WHITE PAPER. Extending Network Monitoring Tool Performance

Size: px
Start display at page:

Download "WHITE PAPER. Extending Network Monitoring Tool Performance"

Transcription

1 WHITE PAPER Extending Network Monitoring Tool Performance Rev. A, July 2014

2 2

3 Table of Contents Benefits... 4 Abstract... 4 Introduction... 4 Understanding Monitoring Tools... 4 Extending 1 Gigabit Monitoring Tool Performance... 5 Finding the Right Solution... 6 Conclusion... 7 About Ixia

4 Benefits Handle higher bandwidth traffic without a total reinvestment in new tools Improve efficiency of network administration and problem solving Increase return on monitoring tool investments Abstract The industry s challenge is to leverage investments in existing monitoring tools as they confront increasing network speeds, higher network utilization, and the explosion of new network services and threats. Many organizations have invested in network monitoring equipment such as protocol analyzers, intrusion detection and prevention systems, and stream-to-disk traffic loggers. The challenge is to extend the performance capabilities of these tools to handle the highspeed, multi-protocol, security threat-laden traffic of today s and tomorrow s networks, without a total reinvestment in new tools, and without sacrificing security. This paper explores how monitoring tools can achieve higher levels of performance without forklift upgrades. It proposes a variety of ways to extend their efficiency, including the use of a stand-alone content filtering device to offload monitoring tools by pre-filtering traffic and assisting with common tasks. Introduction In today s IT-driven organizations, network performance is key to providing excellent customer experiences, driving business process efficiencies, growing revenue, and maintaining competitive advantage. Network administrators, charged with keeping networks responsive to the needs of both internal and external customers, rely on network monitoring tools for a continuous stream of information to baseline and assess the network s health. These tools enable administrators to ensure high application availability and good response times, to enforce network usage policies, and to justify and measure the impact of network upgrades. Network administrators can choose from an array of monitoring tools, ranging from open-source host-based software tools to sophisticated hardware appliances and platforms. Solutions include: Protocol analyzers, RMON probes, and NetFlow collectors for performance tuning Intrusion detection systems (IDS) and intrusion protection systems (IPS) for security Stream-to-disk traffic loggers and monitors for compliance auditing, forensics, and lawful intercept The industry s challenge is to leverage investments in existing monitoring tools as they confront increasing network speeds, higher network utilization, and the explosion of new network services and threats. The key is to find new and innovative ways to extend tool performance and improve network security by modifying the traffic flow or its basic characteristics rather than entirely replacing the tools. The following sections explain where opportunities exist for implementing new enhancements, and for extending tool performance. Understanding Monitoring Tools Most network monitoring tools are task-specific, high-performance software packages running on PC or server hardware. Proprietary boxes sold as appliances may consist internally of standard hardware components running proprietary software, often based on the Linux operating system. The performance of these tools is determined by the speeds of the processors and memory buses, and the size of the memory utilized 4

5 both for caching and for buffering packets from the network. The performance of the network interface cards (NICs) is obviously critical, too, for monitoring high-bandwidth 1Gbps and faster network links. More advanced tools help alleviate these bottlenecks by adding more processors and more dedicated buffers, typically using standard integrated circuit (IC) components on custom-designed boards with proprietary architectures. The highest performing tools go one step further, using custom-designed application-specific integrated circuits (ASICs). The type, speed, and number of processors in a tool dictate its processing performance. As network speeds increase, the number of packets that can be processed at wire speed (in other words, keeping up with the network) reaches a limit. Moreover, the further a tool s hardware architecture diverges from standard, well-understood technology, the trickier it becomes, as engineers push radical new architectures to achieve maximum performance. Buffers enable the tool to handle higher peak traffic loads by storing packets during high traffic periods, and releasing them to be processed when the traffic is less. However, the inability to sustain performance at full network bandwidth, and for extended periods of high traffic, may eventually cause even the largest buffers to fill up, and the tool may not capture needed information. Extending 1 Gigabit Monitoring Tool Performance The objective is to deliver more network performance or security protection from a monitoring tool with minimal change. This goal can be achieved by directly upgrading or replacing software or hardware, or by combining the original tool with another device in a comprehensive system solution. Possible approaches and their impacts may include the following (in no particular order of acceptance or adoption): Upgrade components. If the monitoring tool runs on standard hardware, upgrading with additional memory or faster NICs and processors may be a quick and relatively inexpensive fix. Also, the vendor may have newer software releases that provide faster throughput and newer features that satisfy a particular situation. As network speeds increase, the number of packets that can be processed at wire speed (in other words, keeping up with the network) reaches a limit. Purchase duplicate equipment. In many cases, two monitoring tools can run along side each other, doubling the amount of data that can be captured. For example, one tool can process the TCP traffic while another one handles ICMP and UDP packets; or each tool can capture flows from different IP address pairs. This approach has the advantage of having no learning curve, because users already know how to operate the equipment. In addition, it provides redundancy in case one tool breaks, and the tools can be deployed separately when they aren t needed together. On the downside, this approach may not fit into the budget or architecture. It may also create issues around seeing an integrated view of the traces from both the tools. Upgrade to a faster tool. Higher performance equipment may be available, providing a twoto ten-times performance increase. Be sure to evaluate not only the cost of the tool itself, but also the training expense if the functions or user interface are significantly different. Also, check for compatibility with other tools that may be part of your total solution. For example, an offline protocol analyzer may work with trace files from a logging tool. Is the new logging tool s file format supported by the protocol analyzer? Change the network. It may be possible to temporarily or permanently change the network so the link that needs monitoring simply doesn t carry more traffic than the monitoring 5

6 Management tools can handle. Load balancing, bandwidth limiting, or perhaps adding new network devices might accomplish this goal. In most cases, it probably makes more sense to change the tools rather than the network, but when the network is changed for any reason, the impact on monitoring tools should be considered. It may be possible to pair an overburdened tool with a hardware-based device that is specifically built to offload redundant or well-known tasks. Use pre-capture filters. Pre-capture filters reduce the number of packets a tool needs to store and process, by selecting packets of interest based on header information such as protocol type and IP address. The performance ceiling of the tool is raised because less buffering and processing power are needed to support the traffic load. Many tools offer pre-capture filters, but software-based pre-capture filters have performance limitations of their own. Because the pre-capture filter itself must process every single packet on the wire, it may be limited to selecting ten or fifteen types of traffic; for instance, only flows between ten or fifteen source and destination IP address pairs. This limitation impacts the ability of administrators to debug network problems, costing them time and loss of productivity. Hardware-based filters implemented in custom ASICs may be able to support hundreds of filters at once, but they are found only in the more expensive equipment, so cost and administrator efficiency are a tradeoff. Another approach to improve the capture ability is to copy the pre-filtered traffic stream to a high-speed memory-based file system for subsequent processing, rather than processing the pre-filtered traffic in real time. Finding the Right Solution In some cases, monitoring tool performance can be extended through yet another approach. It may be possible to pair an over-burdened tool with a hardware-based device that is specifically built to offload redundant or well-known tasks. The solution would include pre-filters or offload capabilities that limit traffic being sent to the monitoring tool; a dedicated device that offers Layer-3/-4 and content filtering at 1Gbps wire speed, and only slightly increases the cost of your existing solution; a device that would be useful in a variety of scenarios, ranging from monitor tool performance offload to compliance adherence. What if this device could handle hundreds of filters at wire speed? (a) Without pre-filter (b) With pre-filter Router Tap Switch Router Tap Switch Protocol Analyzer Captures traffic from at most 10 to 15 IP pairs Pre-filter <-> <-> <-> hundreds of IP-pairs Protocol Analyzer Figure 1: Using a hardware pre-filter to capture traffic from hundreds of IP-pairs Figure 1: Using a hardware pre-filter to capture traffic from hundreds of IP-pairs It could be placed in front of a network analyzer to act as a hardware-based precapture filter, forwarding only traffic of interest to the analyzer, and preventing overruns (Figure 1). It could relieve an IPS by eliminating hundreds of known threats identified by content strings, protocols, and port numbers (Figure 2). It could assist in a regulatory compliance solution by logging or blocking content containing hundreds of keywords and phrases such as Company Confidential, Do Not Distribute, and Social Security Number (Figure 3). 6

7 Management Management (a) Without filter Known, repetitive, and keyword-based threats Complex, stateful, and emerging threats OVERLOAD! Router IPS Appliance Switch (b) With filter Known, repetitive, and keyword-based threats Complex, stateful, and emerging threats Router Rule-based Filter IPS Appliance Figure 2: Using a rule-based filter to offload an IPS appliance Figure 2: Using a rule-based filter to offload an IPS appliance Router Switch attachments containing Company Confidential, Social Security Number, and many other keywords and phrases dropped from outgoing traffic Content Filter Switch Web sites containing profanity dropped from incoming traffic Figure Figure 3: 3: Using Using a hardware a content filter filter to to assist a a host-based appliance compliance solution solution It makes good business sense to invest in solutions that enable administrators to solve network problems as quickly and accurately as possible. The ability to deploy a single device in a variety of configurations allows for the flexibility to assist in multiple scenarios, offering offload and pre-filtering for tools of all types. Conclusion Today s network monitoring tools offer levels of performance that were unheard of just a few years ago, but ongoing increases in network speeds and utilization continue to challenge their limits. The move to enhance monitoring tool performance, without sacrificing security, is driven by the hundreds of thousands of dollars in lost revenue and reduced productivity that organizations suffer annually due to underperforming or down networks. One study by the Aberdeen Group estimated that network downtime costs corporations an average of US$69,000 per minute (as high as US$1.5 million per minute in some industries) and those may be minutes that a network administrator is struggling with a monitoring tool that is bumping up against its performance ceiling. Therefore it makes good business sense to invest in solutions that enable administrators to solve network problems as quickly and accurately as possible. Given the wide range of approaches for extending network monitoring tool performance, at least one is sure to be cost-effective for your organization. To learn more about monitoring pre-filter and offload technology, please contact Net Optics at info@netoptics.com. Our technology experts would be happy to discuss possible solutions that Tap into your network monitoring challenges. 7

8 About Ixia Ixia develops amazing products so its customers can connect the world. Ixia helps its customers provide an always-on user experience through fast, secure delivery of dynamic connected technologies and services. Through actionable insights that accelerate and secure application and service delivery, Ixia s customers benefit from faster time to market, optimized application performance and higher-quality deployments. 8

9 9

10 WHITE PAPER Ixia Worldwide Headquarters Agoura Rd. Calabasas, CA (Toll Free North America) (Outside North America) (Fax) Ixia European Headquarters Ixia Technologies Europe Ltd Clarion House, Norreys Drive Maidenhead SL6 4FL United Kingdom Sales (Fax) Ixia Asia Pacific Headquarters 21 Serangoon North Avenue 5 #04-01 Singapore Sales Fax Rev. A, July 2014

WHITE PAPER. Static Load Balancers Implemented with Filters

WHITE PAPER. Static Load Balancers Implemented with Filters WHITE PAPER Static Load Balancers Implemented with Filters www.ixiacom.com 915-6911-01 Rev. A, July 2014 2 Table of Contents Load Balancing of Monitoring Systems as a Key Strategy for Availability, Security

More information

WHITE PAPER. Addressing Monitoring, Access, and Control Challenges in a Virtualized Environment

WHITE PAPER. Addressing Monitoring, Access, and Control Challenges in a Virtualized Environment WHITE PAPER Addressing Monitoring, Access, and Control Challenges in a Virtualized Environment www.ixiacom.com 915-6892-01 Rev. A, July 2014 2 Table of Contents The Challenge of the Virtual Environment...

More information

IxChariot Virtualization Performance Test Plan

IxChariot Virtualization Performance Test Plan WHITE PAPER IxChariot Virtualization Performance Test Plan Test Methodologies The following test plan gives a brief overview of the trend toward virtualization, and how IxChariot can be used to validate

More information

WHITE PAPER. Monitoring Load Balancing in the 10G Arena: Strategies and Requirements for Solving Performance Challenges

WHITE PAPER. Monitoring Load Balancing in the 10G Arena: Strategies and Requirements for Solving Performance Challenges WHITE PAPER Monitoring Load Balancing in the 10G Arena: Strategies and Requirements for Solving Performance Challenges www.ixiacom.com 915-6914-01 Rev. A, July 2014 2 Table of Contents Load Balancing A

More information

WHITE PAPER. Gaining Total Visibility for Lawful Interception

WHITE PAPER. Gaining Total Visibility for Lawful Interception WHITE PAPER Gaining Total Visibility for Lawful Interception www.ixiacom.com 915-6910-01 Rev. A, July 2014 2 Table of Contents The Purposes of Lawful Interception... 4 Wiretapping in the Digital Age...

More information

WHITE PAPER. Network Traffic Port Aggregation: Improved Visibility, Security, and Efficiency

WHITE PAPER. Network Traffic Port Aggregation: Improved Visibility, Security, and Efficiency WHITE PAPER Network Traffic Port Aggregation: Improved Visibility, Security, and Efficiency www.ixiacom.com 915-6893-01 Rev. A, July 2014 2 Table of Contents Summary... 4 Introduction... 4 Differing Goals

More information

EBOOK. The Network Comes of Age: Access and Monitoring at the Application Level

EBOOK. The Network Comes of Age: Access and Monitoring at the Application Level EBOOK The Network Comes of Age: Access and Monitoring at the Application Level www.ixiacom.com 915-6948-01 Rev. A, January 2014 2 Table of Contents How Flow Analysis Grows Into Total Application Intelligence...

More information

WHITE PAPER. Tap Technology Enables Healthcare s Digital Future

WHITE PAPER. Tap Technology Enables Healthcare s Digital Future WHITE PAPER Tap Technology Enables Healthcare s Digital Future www.ixiacom.com 915-6912-01 Rev. A, July 2014 2 Table of Contents Executive Overview... 4 Introduction... 4 HIT s foundation... 5 Keeping

More information

WHITE PAPER. Enabling 100 Gigabit Ethernet Implementing PCS Lanes

WHITE PAPER. Enabling 100 Gigabit Ethernet Implementing PCS Lanes WHITE PAPER Enabling 100 Gigabit Ethernet Implementing PCS Lanes www.ixiacom.com 915-0909-01 Rev. C, January 2014 2 Table of Contents Introduction... 4 The IEEE 802.3 Protocol Stack... 4 PCS Layer Functions...

More information

WHITE PAPER. How To Compare Virtual Devices (NFV) vs Hardware Devices: Testing VNF Performance

WHITE PAPER. How To Compare Virtual Devices (NFV) vs Hardware Devices: Testing VNF Performance WHITE PAPER How To Compare Virtual Devices (NFV) vs Hardware Devices: Testing VNF Performance www.ixiacom.com 915-3132-01 Rev. B, June 2014 2 Table of Contents Network Functions Virtualization (NFV): An

More information

WHITE PAPER. Net Optics Phantom Virtual Tap Delivers Best-Practice Network Monitoring For Virtualized Server Environs

WHITE PAPER. Net Optics Phantom Virtual Tap Delivers Best-Practice Network Monitoring For Virtualized Server Environs WHITE PAPER Net Optics Phantom Virtual Tap Delivers Best-Practice Network Monitoring For Virtualized Server Environs www.ixiacom.com 915-6909-01 Rev. A, July 2014 2 Table of Contents Event... 4 Context...

More information

Scalability in Log Management

Scalability in Log Management Whitepaper Scalability in Log Management Research 010-021609-02 ArcSight, Inc. 5 Results Way, Cupertino, CA 95014, USA www.arcsight.com info@arcsight.com Corporate Headquarters: 1-888-415-ARST EMEA Headquarters:

More information

WHITE PAPER. SDN Controller Testing: Part 1

WHITE PAPER. SDN Controller Testing: Part 1 WHITE PAPER SDN Controller Testing: Part 1 www.ixiacom.com 915-0946-01 Rev. A, April 2014 2 Table of Contents Introduction... 4 Testing SDN... 5 Methodologies... 6 Testing OpenFlow Network Topology Discovery...

More information

Reduce Your Network's Attack Surface

Reduce Your Network's Attack Surface WHITE PAPER Reduce Your Network's Attack Surface Ixia's ThreatARMOR Frees Up Security Resources and Personnel The Threat Landscape When you re dealing with network security, one of the primary measurements

More information

Data Center Automation - A Must For All Service Providers

Data Center Automation - A Must For All Service Providers WHITE PAPER Automation: The Future of Network Visibility www.ixiacom.com 915-6617-01 Rev. A, November 2013 2 Table of Contents Executive Summary... 4 The Need for Monitoring Switch Automation in the Data

More information

Best Practices for Network Monitoring How a Network Monitoring Switch Helps IT Teams Stay Proactive

Best Practices for Network Monitoring How a Network Monitoring Switch Helps IT Teams Stay Proactive White Paper Best Practices for Network Monitoring How a Network Monitoring Switch Helps IT Teams Stay Proactive 26601 Agoura Road, Calabasas, CA 91302 Tel: 818.871.1800 Fax: 818.871.1805 www.ixiacom.com

More information

EBOOK. Software Defined Networking (SDN)

EBOOK. Software Defined Networking (SDN) EBOOK Software Defined Networking (SDN) www.ixiacom.com 915-6885-01 Rev. A, January 2014 2 Table of Contents Your Route to Agility, Accuracy and Availability... 4 SDN Advanced, Next-Generation Networking...

More information

Taps vs. SPAN The Forest AND the Trees: Full Visibility into Today's Networks

Taps vs. SPAN The Forest AND the Trees: Full Visibility into Today's Networks WHITE PAPER Taps vs. SPAN The Forest AND the Trees: Full Visibility into Today's Networks www.ixiacom.com 915-3534-01 Rev. A, September 2015 2 Table of Contents The First Line of Defense: Access... 5 Problem

More information

Best Practices for Network Monitoring

Best Practices for Network Monitoring Enabling a Converged World Best Practices for Network Monitoring How a Network Monitoring Switch Helps IT Teams Stay Proactive 915-6509-01 Rev A February 2012 Contents Monitoring Challenges in Today s

More information

WHITE PAPER. Application Performance Management and Lawful Interception

WHITE PAPER. Application Performance Management and Lawful Interception WHITE PAPER Application Performance Management and Lawful Interception www.ixiacom.com 915-6897-01 Rev. A, July 2014 2 Table of Contents A New Approach Unifies Two Disciplines to Drive Mutual Performance,

More information

Consolidating Multiple Network Appliances

Consolidating Multiple Network Appliances October 2010 Consolidating Multiple s Space and power are major concerns for enterprises and carriers. There is therefore focus on consolidating the number of physical servers in data centers. Application

More information

Application Performance Management - Deployment Best Practices Using Ixia- Anue Net Tool Optimizer

Application Performance Management - Deployment Best Practices Using Ixia- Anue Net Tool Optimizer Application Performance Management - Deployment Best Practices Using Ixia- Anue Net Tool Optimizer Purpose: Overview on how to use Ixia s Anue Network Tool Optimizer (NTO) to provide the CA Application

More information

An Executive Brief for Network Security Investments

An Executive Brief for Network Security Investments An Executive Brief for Network Security Investments Implementing network security resilience is one of the few things that you can do that will: Protect company brand value Decrease operational costs Preserve

More information

WHITE PAPER. Best Practices for Eliminating Duplicate Packets

WHITE PAPER. Best Practices for Eliminating Duplicate Packets WHITE PAPER Best Practices for Eliminating Duplicate Packets 26601 Agoura Road, Calabasas, CA 91302 Tel: 818.871.1800 Fax: 818.871.1805 www.ixiacom.com 915-6501-01 Rev. B, July 2013 Table of Contents

More information

OKTOBER 2010 CONSOLIDATING MULTIPLE NETWORK APPLIANCES

OKTOBER 2010 CONSOLIDATING MULTIPLE NETWORK APPLIANCES OKTOBER 2010 CONSOLIDATING MULTIPLE NETWORK APPLIANCES It is possible to consolidate multiple network appliances into a single server using intelligent flow distribution, data sharing and virtualization

More information

Guidebook to MEF Certification

Guidebook to MEF Certification WHITE PAPER Guidebook to MEF Certification www.ixiacom.com Rev A September 2012, 915-6015-01 2 Table of Contents Introduction... 4 Benefits of Certification... 7 Overview... 7 Equipment Vendor... 7 Service

More information

Evaluating Wireless Broadband Gateways for Deployment by Service Provider Customers

Evaluating Wireless Broadband Gateways for Deployment by Service Provider Customers Evaluating Wireless Broadband Gateways for Deployment by Service Provider Customers Overview A leading provider of voice, video, and data services to the residential and businesses communities designed

More information

WHITE PAPER. Realizing ROI from Your Network Visibility Investment

WHITE PAPER. Realizing ROI from Your Network Visibility Investment WHITE PAPER Realizing ROI from Your Network Visibility Investment www.ixiacom.com 915-6630-01 Rev. A, March 2014 2 Table of Contents Executive Summary... 4 Introduction... 4 Network Visibility ROI... 5

More information

Analyzing Full-Duplex Networks

Analyzing Full-Duplex Networks Analyzing Full-Duplex Networks There are a number ways to access full-duplex traffic on a network for analysis: SPAN or mirror ports, aggregation TAPs (Test Access Ports), or full-duplex TAPs are the three

More information

Unified network traffic monitoring for physical and VMware environments

Unified network traffic monitoring for physical and VMware environments Unified network traffic monitoring for physical and VMware environments Applications and servers hosted in a virtual environment have the same network monitoring requirements as applications and servers

More information

WHITE PAPER. 50 versus 62.5 micron multimode fiber

WHITE PAPER. 50 versus 62.5 micron multimode fiber WHITE PAPER 50 versus 62.5 micron multimode fiber www.ixiacom.com 915-6919-01 Rev. A, July 2014 2 Table of Contents What are 50μm fiber and 62.5μm fiber?... 4 Why two standards?... 4 Which technology should

More information

Denial of Service (DOS) Testing IxChariot

Denial of Service (DOS) Testing IxChariot TEST PLAN Denial of Service (DOS) Testing IxChariot www.ixiacom.com 915-6681-01, 2005 Contents Overview of Denial of Service functionality in IxChariot...3 A brief outline of the DoS attack types supported

More information

Observer Probe Family

Observer Probe Family Observer Probe Family Distributed analysis for local and remote networks Monitor and troubleshoot vital network links in real time from any location Network Instruments offers a complete line of software

More information

Why sample when you can monitor all network traffic inexpensively?

Why sample when you can monitor all network traffic inexpensively? Why sample when you can monitor all network traffic inexpensively? endace power to see all europe P +44 1223 370 176 E eu@endace.com americas P +1 703 964 3740 E usa@endace.com asia pacific P +64 9 262

More information

Router Architectures

Router Architectures Router Architectures An overview of router architectures. Introduction What is a Packet Switch? Basic Architectural Components Some Example Packet Switches The Evolution of IP Routers 2 1 Router Components

More information

Network Management and Monitoring Software

Network Management and Monitoring Software Page 1 of 7 Network Management and Monitoring Software Many products on the market today provide analytical information to those who are responsible for the management of networked systems or what the

More information

PRODUCTS & TECHNOLOGY

PRODUCTS & TECHNOLOGY PRODUCTS & TECHNOLOGY DATA CENTER CLASS WAN OPTIMIZATION Today s major IT initiatives all have one thing in common: they require a well performing Wide Area Network (WAN). However, many enterprise WANs

More information

TIME TO RETHINK PERFORMANCE MONITORING

TIME TO RETHINK PERFORMANCE MONITORING TIME TO RETHINK PERFORMANCE MONITORING New requirements for application awareness and support for unified communications are challenging performance monitoring appliance vendors to reconsider their approach.

More information

Network Instruments white paper

Network Instruments white paper Network Instruments white paper ANALYZING FULL-DUPLEX NETWORKS There are a number ways to access full-duplex traffic on a network for analysis: SPAN or mirror ports, aggregation TAPs (Test Access Ports),

More information

WHITE PAPER. Achieving Total Traffic Visibility in Enterprise and Carrier Grade Optical Networks

WHITE PAPER. Achieving Total Traffic Visibility in Enterprise and Carrier Grade Optical Networks WHITE PAPER Achieving Total Traffic Visibility in Enterprise and Carrier Grade Optical Networks www.ixiacom.com 915-6905-01 Rev. A, July 2014 2 Table of Contents Data Access and Reliability In Modern Optical

More information

Ensuring Success in a Virtual World: Demystifying SDN and NFV Migrations

Ensuring Success in a Virtual World: Demystifying SDN and NFV Migrations Ensuring Success in a Virtual World: Demystifying SDN and NFV Migrations Get Migration Right the First Time The virtualization of traditional networks promises vast and enduring benefits if the challenges

More information

Monitoring Load Balancing in the 10G Arena: Strategies and Requirements for Solving Performance Challenges

Monitoring Load Balancing in the 10G Arena: Strategies and Requirements for Solving Performance Challenges 2011 is the year of the 10 Gigabit network rollout. These pipes as well as those of existing Gigabit networks, and even faster 40 and 100 Gbps networks are under growing pressure to carry skyrocketing

More information

Innovate, Integrate, Lead

Innovate, Integrate, Lead Innovate, Integrate, Lead Ixia s Global Solution Provider Partner Program Application Performance and Security Resilience 86 of the Fortune 100 Profitability. Brand reputation. Customer loyalty. 50 of

More information

Cyber Range Training Services

Cyber Range Training Services Cyber Range Training Services Table of Contents Train Like You Fight... 2 The Global Cyber Range Imperative... 3 Why Traditional Approaches Have Failed... 3 A Pragmatic Strategy for Arming and Training

More information

Net Optics and Cisco NAM

Net Optics and Cisco NAM When Cisco decided to break its Network Analysis Module (NAM) out of the box and into a stand-alone appliance, they turned to Net Optics for monitoring access connectivity. Cisco NAM 2200 Series Cisco

More information

Gaining Operational Efficiencies with the Enterasys S-Series

Gaining Operational Efficiencies with the Enterasys S-Series Gaining Operational Efficiencies with the Enterasys S-Series Hi-Fidelity NetFlow There is nothing more important than our customers. Gaining Operational Efficiencies with the Enterasys S-Series Introduction

More information

Bricata Next Generation Intrusion Prevention System A New, Evolved Breed of Threat Mitigation

Bricata Next Generation Intrusion Prevention System A New, Evolved Breed of Threat Mitigation Bricata Next Generation Intrusion Prevention System A New, Evolved Breed of Threat Mitigation Iain Davison Chief Technology Officer Bricata, LLC WWW.BRICATA.COM The Need for Multi-Threaded, Multi-Core

More information

Overview. Firewall Security. Perimeter Security Devices. Routers

Overview. Firewall Security. Perimeter Security Devices. Routers Overview Firewall Security Chapter 8 Perimeter Security Devices H/W vs. S/W Packet Filtering vs. Stateful Inspection Firewall Topologies Firewall Rulebases Lecturer: Pei-yih Ting 1 2 Perimeter Security

More information

Cloud Networking Services

Cloud Networking Services Cloud computing is a compelling way to deliver web-based and non-web-based applications that better utilize the physical infrastructure, while lowering costs by moving from silos of expensive customized

