BMF 5.7 Datasheet Web
BMF 5.7 Datasheet Web
BMF 5.7 Datasheet Web
Big Monitoring Fabric enables pervasive security and monitoring of network traffic for
an organization and selectively delivers it to multiple security, monitoring, performance
measurement and compliance tools—both Inline and Out-of-Band. Leveraging an Open
Ethernet switch fabric and an SDN controller, Big Monitoring Fabric is a highly scalable
and ultra-low cost (CapEx & OpEx) network visibility solution.
BIG SWITCH NETWORKS Big Monitoring Fabric (Big Mon / BMF) Overview
Big Monitoring Fabric is a modern 1G/10G/40G/100G network visibility fabric that leverages
Our mission is to deliver hyperscale-
high-performance, open Ethernet switches to provide pervasive security monitoring and
inspired, fit-for-purpose visibility of an organization’s network traffic at ultra-low CapEx/OpEx costs. Using an SDN-
networking/monitoring solutions centric architecture, Big Monitoring Fabric enables scale-out fabric for enterprise-wide
to datacenters - enabling monitoring, single pane of glass for operational simplicity, and multi-tenancy for multiple
IT teams (NetOps, DevOps, SecOps) to simultaneously perform network monitoring using
enterprises realize the benefits of
tenant-specific inline or out-of-band tools and policies.
simplified productivity, improved
scalability, and pervasive security Architecture: SDN Software Meets Open Switch Hardware
with a dramatically improved TCO. The Big Monitoring Fabric is a next-generation Network Packet Broker (NPB) that has
been designed from the ground-up to build a pervasive visibility fabric that addresses the
challenges of current NPB-based monitoring solutions. Big Mon’s architecture is inspired
by Hyperscale Networking designs, which consist of Open Ethernet switch hardware, SDN
Big Monitoring Fabric is the next-
controller software and centralized tool deployment.
generation network packet broker,
The Big Monitoring Fabric architecture consists of the following components:
which provides a visibility fabric
• Cluster of SDN-enabled Big Monitoring Fabric Controllers — an HA pair of virtual
for monitoring and security of out-
machines or hardware appliances—that enable centralized configuration, monitoring and
of-band/inline workloads in the troubleshooting in a simplified manner.
enterprise datacenter, DMZ • Big Switch’s SDN-enabled Switch Light OS is a lightweight OS, that runs on the switches
or extranet environments at cost- in the Big Mon fabric. The ONIE-deployable Switch Light OS leverages complete HW ASIC
effective price points. capabilities to support production-grade data center features.
• Open Ethernet Switches (White Box or Brite Box): These switches include Dell Open
Networking switches, as well as ODM switches from Accton and Quanta. The merchant
silicon networking ASICs used in these switches are the same as used by most incumbent
switch vendors and have been widely deployed in production in hyperscale datacenter
networks. These switches ship with Open Network Install Environment (ONIE) for
Get hands-on experience with our offering, automatic and vendor-agnostic installation of third-party network OS.
register for a free online trial at:
labs.bigswitch.com • Big Mon Service Node (optional)—an x86-based appliance that connects to the Big
Contact our sales team at: Mon fabric (either single or as part of a service node chain) to provide advanced packet
[email protected] functions like de-duplication, packet slicing, header-stripping and regex matching.
For general inquiries contact us at: Note: Beta support for the Netflow Generation function with the Big Mon Service Node will
[email protected] be available in Q3’16.
Datasheet
Big Monitoring Fabric
PAGE 2
DATASHEET
Big Monitoring Fabric supports topology agnostic, highly scalable • Monitor Every Location: Big Monitoring Fabric can be extended
fabrics. Depending on the customers’ requirements, a range of across L3 WAN to enable monitoring of remote DCs/POPs, colo
topologies is supported—from a single-switch fabric to a scale-out, facilities, campus/branch locations, as well as retail sites. This
multi-switch/multi-layer fabric. A typical multi-layer Big Monitoring allows centralization of monitoring tools and staff in few data
Fabric design has a layer of open Ethernet switches labeled as centers, thus dramatically reducing CapEx and OpEx cost while
“filter” switches and a layer of open Ethernet switches labeled allowing operations teams to monitor networks across the entire
as “delivery” switches. Most switch interfaces in the filter-switch organization. By simply deploying a commodity Ethernet switch
layer are wired to passive optical taps or switch/router/firewall at each monitored location, the entire Big Monitoring Fabric
SPAN ports in the production network and are configured as “filter (including remote location switches) is operated and managed
interfaces” in the Big Mon controller software user interface. Switch centrally via the BMF Controller with high availability.
