Tech Field Day Events Archives - Gestalt IT: Recent Episodes

None

The Latest News in Enterprise IT, part of The Futurum Group

View Details

Cloud Field Day is back for 2025, continuing the theme of hybrid cloud and multi-cloud from the last Event in October 2024. Our vendor roster for this event aims to ease the complexities and dangers of multi-cloud networks and ensure that applications can be deployed wherever they deliver the most business value. No doubt, the delegate panel will have plenty of questions. You can ask questions on social media, particularly the LinkedIn streaming page for each company.

Learn more about Cloud Field Day 22 on the Tech Field Day website and watch it live on the Cloud Field Day Event page.


Cloud Field Day Presentation ScheduleOn Wednesday, we start at 8:00 AM, with Infoblox and the Infoblox Universal DDI product suite, which handles the fundamentals of efficiently and automatically managing DHCP, DNS names, and IP addresses across complex multi-cloud networks. If you have ever tried to build a unified network across multiple clouds and on-premises networks, you will know the pain of integrating the cloud DNS and ensuring that IP address ranges aren’t accidentally duplicated. From 11:00, Selector AI will showcase the Selector AIOPs solution to provide proactive alerting and easy incident resolution using ChatOps. Selector allows real-time alerting and drill down with comprehensive network visibility, path tracing performance monitoring, and fault isolation by correlating network and cloud events. Selector uses ICMP and HTTP synthetics for performance monitoring to understand traffic latencies in different parts of the network. At 2:00, Catchpoint presents Innovate or Perish: IT Organizations Must Rethink Monitoring in the Cloud Age. Catchpoint will look at why, despite heavy investments, incidents and outages are not going away (they are getting worse). Catchpoint have a new way, a re-envisioning of monitoring to adapt and account for these factors through Internet Performance Monitoring (IPM), which they will demonstrate.

The livestream on Thursday also starts at 8:00 AM Pacific, when the Fortinet team show their fabric platform’s value in combined network and platform signals intelligence that speeds time to detect, decreases SOC effort, and enables rapid and low-risk response. We will see the red team vs blue team demonstrations that Fortinet brings to Tech Field Day events. Combining network visibility to malicious traffic using FortiNDR and anomalous behavior identification through FortiCNAPP’s composite alerts combine to increase signal fidelity, which is more actionable. Through ML, FortiNDR and FortiCNAPP provide signal correlation and pre-investigation, allowing the SOC operator to respond quickly. Thursday will finish with a delegate roundtable discussion where we will undoubtedly gain even more insights into the challenges and joys of deploying and operating applications in a complex multi-cloud network.

Keep Up with the ShowThe live stream for Cloud Field Day will be held on Wednesday, February 19 and Thursday, the 20th. You can watch it on the Cloud Field Day event page, the Tech Field Day LinkedIn page, and our sister site, TechstrongTV. If you want to participate in the conversation, comment on our LinkedIn stream or jump on your favorite social media platform and use the hashtag #CFD22. If you miss any of the action during the livestream, you can always head over to our Tech Field Day YouTube channel.

Event InformationAlastair Cooke is a Tech Field Day Event Lead, now part of The Futurum Group. You can connect with Alastair on LinkedIn or on X/Twitter and you can read more of his research notes and insights on The Futurum Group’s website.

Tech Field Day is part of The Futurum Group. Follow Tech Field Day on LinkedIn, on X/Twitter, on Bluesky, and on Mastodon. See information and look for upcoming events on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Tackling Mulit-Cloud Challenges with AI, Security, and Other Innovations at Cloud Field Day 22

View Details

We may only be a few weeks into 2025 but we’re ready to bring you more great Tech Field Day content! We will once more be broadcasting live from Amsterdam as we kick off Tech Field Day Extra at Cisco Live EMEA 2025. There are lots of exciting technology announcements that you’re not going to want to miss.

Field Day Extra Event ScheduleWe’re starting out on Tuesday, February 11 at 13:00 Central European Time (CET) with our first round of presentations. Expect to hear from Cisco’s Service Provider team and the data center networking group as they bring you the latest buzz around these critical pieces of the IT puzzle. Be on the lookout for Nexus and UCS and more. Some of your favorite presenters will be joining us as we hit all the key points to keep you informed.

We’re back on Wednesday, February 12 at 13:00 CET to continue the action. This day will have presentations from the wireless group and the security team. Wi-Fi 7 is as hot as ever and the Meraki team will also be around to help talk about user access. Add in topics like firewalls and zero trust network architecture and we will all be in for a great ride.

Follow The Field Day ActionOur European audience will be able to tune in live as we will be on local time from Amsterdam! Check out the event page for all the schedule details and delegates. If you want to check out our other streaming video locations make sure to bookmark Techstrong.TV and the Tech Field Day LinkedIn Page. For those that aren’t early rises in the US the videos will be posted to the Tech Field Day Youtube channel. If you want to join the conversation make sure you jump on social media and use the hashtag #TFDx. Content will also be shared on BlueSky.

Tech Field Day Extra is going to rock and we hope to see you there!


© Gestalt IT, LLC for Gestalt IT: Kicking Off The Year with Tech Field Day Extra at Cisco Live EMEA 2025

View Details

In the tech industry, moving up the ranks without the traditional opportunities of visibility and networking can be backbreaking.

Since the pandemic, a majority of workforce has been working remotely. And a blizzard of layoffs sweeping through the industry is only adding to the uncertainty making it even trickier for workers to curve out a successful career.

The 2024 Hiring Trend Report traces a significant shift in the sentiment around technical hiring. Axios Market finds that job postings for developer positions are the lowest in five years.

The business world is transitioning from volume hiring to hiring that matters. A big reason for that is more engineers are upskilling, and tapping into AI tools in their everyday work, delivering greater output than usual.

Full-Time in-Office or Full-Time Remote?Polls show that many seasoned employees favor working in isolation over working out of office as it helps them balance job responsibilities with personal obligations. But for people who are just starting out, being outside the office is a rather uncomfortable experience.

Thankfully, most companies have been hands-on with helping employees close the distance by shoring up communication with the help of technology, putting together practice handbooks, and mandating availability of middle managers and senior staff members during the workhours – but climbing the career ladder is still hard from afar.

“Own Your Career”So how do employees ensure they are moving towards their career goals in this new reality?

By owning your career, says Jack Poller, industry analyst and Tech Field Day delegate.

“Careers are about people, and not resumes,” Poller said while sharing his outlook and wisdom, at the Ignite Talk at the recent Cloud Field Day event.

When a candidate sends in a resume, it first goes through an AI applicant tracking system that checks for keyword matches before pushing it downstream to an HR person. If the application has 9 out of the 10 keyword matches with the job posting, the resume is passed on to the recruiting team. If not – it is simply tossed in the bin.

This is the primary reason why getting a call back from companies is frustratingly hard.

Poller who has played many roles in his long and illustrious career from an engineer to a marketer to now an analyst, says that the secret to, whether it’s landing a dream job, or pushing forward in career, is to understand that every interaction is about selling yourself as the right person to the one in front of you – and that is a critical thing to internalize even before starting the quest.

Another thing to familiarize with is how success is measured in the corporate world.

“Careers are about people, and not resumes.”“There’s exactly one measure of success that matters and that’s profit,” said Poller. “And there’s exactly two ways we can do it: To control profit, we can either increase our revenue and sales, or we can reduce our costs and expenses.”

“At the very end of the day, no matter who you’re talking to, that’s what you want to be thinking about,” he added.

To get closer to the goals, Poller says, it is also imperative that one finds the right set of people who can boost their efforts by helping them choose the right skillset to build on, or assist in drafting a career blueprint by sharing their own experiences.

But none of it is possible without articulating one’s vision adequately to others, Poller reminds. Just communicating your career plans can win you necessary support and all momentum you require.

Communicating not only helps one obtain valuable advice from people ahead of them, but also fosters team relations, and helps hone the ability to influence people into seeing their vision and views.

Doing this remotely is far from ideal, says Poller. The new geography of work, while it lends flexibility and freedom to the masses, is often conflicting with the basic of any relation – trust. When you meet someone on one-one-one video meets, it is hard to create a personal relation without feeling their energy.

Poller suggests professionals to get out there and be among people as much as possible to build that bond.

And last but not the least, there’re no shortcut to success. Poller says that while there are always people around who can provide support and mentorship, the hard work is all one’s own.

“If you’re going to do something that is off-brand or a reach or a stretch for you, you have to do the job in order to get the job,” he emphasizes.

Poller highlights a simple equation in conclusion: Everything narrows down to what is the problem the company has, and how are you solving it for the company.

Conversely, it is important to remember that building a career is not a sprint. It’s a long journey that has many highs and lows, and people must not hesitate to take a step back and reflect whenever necessary.

“Throughout your career, keep an open mind,” he says. But also remember to “take a break, and look at things from a different perspective.”

Catch more Ignite Talks on tech from the Cloud Field Day event on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Career Advice from a Long-Time Practitioner of Tech

View Details

Analysts are predicting that 2025 is the year AI applications take over the enterprise, and we’re learning much more about how this will happen. AI is increasingly being deployed within private infrastructure, where security, governance, and data sovereignty are critical to successful implementations. Innovations like orchestration engines and AI optimization software are helping enterprises integrate advanced AI workloads seamlessly across diverse systems, while ensuring regulatory compliance and efficient model management.

Join Tech Field Day, Techstrong, Futurum, and our panel of independent experts for AI Field Day, January 29th and 30th, 2025. Watch live on TechStrong TV, LinkedIn, and the Tech Field Day website, where you can also see the full schedule.

AI Field Day begins on Wednesday at 10:00 AM Pacific with Broadcom, who are focusing on the key question, why use VMware for private AI? The team will explore trends driving customer interest in private AI, updates on VMware Private AI Foundation, and a deep dive into model governance and security. MemVerge will follow at 2:00 PM with insights into AI infrastructure software, including optimization strategies and a focus on checkpointing software for AI infrastructure. They’ll be joined by Steve Yatko from Oktay with key insights from enterprise AI applications.

On Thursday at 8:00 AM Pacific, Kamiwaza will showcase its orchestration engine for enterprise AI, emphasizing its ability to integrate with third-party applications, ensure data sovereignty, and enable high-efficiency AI inferencing. Key use cases will include real-time data transformations, dynamic sales plan creation, and automating back-office tasks. This will be followed by a roundtable discussion with the Field Day delegates.

We’re also thrilled to get a look at the newest and largest study of AI opinions from CEOs. This groundbreaking research explores how global leaders are approaching AI and is presented by The Futurum Group‘s Dion Hinchcliffe.

Follow the Event LiveAll of our sessions are broadcast live on LinkedIn and TechStrong TV, as well as the Tech Field Day website, and our partner sites, including Techstrong AI. The presentations are recorded and shared on the Tech Field Day YouTube channel, as well as on Techstrong TV. We welcome participation on X/Twitter or Mastodon using hashtag AIFD6, as well as on LinkedIn.

You can learn more about the event and our panel of independent technical influencers by visiting the Tech Field Day website. Each of our delegates has their own blog, podcast, or social media platform where they share their thoughts on enterprise technology. We’re pleased to welcome Dr. Bob Sutor and Mitch Ashley from The Futurum Group, as well as Jon Swartz from Techstrong as part of the AI Field Day delegate panel. Thank you for joining AI Field Day live January 29th and 30th, or on our social media channels.


© Gestalt IT, LLC for Gestalt IT: Redefining Enterprise AI Strategies at AI Field Day 6

View Details

Futurum Intelligence recently released its CIO Insights dataset that reveals what IT leaders think are their biggest challenges in 2025. A staggering majority (89.9%) says that they see talent acquisition and retention as their greatest problem.

This checks out with and explains the general excitement around as-a-service solutions. In networking, the interest in network-as-a-service (NaaS) offerings is getting palpable, and vendors like Nile and Meter are reinventing the old space with simple, but unorthodox solutions.

Offered on a cloud-based model that lets users sign up for a small monthly fee, NaaS solutions give companies the chance to avail a variety of support options without any capital investment. Like cloud, these offer ready-to-consume network infrastructures and integrated solutions that can be rented and used on flexible plans.

“The goal is to create an experience where buying network connectivity is somewhat akin to buying electricity today,” said Ron Westfall, research expert and analyst at The Futurum Group, echoing Nile’s marketing message, at the Mobility Field Day delegate roundtable.

“The NaaS market is going to grow to double digit CAGR over the next several years. It’ll be over $100 billion by the end of this decade because of the combination of new intelligence and AI-enabled enabled capabilities – whether it’s talking natural language to the network, or solving a lot of problems that can take days, weeks, months to do with the established ways,” predicts Westfall.

But adequate skepticism prevails over what these solutions can do and what they mean for the future of networking.

There is great convenience in leaving the care and feeding of the Wi-Fi to a responsible party that would do everything from planning and designing to operations in exchange for a monthly pay if they are able to offer the level of service required. Especially in a down economy where company IT budgets are shrinking every day, this is a highly attractive option for businesses looking to get out of the longer and costlier alternative route.

But what is convenience for one set of people is cause for anxiety for another. “Some people want the control, and some people are much more willing to take their hands off,” notes Darrell DeRosia, wireless engineer.

A Matter of TrustThe crucial factor in the success of any technology is the human trust factor. The humans that a technology enables must be able to trust it enough to be able to handover the tasks.

Drew Lentz, applications and wireless network engineer characterizes the fear of letting go as a “generational thing”. The popular response to self-driving vehicles is a good example. Most Americans initially said that they wouldn’t feel comfortable letting a computer get behind the wheels. But that mentality is slowly waning as autonomous vehicles are making big leaps in ensuring greater road safety.

It wouldn’t be too ridiculous, if, in the future, the technology is able to eliminate all road accidents caused by distracted driving.

In less life-and-death situations like enterprise networking, using as-a-service solution has a critical advantage. The provider takes full responsibility for the network performance.

“They are the ones responsible for it working or not working,” says Lentz. “They are saying don’t worry about the protocol, the channel size, or any of that. That’s going to be handled in a way that will deliver the quality of service that you’re expecting and if that doesn’t meet your SLA, then you don’t pay.”

But skeptics remain unconvinced. “Half of what they are selling you is snake oil,” says Lee Badman, IT analyst.

ScreenshotWhen it comes to messaging, companies often furnish numbers and figures to substantiate their case. Network-as-a-service companies for example claim to reduce TCO by a significant margin. Badman sees these claims as overblown and designed to make services sound more advantageous than they are.

A provider cannot make such promises without knowing anything about a customer’s environment, he says.

“Why people are butting up against this idea of someone else walking in and doing these things for them is because right now in their network, they can pull the stats, and if those numbers are consistent and the users are happy, then they don’t need a new solution,” notes Tom Hollingsworth, former network engineer, and event lead for Tech Field Day.

In and of itself, network-as-a-service is a powerful vehicle for advancing companies’ efforts to provide users top-notch experience. It is the cornerstone of network automation and provides an alternative path to hiring and reskilling in-house talents. But to tap into it, companies must hold the provider accountable to make sure that they deliver as they promise.

There are many ways to measure the quality of service and gauge if a provider is meeting its SLAs, says Hollingsworth. The volume of trouble tickets customers are raising or speed test results are key indicators.

There’s also growing transparency from the vendors which is helpful for establishing trust. More providers are working to offer customers broad and sweeping visibility of their environment, including deep and sub-second feeds of the states and health of network equipment and level of user experience, so that they know when thresholds are violated and if things are being resolved properly and punctually.

For more on this, be sure to check out the delegate roundtable – The Future of Wireless-as-a-Service – and other interesting presentations from the recent Mobility Field Day event,.


© Gestalt IT, LLC for Gestalt IT: Insider Perspectives on NaaS

View Details

Automation is designed to help professionals in any niche reach max productivity in least time. But what does that mean for the future of employment?

Since automation has emerged into public consciousness, there’s wide expectation that it will surge up productivity creating room for cutbacks. Automation tools and technologies are finding broad use at companies. The biggest beneficiaries are organizations where employees are leveraging the technology to ramp up output – and get more done than their share of work, allowing employers to run bigger operations with a relatively small staff.

In the recent years, a ton of low-skill, routine tasks have been automated putting many people out of job overnight. Many others face the risk of losing employment because of the growing popularity of the technology.

Jobs like full-service checkout at a grocery store, tax filing, record keeping, and cashier and clerical positions are fast going away. The U.S. Government Accountability Office estimates that approximately 9% to 47% of jobs can be replaced with automation as the technology matures.

While automated processes no doubt have benefits – flexibility, and opportunities for cost reduction – the question becomes should everything be automated? Stephen Foskett, president of Tech Field Day, asked this question to the panel at the recent Cloud Field Day Delegate Roundtable.

The panel offered two distinct but opposing views. One set of people that is pro-automation said that technologies like AI and robotics have clear benefits, and are an inevitability. The other group is opposed to wholesale automation and worries that it may create a wide socio-economic imbalance.

“We as technologists, like to automate things, but we tend to forget that there are human beings currently doing those thing, and we don’t really think about the effect on them very much, and we should,” notes Justin Warren, who runs a boutique analyst firm in Melbourne.

Mr. Warren humorously reminds that some things should never be automated, for example being a parent or looking after a pet because they are fun to do.

Mr. Warren belongs to a group of IT insiders that anticipates a mass displacement of select jobs in the years to come.

“Automation has allowed us to feed a lot more people than we ever could before. It enables us to provide people with healthcare and clean drinking water and a whole bunch of fundamental and transformative things,” he notes.

“But we should also be careful about how we do it and the transition from one to the other because sometimes it’s going to put someone out of a job and if we don’t care about those people, they might not care very much about us.”

This dovetails with what economists at Darmouth and MIT found in their research. “Firms do not necessarily take into account the consequences that automation has for their workers. Instead, they tend to focus on the value that automation will bring to the firm and its shareholders,” one of the research co-authors commented.

The socio-economic implication has caught widespread attention, and a debate is raging over how the technology will restructure workforce and impact labor market dynamics.

Ken Nalbone, specialist engineer and tech leader, holds a different opinion. He argues, “Over and over throughout history, every time somebody automates some old job that somebody was doing manually, there’s “luddites” – literally, that’s where the term comes from – that’s going to throw the contraption overboard because they don’t want to be automated out of a job.”

“But the rest of the world needs to make progress as humanity,” he insists. “And this is something that we don’t need humans to do anymore, and why should they? When they could be doing something else more productive or more fulfilling.”

Like Mr. Nalbone, most people support the idea of replacing process-based routine tasks that do not require human-level creativity to be handled by automation.

Jack Poller who is an industry analyst also shares this view. In the specific context of cloud, Poller says that automation is a smarter alternative to recruiting humans for repeat processes.

“Automating routine tasks enables your cloud employees to go and do stuff that provides greater value,” he says. “The other thing is, so much happens in the cloud so quickly that it is virtually impossible for humans to keep up, and that’s what’s driving the desire to automate these tasks because we really don’t want humans involved because of the mistakes they make and what impact that has on the business.”

In multiple scenarios, automation has the potential to stamp out the occurrence of errors by aiding humans in a diverse set of tasks. In software development for example, tools like Docker, Kubernetes, Ansible and Terraform, and automated processes like CI/CD, IaC and automated testing, have proven helpful in checking human errors by putting manual tasks on a set-and-forget mode leading to improved software quality, faster releases and overall reduced cost.

Nevertheless, the decision to use or to not use automation remains supremely tricky because the technology, by design, is not infallible, or unbreakable.

“Automation is certainly not without peril,” reminds Mr. Foskett. “Most automated systems are extremely fragile and have very little quality control or quality assurance. Basically, they just assume they’re going to do it right and when they don’t, everything falls apart. I think all of us have experienced that, and it’s a fun day.”

Automation systems in certain applications have proven unreliable simply because of technological limitations. The National Library of Medicine published a paper that shows with example how sensors designed to sense states in the environment get things wrong due to limited detection capacity, or in-vehicle navigation guides fail to give users right directions because of using outdated information.

Human management of these automation errors offers a sliver of hope and shows how humans and machines can work together to build the future.

There are in fact ways to steer around the possible “technological unemployment” that automation is predicted to cause, but there are conditions.

One way to keep human expertise from losing its value in the face of innovation is upskilling.

“If we get people to embrace the automation to upscale into the automation, I think it pushes the societal element of cloud forward,” opines Jay Cuthrell, influencer and entrepreneur. “Once they’re in the boat, we can all be much much safer in the boat than in the rapids.”

But no matter what, one cannot overlook that “a lot of understanding gets lost when things are automated,” reminds Mr. Foskett.

“What if we allowed ourselves to automate stuff in a slightly different way?” proposed Mr. Warren.

He believes that through mindful and responsible implementation, automation can be prevented from becoming a threat to the livelihoods of the masses. This would entail avoiding extreme automation, slowing down the current pace of automation and understanding what improves the welfare of the people in the organization, and working out ways to deliver the broad benefits of the technology.

When automation is used to amplify processes rather than to ratchet up business profits at the expense of the workers, everybody gains. Skilled crafts and workers do not need to get replaced every time a groundbreaking technology arrives in the market. Humans and machines are not meant to cancel each other out. If the concept of human-automation interaction is understood and leveraged well, the economy can progress from the momentum of technological advancement, and economic well-being of the people is assured.

For more, be sure to watch the full Delegate Roundtable from the recent Cloud Field Day event.


© Gestalt IT, LLC for Gestalt IT: Automation Will Change Our Socio-Economic Canvas. But Will It Assure Economic Well-being?

View Details

Aviz Networks, the California-based AI networking company, has made entry into the Japanese telecommunications market, offering an open networking solution that is tailored mindfully to the national networking infrastructure and regulatory demands.

The Fuss over QualityCompanies may be waking up to the competitive potential of quality products just now, but the obsession for quality originated in ancient Japan. Japan’s rigorous code of quality is well-known worldwide. It is the force behind the precision and perfection of its goods. Woven into the Japanese culture, nowhere does the value manifest more clearly than in the country’s organizations.

