SlideShare a Scribd company logo
1© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
IXIA VISIBILITY ARCHITECTURE
Eliminating Blind spots
Юлий Явич, IXIA
2© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
of the
Fortune 100
of the
top 50 carriers
of the
top 15 NEMs
74
45
15
Customer
Focused
Innovation
Enterprise
Carriers/
Service Providers
NEMs
2014 Industry-first ATI security solution
2014 Industry-first virtual tap
2014 Industry-first 400GbE test solution
3© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
IXIA SOLUTION PORTFOLIO
Across the Infrastructure
Across ALL Platforms
Flex Taps,
iBypass,
Virtual Taps
802.11ac,
MU-MIMO
PerfectStorm
BPS vEPC
IxLoad/VE
IxNetwork/VE
Multis SDN
Threat
ARMOR,
ATI
Mobile Endpoint Network Data Center Cloud
NTO, Vision ONE,
Hawkeye,
xStream40,
Control Tower
TEST SECURITY VISIBILITY
6© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | 6© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
INTELLIGENT VISIBILITY
7© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
Clients
INTELLIGENT VISIBILITY - CHALLENGES
Server
Network
TapSwitch Switch
How to:
• Get data access for tools?
• Network taps instead of SPAN
ports?
Network
Tap
Network
Tap
Tool 1 Tool 2 Tool N
How to:
• Deal with limited tool ports?
• Scale tool capacity?
• Filter traffic to tools?
• Manage access for each tool?
8© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
Network
Operations
Application
Operations
Security
Admin
Forensics
INTELLIGENT VISIBILITY
End-to-End Data Access and Distribution
Switch
Switch
Servers
THE DATA CENTER
Taps
Taps
Taps
Network
Packet
Brokers
• Aggregation
• Filtering
• Load Balancing
• SSL Decryption
• NetFlow
1G
10G
40G
9© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
APPLICATIONS AND NETWORK PERFORMANCE TOOLS
10© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
SECURITY TOOLS
13© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
INTELLIGENT PACKET PROCESSING
All unique frames going to
10.0.0.0/8
Only the first 128 bytes of TCP Port
25 frames
Hardware AFM
NPB
Adv. Packet Processing
Advanced Packet Processing (AFM) Features
• Deduplication
• Header stripping
• Trimming
• Tunnel Termination
• Data Masking
• Timestamping
• Burst Protection
21© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
ENTERPRISE – INTELLIGENT APPLICATION PROCESSING
• ATI Processor (ATIP) - Context-rich Application Visibility
• Application forwarding based on application, geography, and RegEx matching
• Real-time dashboard
• Rich NetFlow / IPFIX generation
– Device OS
– Browser
– Carrier BGP AS#
– Geolocation
• Data Masking
• Stateful SSL decryption
All traffic from Georgia
All voice traffic from HTC
Ones
Someone from remote office
Skype for business monitor
NPB –
App Brokering
Meta Data
App Filtering
26© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
ATIP ENABLES SSL INSIGHT
• Passive decryption – no impact on application performance
• Fully compatible with all other ATIP features:
Rich Netflow/IPFIX
Data Masking
Geolocation
• Easy setup – just import server certificate & key
• All popular key exchange & ciphers:
RSA & DH Key Exchange
SHA1/521/384/256/224
MD5
• Application Filtering
• Handset/workstation type
• Browser identification
• 3DES
• RC4
• AES
• ECC (Elliptic Curve)
• Encryption details reported over Netflow Hardware Encryption Offload
27© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
SPY GLASS ACTIVE SSL
28© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
NTO FAMILY
NTO 7300
Vision ONE
• 48x1/10G & 4x40G
