Infoblox Whitepaper Nios - 1
Infoblox Whitepaper Nios - 1
WHITEPAPER
Overview
• An explosion in the number and diversity of network users, devices, and policies;
• An increasing number of network attacks specifically targeting the network services
infrastructure, such as DNS cache poisoning;
• The deployment of real-time IP applications, such as voice over IP (VoIP), which
cannot tolerate delays in data updates;
• New regulations, such as Sarbanes-Oxley, which require more integrated
core network services to enable the creation of audit trails and more
sophisticated reporting;
Infoblox solutions provide the essential platform for delivering reliable, scalable, and
secure core network services including DNS, DNSSEC, DHCP, and IPAM.
Infoblox NIOS software is the security-hardened system software that comes bundled
with all Infoblox core network services appliances. It provides all core services and also
provides an integrating framework for all other components of the modular Infoblox
solution. Specifically, the Infoblox NIOS platform architecture delivers service and
application modules (such as DNS and DHCP); provides a Grid module which allows
distributed enterprises to link collections of appliances into unified Infoblox grids;
offers an API for the extension of capabilities; and contains core technologies that make
Infoblox solutions possible.
1
Infoblox NIOS™ Software
Integration
TFTP/HTTP
Syslog NG
Infoblox software packages run on
VitalQIP
DHCP
Proxy
Infoblox network services appliances.
IPAM
DNS
Grid
NTP
NS1 -- --
NS1 with Grid
Infoblox NIOS core technologies form the foundation of every Infoblox network services
appliance. Infoblox NIOS software contains a security-hardened operating system that
exposes no extraneous open ports, no general user log-in, no unneeded OS services,
and no root access. This makes the OS very difficult to penetrate by hackers, particularly
compared with general-purpose operating systems containing known, exploitable
vulnerabilities. In addition, the software modules (such as DNS and DHCP) are kept
up-to-date and, therefore, free of vulnerabilities. The easy, one-button software upgrades
supported by the Infoblox NIOS platform encourage administrators to apply software
updates and keep Infoblox customers immune to attacks.
Figure 1: bloxHA™ and bloxSYNC™ technologies deliver device and data failover.
The active device in an HA pair sends periodic VRRP advertisements via the HA port to the
standby, which listens for them but remains in a passive state unless it fails to receive an
advertisement for a period of three seconds. Once that three-second threshold has been
reached with no VRRP advertisement received, the standby takes over.
The bloxSYNC engine ensures that the database of host names, IP addresses, zones,
leases, etc. are also continually synchronized between the active device and the standby.
As a result, when the backup unit assumes operation it does so with no loss of data or
network state.
bloxSDB technology allows the key components required for collaboration to be shared
while resolving any conflicts that exists between disparate views. Its unique semantic
architecture allows performance-driven data layouts to coexist with rich management
abstractions without compromising data integrity and transactional consistency. As a
result, protocol engines requiring high-performance data access (such as DNS, DHCP, and
DNSSEC) and the management tools requiring rich data abstraction (such as IP address
management) can, for the first time, use a common database technology. Doing so
enables enterprises to meet the challenging mix of requirements for data performance,
usability, distribution, and integrity required for modern networks.
3
Infoblox NIOS™ Software
The revolutionary Grid module is an optional software component that can be enabled
in an Infoblox network services appliance to allow the appliance to join an Infoblox
Grid, which unifies distributed appliances into a single, consolidated system. This lets
companies distribute services while retaining centralized management, ensuring the
accuracy and integrity of data, and delivering nonstop services.
The bloxSDB databases in an Infoblox Grid are networked together, enabling system-
wide synchronization of all data objects, including IP addresses, host names, devices
addresses, firmware images, etc. Changes to the data that occur on any appliance are
reflected across the Grid, securely, in real time and with full transactional integrity. This
prevents data loss, eliminates possible inconsistencies and errors, and ensures that
usage reports, address assignments, and network access decisions are based on accurate
data. Because they do not require a separate, external database for device configurations
and reporting data, Infoblox Grids provide inherent reliability advantages, data integrity,
faster and easier disaster recovery, and are easier to manage compared with legacy or
second-generation appliance approaches.
Figure 3: The grid module links distributed appliances into Infoblox grids.
Summary
Infoblox NIOS software, including its modules and core technologies, are the foundation
of Infoblox appliance-based solutions and enable the first core network services solution
to combine the power of nonstop appliance-based local service delivery with the benefits
of consolidated management and control via its patented Infoblox grid architecture.
The Infoblox NIOS platform also includes a powerful object-oriented API that eases data
migration from legacy environments and enables customers to provide custom front-ends
and interfaces to legacy applications.
The optional Grid module extends Infoblox solution capabilities enterprise-wide, across
geographically distributed appliances into consolidated Grids. A cohesively managed and
synchronized set of core network services is quickly becoming a fundamental criterion for large
and growing distributed enterprises as IP networks grow larger and more dynamic in nature.
5
For More Information:
+1.408.625.4200
+1.866.463.6256
(toll-free, U.S. and Canada)
[email protected]
www.infoblox.com