But now a crisis is brewing in the Japanese telecom industry because of it. As a rule, Japanese telco companies are required to provide round-the-clock high-quality connectivity to customers. Any outage, if its non-emergency and lasts upwards of an hour impacting more than 1M users, require regulatory reporting.

To be fair, having a consistently performant network saves companies and customers a multitude of expense, and unnecessary grief down the road. But there are significant challenges to delivering it.

“As 5G SA (standalone) and NSA (non-standalone) grow and probably 6G coming soon, the network is getting larger and larger and even more complicated…The impact range is expanding when an outage occurs making network operations more challenging,” noted Atsuhiro Aiyama, director of Itochu Techno-Solutions America Inc., a Japanese technology reseller that helps Aviz Networks distribute its AI networking technology in the Japanese market.

The companies struck up an alliance to make Aviz Networks solution’s unique advantages available to the Japanese telecom sector.

But penetrating the Japanese market is no small ambition. Despite being an established brand on home soil, Aviz faced substantial hurdles entering Japan. It took understanding the high standards of Japanese patrons, and assembling a product that fully meets the ask.

Preventing Issues with Proactive NetworkingIn partnership with Itochu Techno-Solutions, Aviz Networks ran a proof of concept (PoC) that lasted one year. The payoffs justified the effor – in the end, the quality of the solution was markedly elevated, while costs had shrunken significantly, Aiyama told.

“We were able to not only improve the performance and the quality of the network, we were also able to tremendously reduce cost, both initially and the operational cost, compared with other traditional OPB (Open Packet Broker) kind of products,” he said.

Aviz’s solution constituted some core technologies on its portfolio, namely, the Aviz Networks Open Networking Enterprise Suite (ONES), the Open Packet Broker and Aviz Service Nodes for observability, and the Network Copilot for the coveted AI experience.

“We need more raw data observability to optimize the network performance, and especially improve the quality of the experience to subscribers,” Aiyama pointed out.

Aiming those, Aviz put together the most wholistic solution it could design. “We are building the whole packet monitoring fabric and then putting service nodes on top of it. We’re bringing an end-to-end solution,” said Chid Perumal, CTO, while narrating the success story at the Networking Field Day event.

Open-source by design, ONES allows deployment of multi-vendor SONiC while being compatible with multiple NOSs. It unlocks proactive monitoring and management and streamlined orchestration of network operations.

The Service Nodes, powered by AI, add capabilities like packet processing and high-speed data insights, offering the deepest visibility of the environment.

Lastly, the Aviz Network Copilot, a conversational interface, enables a range of operational tasks like upgrade checks, configuration, capacity planning, troubleshooting and auditing, while facilitating decision-making for operators with real-time insights and intelligence.

“Quality is one of the key requirements for Japan, and we have passed that biggest hurdle which makes us comfortable, and now we can get into any other telcos. The requirement remains the same except for small changes. The overall capability or the features they’re looking for is already there, and it can be easily replicated beyond Japan,” Perumal said.

As advanced technologies like 5G and 6G enter the market turning networks more complex and unmanageable, centralized orchestration and management will play a critical role in stripping away operational inefficiencies. And solutions embedded with GenAI will find the widest use because of their capabilities to lighten the burden.

For more, be sure to check out Aviz Networks’ presentations from the Networking Field Day event at on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: How Aviz Networks Cracked the Strictest Quality Code and Made Entry into the Japanese Telecom Sector

View Details

Cisco is set to merge Ultra-Reliable Wireless Backhaul (URWB) and Wi-Fi functionalities in its access points (APs). At the Mobility Field Day event, the company announced that starting 2025, URWB and Wi-Fi will be supported in the same access points whereby both functionalities can be simultaneously used on the same device.

The update came just days after Cisco issued end-of-sale notice for all its LoRaWAN products.

As of today, URWB is deployed on a separate infrastructure comprising its own set of APs and management planes. This requires customers to maintain a parallel overlay to Wi-Fi. With this new update, both the solutions will be on one infrastructure with reduced footprint and overhead.

“The point of all of it is to offer the functionality to customers without needing to double the infrastructure or have two parallel infrastructures of access points and management planes,” said Dave Benham, senior product manager.

Optionally, users can keep using their current URWB architecture should they prefer it. Cisco will continue support for URWB in the usual way. “Think of this as an additional functionality for your existing Wi-Fi infrastructure, not necessarily something we’re forcing you to do.”

Set to be released as a software update, the new feature will provide unified software image and management platforms.

URWB and Wi-Fi images will not be required to boot separately, said Benham. “You boot it one way or the other. It’s only one boot.”

The feature can be enabled on a radio or an access point on both local and Flexconnect modes. “It supports both modes of operation,” he told.

All APs will be managed by the Cisco Wireless LAN Controller (WLC) for now, but more options will be supported in the future.

“For cases where you have an IW9165 for example, as the mobile device, that device will be managed by the WLC as well.” This will give users a single point of control to monitor and manage all APs.

The joint solution will include all URWB features – reliable fiber-like wireless connectivity, sub-millisecond low latency, with the added ability to run all critical applications on the same APs.

For fixed infrastructures, URWB supports Point-To-Point, Point-To-Multipoint, mesh and a mix of topologies, and offers zero loss roaming for mobile architectures.

“Have you ever wished that your wireless devices could roam seamlessly with zero packet loss or that you had less latency and jitters so that your critical wireless devices could have redundant connections to multiple APs?”

URWB was created to overcome the reliability limitations of wireless. Its signature “make-before-break” feature enables connections to be moved reliably between APs without service drops.

The Multipath Operations (MPO) technology allows users to route high-priority packets through redundant paths. URWB sends duplicate traffic to two different APs so that if connection is interrupted on one, packets are not lost.

“Basically you can decide which traffic is important enough that you want it redundant,” Benham said. “It doesn’t mean that your entire infrastructure is redundant necessarily. You have certain things that you want to promote the redundancy for,” he added.

Currently, Cisco URWB addresses a spectrum of mobile and fixed use cases in the sectors of manufacturing, rail, mining and smart cities. The new update, however, will not support all of them right out the gate.

“We aren’t going to support all of the elaborate use cases that URWB supports today. There will be a few that we can’t support initially, but we’re moving to that parity of having all of the features there, and I think a lot of use cases will be satisfied with the initial launch.”

Benham named manufacturing, and campus and smart cities as the key use cases that the new update will primarily support, specifically automated ground vehicle (AGV), video surveillance, building to building connectivity, and roadways and intersections connectivity.

Cisco AP models that will add support for URWB next year include older models like C9130 and C9124, as well as recent ones like CW9178, CW9176I and CW9176D1.

Wi-Fi 8 strongly prioritizes reliability, and promises to bring a much-improved roaming experience with multi-AP coordination, but with the standard still in development, it may be a few years before it sees the light of day.

“Wi-Fi 8 may have some things that can make it a bit more graceful, but it may not be in the initial release,” Benham predicted.

For more, be sure to watch Cisco’s presentations from Mobility Field Day on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Cisco to Add Ultra-Reliable Wireless Backhaul to Wireless APs in 2025

View Details

An issue that has plagued enterprises, especially small and mid-size outfits, for most of their operational years is the operational burden of the network. It has piled on over the years as the network has scaled leading to a litany of issues and complaints.

The slow burning complexity of managing a ornate network model has caused frequent burnouts in employees, while cost blowouts from new tech acquisitions strain enterprises’ budgets.

Now companies are taking a decidedly modern approach to tackle this problem – automation.

Automation obscures a lot of the underlying technicalities while getting the bulk of the routine job done with little to no manual intervention. Analysts project that this can transform the way networking activities have been done through the decades.

Yet, implementation has been irregular nationwide. Although the potential of the technology is universally recognized, experts observe that businesses have not been able to derive measurable value owing to a number of factors.

The cost of developing automation solutions is significant, and often beyond the means of companies that have limited resource. This is further exacerbated by sparse availability of deep domain expertise which makes it harder to build the technology inhouse.

Those companies that can devote the necessary resource are unimpressed by the limited usability of homegrown automation solutions.

A NaaS Solution That Offers a Premium Automation ExperienceA network as a service solution like Nile’s is an enticing option for these struggling enterprises. Nile Access Service that includes Day 0 to lifecycle management automation, takes the entire operational load off of their hands, requiring neither to hire expertise, nor bear the costs of adding third-party tools.

“Typically, when you raise an issue, subject matter experts get involved. You have to go through the hard work of writing a runbook, and there is no magic there,” said Dipen Vardhe, head of Wireless Service and AI Automation Center at Nile.

With Nile, all of the manual tasks of configuration, setup and maintenance are carried out behind the scenes and a truly automated network is delivered to the users.

But how does Nile accomplish this? Vardhe gave a sneak peek of the backstage workings at the recent Mobility Field Day event.

A central piece of the service is the Nile AI Automation Center. This is not a solution that customers interface with, but nevertheless, plays a critical role in Nile’s network operation and optimization services.

“Once the network is up and running on Day 1, internally in the AI Automation Center, it’s ready to be operated and optimized by the Nile team,” said Vardhe.

Designed specially for Nile’s internal team of network engineers, the Nile AI Automation Center is a strikingly plain tool whose function is to catalogue and display information and analytics.

To a Nile network engineer, it principally shows the devices under observation, and the automated actions and optimizations performed on them. Users can view detailed reports of auto-detected point tickets, and the automation runbook that have been deployed to resolve the incidents.

Additionally, the solution provides tenants’ network details like activated Nile elements, AP and sensor placement, and open and accepted deviations. In a highly organized but barebone view, the solution highlights these via a digital twin.

Nile’s team gets access to all this information in real-time. Data gets auto-collected and logged into the console as the incidents are happening.

“During Day 2, we want to make sure that the internal line teams, when they are trying to triage an issue, are able to have all this information about the deployment at their fingertips,” said Vardhe.

But blind automation can just as easily break things, and Nile is mindful of that. Internally, their team of SMEs and engineers constantly review the decision graph that powers the automation to make sure that it is working as it should, Vardhe told.

Lastly, all of this is made possible by Nile’s standardized single network architecture, its fleet of physical and virtual sensors, baked-in advanced automation tooling, and a unified data store.

With “no customer-facing knobs”, and a robust team working tirelessly behind the scenes to keep things going like clockwork, Nile’s automation service is designed to deliver a white-glove experience to it users. Not only does it lift the burden substantially by rendering a lot of the operational tasks invisible, it also brings enterprises closer to a “near-autonomous” network that, for all intents and purposes, drives itself.

Watch Nile’s presentations from the Mobility Field Day to learn more about the Nile Access Service.


© Gestalt IT, LLC for Gestalt IT: Behind Nile Access Service’s Robust Day 2 Automation Is a Little-Known Solution

View Details

Imagine spotting a teeny-tiny needle in a stack of hay. The odds are one in a million.

That’s how most network engineers describe the experience of finding the root causes of network issues. Root-cause analysis or RCA, the process of spotting the invisible factors behind a network incident, is long and winding – and inescapably manual.

Shockingly, monitoring tools designed to make the job easy are one of the key reasons for this. A highly complex setup process involving manual configuration of tools to the devices makes the job inherently tricky. It is easy to miss out some things occasionally, especially when new appliances are being added every day.

“Eventually you will say, I can’t spend another six weeks full-time, configuring and building it out any further. This is as far as you get,” says Tim Titus, CTO and founder of PathSolutions, a company that specializes in automating network monitoring and troubleshooting.

Operators “just want something that tells them what’s broken in the network,” he stresses.

About 17 years back, this led Titus, then network engineer, to quit his job and embark on a startup venture based out of his garage. Thus was born PathSolutions.

Accelerating the Journey from Discovery to Mean Time to InnocencePathSolutions TotalView, a continuous monitoring software solution, aims to give network operators a break from manual RCA and troubleshooting. In a lot of ways, it shortens and simplifies the journey of discovery and remediation as we know it.

The solution deploys on a single machine, typically a VM in the datacenter or the headquarters, told Titus while presenting TotalView at the Networking Field Day event in Silicon Valley last month.

Using SNMP, it pings every device in the network – switch, router, gateway, firewall and interface –building the inventory. This gives it the broad, enhanced visibility essential for network monitoring.

“We go far broader than any other solution,” he highlights.

But more depth and granularity are required to perform troubleshooting, and for that, TotalView picks up individual data from touchpoints all over the network.

“Network equipment have an amazing amount of intelligence stocked up inside. We go deep and automatically pick up all the performance, configuration, 19 different error counters of information, QoS, CDP/LLDP, PoE, and all that rich information,” irrespective of the model or the make of the equipment.

The data is then sent into a heuristics engine that processes it using logic. The output is a detailed report of diagnostics of all the errors happening in the infrastructure.

Findings and recommendations are published in plain English to keep the information digestible for all personas, he says.

One clear benefit of this depth and breadth of visibility is timely resolution of failures. “You’re going to be able to do proactive troubleshooting – maybe for the first time in your career – and say, I can solve the problems before the users complain,” he says.

Titus claims that TotalView reports back every incident in the network on Day 1 of deployment. “By the end of the day, we’re going to tell you everything your network equipment knows is broken,” he underlines. This can reduce the lengthy, tangled process of tracing root causes down to hours.

TotalView also weighs in on the troubleshooting work. The solution generates “network prescriptions” for all errors detected, allowing more trouble tickets to be resolved and closed at the tier 1 help desk. The bulk of issues settled lower in the organizations allows for faster and more cost-effective troubleshooting.

“They can solve the cabling faults, the duplex mismatches, the PoE faults,” with no need to escalate, leaving only the most difficult tickets for the senior-level staff.

Additionally, to keep the network healthy and the number of incidents minimum by default, PathSolutions offers a bundle of essential features out of the box. These include diagramming, path mapping, port mapping, server monitoring, event correlation, cloud service monitoring, full inventory, IP address management (IPAM), BGP monitoring, configuration management and automation, all aimed at keeping the network running with minimum intervention.

Optional Add-On ModulesAlso added in the solution is a set of optional modules curated for specific personas and use cases. For example, the TotalView Telecom Ops Module is aimed at telecom personnel. It specifically includes telecom operations features such as VoIP visibility, path mapping, call simulator, SIP-Trunk monitoring and WAN health, all of which offer deep visibility into the VoIP infrastructure, and provide ready analytics for call quality issues.

Similarly, the SecOps Module, designed for the SecOps team, offers certificate monitoring, OS vulnerability detection, geography risk management, exposure reporting and IoT security, services that are critical to ensure security of the network.

Other modules available on the platform are NetOps and remote user troubleshooting.

Check out PathSolutions’ presentations from the Networking Field Day event to get a holistic idea of TotalView’s capabilities.


© Gestalt IT, LLC for Gestalt IT: Automated Visibility: PathSolutions’ Formula for a Swift RCA and Prompt Debugging

View Details

The best way to monitor the network is to take pulse of everything in real-time. That in essence was the message from Arista Networks during the Networking Field Day earlier this month.

“When it comes to a problem happening in the network that’s impacting your users, understanding that that’s happening before your user opens the ticket,” can provide significant edge to a company looking to deliver an even experience, said Andre Pech, VP of software.

CloudVision, Arista’s flagship orchestration and automation solution, helps get a sense of what’s happening in the network as they are happening.

A decade old now, CloudVision seeks to address a persistent problem in networking – broken visibility, and stilted access to network data.

SNMP tools make an easy pick for polling tasks, which explains their ubiquity in enterprises even today, but they have vices. On one hand, the tools can poll devices and stream back data points that are helpful for monitoring and management tasks. Broad compatibility and low cost on top of that have made them a standard through the decades.

But SNMP struggles to produce in-depth, sub-minute data that is considered a necessity with modern network monitoring. SNMP’s infrequent polling, limited scope and low data granularity pose an obstacle course for network operators, often leading them to incorrect and unreliable readings.

“And when you don’t have access to the data, you turn to the CLI (command line interface)”, reminded Peche, which is often intimidating for non-technical people.

Arista’s CloudVision adds a series of well-thought-out capabilities built on a top-down approach. The goal is to provide unrestricted visibility of the network by focusing on some key pointers – how is the network performing, are users having any issues, and how quickly can one get to meantime to innocence or remediation, Peche said.

CloudVision streams network states in real-time, capturing every state change with sub-second granularity, a sharp contrast to the legacy per-device polling approach.

This data is stored in a scale-out database for historical access, and users can compare data points across time using its time series view. The broad visibility of network data also facilitates live monitoring and troubleshooting.

Screenshot“Traditionally you have your flow collector, and your management collector. But you really want both of them together….We bring it all into one place,” Peche told.

CloudVision captures both flow data and control plane packet data. “This is how we’re able to expose the full state of the network and continue to add features without having to upgrade the network.”

With CloudVision’s integrated flow tracker providing visibility into traffic patterns with real-time flow record streaming, operators can up their capacity planning and gain better understanding of the origins of latency issues.

CloudVision, under the hood, taps into Arista’s core offering, Extensible Operating System or EOS.

“A lot is enabled by EOS and its state-based architecture. We have built CloudVision to stream all of the state off-box. This includes interface counters but also everything you can get from the CLI.”

CloudVision’s scope of visibility is a big leap towards AI-based predictive monitoring.

Peche explained with an example.“We built a model looking at all of the transceiver data in our network. We ended up building a model that looked across these that today can predict about six weeks earlier that a transceiver is going to fail.”

He hopes this super-granularity is going to continue to be the big differentiator for the platform, as it competes with newer solutions.

Arista Networks is a big believer of “building it right” and invests continually in its solutions to deliver cutting-edge features and bring more use cases into the fold. Core to CloudVision is the same platform-focused mentality that allows the company to elastically expand the product with layers of innovation instead of building new solutions from scratch.

“We built it as a scale-out, multi-tenant, cloud service architecture knowing that this is where we wanted to go.”

However, CloudVision is not designed to subsume point products. Many of Arista’s customers use SNMP tools in tandem with CloudVision. Their coexistence allows for improved triaging and faster response.

“The goal is to really make it easy to debug and understand everything you can about the network,” Peche said.

Watch Arista Networks’ presentations from Networking Field Day event to watch CloudVision in action and get a closer look at the feature-set.


© Gestalt IT, LLC for Gestalt IT: Arista Networks’ Visibility Goal with CloudVision

View Details

Automation is widely viewed as a productivity tool for consumers, but rolling out infrastructure automation at scale that can potentially save tens of hundreds of hours, has remained an uphill battle for adopters.

CEOs say that it is downright hard and convoluted to share and standardize automations across the board.

Automation solutions are typically built within small groups of engineers who use them internally or even individually, without plugging into other parts of the business, said Wyatt Sullivan, technical marketing engineer at Itential, a network and cloud automation provider based in Atlanta, GA.

It is extremely tricky for them to engage other people without getting clobbered. There are some big obstacles right out the gate. Each task is a different script – and they may be written in different programming languages – with varying levels of access.

“Operationalizing automation and sharing it with everyone else is its own problem,” Sullivan emphasized.

Engineers are stuck in “operational hell” because of the web of operational tasks tied to it. Imagine the perils of engineers, who, besides having to do the heavy work of building automation workflows from scratch, have to train and tutor people with no initiation to use the technology in their day-to-day work.

For those outside, automation remains esoteric knowledge. Libraries of automations get discarded and are never used again when their engineers leave.

As a result, many companies struggle to mobilize automation in all sectors of business, and have so far used it in a stilted and constrained way within small teams.

Now the rise of operational complexity is testing the way automation is deployed .

Automation, Self-Service StyleItential is working to widen the reach of automation solutions designed by network operators and developers by focusing on operationalizing them without piling up the work for them.

““Operationalize” is kind of a buzzy word. What we are trying to say is how do I get automation beyond myself and share it with my team,” Sullivan elaborated.

This month, at the Networking Field Day event in Calif, the company launched Itential Automation Service, an automation-as-a-service offering that it says will help NetDevOps share, and Operations team execute infrastructure automation at speed.

The solution that is designed to help enterprises “get started quickly and scale seamlessly as needs grow”, adds a set of capabilities that reduces the amount of work otherwise needed to a just few clicks.

A cloud-delivered service, the Itential automation solution has two sets to capabilities addressed individually to NetDevOps and Operations. Powered by Itential Automation Gateway (IAG), the service offers dynamic execution environments for running automation on ad hoc basis. These are single-use environments that can be used to execute scripts instantly, or schedule for future, and can be removed after use.

It can handle any framework, any script, said Sullivan. Developers can consolidate their Python scripts, Ansible playbooks and OpenTofu plans all inside the environments, while operators can view and execute them without any handholding.

Real-time Git pull automatically pushes the automation scripts into a Git repository from where users can then pull and use them to build services. Engineers do not have to worry about how code gets passed down beyond publishing, Sullivan highlighted.

To make it easily executable for personas not involved in building automation, the solutions are packaged as easily shareable self-service solutions. Self-service access ensures that NetDevOps people do not have to share it manually.

The operators’ view, Sullivan highlighted, is equally feature-rich. Role-based Access Control (RBAC) allows operators to regulate access based on roles. A service-based structure is offered to operators as well, who can also plug into the pipelines of third-party solutions like ServiceNow using the solution’s API-driven integration.

“It is creating a new way to deliver applications,” said Sullivan.

Check out Itential’s presentation at the Networking Field Day event to get a feel for the product from the demos, or sign up for a free 30-day trial to tinker with it.


© Gestalt IT, LLC for Gestalt IT: Itential’s Automation-as-a-Service Solution for Operationalizing and Standardizing Infrastructure Automation

View Details

In 2015, brothers, Anil Varanasi and Sunil Varanasi, founded Meter, a networking-as-a-service company based in San Francisco, selling proprietary networking hardware and software products with full-stack service rolled into one package.

Adopters can buy entire networking infrastructure for a monthly subscription. Meter, besides supplying all the hardware and software under the hood, also oversees setup and installation process – as well as manages the donkey work of maintaining the infrastructure beyond Day 1.

