May 1998
By Erica Roberts
Load Balancing
Load Balancing: On a Different Track
Switches and firewalls with load balancing built in keep the Web requests running on time
|
|
|
Balancing requests among Web servers used to take dedication. Not
just the scrupulous attention to detail net managers always exhibit
anywaybut load-balancing software or st
andalone boxes devoted to
the task of keeping the traffic moving. Now some vendors of network
devices say it's time for a different approach: Let linchpins like
switches and firewalls balance the load instead. The advantages seem
hard to ignore. For one thing, it saves money, since net managers
already have to buy vital gear like firewalls and switches anyway. For
another, it can make for better scalability and performance: Balancing
is performed in speedy hardware instead of sluggish software, and with
functions combined the number of network devices through which traffic
passes is reduced. "The switch shunts traffic straight onto a
connection with a server, as opposed to sending it through a host with
load-balancing software," says Jeffrey Burgan, manager of the backbone
engineering group at @Home Network (Redwood City, Calif.), an Internet
access provider.
But getting those benefits means picking the right device. And as
if choosing the swiftest switch or strongest firewall already weren't
hard e
nough, net managers now have to ask questions about load
balancing too. Which makes the first step obvious: Find out how
products identify and forward traffic. Some perform basic round-robin
forwarding across multiple servers (fine when servers are colocated
and contain identical information); others use Layer 3 routing (which
allows requests to be sent to geographically distributed servers); and
others boast sophisticated application-aware forwarding (with which
requests are sent to servers according to the content required). The
second step: Don't assume that any of these new mixed-breed boxes
really scale to match the needs of a large group of Web servers, so be
blunt in asking about simultaneous TCP connections and data
throughput. After that, get straight on which devices boast QOS
(quality of service) for divvying up data among server processors.
Then it's on to familiar issues like management; the tip here is to
look for RMON (remote monitoring), since it helps with troubleshooting
and traffic analysis
in the server net. Redundancy and reliability
also are critical, given the vital roles these devices play. Finally,
find out about pricingand whether the product actually is
shipping with everything the vendor is pushing.
There is good news for net managers looking for a cheaper way to
balance the load. If adding the feature to network devices seems like
an idea that's long overdue, vendors apparently have plans to make up
for lost time. "Load balancing could become a standard feature of
Ethernet switches in a couple of years," Burgan says.
Gang of Six
|
 BUILD YOUR OWN CUSTOM TABLE
Table 1: Selected Vendors of Products With Build-in Load Balancing
|
In fact, of the six vendors now staking out ground in this new
territory, s
witch makers represent the majority. Alteon Networks Inc.
(San Jose, Calif.), Arrowpoint Communications Inc. (Westford, Mass.),
Foundry Networks Inc. (Sunnyvale, Calif.), and Holontech Corp. (San
Jose) all are building load balancing into their LAN switches. Check
Point Software Technologies Inc. (Redwood City, Calif.), meanwhile,
sells an optional software module that lets its Firewall-1 firewall
distribute loads across servers. Finally, there's Allot Communications
Inc. (Los Gatos, Calif.), which has built load balancing into its
AC200 and AC300 traffic tuner products (see
Table 1
).
How do these devices take on the task? All but one perform NAT
(network address translation), so that a single virtual IP address can
be used by the switch, firewall, or traffic tuner to represent
multiple servers. The exception is Holontech's Hyperflow SP800, which
relies on clustering technology from the operating system vendors to
allow a server farm to share a v
irtual IP address.
Is any one approach better than another for load balancing? Going
with a switch makes a certain amount of sense: After all, most net
managers already use a LAN switch to connect serversand making
it responsible for session allocation doesn't add much in terms of
price. At the same time, according to vendors, incorporating load
balancing onto multiple ports increases the rate at which those
sessions can be doled out.
Switch Hits
Nothing wrong with fast and cheapbut net managers also need
to look at flexibility and scalability. In other words, if going with
a switch, choose one that will grow with the network.
All the load-balancing switches are based on Ethernet, but port
densities vary greatly. For instance, Alteon's Aceswitch 110 and
Acedirector, along with Holontech's Hyperflow SP800, come with 8
10/100-Mbit/s ports. But then there are the chassis-based offerings,
like Arrowpoint's WS-800 (64 10/ 100-Mbit/s ports) and Foundry's 4000
and 8000 B
igiron switches (72 and 152 10/100-Mbit/s ports).
