On-chip firewall guards PCs

Nvidia chipset includes a hardware firewall to secure desktops

Written by Daniel Robinson

Chip firm Nvidia will this week announce a motherboard chipset with dedicated hardware to support a client-side firewall. The nForce4 chipset offloads from the processor the task of inspecting data traffic, so it can secure a PC without slowing performance.

The Nvidia nForce4 chipset is shipping now to motherboard makers and system builders, and is expected to appear in PCs before the end of the year. However, the system only supports 64bit AMD chips, while most companies still only buy desktops running Intel processors.

Unsecured networks are a major threat to business, according to Nvidia. "Newly deployed Windows PCs can get infected in seconds, just by being connected to the network," said Drew Henry, general manager of Nvidia's platform business. But he added that software-based firewalls cause the lion's share of processor time to be devoted to filtering IP traffic, especially when using high-speed network technologies such as Gigabit Ethernet.

The Secure Networking Engine (SNE) inside nForce4 serves as dedicated hardware for the Nvidia Firewall app that ships with it. The SNE performs stateful inspection on all data coming in from nForce4's integrated Gigabit Ethernet adapter and blocks any bad packets. "And the advantage is, we can do this at full Gigabit Ethernet speed without slowing down the CPU," Henry said.

Nvidia said that the SNE also monitors outbound traffic, and can alert the user if an unknown program tries to open an internet connection. This capability is already supported by firewalls such as ZoneAlarm from Zone Labs, but not by the Windows Firewall that ships as part of Microsoft's SP2 update for Windows XP.

The Nvidia Firewall ships with predefined security profiles to make it easier to use, but administrators can create customised profiles for their firms' security policies and deploy them using standard management tools, according to Henry.

Nvidia said its system is compliant with Microsoft's TCP Chimney Architecture, a forthcoming Windows API that will support the offloading of portions of the TCP protocol stack to hardware, typically a LAN adapter.

The nForce4 is the first chipset for AMD's Athlon 64 and Opteron chips to support the new PCI Express I/O standard, according to Nvidia. As well as integrated Gigabit Ethernet, it supports a faster 3Gbit/s interface for Serial ATA (Sata) hard disks, and the 1GB/s version of AMD's HyperTransport technology that links the chipset to the processor.

Three versions of the nForce4 chipset are shipping. The baseline nForce4 lacks SNE, while the nForce4 SLI supports multiple Nvidia graphics cards. Business desktops will likely use the mid-range nForce4 Ultra. An nForce4 Pro chipset to support dual processors on workstations is planned.

Tags:

reader comments

related articles

Daniel Robinson

Silicon builds stronger security

There's a clear need for better PC security - and purpose-built chips could help 03 Nov 2004

 

Hitachi brings enterprise storage to mid-size firms

AMS 2000 series offers dynamic load balancing and a Serial Attached SCSI backplane 13 Oct 2008

related whitepapers

today's top stories

Best practice: Five steps to achieving your e-commerce goals

Brian Walker of Forrester Research gives his top tips for ensuring e-commerce success 06 Jul 2009

Google meets the NHS? Politicians show their IT naivety again

The Tories like technology. They increasingly seem to think IT is going to help them win the General Election due next year.... 06 Jul 2009

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

Reaching the email zero count

I have noticed something quite bizarre today. Both my inboxes (work and personal) are empty – somehow I have managed to work... 06 Jul 2009

Habitat gets a web site makeover

The furniture retailer is revamping its online presence to provide a fully transactional web site. CIO Jacques Dekock explains why 02 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use social networking sites to look for a job?

Would you use social networking sites to look for a job?

Tell us what you think about job hunting through LinkedIn, Facebook, Twitter etc

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Phil PavittAnalysis

From tracks man to tax man

Phil Pavitt, outgoing chief information officer for Transport for London, talks to Rosalie Marshall about the lessons he will take to his new role at HMRC 02 Jul 2009

UPS worker making a deliveryAnalysis

Global standardisation delivers benefits at UPS

Delivery giant sees benefits of central IT solution 02 Jul 2009

Advertisement

Primary Navigation