Complexities of setting up internet infrastructure for business have been on the rise, making it harder for slim groups of network engineers to wind up everything inhouse. One setup, depending on the physical footprint, can take months to a year to fully deploy. After months of planning and budgeting, expensive acquisitions and endless vendor negotiations, companies are left with the bulk of the work – a lifetime of support and maintenance.

This cannot be done without a dedicated staff of skilled network engineers. Ironically, for many years now, the industry is grappling with a dwindling labor market while the number of applications, devices and users have been on a steep rise.

Even worse, the rate of innovation in the networking hardware space has been consistently low. “Somehow in the last 10 years, everybody’s come to agree that hardware is commoditized, and it’s sort of become its own self-fulfilling prophecy where nobody’s really spending a lot of time making great hardware,” noted Anil Varanasi, CEO and co-founder.

A Novel Way to Woo the CustomersMeter gets creative and experiments with the traditional business model to rein in the costs and connect with struggling customers. This leads to a lineup of proprietary hardware equipment constituting security appliances, switches, access points and PDUs.

“The goal is to make infrastructure for the most ambitious companies in the world – and that’s across offices, life sciences labs, schools, retail, warehouses and manufacturing.”

Four key verticals dominate Meter’s customer base – schools, shipping carriers, financial organizations, and fast-growing firms that rely on high-performance, dependable network connectivity, Anil Varanasi told.

“On the product side, our incentive is much aligned with customers,” he said, referring to Meter’s unique pricing policy around hardware, at the Networking Field Day event in California.

“We are not looking to sell a box of hardware for a margin to our customers. We want to sell great networks,” he told.

Meter’s OpEx model offers customers its managed service for a subscription without having to bear the upfront cost of hardware or updates.

“We take the capital risk entirely on ourselves for the hardware. We never charge for the hardware, including when we do upgrades, invent new things, any reason it might be,” he said.

The sticker shock of hardware refresh when moving to a new solution is one of the biggest deterrents holding companies back. This model can help eliminate that barrier creating lifelong customers for Meter.

Blanketing the hardware is Meter’s software products that together enable “the fortuitous loop” of powering one another.

Meter’s team of network engineers designs, installs and configures the hardware, while another group supports and manages the network post-deployment, making sure everything is running smoothly, software updates are pushed on time, and troubleshooting is done when things break.

“We believe to build great networking, you have to do it all together. Doing it separately is not something that we found can lead to incredibly great outcomes for customers,” he said.

No Need to Sink Old Investments for New Ones; Meter Has a Way AroundBut with even a fully managed, integrated solution like it, customers face the difficult choice of having to rip out their existing infrastructure. Meter offers a buyback program to expose its solution to those customers who are worried about losing old investments. The plan allows them to trade in old legacy hardware for a credit that is adjusted from their billing when subscription kicks off.

By giving customers a chance to redeem old investments, Meter hopes to eliminate sunk cost while presenting the opportunity to upgrade outdated equipment.

What does Meter gain from it? “Learning about how the network is set up and feeding that back into our own design and configuration” is how Meter keeps innovation in its own product alive and kicking.

Meter also offers an ISP procurement service. For the past five years, Meter Connect, a managed and ISP-agnostic service, has aided customers to find the best internet service provider in their area and help work with existing ISPs. Meter Connect handles negotiations, billing, and support on behalf of the customers.

“Think of it as Kayak or Expedia, but for ISPs,” he said.

This is how it all comes together. Typically, customers reach out to Meter – directly or through its network of partners – with site details, like address and floor plans. Meter’s network engineers have a sit-down with the customers about planning and design. The resulting topology, besides being customized squarely to the footprint, is also extensible to connect to PoP infrastructures and other data centers.

Old infrastructure equipment are removed from the floor, and cabling and installation of the new hardware block begins.

“We’ve seen that if you do the Day 1 part really well, a lot of times you avoid mistakes that will bite you 6 or 12 months from now,” he said. Extra attention is paid to ensure that everything is set up to work optimally

From the integrated software layer, configuration, validation and testing, and onboarding are carried out.

Once the infrastructure is live, operations kick off. This includes servicing, updates, lifecycle management, troubleshooting – the whole nine yards.

Meter believes that the vertical integration – the strategy of gaining control of production to ensure better quality – effectively leads to “a great product and a great service for IT and networking teams”. One clear advantage is that the buyback program. Coupled with the OpEx model, the model will help many struggling enterprises organize their spend and sidestep a load of inefficiencies that come from using multi-vendor solutions. Currently, Meter also offers a capital lease model.

Watch the presentations from Networking Field Day event where Meter explains the technology and dives into the architecture to learn more about the platform.


© Gestalt IT, LLC for Gestalt IT: Meter’s Pricing Model: Can It Make Networking Affordable for Businesses?

View Details

Not so long ago, perimeter-based security used to be the only form of security needed to guard corporate environments. That was until lateral movement became a common trend in cyberattacks. Bad actors slipped past security at the gate and freely gained command and control of the environment.

Breaking up the environment into secure zones with microsegmentation reduces the risk of unauthorized access, and curbs free movement of entities. Microsegmentation works by limiting access based on need, and provides granular protection by placing security at the inner perimeters.

“Every single cyber security standard has said to segment the network,” says Dana Yanch, director of TME, at Elisity. “It’s a great first place to start.”

But companies have had microsegmentation solutions for years without significant adoption. The projects are prone to failure, say CISOs.

In a survey, Forrester investigated the reason. They found that the primary cause microsegmentation projects get discarded or derailed is snowballing complexity.

“It’s such a massive project and there’s so much complexity in the deployment of some solution to solve those problems that it gets put on the back burner,” says Yanch.

Microsegmentation drops more tooling on the lap of operators than they traditionally had that they are now in charge of managing. The management overhead surges up staggeringly leading to a quick analysis paralysis.

Other leading causes microsegmentation projects are killed off prematurely are insufficient visibility of the environments leading to enforcement anxiety. Being deeply disruptive, the projects end up getting a lot of pushback from the staff.

Policy Management Made EasyIn the last quarter, Forrester named Elisity a “strong performer” in its evaluation report on microsegmentation solutions.

An identity-based microsegmentation platform, Elisity is a software-only product that is designed to make microsegmentation for LAN click-button easy. The platform works by discovering users, devices and applications on the network, and matching them to the right policy, before enforcing the policies on the infrastructure.

“The goal is to mitigate the risk as quickly as possible, as efficiently as possible without any disruption to the business,” Yanch says. “The long pole in the tent of deploying a solution is eliminated”.

The platform, Elisity says, is a zero-impact deployment. “We can deploy it without a single second of disruption, not one packet lost, not one outage; you don’t even need change windows.”

Elisity has helped many organizations on segmentation journey to stay on track and achieve the ends at minimum friction and effort.

One example is GSK, a leading pharmaceutical manufacturer with a very large and complex network. GSK’s attempt to do segmentation the traditional way had ended in a disaster with nearly no progress made in 3 years.

“GSK was stuck in an analysis paralysis mode. We came onboard and helped them visualize what’s going on in their network across both their IT and OT environments, and pull it together,” he says.

According to Yanch, GSK now deploys sites at 17 minutes a site, going at 12 sites a month.

Elisity is clear-eyed about “time to value”, and as a result has a very quick and short sales process. It takes half a day for the Proof of Concept, compensating for minor errors and issues, says Yanch. How?

“A lot of the complexity that we’re used to doing in Proof of Value or deploying a solution has been packaged up and delivered as a service in the cloud,” he explained.

At Networking Field Day in California, Yanch took the audience behind the scenes to give a sneak peak of the process flow.

A cloud-delivered interface that serves as the main UI allows administrators to integrate cloud and on-prem solutions with Elisity. Elisity aggregates all identity information from third-party devices like discovery engines, databases, and even spreadsheets that some customers use to this day to store device attributes, and pull that into “one simple view and an easily digestible platform.”

“We don’t just ingest; you can export everything that’s been ingested and processed outbound. We have a very robust API mechanism to export absolutely anything in our product.”

Elisity’s IdentityGraph is a critical component of the solution. It’s an asset engine that triangulates accuracy and serves as the source of truth.

“If you’re doing identity-based and context-based segmentation, the platform that you’re using better have the best view of absolutely everything on the network, whether it’s a user or device.”

That’s what IdentityGraph provides, “the full picture” that tells operators what devices are verified, and which are not, what needs remediation, and what needs to removal. The contextual information from IdentityGraph also guides policy group implementation at a later stage.

Assets, depending on the policies, are grouped under policy groups. When a new device is discovered, it is automatically matched to a group based on the pre-created criteria on the device, and the policy is enforced.

“When it comes to enforcing, everybody’s a little afraid. Nobody wants to accidentally shut down a manufacturing line, or cause an outage where the company loses money.”

Elisity aims to build confidence by transparently showing administrators exactly what policy is enforced, when they are ready to hit the button.

A built-in analytics and reporting plane within the Elisity platform offers insights and tells “what’s real, and what’s rogue” before feeding the data into the CMDB tool in use.

Yanch told that the platform continues with the same level of full-time equivalent (FTE) even when the network grows.

For more, be sure to watch Elisity’s presentations from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Elisity Removes Barriers to Adoption of Microsegmentation in Hospitals and Healthcare Organizations

View Details

We’re closing out 2024 with one last look at the mobility and wireless space at Mobility Field Day 12. This year has seen some huge changes in the market, from new technology releases to massive vendor mergers. While 2025 is going to be a banner year from those that work without wires we wanted to make sure to give the stage to a couple of big names that are hoping to make waves soon.

Mobility Field Day Presentation ScheduleThe event will be taking place on Wednesday, November 20. We’re going to start off with our friends at Cisco. They’re coming off of Cisco Live Australia in Melbourne and they have some big announcements to discuss. One of those is the final combination of Meraki and Catalyst into a single wireless brand. I’m sure we’re going to learn more about this as well as hearing about some of their new advances in technology as well.

Next up is Nile. You’ve already seen them at Networking Field Day earlier this year but they have been one of the most requested companies at Mobility Field Day as well. Their approach to networking-as-a-service has had an impact on the way that organizations think about deploying equipment. Nile has a wireless component as well and our delegates are ready to ask them a lot of questions about how they take on the complex task of proper wireless deployments.

Social Media DetailsThe live stream for Mobility Field Day will be held on Wednesday, November 20. You can watch it on the Mobility Field Day event page, the Tech Field Day LinkedIn page, and even on our sister site TechstrongTV. If you want to be a part of the conversation you can leave a comment on our LinkedIn stream or jump on your favorite social media platform and use the hashtag #MFD12. If you miss any of the event during the live stream you can always head over to our Tech Field Day YouTube channel.

We’re excited to be talking about the state of wireless and we hope that you’ll join us!


© Gestalt IT, LLC for Gestalt IT: Making the Most of Mobility Field Day 12

View Details

From IT operations, platform engineering, and DevOps to application development, we’re considering the complete software lifecycle. That’s the focus at the next Tech Field Day event, AppDev Field Day, which we’re co-locating with the incredible KubeCon + CloudNativeCon, thanks to our partners at the Cloud Native Computing Foundation and TechStrong TV. We’ll be coming to you live and direct from Salt Lake City on November 12th and 13th. Tune in live on LinkedIn, DevOps.com, Techstrong TV, and check out the Tech Field Day website for the complete schedule.

Tech Field Day has partnered with Mitch Ashley of the Futurum Group to organize the AppDev Field Day event. We’re kicking off our next event in this series next week, broadcasting live from Salt Lake City on Techstrong TV.

Event ScheduleWe’ll kick things off at AppDev Field Day on Tuesday at 1:00 MT, 12:00 PT with SOUTHWORKS. They’ll explore the future of cloud migration and multi-cloud strategies, demonstrating how SOUTHWORKS leverages CNCF technologies to help customers realize the potential of multi-cloud.

At 2:30 MT, we’re welcoming Heroku, a Salesforce company, to AppDev Field Day. Heroku will showcase its evolving platform capabilities, including new developments in Cloud Native Buildpacks and OpenTelemetry, while reflecting on a decade of container-driven transformation in application development.

On Wednesday at 12:00 MT, 11:00 PT, we’ll be introduced to Codiac, a new company that simplifies container and cluster management, allowing organizations to focus on software development and applications.

Watch AppDev Field Day LiveAll of our sessions are broadcast live on LinkedIn and Techstrong TV, as well as the Tech Field Day website and partner sites including DevOps.com. The presentations are recorded and shared on the Tech Field Day YouTube channel as well as on TechStrong TV. We welcome participation on X/Twitter or Mastodon using #ADFD2, as well as on LinkedIn.

You can learn more about the event and our panel of independent technical influencers on the Tech field Day website as well. Each of our delegates has their own blog, podcast, or social media platform where they share their thoughts on enterprise technology.

Thank you for joining AppDev Field Day live on November 12th and 13th on our social media channels. Subscribe to our YouTube channel and follow us on X/Twitter, Mastodon, or LinkedIn for more Field Day updates.


© Gestalt IT, LLC for Gestalt IT: Exploring the Future of App Development at AppDev Field Day from KubeCon and CloudNativeCon

View Details

We’re thrilled to be bringing you the latest edition of Networking Field Day coming up November 6-7, 2024 in Silicon Valley. The reason why is because of the way that Networking Field Day advances the industry from a technology perspective but also from an eduction position as well. Our presenting companies and delegates bring the best discussion and content to the entire community. This edition of the event promises to raise the bar across the board.

Networking Field Day Presentation LineupThe event starts on Wednesday, November 6. We’re kicking off with Arista Networks and a look at CloudVision. They’ve been working hard to add new features and they can’t wait to give us an overview of the latest editions. The next presenter is a new part of the event, Elisity. They’re very focused on microsegementation and they have a novel way of making it happen in your network. This first look promises to be a refreshing way to think about network security for the delegates. The final presenter on Wednesday is Itential. There have been some great advances with their platform, including some interesting new workflow automation features. I’m sure their demo is going to be amazing and I can’t wait to see what they’ve come up with.

Thursday, November 7 starts out with an update from PathSolutions. They realize that troubleshooting is hard and they have some new features in TotalView that should make it easier like help with unified communications and NetOps. They’re followed by another new presenter to the event, Meter. The network-as-a-service space has been very hot lately and Meter is one of the companies making waves there. They’ll be talking about their end-to-end solution with a live demonstration of bringing a network up from 0 to 1. This demo will showcase Meter’s end-to-end solution—including our new generative UI product, Meter Command—empowering customers with deep visibility and granular control of their networks. Then we will wrap up with a presentation from Aviz Networks. You’ve seen them already this year back in February but they are back to tell you what they’ve been working on over the last year.

Social Media DetailsThe live stream for Networking Field Day starts on Wednesday, November 6. You can watch it on our Tech Field Day Event page, the Tech Field Day LinkedIn page, and on TechStrongTV. You can ask questions or make comments on any social media platform using the event hashtag #NFD36. If you miss any of the live videos you can always watch the replay on LinkedIn or check out the Tech Field Day Youtube channel for on-demand content.

We’re ready to raise the bar for technical education in the enterprise networking market and we hope to see you there!


© Gestalt IT, LLC for Gestalt IT: Advancing the Industry at Networking Field Day 36

View Details

The dream that every business and every application belong on a public cloud platform has faded into a more nuanced realization that applications have differing requirements leading to different implementations. There has also been a shift to accepting that “cloud” is an operating model rather than a location. Technologies originating as cloud-native have a place in on-premises data centres just as much as existing on-premises technologies can have value in the public cloud. Our next Tech Field Day event has a hybrid cloud focus. Our Cloud Field Day event is on October 23 and 24. Here’s a quick overview of what to look forward to.


Event ScheduleWe kick off on Wednesdayat 8:00 AM with Platform9, who specialises in running a cloud-based management service for your private cloud. Platform9 will demonstrate the Enterprise Virtualization Platform, providing the VM, Kubernetes, clustering and networking features you expect including VM protection and migration from your existing infrastructure. At 11:00, we will have Qumulo present cross-cloud storage with capabilities to help alleviate the pain of connecting applications that run on hybrid and multi-cloud environments. After a lunch break, we will return at 2:30 for HYCU to bring us the news on data protection for hybrid-cloud environments. To finish out the day, we will have some Ignite presentations from our delegates, a great way to soak up some of the knowledge that is around the table at every event and get a flavor of what we talk about during the social events that are part of the on-site Tech Field Day experience.

On Thursday, we will be back at 8:00 AM with VMware and the VMware Cloud Foundation, the lead product in the VMware by Broadcom portfolio. If you’ve not been paying attention for the last year, or were lost on a deserted island, then you’ve completely missed the transformation of the VMware software portfolio under Broadcom. The team from Broadcom will be back at Field Day, this time to talk about private cloud. The company is squarely focused on helping customers adopt a private cloud based on VMware Cloud Foundation, or VCF. The Broadcom team has three hours to unpack the new VCF for our viewers, focusing on deployment, operations and consumption of the platform. In the afternoon, the delegates will get time to discuss the significant issues of hybrid and multi-cloud in a delegate roundtable.

Follow Along LiveYou can learn more about the event and our panel of independent technical influencers by visiting the Tech Field Day website and event pages. Each of our delegates has their own blog, podcast, or social media platform where they share their thoughts on enterprise technology from servers to storage to networking and beyond.

Thank you for joining Cloud Field Day live October 23 and 24. You can watch live on the Tech Field Day website, on LinkedIn, or on our sister site Techstrong TV. You can also watch videos from these presentations shortly after the event on YouTube. While you are on YouTube, please subscribe to our channel, and please follow our LinkedIn page for more Field Day content.


Alastair Cooke is a Tech Field Day Event Lead, now part of The Futurum Group. You can connect with Alastair on LinkedIn or on X/Twitter and you can read more of his research notes and insights on The Futurum Group’s website.

Gestalt IT and Tech Field Day are now part of The Futurum Group. Learn more about upcoming events, delegates, event leads, and more on the Tech Field Day website. Read analyst insights and learn more on The Futurum Group’s website.


© Gestalt IT, LLC for Gestalt IT: Refocusing on Hybrid-Cloud at Cloud Field Day 21

View Details

The Internet will tell you that automation is just minutes away from upending work in offices and industries, but if you spend enough time talking to tech executives and stakeholders, you will learn that it is not the silver bullet that execs hoped it would be, at least not at the moment.

Despite inflation and rising labor costs generating significant interest in process automation, and CIOs stretching their budgets to accommodate the costs, automation adoption rate (AAR) is dwindling at enterprises across America.

The reason is one – the trouble of building automation is too much to even consider for some, and others to maintain. A large percentage of automation projects get abandoned or shut down midway owing of the amount of work needed to see the real dividends.

The Barriers to Expanding AutomationAutomation is great for getting small, repeatable jobs done. For example, it is a trusted tool for configuring periodic notifications, enabling email responses or processing employee payroll. Reliance on these systems is steadily growing across workplaces.

But it has been observed that automation initiatives like these are inclined to get stalled very quickly. Research shows that as enterprises graduate to take on more complex works, there are significant tailwinds to deploying the technology.

Complex jobs require clever and custom automation. That kind of automation only gets built once in a while when the need arises.

“It’s like spring cleaning in your house…You’re only motivated to do it once a year,” commented Tom Hollingsworth during the Delegate Roundtable at Networking Field Day Exclusive with Nokia in September that explores the reasons for stagnation of automation projects.

Another major stumbling block keeping enterprises from deploying automation is the network design. The data center fabric is simply not automatable by design.

“There’s a long laundry list of why network automation is not moving along faster than we think,” said Scott Robohn, networking and automation veteran. “We don’t really think about automation from a network design perspective. We don’t build it to be automatable.”

Scott also said that the lack of holistic understanding of how different workflows and processes chain together and how automation tools can affect change in them poses a big barrier to entry.

This is a growing reality in enterprises fueled by skill shortage in emerging technologies. “Most of the companies do not have anyone who knows automation on the staff,” pointed out Rita Younger, industry expert. “A big fear is if they hire someone trained up on automation who can realize the gains, how long it is going take to level up the next person.”

“We’re busy trying to keep the lights on, and keep the data center from going down,” she said.

The Faultline Separating Investments and PayoffsInvestments and returns are often misaligned in automation projects. Teams wind up overspending time and money building technologies without getting adequate value out of it. This difference has been a consistent friction point hindering automation projects in organizations.

“If people view automation primarily as a way to reduce effort and cut costs, they’re going to find that their cost go up in the short term because they have to do all the things they’re currently doing,” agrees VP of data center unit at Nokia, Michael Bushong.

Bushong believes that the true yardstick of measurement of results should instead be time. “When we equate automation to effort, we get one outcome, and when we equate it to time, we get a whole different outcome. People are oriented around effort for the most part, and I think they should be oriented around time.”

Measurable results come from a combination of investment, effort and time. Any new automation project, while likely to float up expenses initially, is bound to hit the TCO targets with sustained effort across time.

Unfortunately, the goals that professionals are left to pursue and realize at the end of these projects are set by C-suite executives steering the ship. Due to the nature of their work, they do not mind themselves with things happening in the lower tiers unless it impacts the earnings and opportunities. As a result, poor communication and fitful implementation are quite common with these projects. And when targets are not met, teams and departments are downsized as a way to recoup the losses.

A Hopeful SignFor automation to be implemented at scale to make a real difference, companies must, first and foremost, build faith in the technology, said the panel. Across the globe, 30% to 50% RPA projects fail every year. This causes a lot of anxiety around relying on automation tools, causing practitioners to discard technologies when they break the first time.

Like great automation can future-proof operations, bad, underdeveloped ones can severely wreck the system and sink investments. The secret to building decent automation is hiring new skills, but also resetting expectations with clear, realistic goals in mind and approaching with an understanding that results will take time.

Bushong predicts that a workforce turnover will be the accelerant that kicks off adoption.

