55
Ixia Visibility Architecture Artem Kirillov, System Engineer EMEA

Ixia Visibility Architecture - «Сталевий бубен ...€™s Visibility Product Portfolio Serves as the foundation for Application Performance and Security Resilience Visibility

Embed Size (px)

Citation preview

Ixia Visibility Architecture

Artem Kirillov, System Engineer EMEA

2

End-to-End Product Family

Wireless Testing Acquired June 2009

Increased Router Testing

Acquired Oct 2009

Wi-Fi, WLAN TestingAcquired July 2011

Founded in 1997 IP Testing

Network VisibilityAcquired June 2012

Actionable Security Intelligence (ASI)

Acquired August 2012

2

of the Fortune 100

of the top 50 carriers

of the top 15 NEMs

74

42

15Customer Focused

Innovation

Enterprise

Carriers/Service Providers

NEMs

2014 Industry-first ATI security solution2014 Industry-first virtual tap2014 Industry-first 400GbE test solution

4

IT is Central to the Business Value Chain

No Matter What Business You’re In

Connectivity

Application Delivery

Customer Experience

IT has a Central Role

DeliveringInfrastructure & Applications

That Empower Your Business!

No Matter What Stakeholder You Serve

5

The Perfect Data Center Meets these Challenges

SecureEfficient

Constantly EvolvingBusiness Critical

5

6

Sub-optimal Visibility and Security Systems

Carrier NetworksWired and Mobile

Data CenterPrivate Cloud

Virtualization

Core

Remote OfficeBranch Office

Campus

Network Operations

Performance Management

Security Admin

Server Admin

Audit & Privacy

Forensics

APM

HW Monitor

NPM

User ExperienceIPS / IDS

Cloud Monitor

Firewalls

Forensics

• New Complexity• Missed SLA’s• Costs that do not Scale• Churn in Investment

7

What You Need to Solve the Problem

Ixia’s Visibility Architecture

Ixia’s Visibility Product PortfolioServes as the foundation for Application Performance and Security Resilience

Visibility Architecture

AppAware

Carrier NetworksWired and Mobile

Data CenterPrivate Cloud

Virtualization

Core

Remote OfficeBranch Office

Campus

Network Operations

Performance Management

Security Admin

Server Admin

Audit & Privacy

Forensics

Out of BandNPB

NetworkTaps

ElementMgmt

Virtual & CloudAccess

PolicyMgmt

InlineNPBInline

Bypass

SessionAware

Data CenterAutomation

Network Access

PacketBrokers Intelligence Management

8

Visibility Architecture

AppAware

Out of BandNPB

NetworkTaps

ElementMgmt

Virtual & CloudAccess

PolicyMgmt

InlineNPBInline

Bypass

SessionAware

Data CenterAutomation

Network Access

PacketBrokers Intelligence Management

Ixia’s Visibility ArchitectureProvides total application and network visibility

Carrier NetworksWired and Mobile

Data CenterPrivate Cloud

Virtualization

Core

Remote OfficeBranch Office

Campus

Network Visibility FrameworkNetwork, application & end-user monitoring

Virtual Visibility FrameworkInter-VM, east-west traffic monitoring

PhantomVirtualization

Tap

Inline Security FrameworkFailsafe, inline security monitoring & enforcement

Network Operations

Performance Management

Security Admin

Server Admin

Audit & Privacy

Forensics

9

Visibility Architecture Key ComponentsNetwork, application and end-user monitoring eliminates the blind spots

Branch

Campus

CoreData Center

Network Taps

ManagementNetwork & AppPerformance

SecurityIntelligence

Customer Experience

Cloud &Virtual

Global Manageability− Easy global management− Data center automation and service

provisioning using RESTful API− Role based access for compliance

Maintain Network Performance− Speed security and network event

diagnosis with Auto Response− Direct flows to forensics recorders,

IDS or DLP devices, or honey pots

Proven, Patented Control− Auto Filter Compiler speeds set-up

and on-going hitless changes− Simplifies service provisioning− Easy to use Control Panel− Contextual application metadata

Scales to Your Network− Most extensive visibility portfolio− Mission critical reliability - NEBS− Improved tool scalability & resiliency

Network Packet Brokers and Application Intelligence

Aggregation FilteringFlow Linking Regeneration Load Balancing

App and Threat Intelligence Processing Offload Contextual Metadata

Dedup Time StampingBurst Protection Stripping Packet Capture

Acce

ssN

PBIn

telli

genc

eTo

ols &

Mgm

t.