As for the types of ports, only Alteon (with its Aceswitch 110 and
180) and Foundry (with its entire line of switches) support gigabit
Ethernet. Alteon's Aceswitch 180 also is the only box with dual-speed
100/1,000-Mbit/s ports. But it's important to note they're not
autosensing: Instead, there are two physical connectors for each port,
so net managers have to choose whether to set up a 100-Mbit/s link or
a 1-Gbit/s link to the server.
Arrowpoint's switches are notable for something else: They're the
only ones that offer WAN connections. The WS-100 has four serial V.35
interfaces, while the WS-800 boasts up to 32 T1/E1
(1.544/2.048-Mbit/s) interfaces and, as an option, up to 16 HSSI
(high-speed serial interface) ports. What's the purpose of WAN ports?
Arrowpoint says it means the switch can handle distributed
load-balancing services for Web servers over wide-area connections,
without having to hand off traffic to an intermediate device like a
r
outer.
The vendor also plans to offer full IP routing with support for RIP
(routing information protocol) I and II, OSPF (open shortest path
first), and BGP (border gateway protocol) version 4 in the fourth
quarter, at which point it believes the WS-100 and WS-800 could become
a valid router replacement on the WAN.
At the Wall
With the Connect Control module for its Firewall-1, Check Point is
the only firewall vendor plying the load-balancing trade. The module
can be loaded onto server hardware running HP-UX, IBM AIX, Solaris,
SunOS, and Windows NTwhich makes for flexibility: Depending on
the network adapter, Connect Control can be used to front end an
Ethernet network, a token ring network, or an FDDI network.
Still, net managers should note that performance depends heavily on
how much they're willing to invest in hardware configuration of the
host platform. And even with the fastest hardware, the Firewall-1
Connect Control product will still act as a bottleneck when
tied into
the fastest networks. For instance, the device could not pump through
1 Gbit/s worth of Ethernet packets. Check Point itself says the
maximum the box can handle is 89.75 Mbit/sbut argues that this
isn't really a limitation because it's still far faster than the speed
of most companies' wide-area Internet links. "It's not the firewall
that's the bottleneck [for load balancing]; it's usually the wide-area
connection," says Greg Smith, product marketing manager with Check
Point.
Allot is the only vendor of traffic-shaping devices offering load
balancing, and it also uses a separate module for the task. The
vendor's AC200 (two 10/100-Mbit/s ports) and AC300 (3 10/100-Mbit/s
ports) sit behind the wide-area router at the edge of the net and
prioritize packets or carve out bandwidth for incoming and outgoing
traffic. But with the software module added on, the devices can
perform a similar type of traffic management for accessing and
retrieving data from a cluster of Web servers or a server f
arm.
But while the AC200 and AC300 furnish both IP routing and bridging,
they're not intended as replacements for a switch front-ending a
server farm or a router managing the WAN connection at the LAN's edge.
Nor do they perform firewall functions. In other words, net managers
will still have to buy both a switch and firewall.
Regardless, Allot cites some of the same benefits as other vendors
that are adding load balancing to their productslike simplified
management. "We're finding that net managers are looking for the
integration of traffic shaping and load balancing because they don't
need or want to configure two separate polices for two devices," says
Rich Waterman, director of architecture.
Balanced Lineup
|
 Figure 1: Altogether Now
|
Those are the product basic
sbut what about the load-balancing
specifics? Start by looking at the balancing schemes: All the products
use proprietary, vendor-developed algorithms to distribute incoming
requests across a pool or farm of servers. And all of these algorithms
use Layer 2 information to distribute traffic in a round-robin
fashion: Each new request is forwarded to each server in sequence,
with each server receiving the same number of requests.
The Allot, Check Point, Foundry, and Holontech products also can
distribute traffic using a weighted round-robin approach. In other
words, each server is given a specific priority, or weight, based on
its ability to process requests. Trouble is, net managers who choose
switches will (for now, at least) have to configure the weighting
manually. Those who go with the Check Point firewall might have an
easier time: Agent software on the Web servers sends loading
information to the Connect Control module, which then uses it to
direct requests to the server with the lightest l
oading.