“Over the next 10 years, when network engineers age out and retire, the bumper crop of folks that follow are unlikely to come out of university with networking degrees and four and five letter certifications. If companies require crazy certification and rote memorization of vendor-specific syntax to be effective in an environment, they’re not going to be able to hire. The looming workforce transition will force people to make decisions if only because they have to hire.”

Unable to find new workers to do the job the old way, these companies will turn to automation for certain tasks. Meanwhile, the work to encourage and support talent upskilling must continue.

Parting ThoughtsProgress is incremental. Statistics show that in enterprises, some business units are implementing automation with more success, while others are yet to catch up.

Ron Westfall, research expert and analyst at The Futurum Group, has a positive outlook. “I think progress is being made. We’re getting more data, more evidence for that. For example, through network automation, you can decrease operational overhead by up to 40%. That is an encouraging stat.”

How an enterprise works toward exploiting the promise determines the outcome. “I’m not sure how many companies have deliberate plans, but it could be that the enlightened will have a plan, and for the others, it’ll happen and they may scramble to figure it out, but either way, you’ll see things will start to move. Individuals can decide whether that’s a painful move or a graceful leap,” said Bushong.

Change is afoot, and in organizations, the automation creep is getting real. Whether or not it kills jobs in scores, it will surely enforce real progress.

“We’re at the threshold of having breakthroughs that are going to be ecosystem-wide in terms of automation being implemented in a more widespread basis within data center environments,” Westfall concluded.

Catch the Delegate Roundtable conversation and other interesting presentations on network automation from Networking Field Day Exclusive with Nokia on the Tech Field Day website. Also check out Ron Westfall’s coverage from the event on The Futurum Group’s website.


© Gestalt IT, LLC for Gestalt IT: Automation Is Progressing, but at a Less-than-Breakneck Speed – A Conversation with Nokia

View Details

For millennia, farming has been a skill-dependent occupation. The size of the yield varied with the farmers’ success at predicting weather patterns, predetermining market demands, and efficiency of their agricultural practices. Smart agriculture introduces data-driven farm operations, for the first time unlocking record output without relying on individual skills or physical work.

Red Flags for Smart FarmingRobotic harvesters, remote monitoring apps, AI-enabled quality control, digital soil mapping and drone-based irrigation are some instances of smart farming methods that are being applied on farms around the globe. These processes have greatly optimized agricultural production and unlocked more revenue for farming companies, besides improving sustainability of certain farming practices.

But, operating at the edge, farming companies face some tailwinds adopting these practices and technologies.

“The edge is far away from the enterprise, the data center or the cloud,” noted Ross Hamilton, systems architect at OnLogic. “It is the area beyond what you can say is a reliable network connection.”

But the problem runs beyond not having decent network connectivity, he said. At the farms, open-air conditions produce an inhospitable environment for computer systems to survive. Weather takes a heavy toll making it fiendishly difficult for the frangible hardware of the data centers to perform.

High-tech farming applications require purpose-built hardware that have been hardened through engineering to be less susceptible to extreme weather conditions. These systems must have the physical resilience to live and operate in exposed environments for extended periods of time.

The key to navigating the challenges at the edge, Hamilton said, is to grasp the extensive complex of edge.

“Latency and bandwidth are all considerations we need to think about, but really, it’s about figuring out what those solutions that have the most impact are, and where they need to be. The hardware aspect of it, the latency of the network, that comes into play as a result of that effort,” he stated.

An Edge-Smart Computing Platform for Rugged EnvironmentsOnLogic is an edge computing hardware company that has built an enduring reputation on its portfolio of industrial-grade edge computers. It’s line of edge devices stand out by the quality of their “look and feel” which include a small form factor, a compact design, and extended life. Being highly configurable and easily deployable, the devices serve as entry points to operating in many edge environments, said Hamilton while presenting OnLogic’s family of computer solutions for farming and mining use cases at the Edge Field Day event in September.

“We don’t think of the edge as the endpoint. We think of it as the starting point.”

OnLogic seeks to drive home the point that many miss. The architectural complex of the edge is unlike traditional IT. It is fraught with a myriad of challenges. Wide temperatures, presence of dust and water, and vibrations threaten to damage most computer systems. In the fields, temperature swings between morning and noon hours are most normal. Robotic pickers cause significant vibrations and shocks as they roll through uneven lands blowing off dust and grime in the air.

OnLogic computers provide a breadth of functions and capabilities for edge use cases such as this. Narrating a customer story, Hamilton explained how OnLogic is helping farms leverage the synergy between smart technology and conventional methods.

The OnLogic Karbon 800 Series, under which all its rugged solutions are listed, is designed to operate in dusty settings, and temperature ranging between -40°C to 70°C. The family boasts a fanless design which makes it more reliable with higher mean time between failures (MTBF). Under the hood, the platform leverages Intel’s embedded processors.

“These SKUs are set out there to live so that they can operate at a much greater level of reliability than your otherwise typical desktops,” he said.

Built-in features allow Karbon devices to interface with motor controllers, and process and export sensor data to dashboards or the cloud via cellular connectivity or mobile uplink. Additionally, the computers feature an internal microcontroller (MCU) which works behind features like ignition sensing, DIO and CAN.

“The integrated programmable MCU has the ability to do external power switch connectivity that you can access via the programmable microcontroller.”

The Karbon series also offers support for AI applications and capabilities through GPU expansion optionality. This allows users to add additional computing hardware to the systems when built-in processors fail to handle the workloads.

Check out OnLogic’s presentations from Edge Field Day to learn more about the Karbon Rugged Computer solutions.


© Gestalt IT, LLC for Gestalt IT: OnLogic Powers Smart Agriculture with Its Karbon Series

View Details

Security is more than firewalls and access lists today. It’s about policy and procedure and other technological advances that make it easier for operations teams to keep users safe and secure at all times. How can you learn about all those advancements and understand their impacts?

Security Field Day 12 is here to help! We’ve got a great lineup of presenters from across the security spectrum to help you get the most out of what you’re doing as well as ensuring that you know the right questions to ask when deciding what needs to be done to keep your people safe.


Security Field Day ScheduleWe start the event on Wednesday, October 16 with a special delegate roundtable discussion. This is how we make sure that our audience is on the same page as our delegates when it comes to the discussions going on in the community. Make sure you tune in to hear what they have to say and what kinds of questions I’m going to come up with for them!

Next up is first-time presenter DigiCert. DigiCert VP, Mike Nelson, will present how digital trust has evolved into a strategic imperative, helping organizations enhance security, customer satisfaction, and operational efficiency. Today, enterprises manage an average of 55,000 certificates, which creates huge scale problems. We’re going to learn how they help you manage it all.

Wednesday closes out with our friends at Dell. Dell may not be the first name you think of when you talk about security but they build security into every part of their product lines. They’ll be focusing on how they help reduce attack surface, detect and respond to cyber threats, and how to recover if you do end up getting attacked. In addition, they’ll be discussing how they are helping implement post-quantum encryption.

Thursday starts off with a presentation from first-time presenter SonicWall. In this presentation, they will showcase some of SonicWall’s newest offerings, such as Cloud Secure Edge and Secure SD-WAN, as well as our new unified management console. Given the acquisitions they’ve made over the past couple of years I think it’s going to be awesome to see how it’s all working together as well as how it can simplify operations for the people in the trenches.

We close out on Thursday with a talk from Citrix. The delegates will will learn about the Citrix approach to zero trust application delivery and protection. including a demo that showcases how easy it is for IT Admins can deploy, manage and troubleshoot Citrix Secure Private Access and another about the end user experience and how the different personas in your organization can securely access their applications using desktop virtualization, ZTNA or enterprise browser.

Be A Part of the ActionThe live stream for our event start on Wednesday, October 16. You can watch it on the Tech Field Day website, Techstrong TV, or the Tech Field Day LinkedIn page. You can also follow us on X/Twitter and use the hashtag #XFD12 to add your voice to the conversation. If you can’t catch the live stream on the 24th we will be posting the entire presentation to our Tech Field Day YouTube channel soon after.

We hope to see you online and hear from you!


© Gestalt IT, LLC for Gestalt IT: The Brave New World of Security Field Day 12

View Details

Filmmaking has come a long way since the early days when movies were shot on old-fashioned film cameras, and footages were stored on 35-milimeter tapes. The creative workflows constituted artistic traditions and manual processes.

“It was a photochemical and mechanical process for 100 years,” Jimmy Fusil, media & entertainment technologist at Tsecond, said, recalling the days when crew spent hours on movie sets working on tedious manual processes.

The Crossover to Modern Moviemaking“What’s been incredible in the last 25 years is the explosion and the importance of data in that industry,” Fusil noted.

A grass-roots movement revived the old way of working, introducing a battery of smart technologies and digital workflows that shaped the modern digital moviemaking. In this new chapter, manual workflows are replaced by digital processes, and files, not films, are the digital assets. Data is distributed in more places than one can count, and the volume grows staggeringly with each production as directors and cinematographers adopt new styles of filming.

“Very quickly we went through the digital transition where files represented millions of dollars of investment, and they became the thing that needs to be protected and shuttled from place to place.”

Today moviemaking happens largely outside the walls of the studio, at what is described as the edge.

“Production is the most edge-centric activity that I can think of,” Fusil exclaimed.

The crew sets up gears and equipment for recording at a certain location, with a makeshift server room backstage with a tiny computer setup collecting and storing terabytes of data – picture, sound, ancillary files – every minute.

Post-processing, like color-correcting and color-grading, too has by and large shifted to the edge where terabytes of high-resolution pictures are being processed in non-datacenter conditions.

Data, sometimes, is transmitted to the cloud as an intermediary storage location, but it is worked on in pop-up labs or provisional studios scattered across locations, Fusil told.

“It’s not a glamorous set, or some far-off location. It’s a dark room in the metropolis somewhere. All the machinery to make a film is at somebody’s knees or in the closet. If you’re lucky, it’s in a little data center that has some real cooling.”

“VFX companies have their own data centers where things are very well maintained, but still people work in the self-contained manner, and for reasons of both content security and performance, the data needs to be really close to the people who use it and to the workstations that access it.”

Like all industries, the media sector too has adopted new ways of working after COVID. “Since the pandemic, we’ve seen these workflows to be distributed. Now the data needs to be in multiple places, and it gets heavily replicated. Instead of having one copy or two copies, you now have 16 copies because the data needs to be here and there, in the cloud and at the edge, all at the same time,” he said.

Not only does this digital way of moviemaking require robust data management capabilities to tackle the ever-growing file sizes, but also high-speed storage that can support and enable rapid on-device data processing, while allowing easy and cost-effective transportation of data across various locations.

A Mobile Data Solution for Digital FilmmakingThe Tsecond BRYCK platform is an advanced storage solution that revolutionizes the way data is captured, transported and processed at the edge. With density of up to 1 PB, and performance up to 20GB/s, the BRYCK is a compact, ruggedized solution weighing 14lbs. It is a data solution designed to provide high throughput, in this case letting powerful workstations have super-fast access to the data they need.

Users can directly plug the BRYCK into the server tray.

“Throughput depends on the configuration of the server, and we’re not religious about what type of server it is, but the connectivity between the tray and the server is up to 40 gigabytes a second, and the connectivity out of that server to a workstation is 10 gigabytes a second,” he said at the launch of BRYCK AI at the Edge Field Day event.

Already, hundreds of users have BRYCK devices deployed on the sets where they are picking up volumes of high-resolution data every day. The devices are driven back to the production houses nearby where the data is post-processed for theatrical release.

“A lot of our customers connect the SMB or NFS over RDMA so they can take full advantage of the performance, not across 100 links, but across just 20,10, 5 or 3 links.”

Fusil recalled some customer stories that explained how creatives use BRYCK for use cases in media and entertainment.

In one case study, Fusil told Tsecond helped a company move 130TB of data coast to coast within a day. The entire block of data was copied to a BRYCK device within a few hours, and flown into LA to a studio where it was plugged directly into the workstation and the data was processed immediately.

BRYCK offered more than the required 1.5 GB throughput that the director needed, allowing a quick editing job without having to reconstitute the file system, or move the data to another physical location.

In another case, BRYCK supported 16K 60fps rendering, he told. With BRYCK, the client was able to make copies of 16K videos from a separate storage device at 5GB per second speed via NFS over RDMA, enjoying 9GB seconds of read speed for multiple concurrent streams at the end of the process, he told.

Through the final customer story, Fusil highlighted what makes BRYCK an excellent fit for rugged non-datacenter environments.

Among high-end cameras used in big-budget movies, RED cameras are a well-known brand. RED’s advanced digital cinema cameras are used by film makers the world over for their top-notch image quality. BRYCK has integration with RED Connect which allows it to record and store volumetric, immersive and multi-camera videos.

In this particular case, Fusil told that the film was being shot in the Atacama Desert in Chile. Filming went on 20 hours a day for a month in the extreme heat and dusty conditions.

The BRYCK single-server architecture provided the crew a way to directly store volumetric video footages on the device, sidestepping the pain of swapping out memory cards mid-process, and allowing recording and processing to happen simultaneously. Additionally, copies of the whole 150TB chunk were produced for insurance and security purposes.

Fusil highlighted that the soon to release BRYCK Mini is particularly suited for harsh edge environments like this, because of its compact and highly portable form factor and low power consumption.

At present, Tsecond is working on supporting the set of use cases around multi-camera filming, and on-site processing at the edge. The focus is to let recording happen directly on the BRYCK, and allow the devices be carried to close-by laboratories for fast processing, Fusil told the audience.

Check out Tsecond’s presentations of the BRYCK platform from Edge Field Day to learn about more such interesting use cases and scenarios it serves.


© Gestalt IT, LLC for Gestalt IT: Moviemaking Crosses Major Hurdles with Tsecond’s BRYCK Platform

View Details

One of the common themes that I hear in the data center networking industry is how automation efforts seem to have stalled in many companies. After some easy successes with reducing keystrokes on simple tasks the projects become aimless and eventually just flounder. There are a variety of reasons for this that have been explored but one that I want to focus on is the lack of standardization.

One of my first big IT projects happened when I was an intern at IBM. I had to write a simple script to change an MTU value in Windows 2000. I had to iterate through various interfaces looking for a value and change it. Simple, right? You’d think that but getting things going was a nightmare. One group that I worked with wanted me to learn Perl and use it. Another felt I needed to use IBM’s own ObjectREXX scripting language. My mentor told me I needed something easy to use that was also easy to decipher. I ended up “automating” this task with a series of nested IF statements in a batch file. Ugly and effective.

Fast forward almost 25 years and I find that the same challenges are being fought again and again in the enterprise. What standards should we use? Are we going to create a custom hodgepodge of code that accomplishes the goal while being completely unmaintainable? How can we build automation systems that can only be worked on by one or two people in the organization. If you are a fan of Gene Kim’s Phonenix Project, you can already see the Brent Block happening here. If one person or team is the only one that can decipher the collection of tools and code used to build your automation efforts, what happens when they leave?

Picking A WinnerI can tell you what’s going to happen when they leave. Their replacements are going to give up. They’re going to take one look at the motley code you’ve created and toss it in the bin. They’re going to start over with something they’re more familiar with. Honestly? They’re going to start with Kubernetes.

How do I know that? Because everything is based on Kubernetes today. What was once a small little Google project for container orchestration has become the leader in the field. People don’t even say “containers” any more. They say Kubernetes even when they mean someone else’s platform. It’s the kind of standard that is one of the first things people learn when they get into enterprise IT. If you want to have a future in computing you have to know it.

Why would a networking team want to use it? Honestly it’s because the concept of a dedicated networking team is quickly riding off into the sunset. With the advent of cloud computing forcing those concepts into the private enterprise very few engineers are ignorant to cloud concepts. They know what they can do on AWS or GKE with Kubernetes and they seek out those same capabilities in other systems. They have a standard toolkit they work from and they expect to see it no matter where they are.

Who are these engineers and operations teams? They are the professionals that are going to replace your aging networking teams. If you’re old enough to remember when Ethernet wasn’t the only protocol on the block you’re getting to the point where retirement is an achievable goal. You’ve spent your whole career trying to make stuff work. You didn’t follow the standards because they weren’t standards yet.

As a pathfinder in a jungle, your replacements are constructing roads along the path you created. They will utilize asphalt and concrete instead of a machete and torch. They do not intend to create from scratch; rather, they seek to enhance what already exists. Therefore, when determining how to sustain the automation push within your organization, how should you approach its development? Should you build it from the ground up or establish a platform that aligns with the standards your replacements will comprehend?

Nokia KnowsNokia has built a platform that meets your needs. Nokia Event Driven Automation, or EDA, features Kubernetes principles as the core. Here’s a video from our recent Networking Field Day Exclusive event with them that goes into detail about it:

Wim Henderickx explains it way better than I ever could. Why reinvent the wheel when you don’t have to? Kubernetes gives you all the tools you need to do things right. Complex problems are easy to solve now. For example, what if you deploy a code update that breaks functionality? How can you roll that back efficiently? If you’re automating the change how many systems have been affected. Even in an organization where toolsets are easy to use finding this information isn’t always easy, especially in a crisis. However, with the change tracking built into Nokia EDA, it’s a simple as going to the changelog and rolling back the deployment. Once you’ve confirmed that the changes are rolled back you can even query the network using natural language to ensure that no devices are online that have the suspect code. An easy fix because you based it on principles that your up-and-coming engineers respect and expect.

Bringing It All TogetherIf you’re starting to wonder what life after IT is going to look like you also need to consider what your legacy will be. You’ve blazed a trail through buggy code and created concepts that were just pipe dreams. However, we live in a world where the exploration is done and the maintenance is key. Networks aren’t playgrounds any longer. They are the arteries to ensure your digitally transformed enterprise is solvent. That means whomever is going to step up to take your place needs to have a system they understand to maintain what you’ve built. Nokia EDA gives you one of those platforms. By utilizing Kubernetes as the bedrock for their automation platform they can ensure that your descendants can take what you’ve built and keep it running long after you’ve moved to the beach to enjoy retirement. Before you decide to hang up your CLI window for good, check out Nokia EDA and leave the next generation a legacy to be proud of.

You can watch videos from our Networking Field Day Exclusive Event with Nokia and more on the Tech Field Day website or on YouTube.


© Gestalt IT, LLC for Gestalt IT: Automation Sustainability with Nokia Event-Driven Automation

View Details

Edge is the new cloud, as Jason Grimm, consulting solutions architect at ZEDEDA, will tell you. IoT devices have multiplied exponentially, and by 2025, are set overshoot 75 billion, according to IHS Markit estimates. This is shifting computing back from the cloud to the physical edge of the network where data originates.

Grimm has witnessed the explosion of edge computing use cases across industries in the recent years, which have come to include even the most unlikeliest sectors like manufacturing and maritime.

The demand for near real-time data processing and infinitesimally low latency of these use cases necessitates building cloud-like environments at the edge.

Referring to a customer story, Grimm, at the Edge Field Day event in California last month, highlighted the advantages of edge computing in international maritime shipping, and ZEDEDA’s capabilities to support the use case.

Shipping Goods Around the WorldBig shipping companies carrying out long-distance transportations own and operate large fleets of container vessels that haul thousands of cargos across ports. These vessels spend weeks on end at the sea, which means moving temperature-sensitive, perishable goods to distant places is tricky. Groceries, for example, need to be preserved at optimal operating temperatures and delivered well before they spoil to ensure freshness and quality.

Shipping refrigerated cargoes like groceries across the world often comes at a cost to the vendors, reminded Grimm. Companies like the one he talked about, move fresh and frozen goods worth approximately $21 million. That is no small stake.

Lack of connectivity can pose significant risks to monitoring these containers, he said. Scant onboard staffing makes it even more difficult to maintain the ideal temperature, leading to risks of spoilage and degradation of products.

Onboard connectivity in container vessels typically supports basic radio communication but falls short of enabling reliable on-ship to onshore communication. This leaves vendors struggling to do things like IoT steaming and real-time data analysis directly from the vessels. The physical safety of the devices is another key concern for companies looking to get value out of the data they collect.

To accelerate edge use cases, shipping companies must redesign and modernize their on-ship connectivity infrastructure with 4G and satellite connectivity to ensure consistent IoT streaming throughout the course of the journey.

ZEDEDA’s Edge Cloud for International Shipping CompaniesZEDEDA’s solution to this is based on the principle of extending the cloud operating model to the edge. The cornerstone of that is a private core network powered by ZEDEDA’s flagship EVE-OS running on third-party partner hardware, and SD-WAN implementation.

“Local network is basically for wide networking, and implementing SD-WAN’s ability to go between low earth orbiting and geo satellites.”

ZEDEDA upgraded the local connectivity to 4G ensuring reliable on-ship communication, and via satellite connectivity, sent IoT streams over to the company and ZEDEDA’s own NUCs. This way, sundry management functions like pushing updates, performing troubleshoots and monitoring container health are possible to orchestrate automatically and remotely, without requiring an IT team onboard.

Grimm said that this infrastructure allows companies to “manage all of that in a way that doesn’t require local staff, so that they can get the local insights and push them up to the cloud as well as the rest of the fleet.”

The IoT sensor streams for temperature measurements are read and processed by an app running on ZEDEDA’s hardware. Real-time insights and recommended actions are delivered to the ship crew, who, based on the alerts, can then make fixes where required.

Central to edge is security of connected devices. ZEDEDA protects against physical tampering and unauthorized accesses through built-in features of the platform like measured boot and remote attestation that ensure the safety of the devices while on transit.

“It’s a complete solution to modernize and revolutionize the business and meet all of the standards, while reducing that $21 billion risk of spoilage down to as near zero as we can get,” Grimm said.

Following its success with freight vessels, ZEDEDA is working on foraying into chartered vessels and other shipping companies where it is set to enhance fleet management and edge compute capabilities with a portable tech kit.

For more, be sure to watch ZEDEDA’s presentations from the Edge Field Day event on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: A Cloud at the Edge of the World, with ZEDEDA

View Details

Erwan James is one of the champions of automation in the data center. He has a long association with the technology behind making the data center a better place for operations teams. I talked to him about Nokia Event Driven Automation (EDA), an exciting new platform that will help this process along.