10

Visibility Architecture Key Components - AccessInstant, Fail-safe access to all network traffic eliminates the blind spots

Branch

Campus

CoreData Center

Network TapsCloud &Virtual

Exact Copies of Network Traffic, including Errors and Fragments for Complete Analysis

Zero Impact to Network Performance or Uptime

Instant Access to all Network Traffic without Change Boards or Live Network Impacts

Unified Access to Physical and Virtual Network Traffic

Acce

ssN

PBIn

telli

genc

eTo

ols &

Mgm

t.

High Density• Highest Density Available• Flexible 1/10/40/100G• Easily Scales

Managed• Remote Control/Config• Additional Flexibility

Virtual / Cloud• Visibility to East / West

Traffic• Kernel-Level Integration

11

Visibility Architecture Key Components – Packet BrokersLine-Rate Filtering and Application Intelligence for Tool Optimization and Security

Control Tower Architecture allows easy management of hundreds of ports in a single UI, seamless upgrades, and more.

A broad gamut of deployment options from 1U to distributed deployments to large chassis.

Automated Filter Compiler that automatically configures all filters via simple GUI

Advanced features provide exactly the right traffic to the right tools at the right time. (real-time, lossless)

Acce

ssN

PBIn

telli

genc

eTo

ols &

Mgm

t.

Key Capabilities• Deduplication• Burst Protect• Time Stamping• Stripping• Packet Capture• Aggregation• Filtering• Flow Linking• Load Balancing

Core andHigh Density

Distributedand SDN

Branch andRemote Office

12

Automated Filter CompilerAutomation of difficult manual functions - speeds set-up and on-going changes

Simple and quick flow control - quick deployment, changes and troubleshooting

Hitless changes – no packets dropped

Concurrent changes by different admin users

Simple to integrate with external provisioning systems – automated service provisioning

Network SPAN Port

Tool Port #1

Tool Port #2

Tool Port #3

Traffic multi-casted from one SPAN port to 3 tools

TCP

Enter 3 simple filters in the Network Tool Control Panel

VLAN 1-3

VLAN 3-6

TCP

Automatically calculates filter overlaps, and creates rules

No. Criteria Action

0 VLAN 3 + TCP Tool 1, 2 & 3

1 VLAN 1-3 + TCP Tool 1 & 2

2 VLAN 4-6 + TCP Tool 2 & 3

3 VLAN 3 Tool 1 & 3

4 VLAN 1-2 Tool 1

5 VLAN 4-6 Tool 3

6 TCP Tool 2

7 Null Drop

3. What Automated Filter Compiler does 4. Why is this a big deal

2. What you do1. What you want

13

Visibility Architecture Key Components – Application-aware Packet BrokersBetter Data for Better Decisions

Supports generation of NetFlow v9 &10 and IPFIX data

ATI subscription delivers frequent updates for new applications and as applications change over time.

Combines traditional packet broker capabilities with application awareness and context

Automatic recognition and filtering of 200+ applications, and dynamic detection

Acce

ssN

PBIn

telli

genc

eTo

ols &

Mgm

t.

Key Capabilities• Application Filtering• Application

Recognition and Categorization

• Threat Intelligence• NetFlow provides

crucial Metadata for network intelligence.

Chassis or 1U Deployment

14

Visibility Architecture Key Components – Management and AutomationAutomation that responds instantly to the Network

The NTO immediately starts forwarding traffic with the new rules without any packet loss to other tools or admin intervention.

The issue is now being fully analyzed and recorded for forensics as soon as it is detected. It can be stopped in the same way after the event is over.

Security tool instructs the Ixia NTO to forward all packets from the event site to itself for real-time assessment and a data recorder for later analysis

Security tool detects an attack on a network device through packet or metadata monitoring

Acce

ssN

PBIn

telli

genc

eTo

ols &

Mgm

t.

