VSS - Game Changing Technology Dean Beaver Vice President of Sales
Danaher Business Platforms Test & Measurement $3.0B Environmental $3.3B Dental $2.1B Life Sciences & Diagnostics $6.8B Industrial Technologies $2.3B 2012 Revenue ($17.5B) 2
Danaher..The Best Kept Secret 3
What is a Packet Broker? More Tools Need Access Visibility Scalability Cyber Security Tool Longevity Optimize Efficiency NPB s NPB s : Fault-tolerant Design, 100% Uptime, Unparalleled Scale The use of network packet brokers (NPBs) allows better visibility into and longevity of tool investments spanning network application monitoring (NPM), application performance monitoring (APM), security, network forensics and other monitoring technologies that require packet data. Gartner (4/2012) packet brokers solve the visibility challenge by easily scaling with your network and delivering only the traffic you need to see. 4
Evolution of NPB Growing Need Business Intelligence Business Intelligence Business Intelligence Analyzer Tools NPB Presentation Analytics Data Processing Optimization Reassembly Grooming Access 3 2 Analyzer performance optimized, focus on core analytic functions Shifting packet optimization functions toward NPB Presentation Analytics Data Processing Optimization Reassembly Grooming Access Packets 1 Analyzer + NPB = Total Solution Packets Packets Today Future NPB Improving Intelligence, Lower TCO, Better ROI 5
Value of a Packet Broker Performance & Security Monitoring Applications Data Recorder Lawful Interception APM VoIP Analyzer IPS DLP Optimize Tools Reduce tool clutter Capture Groom and Filter Intelligence Optimization Fabric Better Visibility Scalability Fault Tolerence Infrastructure Service Provider Apps Enterprise Data Center Media Conversion Better NW Access Database DC Core
VSS is a Different NPB Solution Performance & Security Monitoring Applications Data Recorder Lawful Interception APM VoIP Analyzer IPS DLP What We Do NPB +, Any Packet to Anywhere in your network What We Enable E2E visibility for converged networks. Big Data problem. Packet Brokers Active/in-line monitoring and threat protection High availability, Self-Healing Why We Win Infrastructure Service Provider Apps Enterprise Data Center Unparalleled scalability, Virtual 4000+ port chassis Game changing technologies System approach vs. Silo Database DC Core Day 1 ROI
The NPB Opportunity Growth across enterprise segments 22%+ CAGR Total NPB ~$800M Service Provider Mobile Service Assurance VOIP/IPTV Monitoring Bandwidth Optimization (55%)* Enterprise Application / Performance Mgmt Latency Monitoring VOIP Monitoring WAN Optimization (19%)* Performance Driven ~$360M 2012 2017 Core NPB Lawful Interception Policy Control DDOS Prevention Data Compliance (5%)* Forensics Intrusion Prevention Web Security Malware Protection Data Compliance (21%)* Security Driven NPB+ (virtualization, SDN, Direct to Storage) * Indicates distribution of VSS 2013 YTD Revenue Served available market is growing at 22%, while VSS is growing at over 60% 8
Robust Partner Ecosystem Service Provider Security / DPI Enterprise Security Enterprise A/NPM Monitoring/ Security Applications Packet Brokers (NPBs) Infrastructure Internal Use Only 9
Customer Value 1 st Gen TAP Distributed TAP Packet Broker VSS Monitoring = Technology Leadership Broadest Feature Set Unparalleled Scalability Tool Chaining vspool (Direct to Storage) vmesh (Self-healing Fabric) Port HW Acceleration VSS Unique Bypass Taps De-Duplication Microburst Protection Protocol Stripping Time/Port Stamping L2-L7 Grooming Active, Inline Aggregation vnetconnect (Virtual) Dynamic DPI Fragment Reassembly IMSI Balancing GTP Load Balance vcapacity vslice BASIC INTERMEDIATE ADVANCED VSS Monitoring is the only NPB maker to use Port-based Hardware Acceleration, which lets customers achieve higher performance rates for a wider range of use cases. 10
Traditionally, the audit trail is Spooled directly to hard drives on tools Monitoring Tools DLP IPS APM NPM Forensics Traffic Delivery Platform Communications Infrastructure 11
Write to Disk vspool Traditional Probe Deployment Multiple Probe Types Proprietary Hardware vspool Implementation Vendor Neutral Standard Infrastructure Monitoring Tools DLP IPS APM NPM Forensics Traffic Delivery Platform Communications Infrastructure Solution 1. Spool network data (PCAP) directly to common storage infrastructure 2. Centralize storage - Store once, analyze many 3. Virtualize monitoring tools. 4. Scale beyond on-board storage Existing Storage Servers Applications Stock exchange Data compliance & audit forensics Subscriber intelligence & data monetization 12
Use Case 1: VSS Node to NAS 13
Security & Monitoring Infrastructure Today Advanced Persistent Threat Distributed Denial of Service ACTIVE TOOLS NextGen Fire Wall Secure Web Gateway Intrusion Prevention System Security Event & Incidental Management Behavior Analysis PASSIVE TOOLS Data Loss Prevention Forensics Intrusion Detection System Application Performance Monitor Lawful Intercept Customer Security & Forensics Tools compete for network access Unable to keep up with network speeds Add unnecessary complexity and risk Databases Apps DC Core Branch A Branch B DATACENTER 14
With VSS - Simplified Design and Deployment for Scalable Fail-Safe Security Optimize Tool Performance Speed/Media conversion L2-L7 traffic grooming Load balancing / Asymmetric Routing support Transparent SSL Proxy NGIPS Anti APT / ATA Security Analytics Security Service Assurance High availability for tools Fault tolerance for tools & networks Custom health-checks Thresholds, alerts & auto triggers Defense-in Depth-Architecture Security-in-Series Security Service Chaining Add defense layers on-demand Minimize network re-instrumentation Decrypt Once; Feed Many tools SSL Clear Txt Packet Brokering (NPB) vprotector Filter & Flow Balancing Filter & Flow Balancing (Passive) Filter Segment A Segment A Segment B Segment B 16
vmesh A Unique Fabric Approach to NPB ACTIVE TOOLS PASSIVE TOOLS Distributed Denial of Service Secure Web Gateway Security Event & Incidental Management Forensics Application Performance Monitor Value Proposition: Advanced Persistent Threat NextGen Fire Wall Intrusion Prevention System Behavior Analysis Data Loss Prevention Intrusion Detection System Lawful Intercept Optimize traffic delivery to any & all security monitoring tools Centralize monitoring tools NETWORK PACKET BROKERS Support multiple 1/10G tools in multiple 1/10/40G segments Full network visibility Customer Unlimited scalability Self-healing data delivery fabric Maximize ROI from tool investments Apps Branch A DC Core Databases Branch B DATACENTER 17
Silo vs. System View of the Growing the Tools 18
Silo vs. System View of the Growing the 19
vstack over IP Cloud-Ready Monitoring Challenges Tools silos Tools congestion Management overhead (Opex) Visibility across network domains Need to ensure SLA of cloud services Datacenter B Monitoring Tools NOC Datacenter A VSS Solution Centralized tool farm Secure data encryption (AES) Scalable to any number VSS devices Time sync over NTP, GPS, PTP Probeless monitoring across domains/wan Branch Site WAN Cloud Services (Storage, Security, Email, Games, Enterprise Apps, etc.) Corporate Client HQ 20
vmc : Manage from -wide Perspective Manage all VSS NPBs Bulk software updates Drag & drop Topology & rule mgmt from single pane Any location Virtualize Traffic access Vmware and Cisco Benefits: Simplified device mgmt / lower TCO All VSS brokers supported & incorporated in topology Any packet anywhere, anytime 22
Total Visibility with vnetconnect Agentless visibility into East-West traffic Uses virtual server to connect traffic to monitoring tools outside venvironment Programs vmesh traffic grooming and mapping for seamless SDM VMware and Cisco Nexus 1000 Virtual Workloads 23
Available now VSS vmc Integration with VMware vcenter
VSS Game Changing Technology Tool Chaining vspool (Direct to Storage) vmesh (Self-healing Fabric) Port HW Acceleration vnetconnect (Virtual) Dynamic DPI Fragment Reassembly IMSI Balancing GTP Load Balance vcapacity vslice Value Proposition: Write traffic once, read by many tools Centralized data collection capability Tool visibility into remote locations/traffic without remote tools High availability enterprise wide, Self-healing Maximize ROI from tool investments (1GB tool in 10GB NW) Inline/Passive interchangeability and line rate grooming Virtual traffic visibility without an instance or agent Virtual chassis with over 4000 ports and growing 25