Erwan talked about three big pillars in this interview that are crucial to the vision for Nokia EDA. The first is abstraction. By abstracting the implementation details of a fabric away from the underlying hardware you can focus more on the intent of what you want to accomplish instead of worrying about things like CLI commands or platform capabilities. Nokia EDA understands the components of the system that it operations so all you need to do is declare what you want to happen and the platform will take care of the rest. Today it supports Nokia SR-Linux but soon it will support even more operating systems.

The second pillar is reliablity. Declaring your intent for the network and actually making it happen are two different things. Half-baked automation implementations usually fail when the network crashes because of bad commands or because the system decides to make changes outside of approved windows. Nokia focused on ensuring that EDA was reliable and predictable so that changes and updates were easy to do but also easy to roll back in the event that something is amiss. With the database of modifications that Nokia tracks you can even rollback device software upgrades!

The final pillar is extensiblity. It’s one thing to build a fabric. It’s another to build a good one. Vendors will all tell you that their approach is the best, even if everyone builds them the same way from standards like EVPN and VXLAN. However, the implementation details do matter once you start trying to build systems that interact with each other. Nokia recognized that having a strong opinion about how to build something is an asset, but so too is being able to relax that opinion to make a data center fabric consumable to the masses.

If you want to learn more about the Nokia EDA platform and how Event Driven Automation can help you, please make sure to check out the Networking Field Day Exclusive with Nokia videos available on the Tech Field Day website


© Gestalt IT, LLC for Gestalt IT: Nokia EDA Under the Hood with Erwan James

View Details

I sat down for a great interview with Michael Bushong of Nokia to talk about why automation seems to have stalled out in enterprises. He had some great insights around this topic. He noted that automation has been around in some form or another for almost two decades and it’s something that everyone seems to do but never really commits to.

The assumption is that most people start small by doing something he calls keystroke removal. By automating easy tasks that feel repetitive people have a sense of accomplishment. However, that’s not where the majority of time accumulates inside of an organization. Instead, the handoffs between people and organizations is where the majority of waiting is occurring. When you also factor in how big the efficiency gap is between on-site IT and cloud-based solutions it leads organizations to shelve their attempts.

The advice? Focus on the big workflows and go deeper than simple scripting. Understand those workflows and ensure that you’re solving the right problems instead of the easy ones. Another great suggestion is using Nokia EDA for your rollout. The platform uses common, familiar tools to overcome adoption hurdles while also allowing you to build out your automation projects on your terms with no need to rearchitect the entire enterprise or hire a lot of new staff.

If you want to learn more about what Nokia EDA can help you accomplish, please make sure to check out the Networking Field Day Exclusive with Nokia videos available on the Tech Field Day website


© Gestalt IT, LLC for Gestalt IT: The Promise of Automation with Michael Bushong of Nokia

View Details

AI technologies like robotics, computer vision, 3D printing, and advanced analytics have grown into mainstays in manufacturing plants. These smart technologies are evolving and enhancing assembly lines, supply chains, quality control, procurement and a host of other processes across the factory floor.

Big automakers like Audi, Tesla and BMW have made big commitments to realize this planned digital manufacturing initiative. BMW, using stunningly realistic simulation of entire factories and manufacturing processes, has streamlined and optimized production lines in some of its biggest factories. Audi, on the other hand, is building edge clouds with VMware to optimize processes on the shop floor.

Market intelligence shows that integration of AI technologies in the manufacturing market is growing at 45.6% CAGR, and by 2028, it is projected to reach $20.8 billion.

SetbacksDespite the positive predictions, it’s observed that many manufacturing companies are facing pilot fails in their initiatives to implement and scale Industry 4.0 technologies. According to estimates by the World Economic Forum, over 70% of the companies investing in smart technologies never make it beyond the pilot phase of development.

This is no surprise. There are some clear barriers to harnessing complex technologies like AI, especially for an industry that has chronically stumbled to adopt new technologies.

Making the Edge SmarterVMware by Broadcom is working at the intersection of traditional and new, helping manufacturers embrace smart technologies with what it calls a “software-defined edge”.

Chris Taylor, product marketing manager, and Alan Renouf, technology product manager, explained the concept while presenting at the Edge Field Day event in California. “The software-defined edge is a distributed digital infrastructure for running workloads across dispersed locations, placed close to where endpoints are producing or consuming data.”

To make Industry 4.0 a successful and sustainable movement across manufacturing, enterprises need to transform operations at the edge such that it resembles the rest of IT.

VMware offers a platform solution – the VMware Edge Compute Stack – that is edge-optimized and designed to help manage edge at scale with limited resources.

Designed addressing the radical constraints at the edge such as scale, lack of stable inbound network connections, edge hardware and protocols, and shortage of onsite personnel, the Edge Compute stack aims to provide a resilient and automated cloud-like compute infrastructure at the edge.

“We’re working with new smart manufacturing and Industry 4.0 technologies, and we’re also helping manufacturers virtualize their manufacturing floor with edge computing.”

The goal, VMware says, is to reduce the number of dedicated function devices and enforce a single operating model to manage workloads at factories.

The VMware Edge Compute Stack is based on VMware ESXi which provides it real-time capabilities to keep applications up-to-date automatically.

The Edge Compute Stack adopts a proven management model called pull mode approach. This ensures that connected devices scan for updates and maintain a desired state autonomously.

“It’s like updating your iPhone,” said Taylor. “Your iPhone sees the updates, pulls it down and installs it when you’re sleeping.”

“It’s using a GitOps and desired state methodology which works really well when you have the scale of edge sites.”

The star of the show, VMware Edge Cloud Orchestrator is designed to offer a painless management experience for heterogenous edge applications and infrastructure. Launched last year, the orchestrator makes it simple to deploy disparate edge deployments without IT staff on-site.

Leveraging the pull-based orchestration, it provides zero-touch provisioning ensuring that all security and administrative updates are pulled in timely by the workloads, keeping even the most remote and disconnected sites operational 24/7.

Renouf said, “This is about providing that full stack that everybody needs at the edge. If you have the complete picture of all the data that’s at the edge all the way from the sensors and the applications that are running there and the infrastructure they’re running on, together with the network layer, you can really start to do useful things and optimize for what that edge location does.”

In Aug, VMware released v3.6 of the VMware Edge Compute Stack. The new version comes loaded with additional new features like, a friendly host identifier that allows users to name and identify hosts easily, and the ability to assign static IP addresses to host components instead of setting up DHCP service separately for every site.

To learn more, check out VMware’s presentations from the Edge Field Day event, or head over to VMware’s website for more resources on the Edge Compute Stack.


© Gestalt IT, LLC for Gestalt IT: VMware by Broadcom Builds Software-Defined Edge for Manufacturing Facilities

View Details

The use of artificial intelligence technology is taking hold in the enterprise, and many are discovering the importance of a solid data infrastructure for these new applications. No matter what model or technology is used, or whether it’s part of training or inferencing or RAG, data is the foundation for productive AI applications. That’s why the next Tech Field Day event will focus on AI Data Infrastructure, serving as a companion to our recent AI Field Day event, happening October 2 and 3. Tune in live or watch our recordings. Here’s a quick overview of what to look forward to.

AI Data Infrastructure Field Day is broadcast live on LinkedIn and Techstrong TV starting at 8:00 AM Pacific time Wednesday and Thursday, with more presentations throughout the day. All of our sessions will be recorded and posted to YouTube in case you miss anything!

Kicking things off Wednesday October 2 at 8:00 AM Pacific with MinIO, who are building an enterprise object store for AI data. MinIO will discuss the considerations for large-scale object storage for AI, including connectivity, caching, and observability. Google Cloud presents at 10:30 AM, focusing on storage solutions for different stages of the AI pipeline. We recently heard about Google Cloud storage at our Cloud Field Day event, and this will dive deep into Vertex integration and managed AI services. After lunch we’ll hear from HPE at 1:30 PM. HPE recently announced NVIDIA AI Computing by HPE, a new private AI solution that provides turnkey accelerated computing.

On Thursday we will start with Infinidat at 8:00 AM. They are bringing advanced cybersecurity and AI features to their leading enterprise storage platform. At 10:30 AM we welcome enterprise SSD leader Solidigm back to Tech Field Day. Their presentation focuses on the way SSDs can bring TCO and performance benefits to AI workloads. We’ll wrap up AI Data Infrastructure Field Day at 2:00 PM with Pure Storage. Their consolidated scale-out storage platform known as FlashBlade is seeing rapid adoption with AI workloads.

You can also catch the AI Data Infrastructure Field Day delegates on our Tech Field Day podcast, including two special episodes recorded next week. Check out our appearances on Techstrong Gang and the Gestalt IT Rundown, too. And tune in for behind-the-scenes shorts, Tech Talks, and extras recorded in Silicon Valley!

All of our sessions are broadcast live on LinkedIn at the Tech Field Day page and recorded and shared on YouTube. You can also catch the sessions on Techstrong TV, with our coverage continuing on Techstrong AI. We welcome participation on X/Twitter, LinkedIn, and Mastodon using hashtag AIDIFD1.

You can learn more about the event and our panel of independent technical influencers by The Tech Field Day website. Each of our delegates has their own blog, podcast, or social media platform where they share their thoughts on enterprise technology from servers to storage to networking and beyond. We’re proud to have Camberley Bates and Steven Dickens from The Futurum Group joining us on the delegate panel, and we look forward to their analysis and reactions.

Thank you for joining AI Data Infrastructure Field Day live October 2 and 3. While you are on YouTube, please subscribe to our channel, and please follow our LinkedIn page for more Field Day content.


© Gestalt IT, LLC for Gestalt IT: Exploring the Importance of Solid Data Infrastructure at AI Data Infrastructure Field Day 1

View Details

The landscape of the data center is being transformed. Applications like AI are forcing design and operations teams to understand the new usage patterns for users. Shrinking budgets mean management has to do more with less. How can companies get ready for complex new ideas while also keeping their existing data center infrastructure running in prime condition?

Enter Nokia. A stalwart in the enterprise IT space, Nokia has been a fixture in a number of advanced IT disciplines for decades. However, Nokia may not be the first name that comes to mind when you think about enterprise IT networking. They produce a lot of great solutions and are highly regarded by a number of practitioners. Once you get a look at their solutions you will be pleasantly surprised with their capabilities.

Networking Field Day Exclusive with NokiaThat’s where Tech Field Day comes in. We’re excited to be partnering with Nokia to bring you Networking Field Day Exclusive with Nokia. This is a one-day special event happening on September 24 will look at the solutions that Nokia is bringing to the table to help shape the future of data center networking. Nokia’s solutions are built to help operations teams keep up with technical advances as well as making the network easier to configure and consume.

One of the key places that Nokia will be focusing on during this event is automation. Thanks to platforms like SR-Linux they already have a great baseline for making the network behave like the cloud. Our Field Day delegates will also get a look at the newest innovations in the Nokia lineup as well as getting hands-on time to see how it all works.

Our Field Day delegates will make sure to ask all the right questions to help the community understand where these solutions make sense and why it matters to modern organizations. We’ll make sure to ask the questions that are important to the audience and discuss the drivers in the industry that keep networking moving toward a better future.

Join Us LiveWe will be streaming live on our website on Tuesday, September 24th. You can follow along on on the Tech Field Day website, TechStrong TV, and our Tech Field Day LinkedIn page. Make sure you tune in and be ready with questions. We’ll be using the hashtag #NFDxNokia on social media so you can ask away and our delegates will relay the questions into the room. If you can’t catch the live stream on the 24th we will be posting the entire presentation to our Tech Field Day YouTube channel soon after.

We hope to see you on September 24th with Nokia!


© Gestalt IT, LLC for Gestalt IT: Rethinking the Data Center with Nokia

View Details

Most of IT by now is familiar with DevOps as the movement that steered organizations away from yesterday’s defunct methods of software development towards smarter more efficient ways of building applications. 5 out of 10 organizations practice DevOps, and out of those, a majority says that DevOps practices have helped them improve team performance and collaboration, finds a survey of 500 DevOps practitioners by Atlassian.

Although originated in IT, DevOps appears everywhere in diverse forms, and its principles are applied in all places of business.

DevOps speaker, Chrystina Nguyen observed, “DevOps is everywhere.”

“It is a culture, a group of people working together to produce a product and having that seamless teamwork culture conversation,” she said while giving an Ignite Talk at the AppDev Field Day event in May.

Drawing on a 2019 talk of her’s, Nguyen’s speech provides a refreshing view of the universality of DevOps principles and practices, and its application within the restaurant industry.

The DevOps Cycle Is at the Core of Iterative Improvement in Restaurant BusinessThe DevOps lifecycle is often represented through a diagram called the DevOps loop. The DevOps loop is an infinity loop that represents the continuous nature of the methodology.

It visualizes various phases of the DevOps lifecycle – plan, code, test, release, deploy, operate and monitor. The phases sequentially flow from one to the next leading back to the start again, forming a closed loop.

The loop aims to show that every phase in the development lifecycle builds on the previous one and a change in one reflects a change in the other.

As feedback from a last cycle comes through, this loop allows them to be absorbed in the new cycle for enhancement of the following phases.

The constant optimization helps ensure that there are fewer bugs and errors, and the products are optimized for a rich user experience.

The loop of continual improvement is the secret sauce of restaurant operations. For decades, restauranters have intuitively practiced the feedback loop to enhance and personalize customer experience.

When a diner sends back a dish, the chefs and cooks back of the house instantly replace it with something better curated to the customers’ palate, while taking notes for future deliveries.

Nguyen who transitioned from a long career in the restaurant industry to public speaking owns a firm called Ghost Management LLC that provides event marketing for small businesses. In her business, she leans on DevOps principles as a way to regularly check-in with clients and connect their preferences and suggestions with business goals.

“Communication is key,” she said. “Just like it is in your relationships and friendships and in events like this, having a space where people can communicate is important.”

Nguyen borrowed from her experiences and takeaways from her restaurant days to support her statement. She pointed to four elements as the building blocks of the DevOps culture – communication, shared accountability, results and a recognition that all units are different.

“There’s a lot of teams involved when it comes to restaurants, and between them, they have a shared accountability that if something goes down, everybody goes down. It’s not just a siloed effect,” she said.

Achieving Operational Efficiencies with through Transparent CommunicationThe staff at the back of the house and front of the house are joined by this continuous system that allows customer inputs to be shared in a series of ongoing and structured conversations.

Nyugen says that even a casual exchange in the hallway about a client’s remark or a concern they raised regarding the service can go a long a way in making small improvements happen over time. Every rating or comment yields precious bytes of information that if utilized can help make the process more rigorous.

The DevOps loop kickstarts with such inputs. “The DevOps processes is so agile that they can get a new plate, a new product, or a new line of code, right back out to you so that it can help you get out of a downtime or whatever it may be, in mostly minutes,” she said.

This underlines the importance and effectivity of sharing and communication in business. If clients do not shy away from sharing difficult feedback, and if that message is responsibly carried back to the managers and developers, it can unlock improvements in product quality, employee productivity and ultimately customer satisfaction.

However, one must respect the fine line between being candid and being picky, says Nyugen.

If done properly, the DevOps loop can allow developers to deliver products aligned with the business needs and customer expectations as opposed to deploying them blindly without an afterthought. And in restaurants, it can help the staff better connect with the diners and build a stronger engagement.

Adopting the agile methodology which involves distributing work among various groups of people further reinforces the DevOps culture.

“Small batch size is king,” says Nyugen. “You’re not cooking huge batches of soups and freezing them. Instead, you have small batches that is a quicker process and easier to fix versus taking down a whole dish and recreating it from scratch.”

“You already have some of the items prepped and ready. It’s about putting them together quick enough so that the dish reaches the customer, and they’re not left waiting while the rest of the tables eat.”

This division of labor promotes agility leading to significantly shorter release cycles. “Speed and quality come into play when all the teams are working cohesively much like a very well-thought-out DevOps team.”

Wrapping Up

No strategy can fully eliminate the occasional slipups that’re inevitable with humans being part of the loop. Preventing those isolated bad experiences from becoming a standard is where the true power of DevOps lies. A forceful collaborative effort wins out against all odds.

“There’s a lot that can happen in any environment and you can’t predict everything but if you have good processes and good team communication, it really helps the DevOps process.”

To know more, check out Chrystina’s Ignite Talk – DevOps on the Menu – from the AppDev Field Day event at Gestaltit.com.


© Gestalt IT, LLC for Gestalt IT: DevOps, the Secret Sauce of All Business, a Talk with Chrystina Nguyen

View Details

No matter what area of technology you’re interested in, it’s moving to the edge. We’re seeing a proliferation of applications for advanced networking, AI, compute, and storage solutions across industries like retail, industrial, military, media, and more. Over the past few years, Edge Field Day has highlighted key products and technologies for edge environments, and the next Tech Field Day event is coming soon. Our next Edge Field Day event is on September 18th and 19th, and I hope you can tune in live or watch the recordings. Here’s a quick overview of what to look forward to.

Things kick off on Wednesday, September 18th at 8:00 AM Pacific with VMware by Broadcom, which is bringing advanced application and networking services to edge environments. We recently got a glimpse of software-defined edge at VMware Explore, and this discussion continues at Edge Field Day. Avassa takes the stage at 10:30 AM to demonstrate how easy it is to migrate legacy VMs and containers to the edge. The Avassa platform simplifies edge deployments by packaging VMs as containers during migration. At 1:30 PM, we welcome TSecond, a company specializing in large data capture, data transport, and AI in unforgiving environments. The TSecond BRYCK is a high-performance, petabyte-scale mobile data solution that now enables AI right at the edge.

Thursday begins with Ignite presentations by the Edge Field Day delegates, which is always a highlight of our events. We welcome ZEDEDA back to Edge Field Day at 10:30 AM Pacific for a session focused on edge orchestration and management. They’ll dive into Kubernetes, edge AI, and more. At 1:30 PM, we’ll learn about OnLogic, the leading manufacturer of industrial small-form-factor computers for edge environments. Their presentation will take us through various environments that require unique compute solutions.

You can also catch the Edge Field Day delegates on our Tech Field Day podcast, including two special episodes recorded next week. Check out our appearances on Techstrong Gang and the Gestalt IT Rundown, and tune in for behind-the-scenes shorts, tech talks, and extras recorded in Silicon Valley.

Tune in to Edge Field Day LiveAll of our sessions are broadcast live on the Tech Field Day LinkedIn page and are recorded and shared on the Tech Field Day YouTube channel. You can also catch the sessions live on Techstrong.TV, with coverage continuing on our website and our sister sites across Techstrong. We welcome participation on X (formerly Twitter), LinkedIn, and Mastodon using #EFD3. You can learn more about the event and our panel of independent technical influencers by visiting the Edge Field Day event page. Each of our delegates has their own blog, podcast, or social media platform where they share their thoughts on enterprise technology, from servers and storage to cloud and edge. We’re proud to have Alastair Cooke and Guy Currier from The Futurum Group joining the delegate panel, and we look forward to their analysis and reactions.

Thank you for joining Edge Field Day live on September 18th and 19th! While you’re on YouTube, please subscribe to our channel and follow our LinkedIn page for more great Field Day content.


© Gestalt IT, LLC for Gestalt IT: Taking Technology to the Edge at Edge Field Day 3

View Details

Enterprise AI is rapidly advancing, with real-world applications emerging daily. As we move beyond the initial hype surrounding large language models and massive training clusters, the focus shifts toward vector databases, agentic AI, and integrations that support a wide range of solutions. This is the central theme of AI Field Day, a three-day event dedicated to exploring modern artificial intelligence applications.

Event ScheduleAI Field Day will be broadcast live on LinkedIn and Techstrong.TV, starting at 8:00 AM Pacific time, running from Wednesday through Friday with presentations throughout each day. All sessions will be recorded and posted on YouTube for those unable to attend live. Our next AI Field Day event will be held from September 11 to 13, and we invite you to join us live or watch the recordings. Here’s an overview of what to look forward to.

On Wednesday, the event kicks off at 8:00 AM Pacific with Keysight, a leader in design emulation and testing. Their network testing products help customers ensure that AI solutions perform well in real-world environments. At 10:30 AM, Integrail will demonstrate how they are bringing agentic AI to production with their enterprise AI platform, enabling customers to easily build and deploy custom AI applications and automate business workflows. Later in the day, Cisco will present at 2:00 PM, discussing how they are developing AI-ready infrastructure and empowering network operations and security in the AI era.

On Thursday, VMware by Broadcom will present at 10:30 AM, continuing their discussion on private AI, a topic highlighted at the previous AI Field Day event. VMware’s private AI solutions provide customers with the tools to build best-in-class applications within an open and flexible ecosystem. Elastic, a leader in database technology, will take the stage at 2:00 PM. to discuss their scalable Elastic search platform, which supports advanced vector databases for modern AI applications.

On Friday, networking giant Arista will showcase their latest products and AI features. Their presentation will include deep dives into network design for AI applications and insights into their AI agent technology.

In addition to the live presentations, you can listen to the AI Field Day delegates on the Tech Field Day Podcast, which aired two episodes in August to dispel AI myths. We will also be recording two special episodes during the event. Be sure to check out our appearances on Techstrong Gang, the Gestalt IT Rundown, and the Utilizing Tech series, which explored AI data infrastructure. You can also look forward to behind-the-scenes content, tech talks, and additional segments recorded live from Silicon Valley.

Watch AI Field Day LiveJoin the conversation on social media using #AIFD5 and visit the Tech Field Day website to learn more. Our panel of independent technical influencers will be sharing their thoughts through blogs, podcasts, and social media channels. Notable delegates include Alistair Cooke from the Futurum Group and Mitch Ashley from Techstrong.

We hope you’ll join us for AI Field Day, September 11-13. While you’re on YouTube, don’t forget to subscribe to our channel and follow our LinkedIn page for more exciting Field Day content.