Holontech says it's working on a similar approach: Agents will
collect information on CPU loading, disk loading, and memory
utilization from Microsoft NT and Unix servers. Currently, its SP800
switch tracks the server with the least number of IP connections and
distributes data across the cluster of servers based on IP source
address.
Other vendors also offer other load-balancing options. For example,
Check Point uses ping commands to measure round-trip delays so that
the server with the fastest response time gets the most connections.
The firewall also can direct requests randomly if all servers are
equally busy. Foundry uses an additional algorithm for distributing
traffic across a pool of servers based on the least number of open
connections on each. The vendor says the scheme works whether servers
are handling an equal load or capacity differs greatly.
Smart Plays
|
 MORE INFO
Balanced Viewpoints
|
All of the products can balance loads among colocated Web servers
in the same server farm. But vendors offer more than basic balancing;
they're also using routing (Layer 3) and application layer (Layer 4)
forwarding to add sophistication to their schemes. Simply put, the
more routing intelligence and application awareness, the more options
network managers have when deciding which traffic should be
forwardedand where. For instance, devices with Layer 3 smarts
can balance loads among local and remote servers that reside in
different subnets or in different geographic locations.
What's more, the Arrowpoint and Foundry switches and the Allot
traffic shaper all offer full IP routing. And all the Foundry boxes
(except the Layer 2 Fastiron backbone switch) also boast
hardware-based IPX routing; the vendor's Bigiron platform also routes
Appletalk.
Meanwhile, devices that have application-layer capabilities free
net managers from having to mirror identical versions of the same data
on different servers. That's because they're smart enough to forward
data based on contentand that's a big deal. Mirroring data might
not be hard in small Web sites, but ensuring identical content across
a server farm that's distributed across multiple domains in different
locations can be next to impossible.
Products from Allot, Arrowpoint, and Check Point all can identify
traffic based on URL information and Web content. Switches from
Arrowpoint and Foundry, and the tuner from Allot, perform
application-level filtering based on known TCP and UDP port numbers
(which are used by specific applications). Alteon's switches also can
filter and forward traffic based on Layer 4 TCP and UDP port numbers.
Some products also can maintain so-called sticky connections for
HTTP (hypertext transfer protocol) sessions. This ensures that
multiple
requests that are issued as part of the same app are directed
to the same server. Belonging to this category are devices from
Arrowpoint, Check Point, and Foundry.
Such capabilities hold huge promise for distributed Web server
farms. And some users already find the idea of switching based on
application or content appealing. "Having something in the net that's
content-aware is more intelligent [than basic load balancing]," says
@Home's Burgan.
Holontech, which doesn't offer session-level support for load
balancing, takes issue with the idea of using TCP/ UDP session-layer
information. The vendor claims that maintaining information on every
session can chew up resources on the switch and limit performance.
And net managers should remember that switches with the ability to
read information at Layer 3 (or higher) come with a familiar downside:
They're harder to configure and manage than Layer 2
switchesexactly why Holontech contends that Layer 2 suffices.
"Load balancers should be v
ery transparent and easy to install for the
end-user," says Sri Chaganty, vice president of engineering.
Top of the Order
In addition to various load-balancing schemes, some vendors also
are pitching QOS (quality-of-service) features which, they say, can be
used to give users or applications priority access into a Web server
(see "Policy-Based Networking: The New Class System," October 1997;
http://www.data.com/roundups/class_system.html
). Arrowpoint, for
instance, includes prioritization for specific URLs. It uses an
ATM-based switching fabric to classify traffic into distinct queues
and IEEE 802.1p prioritization and IP precedence bits to identify
traffic that needs to be prioritized. Foundry prioritizes according to
MAC (media access control) address, IP source or destination address,
UDP/TCP port number, or virtual LAN. It uses priority queuing, 802.1p,
and the IETF's RSVP (resource reservation protocol).
Check Point and Allot both have
dedicated modules for QOS. Check
Point's Floodgate-1 runs on the same platform as its firewall and
Connect Control module, and it bases prioritization on MAC addresses,
IP source or destination address, protocol, TCP/ UDP port number, or
URL. Allot offers similar capabilities with its AC200 and AC300
platforms, including the ability to assign priority based on time of
day.
At the moment, both Alteon and Holontech say they're looking to QOS
capabilities.
Pressure's On?
