Cavium Networks Debuts NITROX DPI Family of Layer 7 Content Processors With Market Leading Performance

NITROX DPI CN17xx Family Uses Cavium's Innovative 3rd Generation Deep Packet Inspection Technology; Delivers 4 to 20 Gbps performance independent of pattern rule-set size, with support for very large number of patterns for future-proofing designs

July 20, 2009

5 Min Read
NetworkComputing logo in a gray background | NetworkComputing

Cavium Networks (NASDAQ: CAVM), a leading provider of highly integrated semiconductor products that enable intelligent processing for networking, storage, wireless and video applications, today announced the NITROX DPI CN17XX Layer 7 Content Processor Family. The NITROX DPI CN17XX processors offer 4 Gbps to 20 Gbps of deterministic performance with low latency and support for an unlimited number of pattern rule-sets and flows. The NITROX DPI processors target a wide range of applications including application level firewalls, intrusion prevention (IPS), gateway anti-virus, unified threat management and content-based QoS in routers, switches, appliances and services blades for the Enterprise, Datacenter and Service Provider markets. This scalable product family is offered to customers as silicon products as well as production-ready boards with extensive software support.

Two trends in the networking marketplace are driving the need for L7 content and deep packet inspection. Network security requirements have now evolved to include IPS, Anti-Virus, Malware, Spam and DoS in addition to the traditional VPN, Firewall and IDS functionality. Additionally, with the rapid integration of voice, video and data traffic on the network, content-based QoS is critical. Networking equipment built to address these evolving content processing needs must address several challenges in order to meet increasing line rate performance. The performance has to be deterministic with low latency to support increasing multi-media and real-time traffic. Additionally, performance has to be independent of the number of pattern rule-sets and flows as the number of content inspection signatures and traffic flows is increasing rapidly. Finally, solution scalability and flexibility is required to address several price/performance points and different system architectures.

Solutions available in the marketplace today often fall short in addressing these requirements. Some solutions limit the number of flows while others deliver acceptable performance only for a limited pattern rule-set which fits in on-chip memory. The NITROX DPI CN17XX processor family, based on 3rd generation Deep Packet Inspection technology from Cavium, delivers deterministic, low-latency, and leading performance without compromising the number of pattern rules or flows, enabling scalable 4 Gbps to 20 Gbps performance in a software-compatible manner.

Cavium's first and second generation Deep Packet Inspection technology is integrated into the OCTEON and OCTEON Plus multi-core family of products and is already shipping in Tier 1 customer systems today. Cavium's third generation DPI technology delivers several significant enhancements to reduce latency and increase performance. The high performance and scalability offered by these devices is enabled by the on-chip revolutionary Hyper Finite Automata (HFA) engines.

The NITROX DPI CN17XX processor and board family offers look-aside L7 content processing with PCI-Express connectivity. These processors offer up to 20 Gbps of performance and can be used in conjunction with the OCTEON family and other general purpose processors such as the x86 to increase DPI performance. The same engines are also integrated on Cavium's OCTEON II processor family, enabling seamless software migration from CN17XX family to OCTEON II. For future designs that need even higher performance, the CN17xx family can be used in conjunction with Cavium's high end OCTEON II processor family to deliver up to 40 Gbps performance.
The ability to use the HFA technology as a coprocessor as well as integrated in a CPU, with performance ranging from 4 Gbps - 40 Gbps provides customers with the most flexible, scalable and highest performing L7 content processing solution in the marketplace. The NITROX DPI CN17XX family includes four different products."Over the past few years, Cavium's outstanding execution has enabled it to achieve the #1 position in the security processor market share and achieve the highest growth rate in the embedded processor category," said Bob Wheeler, senior analyst at The Linley Group. "The NITROX DPI family expands the Cavium NITROX product line into layer 7 security with sophisticated new DPI technology that eliminates the tradeoff between performance and pattern rule-set size found in other solutions."

The NITROX DPI CN17XX Software Development Environment
The CN17XX processor is supported by comprehensive software that includes:

  • NITROX DPI CN17XX Software Development Kit

  • Linux drivers for OCTEON Plus, x86 and other general purpose processors

  • Simple Executive drivers for OCTEON Plus

  • Regular Expression Compiler on Linux for OCTEON Plus and x86 processors

  • Perl-Compatible Regular Expression (PCRE), POSIX Regex Syntax &

  • String Signatures with support for fast incremental compilation and hot update capability

  • Optimized C libraries/API for regular expression processing offload

  • Functional simulator and profiling tools

  • Complete production quality development toolkits support for SNORT XL

  • Comprehensive support for RegEx Applications including commercially available AV, IPS signatures

  • Support for highly complex RegEx patterns from a number of leading networking OEMs with market leading results


"Our new NITROX DPI product line with HFA technology has solved key fundamental issues which previously prevented mass deployment of deep packet inspection across a range of networking applications," said Rajiv Khemani, VP and GM, Networking and Communications at Cavium Networks. "We developed this product line in close partnership with several major OEMs, who have been extremely pleased with its features and performance."

Pricing and Availability
The NITROX DPI CN17XX processors are available in scalable options ranging from 4 Gbps to 20 Gbps. Each processor also has a corresponding board product. The product line is sampling now. Pricing is available on request.
About Cavium Networks
Cavium Networks is a leading provider of highly integrated semiconductor products that enable intelligent processing in networking, communications, storage and security applications. Cavium Networks offers a broad portfolio of integrated, software-compatible processors ranging in performance from 10 Mbps to 20 Gbps that enable secure, intelligent functionality in enterprise, data-center, broadband/consumer and access and service provider equipment. Cavium Networks processors are supported by ecosystem partners that provide operating systems, tool support, reference designs and other services. Cavium Networks principal offices are in Mountain View, CA with design team locations in California, Massachusetts and India. For more information, please visit: http://www.caviumnetworks.com.

SUBSCRIBE TO OUR NEWSLETTER
Stay informed! Sign up to get expert advice and insight delivered direct to your inbox

You May Also Like


More Insights