© Gestalt IT, LLC for Gestalt IT: The Shifting Focus of AI at AI Field Day 5

View Details

CEOs are frowning faces and wringing their hands about a growing skill vacuum that is silently spreading across IT. The void threatens to sink many successful businesses and small shops using mainframe.

A Crisis Is BrewingScores of mainframe jobs land on job portals every month. The market for talent is hot, but tech graduates are missing out the opportunity of having a well-paid career because of lack of skill.

So how are these jobs passing talents by? And is it safe to gather that the skill gap is accumulating particularly around mainframe? At Tech Field Day Experience at SHARE Kansas City 2024, we asked the delegates about this.

“It’s a lot more nuanced than that,” says Derek Britton, technology marketing specialist. “If you look at it from an organization-by-organization perspective, you’ll get a completely different answer from one organization as you will from another.”

There are many government departments where skill gap is growing steadily worse, says Cameron Seay, technology evangelist. “Ask the IRS or Social Security or the state of North Carolina. They can’t find anybody, and they need people. People are retiring every single day.”

With IT companies however, the responses are strictly based on their level of strategic enlightenment, says Britton. In other words, how well the company’s resources and requirements are aligned.

For example, some organizations that are good at it say they are very happy with their apprenticeship and training programs. Others say that the struggle to find mainframe skills is very real.

It’s partly on enterprises to up the ante in the skill search, Britton says. “Certain organizations that have not established that level of investment, rigor or management oversight have fallen behind on skills.”

The distress is growing among some small offices where mainframe talent is getting scarcer than it was a few years ago.

The Hidden Causes of Skill GapThe reason is rooted in mainframe’s receding glory. Once a hot technology, these monolithic computers are outshone by cloud and distributed computing. Since the past decade, mainframe has only existed in the shadows quietly powering backend business processes.

“Skill gap challenges will exist, and they will come to pass at some point in many organizations.”But make no mistake. Mainframe is not going anywhere. “The mainframe environment and applications have outlasted anyone’s reasonable prediction of their tenure,” Britton notes. “Those challenges will exist, and they will come to pass at some point in many organizations because the systems are just more successful than anyone ever thought. They would be the microcosm of the skills discussion.”

Studies have linked low mainframe skills to shortage of successful training programs in enterprises. Many IT companies offer resources free training courses on mainframe to upskill them for mainframe operations, but the courses run only a few weeks, and do not nearly cover enough things.

Geoffrey Decker who has been a mainframe software developer for over a decade and now teaches mainframe courses to new graduates says that lack of premeditated learning outcomes is a huge obstacle for trainers.

“What I find hardest to get a basis of is what companies really need out of the education that I provide only in two semesters,” Decker says. “What I’d really like is some type of a survey to say this is what we need as companies.”

One big challenge is that everything that needs to be taught about mainframe to prepare workers for a career in mainframe is impossible to fit in a two-term curriculum. Companies need to identify that limitation and reform their training programs to correct this.

There is a lot to be familiar with – the programming languages, operating systems, virtualization, the lingos, which maybe a lot to absorb on the fly for a newcomer who has had little or no initiation on the subject.

But there is merit in skilling professionals with mainframe expertise. “Back in the UK, we have a need to grow what we call “pointy-headed techies” – real bits and bytes people because our customers come to us when things break,” says Mark Wilson, IT veteran.

An overwhelming amount of interest in modern and contemporary technologies is serving as an added distraction for professionals, deflecting them to other areas.

“The general world has moved on to the new and the cool,” says Jeremy Meiss, app developer and business analyst. “The general user moved past the command line.”

Addressing the Gap with Small StepsUpskilling is a big part of remaining successful in IT, and workers naturally gravitate towards the latest technologies to boost their resume. But it’s worth remembering that having basic mainframe skills can be helpful for thriving even in those areas. After all, interaction with mainframe on the job, on any job, is unavoidable.

Of course there are workarounds like everything else in IT. PopUp Mainframe is a good example of that. PopUp Mainframe provides on-demand pop-up mainframe environments for testing and development – no skills required.

“But to my folks I say, learn the command line stuff first,” says Wilson. “Then to make your life easier, use all the UI stuff and get that done.”

Marian Newsome speaking at the Tech Field Day Delegate Roundtable at Kansas CityMarian Newsome, cybersecurity specialist, proposes that changing the messaging around mainframe can help reduce the gap. “There are skill gaps even in the new and emerging tech. I think there is an image problem. Marketing saying mainframe is the backbone of what business runs off of, needs to happen.”

Skill accumulation has been slow in mainframe for another reason. “We create so much of a barrier to entry when we assume that everybody knows the lingo,” says Meiss.

IT is a highly niche field of work where there are more specialists than generalists. It’s fair to not assume that everybody knows everything.

The solution is clear. “We have to recklessly remove any barrier that helps to get someone to be successful,” says Meiss. “Part of that is to start reframing the conversation around why mainframe skills matter in the cloud era. We can then try and bridge this gap and explain how the newer DevOps cool things that we talk about and have been for the last 15 years, all relate to it.”

Preparing new talents for mainframe jobs would require offering them a safe space to learn first and foremost. An inclusive approach that cultivates IT skills holistically instead of isolating a relatively small field as an island of its own and denying its existence, is another way to help reshape the situation.

Britton believes that HR has a bigger role to play than most understand. At the people’s level, Human Resource can help foster a positive learning culture through certain policies and programs. Companies also need to be keen to invest in people, and look at reforming training programs when required. Doing these can help an entire generation of young professionals learn mainframe from ground up and seize job opportunities, thereby ending the problem of skill shortage.

Check out the full Tech Field Day Delegate Roundtable – Addressing the Mainframe Skills Gap – from Tech Field Day Extra at SHARE Kansas City 2024 to learn more.


© Gestalt IT, LLC for Gestalt IT: What’s Causing a Skills Shortage in Mainframe?

View Details

Whenever there is a conversation about AI chatbots, there is a chorus of praise about how impressive the technology is, or the incredible things it can do.

People from all walks of life are noodling with chatbots to better their work and personal lives.

“Generative AI and chat technology is fantastic, but it’s only fantastic when you interact with it,” says Anthony DiStauro, solutions architect of the AMI Platform at BMC. “Otherwise, the technology sits there cold and idle until you go and work with it.”

It is becoming plain that the only way to get them working to their fullest potential is through prompts.

The AI Era in Mainframe has BegunMost co-pilots packaged with IT tools do a passable job of answering questions and finding information when asked, but they fare somewhat underwhelmingly when it comes to acting on scheduled commands, or making smart decisions about how much to share with a particular user.

BMC is doing the work of infusing sixth sense into its co-pilot taking AI awareness to the next level. At the Tech Field Day Extra at SHARE Kansas City 2024, BMC introduced AMI Assistant, a conversational interface that is always aware of who’s at the other end.

AMI stands for Automated Mainframe Intelligence, an initiative aimed at making mainframe self-managing using AI, ML and predictive analytics.

A difficulty that all companies experience with mainframe is the prevalence of old practices and workflows, and a mixed demographic of workers.

“We have our 30+ year professionals. Bright and true, but they are on their way out as we segue to a new generation of mainframers,” says DiStauro.

Only companies that can synergize modern technologies like AI and cloud-native with mainframe stand the chance to stay competitive when the next wave of digital transformation hits.

But BMC disagrees that the relation between GenAI and tech is one of hammer and nail that it is often made out to be. Over-reliance on GenAI tools can in many cases be opposite of helpful.

At BMC, the thinking goes like this – GenAI is a value addition to IT products. If done right, it can significantly elevate the value of a product. But by no means is it the hammer to all IT’s problems.

The AMI Platform Bolsters Mainframe ProcessesThe AMI Platform provides services and capabilities that help a new generation of mainframers reach their potential without the care and feeding of the previous generation. Out of the box, it provides a single point of entry through the AMI console, APIs, CLI and SDK that new mainframe engineers are in the habit of using, useful data services, and a GenAI experience delivered through GPT services, tooling and the AMI Assistant.

Mainframe GenAI for BMC boils down to four key objectives – an in-product GenAI experience that eliminates the need for context-switching, flexibility of deployment that makes the product adaptive to any environment, ability to bring customers’ own data and LLMs, and the option to augment the platform using “tribal knowledge” assets.

“We’re using open source LLMs where we need,” informs DiStauro, “but we have a retrieval augmented generation pipeline that is where we go for external knowledge that is specific to your domain that the LLM wasn’t trained on.”

“We have a vector database infused with a bunch of BMC knowledge that is used alongside the LLM,” he continues. “But then we also allow you to bring in your own tribal knowledge.”

This could be rules, business logic, best practices, existing code, and so on. The platform processes and integrates this information into the built-in database. The in-house tooling used by the team at BMC will be available to the customers for building this database.

A Smart Assistant for New MainframersDiStauro describes the AMI Assistant as “an expert in a box that professionals can lean on”.

The AMI Assistant is an embedded interface inside the AMI Platform Management Console. Users can log into the platform using single sign-on (SSO). All products and services that are available to consume are displayed on the landing page. These services can be accessed directly without separately logging into each one of them as the SSO works across all services.

The AMI Assistant appears on the right-hand side of the screen. The chatbot responds to prompts on the fly, answering questions, providing explanations and summaries, and even taking actions on behalf of the users.

For example, if you ask AMI Assistant about the deployment frequency of a certain component, it will come back with the numbers. If you ask it to explain what the numbers mean, it will describe them for you.

But what makes it truly impressive is that it is an “active GPT”, meaning it can execute commands set-and-forget style. To help understand, imagine that you need to aggregate certain metrics over a time horizon and build a report around it. You need to email this report to a group of people in the company periodically. At a scheduled time every week or month, AMI Assistant can do this work for you without requiring repeated commands.

It can take this action based on calendar events, and additionally control all the data moving in and out of it using AMI Data Services. With a built-in security layer that polices all activities, it can control sharing of information based on role and role accesses.

DiStauro highlights that the AI engines working at the backend can also tweak the responses to match the skill level of the user.

“We give you the knobs and switches to rate our responses to keep fine-tuning the AI engine so that they get smarter as we go.”

DiStauro shared a few forward-looking things during the presentation that will be the part of the solution in the near future. Among them is a prompt builder. This application will help users fashion and manage prompts in a point and click fashion.

Additionally, a layer of explainability will be added for mainframe professionals new in the job to gain clarity and transparency on complex datasets.

Be sure to watch BMC’s presentations from the Tech Field Day Extra at SHARE Kansas City 2024 for a deep dive into the AMI platform. Also check out this Gestalt IT Rundown episode where Stephen Foskett and Tom Hollingsworth discuss the criticality of BMC’s AMI initiative to the revival of mainframe.


© Gestalt IT, LLC for Gestalt IT: An AI-Infused Experience for New Mainframe Talents, with BMC AMI

View Details

In an era of rapid digital renovation, the mainframe tells a story of technological endurance and longevity.

A Tale of Continued AdaptationThese granddaddies of modern computer – or “big iron” as they’re called because of their room-sized frame and 5-ton weight – instantly became the hottest thing in town. They could perform bulk data processing like nobody’s business.

Mainframes faced an existential threat as client-server architectures and distributed computing came along. Physically daintier systems designed to perform specific tasks promised better support for business functions like database management and web hosting.

As competition heated up, many industry pundits prophesied a grim future for mainframes. Word on the street was that mainframe computers were going to be buried under the flurry of brisk, zippy computer systems that would sweep these mammoths into extinction.

But new lines of mainframe computers continued to add new chapters to the story. Modern mainframe computers are quite the workhorse for running heavy workloads and mission-critical applications. Worldwide, thousands of corporations rely on them for processes like customer billing, employee payroll processing and inventory management. It is estimated that a whopping 30 billion transactions are processed daily on mainframes.

Mainframe computers also serve as the backbone of IT in sectors like banking and telecommunication predominantly.

Today, 90% of the mainframe market is captured by IBM zSystems. These computers look nothing like their ancestral monoliths. Approximately the size of a big refrigerator – but look like they could be from another planet – these pack a lot of capabilities for handling heavy data analytics workloads.

On-Demand PopUp MainframePopUp Mainframe, a company based in London, is working to modernize mainframe and rehome it alongside modern technologies in the cloud era. PopUp Mainframe’s vision is to give the technology a jolt of refresh without escalating costs or adding technical chores.

At Tech Field Day Extra at SHARE Kansas City 2024, CEO and founder, Gary Thornhill noted, “There’re a few cases of real ROI coming off the mainframe in this world of big data, security threat and climate change. Mainframe is by far the most sustainable platform in the world.”

But cloud-level resiliency is not one of its strengths. Creating a dev test environment on mainframe is a still painfully slow, and a high-tech routine that takes several weeks to months.

“Mainframe tends to exist in silos with old ways of working using waterfall, static environments that are interwoven, and buggy. There’s often quite a lot of delays in being able to actually set up your environment to start your project,” he pointed out.

The cost of maintenance and updates on mainframe add to the total cost of ownership.

PopUp Mainframe’s flagship product, PopUp Mainframe, provides a neat workaround. PouUp offers instantaneous dev test environments for mainframe systems. Like pop-up stores, these require far less commitment and cost.

“We can pop up a full mainframe platform in roughly 10 mins in the cloud or on-prem,” Thornhill stated.

The goal, he said, is to “revolutionize the developer experience by allowing the developer to test against a production-like environment even at the very earliest stage of testing.”

The instant rollout of a mainframe can hugely facilitate testing, development, R&D, software evaluation and employee education in enterprises.

“If you can do these with quality and meet the demands of the business with far less people, your business is going to win through and naturally beat its competitors.”

Inside PopUp MainframeIBM’s proprietary OS for zSystems mainframes, z/OS form the bedrock for this solution.

PopUp Mainframe combines Red Hat Enterprise Linux distribution with IBM ZD&T (Z Development and Test Environment) mainframe emulator which comes preinstalled, preconfigured and ready to run on any x86-compatible systems.

There is a bit to unpack here. As noted, under the covers of PopUp is ZD&T, a fact the company does not try to mask with marketing polish.

“This technology has been around pretty much 20 years in various guises,” Thornhill said.

One of the standing challenges for enterprises is setting up ZD&T. The technical chores of it require a full project team to assemble, deploy and optimize the environments.

PopUp Mainframe gets enterprises straight to value. With a fully optimized and provisioned z/OS virtual instance that is identical to a physical mainframe, developers have a ready environment to work with that run anywhere they like.

PopUp comes fully loaded – VM image, additional tools and helper utilities. System utilities include automated archiving, resource monitoring, and so on.

The PopUp blends smoothly with the rest of the IT estate, and lets developers run z/OS software and code directly on it.

The ephemeral environments are self-service, and come in different flavors catering to specific sets of business needs. Currently, their portfolio includes Vanilla PopUps, PopUp & Delphix, PopUp on Azure, and PopUp & BMC.

PopUp integrates with Delphix, a tool used to mask sensitive data values in non-production environments.

“The way Delphix works is that it uses the same algorithms to mask multiple data sources altogether into one dataset. But this can’t work on the mainframe without a PopUp Mainframe.”

PopUp Mainframe provides z/OS Masking Plugin for Delphix. This allows full data masking across all z/OS data sources. These also include fixed-length mainframe files, as well as variable-length ones like VSAM and IMS database.

Developers can migrate production data and config to the PopUp environment and that’ll be the gold copy.

“It’s important to note that we can mask directly on the gold copy or mask data at source and then move it. There’re different use cases depending on the risk-adversity of the client,” he mentioned.

Ingested into Delphix, independent copies of the gold copy can be provisioned out via self-service.

“These all run in different virtual machines, and they can be at different stages of code. All of these can be managed by the management console, and controlled and they can be forwarded and rewound.”

Mass data refreshes can be done by refreshing the first gold copy environment.

You can optimize by creating slim “slices” that have, by default, a low energy and resource footprint, or by simply turning off the environments when not in use.

To get a complete guide on the delivery mechanism of PopUp Mainframe, check out PopUp Mainframe’s PopUp Delivery manual, a document that discusses the steps of reproducing physical mainframes in a repeatable manner with PopUp.

Be sure to check out PopUp Mainframe’s presentation from the Tech Field Day Extra at SHARE Kansas City 2024 for more on this.


© Gestalt IT, LLC for Gestalt IT: Mainframe Modernization with PopUp Mainframe

View Details

Broadcom is working on making it easier for IT observability players to analyze data faster and get to the root cause of issues in mainframe without distraction. Its latest release, the WatchTower Platform, leverages embedded ML algorithms to provide granular visibility for domain experts.

“This solution is about bringing data in the context in the right moment to the person who needs to see it so that they don’t have to go hunting all over the place,” says Nicole Fagen, director of R&D for AIOps and automation at Broadcom.

Broadcom’s Foray into the Mainframe MarketBroadcom released WatchTower at a previous SHARE summit in March this year. The company’s mainframe initiative is fueled by CEO, Hock E. Tan’s deep fondness for the technology.

“So many large enterprises around the world continue to bet their business on the capabilities that are running on the mainframe,” Fagen says during her presentation at the Tech Field Day Extra at SHARE Kansas City 2024.

There a strong and stable market opportunity, and Tan is eager to tap into it. “The depth in his understanding of how the business runs, the importance of mainframe, and which customers are running what, is astronomical. This is a space he is going to double down on.”

But how did Broadcom, a semiconductor supplier, end up in the software business?Broadcom’s legacy in the semiconductor space is not unknown to many. “Any phone has an average of five of our semiconductors in it.”

After the Qualcomm acquisition fell through in 2018 due to a government veto, it was time for Broadcom to look at new horizons. After noodling with a list of potential acquisition opportunities, the acquisition of CA Technologies happened the same year.

CA offered a firm foundation of enterprise relations with mainframe users that is built over decades opening opportunities for Broadcom to break into the market where mainframe remains the backbone of IT.

Decluttering and Denoising Observability DataBroadcom’s mainframe software products are organized around five key solution areas – data management, DevOps, cyber security, open-source, and AIOps.

Falling in the last category, WatchTower is an observability platform that aims to reduce the data mess and provide a clean picture of the mainframe health.

While most enterprise observability solutions seek to democratize data for all, WatchTower adopts a slightly different approach. It serves data differently to people of different skill levels.

“It’s customized to the roles,” says Fagen. For example, the datasets an operator would see would be streamlined to their role and responsibilities, and would, therefore, be different from what a business line manager would see.

An operator goes through “an average of eight different systems for every single alert that they are trying to resolve,” she notes.

The moment a problem erupts, the hunt for the proverbial “needles in the haystack” begins. Operators move from one interface to the next, collecting data relevant to the problem. They huddle to analyze this data and make correlations. The findings may take a few hours to several weeks to surface depending on the complexity of the problem.

Two casts of professionals are responsible for this hunting and pecking. Operators, subject matter experts and optimization experts on the mainframe side, and business line managers and site reliability engineers over on the enterprise side.

Many of these professionals spend time on diverse tools and technologies that are isolated from each other, and often detached from mainframe. For people on the enterprise side that have no visibility into mainframe, “transitioning their work to mainframe solutions is too big of a leap,” Fagen says.

WatchTower’s special power is to bring augmented intelligence to the fingertips of these IT personas.

“We’re going to enable them by bringing them the mainframe data in a context they already understand, in a workflow that they’re already leveraging.”

WatchTower performs alert clustering to declutter notifications. Metrics are correlated in context and alerts are consolidated before surfacing. For each alert, WatchTower provides exhaustive insights that make drilling down to the root cause surprisingly easy. If there is a shortage of storage space, it will show where the capacity is running low, the sub-pools and their capacities, and any related alerts that can add to that information.

“If you’ve had an alert that’s similar to this in the past, we’ll tell you what that related alert was. You can look at it to see how it was resolved and that makes it a whole lot more effective to resolve this one,” Fagen says.

ML-driven insights offer a chance to compare baselines, reduce triage times, and anticipate issues well in advance.

Another key capability is infrastructure topology mapping. WatchTower overlays topology maps with alerts about problem applications showing navigation paths for particular issues. The maps are fully populated through auto-discovery. “It is not the case that you have to define a policy and then we decorate it,” she highlights.

But a big, busy topology map can also be challenging to glean data from. To avoid that, WatchTower isolates the relevant areas based on context to keep data streamlined.

“We will give you only the portion of the topology that is most relevant to the alert you’re looking at. You can then change the filters and augment it and change it as you see fit.”

While brainstorming, SMEs can avail WatchTower’s shared virtual space that comes with a set of maps and insights as opposed to using a whiteboard, for better collaboration. This data is exportable to any CMDB solution, Fagen informs.

WatchTower is an on-prem solution, but offers the optionality to be deployed in public cloud.

To learn more about the WatchTower Platform, be sure to watch Broadcom’s presentation from Tech Field Day Extra at SHARE Kansas City 2024 at the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Broadcom WatchTower – Observability Data Tailored for Every Role

View Details

Quantum tech is slowly inching closer to becoming a reality. A global race has begun to harness the powers of quantum mechanics to build super-networks. The Quantum Internet, when it arrives, will make the World Wide Web look antiquated.

Quantum networks can transmit quantum data between distant machines through channels that are unassailable by hackers. But don’t hold your breath, because researchers are only testing the building blocks and working on prototypes. Leading companies like AWS, Microsoft, Google, Cisco and IBM have skin in the game.

During Cisco Live US 2024, Cisco unveiled some of its in-house technologies that are incubating in its newly opened Quantum Lab in Santa Monica. Led by Cisco Outshift, a visionary team that is behind many of Cisco’s breakthrough innovations, its quantum roadmap encompasses many milestones. The near-term goal is to build a quantum switch based on quantum teleportation. Stay with me because it gets interesting.

Quantum Networking 101Let’s get some basic questions out of the way first. What is the quantum internet? Simply put, it is a large and interconnected system of geographically dispersed quantum computers that communicate via quantum links.

