Science DMZ: Network Components

When choosing the network components for a Science DMZ, you should consider the following issues:

  • Make sure your routers and switches have enough buffer space to handle "fan-in" issues, and are configured to use this buffer space.  See also this paper that describes the impact. 
  • Check to see if the hardware is supported by OSCARS virtual circuit system, to allow the ability to easily extend layer-2 circuits all the way to the DTN hosts.
  • Look for devices that have flexible ACL (Access Control List) support to eliminate the need for stateful firewalls that will slow down the DTN hosts.
  • Consider deploying devices that will support OpenFlow, as Software Defined Networking via OpenFlow is a promising new technology for Science DMZs in the future.