than twice that of the company’s previous high-end system.
The vendor’s T1600, in a half-rack configuration, blows past the 5-year-old T640, which tops out at 640Gbps. Juniper claims its new box provides 2.5 times the capacity of Cisco’s CRS-1 router with 30% less power and cooling requirements.
T640 customers can upgrade to the new router in 90 minutes without service interruption, Juniper says.
Given that the T640 came out in 2002, they might be eager to do just that.
“The T640 is old,” says Mark Seery, an analyst at Ovum. “Five years is a long time in this business.”
Service-aware routers
The T1600 is also “service aware,” according to Juniper, meaning that it can provide content-specific transmission quality depending on the traffic type – voice and video, in addition to data. Core networks that are not service aware delay new service introduction, lead to inefficient use of resources, force the construction of complex network architectures, and ultimately limit an operator’s competitiveness, according to Juniper.
Service awareness is achieved through in-depth packet processing and policy control. Policy is enabled by Juniper’s recently announced Session Resource Control products, hardware-based controllers running applications which mange subscribers and network resources.
The T1600 also supports the recently introduced point-to-multipoint MPLS (P2MP) feature in the JUNOS operating system. P2MP is intended to provide efficient core video distribution and enhanced optical network integration at 10G and 40Gbps.
A potential downside to the T1600 is its initial lack of support on Juniper’s TX switching matrix, a centralized fabric designed to connect T-series routers into a multiterabit-per-second virtual megarouter. Juniper says customers are demanding higher density and capacity in individual elements for scale rather than connecting multiple lower density systems together.
Juniper also says TX will require an upgrade to support the 100Gbps-per-slot capacity of the T1600. Company officials did not say when this upgrade would be unveiled.
What carriers think
Ovum’s Seery says carriers are not yet confident in the multichassis interconnect options from their vendors.
“I believe all carriers are trying to assess whether they are comfortable with multichassis configurations,” he says. Some carriers are looking for redundancy features, such as the ability to deploy dual distributed switch fabrics, to eliminate the single point of failure current offerings present, Seery says.
Juniper’s hoping carriers won’t wait for the TX support before buying the T1600. Juniper’s deployed 2,500 T640s to date but the company’s share in the core router market slipped from 37% to 30% over the past year.
And Cisco, which announced Monday that it shipped 900 CRS-1s since the product’s launch in 2004, stole some thunder when AT&T picked the CRS-1 to replace its Avici Systems installation after Avici announced it was exiting the core router market.
“The T1600 will help defend Juniper against [Cisco’s] CRS-1,” Seery says. “But it’s not in a strong position until it’s in a TX configuration.”
The T1600 is slated for fourth quarter availability.
The vendor’s T1600, in a half-rack configuration, blows past the 5-year-old T640, which tops out at 640Gbps. Juniper claims its new box provides 2.5 times the capacity of Cisco’s CRS-1 router with 30% less power and cooling requirements.
Sunday, September 23, 2007
Cognio's spectrum intelligence technology to enhance, complement Cisco's Unified Wireless Network vision
Cognio's industry-leading spectrum technology enhances performance, reliability and security of wireless networks by detecting, classifying, locating and mitigating sources of radio frequency (RF) interference. The acquisition will provide Cisco with complementary and differentiating technology, intellectual property and a core team to expand Cisco's leadership in unified wireless networking.
Wireless and mobility are becoming mission critical components of today's networks, with businesses viewing the wireless spectrum as a strategic corporate asset. Businesses now require robust, next generation wireless networks to support the unprecedented growth of wireless devices and the increased reliance on mobility applications. Cognio's spectrum intelligence solution enables network managers to proactively manage their wireless spectrum and minimize RF interference for an optimal user experience.
"With a strong product and technology portfolio and consistent innovation from a talented group of engineers, Cognio has emerged as the leader in spectrum intelligence technology," said Brett Galloway, vice president and general manager of the Wireless Networking Business Unit, Cisco. "Wireless spectrum is a strategic asset for our customers, and its management is key to the robust delivery of mobility applications. Cognio's innovation in spectrum intelligence will help ensure Cisco continues to differentiate our ability to deliver our customers rich and dependable end-user mobility experiences."
The Cognio acquisition complements Cisco developed technology as well as expertise from other acquisitions that Cisco has made in the wireless networking space. This acquisition will expedite the delivery of industry-changing capabilities and is consistent with how Cisco uses business development strategies to move into new markets or to gain new technologies. Cisco classifies wireless networking as a Cisco Advanced Technology -- one of six -- with application networking services, home networking, security, storage networking and unified communications being the others.
The Cognio acquisition is subject to various standard closing conditions and is expected to close in the first quarter of Cisco's 2008 fiscal year. Upon the close of the acquisition, Cisco plans to integrate Cognio into its Wireless Networking Business Unit, under the Ethernet and Wireless Technology Group.
The Cognio acquisition will be No. 122 for Cisco and the first one in fiscal year 2008.
