home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Network + Systems Infrastructure
S N E A K   P R E V I E W  
Nauticus Simplifies Load Balancing

  July 10, 2003
  By Lori MacVittie


TOC Issue TOC
Printer Print full article
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author

Virtualization and consolidation in the data center are hot topics, with most of the talk centering on servers. Now Nauticus Networks brings consolidation to load balancing and acceleration with its N2000 series of fixed-configuration application switches.

The N2000, available with 40 ports of 10/100 or 12 ports of small-form-factor GBICs, uses virtual switching to offer the features and functionality of multiple load-balancers in one easy-to-manage device.

Nauticus' TideRunner chipset drives Layer 4 to 7 switching with a maximum of 3 Gbps of throughput. TideRunner also handles TCP termination in silicon, reducing the overall latency introduced by conventional content-networking devices.


N2000 configuration is a familiar process to those who use Cisco's IOS CLI (command-line interface). If you want a sexy UI, you won't be disappointed by the elegant, Flash-enhanced Web configuration option, complete with real-time statistical graphing.

The big drawback for those interested in gigabit connectivity is the use of small GBICs.



Nauticus N2000

click to enlarge

I needed to use FC-to-SC converters to connect to Spirent's WebAvalanche and WebReflector in our Green Bay, Wis., Real-World Labs®. I needed to do the same when connecting to Extreme Network's Summit7i--a necessity for including our Synthetic Network's gigabit copper-connected NetPressure clients for testing. The Nauticus processors cannot handle tristate interfaces, and, unfortunately, Nauticus chose 10/100 instead of a single-state gigabit copper interface, which the processors could support.

The most difficult part of configuration is adjusting to the device's virtual switching technology. The virtual switch (vSwitch) is like a VLAN for Layer 3 and above. It has its own memory and a user-configurable percentage of the processor. A vSwitch's routing tables (vRouter) and services are not accessible by other vSwitches; they are completely self-contained. Although it is possible to purchase an N2000 without this feature and use it as a strict Layer 4 server load-balancing device, the real power of the N2000 is in its virtualization and TCP termination capabilities.

Load Balancing

I tested a beta version of the N2000 at strict Layer 4, advanced Layer 4, Layer 7 and finally SSL. Strict layer 4 load balancing does not take advantage of the TideRunner chipset and therefore does not do TCP termination. It allows only for a weighted hash algorithm to be used for load balancing and is used when speed is a necessity and all machines in the pool are equivalent. Sessions are passed through to the appropriate server (chosen by a weighted hash algorithm) and bound directly to that server.

Strict Layer 4 testing under the maximum load we could dish out with our Avalanche-Reflector combination showed TCP session latency of less than 1 ms, with HTTP latency climbing no higher than 25 ms under a load of 27,000 HTTP transactions per second, distributed over four back-end Web servers simulated by the WebReflector. Because the N2000 uses a half-NAT (Network Address Translation) scheme, a virtual service and its supporting back-end servers must be on different subnets. This also means that the N2000 does not support DSR (direct server return). Given the high-volume backplane, this should not be the concern it might be with lower-capacity load balancers. Throughput averages of 750 Mbps were not a problem, and the N2000 appeared limited only by our test equipment.

With advanced Layer 4 testing you can use more varied algorithms because sessions are passed through the TideRunner chip. Running the same tests with a round-robin algorithm showed no increase in TCP session latency, with HTTP latency peaking at 60 ms to 70 ms.

Rules and Routing

The N2000 lets you create content-matching rules, which can be used by any forwarding policy, meaning rules can be configured on virtually any portion of the URI as well as almost all HTTP headers.

Good
• Fixed-configuration switches with optional modules
• Virtual switch technology takes VLAN idea to the application layer
• Use of custom TideRunner chipset for content-switching functionality reduces latency

Bad
• Gigabit version is FC; will require converters to SC
• No gigabit over copper option
• VLAN IDs are numerical only

Nauticus N2000 Series, starts at $25,000. Nauticus Networks, (508) 270-0500. www.nauticusnet.com

More Infrastructure Resouces
white papers & research reports
books

Also unique to the N2000 is the ability to create rules based on HTTP responses as well as HTTP requests. I configured two policies, one to match on JPEG images and the other a default wildcard-based rule. Matching is case sensitive, so it's necessary to consider all possible cases that could make rules grow unwieldy. Policies make use of rules and assign positive matches of a rule to a group of real servers. Rules are not strictly bound to groups or individual servers, as they are with other Layer 7 devices; they are instead used by policies to make routing decisions. Running the same test on Layer 7 that I had run on Layer 4, TCP latency was still less than 1 ms, but as expected, HTTP latency increased, peaking at 1,000 ms and averaging 500 ms to 600 ms overall under heavy load.

Speed

SSL acceleration is provided using two different integrated chipsets: one for bulk encryption, the other for the handshaking process. Changing the virtual service from HTTP to HTTPS requires only the generation (or installation) of a certificate and changing the service of the port and the service type. The Avalanche managed to churn out 1,600 SSL sessions per second and the N2000 handled it without breaking a sweat.

The potential for creative network design with virtual switching is limitless. You can consolidate load balancers or use a single N2000 to support a tiered Web infrastructure. Four virtual switches can be supported, and each can be managed as a separate entity with user authentication and authorization provided internally or via TACACS+ (LDAP or RADIUS will be provided in a future release). Pricing is flexible, depending on functionality.

Lori MacVittie is a Network Computing technology editor working in our Green Bay, Wis., labs. Write to her at lmacvittie@nwc.com.

Post a comment or question on this story.









Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights