Tag: network performance

  • VMware Embraces SmartNICs to Extend Virtualization

    VMware Embraces SmartNICs to Extend Virtualization

    VMware, as part of a bevy of updates to its portfolio announced today at its online VMworld 2020 conference, previewed its Project Monterey initiative to provide IT teams with composable infrastructure.

    At the core of that effort will be support for smart network integration cards (NICs) within VMware Cloud Foundation, the suite of software through which VMware bundles its vSphere, vSAN and NSX platforms. SmartNICs make it possible to offload network and storage I/O function from a virtual server by enabling its ESXi hypervisor to run on a SmartNIC.

    VMware also revealed plans to rearchitect VMware Cloud Foundation to enable disaggregation via SmartNICs that can be plugged into either a bare-metal server or a server running virtual machines from VMware. That capability will make it possible for applications to invoke bare-metal servers via an application programming interface (API) and will also enable VMware to extend its management framework to bare-metal servers that have SmartNICs installed.

    The decoupling of networking, storage and security functions will also allow IT teams to patch and update IT infrastructure independently from the server running VMware vSphere.

    VMware also noted that via Project Monterey each SmartNIC will be capable of running a stateful firewall along with other security software. IT teams will be able to enhance security by deploying thousands of firewalls on SmartNIC across the extended enterprise.

    There is no timetable for when Project Monterey will be available. Chris Wolf, vice president for the Advanced Technology Group in the Office of the CTO at VMware, said SmartNICs will play a major role in enabling IT organizations to compose IT infrastructure either using graphical tools employed by IT administrators or via APIs programmatically invoked by DevOps teams.

    Separately, VMware today also announced plans to update to its Virtual Cloud Network, a platform through which it bundles VMware NSX, VMware SD-WAN by Velocloud and VMware vRealize Network Insight in a single offering.

    VMware is committing to bringing more automation, making available predictive analytics enabled by machine learning algorithms, increased virtual networking scale enabled by VMware NSX-T 3.1. VMware will double the scale of NSX Federation, add advanced routing and multicast capabilities based on APIs and add support for configuration tools based on open source Terraform tools.

    Version 6.0 of vRealize Network Insight 6.0 will add assurance and verification capabilities as well as expanded support for VMware SD-WANs. VMware Edge Network Intelligence, meanwhile, adds a tool that applies artificial intelligence (AI) to optimize network performance.

    VMware also announced that its Virtual Cloud Network platform can now support Kubernetes clusters.

    In addition, VMware announced that VMware vRealize AI Cloud, a cloud service for optimizing application performance using machine learning algorithms, formerly known as Project Magma, is now available and that CloudHealth by VMware services has been extended to add support for Oracle Cloud Infrastructure along with tools for analyzing the security of workloads deployed on Google Cloud.

    Finally, VMware is making a series of other security updates, including providing access to VMware NSX Advanced Threat Prevention, which combines NSX Distributed IDS/IPS with malware detection software and network traffic analysis (NTA) technologies acquired from Lastline Inc.

    VMware is also committing to reselling a secure web gateway from Menlo Security as part of the VMware SD-WAN portfolio and formed an alliance with Zscaler to manage security as a service.

    Finally, VMware today launched VMware Carbon Black Cloud Workload, which combines vulnerability reporting with workload hardening software for both legacy platform and microservices-based applications deployed on Kubernetes clusters.

    VMware now has one of the broadest portfolios of offerings of any enterprise IT vendor. It’s not clear to what degree IT organizations are consuming all that software on top of VMware vSphere. However, for IT teams looking to reduce the number of vendors they need to engage VMware has become a compelling option.

  • Is Your Infrastructure Ready for Edge Computing?

    Is Your Infrastructure Ready for Edge Computing?

    Like many IT innovations, edge computing began with engineers as a natural extension of technology to address a growing need. The concept isn’t new; distributed computing has been around for decades. But, at the same time standards began to converge and edge hardware started making the rounds at trade shows, the hype machine saw an opportunity. It amplified edge’s considerable promise in reducing latency, offering software-defined deployment, decreasing cloud networking costs and more. But as is too often the case, the bold feature bullets ignored the production concerns businesses must address, including edge computing’s rough spots and the additional operations complexity it adds.

    Of course, edge computing will survive a little overexcited promotion, just like many of the once improbable technologies before it. People used to say, “What? Abstract all my data center applications away from the hardware as virtual servers? Impossible!” A decade later, we can’t imagine how we’d deliver traditional enterprise services, cloud computing, online retail, media streaming and everything else in between without exactly this. Virtualization survived its awkward hype adolescence, and edge computing will, too. The needs edge computing addresses are only growing.

