Juniper at the edge, Dell in the cluster, and nothing improvised
One vendor for routing, one for the filtering fleet, and the same build at all ten locations. A uniform platform is not tidiness for its own sake - it is what lets a change be validated once and deployed everywhere, and what makes an escalation at four in the morning short.
We run Juniper end to end, and have for long enough to have
opinions about it. Routing and switching are Juniper at every site; the filtering cluster is
Dell, uniformly, with NVIDIA ConnectX-8 and BlueField-3 adapters - the cards the XDP program
attaches to. One platform everywhere means a rule verified at one site behaves identically at
the other nine.
Nothing in the path is singular. Every location runs at least two MX304 routers
and at least two QFX10008 switches, so any one chassis can be lost - or taken out for an
upgrade during working hours - without the site losing traffic. The QFX10008 does double duty:
the fabric inside the site that the filtering cluster hangs off, and the spine and edge
switching that carries our own backbone between locations.
Routing
Juniper MX304
Border and edge routing at every point of presence
4.8 Tbps2+ per location
Switching
Juniper QFX10008
Fabric within each site, and spine and edge switching between locations
48 Tbps2+ per location
Filtering
Dell PowerEdge R670
The scrubbing cluster itself, one filter per server
400G each10+ per cluster
Adapters
NVIDIA ConnectX-8 & BlueField-3
Where the XDP program attaches, in the driver
400GOne per filter
Clusters, not boxes
At least 10 servers per cluster
Every scrubbing location runs a filtering cluster of ten servers or more, sharing the
load by weighted ECMP. Each holds its proportional share of every budget, so the group
enforces the figure that is written down rather than a multiple of however many machines
happen to be racked. Adding one raises capacity without loosening a single limit.
Redundancy
Two of everything, then EVPN-MPLS
A minimum of two routers and two switches at every location, carried over EVPN-MPLS with no
single point of failure in the path. A failed link, line card or whole chassis is a
re-convergence rather than an outage, and the traffic that was on it is already somewhere else
before anyone is paged.
Uniform fleet
One platform, ten locations
Identical hardware and identical software everywhere. A change is proven at one site
before the other nine follow it unchanged, a spare part fits at any location, and an
engineer who knows one site knows all ten.
No cookies here.
This site sets zero cookies - no analytics, no trackers, no profile of you. The only
third-party requests are the fonts, served by Google Fonts, and the spam check on the contact
form. Everything else stays between your browser and our network -
the full privacy note.