Back in 2008 Fujitsu has one of the best performing 10Gbps Switches. We were building 40 Gbps packet sniffers at Google (4x 10 Gbps NICs) and needed switches that could do things like mirror traffic across ports at line rate. Fujitsu was way ahead of the pack. I always wondered what held them back from building a meaningful networking business in the US.
> I always wondered what held them back from building a meaningful networking business in the US.
It was just timing. Their networking gear was built on some very impressive ASICs which became commodity chips a few years later before they could grow. Arista, Juniper, et al ate their lunch using other vendors’ IP. IIRC it was Broadcom and Fulcrum that released the chips that killed them.
Another broadcom related tragedy
Broadcom has a vast amount of patents that they leverage in their business decisions.
[dead]
>We were building 40 Gbps packet sniffers at Google (4x 10 Gbps NICs) and needed switches that could do things like mirror traffic across ports at line rate
I'm sure there were good reaasons for this, but man this just sounds bad. Like that's the spec I think NSA must give to their contractors outfitting 611 Folsom Street's Room 641A
These tools are very common in non-nefarious ways for troubleshooting networking, and while vendors set up to serve this space solely as troubleshooting tools, I've also built my own that can sit on a network link and monitor for problems.
In my case it was for mobile wireless signaling traffic (all the coordination for creating a mobile internet connection, handing the connection off between towers, etc), and I'd credit it as one of the reasons you're mobile internet connection is so stable. When LTE first came out, myself and many others solved all sorts of bugs in the equipment and protocols by using or building these sorts of tools.
Port mirroring is the network engineer's equivalent of using breakpoints in a debugger for a programmer. It allows you to inspect what happens on the wire to get a clue for what's wrong.
It does sound bad the way OP described it, but packet or HTTP mirroring is a standard feature of A/B testing and blue-green deployments of a very critical code. Mirror traffic between version 1 and 2, then compare response body, response time and return response A to the end users.
But the comment says ”we were building packet sniffers” … and needed mirroring as part of that.
I used to operate several dozen 10G/25G/40G/100G taps which fed a series of tools in the DC at a regional healthcare back in the day.
80% of the relevant outcome was typically to get a true-to-the-wire sniffer capture (switch mirrors won't always mirror 100% of packets for various reasons) for troubleshooting performance of whatever the complaint of the day from the server team was.
19% was for feeding a security monitoring systems which looked for abnormal flow patterns to let us know a server was compromised.
1% was for the call recording system compliance requirement for the emergency department.
0% was because I was a cool superspy tasked by the government to siphon info to them or trying to sell medical records on the black market or something. I mean, you can try to something nefarious with such tools... but one could say the same about a generic server, SAN, application, etc as well. People are just used to understanding what those would typically be used for so they don't assume it must be for the scary thing they've heard about.
That said, it doesn't rule it out either. But again, the concern shouldn't be sourcing from their usage of normal infrastructure tools it should be sourcing from... well, all of the user analytics Google very publicly does directly in the server.
I was under the impression that the superspy stuff usually happens more at the undersea-cable terminal or at satellite links anyway.
It's super common and very useful for security systems to work like this. Instead of putting something in-line that might choke on a burst of traffic you put it off to the side and send it a firehose of packets it may or may not be able to handle. If it falls over, no problem.
Common tools for any network engineer
Nah, packet mirroring is a standard networking feature and ideally every feature is line rate.
Indeed. Juniper had this over 20 years ago.
It came for free on hubs :)
the cost there was performance
There are companies that mirror their traffic to storage for a few days to be able to look back and troubleshoot issues. ALL their traffic, proactively.
For US federal government, "Office of Management and Budget" says to store 72 hours of packet capture, since 2021 (partially in response to SolarWinds attack). (M-21-31)
https://www.cisa.gov/sites/default/files/2023-02/TLP%20CLEAR...
I do that with very, very low traffic industrial automation systems.