    Thanks to engineers and operations teams, the edge distributed model is moving toward practical use. It’s proving itself capable of meeting requirements for new levels of network performance through reduced latency, scalability and, more importantly, manageability. For some businesses, it’s even reducing costs over the long haul.

    Not All Data Is Created Equal

    With the proliferation of connected devices and a growing focus on 5G-enabled technology, tech pros should set aside their natural reluctance to wade through the edge hype and consider it a genuine possibility. Its adoption is following the rise of emerging technologies and the applications taking best advantage of it: 5G, augmented reality, autonomous vehicles, IoT and smart manufacturing. These environments require not only low upstream latency, but high-performance compute and timely result data. Light only travels so fast, pushing infrastructure closer and closer to consumers for faster, more seamless processing in the form of brand-differentiating user experiences.

  • Despite Downturn, Enterprise IT Budgets Remain Intact

    Despite Downturn, Enterprise IT Budgets Remain Intact

    A survey of 137 IT operations leaders at companies in the U.S with at least 500 employees and an annual IT budget in excess of $5 million finds a surprising amount of resiliency at the beginning of the COVID-19 pandemic.

    Conducted April 1 by OpsRamp, a provider of IT operations tools, the survey finds more than half of the survey respondents (58%) said they expect to either significantly or moderately increase their annual technology budgets, while 38% plan to either significantly or moderately reduce their technology spending.

    The survey also finds 73% of respondents expect to either accelerate or maintain digital transformation initiatives and projects.

    Bhanu Singh, senior vice president of engineering and DevOps for OpsRamp, said that at least for now among larger enterprises, digital business initiatives are being accelerated as organizations recraft their business continuity plans. With most customers and employees working from home, the need for applications that digitize business processes has become more critical, especially since no one knows for sure when the COVID-19 pandemic might subside or whether there will be another one, he said.

    Many of those projects will rely on cloud-native technologies that make it easier for organizations to scale IT resources up and down, added Singh, noting organizations are quickly discovering that monolithic applications even when they are deployed on a public cloud are not as flexible as they now require.

    Specifically, the survey finds IT leaders are investing heavily in AIOps (69%), information security and compliance (62%), self-service platforms (60%), cloud-native observability (51%), network performance monitoring and diagnostics (51%), big data analytics (46%) and cloud infrastructure (45%).

    IT leaders are also planning to drive technology vendor consolidation (59%) to reduce costs and rely more on third-party managed service providers (58%).

    In terms of hiring, IT financial analysts (68%), cloud architects (53%), DevOps engineers (50%) and data scientists (47%) top the list of priorities.

    Of course, as the impact of the COVID-19 pandemic on the global economy becomes more apparent it is too early to say what the impact on IT budgets will be. Industry analysts Gartner and International Data Corp. (IDC) are forecasting a relatively small decline in IT spending of about 5% for the year once the economy begins to recover in the second half. However, it’s clear that certain vertical industry segments, such as travel and hospitality, might have a much longer way to go than, say, healthcare companies.

    In addition, it’s likely that much smaller companies than those surveyed by OpsRamp may find it more challenging to restart operations after being forced to lay most of their employees in some cases.

    Whatever the timing, the one probable thing is many of the IT trends that were just beginning to gain traction are likely to see accelerated adoption once the economy recovers. There will be a natural tendency to limit the adoption of new platforms and processes in the short term. However, now that it’s clear existing platforms and processes are not especially flexible it’s only a matter of time now before most of them one way or will be replaced or at the very least completely modernized.

  • 3 Lessons in Network Visibility from the A-List

    3 Lessons in Network Visibility from the A-List

    The network can be host to multiple performance killers. Here are three worth noting

    Like Ed Sheeran as a secret stormtrooper in “Star Wars: The Rise of Skywalker,” some cameos are hard to spot. They can appear out of nowhere halfway through the film or remain a complete mystery until behind-the-scenes footage reveals the masked actor.

    The same can be said for guest appearances on your network. It’s tough to spot the hidden malware, application interactions, network delays and other “cameos” popping up, especially when organizations today are grappling with the complexities of public, private and hybrid cloud infrastructure and multi-tier applications. To adequately support a robust and secure digital infrastructure, you need network and application-layer visibility.

    With movie awards season upon us, I invite you to sit back, relax—pop some champagne, if you’d like—and I’ll tell you about three cameos that can be easy to miss in the network environment, and what you should do about them.

    Hidden Malware

    At a pivotal moment in the Oscar-nominated “Joker,” the evil protagonist studies a tape to prepare for his appearance on a popular TV show. On the tape, he sees a comedian appear on the same show—played by Justin Theroux. It’s a blink-and-you’ll-miss-it cameo from Theroux, very much like hidden malware traversing the network without detection.

    Whether they’re sophisticated or non-targeted, high-volume criminally motivated attacks can move throughout the network without your knowledge and cause enterprises significant damage and cost, to the tune of $6 billion by 2021. Emotet, described by the Department of Homeland Security as one of the most costly and destructive instances of malware, likely comes to mind as one of the most pertinent examples. It has the ability to move laterally through the organization, spread other damaging malware and constantly evolve.

    Spotting hidden malware requires network visibility that spans the entire distributed digital infrastructure, as well as having access to network data to ensure visibility for all security and performance tools. Specifically, organizations need reliable access to data in motion to tap into traffic across cloud and on-premise infrastructure and traffic flowing across 5G and 100GB networks. This type of pervasive visibility allows enterprises to keep up with the speed at which networks and businesses run, as well as with security demands.

    Interactions Between Applications or Microservices

    When Brad Pitt’s character in “Once Upon a Time in Hollywood” unknowingly ends up at the Manson Family compound, he comes across Dakota Fanning, who plays a key member of the infamous cult. Their meeting is short but meaningful, and sets the stage for additional character development and exchanges down the line. Interactions between applications or microservices are just as meaningful, with 80% of network traffic consisting of such communication on average.

    Understanding these interactions is critical for guiding digital transformation (DX) efforts, which are a top priority for 87% of business leaders. Among the goals of DX are streamlining business processes, cutting costs, improving productivity and introducing new business models that redefine industries—or build new ones. These are ambitious goals, and they’re ultimately realized through new digital applications built on intricate microservices-based architectures that need to be managed and secured.

    Only with a clear view, and the right kind of data, can you understand the applications’ interactions, performance and security characteristics to accelerate DX. And the only way to get to this view is to look at the data in motion on the network. The ability to isolate specific applications or microservices communication streams for deeper inspection allows infosec teams to easily understand access patterns and put in place effective micro-segmentation strategies. Application developers, too, can benefit from this by better understanding communication bottlenecks between applications and microservices, as well as troubleshoot them.

    Traffic Bottlenecks

    The latest rendition of “Little Women” follows a non-linear storytelling structure, constantly jumping between two timelines. It can be jarring to viewers when the girls’ father returns from war, revealing himself as the actor Bob Odenkirk. While this moment is meant to be an intimate glimpse into a family coming together after a long separation, it brings the movie-watching experience to a standstill, since the audience associates Bob Odenkirk less with a serious scene and more with his previous comedic roles.

    Networks today are similarly prone to experiencing abrupt slowdowns or bottlenecks that limit network performance and waste bandwidth. Managing the network to ensure constant availability is a major challenge when data volumes are growing exponentially. It’s estimated that about 1.7MB of new information will be created every second for every human being on the planet this year. This data explosion paired with digital transformation technology investments and lightning-fast 5G and 100GB networks has led to a very complex enterprise infrastructure setup—and network blind spots across physical, virtual and cloud environments.

    The solution lies in having the right kind of data to help you understand network and application performance. By analyzing the network traffic, you get immediate actionable data points that can be used to address trouble spots.

    Whether we’re talking big screen or enterprise network, surprise cameos are common and they are easy to miss—and this is particularly problematic when things like malware and bottlenecks pose a threat to network security and speed. For the NetOps and infosec pros tasked with complex infrastructure development, implementation, maintenance and security, you need a clear line of sight into what’s happening within the network. Armed with insights on traffic patterns (both cloud and on-premises), delays in data flow and insecure areas, you can use this intel to write the screenplay (or plan) to support a robust and secure digital infrastructure.

    — Shane Buckley

  • An Easy Way to Optimize Network Performance Monitoring

    An Easy Way to Optimize Network Performance Monitoring

    Network performance monitoring, and especially network optimization, is more of an art than a science because there are so many factors that figure into network and application responsiveness. In addition, because there is a vast amount of data traversing the network, determining the right kind of data you need to monitor (and where you should you be capturing the data from) can become very difficult. As an example, according to research conducted by Enterprise Management Associates in October of 2016, 41 percent of IT personnel spend more than 50 percent of their time working on network and application performance problems.

    The data collection process is further complicated by the fact that tactical data loses up to 70 percent of its value after 30 minutes. This makes the speed and accuracy of data analysis critical if you hope to resolve your network or application issues.

    There is one easy way to improve your lot in life, though: Add a network visibility architecture. Most IT personnel have a security architecture and a network architecture, but very few have a visibility architecture. Network visibility is what enables you to capture the right data at the right time, so you can do something useful such as quickly isolate potential problems.