• Advanced Features
• ATI Processor
> Application layer filtering
> SSL Encryption
> Netflow Generation
• Inline Support
• Load Balancing
• GUI
• 1/10/40/100G Interfaces
• Advanced Features
• ATI Processor
> Application layer filtering
> SSL Encryption
> Netflow Generation
• Packet Capture
• Load Balancing
• GUI
31© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
General Features
> Full Duplex Mode
> Passes all traffic (including errors) from all
layers for comprehensive Troubleshooting
> Regeneration TAP
> No IP address is needed
> Redundant power ensures monitoring uptime
TP-CU3; TP-CU3-ZD
Network A Network B
Mon A
Mon B
TX
TXRX
RX
TX
TX
FULL DUPLEX COPPER TAP
32© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
- 1G/10G/40G/100G (LR & ER)
> Single Mode with LC Connector
-
1G (SX)
> Multi Mode with LC Connector
-
10G (SR)
> Multi Mode with LC Connector
- 40G (SR4 / Cisco Bidi/ MR4)
- 100G (SR10)
> Multi Mode with MTP Connector
IXIA FLEXTAP
34© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
GETTING VIRTUAL TRAFFIC TO MONITORING TOOLS
38© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
CUSTOMER CASE STUDY
International Bank
Customer
• Leading International Bank
Need
• Massive volumes or raw application traffic to monitor
• Control traffic inspection costs
• Improve overall Incident Response Team effectiveness
Results
• Deployed Ixia Intelligent Visibility solutions including NTO 7300
• Reduced monitored traffic using advanced filters of deduplication, packet slicing, IPs, VLANs
• VLAN marking and Time stamping to monitoring tools
• Reduced planned CapEx investments
39© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
CUSTOMER CASE STUDY
Large Hi-tech Company
Customer
• Large L2/3 manufacturer
Need
• Control traffic inspection costs
• Layer 7 filtering to Nectar tool
Results
• Deployed Ixia Intelligent Visibility solution including Vision One
• Reduced monitored traffic using deduplication
• Provided Skype for business specific traffic to Nectar tool
• Reduced planned CapEx investments
40© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
TECHNOLOGY ECOSYSTEM
TrafficREWIND is a unique patent pending solution that uses NetFlow metadata to regenerate the
dynamics of production networks within BreakingPoint test beds
Solution Overview
42© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | 42© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
RESILIENT SECURITY
43© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
RESILIENT SECURITY
Serial Deployments of Inline Security Tools is Dangerous
Switch
Server
Server
Switch
Switch
Switch
 Very complex operationally
 Single points of failure
 Administrative tension
 Expensive to scale
44© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
Inline
Security
Tool Farm
RESILIENT SECURITY
A More Detailed View of a Resilient Security Framework
Switch
Server
Switch
Inline Security
Tool Farm
Server
Switch Switch
Bypass Switch
Bypass Switch
Network Packet
Brokers (HA)
Out of Band
Sandboxing
Monitored Tool Links via Heartbeat Packets
Threat Intelligence
Gateway
46© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
INLINE & MONITORING TOGETHER
Inline Monitoring
Inline
• IPS (multiple vendors)
Out-of-band Monitoring
• Data logging
49© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
WORLD-CLASS GLOBAL SUPPORT
Expert team of
>100 engineers
Proven track record
of superior support
Always-on
24x7 coverage
Best-in-class
support tools
50© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
WE MAKE
APPLICATIONS
STRONGER