Network & AppPerformance

Customer Experience

SecurityIntelligence

Branch

Campus

CoreData Center

Cloud &VirtualNetwork Taps

Data Recorder

15

16

Virtual Visibility FrameworkInter-VM, east-west traffic monitoring eliminates the blind spots in virtualized environments

Scales to Your Network− Single solution for – Vmware,

Microsoft Hyper -V, Citrix Zen, KVM, Parallels and Oracle

− Existing physical monitoring tools

Virtualized Host

Core Switch

Top of Rack Switch

Hypervisor

Kernel Module

vSwitch

VM

OS

AppVM

OS

AppVM

OS

AppVM

OS

AppVM

OS

App

Proven, Patented Control− Existing physical network packet

brokers− Quick and easy to deploy− Single solution for physical and

virtual visibility and troubleshooting

Performance− Kernel implementation preserves

hypervisor performance, capacity, throughput and utilization

Global Manageability− Simple virtual tap management− Single pane of glass management

for physical and virtual

Virtual Tap

Network Packet Brokers

17

Visibility for the Physical and Virtual Network

Top of Rack Switch

Kernel Module

vSwitch

Virtual Tap Virtual Tap Virtual Tap

OS

App

OS

App

OS

App

OS

App OS

App

OS

App

OS

App

OS

App OS

App

OS

App

OS

App

OS

App

Network Management

Application Performance

SecurityIntelligence

Customer Experience

Virtualized Servers ClusterPhysical Servers

Blade Server Chassis

Inline Security

Net

wor

k

Branch

Campus

Core Data Center

Cloud

Typical Inline Security Deployments

Threat prevention, not reaction Compliance requirements

Typical inline security devices− Intrusion prevention systems− Firewalls and NGFWs− DLP (Data Loss Prevention) systems− UTM (Unified Threat Management) systems− SSL decryptors− WAFs (Web Application Firewall)

Critical ConsiderationsWhy Inline Security?

Cannot take the network down Cannot slow or block application traffic Must scale with network demands

18

19

Inline Security FrameworkEnabling fail-safe, proactive security models throughout the network

Net

wor

k

Branch

Campus

Core Data Center

Cloud

Scales to Your Network− Most extensive inline portfolio− “Double Your Ports” NPB technology

provides 2x density− Single and high density bypass

configurations

Inline Performance & Reliability− Designed specifically for inline

deployments− Cut through architecture with

~300ns latency

Proven Inline Control− Industry proven fail-safe deployment

designs− Multi-stream heartbeat improves

overall design resiliency

Core Switches

Data Center Switches

Inline Bypass

Network Packet Brokers

IPS Load Balanced Group

NGFW Load Balanced Group

20

Why Visibility? Why Ixia? Why Now?

IT Evolving → Customer Service Approach

Focus on Improved Visibility for Improving Customer Service

The Answer:Ixia’s Visibility Architecture

Eliminating Visibility Blind Spots Scalable, end-to-end network,

application and user visibility Integrated virtual & physical solution Fail-safe, inline security

E R 2 9 9 - 4 5 - 0 0 2 > S O L O M O N S A M U E L > D 成龙 6 8 0 9 2 4 > Z U K A U SK I E N E J A N I N A > U P A T I O N C O N T R A C T O R > S A L A R Y $ 5 4 G R A N TB O B > K I M M I N J U N > 0 3 - 3 2 2 4 - 9 9 S C O V E R C A R D 8 3 3 0 9 3 2 0 5 > S TA V E N H D E 5 0 1 0 C C > S C H O D E R J U R G E N > M O B I N A U S T A L L I A >H Y P O T H E K E N Z A H L U N Y O S H I M I > И М Я : D U B O V V I C T O R > N U M

21

How about a DEMO?

Thank you

Medium Enterprise Design

Network Taps

Servers with Phantom TapNTO 2113 Packet Broker

Monitoring Tools

Network & AppPerformance

SecurityIntelligence

Protocol Analyzer

Branch

Campus

CoreData Center

Cloud

NetworkVisibility

Management

Large Enterprise Design

Net Optics Taps

NTO 7300Packet Broker

Monitoring Tools

NTO 5288Packet Broker

Servers with Phantom Tap

Branch

CoreData Center

Cloud

NetworkPerformance

VoIP Monitor

ApplicationPerformance

SecurityIntelligence

Protocol Analyzer

NetworkVisibility

Management

Campus

Carrier Design

NetOptics Taps

NTO 7300

EPCSGW PGW

MME

IMS

SLFAS

NFV Environments

GTPSession Controller

Monitoring Tools

ProbeProbe

Probe

NetworkPerformance

LTEMonitor

ApplicationPerformance

SecurityIntelligence

NetworkVisibility

Management

HSSPCRF

Inline Bypass Design

IPS

Bypass Switch

Security Monitoring Tool

IPS

Bypass Switch

Security Monitoring Tool(down/removed/upgrading)

