|
|
|
|
|
|
NS1®
Package
ESSENTIAL CORE NETWORK SERVICES FOR
NETWORKS AND APPLICATIONS
High-availability Services The NS1 package runs on the reliable Infoblox appliance platforms, which are designed for nonstop operation in high-performance networks. High-availability (HA) services are supported by bloxHA™ technology—which uses industry-standard Virtual Router Redundancy Protocol (VRRP) for sub 5-second network failover—and bloxSYNC™ technology to ensure real-time database synchronization with no loss or duplication of data. Together, these two technologies allow critical name server and DHCP services to always remain responsive and up-to-date and eliminate common but challenging problems such as issuing duplicate IP addresses Integrated, Zero-admin Database The NS1 package stores all DNS and DHCP data in the integrated bloxSDB™ database, which is built into the Infoblox NIOS™ operating system software provided on all Infoblox appliances. The bloxSDB database is designed specifically to support integrated core network services and provides unmatched consistency between service and management views of IP-address-centric network services data without compromising performance.. Integrated Web GUI The Infoblox Web GUI allows administrators to deploy and manage the entire DNS/DNSSEC, DHCP and IPAM infrastructure with just a few mouse clicks. The powerful, Web-based Infoblox GUI is the only solution that manages all aspects of the infrastructure and data – including software updates and upgrades, backup and restore, disaster recovery and all services and data management – without resorting to client based or command-line interfaces. The Infoblox Web UI manages all aspects of the product including DNS/DNSSEC, DHCP, IPAM and Grid management, monitoring and reporting. Wizards and visual tools are available to make configuration and monitoring error-free. Integrated Management The NS1 package provides practical operational efficiencies that lower total cost of ownership. For example, creating a DHCP range automatically creates an associated DNS record, reducing the number of tasks required of network administrators.
Granular, Role-Based Administration
Enhanced Security The Infoblox NIOS software is hardened and consistently withstands security scans and attacks within the most demanding government and military organizations. The DNS/DNSSEC and DHCP services provided by the NS1 package can be upgraded easily to support the latest versions of BIND and DHCP, ensuring minimum exposure to security threats. In the event that a new exploit is discovered, the underlying Infoblox NIOS software can be upgraded in minutes via a single, simple operation. This makes it much more difficult to penetrate than general-purpose operating systems with known vulnerabilities. Management communication is secured using Secure Sockets Layer (SSL)-encrypted VPNs for protection against management compromise. DNS Attack Detection and Mitigation Infoblox provides the ability to detect, alert and mitigate any attacks against members that are configured as recursive DNS servers. The NIOS software will monitor two key parameters that are indicators of an attack: mis-matched DNS message IDs and mis-matched UDP ports on DNS responses. This happens when an attacker is guessing on those parameters to “spoof” a response with the poisoned data. The administrator can set a threshold for both parameters and when either is exceeded the system will send an email alert and/or SNMP trap (whichever is configured for the system). This feature will give administrators an early warning that one of their servers is under attack. In addition, Infoblox NIOS allows attack mitigation by implementing query rate-limiting. The administrator can implement a filter on a specific IP or network to limit or stop all traffic. This will slow down or stop the attack, the success of which is based on the attacker’s ability to try as many response “guesses” as possible before the legitimate DNS server can respond. Push Button DNSSEC Implementation and Management DNSSEC management is completely automated. Zones are signed with a single command and are re-signed automatically when records are updated. Keys are generated and distributed automatically. Infoblox provides the only DNSSEC solution with fully automated key management and key rollover.
The flexible Infoblox Device Manager user interface provides the visibility and control needed to manage all core network services in dynamic IP networks. The Device Manager simplifies the management of the appliance, services, and data—and provides summary and drill-down views with a simple click. Granular, role-based management capabilities enable administrators to delegate specific networks, ranges, hosts, and devices to junior or departmental personnel. The Infoblox Device Manager makes it easy to cope with fast-changing networks, and because all data reside in the Infoblox appliance database, the status of devices and services shown in the Device Manager always reflects the actual, real-time state of the network.
Infoblox network services appliances include a range of special capabilities that serve key network applications: Voice over IP Users demand dial-tone reliability for voice communications. To deliver this level of reliability in an IP environment requires a nonstop DHCP service for assigning IP addresses to voice-over-IP handsets and IP soft phones, as well as file delivery services for providing updated phone firmware and configurations. The NS1 package delivers a combination of features that provides an easy-to-manage, high-availability solution for IP voice applications: High-availability DHCP. Infoblox supports industry-standard DHCP failover that works across distributed WANs. In addition, pairs of Infoblox appliances can be easily configured in “HA mode” to provide fast failover and real-time data synchronization without requiring inefficient allocation of IP addresses. Built-in TFTP, FTP and HTTP file transfer. Historically, TFTP, FTP and HTTP has been provided by stand-alone servers managed individually at each location with no centralized control and no high-availability capabilities. The NS1 package extends the benefits of network services appliances to managing IP telephony by providing a reliable, easy-to-manage TFTP, FTP and HTTP service. Firmware and configuration files are uploaded to the appliance and served to IP phones when they boot up. Added reliability, expected in a telephony environment, can be provided using an HA pair of appliances to provide reliable TFTP services. > More Reliable DNS Infrastructure for Microsoft Active Directory (AD)
> More |
|
© 2010 Infoblox Inc. All rights reserved. All registered
trademarks are property of their respective owners. Privacy policy. Site Map.
|