More information

SiteCelerate white paper

SiteCelerate white paper SiteCelerate white paper Arahe Solutions SITECELERATE OVERVIEW As enterprises increases their investment in Web applications, Portal and websites and as usage of these applications increase, performance

More information

FULL SPEED AHEAD THE IXIA CHANNEL XCELERATE PROGRAM LATIN AMERICA

FULL SPEED AHEAD THE IXIA CHANNEL XCELERATE PROGRAM LATIN AMERICA FULL SPEED AHEAD THE IIA CHANNEL CELERATE PROGRAM LATIN AMERICA 1998-2016 Ixia All Rights Reserved. Be Part of the Momentum... Nothing beats playing on a winning team. Joining Ixia s Channel celerate Partner

More information

APRIL 2010 HIGH PERFORMANCE INTRUSION PREVENTION SYSTEMS

APRIL 2010 HIGH PERFORMANCE INTRUSION PREVENTION SYSTEMS APRIL 2010 HIGH PERFORMANCE INTRUSION PREVENTION SYSTEMS A new approach to network security appliance development that promises lower overall cost, lower risk and faster time-to-market Disclaimer: This

More information

Net Optics xbalancer and McAfee Network Security Platform Integration

Net Optics xbalancer and McAfee Network Security Platform Integration Under the McAfee SIA Partner Program, Net Optics is integrating its xbalancer with the McAfee Network Security Platform (NSP). This partnership will enable mutual customers to realize the benefits of load

More information

Solving Monitoring Challenges in the Data Center

Solving Monitoring Challenges in the Data Center Solving Monitoring Challenges in the Data Center How a network monitoring switch helps IT teams stay proactive White Paper IT teams are under big pressure to improve the performance and security of corporate

More information

White Paper. Best Practices for 40 Gigabit Implementation in the Enterprise

White Paper. Best Practices for 40 Gigabit Implementation in the Enterprise White Paper Best Practices for 40 Gigabit Implementation in the Enterprise 26601 Agoura Road, Calabasas, CA 91302 Tel: 818.871.1800 Fax: 818.871.1805 www.ixiacom.com 915-6506-01 Rev. B, June 2013 2 Table

More information

WHITE PAPER. Best Practices for Network Monitoring Switch Automation

WHITE PAPER. Best Practices for Network Monitoring Switch Automation WHITE PAPER Best Practices for Network Monitoring Switch Automation www.ixiacom.com 915-6623-01 Rev. A, December 2013 2 Table of Contents Executive Summary... 4 What Is Adaptive Monitoring?... 4 Adaptive

More information

Observer Probe Family

Observer Probe Family Observer Probe Family Distributed analysis for local and remote networks Monitor and troubleshoot vital network links in real time from any location Network Instruments offers a complete line of software

More information

Building High-Performance iscsi SAN Configurations. An Alacritech and McDATA Technical Note

Building High-Performance iscsi SAN Configurations. An Alacritech and McDATA Technical Note Building High-Performance iscsi SAN Configurations An Alacritech and McDATA Technical Note Building High-Performance iscsi SAN Configurations An Alacritech and McDATA Technical Note Internet SCSI (iscsi)

More information

Diagnosing the cause of poor application performance

Diagnosing the cause of poor application performance Diagnosing the cause of poor application performance When it comes to troubleshooting application performance issues, there are two steps you can take to make diagnosis easier, faster and more accurate.

More information

Benefits. Product Overview. There is nothing more important than our customers. DATASHEET

Benefits. Product Overview. There is nothing more important than our customers. DATASHEET DATASHEET Security Information & Event Manager (SIEM) Compliance through Security Information and Event Management, Log Management, and Network Behavioral Analysis Product Overview Delivers fast, accurate

More information

OptiView. Total integration Total control Total Network SuperVision. Network Analysis Solution. No one knows the value of an

OptiView. Total integration Total control Total Network SuperVision. Network Analysis Solution. No one knows the value of an No one knows the value of an Network Analysis Solution Total integration Total control Total Network SuperVision integrated solution better than network engineers and Fluke Networks. Our Network Analysis

More information

OptiView. Total integration Total control Total Network SuperVision. Network Analysis Solution. No one knows the value of an

OptiView. Total integration Total control Total Network SuperVision. Network Analysis Solution. No one knows the value of an No one knows the value of an Network Analysis Solution Total integration Total control Total Network SuperVision integrated solution better than network engineers and Fluke Networks. Our Network Analysis

More information

EBOOK. Top Five Ways To Enhance Your Cisco Environment

EBOOK. Top Five Ways To Enhance Your Cisco Environment EBOOK Top Five Ways To Enhance Your Cisco Environment www.ixiacom.com 915-6880-01 Rev. A, January 2014 2 Table of Contents The Secrets You Will Want To Know... 4 Five Ways to Say Eureka!... 4 The Top Five

More information

Fail-Safe IPS Integration with Bypass Technology

Fail-Safe IPS Integration with Bypass Technology Summary Threats that require the installation, redeployment or upgrade of in-line IPS appliances often affect uptime on business critical links. Organizations are demanding solutions that prevent disruptive

More information

Firewalls and VPNs. Principles of Information Security, 5th Edition 1

Firewalls and VPNs. Principles of Information Security, 5th Edition 1 Firewalls and VPNs Principles of Information Security, 5th Edition 1 Learning Objectives Upon completion of this material, you should be able to: Understand firewall technology and the various approaches

More information

Chapter 15. Firewalls, IDS and IPS

Chapter 15. Firewalls, IDS and IPS Chapter 15 Firewalls, IDS and IPS Basic Firewall Operation The firewall is a border firewall. It sits at the boundary between the corporate site and the external Internet. A firewall examines each packet