Normal Operation

Bypass Mode

• Traffic routes through IPS• Monitored with custom heartbeat• Switch programmed to fail

open/closed• Managed via CLI, Web, etc.• Optional NPB to route through

multiple security devices

• Traffic bypasses the IPS• Security tool(s) can be

replaced/upgraded without interruption

Virtualization Design (detail)

Thank you

29

NVS Product Slides

Visibility Architecture

Network Visibility FrameworkNetwork, application & end-user monitoring

Virtual Visibility FrameworkInter-VM, east-west traffic monitoring

PhantomVirtualization

Tap

Inline Security FrameworkFailsafe, inline security monitoring & enforcement

Ixia’s Visibility ArchitectureProvides total application and network visibility

Carrier NetworksWired and Mobile

Data CenterPrivate Cloud

Virtualization

Core

Remote OfficeBranch Office

Campus

Network Operations

Performance Management

Security Admin

Server Admin

Audit & Privacy

Forensics

Net

wor

k Vi

sibi

lity

Virt

ual

Visi

bilit

yIn

line

Secu

rity

AppAware

Out of BandNPB

NetworkTaps

ElementMgmt

Virtual & CloudAccess

PolicyMgmt

InlineNPB

InlineBypass

SessionAware

Data CenterAutomation

Network Access

PacketBrokers Applications Management

30

TAPs and Bypass Switches: Fail-safe Network Access

Innovative FlexTap 1-100G SM and MM High density design saves rack space All-optical Flexible deployment, up to 24 Taps in 1U

Secure, intelligent remote management and ProPush™ statistics

Zero delay technology eliminates packet drop

Single and high density bypass configurations

Multi-stream heartbeat with micro second response

StrengthsDeployment Flexibility Security and Reliability Industry Leading Recovery Times

Ixia TAPs and Bypass Switches Provide the Industry’s Broadest and Most Robust Access Portfolio

FlexTap (1 / 10 / 40 / 100G)Gig Zero Delay Tap

Net Optics Bypass 3 10 GigaBit Regeneration Tap

iTap Dual Port Aggregator

1Gigabit

10Gigabit

40Gigabit

100Gigabit

31

32

NTO Modular Network Packet Broker Portfolio: A Solution for Every Need

211x5204

Carrier-Class/NEBS

High Performance 10/40/100G

Advanced1/10G

Entry

• Flexible, scalable, high density• 100G, 40G & 10G• 4x 100G, 16 x 40G, or 64 x 10G

• High-density, Carrier-Grade• 100G, 40G & 10G (NEBS)• 4x 100G, 16 x 40G, or 64 x 10G

EnterpriseCapability

5236

5273

5288 5293

• 10G networks (NEBS)• 24 x 10G• 24 x 10G

• Small Enterprise• 4 x 10G + 20 x 1G

Flexible & Scalable10/40/100G

• ControlTower Architecture• 16 x 40G, or 64 x 10G

5268

• Medium Enterprise• 10/1G + Advanced

• ControlTower Architecture• 16 x 40G, or 64 x 10G

5260/3

StrengthsRich Feature Set Carrier Class Reliability Easy Configuration and Management

NTO Packet Brokers Bring Intelligence and Scalability to Visibility Architectures to Maximize Tool Capability

6212• 48 x 10G & Optional ATI Processor

NTO 7300 Platform Summary

7U Chassis with 6 SlotsBest Density in the Industry! (584G/U)

– 384 Ports of 10Gb (via 40Gb breakout)

– 288 Ports of Native 10Gb SFP+– 96 Ports of 40Gb

High Availability Design – Redundant Fans– Redundant DC Power (1U AC Shelf)– Redundant Fabrics– Hot-Swap Capable (Post-RTS)

Switching Capacity: 3.8Tb/sControl Tower and NEBS 3 Ready

• 6 Slot Chassis w/non-block Fabric• 48 port 1/10G Line Card• 16 port 40G Card• Advanced Function (AFM) Cards• NEBS Option• AC or DC Power

StrengthsProtect Tool Investment Carrier Class Reliability Scalability to Adapt with Your Network

Carrier-class reliability and scalability in a compact 7U footprint

NTO 7300 Platform Line Cards

10G 40G 100GAdvancedCapability

48x10G 48

16x40G 64 16

48x10GPacket Capture 48 Packet Capture

8x40G 16x10G NetPort 16 8 NetPort AFM

AFM Carrier 32 12 210G AFM40G AFM

100G

ATI Processor 48Application Intelligence

Port capacities shown are a maximum configuration for that card

35

Application & Threat Intelligence Processor

ATI Processor delivers higher value data to monitoring tools so they deliver better information.Better information results in better decisions.

