Cisco going to widely adopt “virtual firewalls”

Cisco Systems introduced this summer a new feature for Cisco Catalyst 6500 Series switches and Cisco 7600 Series routers, thanks to the Firewall Services Module (FWSM) 2.2 able to provide virtual environments where create isolated rules and policies, called Security Contexts.

Quoting from official announcement:



A security context is a virtual firewall that has its own security policies and interfaces. When properly configured, security contexts enable the same capabilities as multiple independent firewalls, with fewer management headaches. In essence, these contexts provide completely independent security domains. ‘ FWSM version 2.2 allows any port on the switch to operate as a firewall port, integrating firewall security inside the network infrastructure. Up to four FWSMs can be installed in a single chassis, providing scalability to 20 Gbit/s per chassis. Network administrators can use this infrastructure to create up to 100 separate security contexts per module (depending on the software license).

Security contexts are functionally similar to a collection of independent physical firewalls but are much easier to manage. Because they are virtual devices, it is easy to add or delete security contexts based on subscriber growth. This reduces management costs, because organizations do not need to deploy multiple devices, yet they can achieve the same capabilities and maintain complete control over the firewall infrastructure from one consolidated platform.

“FWSM provides many of the key firewall and networking features that security managers need to implement multiple security zones or contexts throughout a switched campus network or enterprise data center,” says Iqlas Ottamalika, technical lead, Cisco Security Appliance Group. “Instead of having hundreds of small firewalls spread around the network you can install one hardware platform that will manage everything. This can represent tremendous administrative savings.”‘

Some rumors report that upcoming PIX OS 7.0 (not even in beta) will introduce this feature for every Cisco PIX firewall device around.

More news as soon as possible.

Red Hat, Novell to package Xen open-source alternative to VMware

Quoting from CRN:


Watch out VMware and Microsoft. Here comes Xen.

Xen, an open-source project with growing ties to Red Hat, Novell and Hewlett-Packard, is emerging as the leading contender for providing open-source virtualization for the Linux environment.
Ian Pratt, the founder of the Xen project that originated from the University of Cambridge in England, confirmed that developers from Red Hat and Suse are preparing “testing packages” of Xen that will be released in the near future.
Additionally, Xen has joined forces with leading Linux distributors, chip vendors and platform vendors to create a consortium that will more broadly enable open-source virtualization development and deployment.
Xen backers are hopeful that support from heavy hitters in the Linux industry will make Xen a household name in the open-source community. The open-source project completed the first major update of Xen version 2.0 in November.
Steven Hand, another computer scientist at the University of Cambridge’s computer lab, said he expects the Red Hat drop will be available in the same time frame as Red Hat Enterprise Linux 4.0, which is due in the first quarter of 2005.

“Red Hat’s packaging Xen in the near future as part of Fedora. We’ve talked to Suse,” said Hand. “We have a lot of momentum in the open-source community. Now we’re pushing into mainstream Linux so when Xen goes into the latest versions of Linux, users can compile a Xen kernel out of the box.”
Red Hat will release test builds for Red Hat Fedora Core 3, and Novell will soon release test builds for Novell Suse Linux, Pratt said. The Xen components will be dropped into experimental Linux packages, but they won’t be commercially supported.

Xen does not support Windows today because it uses a technique called para-virtualization to achieve high performance that involves modifying the operating system kernel, Pratt said. However, the debut of virtualization features in next-generation CPUs from Intel and AMD will make it easier to support unmodified operating systems, Pratt said.
“At that time we will reconsider Windows support,” he said.

Neither Red Hat nor Novell would comment on their plans with Xen. A Novell spokesman said the company is “excited about what Xen is doing. But it’s premature at this point for us to talk publicly about our strategy and potential partnerships around virtualization.”
Xen will be available under the General Public License; some components may be available under a NetBSD-style license, Hand said.

Consultants and solution providers in the open-source market said they would welcome an alternative to VMware and Virtual Server, but Xen needs to add support for Windows. VMware supports Linux but is often an expensive add-on to an open-source stack, other observers said.
“Xen is very, very good, but it does not yet support Windows,” said Chris Maresca, senior partner at Olliance Group, Palo Alto, Calif. “A lot of people use VMware to support WinX on Linux.”
Ironically, Microsoft Research provided funding for the Xen group when it was founded two years ago, but has since back out, Xen officials said.