The XG series switches? Force10 sold them until Dell bought Force10 and continued to sell them (although the firmware changed a lot along the way). They were, AFAIK, pretty popular in the US under the Dell brand.
My home network is XG2000 10G core and a few XG0224 1G/10G dist. Very nice switches.
Ubiquity proved you can bust into the market from the bottom end if you want. Nothing was stopping them from doing the same but like many companies they prefer to focus on how much money they can siphon from the Fortune 1000 so I can't say I feel sorry for them.
I'm not sure why that's relevent, particularly since Ubiquity's approach wouldn't have remotely competed with Fujitsus custom ASICs if they were actual contemporaries, but you clearly have an agenda you're in love with, so...ok, sure.
AFAIK those sold relatively well, considering the TCO of both sides (NICs were very expensive and there were like a dozen companies vying for position once upon a time). They were also interesting because they were cut-through. CX4 was noticeably lower latency than SFP+. So a very fast, but feature limited architecture which is probably why other players like Cisco and then Arista (aka Broadcom) took over.
The likely just didn't want another round of tantrums and troubles: https://en.wikipedia.org/wiki/1986_U.S.%E2%80%93Japan_Semico...
Having a us based vendor. Fujitsu is huge in Asia for ISPs and so is Mitsubishi and Sumitomo (yes they made or used to make network equipment too)
We have alliances with Japan and S Korea which predispose us to believing we might be able to get a clean supply chain from them if a new Cold War starts. Out other options don’t even pass a giggle test and that’s the state of the world until some manufacturing is brought back onshore for strategic reasons.
The same way Congress has been subsidizing Boeing and its competitors since WW2 to make sure we can build things that fly if another war ever starts. Or with drones, that we can build ones that will be flown BY US instead of defecting the moment they get in range of the other side.
> The same way Congress has been subsidizing Boeing and its competitors
Funny you should mention that. Boeing deliberately buys 35% of a 787's airframe from Japan (along with other equipment for the 787 and other models).
That's a deliberate play: we buy a lot of parts from Japanese companies, your airlines buy mostly Boeing airplanes. Even today despite some diversification Boeing has over 70% marketshare in Japan.
If you ever wondered why Airbus setup factories in the USA that's a similar deal. The US Gov and Mil want to ensure factories and workforce on home soil should the need arise. In some unrecorded meetings somewhere strong hints were no doubt dropped that it would be in Airbus' best interest to play ball. They obliged.
That said the USA is the largest supplier of parts for Airbus airliners so there's also a benefit to having aerospace manufacturing and R&D here.
Boeing proposes sth called the “Boeing Honeywell Uninterruptible Autopilot” to add drone-like remote control capabilities to its airliners (for security reasons, obviously). I'm not aware of a similar offering for Airbus but I have no doubt such a capability has existed in Airbus as well for perhaps two decades. I expected development of such a sensitive system for Airbus to be based in France, but your comment about “strong hints” and “play ball” has me thinking…
Their servers were gorgeous (on the inside) as well. Clean designs, no clutter.
Seems like a story mirrored across Japanese companies.
[flagged]
Do you mind elaborating?
This is the first time ever I am hearing of Fujitsu being involved in any bribing/lobbying controversy in the US (whether as a victim or an offender), and I doubt I am the only user in this thread in this position.
Unless it is a very well-known controversy, I feel like there is a need for extra context here. I am not even asking for anything of the "proof beyond any reasonable doubt" nature, I simply want to understand what you are trying to reference.
I wasn’t referencing anything specific, but a general response to how/why many companies can’t or won’t do business in the United States.
>I wasn’t referencing anything specific, but a general response to how/why many companies can’t or won’t do business in the United States.
Its a genuinely terrible place to do business, and its full of genuinely terrible people to do business with.
Oh and Trump made it a bit worse with Tariffs I guess.
Hope this helps.
The other sort of network, ironically.