What is it?• Processor that allows customers to see real-time application level traffic and

metadata Data available in any format – web API, NetFlow/IxFlow, or Dashboard

• Standard NTO features 48 ports of 10 GE SFP+ Application filtering Port/Group Load Balancing Port tagging Standard stripping features Uses NTO GUI management interface

Who is it for:• Ixia NTO 6212 1U Applicance (stand-alone)• Ixia NTO 7300 customers (Line Card)

36

Packet Capture Module

Quick Data Capture for Quick Troubleshooting

What is it?• Provides ability to capture a range of packets (up to 14 GB) at line rate on up to 40 GE links

(or 40 Gb aggregate) • The packet captures can then be quickly decoded with an on-board (Wireshark) analyzer • Standard NTO features

48 ports of 10 GE SFP+ Dynamic filtering Port/Group Load Balancing Port tagging Standard stripping features Uses NTO GUI management interface

Who is it for - Ixia NTO 7300 customers

Inline Network Packet Broker Portfolio: Advanced Capabilities

Product Key Benefits

10G Load Balancing

xBalancer

• Combined feature set: Tap, Aggregation, Regeneration, Dynamic Load Balancing

• Distribute traffic to multiple tools for parallel processing

Timestamping

Director xStream Pro

• Combined feature set: Tap, Aggregation, Regeneration, Static Load Balancer, Timestamping

10G Monitoring Switch

Director xStream

• Combined feature set: Tap, Aggregation, Regeneration, Static Load Balancer

1G Monitoring Switch

Director and Director Pro

• Aggregation, Regeneration• Deep Packet Inspection• L2-7 Filtering

10G AggregationiLink Agg xStream

• Aggregates multiple traffic streams for monitoring by a single tool

StrengthsHigh Performance Broad Feature Sets Kernel Level Software

Forward relevant network traffic from multiple links to multiple monitoring tools for monitoring and analysis

37

38

Virtualization and Cloud Platforms: Visibility for Virtualized Environments

HypervisorSupport:

StrengthsHighest Performance Cross Platform Certified Kernel Level Software

Market’s Only Software Certified by VMware, Cisco, Microsoft, IBM, V Block, Oracle, Citrix and Red Hat

Preserves performance, capacity, throughput and utilization for a true cutting-edge technology solution

Lowers investment in virtual tools by bridging existing physical tools to the virtual network

Enables routing of data from data centers to central monitoring facilities

Enables monitoring of virtual network traffic in a virtualized computing infrastructure that is unable to process VN-Tags

39

GTP Session Controller - GSC 7433

Industry-First GTP Session Controller

GSC 7433

GTP-session Awareness Offloads GTP session correlation from monitoring tools Keeps GTP sessions together across multiple probes Session Distiller offers unique GTP sampling capability Based on the proven Anue software interface

Scalable Load Balancing Solution Distributes over 50 million subscriber sessions Scalable from 32 to 64 ports in the same 2RU chassis Session Safety Net detects probe failure and redistribute traffic until recovery

Carrier-grade Availability NEBS Level 1 Certified Product Front to Back Air Flow Redundant Management Ports

StrengthsHighest Performance Robust Load Balancin High Reliability

The Most Advanced GTP Session Capabilities Available in the Market

Visibility Architecture Management

StrengthsGlobal Management Capability Complete Portfolio Coverage

Visibility Management Allows Deployment of Global Visibility Architectures and Advanced Automation

The Ixia GMS solution meets the needs of NTO users in three main areas:• NTO Inventory Management• NTO Performance and Fault Monitoring• Multi-NTO Configuration Management

Ixia GMS ManagementNetOptics VMS

• Auto discover and configure Net Optics devices (Director, Director Pro, iTap)

• Collect statistics using ProPush™ technology and SNMP

• Scheduler for device and policy management

40

41

Product Detail and Backup

42

NTO 5293

Telecom & Carrier Class

NTO 5293

NEBS Level 1 Certified Product Up to 4x 100G, 64x 1G/10G ,or 16 40G ports in a 2 RU chassis Non-blocking architecture; 640 Gb/s total bandwidth Redundant, Hot-Swappable Power Supply / Fan Modules -48V DC or 120-240VAC Power Input Front to Back Air Flow Local and Remote Alarm Relay Support Redundant Management Ports Craft Interface for Emergency Out-of-Band Reset

