On-chip firewall guards PCs

Nvidia chipset includes a hardware firewall to secure desktops

Written by Daniel Robinson

Chip firm Nvidia will this week announce a motherboard chipset with dedicated hardware to support a client-side firewall. The nForce4 chipset offloads from the processor the task of inspecting data traffic, so it can secure a PC without slowing performance.

The Nvidia nForce4 chipset is shipping now to motherboard makers and system builders, and is expected to appear in PCs before the end of the year. However, the system only supports 64bit AMD chips, while most companies still only buy desktops running Intel processors.

Unsecured networks are a major threat to business, according to Nvidia. "Newly deployed Windows PCs can get infected in seconds, just by being connected to the network," said Drew Henry, general manager of Nvidia's platform business. But he added that software-based firewalls cause the lion's share of processor time to be devoted to filtering IP traffic, especially when using high-speed network technologies such as Gigabit Ethernet.

The Secure Networking Engine (SNE) inside nForce4 serves as dedicated hardware for the Nvidia Firewall app that ships with it. The SNE performs stateful inspection on all data coming in from nForce4's integrated Gigabit Ethernet adapter and blocks any bad packets. "And the advantage is, we can do this at full Gigabit Ethernet speed without slowing down the CPU," Henry said.

Nvidia said that the SNE also monitors outbound traffic, and can alert the user if an unknown program tries to open an internet connection. This capability is already supported by firewalls such as ZoneAlarm from Zone Labs, but not by the Windows Firewall that ships as part of Microsoft's SP2 update for Windows XP.

The Nvidia Firewall ships with predefined security profiles to make it easier to use, but administrators can create customised profiles for their firms' security policies and deploy them using standard management tools, according to Henry.

Nvidia said its system is compliant with Microsoft's TCP Chimney Architecture, a forthcoming Windows API that will support the offloading of portions of the TCP protocol stack to hardware, typically a LAN adapter.

The nForce4 is the first chipset for AMD's Athlon 64 and Opteron chips to support the new PCI Express I/O standard, according to Nvidia. As well as integrated Gigabit Ethernet, it supports a faster 3Gbit/s interface for Serial ATA (Sata) hard disks, and the 1GB/s version of AMD's HyperTransport technology that links the chipset to the processor.

Three versions of the nForce4 chipset are shipping. The baseline nForce4 lacks SNE, while the nForce4 SLI supports multiple Nvidia graphics cards. Business desktops will likely use the mid-range nForce4 Ultra. An nForce4 Pro chipset to support dual processors on workstations is planned.

Tags:

reader comments

related articles

Daniel Robinson

Silicon builds stronger security

There's a clear need for better PC security - and purpose-built chips could help 03 Nov 2004

 

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

E-paper displays are an open book

A display revolution is on the way - but only once the user interface issues are solved 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

A meetingAnalysis

Turning adversity into an advantage

IT chiefs under pressure to make cost cuts can turn the situation to their benefit 04 Sep 2008

CloudAnalysis

How to introduce cloud computing into your organisation

Best practice advice from Forrester Research 04 Sep 2008

Primary Navigation