Xen is only one of several open-source projects devoted to offering virtualization software for the open-source and Linux environment.
Bochs, an open-source project founded in 1994 that evolved into Plex86, focused on Linux virtual machines. Observers said Plex86’s approach is more like VMware’s. Founder and developer Kevin Lawton said he talked with IBM, Red Hat and Novell about getting backing for the Linux VM project in 2003, but those discussions didn’t pan out.
The existing code, he said, is very experimental in nature and needs additional development before it could be classified as a “version 1.0” commercially ready server. The last update of Plex86 posted in December 2003. The project is now stalled, said Lawton, who is consulting for a startup company.
Top Linux vendors have also explored another open-source project, called user-mode Linux, or UML, said Lawton. UML is said to be slower than Xen but runs on more established technology and is often used for testing and debugging applications, observers said.

HP Labs and Intel Labs are other backers of Xen. HP is using Xen in its utility computing efforts, Hand said.
While HP would not comment on its plans for Xen, one HP executive said the company is working with several source projects and commercial companies as well as HP’s own virtualization technology to help enable utility computing.
“We’re primarily working with VMware and Microsoft in the virtualization space,” said Nick van der Zweep, director of virtual and utility computing at HP, noting that HP is not bundling Xen at this point but is investing in “various OS initiatives.”
Dave McCrory, founder of Surgient, an ISV and ASP whose platform uses virtualization technology, said there is a market for an open-source spin-off of VMware, but there are limitations to Xen that could stymie its acceptance.
“Xen is semi-virtualization. Right now, you can’t run Windows except a modified XP version and modified Linux. If someone could come up with an enterprise virtualization solution that was open source, it would be fantastic,” said McCrory, also chief scientist at the Austin, Texas, firm.
“Another problem that would face open-source solutions is that a lot of the real virtualization ground is consumed by patents created by VMware and Connectix and now owned by EMC and Microsoft,” he said. (EMC owns VMware while Microsoft now own Connectix’s virtualization software and is marketing it under the Virtual Server brand.) “This would pose another problem if corporations were considering adopting these types of solutions. I do believe there would be a market for it, however.”

As Xen tries to impress customers of Red Hat Fedora and Suse and eventually gain commercial support, its leaders are busy trying to secure support from a broad cross-section of chip vendors, hardware vendors and management tool vendors, Pratt said.
He noted that research and development on Xen will continue within the computer lab at Cambridge University, but product development and support will be a separate spin-off.
One Linux ISV said it’s still early for virtualization software on Linux, but Xen is the most promising open-source project to date.
“While it can be more complex to set up than VMware, it is able to achieve near-native performance on even the most taxing of tests. Xen is under active development, and is rapidly becoming a major player in the virtualization space,” said Nick Lassonde, chief software architect at Versora, Santa Barbara, Calif. “We’re seeing more and more demand for virtual machine technology for Linux-based servers, and we expect that this will continue to grow over the next five to seven years.”

Whitepaper: Introduction to NUMA on IBM xSeries servers

IBM RedBooks department released a nice small paper about NUMA architecture on xSeries:


Abstract

There are currently two main concepts related to connecting processors and memory together in a multi-processor system. One way of achieving multi-processor scalability is using symmetrical multiprocessing or SMP, and the other way is using non-uniform memory access or NUMA. SMP has been in use in xSeries-class servers since the early days. However, NUMA has only appeared in commercial xSeries servers over the past few years. This document introduces the concepts behind NUMA and explains the benefits.

Yes, I know this isn’t directly related to virtualization topics, but since IBM xSeries are a preferred platform for virtualization environments, I think someone could appreciate.

VMguru releases a VMware stencil for Microsoft Visio

Quoting from official announcement:


I have finally decided that since I do not have an immediate need for additional objects, I’ll go ahead and release my current Visio Stencil set that I have been working from…
While there are only six objects initially, I will be continuously adding more as I find the need for them. I will also watch for requests in the forums and attempt to meet specific requests that I can find useful.

Please head over to the downloads section and check them out. Your feedback is welcome.

A great job guys! Many thanks for this jewel.

Green Hills adds server virtualization software

Quoting from Socal Tech:


Santa Barbara-based Green Hills Software said this morning that it has introduced a new technology which allows integration of Linux and other operating system software easily into its secure operating system.

The new INTEGRITY PC product creates a “virtual computer” that runs on top of Green Hills INTEGRITY operating system, allowing companies to run operating systems such as Linux without requiring porting of those applications. The company reports that Boeing is using the technology in several of its military development programs. Green Hills said that the product, based on its Padded Cell technology, allows multiple virtual computers to run in user mode on top of their operating system. Each of those virtual computers are separate, and even if they crash cannot affect other parts of the operating system.

The software is similar to products in the desktop space from Microsoft and VMware, and reflects a general industry trend toward server virtualization. Green Hills’ products are focused on the embedded operating system market.

VMware opens up RSS feeds

VMware just published various RSS feeds on official website for news hungry customers:


– Articles
– Events
– News Releases
– Success Stories
– VMware Products

Anyway, if you are a virtualization.info reader you don’t need them 😉