100Gb ModuleEnables Network Visibility for any tool up to 100Gb

43

NTO 5293

Configuration Details

Dual Management Ports

Modular Ports (A, B, C, D)1x100Gb, 16x1G/10G SFP/SPF+,

OR 4x40G QSFP+

Fan Modules X 3 (2U)Craft Interface for Emergency

Out-of Band Reset

Power Modules(Redundant Power Optional)

44

NTO 5288

High Performance 10/40/100G

NTO 5288

High density 10G / 40G /100G solution Up to 64 10Gb, 16 40 Gb, or 4x100Gb ports Full line rate across all ports Low power consumption Non-blocking architecture Compact 2U rack-mountable chassis

100Gb ModuleEnables Network Visibility for any tool up to 100Gb

45

NTO 5288

Configuration Details

Dual Management Ports

Fan Modules X 3 (2U)Craft Interface for Emergency

Out-of Band Reset

Power Modules(Redundant Power Optional)

Modular Ports (A, B, C, D)1x100Gb, 16x1G/10G SFP/SPF+,

OR 4x40G QSFP+

46

NTO Control Tower Architecture Components

Flexible and Scalable 10/40/100G

NTO 5260

Manage Complex, Distributed Environments with Ease from a Single UI

Most efficient architecture in the industry

Supports high-density or distributed architectures

Scalable up to 64 10Gb, 16 40 Gb, or 4x100Gb ports

NEBS 3 Certified Solution (5260 and 5263)

ControlTower Architecture

High Density Campus Top-of-Rack

NTO 5263

NTO 5268

47

NTO 526x

Configuration Details

Fan Modules X 3 (2U) Craft Interface for Emergency Out-of Band Reset

Power Modules(Redundant Power Optional)

Modular Ports (A, B, C, D)1x100Gb, 16x1G/10G SFP/SPF+,

OR 4x40G QSFP+

Dual Management Ports

48

NTO 5273

Telecom & Carrier Class

High availability carrier grade solution Fully NEBS Level 3 certified Up to 20 10Gb or 1Gb SFP+ ports Up to four RJ-45 copper Ethernet ports Available in 1Gb or 10Gb versions Upgradable in the field 2U rack-mountable chassis

NTO 5273

49

NTO 5273

Configuration Details

Dual Management Ports

Twenty 1Gb or 10Gb/1Gb SFP+ ports

Four 1Gb RJ-45 ports

Craft Interface for Emergency Out-of-Band Reset Local and Remote Alarm Relay

Support

Redundant Power Supplies and Fans

Four total 10Gb ports - 2 rear unit bays for 10Gb XFP or CX4 cards

50

NTO 5236

1/10G Advanced Functionality

NTO 5236

Designed for networks with 10Gb architecture High-performance platform Up to 24 10Gb SFP+ fiber ports Up to four 1Gb copper ports Available in 1Gb or 10Gb versions Upgradable in the field 1U rack-mountable chassis

51

NTO 5236

Configuration Details

Four total 10Gb ports - 2 rear unit bays for 10Gb XFP or CX4 cards

Twenty 1Gb or 10Gb/1Gb SFP+ portsFour 1Gb RJ-45 ports

1Gb ports can be upgraded to 10Gb/1Gb via SW

52

NTO 5204

Entry – Value Driven

NTO 5204

Designed for networks with 1Gb architecture Entry-level platform 24 1Gb copper ports Up to four 10Gb SFP+ fiber ports 1U rack-mountable chassis

53

NTO 5204

Configuration Details

Twenty 1Gb RJ-45 copper portsFour 1Gb dual media ports (RJ-45 or SFP)

Four total 10Gb ports - 2 rear unit bays for 10Gb XFP or CX4 cards

54

NTO 2112 and 2113

Entry – Distributed and Low Density Environments

NTO 2112

Designed to be easy to Deploy and Manage Full feature set No Configuration or Port Licenses, all Features Available by Default Software Upgradable Automation using RESTful/WebAPI NTO 2113 Ships with Advanced Feature Module (AFM)

NTO 2113

55

Advanced Packet Processing Product Family

Advanced Feature Module 16Advanced Feature Module 2• For medium enterprises and

service providers

• 2-Port, 1/10G module• Extended burst protection• NEBS certified• NTO 5236 and NTO 5273

• For large enterprises and service providers

• 16-Port, 10G module• VNTag Stripping• Time-stamping• NTO 5288