Simplified Network

Building efficient, intelligent, and open 5G Cloud & Network

ZXUS vCube 9000 Introduction

With the development of new technologies such as virtualization, cloud computing, SDN/NFV, big data, IoT, etc., traditional data centers and networks have undergone great changes. Traditional security devices are difficult to apply on the cloud platform.  For example, traditional security devices do not have the features of automatic deployment and dynamic elasticity required for virtualization, and it is also difficult to meet the dynamic creation and on-demand allocation of multi-tenancy.

Based on the traditional security architecture, ZXUS vCube 9000 enables integrated security gateway abstraction and the pooling technology. Featuring elastic expanding and automatic on-demand deployment, ZXUS vCube 9000 can be extensively used to protect core networks, medium and large private clouds, VDC,etc. 

Major Function

  • High Performance/Low Latency

    • By using the SR-IOV technology to share one PCI device with multiple VMs, the vCube enhances the utilization rate of I/O devices and shortens the network latency. The SR-IOV can work on GE/10GE/40GE interfaces. 
    • The vCube employs the DPDK technology to enable more powerful system processing. Using multi-alignment hardware directly, the DPDK accesses the hardware resources via polling in user mode, which improves the network I/O throughput capability. Sorting hardware into different classifications effectively saves CPU resources. Using Hardware queues for processing messages can prevent obstacles caused by software distribution threads. 
    • The vCube uses different paths to separate control plane services (for example, protocol processing and dynamic generation of policy information) and user plane services (for instance data packet filtering, forwarding and processing), making data forwarding more efficient. 
  • High Reliability

    • Employs the enhanced VRRP protocol running on the HA path between the active and standby OMPs to ensure the firewall capable of working in the hot redundant mode.
    • To keep the system reliable and away from data blocking, the vFW implements data synchronization and backup via multiple HA paths.
  • Easy operation and maintenance

    • Automatic Deployment: The vCube can be deployed on a universal server automatically. When maintenance engineers finish making the vCube deployment blueprint, the entire deployment can be done rapidly, flexibly and automatically, which obviously makes the O&M much easier.
    • Elastic Scale-In/Out: To enable simplified deployment and management, as well as more efficient resource utilization, the vCube enables user-defined Scale-In/Out policies.
    • Easy to Integrate: The vCube can be easily integrated to different security protection scenarios. Related cloud management centers are responsible for the orchestration and management.
  • Rich Security Services

    • In addition to detect and control multiple sorts of protocol messages, the vCube can also provide rich precaution services, for instance, the ACL-based packet filtering, status inspection, ASPF, inter-zone policies, DDoS, DPI and carrier-grade security protection. 
    • Support a variety of VPN features, including IPsec VPN and SSL VPN.
Documentation

News