Sunday, September 16, 2007
Juniper and Symantec security alliance to challenge Cisco
The two Californian companies, Juniper from Sunnyvale and Symantec from Cupertino, recently announced what they call "a broad strategic partnership" in security, involving joint development of unified threat management (UTM) appliances, intrusion-prevention systems, and network access control.
The two are heavyweights in their respective areas, and though they compete today in firewall/VPN, NAC and IDS/IPS, they are both major competitors to Cisco, a factor that clearly forms the backdrop to this alliance.
Depending on the analyst firm, Juniper is either number two or three in the carrier routing market behind Cisco. The other player is Alcatel, which some analysts rank above Juniper whose efforts to break into the enterprise market with its J-Series routers had a tepid reception, so two years ago it adopted a different tack, and spent $4bn to acquire firewall/VPN, SSL VPN and IDS/IPS upstart NetScreen.
Earlier this year it began to move into UTM appliances, which are multi-function security appliances aimed primarily at the branch and remote office environment, adding a routing capability to offer what some analysts are calling a branch-in-a-box, or BiaB, product: its Integrated Security Gateway portfolio. The products compete directly with Cisco's Integrated Services Router and Adaptive Security Appliance product lines, which use some perimeter security functionality from Symantec competitor Trend Micro.
Meanwhile, Symantec last year acquired Sygate, taking the AV heavyweight into endpoint security where Cisco has its Network Admission Control offering and Juniper its Unified Access Control.
However, rather than continuing to compete in isolation against the networking giant, the two are now pooling their NAC technologies and working within the context of the standards-based approach by the Trusted Computing Group, based on its Trusted Network Connect spec, which they both want to drive to avoid Cisco dominance of this emerging space.
Equally, Cisco has just unveiled a collaboration with Microsoft Corp to make its NAC interoperate with the Microsoft's Network Access Protection technology that is due to appear in Vista and Longhorn. This clearly behoves Symantec and Juniper to drive TNC-based NAC harder now before it is rendered irrelevant by a de facto standard represented by the Cisco NAC/Microsoft NAP coupling.
Another recent development that is also a factor here is EMC's June $2.1bn acquisition of authentication vendor RSA. Market rumors suggested EMC swooped on RSA before another major player got there, with Symantec the name most commonly bandied about. Since its merger/acquisition of storage software heavyweight Veritas last year, Symantec has been butting heads directly with EMC's own software division. Industry insiders say that with RSA providing some encryption technology used in EMC's arrays, the prospect of the token authentication vendor falling into the hands of Symantec was unpalatable.
However, that move also left Symantec in edge security (anti-X, content filtering, firewall/VPN, and IDS/IPS) with a play in the core (NAC), but needing to beef up its offering in the latter, which is one of the areas the alliance with Juniper seeks to address.
While Juniper has been getting into UTM this year, Symantec a couple of month ago made a hazy announcement that it was exiting, or at least de-emphasizing the appliance market, a move which the announcement with Juniper throws into a new light. Rather than go it alone on UTM box development, Symantec sees benefits to riding in with its technology on Juniper's hardware, leveraging both their channels to get to market.
On the back end, both companies have research teams sitting in network operation centers around the world, monitoring screens for threats and exploits. Juniper has its J-Security Team and Symantec the Global Intelligence Network, collaboration between which should in theory enable more a comprehensive service of security info feeds to common customers.
Symantec is already a significant security services player, and another recent relevant development is that IBM's Global Services arm recently acquired IDS/IPS pioneer ISS, whose recent business strategy had been all about populating its customer's networks with its Proventia security appliances, then selling the info feeds to them as part of an overall services play.
The Symantec/Juniper partnership looks similar in approach, at least in terms of the U and IPS strains of the announcement, while the NAC part appears to be a way of gaining mindshare and market share to compete with Cisco. Joint developments in all three areas will give the partners a portfolio to rival that of Cisco in security, even though neither company is currently in Ethernet switching, which is still the largest single contributor to the networking giant's $29bn annual revenue. However, there are persistent rumors of a project deep within Juniper to develop a low-cost switching line based on Marvell silicon for launch in the second half of 2007.
Cisco adds NAC to ISR, updates endpoint recognition
The Cisco NAC Network Module for ISRs is a modular security solution that is integrated into the network infrastructure. It authenticates, authorizes, evaluates and remediates remote user machines connected via wired or wireless links, prior to granting them access to corporate networks. The NAC module for the ISR, designed for branch offices, thwarts potential threats and vulnerabilities locally before they're sent over the WAN to prevent them from entering the network, said Fred Kost, director of security solutions for Cisco.
The module includes all of the features of the Cisco NAC Appliance Server and is supported by the Cisco 2800 and 3800 Series ISRs. It enforces security policy on networked devices such as Windows, Mac and Linux machines; laptops; desktops; PDAs; printers; and IP phones.
The NAC module works in concert with firewalls, intrusion-prevention systems and VPNs to round out the security offered in the ISR, giving branches a secure infrastructure.
