Ngenius 5000 Series Packet Flow Switches
Ngenius 5000 Series Packet Flow Switches
Ngenius 5000 Series Packet Flow Switches
Product Description
HIGHLIGHTS The nGenius® 5000 Series Packet Flow Switches (PFS) are dense, 1G to 100G models designed
for dense 1GbE to 100GbE deployments and bridge the gaps between 1GbE, 10GbE, 25GbE,
• 1-, 2-, or 4RU (Rackmount Unit) space- 40GbE, and 100GbE networks and tools.
efficient, fixed configuration devices
• 720 Gbps to 12800 Gbps throughput with The nGenius 5000-series Packet Flow Switches offer SFP+, SFP28, QSFP+, and QSFP28 ports
non-blocking switching fabrics in various 1RU, and 2RU, and 4RU fixed configuration form factors. All ports are enabled by
• 1GbE, 10GbE, 25GbE, 40GbE, and default1, with each port configurable as an input port, intermediate (service) port, or output port.
100GbE port options With the NETSCOUT pfsMesh, a self-organizing architecture, the nGenius 5000-Series Packet
• Network packet broker functionality Flow Switch can be deployed in a redundant, low-latency meshed architecture for dynamic and
including rate conversion, aggregation, fault-tolerant visibility that can scale to over 40002 ports across LAN and WAN environments.
replication, filtering, load balancing, and
source port tagging Cost-Effective Feature Set
• Protocol stripping & de-encapsulation
Providing a lot of interfaces into a compact form factor, the nGenius 5000 Series Packet Flow
(e.g. VLAN, VN-tag, VXLAN)
Switches support core network packet broker features including filtering, load balancing,
• IP Tunnel termination (e.g. ERSPAN) replication, and aggregation. With an expansive feature set, the nGenius 5000 Series Packet Flow
• Intelligent fully meshed stacking / Switches are capable of managing a monitoring network independently. Connect the HD Fiber
interconnect (pfsMesh) TAPs and any number of tools, including NETSCOUT’s Service Assurance and Security Assurance
• Flexible policy defined triggers for event products, to an nGenius 5000 Series Packet Flow Switch and easily manage a diverse and
handling and high availability scenarios complex monitoring network.
• Management via command line, NETCONF,
RESTCONF, and graphical user interfaces Flow-aware load balancing enables intelligent control of traffic distribution to the monitoring
for local and remote access tools, increasing output capacity while maintaining session integrity. For example, packets
• Zero Touch Provisioning (ZTP) for easy from a 40GbE TAP can be captured and automatically load-balanced across multiple 1GbE or
system turnup 10GbE monitoring tool ports based on user-defined session criteria. The PFS 5000 series can
• Software-driven and powered by the load balance among tools of different processing capacity (e.g., 10GbE tools and 40GbE tools)
NETSCOUT® Packet Flow Operating by assigning weights to each tool port to achieve weighted load balancing. Flow-aware load
System (PFOS) balancing can operate in tandem with hardware-based filtering or independently.
Total number of ports in a single pfsMesh is dependent on quantity and complexity of filtering.
2
Management
The nGenius 5000-Series Packet Flow Switches can be managed via Web UI (over HTTP or
HTTPS) and CLI (via SSH) and include NETCONF XML (over SSH) and RESTCONF (HTTP or HTTPS)
APIs for programmatic management; the systems can be monitored via Syslog and SNMP. Each
device ships with an intuitive and easy to use graphical element management system (EMS) out
of the box. Simply point a web browser at the nGenius 5000-Series Packet Flow Switch and let
the web-based user interface (WebUI) power the packet flow system. IPv4 or IPv6 management
IP addresses can be manually assigned or obtained via DHCP; DHCP can also be used to
bootstrap new PFS via Zero Touch Provisioning.
Virtual Access
For accessing traffic that is completely virtualized and never makes it onto a physical network,
traffic can be mirrored and forwarded from the virtual network to the physical network using
tunneling protocols such as NVGRE (L2GRE) or ERSPAN which encapsulate the traffic of interest.
The nGenius 5000 Series Packet Flow Switches can terminate these tunnels so the traffic can
then be forwarded on to monitoring applications.
