Presentation is loading. Please wait.

Presentation is loading. Please wait.

FireEye NX In line Solution

Similar presentations


Presentation on theme: "FireEye NX In line Solution"— Presentation transcript:

1 FireEye NX In line Solution
Dennis Carpio Sr. Director Business Development Xceed Technology Partners

2 Xceed Technology Partner
Ixia and FireEye: A Winning Combination • Strategic partner since 2011 • Only OEM vendor to provide Bypass products on FireEye pricelist • Ixia helps FireEye get deployed In-line • Ixia products in FireEye labs to showcase joint solution (vice versa) • Momentum Sponsor since inaugural event (5 years) • Executive alignment within cross-functional teams

3 Joint Partnership value
FireEye uses Ixia to get In-Line Challenge FireEye provides an advanced threat prevention solution (NX appliance) that is most effective when deployed in-line (as opposed to out-of-band) Out-of-band monitoring allows you to detect threats, but In-Line monitoring allows you to both detect and prevent Many customers are hesitant to deploy security tools in-line because they are a single point of failure that can bring the network down Solution Ixia’s Bypass Switches solve this because they are fail-safe active Taps that can be used for both in-line and out-of-band deployments It is best for FireEye to start a POC out-of-band with a Bypass, and when the customer is ready, use the Bypass to instantly go in-line at the "flip of a switch”  Every FireEye NX appliance should be bundled with an Ixia Bypass solution to give customers the network uptime reliability they require

4 INLINE ON DEMAND TAP (Span) Mode In-Line Mode “Flip the Switch”
Inbound traffic Outbound traffic Heartbeat packet Bidirectional traffic Unidirectional traffic TAP (Span) Mode In-Line Mode Passive out-of-band monitoring Bypass Switch acts like a Network Tap Full-duplex traffic on two separate ports (1 & 2) No heartbeat packet NX will be in receive (passive) mode only Active in-line monitoring Bypass Switch acts like a fail-open device Full-duplex traffic on both ports (1 & 2) Heartbeat packet transmitted NX will be in transmit and receive mode “Flip the Switch” • Gets FireEye NX in-line quickly • No added network downtime • Bundle a Bypass with every NX Port 1 Port 2 Port 1 Port 2

5 INTEGRATED CONFIGURATION
Easily deploy FireEye NX appliances FireEye specific ’heartbeat’ configuration Loads directly from a pull-down menu Available on Bypass and Packet Broker Customer Benefits Security without the added risk of downtime Easy on-demand control of in-line vs out-of-band Enforce mitigation capabilities only when needed

6 Scalable Security Architecture
FireEye Value Proposition Ixia AFO helps FireEye get In Line on demand Ixia’s Packet Broker drops zero packets to enable the most effective security inspection Use Ixia platform to scale FireEye NX capacity to over 40G, and upsell FX and PX appliances Joint Solution Overview Ixia OEM’s its Bypass Switch as the FireEye AFO solution that enables active in-line security monitoring. Combining it with Ixia’s NPB (Network Packet Broker) solution, customers can aggregate, filter, and load balance traffic to multiple FireEye NX appliances for scalability. This allows our joint customers to achieve the highest levels of security inspection. FireEye AFO Ixia NPB FireEye NX Appliances (Load balanced) FireEye FX FireEye PX Ixia Key Features Session-based load balancing – keeps flows intact to the same NX appliance Heartbeat health check – ensures maximum network uptime HA Active/Active – provides network redundancy at the highest level

7 CASE STUDY Financial Organization High Availability & Aggregation
Support Multi 10G Architecture w/Asymmetric Traffic Highly Redundant Architecture Requirements Prevent Service Disruption to Existing Resources CASE STUDY Financial Organization High Availability & Aggregation FireEye NX NPM Storage NPB Asymmetric Traffic Throughput support of over 20G across multiple NXs Minimized Failure scenarios using heartbeat technology Rollout across all of their 7 major data centers Why Ixia: Only solution to offer multi layered redundancy Meet reliability requirements with improved SLA The Result: What We Tested Active Fail-open Aggregation/Load Balancing Filtering & Re-direction Products Used 10G AFO Ixia xStream10 FireEye NX The Results Support up to 4 NXs HA Active/Standby for Improved SLA Increased Network Availability

8 CASE STUDY Large Retailer in US
Support Multi 10G At Line Rate HA Required To Protect 24x7 Ecommerce App Threat Prevention Needed on both HTTP and SSL Traffic Requirements CASE STUDY Large Retailer in US Multi-Vendor High Availability Throughput support of over 10G across multiple NXs Achieved network availability metrics for Ecommerce site Maximized protection without sacrificing performance Why Ixia: In-Line Load Balancing for multiple appliances Filtering to separate SSL and non-encrypted traffic The Result: NPB SSL Decryption FireEye NX SSL Decryption FireEye NX IDS IDS What We Tested Active Fail-open Aggregation/Load Balancing Filtering & Re-direction Products Used 10G AFO Ixia xStream10 FireEye NX The Results Support up to 2 NXs HA Active/Standby for Improved SLA Increased Network Availability

9 CASE STUDY US Government Agency
System Redundancy To Eliminate Single Point of Failure Highly Availability Architecture That Provides Reliable Crossover Requirements Eliminate Downtimes To Increase Detection Rates CASE STUDY US Government Agency High Availability & Redundancy Multi-tiered heartbeat technology provided reliability across all layers Achieved Five 9’s reliability with Dual Bypass capbilities Eliminated points of failure with highly redundant architecture Why Ixia: Only solution to offer Bypass with dual output paths Meet reliability requirements with HA architecture The Result: Asymmetric Traffic NPB FireEye NX What We Tested Active Fail-open Aggregation/Load Balancing Filtering & Re-direction Products Used 1G Bypass HD Ixia xStream10 FireEye NX The Results Support up to 2 NXs HA Active/Standby Increased Network Availability

10 THE IXIA + FireEye DIFFERENCE
Xceed Technology Partners Combine to Deliver Complete Solution Making Your Network & Applications Secure, Fast and Reliable COMPREHENSIVE SOLUTIONS Next Generation Threat Prevention with Maximum Network Performance INNOVATIVE TECHNOLOGY Extensive Partner Base Worldwide GLOBAL PARTNERS Ensure Successful Deployment and Operations 24/7 PROFESSIONAL SUPPORT We solve our customers’ many test, visibility and security challenges by anticipating tomorrow’s landscape today. We deliver world-class technology. Our solutions are also scalable, high performance and most importantly manageable to help you make applications run stronger. We pride ourselves with leading technology and nonstop innovation so that you have what you need when you need it. Our global partners ensure the extensive reach to serve our customers everywhere and our professional services ensure a successful deployment and are there for you 24x7. Our customers – the largest service providers and equipment manufactures and enterprises - trust us to test and secure their most complex and sensitive environments. And we work every day to continue to earn that trust. Ultimately the Ixia difference is to seamlessly and securely deliver a quality experience for the end customer. Thank you.

11 Ixia FireEye Xceed Technology Partners Dennis Carpio
FireEye Cyber Security Coalition Ruby Sharma


Download ppt "FireEye NX In line Solution"

Similar presentations


Ads by Google