Pro Active Monitoring

US Telecom

CHALLENGE

To roll out a pilot program of video services using network functions virtualization (NFV) across the infrastructure—without dropping quality

SOLUTION

Hawkeye

RESULTS

Boosted performance by proactively monitoring simulated video traffic and measuring quality at timed intervals
Reduced service calls and eliminated house calls by troubleshooting before customers were impacted

Large Wealth Management and Insurance Company

CHALLENGE

Monitor application QoE and resolve network performance issues across 345 remote sites

SOLUTION

Hawkeye, XR2000 Active Hardware Endpoint

RESULTS

Proactive monitoring of network performance and latency improved Skype end user QoE, met 99% uptime SLA
Continuous live monitoring of 345 sites enabled global SLA validation across HQ, remote offices, and retail sites

In-Line Network Resiliency

DESCRIPTION

In-line bypass with Imperva SecureSphere solutions can help customers over come network resiliency concerns.

SOLUTION

External Bypass Switch

FEATURES

Active in-line access for 1G and 10G links
Automatic fail-open and fail-closed options (configurable)
Heartbeat heath check technology

BENEFITS

Traffic continuity is preserved in case of IPS appliance outage
Imperva WAF can be taken out of service for upgrade w/o taking down the network
Imperva WAF can be connected in tap mode or in-line mode w/o rewiring the network
Proven Bypass Switch technology eliminates single-point-of-failure

Load Balancing for In-Line & Out-of-Band Deployments

DESCRIPTION

Individual Imperva appliances may not have sufficient capacity to fully protect busy network links, especially in the case of high speed connections and bandwidth intensive applications

SOLUTION

Inline load balancing

FEATURES

Load balance 10/40G network traffic across multiple Imperva appliances
Two or more Imperva WAF appliances, up to 16 per load balanced group
Symmetry awareness, specific session uses same WAF in both directions
Intelligent Inline 5 tuple filtering to exclude non-essential traffic from WAF inspection
Configurable options to pass through or block non-essential traffic on network
Configurable heartbeat health check technology

BENIFITS

Wire speed protection for 10/40G network links & bandwidth intensive applications
Heartbeat technology protects against “brown out” type issues – i.e. degraded performance due to too much traffic going through Imperva WAF appliance, removes appliance from group until heartbeats return
Improve capacity by filtering and forwarding only relevant protocols to WAF appliance and protection scenario
Proven bypass technology addresses customer objections of single

Advanced Fail-Over & Redundancy

DESCRIPTION

In event that the Imperva SecureSphere unit fails or requires maintenance, the need to ensure that remaining units automatically take over inspection of the units traffic in a fault tolerant, session aware manner.

SOLUTION

Inline protection of multiple network links

FEATURES

Traffic that comes into NPB from a particular network link is sent back out the same link
Works based on mac address filtering rules
All features of single network link load balancing continue to be available (as per previous sections)

BENEFITS

Graceful load balancing algorithm minimizes session disruption when appliances fail
Flexibility to support any combination of Active/Active & Active/Spare fail-over
Automatic hot standby failover
Take units out of service for maintenance without disruption the network
Ability to support multiple different inline tools in load balanced groups, so that Imperva SecureSphere can be integrated in any existing customer environment
Also supports out-of-band deployments

Load Balance Multiple Links

DESCRIPTION

Customer wants to distribute traffic from multiple network links across a common Imperva SecureSphere appliance, or load balanced groups of Imperva appliances

SOLUTION

Inline protection of multiple network links

FEATURES

Traffic that comes into NPB from a particular network link is sent back out the same link
Works based on mac address filtering rules
All features of single network link load balancing continue to be available (as per previous sections)

BENIFITS

Maximize resource utilization, using a pool of Imperva
SecureSphere appliances for multiple network links
Maximize Imperva SecureSphere capacity when used with load balancing
Transparency, no tags added to disrupt communication through Imperva SecureSphere WAFs

Service Chaining Multiple In-Line Tools

DESCRIPTION

Customer wants to distribute traffic from multiple network links across one or more Imperva appliances and deploy Imperva along side additional monitoring tools (both inline and out of band)

SOLUTION

Inline load balancing

FEATURES

Load balance 10/40G network traffic across multiple Inline appliances
2 or more Imperva WAF appliances, up to 16 per load balanced group
Symmetry awareness, specific session uses same IPS in both directions
Intelligent Inline 5 tuple filtering to exclude non-essential traffic from WAF inspection. Configurable options to pass through or block non-essential traffic on network
Configurable heartbeat health check technology
Also supports out-of-band deployments

BENEFITS

Wire speed protection for 10/40G network links & bandwidth intensive applications
Heartbeat technology protects against “brown out” type issues – i.e. degraded performance due to too much traffic going through IPS appliance, removes appliance from group until heartbeats return
Improve capacity by filtering and forwarding only relevant protocols to Imperva appliance and protection scenario
Proven bypass technology addresses customer objections of single point of failure