More Related Content

What's hot

What's hot (20)

Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
Cisco Connect Toronto 2017 - NFV/SDN Platform for Orchestrating Cloud and vBr...
 
Cisco Connect Montreal 2017 - Mise à Jour UCS et Hyperflex
Cisco Connect Montreal 2017 - Mise à Jour UCS et HyperflexCisco Connect Montreal 2017 - Mise à Jour UCS et Hyperflex
Cisco Connect Montreal 2017 - Mise à Jour UCS et Hyperflex
 
Network Function Virtualization (NFV) using IOS-XR
Network Function Virtualization (NFV) using IOS-XRNetwork Function Virtualization (NFV) using IOS-XR
Network Function Virtualization (NFV) using IOS-XR
 
Simplifying Cloud Adoption
Simplifying Cloud AdoptionSimplifying Cloud Adoption
Simplifying Cloud Adoption
 
Gain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC NetworkingGain Insight and Programmability with Cisco DC Networking
Gain Insight and Programmability with Cisco DC Networking
 
Развитие решений по коммутации в корпоративных сетях Cisco
Развитие решений по коммутации в корпоративных сетях CiscoРазвитие решений по коммутации в корпоративных сетях Cisco
Развитие решений по коммутации в корпоративных сетях Cisco
 
Data models-and-automation-jp
Data models-and-automation-jpData models-and-automation-jp
Data models-and-automation-jp
 
Meraki Cloud Networking Workshop
Meraki Cloud Networking WorkshopMeraki Cloud Networking Workshop
Meraki Cloud Networking Workshop
 
NFV Cloud DataCenter Adaptation & Tobe evolution ways
NFV Cloud DataCenter Adaptation & Tobe evolution waysNFV Cloud DataCenter Adaptation & Tobe evolution ways
NFV Cloud DataCenter Adaptation & Tobe evolution ways
 
Security and Virtualization in the Data Center
Security and Virtualization in the Data CenterSecurity and Virtualization in the Data Center
Security and Virtualization in the Data Center
 
Cisco Connect Toronto 2017 - Model-driven Telemetry
Cisco Connect Toronto 2017 - Model-driven TelemetryCisco Connect Toronto 2017 - Model-driven Telemetry
Cisco Connect Toronto 2017 - Model-driven Telemetry
 
Innovations in the Enterprise Routing & Switching Space
Innovations in the Enterprise Routing & Switching SpaceInnovations in the Enterprise Routing & Switching Space
Innovations in the Enterprise Routing & Switching Space
 
10G/40G gen to 25G/100G gen, and go forward (HPVI community meetup)
10G/40G gen to 25G/100G gen, and go forward (HPVI community meetup)10G/40G gen to 25G/100G gen, and go forward (HPVI community meetup)
10G/40G gen to 25G/100G gen, and go forward (HPVI community meetup)
 
Presentation asa 5585-x next generation multi-service adaptive security app...
Presentation   asa 5585-x next generation multi-service adaptive security app...Presentation   asa 5585-x next generation multi-service adaptive security app...
Presentation asa 5585-x next generation multi-service adaptive security app...
 
Putting firepower into the next generation firewall
Putting firepower into the next generation firewallPutting firepower into the next generation firewall
Putting firepower into the next generation firewall
 
Extreme fabric connect
Extreme fabric connectExtreme fabric connect
Extreme fabric connect
 
Cisco Spark Hybrid Services Architectural Design
Cisco Spark Hybrid Services Architectural DesignCisco Spark Hybrid Services Architectural Design
Cisco Spark Hybrid Services Architectural Design
 
Catalyst 6500 ASA Service Module
Catalyst 6500 ASA Service ModuleCatalyst 6500 ASA Service Module
Catalyst 6500 ASA Service Module
 
Enterprise Networks - Cisco Digital Network Architecture - Introducing the Ne...
Enterprise Networks - Cisco Digital Network Architecture - Introducing the Ne...Enterprise Networks - Cisco Digital Network Architecture - Introducing the Ne...
Enterprise Networks - Cisco Digital Network Architecture - Introducing the Ne...
 
TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6
TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6
TechWiseTV Workshop: Cisco Catalyst 9100 Access Points for Wi-Fi 6
 

Similar to IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots

Palo_Alto_Networks_Cust_June_2009.ppt
Palo_Alto_Networks_Cust_June_2009.pptPalo_Alto_Networks_Cust_June_2009.ppt
Palo_Alto_Networks_Cust_June_2009.ppt
PatrickAng14
 

Similar to IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots (20)

Vision one-customer
Vision one-customerVision one-customer
Vision one-customer
 
100%-ный контроль для 100%-ной безопасности
100%-ный контроль для 100%-ной безопасности100%-ный контроль для 100%-ной безопасности
100%-ный контроль для 100%-ной безопасности
 
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...Cisco Connect Halifax 2018   Understanding Cisco's next generation sd-wan sol...
Cisco Connect Halifax 2018 Understanding Cisco's next generation sd-wan sol...
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
 
Mạng chuyển mạch thế hệ mới
Mạng chuyển mạch thế hệ mớiMạng chuyển mạch thế hệ mới
Mạng chuyển mạch thế hệ mới
 
Cisco connect winnipeg 2018 gain insight and programmability with cisco dc ...
Cisco connect winnipeg 2018   gain insight and programmability with cisco dc ...Cisco connect winnipeg 2018   gain insight and programmability with cisco dc ...
Cisco connect winnipeg 2018 gain insight and programmability with cisco dc ...
 
Understanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN SolutionUnderstanding Cisco Next Generation SD-WAN Solution
Understanding Cisco Next Generation SD-WAN Solution
 
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WANCisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
Cisco Connect Vancouver 2017 - Understanding Cisco next gen SD-WAN
 
Understanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN TechnologyUnderstanding Cisco’ Next Generation SD-WAN Technology
Understanding Cisco’ Next Generation SD-WAN Technology
 
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
Cisco connect montreal 2018 sd wan - delivering intent-based networking to th...
 
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with ViptelaUnderstanding Cisco’s Next Generation SD-WAN Solution with Viptela
Understanding Cisco’s Next Generation SD-WAN Solution with Viptela
 
Disaggregation, automation and autonomy in optical networking
Disaggregation, automation and autonomy in optical networkingDisaggregation, automation and autonomy in optical networking
Disaggregation, automation and autonomy in optical networking
 
Palo_Alto_Networks_Cust_June_2009.ppt
Palo_Alto_Networks_Cust_June_2009.pptPalo_Alto_Networks_Cust_June_2009.ppt
Palo_Alto_Networks_Cust_June_2009.ppt
 
OmniSwitch 6860/E Overview
OmniSwitch 6860/E Overview OmniSwitch 6860/E Overview
OmniSwitch 6860/E Overview
 
Secure Connectivity on Every Network Layer
Secure Connectivity on Every Network LayerSecure Connectivity on Every Network Layer
Secure Connectivity on Every Network Layer
 
TechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WANTechWiseTV Workshop: Cisco SD-WAN
TechWiseTV Workshop: Cisco SD-WAN
 
VMworld 2013: Network Function Virtualization in the Cloud: Case for Enterpri...
VMworld 2013: Network Function Virtualization in the Cloud: Case for Enterpri...VMworld 2013: Network Function Virtualization in the Cloud: Case for Enterpri...
VMworld 2013: Network Function Virtualization in the Cloud: Case for Enterpri...
 
Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...Extend mobility to remote branch networks with Aruba's new cloud services con...
Extend mobility to remote branch networks with Aruba's new cloud services con...
 
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
The Hitch-Hikers Guide to Data Centre Virtualization and Workload Consolidation:
 
 Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation Network Innovations Driving Business Transformation
 Network Innovations Driving Business Transformation
 

More from Cisco Russia

More from Cisco Russia (20)

Service portfolio 18
Service portfolio 18Service portfolio 18
Service portfolio 18
 
История одного взлома. Как решения Cisco могли бы предотвратить его?
История одного взлома. Как решения Cisco могли бы предотвратить его?История одного взлома. Как решения Cisco могли бы предотвратить его?
История одного взлома. Как решения Cisco могли бы предотвратить его?
 
Об оценке соответствия средств защиты информации
Об оценке соответствия средств защиты информацииОб оценке соответствия средств защиты информации
Об оценке соответствия средств защиты информации
 
Обзор Сервисных Услуг Cisco в России и странах СНГ.
Обзор Сервисных Услуг Cisco в России и странах СНГ.Обзор Сервисных Услуг Cisco в России и странах СНГ.
Обзор Сервисных Услуг Cisco в России и странах СНГ.
 
