What are the high speed and feature-wise comparable open source solutions to a the compromised Juniper switches?
What are the high speed and feature-wise comparable open source solutions to a the compromised Juniper switches?
You might be able to get close in performance with your high-end Altera's and Xilinx's gear, but that certainly won't be cheap and AFAIK the FPGA synthesis tools are still closed source -- so you're not going to get an 'open source' from top-to-bottom solution at all 3 levels (Silicon, firmware, OS and packet switching). It's arguably more trust-worthy than buying Juniper/Cisco which has complete control of the stack, from silicon to software, but you'll be paying through the nose either way.
The standard Intel e1000's running OpenBSD and libpacket might be the best trade-off you're going to get in price/performance (again, if you make the concession that Intel isn't backdooring on: a) the firmware and/or drivers for the e1000s, or b) somewhere along the controller bus path -> PHY on the processor). This whitepaper [1] re: OmniPath + Xeon/PHI architecture boasts brilliant numbers (page 7 for an architecture summary, column 2 for the network switching summary, page 8 for the benchmark numbers). Again, not open-source at the hardware level, but the drivers, libraries and OS can all be audited. And at those rates of transmission, I'm guessing you could use physical probing along each component to see if any deep-packet tomfoolery is occurring, as the latency increase would be detectable, and you can't just add an extra login password at that level.
Tyan's OpenPOWER compliant stack will run on BSD and other than the processor (which uses an IBM POWER8) pretty much uses jellybean components-- so you get what I'm going to coin as "security through vendor diversity" from now.[2]
It comes down to how tightly your tin-foil hat has been sized I suppose. The upside is right now there's a huge open-source hardware revolution going on. OpenCores' Virtex based RISC stuff is available and that's top-to-bottom open source, and if you were really motivated and had the engineering know-how, ASIC runs can be done for under a million.
[1] https://ramcloud.atlassian.net/wiki/download/attachments/224...
Hmm, really? The highest end Netscreen (550, IIRC) only has 4 x 1 GbE interfaces. Linux or FreeBSD can't keep up?
Modern Juniper JUNOS products like the EX switch series contain 1GbE, 10GbE, and 40GbE wire ports and I think push the upper limits of standard linux / freebsd on plain x86.
Note that JUNOS is actualy based on freebsd (Juniper forked freebsd a while ago into JUNOS) - but they do it on custom asics.
Now that I'm thinking about it, though, Arista runs a Linux kernel on their switches. Or they did anyways, the last time I was out there being briefed; it was a Fedora Core 3 install (yes, it's been a few years), if memory serves, so it must be possible anyways. No idea if they're still doing that but, at the very least, they were at some point.
nortel networks. no bugs in the last few years.
No known bugs.
One week ago we could say this of Juniper as well.
(yes, those aren't the device that was found to be compromised, but the grandparent post suggested we "stop using Juniper's products altogether")