Is quantum network going to replace the classical network? The short answer is no. Quantum networks are not meant to replace conventional networks, and it will be many many years before the technology achieves scale or maturity. However, its basic construct is analogous to that of today’s network which serves as its foundation.

This begs the question – why then build quantum networks? Several use cases have emerged in the quantum realm that require quantum networks to deploy. Some examples are cryptography, distributed quantum computing, distributed sensing and quantum money.

Distributed quantum computing is going to be the most dominant in the observable future, according to Tim Szigeti, distinguished technical marketing engineer for Outshift.

Quantum computers interconnected over vast geographic distances can realize huge benefits that today’s computers cannot come close to – unlimited processing power, fault-tolerant computation, massive parallelism, and so on.

Distributed sensing is another use case that has applications in the fields of astronomy and cosmology. Studies show that signals picked up by distributed sensors when merged over quantum networks provides shockingly high-precision results. The accuracy level significantly surpasses calculations done over classical networks.

“With a radio telescope array looking into deep space, the classical precision could be significantly improved by a factor of ± 1/N, “N” being the number of telescopes. So without touching the hardware itself, I can see deeper into space or farther back in time just by using a quantum network,” Szigeti explains.

Quantum-Proofing the PKIBut the most pressing and urgent use case, Szigeti says, is quantum key distribution (QKD). QKD and post-quantum cryptography are two of the proposed solutions to the Y2Q (Year to Quantum) problem. The Year to Quantum is still an unknown year, but as it approaches quietly, the current encryption schemes are at risk.

In a future where large-scale quantum computers enter the scene, the public-key cryptosystems currently in use face an existential threat. Quantum computers, infinitely smarter and faster at solving problems than conventional systems, can become the key to illegally decrypting cryptosystems.

“Your encryption is only as strong as your key exchange,” he cautions.

With approaches like “harvest now, decrypt later” where data is acquired and saved for later to read awaiting a possible decryption breakthrough, the public key infrastructure (PKI) can be broken in the blink of an eye with the quantum computer.

“Quantum computers are really fast, and they present a real and imminent threat to asymmetric key exchanges, particularly any type of public key infrastructure (PKI), all the Diffie-Hellmans, and elliptic curve cryptographies.”

The key to making PKI quantum-safe lies in the pages of quantum physics. Quantum physics is the study of behavior and characteristics of subatomic particles. Interestingly, this branch of physics defies all laws of classical physics.

“All the physics that we know apply to things that are larger than an atom. Once you get smaller to that scale, all rules just go out the window,” Szigeti states.

The reason for this is sub-atomic particles are unique. They have dualities whereby they exhibit behaviors and characteristics consistent with both particles and waves, a phenomenon not observed in larger objects.

“How can you be a particle and a wave at the same time is very difficult to express,” he says.

The technique of quantum teleportation capitalizes this. Quantum teleportation is nothing short of science fiction. But to be able understand it, you need to grasp a few fundamentals of quantum physics.

In quantum computing, the basic unit of information is quantum bit or qubit. Qubit can be made from electrons, photons or trapped ions.

The way it is different from a binary bit is that while a binary bit can only represent one of the two binary values, 0 and 1, a qubit, represents any proportion of these two values, in addition to the values themselves. In other words, probabilities of 0 and 1 simultaneously. This is called a superposition.

Superposition is key to manipulating qubits and achieving teleportation.

“Take for example a coin,” Szigeti says. “As it’s flipping in the air, at any given instant in time, it has a probability of resolving to heads or to tail. That probability is constantly changing until you finally take a reading and then it collapses that superposition to a single discrete value.”

These states of a qubit are highly delicate and easily disturbed. As long as a qubit is unobserved, it remains in superposition of probabilities. The instant it is read or measured, it collapses into one of the basis states.

Qubits are transmitted between quantum computers using the principle of quantum entanglement. The theory of entanglement states that two quantum particles can be intimately linked such that any change in the state of one is instantaneously reflected in the other, even when separated across billions of lightyears of space.

Quantum entanglement, the property of a quantum unit where two or more particles are linked across great distances without a physical medium.Leveraging this, a qubit can be manipulated to be entangled with another across vast distances with no physical medium in between. Entangled, their states are related, meaning measuring the state of one particle will tell you the state of the other.

Two or more qubits can be entangled in this way. The highest recorded number of entangled qubits in a quantum computer is 54.

Depending on how two qubits are entangled, they will represent one of the four Bell’s states – equal or opposite basis states.

This has its advantages. “Qubits can represent multiple values at the same time – 0 and 1,” he explains. “So, essentially, you’re actually sending much larger amounts of data with far fewer qubits than you would with regular bits. For instance, if you had one qubit to transfer, you’re transferring to the equivalent of two binary values for computation.”

A third phenomenon that makes faithful transfer of quantum states possible, and is especially beneficial in networking and communication, is no-cloning.

Quantum teleportation is the process of transferring an unobserved state of one particle over to another particle.It is scientifically impossible to clone a qubit. “Mathematically, it can be proven that it’s impossible to clone information that’s encoded in a quantum state. The simple descriptive proof is that you can’t copy something without first reading it, and if we take an instantaneous reading, we can’t copy and then eavesdrop and propagate.”

Quantum Key Distribution leverages this property. Information encoded in one qubit cannot be copied or duplicated because of the volatility of the states. If the state of a qubit is intercepted or changed, it will lose its superposition and because of entanglement, the information will be instantly transmitted to the other end.

If you are still with me, here is how these phenomena open doors for quantum teleportation. Imagine that you want to send over a secure message to a receiver at the other end of the line. In the first step, over a quantum network, you will entangle two qubits ensuring that the particles are fully correlated. Now send one over to the receiver while the other stays with you. Taking a reading of the state of the qubit at your end will create a shared key which can be used to encrypt the message you want to send via the usual channel. The receiver can then use the same key to decrypt and read the message.

Along the way, if a bad actor intercepts the qubit and gets the encryption key, the state of qubit will change to “read” instantly at the other end, indicating that the data has been snatched.

The Quantum RoadmapA comprehensive quantum program fuels all of Cisco’s research works around quantum networking. “Our charter is to say what kind of business problems of tomorrow should we start tackling today so our customers have the solutions as they run into these,” Szigeti says.

“We have quantum research scientists as part of our group at Outshift and they are doing mathematical modelling and publishing groundbreaking research on top of that.”

Insofar, Cisco has two published papers under its belt. One explains the blueprint for designing an extended quantum network spanning millions of nodes, and the other provides a framework for designing a quantum network on top of an existing optical network infrastructure.

“You don’t require rip and replace mandate in order to support quantum in the near future,” says Szigeti. “You can maximize the utility of what’s already available, minimizing the hardware investments.”

To offer a more practical experience, Cisco has developed a Quantum Network Design Kit (QNDK) Simulator. The QNDK Simulator is a software program that reproduces aspects of quantum networking. You can play with the protocols, or try building and interconnecting quantum networks on it. Besides being a good place to practice, the simulator also helps gain a good sense of what to expect from quantum networks before investing in the hardware.

Extending quantum networks over large physical distances require quantum repeaters to prevent data loss. These devices will link quantum computers across sites that have not interacted in the past into a giant quantum network.

“If you lose something along the way, you can do a parity check and then you can restore that loss and keep propagating it without actually taking a reading of the logical value of the qubit. It’s a workaround.”

Cisco is working on a one-way quantum repeater prototype, Szigeti informs.

Another technology shaping out in Cisco’s Quantum lab is a hardware Quantum Random Number Generator (QRNG).

“Current digital algorithms are actually not random. They’re pseudo random that take a specific seed and perform some mathematical operations in order to produce a string of numbers but it’s not truly random.”

Cisco’s Quantum Random Number Generator guarantees true randomness. Harnessing quantum uncertainty, QRNG produces mathematically proven random number sets.

“Not only it is a purely random number generator, it also has verification capabilities using the same Bell’s inequality theorem to prove that every component is maintaining true randomness.”

Do not miss Tim Szigeti’s in-depth presentation on quantum networking from the Tech Field Day Extra at Cisco Live US 2024 at the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Building Quantum-Resistant Encryption Systems, with Cisco

View Details

A question that has bent the mind for ages is “What really came first, the chicken or the egg?” An equally confounding question that has lately got many tech insiders scratching their heads is – What’s driving innovation? Is it hardware or software?

At the Networking Field Day event, Ed Horley, IT professional, author, and Field Day delegate, raised this question. Next day, him and the attending panelists met over a delegate roundtable to sink their teeth in and get to an answer.

Software and hardware have been locked in an incessant cycle of innovation for the past decade. New inventions in one category have been followed by even bigger disruptions in the other. So, it’s hard to put a finger on which of the two is ahead, or perhaps, which is a bigger catalyst to innovation. It’s quite a chicken-or-egg situation.

The Shape of InnovationThe proliferation of virtual technologies on the heels of cloud adoption has been a true accelerant for software demands. Software sales across the globe have skyrocketed.

Software sells three times more than hardware, said Ron Westfall, research expert and analyst at The Futurum Group.

The numbers don’t lie. More software products have found their way into the market in the recent years. Experts suggest that the continuing move to subscription-based services is another correlating factor.

To keep up, traditional networking hardware companies like Cisco, Ericsson and HPE have poured in sizable investments to establish that they now have software capabilities they didn’t have before, Westfall continued.

“Software sells three times more than hardware,” says Ron Westfall.It is plain that the industry as a whole has been focusing bulk of its attention and energy on software development. For many companies, it has served as a source of incremental income, but the hype is not immune to the transitory nature of the market.

“We did a lot of work around software, but the hardware has a chance to really change the dynamics about what’s going on in the industry overall,” Horley opined.

Hardware is not a supporting cast. Demand and revenue for hardware continue to remain strong globally across markets. The rise of AI and ML has heavily contributed to this.

AI has brought hardware to the top again by stoking demand for specialized accelerators like the GPU. To power these workloads, hardware is a critical component.

Another major driver is digital transformation that has led to new acquisitions of hardware technologies in on-premise data centers.

But spotting the real driver of innovation is still tricky. “The hype cycle around AI may be driven by hardware, but inside organizations, with trends like cloud adoption and hybrid workforce, hardware matters a whole lot less than what it used to,” Jordan Martin, principal architect, pointed out.

Greater emphasis is being laid on virtual services and how they will be consumed, over the underlying hardware ecosystem that’s making it all work.

A SymbiosisThere is an intertwining at play that must not be missed. Hardware and software in a solution constantly interact with each other. Out-of-the-box, hardware products promise a certain level of performance and efficiency. Companies write software that allows users to vacuum out that promised performance during real-world applications.

Businesses have relied on this hack for years to get max utilization out of their hardware. Disaggregation of resources at the software level has created newer opportunities to influence and exploit the hardware. So, it’s fair to say that in some ways, software is strengthening the demand for hardware.

But the role of hardware remains indisputable in IT. “If software’s reaching a point where they can fully consume everything that’s happening in hardware, you need a brand-new hardware,” Horley pointed out.

Ed Horley speaking at the Networking Field Day Delegate Roundtable in California.The symbiotic link between the two have been carefully fostered and capitalized by many vendors over the years. In the networking space, it is quite common to see software bundled with hardware products.

“With proprietary ASIC, you build a switch that only you and no one else can build, and then you write a software that only interfaces with that ASIC,” pointed out Chris Grundemann, founder and director of Grundemann Technology Solutions.

The two-in-one packaging benefits both parties. Customers are able to leverage the dependency getting the most out of the hardware, while companies earn more revenue selling the accompanying software.

Wrapping UpHorley’s analogy puts things in perspective. Imagine building a modern home with a paraphernalia of outdated tools. You may still be able to build a strong construction. But if you have a certain set of skills to give that modern flourish it needs, then it’s an extra advantage. That skill will go the extra mile that the tools cannot.

Software serves as that additional element that enables users to harvest more resources from a hardware solution by bypassing certain limitations.

Networking vendors’ visible interest in software innovation demonstrates that it continues to be a key enabler for hardware. It is unlikely, however, that software will leapfrog hardware at any point, becoming the sole driving force of innovation. Like an orchestrator to an ensemble, it will continue to make hardware better through intelligent manipulation.

Be sure to watch the full delegate roundtable from the Networking Field Day event at the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: The Interchanging Roles of Hardware and Software in Fueling Innovation

View Details

Technology is advancing rapidly. The parade of new innovations that have seen the light of day in just a few years’ time is telling of how rapidly the advancements are building up on top of one another. And the footprint only continues to grow.

New Problems Demand New SolutionsMuch of these next-gen technologies are developed in and delivered from the cloud. The cloud provides the ultimate infrastructure for innovation – on-demand resources, easy renting and little to no housekeeping.

Fun fact, the glitzy cloud data centers are no different than the private data centers. The racks are modeled on the same server architecture as enterprise data centers.

In the classic architecture, all of the software and services run off of the CPU, the brain of the computer server. Applications, infrastructure services, operating systems, hypervisors – the CPU caters to all.

There are significant drawbacks that make this blueprint unsuitable for cloud. For one, it is meant for use by a single party only.

Today, CSPs support a near-infinite number of parties and tenants out of the cloud data centers. Doing that amount of processing off of the CPU is impractical. Not only services have to constantly compete for resources and take hits on performance periodically, the design also poses a problem for the cloud business model.

Cloud operators are in the business of offering compute-as-a-service. Naturally, they want everything that is not associated with the service removed from the CPU. At the top of their list is infrastructure service.

“There are two reasons for this,” says Thomas Scheibe, VP of solutions and business development at Intel. “One, you don’t want to burn the CPU that you want to make money off of. The other, you want to have a hardening around security because you don’t want to have to use the app running in the same space where you run your infrastructure services.”

Intel likens it to the problem of comparing hotels to homes. If homes and hotels were built on the same architectural design, it would have been a disaster.

Disaggregation as the Foundation for Infrastructure OffloadingThe Intel Infrastructure Processing Unit, or IPU, provides a path for infrastructure offloading through disaggregation. Co-designed with Google, the IPU is a game-changing technology that alters the way processing happens within the server.

“IPU is a fun product with a bunch of networking and a bunch of compute – best of all worlds,” says Scheibe.

The IPU forges a design where the CPU does not carry the full weight of processing. Instead, it allows the load to be shared between the CPU and an improved NIC (Network Interface Card), which is essentially what the IPU is.

Standard NICs do not have embedded cores. Straddling the categories of Ethernet NIC and AI-optimized NIC, the IPU is an ethernet NIC that has an embedded CPU complex that lets it do additional stuff.

“The IPU is the most premium, flexible NIC you can think of – you have standard Ethernet path and all the flexibility of an embedded set of cores,” he says.

There are many advantages to this. First, all infrastructure services are offloaded from the CPU onto the IPU. This itself lowers server overheads leading to performance gains, which can then be leveraged for applications, the part of the business that generates revenue.

The other big advantage is that functional isolation gives CSPs complete control of the infrastructure.

“You can decouple what you want to do in terms of feature development on the infrastructure side, from what you do for customers that are actually using the main host.”

As tasks like networking, security and storage are performed on the IPU, a provider can gain infrastructure acceleration through the hardware accelerators.

“You will build, in these IPUs, hardware accelerators, whether it’s encryption or decompression-compression. You basically have the chance to just add that little node because it’s silicon, and you just have this as an accelerator sitting right there.”

The salvaged host compute cycles previously spent on doing infrastructure tasks can be utilized to power the workloads.

With the two parts separated, tenants have the CPU all to themselves. “Now you can look at these different use cases you can really go after,” Scheibe says.

Intended Areas of UseIntel proposes a host of use cases for the Intel IPU. Key among them are cloud and edge.

“Where this is going and where we see a lot of interest is moving from the public deployments to more of a private cloud operations model deployment, and service edge where you actually want to have real separation of service and the edge.”

At the edge, IPUs introduce network and compute resources in edge appliances. The IPUs virtually serve as plug-and-play compute units. This eliminates the need for building big, dedicated edge servers.

Scheibe also highlights edge inference as a major use case where the decoupling provides special benefits in terms of isolating and securing the models running on the host from the rest of infrastructure.

Be sure to check out Intel’s presentations from the Networking Field Day event to learn more about Intel IPUs.


© Gestalt IT, LLC for Gestalt IT: Intel IPU – Unlocking the Power of Functional Isolation

View Details

Military strategist, John Boyd, back in the mid-1900’s, developed a decision-making model that’s passed down as one of the most enduring approaches of combat operation. It is famously known as the OODA loop.

OODA stands for observe, orient, decide and act. The model explains how a quick retaliation in the battlefield can gain an army significant advantage over brute power.

The OODA loop has not only been a principal concept in military defense strategies. In modern-day cybersecurity, it is the gospel of security analysts.

A Tool to Enforce and Boost the OODA LoopCisco XDR is built to hyper-enable this loop in cybersecurity. Distinguished engineer, Matt Robertson, describes it as “an efficiency tool” for the Security Operations Center (SOC).

XDR brings to offer a very specific set of capabilities,. If properly implemented, they can help SOCs deliver a swift response to unfolding attack chains and get ahead of the opponent.

XDR follows three logical steps – investigate, prioritize and act. In a nutshell, Robertson explained them the TFD audience at Tech Field Day Extra at Cisco Live US 2024.

“Cisco XDR is a collector of data from multiple security tools. We apply analytics to the data to arrive at detection of maliciousness, and then provide response through automated actions.”

In short, operators can go straight to action and remediation with speed and efficacy with the insights it offers.

Cisco XDR performs two types of detections – native and extended. Detections that are made from downstream sources – like cloud logs, NVM and NetFlow- that do not contain native verdicts, are called native detections. Data is run through behavioral models that list down the observations, and subsequently alerts are built around them.

These are high-fidelity, low-noise alerts. Only observations that strictly meet the threshold of active alerts are passed as alerts. “Not everything that is malicious passes this threshold,” he says.

For extended detection, data is taken in from integrated products and investigated through correlation. This data already has verdict natively built into it. Cisco XDR enriches it by layering it with additional data.

A Long and Complex Analytics PipelineThe data analytics pipeline where incidents are created and fine-tuned in XDR is highly nuanced. “It goes through a long, complex analytics pipeline.”

Robertson explains what is an incident in XDR terminology. “An incident is a data object that is made up of data from multiple security tools or integrated toolsets. As data comes in, we do analytics and correlation, and create a logical incident bundle which is the object upon which an analyst is going to interact.”

To help understand the process of incident generation, lets divide the pipeline into two segments – data acquisition and data analytics.

Data is the meat and potato of this pipeline. Multiple sources across various domains are scraped to collect this data. Some examples of data collected are EDR (end-point detection and response) technologies, network telemetry, data from hosted infrastructures like AWS, GCP and Azure, identity service engines, emails, etc.

“Depending on the source, some are API, and some are streaming data,” Robertson notes.

This corpus is normalized and sent to the data warehouse where analytics engines thresh insights from the raw datasets.

The analytics segment reveals another complex layout of phases and processes. It primarily includes observation, alerting, prioritization and incident generation.

Algorithms skim data for indicators of compromise. The observations are then profiled based on severity. A probability-driven model does this by sifting through the datapoints and deciding which of the findings qualify as alerts.

Inside Cisco XDR’s Correlated Incident GenerationPerhaps the most important and intricate of the processes in the pipeline is correlated incident generation.

“It’s about taking multiple alerts and reconstructing the attack chain,” explains Robertson.

The process begins by aggregating a bunch of independent alerts from across domains and correlating them to trace a logical attack path. If the findings correlate, a GenAI SOC assistant takes over to investigate the datapoints. It puts together a brief summary of the attack, and incidents are surfaced on the UI for operators to inspect.

The SOC Assistant is a newly-introduced feature that also guides the investigation by producing incident-specific workflows with next best steps, and lets operators launch war rooms on integrated messaging platforms.

“An incident is never complete until you mark it as complete,” Robertson reminds. “It can continue to have more data put into it as detection analytics identify more alerts.”

All incidents go through a scoring process where scoring algorithms determine their priority levels based on risks and asset value. Depending on whether an incident is gaining additional data or not, the algorithms prioritize or deprioritize them.

In the final stage, insights are enriched with additional information from integrated products. “That data is then decorated on top of the logical incident bundle.”

Check out the Cisco XDR presentation from Tech Field Day Extra at Cisco Live US 2024 to catch the demo at TechFieldDay.com.


© Gestalt IT, LLC for Gestalt IT: Act on the Highest Priority Cyber Incidents with Speed and Success, with Cisco XDR

View Details

There is a prevailing narrative in IT that complexity kills productivity. Complexity is the enemy of efficiency, and yet, it is the inevitable trade-off of upgrading to a new technology.

In networking, where there is a bewildering amount of variety just in terms of network architecture and design, operators are drowning in complex operational workloads.

Joining two types of network fabrics, for example – ACI and VXLAN EVPN – requires addressing many independent and interdependent facets in isolation. These include provisioning, security, management and so on.

It is a deeply technical and time-intensive job, one that is made trickier by the underlying architectural differences of the topologies. The skill is painfully hard-won, and takes significant training and practice hours.

A Solution that Helps SubstantivelyCisco has come up with a solution that makes the highly technical work of managing and joining different flavors of data center network fabrics surprisingly low-tech.

The Cisco Nexus One Fabric Experience solution hides away complex technicalities of fabric technologies, making them operationally uniform and consistent.

The inspiration for designing Nexus One Fabric Experience came from this: Cisco customers fall in one of three buckets – the ACI fabric users, the users of NX-OS with Virtual Extensible LAN Ethernet VPN (VXLAN EVPN) fabric, and those that deploy massively-scalable, large, routed fabrics.

What Nexus One Fabric attempts to do for each of these customers is offer “a unified experience that allows them to provision and connect application to these different fabrics and manage them in a seamless way,” said Max Ardica, distinguished TME at Cisco, while presenting the solution at the Tech Field Day Extra at Cisco Live US 2024.