Клиентские контракты на техническую поддержку Cisco Smart Net Total Care
Клиентские контракты на техническую поддержку Cisco Smart Net Total CareКлиентские контракты на техническую поддержку Cisco Smart Net Total Care
Клиентские контракты на техническую поддержку Cisco Smart Net Total Care
 
Cisco Catalyst 9000 series
Cisco Catalyst 9000 series Cisco Catalyst 9000 series
Cisco Catalyst 9000 series
 
Cisco Catalyst 9500
Cisco Catalyst 9500Cisco Catalyst 9500
Cisco Catalyst 9500
 
Cisco Catalyst 9400
Cisco Catalyst 9400Cisco Catalyst 9400
Cisco Catalyst 9400
 
Cisco Umbrella
Cisco UmbrellaCisco Umbrella
Cisco Umbrella
 
Cisco Endpoint Security for MSSPs
Cisco Endpoint Security for MSSPsCisco Endpoint Security for MSSPs
Cisco Endpoint Security for MSSPs
 
Cisco FirePower
Cisco FirePowerCisco FirePower
Cisco FirePower
 
Профессиональные услуги Cisco для Software-Defined Access
Профессиональные услуги Cisco для Software-Defined AccessПрофессиональные услуги Cisco для Software-Defined Access
Профессиональные услуги Cisco для Software-Defined Access
 
Обнаружение известного вредоносного кода в зашифрованном с помощью TLS трафик...
Обнаружение известного вредоносного кода в зашифрованном с помощью TLS трафик...Обнаружение известного вредоносного кода в зашифрованном с помощью TLS трафик...
Обнаружение известного вредоносного кода в зашифрованном с помощью TLS трафик...
 
Промышленный Интернет вещей: опыт и результаты применения в нефтегазовой отрасли
Промышленный Интернет вещей: опыт и результаты применения в нефтегазовой отраслиПромышленный Интернет вещей: опыт и результаты применения в нефтегазовой отрасли
Промышленный Интернет вещей: опыт и результаты применения в нефтегазовой отрасли
 
Полугодовой отчет Cisco по информационной безопасности за 2017 год
Полугодовой отчет Cisco по информационной безопасности за 2017 год Полугодовой отчет Cisco по информационной безопасности за 2017 год
Полугодовой отчет Cisco по информационной безопасности за 2017 год
 
Годовой отчет Cisco по кибербезопасности за 2017 год
Годовой отчет Cisco по кибербезопасности за 2017 годГодовой отчет Cisco по кибербезопасности за 2017 год
Годовой отчет Cisco по кибербезопасности за 2017 год
 
Безопасность для цифровой экономики. Развитие продуктов и решений Cisco
Безопасность для цифровой экономики. Развитие продуктов и решений CiscoБезопасность для цифровой экономики. Развитие продуктов и решений Cisco
Безопасность для цифровой экономики. Развитие продуктов и решений Cisco
 
Cisco StealthWatch. Использование телеметрии для решения проблемы зашифрованн...
Cisco StealthWatch. Использование телеметрии для решения проблемы зашифрованн...Cisco StealthWatch. Использование телеметрии для решения проблемы зашифрованн...
Cisco StealthWatch. Использование телеметрии для решения проблемы зашифрованн...
 
Обеспечение бесперебойной работы корпоративных приложений в больших гетероген...
Обеспечение бесперебойной работы корпоративных приложений в больших гетероген...Обеспечение бесперебойной работы корпоративных приложений в больших гетероген...
Обеспечение бесперебойной работы корпоративных приложений в больших гетероген...
 
Новое поколение серверов Сisco UCS. Гиперконвергентное решении Cisco HyperFle...
Новое поколение серверов Сisco UCS. Гиперконвергентное решении Cisco HyperFle...Новое поколение серверов Сisco UCS. Гиперконвергентное решении Cisco HyperFle...
Новое поколение серверов Сisco UCS. Гиперконвергентное решении Cisco HyperFle...
 