More information

Extending Network Visibility by Leveraging NetFlow and sflow Technologies

Extending Network Visibility by Leveraging NetFlow and sflow Technologies Extending Network Visibility by Leveraging and sflow Technologies This paper shows how a network analyzer that can leverage and sflow technologies can provide extended visibility into enterprise networks

More information

Benefits. Product Overview. There is nothing more important than our customers. DATASHEET

Benefits. Product Overview. There is nothing more important than our customers. DATASHEET DATASHEET Security Information & Event Manager (SIEM) Compliance through Security Information and Event Management, Log Management, and Network Behavioral Analysis Product Overview Delivers fast, accurate

More information

Silver Peak s Virtual Acceleration Open Architecture (VXOA)

Silver Peak s Virtual Acceleration Open Architecture (VXOA) Silver Peak s Virtual Acceleration Open Architecture (VXOA) A FOUNDATION FOR UNIVERSAL WAN OPTIMIZATION The major IT initiatives of today data center consolidation, cloud computing, unified communications,

More information

Architecture Overview

Architecture Overview Architecture Overview Design Fundamentals The networks discussed in this paper have some common design fundamentals, including segmentation into modules, which enables network traffic to be isolated and

More information

How to Build a Massively Scalable Next-Generation Firewall

How to Build a Massively Scalable Next-Generation Firewall How to Build a Massively Scalable Next-Generation Firewall Seven measures of scalability, and how to use them to evaluate NGFWs Scalable is not just big or fast. When it comes to advanced technologies

More information

Deploying Probes and Analyzers in an Enterprise Environment

Deploying Probes and Analyzers in an Enterprise Environment Network Instruments White Paper Deploying Probes and Analyzers in an Enterprise Environment As an IT manager, you need visibility into every corner of the network, from the edge to the core. A distributed

More information

High-Performance IP Service Node with Layer 4 to 7 Packet Processing Features

High-Performance IP Service Node with Layer 4 to 7 Packet Processing Features UDC 621.395.31:681.3 High-Performance IP Service Node with Layer 4 to 7 Packet Processing Features VTsuneo Katsuyama VAkira Hakata VMasafumi Katoh VAkira Takeyama (Manuscript received February 27, 2001)

More information

Optimize Your Microsoft Infrastructure Leveraging Exinda s Unified Performance Management

Optimize Your Microsoft Infrastructure Leveraging Exinda s Unified Performance Management Optimize Your Microsoft Infrastructure Leveraging Exinda s Unified Performance Management Optimize Your Microsoft Infrastructure Leveraging Exinda s Unified Performance Management Executive Summary Organizations

More information

Efficient Network Monitoring Access

Efficient Network Monitoring Access Abstract Organizations that rely on the reliability, security, and performance of their networks can no longer afford to wait for outages or security breaches to occur before installing test access points.

More information

Ixia Director TM. Powerful, All-in-One Smart Filtering with Ultra-High Port Density. Efficient Monitoring Access DATA SHEET

Ixia Director TM. Powerful, All-in-One Smart Filtering with Ultra-High Port Density. Efficient Monitoring Access DATA SHEET Ixia Director TM Powerful, All-in-One Smart Filtering with Ultra-High Port Density The Ixia Director TM is a smart filtering appliance that directs traffic of interest to your monitoring tools. Now you

More information

Network Instruments white paper

Network Instruments white paper Network Instruments white paper EXTENDING NETWORK VISIBILITY BY LEVERAGING NETFLOW AND SFLOW TECHNOLOGIES This paper shows how a network analyzer that can leverage and sflow technologies can provide extended

More information

NetFlow Performance Analysis

NetFlow Performance Analysis NetFlow Performance Analysis Last Updated: May, 2007 The Cisco IOS NetFlow feature set allows for the tracking of individual IP flows as they are received at a Cisco router or switching device. Network

More information

Securing the Intelligent Network

Securing the Intelligent Network WHITE PAPER Securing the Intelligent Network Securing the Intelligent Network New Threats Demand New Strategies The network is the door to your organization for both legitimate users and would-be attackers.

More information

tap into your network product brochure

tap into your network product brochure tap into your network product brochure Leadership Net Optics is dedicated to helping customers obtain the highest efficiency from their networks. Our products help Network IT and security professionals

More information

Product Summary Report

Product Summary Report Product Summary Report March 2008 S Report 080330 olera Networks engaged Miercom, to independently evaluate the performance of its Model DS5100 deep packet capture and storage appliance. Testing was conducted

More information

HIGH-PERFORMANCE SOLUTIONS FOR MONITORING AND SECURING YOUR NETWORK A Next-Generation Intelligent Network Access Guide OPEN UP TO THE OPPORTUNITIES

HIGH-PERFORMANCE SOLUTIONS FOR MONITORING AND SECURING YOUR NETWORK A Next-Generation Intelligent Network Access Guide OPEN UP TO THE OPPORTUNITIES HIGH-PERFORMANCE SOLUTIONS FOR MONITORING AND SECURING YOUR NETWORK A Next-Generation Intelligent Network Access Guide OPEN UP TO THE OPPORTUNITIES Net Optics solutions dramatically increase reliability,

More information

CISCO INFORMATION TECHNOLOGY AT WORK CASE STUDY: CISCO IOS NETFLOW TECHNOLOGY

CISCO INFORMATION TECHNOLOGY AT WORK CASE STUDY: CISCO IOS NETFLOW TECHNOLOGY CISCO INFORMATION TECHNOLOGY AT WORK CASE STUDY: CISCO IOS NETFLOW TECHNOLOGY CISCO INFORMATION TECHNOLOGY SEPTEMBER 2004 1 Overview Challenge To troubleshoot capacity and quality problems and to understand