Kost said the module is designed for branches and office locations that don't have the time or resources to manage separate security solutions in addition to the routing infrastructure.
According to Ladi Adefala, security practice manager with systems integrator and Cisco partner World Wide Technologies, adding the NAC module to the ISR has the potential to give branches more bang for their buck when they are working with limited management and financial resources.
"From the administrator standpoint, the user is empowered with that all-in-one solution for the branch office," Adefala said. "You get the same level of security on the endpoints, and you get it with something less complex."
A modular NAC approach eliminates the need to devise new solutions around how to centralize management of security at a time when a lot of enterprises are focusing on centralization, he said.
"Aside from streamlining our management, the NAC ISR module allows us to concentrate our security efforts within the network itself," Adefala said. "It gives us an opportunity to offer our customers more synergy between their network and security as well."
Moreover, he added, eliminating the complexity should make NAC as a whole more marketable and affordable.
"You want to make sure whatever level of security you have at headquarters is carried over to branch offices, and this does that," he said.
Andrew Braunberg, research director with Current Analysis, agreed that putting NAC capabilities in the ISR brings more visibility to the edge, where it's needed most.
"The fact that they're going to be able to push NAC capabilities out to the branch makes sense," he said. "Logically and physically it makes sense to put them together."
Braunberg said he questions whether or not the NAC module for ISR is a step toward or away from Cisco's trying to marry both the NAC appliance and the CNAC framework, which has been rumored to be in the works for more than a year.
Along with the ISR module, Cisco enhanced its NAC Appliance Server by offering the Cisco NAC Profiler, an endpoint-recognition technology that keeps an inventory of networked devices so they can be evaluated before and during sessions on the network. The Profiler boosts the ability of networked devices that aren't associated with particular users to be identified, authenticated and then granted or denied network access. Devices that are unassociated with a particular user include printers, IP phones, wireless access points, sensors and medical devices. The Profiler also performs continuous behavioral assessments for post-admission access control.
"The Cisco NAC Profiler arrives at a time when businesses are supporting growing numbers of devices critical to operations and productivity," said a Cisco statement. "The NAC Profiler addresses the growing complexity of protecting an increasingly diverse array of networked devices by taking an in-depth and automated inventory and enabling actions to be taken based on their behavior."
NAC Profiler, which stems from an OEM agreement with Great Bay Software, consists of a software update on the NAC Appliance Server, and the NAC Profiler Server pulls information from the NAC Appliance Server and sends it to the management console, according to Brendan O'Connell, Cisco's NAC product marketing manager.
"It's about making sure a device is what it claims to be," O'Connell said, adding that in the past, devices like printers, copiers and other IP-addressed devices weren't assessed by NAC tools. "It's gathering information about the networked endpoint to ensure it's doing what it should be doing."
Braunberg agreed. "This does all of the heavy lifting of making sure there's an updated list of these non-responsive hosts," he said. "Since it can look at the behavior from a particular address, you can know what that device is supposed to be and what it's supposed to be doing. That can help considerably."
Sunday, May 27, 2007
Cisco Infrastructure for i-City
Residents and businesses in i-City, touted as Selangor's first Multimedia Super Corridor Cybercentre, will enjoy a variety of IT services.
These range from datacentres to wireless networks to high-end videoconferencing facilities; the first phase of the project will be completed by year end.
Kumaran Singaram, managing director of Cisco Malaysia, said companies planning to have their business premises in i-City would not have to build their own IT infrastructure from scratch. Everything they need will be at their disposal as soon as they move in.
“IT services will be available to every building,” he said, adding that in i-City, IT services would be as available as basic utilities such as running water and electricity.
Eu Hong Chew, chief executive officer of I-Berhad which is developing i-City, said the company's objective is to build an IT hub in Selangor.
He said Shah Alam was chosen because it is a well-known spot for industries. “Industries here will be able to use i-City to support their R&D clusters,” he said.
Wednesday, March 21, 2007
frame-relay static route problem
the problem occur when two routers connected via frame-relay switch (2522 router), the configuration on switch is correct as well as on both routers, the loop back interface has been made on RB router i.e RB has 20.0.0.0/8, while at RA router the static router is defined as
ip route 20.0.0.0 0.255.255.255 serial 0
it was not able to send packets to 20.0.0.0/8 when run debug, it got error like encapsulation failed, now when it replaced the static route with next hop ip it was working fine, why ????
When a layer3 packet is going to be sent out, the router must know the layer 2 header to encapsulate the Layer3 packet.In this case, it must know which dlci number (as well as other layer2 information) to encap the IP packet. If you only indicate a connected interface for the static route, and there are many dlci numbers on this interface, the router will not know which dlci number to use and thus gives you a encapsulation failure message.
On the other hand, if you indicate a next-hop address on the static route and there is a frame-relay map which maps a dlci number to this next-hop address , the router will know the exact dlci number to encapsulate the ip packet and the packet will be sent out successfully.