Recently uploaded

Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Peter Udo Diehl
 

Recently uploaded (20)

Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
 
Powerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara LaskowskaPowerful Start- the Key to Project Success, Barbara Laskowska
Powerful Start- the Key to Project Success, Barbara Laskowska
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2
 
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptxIOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
 
Key Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdfKey Trends Shaping the Future of Infrastructure.pdf
Key Trends Shaping the Future of Infrastructure.pdf
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
 
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
 
AI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří KarpíšekAI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří Karpíšek
 
JMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and GrafanaJMeter webinar - integration with InfluxDB and Grafana
JMeter webinar - integration with InfluxDB and Grafana
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
 
IESVE for Early Stage Design and Planning
IESVE for Early Stage Design and PlanningIESVE for Early Stage Design and Planning
IESVE for Early Stage Design and Planning
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi IbrahimzadeFree and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
Free and Effective: Making Flows Publicly Accessible, Yumi Ibrahimzade
 
Introduction to Open Source RAG and RAG Evaluation
Introduction to Open Source RAG and RAG EvaluationIntroduction to Open Source RAG and RAG Evaluation
Introduction to Open Source RAG and RAG Evaluation
 
10 Differences between Sales Cloud and CPQ, Blanka Doktorová
10 Differences between Sales Cloud and CPQ, Blanka Doktorová10 Differences between Sales Cloud and CPQ, Blanka Doktorová
10 Differences between Sales Cloud and CPQ, Blanka Doktorová
 

IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots

  • 1. 1© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | IXIA VISIBILITY ARCHITECTURE Eliminating Blind spots Юлий Явич, IXIA
  • 2. 2© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | of the Fortune 100 of the top 50 carriers of the top 15 NEMs 74 45 15 Customer Focused Innovation Enterprise Carriers/ Service Providers NEMs 2014 Industry-first ATI security solution 2014 Industry-first virtual tap 2014 Industry-first 400GbE test solution
  • 3. 3© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | IXIA SOLUTION PORTFOLIO Across the Infrastructure Across ALL Platforms Flex Taps, iBypass, Virtual Taps 802.11ac, MU-MIMO PerfectStorm BPS vEPC IxLoad/VE IxNetwork/VE Multis SDN Threat ARMOR, ATI Mobile Endpoint Network Data Center Cloud NTO, Vision ONE, Hawkeye, xStream40, Control Tower TEST SECURITY VISIBILITY
  • 4. 6© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | 6© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | INTELLIGENT VISIBILITY
  • 5. 7© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | Clients INTELLIGENT VISIBILITY - CHALLENGES Server Network TapSwitch Switch How to: • Get data access for tools? • Network taps instead of SPAN ports? Network Tap Network Tap Tool 1 Tool 2 Tool N How to: • Deal with limited tool ports? • Scale tool capacity? • Filter traffic to tools? • Manage access for each tool?
  • 6. 8© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | Network Operations Application Operations Security Admin Forensics INTELLIGENT VISIBILITY End-to-End Data Access and Distribution Switch Switch Servers THE DATA CENTER Taps Taps Taps Network Packet Brokers • Aggregation • Filtering • Load Balancing • SSL Decryption • NetFlow 1G 10G 40G
  • 7. 9© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | APPLICATIONS AND NETWORK PERFORMANCE TOOLS
  • 8. 10© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | SECURITY TOOLS
  • 9. 13© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | INTELLIGENT PACKET PROCESSING All unique frames going to 10.0.0.0/8 Only the first 128 bytes of TCP Port 25 frames Hardware AFM NPB Adv. Packet Processing Advanced Packet Processing (AFM) Features • Deduplication • Header stripping • Trimming • Tunnel Termination • Data Masking • Timestamping • Burst Protection
  • 10. 21© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | ENTERPRISE – INTELLIGENT APPLICATION PROCESSING • ATI Processor (ATIP) - Context-rich Application Visibility • Application forwarding based on application, geography, and RegEx matching • Real-time dashboard • Rich NetFlow / IPFIX generation – Device OS – Browser – Carrier BGP AS# – Geolocation • Data Masking • Stateful SSL decryption All traffic from Georgia All voice traffic from HTC Ones Someone from remote office Skype for business monitor NPB – App Brokering Meta Data App Filtering
  • 11. 26© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | ATIP ENABLES SSL INSIGHT • Passive decryption – no impact on application performance • Fully compatible with all other ATIP features: Rich Netflow/IPFIX Data Masking Geolocation • Easy setup – just import server certificate & key • All popular key exchange & ciphers: RSA & DH Key Exchange SHA1/521/384/256/224 MD5 • Application Filtering • Handset/workstation type • Browser identification • 3DES • RC4 • AES • ECC (Elliptic Curve) • Encryption details reported over Netflow Hardware Encryption Offload
  • 12. 27© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | SPY GLASS ACTIVE SSL
  • 13. 28© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | NTO FAMILY NTO 7300 Vision ONE • 48x1/10G & 4x40G • Advanced Features • ATI Processor > Application layer filtering > SSL Encryption > Netflow Generation • Inline Support • Load Balancing • GUI • 1/10/40/100G Interfaces • Advanced Features • ATI Processor > Application layer filtering > SSL Encryption > Netflow Generation • Packet Capture • Load Balancing • GUI
  • 14. 31© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | General Features > Full Duplex Mode > Passes all traffic (including errors) from all layers for comprehensive Troubleshooting > Regeneration TAP > No IP address is needed > Redundant power ensures monitoring uptime TP-CU3; TP-CU3-ZD Network A Network B Mon A Mon B TX TXRX RX TX TX FULL DUPLEX COPPER TAP
  • 15. 32© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | - 1G/10G/40G/100G (LR & ER) > Single Mode with LC Connector - 1G (SX) > Multi Mode with LC Connector - 10G (SR) > Multi Mode with LC Connector - 40G (SR4 / Cisco Bidi/ MR4) - 100G (SR10) > Multi Mode with MTP Connector IXIA FLEXTAP
  • 16. 34© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | GETTING VIRTUAL TRAFFIC TO MONITORING TOOLS
  • 17. 38© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | CUSTOMER CASE STUDY International Bank Customer • Leading International Bank Need • Massive volumes or raw application traffic to monitor • Control traffic inspection costs • Improve overall Incident Response Team effectiveness Results • Deployed Ixia Intelligent Visibility solutions including NTO 7300 • Reduced monitored traffic using advanced filters of deduplication, packet slicing, IPs, VLANs • VLAN marking and Time stamping to monitoring tools • Reduced planned CapEx investments
  • 18. 39© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | CUSTOMER CASE STUDY Large Hi-tech Company Customer • Large L2/3 manufacturer Need • Control traffic inspection costs • Layer 7 filtering to Nectar tool Results • Deployed Ixia Intelligent Visibility solution including Vision One • Reduced monitored traffic using deduplication • Provided Skype for business specific traffic to Nectar tool • Reduced planned CapEx investments
  • 19. 40© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | TECHNOLOGY ECOSYSTEM TrafficREWIND is a unique patent pending solution that uses NetFlow metadata to regenerate the dynamics of production networks within BreakingPoint test beds Solution Overview
  • 20. 42© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | 42© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | RESILIENT SECURITY
  • 21. 43© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | RESILIENT SECURITY Serial Deployments of Inline Security Tools is Dangerous Switch Server Server Switch Switch Switch  Very complex operationally  Single points of failure  Administrative tension  Expensive to scale
  • 22. 44© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | Inline Security Tool Farm RESILIENT SECURITY A More Detailed View of a Resilient Security Framework Switch Server Switch Inline Security Tool Farm Server Switch Switch Bypass Switch Bypass Switch Network Packet Brokers (HA) Out of Band Sandboxing Monitored Tool Links via Heartbeat Packets Threat Intelligence Gateway
  • 23. 46© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | INLINE & MONITORING TOGETHER Inline Monitoring Inline • IPS (multiple vendors) Out-of-band Monitoring • Data logging
  • 24. 49© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | WORLD-CLASS GLOBAL SUPPORT Expert team of >100 engineers Proven track record of superior support Always-on 24x7 coverage Best-in-class support tools
  • 25. 50© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | WE MAKE APPLICATIONS STRONGER