More information

whitepaper Network Traffic Analysis Using Cisco NetFlow Taking the Guesswork Out of Network Performance Management

whitepaper Network Traffic Analysis Using Cisco NetFlow Taking the Guesswork Out of Network Performance Management whitepaper Network Traffic Analysis Using Cisco NetFlow Taking the Guesswork Out of Network Performance Management Taking the Guesswork Out of Network Performance Management EXECUTIVE SUMMARY Many enterprise

More information

Netsweeper Whitepaper

Netsweeper Whitepaper Netsweeper Inc. Corporate Headquarters 104 Dawson Road Suite 100 Guelph, ON, Canada N1H 1A7 CANADA T: +1 (519) 826 5222 F: +1 (519) 826 5228 Netsweeper Whitepaper Deploying Netsweeper Internet Content

More information

Extending Network Visibility by Leveraging NetFlow and sflow Technologies

Extending Network Visibility by Leveraging NetFlow and sflow Technologies Extending Network Visibility by Leveraging and sflow Technologies This paper shows how a network analyzer that can leverage and sflow technologies can provide extended visibility into enterprise networks

More information

Firewalls. Securing Networks. Chapter 3 Part 1 of 4 CA M S Mehta, FCA

Firewalls. Securing Networks. Chapter 3 Part 1 of 4 CA M S Mehta, FCA Firewalls Securing Networks Chapter 3 Part 1 of 4 CA M S Mehta, FCA 1 Firewalls Learning Objectives Task Statements 1.3 Recognise function of Telecommunications and Network security including firewalls,..

More information

Enabling Cloud Architecture for Globally Distributed Applications

Enabling Cloud Architecture for Globally Distributed Applications The increasingly on demand nature of enterprise and consumer services is driving more companies to execute business processes in real-time and give users information in a more realtime, self-service manner.

More information

Open Source in Government: Delivering Network Security, Flexibility and Interoperability

Open Source in Government: Delivering Network Security, Flexibility and Interoperability W H I T E P A P E R Open Source in Government: Delivering Network Security, Flexibility and Interoperability Uncompromising performance. Unmatched flexibility. Introduction Amid a growing emphasis on transparency

More information

The Future Of The Firewall

The Future Of The Firewall SECURITY The Future Of The Firewall Jeff Wilson Jeff Wilson is principal analyst, VPNs and security with Infonetics Research (www.infonetics.com), specializing in firewalls, IDS/IPS, VPNs, integrated security

More information

Observer Analysis Advantages

Observer Analysis Advantages In-Depth Analysis for Gigabit and 10 Gb Networks For enterprise management, gigabit and 10 Gb Ethernet networks mean high-speed communication, on-demand systems, and improved business functions. For enterprise

More information

Proven techniques and best practices for managing infrastructure changes

Proven techniques and best practices for managing infrastructure changes Proven techniques and best practices for managing infrastructure changes When a business expands an existing facility, adds a new location, incorporates an influx of new users, or upgrades an existing

More information

Cisco Integrated Services Routers Performance Overview

Cisco Integrated Services Routers Performance Overview Integrated Services Routers Performance Overview What You Will Learn The Integrated Services Routers Generation 2 (ISR G2) provide a robust platform for delivering WAN services, unified communications,

More information

ETM System SIP Trunk Support Technical Discussion

ETM System SIP Trunk Support Technical Discussion ETM System SIP Trunk Support Technical Discussion Release 6.0 A product brief from SecureLogix Corporation Rev C SIP Trunk Support in the ETM System v6.0 Introduction Today s voice networks are rife with

More information

Sygate Secure Enterprise and Alcatel

Sygate Secure Enterprise and Alcatel Sygate Secure Enterprise and Alcatel Sygate Secure Enterprise eliminates the damage or loss of information, cost of recovery, and regulatory violation due to rogue corporate computers, applications, and

More information

I/O Virtualization Using Mellanox InfiniBand And Channel I/O Virtualization (CIOV) Technology

I/O Virtualization Using Mellanox InfiniBand And Channel I/O Virtualization (CIOV) Technology I/O Virtualization Using Mellanox InfiniBand And Channel I/O Virtualization (CIOV) Technology Reduce I/O cost and power by 40 50% Reduce I/O real estate needs in blade servers through consolidation Maintain

More information

How Solace Message Routers Reduce the Cost of IT Infrastructure

How Solace Message Routers Reduce the Cost of IT Infrastructure How Message Routers Reduce the Cost of IT Infrastructure This paper explains how s innovative solution can significantly reduce the total cost of ownership of your messaging middleware platform and IT

More information

Advanced Core Operating System (ACOS): Experience the Performance

Advanced Core Operating System (ACOS): Experience the Performance WHITE PAPER Advanced Core Operating System (ACOS): Experience the Performance Table of Contents Trends Affecting Application Networking...3 The Era of Multicore...3 Multicore System Design Challenges...3

More information

Hosting Solutions Made Simple. Managed Services - Overview and Pricing

Hosting Solutions Made Simple. Managed Services - Overview and Pricing Hosting Solutions Made Simple Managed Services - Overview and Pricing NETRACKservers Internet Security Package: NETRACKservers's Internet Security Package is an ideal security service for business that

More information

Diagnosing the cause of poor application performance

Diagnosing the cause of poor application performance Diagnosing the cause of poor application performance When it comes to troubleshooting application performance issues, there are two steps you can take to make diagnosis easier, faster and more accurate.

More information