    Setting up a visibility architecture is straightforward. There are four main components:

    • Data access
    • Data manipulation
    • Application intelligence
    • Purpose-built analysis tools

    Data access can be provided by physical taps, virtual taps and bypass switches. These devices give you timely access to the data you need. A SPAN port also can be used; however, there can be issues with the quality of the data from this type of device, so it is not recommended.

    After you have acquired the monitoring data you need— probably along with a bunch that you don’t need—the next step is to send it to a network packet broker (NPB). This device provides granular filtering capability to maximize the flow of relevant information to your monitoring tools. Specific types of data can be segmented out and sent to specific tools to improve efficiency and faster time to resolution. NPBs can provide the following services as well: data aggregation, deduplication and load balancing of Layer 2 through 4 (of the OSI model) packet data.

    Application intelligence is another capability available through an NPB. This functionality provides additional filtering and analysis at the application layer, i.e. Layer 7 of the OSI stack. For instance, you can leverage application intelligence to prevent application bandwidth overloads on your network. You can literally see the amount of traffic on your network based upon application type (e.g. Hulu, Netflix, Pandora, FTP, HTTP, RTP, etc.). You also can use it to identify slow or underperforming applications.

    The final layer of the visibility architecture is made up of your security and monitoring tools. These devices typically are special-purpose tools (e.g., sniffer, network performance monitoring [NPM], application performance monitoring [APM], etc.) that are designed to analyze specific data. For instance, APM tools can provide real-time data analytics to help you manage your network and lets you see problems before your users do.

    However, standalone deployments of these tools can run into different problems, such as overloaded disk space and processing, the need for different interface ports based upon network traffic speed and the need for lots of input ports to capture data across the network. An NPB can be used to capture network data and filter that data before it goes to the NPM tool. This increases the efficiency of the tool by reducing clutter. The additional filtering of duplicate data further enhances the efficiency and also removes the storage waste associated with storing irrelevant data.

    Network administrators need network visibility solutions to help them discover, isolate and solve problems related to the network and its applications. This architecture gives your network tools a complete picture of the network so they can resolve issues faster.

    — Keith Bromley

  • Riverbed Aims to Unify App, Network Performance Management

    Riverbed Aims to Unify App, Network Performance Management

    Much of the initial focus on DevOps has been on accelerating the rate at which applications are built and deployed. But once those applications are deployed, it’s not too long before the focus shifts to the quality of the end-user experience. Aiming to make it easier to determine what the quality of that experience really is, Riverbed Technology has launched a Digital Experience Management initiative based on the SteelCentral management platform.

    Erik Hille, director of product marketing for Riverbed, says the latest release of SteelCentral provides tighter integration between SteelCentral Portal and the SteelCentral Aternity end-user monitoring tool and SteelCentral AppInternals, an application performance management (APM) platform. The goal, says Hille, is to make it easier for an organization to holistically manage individual end-user experience by correlating information at the device, network and application levels. As part of that effort, Riverbed also has integrated the workflow between SteelCentral Aternity and AppInternals to create an integrated monitoring system.

    Hille says IT operations teams can use a comprehensive approach to managing digital experiences that can be set up in fewer than 10 days. Once in place, IT operations teams can more quickly identify the root cause of any issue by correlating application, device and networking data through a single pane of glass. In addition, Riverbed is employing REST APIs to make it possible to consume alerts generated by collaboration tools such as Slack and HipChat. IT operations teams can not only automatically open incident management tickets, but also collect additional metrics via those APIs.

    Riverbed is also providing integration between NetProfiler, a network performance monitoring tool, and NetIM, a network device management tool, to provide more visibility into how network infrastructure impacts network performance.

    Hille notes that most IT operations teams are swiveling between different sets of tools to correlate the same information. The problem is that as more organizations strive to become a digital business, any performance issue has a direct impact on customer satisfaction and the amount of revenue being generated. Faced with that increased business pressure, Hille says IT organizations need to re-evaluate legacy approaches to IT operations based on silos. The goal should be to implement a more proactive approach to IT focused on proactively preventing issues from occurring or escalating, versus merely reacting to isolated events as they occur.

    One of the few things in DevOps that developers and IT professionals can agree on is that whenever there’s an issue, it’s the fault of the network guy. That’s not always true, but it does take networking professionals a long time to prove their innocence. Until then, there’s a tendency to assume their guilty until proven otherwise. Obviously, that kind of bias isn’t in keeping with the whole spirit of integrated DevOps. A more comprehensive approach to application and networking performance management should go a long way toward reducing the amount of finger-pointing inside any organization.

    There will never be a perfect IT environment. The goal is to discover issues before the end-user notices—and, failing that, resolve that issue in as little time as possible. Any argument about what exactly happened to cause the problem can occur at a later date and time.

    — Mike Vizard