interfaces in the delivery-switch layer are wired to tools and are
configured as “delivery interfaces”. Filter interfaces (where packets
come in to the fabric) and delivery interfaces (where packets go
out of the fabric to tools) represent the primary functions of the
PAGE 3
Datasheet
Big Monitoring Fabric
Figure 4: Big Monitoring Fabric Inline—In-band Security & Monitoring Tool Chaining in the DMZ
Big Mon Inline consists of a Big Mon Controller and open Ethernet • Supports dynamic, programmatic (REST API based)
switches deployed in High availability configuration. The inline configuration to drop certain marked flows (e.g. DDoS) or even
security tools directly connect (optionally via link aggregation) to bypass (whitelist) certain flows for a tool on the switch. In such
these Ethernet switches. Leveraging the Big Mon controller as the scenarios, the fabric switch drops the marked flows, rather than
central point of management, Big Mon Inline configures policies sending the flows to the tool to drop them.
that create paths through the inline tools. The solution supports • Simplify Multi-team operational workflows
load balancing across multiple instances of the same tool as well as
• Single Pane of Glass management/configuration; No complex,
chaining of a set of tools on a per-policy basis.
error-prone PBRs needed; Easily load-balance or chain tools.
• Replicate certain traffic (at line-rate) via a rule-based SPAN to
send to offline tools for further processing.
• The Big Mon Controller is the unified, single point of
management for inline / out-of-band monitoring.
PAGE 4
DATASHEET
FEATURE Benefits
Network-Wide Visibility • Packet Filtering, Aggregation, Tool Port Load-Balancing and Packet Replication functions.
(Monitor or Tap Every Rack) • Single switch or scale-out 1 / 2 / 3 layer Fabric designs: 1G, 10G, 40G & 100G.
• Centralized fabric / policy definition and instrumentation of open Ethernet switches
within the network.
• Programmatic Event-triggered monitoring (via REST API).
• Multiple Overlapping Match Rules per Filter Interface based on a variety of L2, L3, L4
header as well as via Deeper Packet Matching (DPM) attributes.
• Time / packet based scheduling of Policies.
• Ensures efficient utilization of open Ethernet switch capabilities via Controller Policy
Optimizer Engine.
Centralized Management, Big Monitoring Fabric Controller is single pane of glass for fabric and policy management.
Configuration, Troubleshooting • Policies can be configured from a centralized controller to forward flows from multiple
filter interfaces to multiple delivery interfaces, including optional service nodes. Packet
replication is made at the last common node to optimize the fabric bandwidth.
• GUI, REST API, and CLI for configuration and viewing operational state.
• Centralized interface, flow and congestion statistics collection.
• Centralized automatic upgrade of the monitoring fabric switches.
• Simplified install / upgrade of the fabric via the Big Mon Controller
Production Network Visibility, Big Monitoring Fabric further facilitates trouble-shooting and simplifies operations and
Telemetry and Analytics
management with the Production Network Visibility features:
• Host Tracker: shows detailed information about hosts in the production network.
• Subnet Tracker: shows IP subnets used in the production network.
• Tap Tracker: shows devices connected to TAP interfaces in the production network.
• DHCP Tracker: shows which subnets, served by DHCP servers are in the
production network.
• DNS Tracker: shows which DNS are being used to resolve domain names in the
production network.
• Sflow Generator & Collector: provides clear visibility on the activities in the production network.
PAGE 5
Datasheet
Big Monitoring Fabric
Advanced Filtering & Deeper • L2/L3/L4 header filtering on ingress and packet replication (as required) in the fabric
Packet Matching capabilities for multiple egress tools.
• Deeper Packet Matching (DPM) with masking (up to 128 bytes in packet). Supports
matching on inner header fields for encapsulated packets (e.g MPLS, VXLAN, GRE) and/
or protocols (e.g. GTP, SCTP).
• IPv4 and IPv6 based filtering.
• IPv4, IPv6, MAC Address masking, TCP Flags, DSCP matching.
• Support filtering on inner VLAN of a Q-in-Q packet
Packet Capture • Quick and easy 1G/10G interface available for packet capture on the controller
(With Controller Hardware Appliance only)
hardware appliance.
• Additional 1TB hard disk available
• Configurable auto deletion of older pcap files.
Marker Packet Generation • Injection of a “marker” packet into the tool or pcap file.
Specialized Packet Functions • Packet De-duplication—Enhances tool efficiency, by dropping duplicate packets.
• Packet Slicing—Improves security and tool throughput by stripping off the payload.
• Regex Pattern matching—Improves filtering of traffic based on regex patterns anywhere
within the packet.
• Header stripping for VXLAN, Cisco Fabric Path, ERSPAN and MPLS packets. Generic
user-defined header stripping function is also supported.
• Netflow Generation Function (Beta in Q3’16) will also be supported.