Features Benefits
32 to 128 ports in 1RU, 2RU, or 4RU, Fixed Configurations High Density Systems
Compatible with SFP, SFP+, SFP28, QSFP+, and QSFP28 MSA compliant • Drives cost-effectiveness by reducing per-port cost and
transceivers – for complete details, please refer to the list of transceivers increasing flexibility
offered by NETSCOUT • Condenses the nGenius PFS footprint (rack space) into a minimum of
space in a fixed configuration
• Reduces power consumption
• Software-driven, simplifies management
Flexible and Powerful Filtering • Line-rate filtering allows only traffic of interest to be forwarded to
• Line Rate each tool, increasing tool efficiency and reduces the number of
• OSI Layers 2 - 7 required tool interfaces
• Ingress
• Overlapping
Session-Based/Flow-Aware Load Balancing • Prevents oversubscription of monitoring tools and security systems –
• Distributes traffic load across multiple instances of a tool or tool port eliminating blind spots without sacrificing session integrity
• Maintains session stickiness for full conversations • Copied traffic can be easily distributed across multiple lower speed tool
ports, allowing users to preserve existing tool investments
Features Benefits
Weighted Load Balancing • Prevents oversubscription of monitoring tools and security systems
• Distributes traffic among tools of different capacities • Preserves investment in existing tools while allowing growth with newer,
higher-capacity tools
Monitor Traffic Port Tagging • Users can quickly and precisely pinpoint where an issue, such as latency
• Provides identification of traffic based on source network/link using or security event, is occurring in the network
VLAN tagging • Allows different tools to access port identification
Line-Rate Header Stripping5 • Preserve tool resources (bandwidth and processing) by eliminating
• VLAN unnecessary headers
• VxLAN • Re-use legacy tools that may not understand newer protocol headers
• VN-tag • Enable native filtering and load balancing on inner packet fields
Policy-Based Event Triggering and Actions • Reduces management overhead and enables faster response
• Dynamic traffic redirection based on occurrence of events times to incidents
• Send alerts when specific events occur
Local and Remote Management • Easy to use via graphical interfaces or via CLI
• GUI (HTTP/HTTPS) • Easy integration with applications using the NETCONF XML or
• CLI (SSH) RESTCONF APIs
• NETCONF XML API • Alerts can be sent to any Syslog server or SNMP manager, with options
• RESTCONF RESTful API for secure transport
• SNMP
• Syslog (transport over UDP, TCP, TLS, or SSH)
• IPv4 and/or IPv6
Zero Touch Provisioning (ZTP) • Configuration via DHCP dramatically reduces time to bring new
PFS online
Flexible Authentication and Authorization • Meets authentication and authorization policy needs of IT organizations
• Local Authentication
• RADIUS
• TACACS+
• LDAP (including Active Directory)
Total number of ports in a single pfsMesh is dependent on quantity and complexity of filtering.
4
Standard Specification(s)
Ethernet IEEE 802.3, IEEE 802.3ab, IEEE 802.3ae, IEEE 802.3ba, IEEE 802.3bm, IEEE 802.3by, IEEE 802.3z, 802.3cu, 802.3cd
VLAN IEEE 802.1Q, IEEE 802.1ad
ARP IETF RFC 826
IP IETF RFC 791, 2460
UDP IETF RFC 768
TCP IETF RFC 793
SSH IETF RFC 4251, 4252, 4253
HTTP IETF RFC 2616, 2817
TLS (SSL) IETF RFC 4492, 5246
NETCONF IETF RFC 4741, 4742, 6241, 6242
RESTCONF IETF RFC 8040
SNMP IETF RFC 1157, 3411-3418
Syslog IETF RFC 5424, 5425
NTP IETF RFC 5905
RADIUS IETF RFC 2865, 2866
TACACS+ IETF RFC 1492
FCC Part 15 Subpart B/ICES-003 Class A, EN 55032 Class A, VCCI Class A, AS/NZS CISPR 32 Class A, AS/NZS CISPR
EMC 22 & 24, EN 61000, EN 300 386 Class A, CNS 13138 Class A, IEC-003, KCC Class A (except PFS 5130-128X), TUV-GS
(PFS 5010 and 5100 only)
IEC 60950-1:2005 (2nd Edition) + Am 1:2009 + Am 2:2013, UL 60950-1, EN 60950-1, CAN/CSA-C22.2 No. 60950-1,
Safety
IEC 62368-1 (2nd Edition), EN 62368-1 (2nd Edition), UL/CUL
Federal Information
Processing Standards 140-2 (PFS 5010, 5010-16X, 5110, 5100, 5120 only)
(FIPS)
Common Criteria Network Devices Protection Profile (NDcPP) v2.2E (PFS 5010, 5010-16X, 5110, 5100, 5120 only)
Ordering Information
SPECIFICATIONS
SFP28 port speeds on the PFS 5110 (and PFS 5111) and QSFP28 port speeds on the PFS 5130-128X are assigned in groups of 4 (e.g., ports 1-1 through 1-4 must have the same speed).
7
1GbE fiber (IEEE Clause 37) auto-negotiation is not supported by the PFS 5110 so use of 1GbE fiber should be limited to use with TAPs. 1GbE copper does not have this restriction.
8
Airflow Front-to-back
Operating
32° to 104°F (0° to 40°C) 32° to 113°F (0° to 45°C)
Temperature
Storage
-40° to 158°F (-40° to 70°C)
Temperature
Operating Humidity 5% - 95% (non-condensing)
NETSCOUT offers sales, support, and services in over 32 countries. Global addresses, and international numbers are
listed on the NETSCOUT website at: www.netscout.com/company/contact-us
© 2022 NETSCOUT SYSTEMS, INC. All rights reserved. NETSCOUT, the NETSCOUT logo, Omnis, Guardians of the Connected World, Adaptive Service Intelligence, Arbor, ATLAS, InfiniStream,
nGenius, and nGeniusONE are registered trademarks or trademarks of NETSCOUT SYSTEMS, INC., and/or its subsidiaries and/or affiliates in the USA and/or other countries.
Third-party trademarks mentioned are the property of their respective owners.
PFSPDS_022_EN-2201 07/2022