Of course, when it comes to adding load balancing to a critical
network device, the big question is performance. Just how much of a
bite does the added task take? Net managers can use two metrics to
assess performance: the number of concurrent TCP sessions a platform
can handle, and the volume of data it can pump.
As might be expected, the numbers vary greatly. Allot claims that
its AC200 can support 1,000 concurrent sessions scaling to T1 (1.544
Mbit/s), and its AC300, 5,000 concurrent sessions scaling to T3 (4
5
Mbit/s). Check Point says its product has been tested and shown to
handle up to 23,000 concurrent TCP connections, at speeds of about 90
Mbit/s. Foundry makes the boldest claims: up to 1 million concurrent
sessions at 500 Mbit/s to 1 Gbit/s.
Holontech is the only vendor that does not measure its performance
in terms of TCP sessions. But it says that its switching platform can
handle close to 620 packets per second and boasts throughput of nearly
800 Mbit/s.
Count On It
As far as reliability is concerned, all six vendors say have they
have this base covered. It's just that they tend to define "covered"
differently.
Take Check Point, whose firewalls can be synchronized for
redundancy between products. Or Allot, which relies on routing and
spanning tree (if only bridging) to set up an alternate path through a
second device when a link fails. It's also worth noting that both
Allot's AC200 and AC300 can continue to pass packets in the event that
the load-balancing and traffic m
anagement software on the device
fails.
Meanwhile, all the switches can reroute sessions from a failed link
using spanning tree, and those forwarding packets at Layer 3 also can
reroute using RIP or OSPF. In addition to these basic services,
Alteon, Arrowpoint, and Foundry also offer Layer 2 trunking services,
whereby multiple switch ports can be configured and connected to a
single server for greater redundancy. If one connection fails, the
server is still able to send traffic to the switch.
Alteon's Aceswitch 180 also has built-in reliability, thanks to its
dual-speed 100-Mbit/s and 1-Gbit/s Ethernet interfaces. With two
physical interfaces per switch port, net managers can physically
connect each to a second Aceswitch 180 for redundancy. If both links
are operational, the Aceswitch 180 selects the 1-Gbit/s interface and
fails over to the 100-Mbit/s interface.
Still, Arrowpoint and Foundry probably offer some of the most
sophisticated redundancy features. Arrowpoint's WS800, for exam
ple,
has a fully redundant 10-Gbit/s switching fabric as well as redundant
power supplies, fans, and system control module. Foundry offers
something it calls Hot Standby Redundancywhich the vendor says
allows two identically configured switches to serve as primary and
standby units. The primary switch takes care of the load balancing
while the standby switch monitors the Layer 2 and 4 session
information. In the event the primary switch fails, the backup
automatically takes over and no sessions are lost, according to the
vendor. Holontech's Hyperflow SP800 also is fitted with redundant
power supplies and fans.
Management Skills
Management is always a concern when it comes to core networking
devicesand the vendors make sure to address it. Alteon,
Arrowpoint, Foundry, and Holontech all furnish a choice of Web-based,
SNMP, or command-line interface management. Allot, meanwhile, offers
Web and SNMP management, while Check Point uses a standalone app that
runs under Microsoft's Window
s NT and a broad range of Unix
platforms.
Corporate networkers who are focusing on the switch platforms may
also want to check into RMON capabilities. Alteon, Arrowpoint, and
Foundry products all handle the first four groups of RMON (alarms,
events, history, and statistics) along with port mirroring.
|
 CONTACT AUTHOR
eroberts@data.com
|
Finally, when trying to get a fix on price, find out whether load
balancing is a core featureor it will cost extra. For example,
net managers considering Check Point's Firewall-1 and Connect Control
module also need to factor in the price of the server hard-ware.
Similarly, Allot, Alteon, and Foundry charge extra for load balancing,
though the add-ons still cost less than buying a separate
load-balancing device. The exceptions are the Arr
owpoint switch,
Holontech's box, and Foundry's Bigiron switcheswhich include all
the switching and load-balancing services on the main platform. The
most expensive device is Arrowpoint's fully loaded WS-800; it costs
$60,000 with 64 10/100-Mbit/s Ethernet ports.
Erica Roberts is internetworking editor for Data Communications, based in San Mateo, Calif. She can be reached via e-mail at
eroberts@data.com
.
|
|
|
 |
 |
|