• L2GRE tunnel packet decapsulation.
• VLAN tag stripping—Useful for stripping RSPAN tag.
• VLAN tag push—Useful for filter interface tagging.
• Match on inner packet post stripping.
• Additional specialized packet functions (like packet obfuscation, and time-stamping)
can be realized by service chaining 3rd party NPBs as service nodes.
Fabric wide CRC check • Allow/Disallow bad CRC packets in the production network to reach the tools for analysis.
(Graphical User Interface)
Rich Web-based GUI • The Dashboard shows the resources used by the fabric as well as a bird’s eye-view of
the topology
• A highly attractive as well as functional GUI Topology view which shows:
- All the switches / ports in the fabric.
- Paths taken across the fabric on a per-policy basis.
- An intelligent Context sensitive Properties Panel triggered by a mouse-over on a
topology object.
• Customizable tabular views which are persisted as user preferences.
• Various table export options like JSON, CSV are available throughout the GUI.
• Presents a highly intuitive, simplified management and operations workflow.
PAGE 6
DATASHEET
Support for Ethernet-Based Support for 1G, 10G, 40G and 100G switches from Dell, Accton and Quanta. The common
Open Switch Vendors supported switch configurations are:
• 48x1G + 4x10G
• 48x10G + 4x40G (BRCM Trident/Trident+ ASIC)
• 48x10G + 6x40G (BRCM Trident-II ASIC)
• 32x40G (BRCM Trident-II ASIC)
• 64x40G (Beta in Q3’16) (BRCM Tomahawk ASIC)
• 32x100G (BRCM Tomahawk ASIC)
For the complete list of supported switch vendors/configurations as well as optics/cables,
included in the Big Monitoring Fabric Hardware Compatibility List (HCL), please contact the
Big Switch Sales Team ([email protected]).
Environment Version
Minimum VM Requirements
4 GB of virtual memory.
20 GB of Hard disk.
Note: A VM’s performance depends on many other factors in the hypervisor setup, and as such, we recommend using hardware appliance for production deployment.
PAGE 7
Datasheet
Big Monitoring Fabric
Processor Intel Xeon E5-2620 v3 2.40GHz, 15M Cache, 8GT/s QPI, Turbo, 6 Cores, 2 Sockets, 85W
Hard Drive 2 x 1TB 7.2K RPM SATA 6Gbps 3.5in Hot-plug Hard Drives; RAID 1 for H330/H730/H730P
Additional Features Fan fault tolerance; ECC memory, interactive LCD screen; ENERGY STAR® compliant
Environment Specification
Temperature–Storage -40°C to 65°C (-40°F to 149°F) with a maximum temperature gradation of 20°C per hour
Relative Humidity–Continuous 10% to 80% with 29°C (84.2°F) maximum dew point
Relative Humidity–Storage 5% to 95% at a maximum wet bulb temperature of 33°C (91°F), atmosphere must be
non-condensing at all times
PAGE 8
DATASHEET
Environment Version
Minimum VM Requirements
16 GB RAM
• 8 vCPUs
Processor Intel Xeon E5-2658 v3 2.20GHz, 30M Cache, 9.60GT/s QPI, Turbo, HT, 12 Cores,
1 Socket, 105W
Hard Drive 1 x 1TB 10K RPM SATA 6Gbps 2.5in Hot-plug Hard Drive
Additional Features Fan fault tolerance; ECC memory, LCD Access Control Panel; NEBS Level 3 and ETSI
certified, fresh-air cooling systems
PAGE 9
Datasheet
Big Monitoring Fabric
Environment Specification
Temperature–Storage -40°C to 65°C (-40°F to 149°F) with a maximum temperature gradient of 20°C per hour
Relative Humidity–Continuous 10% to 80% with 26°C (78.8°F) maximum dew point
Relative Humidity–Storage 5% to 95% at a maximum wet bulb temperature of 33°C (91°F), atmosphere must be
non-condensing at all times
Headquarters
3965 Freedom Circle, Suite +1.650.322.6510 TEL www.bigswitch.com
300, Santa Clara, CA 95054 +1.800.653.0565 TOLL FREE [email protected]
Copyright 2016 Big Switch Networks, Inc. All rights reserved. Big Switch Networks, Big Cloud Fabric, Big Monitoring Fabric,
Switch Light OS, and Switch Light VX are trademarks or registered trademarks of Big Switch Networks, Inc. All other
trademarks, service marks, registered marks or registered service marks are the property of their respective owners.
Big Switch Networks assumes no responsibility for any inaccuracies in this document. Big Switch Networks reserves the
right to change, modify, transfer or otherwise revise this publication without notice. Big Monitoring Fabric Datasheet v1
(June 2016)