Highlights of the ArchitectureArdica dug into the solution architecture that constitutes three core building blocks – ACI VXLAN EVPN Border Gateways, VXLAN GPO or group policy option (GPO), and the Nexus Dashboard.

The ACI fabric is perceived as a closed ecosystem that can only be linked to its own kind of fabrics. The ACI VXLAN EVPN Border Gateway opens up the ACI architecture allowing it to be interconnected with any standard VXLAN EVPN fabrics.

The gateway serves as the hook that establishes standard VXLAN EVPN connectivity between an ACI domain environment and VXLAN EVPN domain, he explained.

The ACI VXLAN EVPN border gateway behaves and functions essentially the same way as a fully standard VXLAN EVPN border gateway that Cisco has been shipping to build multi-site networks for the past 7 to 8 years.

“When you bring an ACI fabric together with VXLAN EVPN, you may have some conflicting resource ID like VXLAN IDs or group conflict,” Ardica noted. “We are going to build a namespace normalization translation function on the ACI border gateway that will translate to ensure that they can functionally operate as a single object even if they have been assigned different resources.”

Done this way, ACI and VXLAN EVPN will become “equal-class citizens”. The use cases formerly supported on ACI can now be extended to VXLAN EVPN.

An ACI fabric by design is zero-trust and identity-based. It is configured with endpoint groups or EPGs that are named logical entities for endpoint groups.

“When you want to establish connectivity between two endpoints, you need to map them to two security groups and create a contract.”

By contrast, VXLAN EVPN has a different design that de-prioritizes security. ““EVPN VXLAN has always been around connectivity layer 2 or layer 3, but the policy is never considered an important functional component,” he pointed out.

VXLAN GPO or group policy option allows security groups and contracts to also be enforced in VXLAN EVPN. This extension of policy makes for a unified policy domain end-to-end between the two heterogenous fabrics, allowing operators to centrally permit and deny traffic.

Customers can configure the VRF in two modes to enable GPO – deny by default, or permit by default.

“ACI is a whitelist model which means two different groups in ACI do not talk to each other unless you create a contract that allow them to talk. But we have customers who would like to start with a blacklist model where everything is allowed even if you create different groups and then just deny specific flows between these groups.”

Principal engineer, Matthias Wessendorf said, “We, from the beginning, started to decouple the forwarding from the policy because in ACI, the forwarding and the policy is coupled. Now the ESG or the GPO is across the forwarding, just defining the policy, and carrying the identity through the network.”

The Cisco Nexus Dashboard is the final piece that complete the solution. Designed to mask the differences in the fabric designs, it provides a single touch-point, offering a seamless policy management and provisioning experience without delving into the mechanics of different fabric types.

With the Nexus Dashboard One Fabric Experience, users can link two similar fabric types or two different types of fabrics depending on the use case. “You describe what you want to do and the system takes care of it,” Wessendorf said.

Know more about the Nexus One Fabric Experience by watching Cisco’s full presentation from the Tech Field Day Extra at Cisco Live US 2024 at the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Taming Architectural Complexities of DCN Fabric Technologies with Cisco Nexus One Fabric Experience

View Details

The recent Microsoft outage was a jolting reminder of what happens when a technology that has a track record of being reliable and consistent breaks. Flights were grounded, hospitals went into a scramble, retail stopped working, the world came to a screeching halt.

When network issues strike, the consequences are just as disastrous. The network works very well on good days, and that is most days, leading to the expectation that it will always work the same. But potential problems can manifest any day, degrading user experience across the board.

What No One SeesOutages and disruptions knocking systems out in the middle of busy workdays have become more and more frequent in the news. To help understand what causes these impactful incidents, one needs to look behind the scenes.

The way users perceive connectivity is misleadingly simple. It is not just a device and a resource communicating over the network. It’s a little more complicated than that.

Connectivity encompasses a breadth of things that include people, devices, network services, infrastructures, and applications.

“The complexity of how a user accesses an application or a resource today is very complex,” remarks Marko Tisler, group product manager at Cisco ThousandEyes. “It breaks in so many fabulous ways.”

Tisler explains that when a user connects to a resource, the request traverses multiple networks via various paths, going through several hops and handshakes, before it is able to consume the service. Interruptions can happen at any point in this complex and dynamic path.

A problem can originate in the client device, itself for example. Or an authentication error or service problem in the middle mile can break or slowdown the communication. App downtime too is a leading cause of poor user experience.

“Users don’t see any of these complexities that lie between the two points of connectivity,” he says.

DXA, a Three-Legged StoolOn the provider’s side, it’s a complex diagram of IoTs and ISPs, gateways and VPNs, cloud and datacenters networks. Some of these networks they control, but the ones outside their perimeters, are not in their control.

In an ideal world, a provider should have visibility of everything that’s happening in any of these networks at any given time of the day, like their own networks. But in reality, broken observability of intermediate networks and nodes make service assurance hard.

More than one network visibility solution has failed to provide fine-grained visibility across the nodes because the key principles of digital experience assurance were not identified.

Consider a three-legged stool. If DXA is this stool, the three legs it stands on are visibility of the end-to-end path, AI-augmented intelligence, and closed-loop operations.

If a solution has these three capabilities, digital service assurance can be rightfully expected.

More Data, Clearer VisibilitySince its inception, ThousandEyes has sought to understand all the interesting ways the network breaks.

Cisco, for years, has done visibility by means of synthetic testing where different favors of agents are leveraged to perform tests on certain resources. There are two approaches to this – an “outside looking in” methodology where cloud-hosted agents test resources hosted in client environments.

“We have multiple points of presence across the globe, and our customers can use those as proxy metric of find out how the connectivity looks, their applications, from customers that are distributed across the globe,” he informs.

The other is the “inside looking out” approach where agents hosted in customer environments are used to test SaaS services used by employees.

But the “end-to-end visibility from the network interface of the user device to where the application is hosted – be it datacenter, physical server or a hyperscaler environment,” that is the ultimate goal demands more datapoints.

Besides synthetics, “we need to consume other datapoints to be able to be more precise, to give more context, and context is what we really are after,” Tisler points out. It is the cornerstone for establishing root cause.

New DXA Innovations from the House of ThousandEyesAt Tech Field Day Extra at Cisco Live US 2024, ThousandEyes debuted three new solutions – Cloud Insights, Traffic Insights, and Shared Cross-Domain Context.

The trifecta of these solutions will give customers highly specific context and the right datapoints to expedite troubleshooting and reduce mean time to resolution (MTTR). This, they say, will assure top-notch digital experience end-to-end over any network.

ThousandEyes Cloud Insights is a cloud topology visualization tool designed to provide enhanced visibility into public clouds.

Cloud Insights creates topological mappings of customers’ cloud infrastructures and environments. It can auto-discover cloud provider resources, drill into service dependencies individually for that extended visibility, and show traffic patterns and characteristics in the cloud.

Additionally, it can track down infrastructure changes, and correlate them to the user experience. This tells operators how a change affects the digital experience for a group of users.

Knowing what’s going on “beyond the front door of the hyperscalers” enables operators to identify issues faster, triage quickly and perform a speedy root cause analysis.

ThousandEyes Traffic Insights is a traffic analytics system. Its key capability is unifying views of the internal and external network conditions.

Traffic Insights gathers flow data from the routers, and surface contexts allowing operators to cross-relate them with synthetics.

“We’re seeing the demand for this from two different perspectives,” Tisler told.

Synthetic tests point to a problem, but they do not offer any insights into experience degradation.

“In some cases, there’s nobody on-site using an application at a point in time which probably means it’s a less important issue compared to the same problem manifesting itself when thousands of users are trying to access that resource from that same site.”

ThousandEyes can determine the urgency of an issue based on the number of users trying to access the resource.

Traffic Insights’ advanced analytics also prove helpful for capacity planning. The holistic view of usage makes planning precise while providing basis for future forecasts.

Shared Cross-Domain Context is a joint implementation of ThousandEyes and Meraki. When a problem occurs, the team jumps in to find the proverbial needles in the haystack.

Shared Cross-Domain Context enables a bidirectional exchange of data between Meraki and ThousandEyes. This gives it the ability to correlate data from across the digital supply chain. With information about infrastructure health, client health and app health in one place, operators can promptly isolate service degradations and dig into the root cause.

For more, watch Cisco ThousandEyes’ presentation from Tech Field Day Extra at Cisco Live US 2024 at the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Take Daily Measurements of User Experiences across the Network with New DXA Innovations from Cisco ThousandEyes

View Details

We’re taking Tech Field Day to the SHARE conference this year, and we hope you can tune in live or watch the recordings. Tune in August 6th on the Tech Field Day website, Techstrong TV, or on our LinkedIn page. Here’s a quick overview of what to look forward to with Tech Field Day Extra at SHARE Kansas City.

Learn more about the event on the Tech Field Day Extra at SHARE Kansas City Event Page.


Event ScheduleTech Field Day at SHARE will be broadcast live on LinkedIn, the Tech Field Day website, and Techstrong TV starting at 9:00AM Central time on Tuesday, August 6th, with more presentations throughout the day. All of our sessions will be recorded and posted to the Tech Field Day YouTube channel just in case you miss anything.

We start off at 9:00AM Central with PopUp Mainframe. They’re a leader in on-demand Mainframe for development and testing, democratizing access to Mainframe environments. We’ll then follow up with a roundtable discussion with our delegates, which I’ll be leading, looking at the state-of-the-art for modern Mainframes and enterprise IT.

After lunch, we’ll have BMC presenting their cutting-edge solutions in the DevX and AI Ops space. Finally, we’ll wrap up with Broadcom, who will present Watchtower, their OTL-driven platform that is transforming observability and AI Ops for the Mainframe.

You can also catch the Tech Field Day delegates on a special episode of the Tech Field Day podcast published on July 30th, and tune in for behind-the-scenes shorts, Tech Talks, and extras recorded at SHARE in Kansas City.

Watch Live and Follow AlongAll of our sessions are broadcast live on LinkedIn and the Tech Field Day page, as well as on Techstrong TV and our social media platforms. They are also recorded and shared on the Tech Field Day YouTube channel in case you miss anything. We welcome participation on X/Twitter, LinkedIn, and Mastodon using #SHAREkc2024 and #TFDx. You can learn more about the event and our panel of independent technical influencers by visiting the Tech Field Day website. Each of our delegates has their own blog, podcast, or social media platform where they share their thoughts on enterprise technology, from servers to storage to networking and, yes, mainframes.

We’re proud to have Steven Dickens joining us from The Futurum Group, and we look forward to his analysis and reactions. Thanks for joining Tech Field Day live from SHARE Kansas City on August 6th. While you’re on YouTube, please subscribe to our channel and follow our LinkedIn page for more great Field Day content.


Stephen Foskett is the Organizer of the Tech Field Day Event Series, now part of The Futurum Group. Connect with Stephen on LinkedIn or on X/Twitter.

Steven Dickens is Chief Technology Officer at The Futurum Group. You can connect with Steven on X/Twitter or on LinkedIn and listen to his frequent appearances on Infrastructure Matters.


© Gestalt IT, LLC for Gestalt IT: Mainframes Take the Main Stage at SHARE Kansas City 2024

View Details

Amid ravings of AI hallucination and bias, theories of bots replacing humans, and rumors that the models have quietly stopped learning, the tech industry is aggressively putting AI behind its legion of products and services.

AI’s explosive popularity can mean only one thing – more innovations are heading our way.

AI, a Resounding Theme in TechAt Qlik Connect 2024 in Orlando, Florida, “there were 129 mentions of “AI” in the keynote,” noted Joey D’Antoni, IT veteran and a long-time Field Day delegate.

D’Antoni attended the event with other Tech Field Day panelists, and Futurum Group analysts, and like his peers, he too was not surprised by the undisguised underscoring of AI.

AI has certainly been a dominant talk in all of the tech shows and events this year. Qlik Connect struck a slightly different chord, however. The panel observed that Qlik leaders decisively steered the conversation towards the burden of responsibility.

In the past few years, data companies have seized the reins of discussion around responsible AI and sustainability. But a handful of companies like Qlik have been spearheading a movement to use AI for the greater good.

Qlik’s deep engagement in AI sustainability is no news. For quite a while, it has been the talk in the press.

“Qlik has an amazing team doing sustainability, and they have been doing it since the company was founded,” pointed out Gina Rosenthal, founder and CEO of Digital Sunshine Solutions, a B2B marketing firm.

Qlik’s analytics platform has been the foundation for building custom data-driven analytics applications for many organizations.

Through the Qlik Corporate Social Responsibility program, the company has engaged with many non-profit organizations helping drive development and value in the areas of economy, society and environment.

“They’ve begun working with the UN Council on climate change to give them the AI tools they need to float things up,” she told.

Qlik has been one of the forces behind UN’s sustainability and humanitarian missions since 2018. The platform provides the UN staff members a self-service portal for data visualization and reporting.

Expanding Analytics Initiatives with Other NGOsQlik is working with a growing army of NGOs that provide relief and aid through global crisis like the war in Ukraine, and the COVID-19 pandemic. Qlik has made its software available to these partners enabling them to leverage data for their operations.

Qlik has also thrown its weight behind groups that are addressing and combatting climate change in various parts of the world. For bodies like C40 and UNFCCC (United Nations Framework Convention on Climate Change), the Qlik software provides actionable analytics on global datasets on climate, helping flesh out intelligence and meaning from vast volumes of raw data.

“They have a really nuanced and realistic picture of AI,” Stephen Foskett, president of Tech Field Day commented. “Qlik understands that AI is coming, and they have brought forward their background in ESG and concern for climate change.”

Qlik’s sustainability efforts are further amplified by the company’s choice to deploy AI in a cloud-hosted environment. By training the model on a limited subset of data instead of building it from scratch, it is able to deliver intelligent, precise, data-driven analytics for each use case.

A big part of the brand is the Qlik Community which is a global group consisting of employees, users, experts, partners and technologists. The community provides people a space to connect and interact. Anybody that is a part of the community can tune in and join the chatter, browse resources and obtain support.

“Qlik Connect is showing a complete community,” said Keith Townsend, analyst and thought leader at The Futurum Group.

No-Fluff MessagingLike its vision, Qlik’s messaging is bang-on. As the rest of the industry is busy AI-washing, Qlik has taken up the initiative to raise awareness about the importance of good-quality data.

“Pretty reports aren’t really meaningful unless you have a good data model behind them,” said D’Antoni.

The measure of data quality is not accuracy alone for Qlik. Qlik takes into account five additional dimensions, namely, diversity, timeliness, security, discoverability and consumability, to define data quality.

Qlik’s marketing is free of the usual puff. Instead of upselling AI like many companies, it has adopted a more balanced approach towards promoting it.

“They’re telling people to not go for the whiz bang at the end because this is going to take some time,” said Rosenthal. “It’s something that works that you’re going to have to construct from your data in business process.”

Steadfast on its mission to democratize data, Qlik is working on making analytics consumable for all, irrespective of their technical know-how.

“It’s made for the data engineers that can get in at the backend and do lots of checking. It’s made for people who have no engineering experience to get things up and started. It’s very low code,” Rosenthal added.

Joey D’Antoni speaking at the Delegate Roundtable“The emphasis on data quality and some of the technologies Qlik has acquired through the years help take them out of just being a dashboard software company into being a more complete data analytics company and make for a compelling offering,” D’Antoni said.

Acquisitions like Talend, Kyndi and Mozaic Data have generated significant buzz gaining Qlik more mindshare. They have also brought new capabilities to add to the platform making the product more powerful and effective.

Even the Qlik website reflects the same brand distinctiveness that is its identity, points out Jay Cuthrell, founder and CEO of Cuthrell Consulting.

The Qlik Bot on the website serves as not just a finder for the solutions, but also works as a second banner for announcements.

“They pre-position the content for the announcement as the first thing that the chatbot would tell you about, which corresponds with the top of the website banner. Little attention to detail like that tells you just how platform thinking this organization is,” he said.

Be sure to watch the full Qlik Connect 2024 Delegate Roundtable – Data Pipelines for AI. Also check out Qlik’s presentations from the Tech Field Day Experience at Qlik Connect 2024 where Qlik showcases many of its solutions discussed in this roundtable.


© Gestalt IT, LLC for Gestalt IT: Qlik – Opening a Broader Access to AI-Driven Data Analytics

View Details

With cloud app development on an upswing, companies have more than doubled their cloud spend in the past two years.

On an average, an organization spends over a million dollar yearly on public cloud services. IDC projects the global spending to grow significantly, reaching $1.35 trillion by 2027.

As revenue is ticking down from the economic slowdown, many businesses are now looking for areas where they can cut costs. Even the biggest spenders in the cloud have FinOps teams looking into their monthly cloud bills, and understand resource utilization, cloud-computing charges, and hidden costs.

The Cost to Get Data OutOne of the things that have been sneakily mounting the total cloud spend for organizations is data egress charge. Hyperscalers do not charge anything when data is brought into the platform. But they charge a significant fee for moving it elsewhere. This is called data egress cost.

For example, AWS charges an egress fee of 9 cents per GB for outbound data. A nominal sum it may seem, but it’s not.

“These costs seem very minimal, but if you are doing transfers of 100 Terabytes or 1 Petabyte, they multiply by 10 to the power of 6 or 9,” said Ashish Swaroop, sr. director of product management at Arrcus.

Cloud providers charge egress fees for a reason. It costs them money to move data out of their network.

It is a complex model that varies from provider to provider and the time of the day. Egress costs are metered and billed in multiple categories for example, VMs, storage, and the path chosen to route the egress traffic.

A Solution That Keeps Egress Data Transfer Costs MinimumIn Jan, Arrcus unveiled a solution that provides cost relief for multi-cloud enterprises. It’s called EgressCostControl (ECC). At the Networking Field Day event in California, the team presented it to the audience.

Through a demo scenario, Swaroop showed how ECC manages and controls egress costs in the cloud.

ECC is a dashboard embedded in the ArcOrchestrator, a multi-tenant platform for cloud connectivity management. The ECC dashboard provides a digital map of cloud consumption and cost tied to an account.

As an operator logs in and starts a transfer, it calculates the total utilization and cost of the transfer and displays it in a graph. When more than one path is chosen, the graph provides comparative values between them indicating the cheaper alternative.

This is how it happens behind the scenes. The ArcOrchestrator provides ECC access to telemetry data streaming from ArcEdge instances.

When ECC is turned on at a certain interface, ArcEdges can start transmitting data to the orchestrator telling it about the volume of data leaving the network via the routers. The orchestrator works out the accumulated egress charges for that account.

This is done via polling of publicly available information on rates of various providers.

Specific information too can be uploaded on ArcOrchestrator. “For example, if you have a leased line or a dedicated link, you’ve negotiated some prices for it, you can upload all of that information into ArcOrchestrator, and it will take that into account as well,” said Sanjay Kumar, VP of marketing.

The egress cost of the interface is fed into the routing tables, and the routing protocols decide which path to use to keep the cost between the source and destination a minimum.

Border Gateway Protocol (BGP), which is a common routing protocol, normally favors the shortest path to route the traffic. ECC picks the path that costs the least.

“By activating ECC, we are forcing the routing protocols to consider all the underlay paths available, and make a routing decision that minimizes the egress charges,” told Swaroop.

To put it plainly, ECC influences the routing selection algorithm, getting it to choose only the most cost-optimal path.

It is worth noting though that the cheapest path is often the longest. Therefore, it is not the smartest choice for low-latency data transfers. To stop ECC from routing egress traffic via the longer paths by default, users have the ability to turn it off at certain interfaces where real-time speeds are required.

Don’t forget to check out Arrcus’ presentations from the Networking Field Day event to know more about the solution.


© Gestalt IT, LLC for Gestalt IT: Save on Outbound Data Transfers in the Cloud with Arrcus EgressCostControl

View Details

Chatbots like ChatGPT and Copilot are remarkably skilled and articulate when it comes to subjects they are trained on. But they frequently struggle with domains outside their scope of learning.

One area that has stood out in that regard is network monitoring. The human-level fluency that open-source AI tools are loved for tend to fall apart when faced with questions about domain-specific information. For example, if you ask ChatGPT questions about SNMP data or syslog, it will not be able to provide helpful answers.

The reason is, it was never designed to do that. Yet it does not seem to dampen the desire of users to throw problems at it that it doesn’t know how to solve.

“There is a natural tendency to assume that we can take our infrastructure data and just connect up to ChatGPT and get a conversational interface,” says Nitin Kumar, co-founder and CTO of Selector AI, at the recent Networking Field Day event.

It’s a reasonable argument, except, it has a major flaw. The cloud platforms where these services run, are vastly different from the private infrastructures where the data resides. Connecting the two requires a medium.

“Not only is the distance a problem, even the semantics of that information that sits in these systems is incomplete.”

A Skill ProblemHybrid cloud deployments have been on the rise in the past few years, a trend that has made networking woefully complex. Think of a retail network that connects hundreds of stores scattered across the globe. These stores connect to a cloud network where all their applications run.

If a cash register at one of the stores fails to connect up to the payment application in the cloud, it can grind things to a halt in a moment.

The network is the usual suspect of course, but to an ordinary IT guy, that tells nothing of the real root cause.

Increasingly, it is getting trickier for people without specialized knowledge to analyze network data. Data silos demand specific types of domain expertise, and only a small group of people can make sense of that information.

“People who are experts in these domains have access to that data. They understand what’s going on, but any other person is not able to figure out where the problem is,” Kumar points out.

Serving Data to a Wider Group of PeopleData democratization can change that. “The ability to access and understand any kind of data across all of these different domains,” has been the key driver for the Selector Platform.

Selector provides two key capabilities – a conversational interface like ChatGPT where any IT persona can make natural language queries and get answers instantly, skill no bar, and an alert layer that puts together information about errors and failures into comprehensive alerts. Together, Selector Copilot and Smart Alerting bring intelligible and consumable data to the fingertips of users across the board.

“You are no longer hostage to experts or vendors or a particular domain,” Kumar emphasizes.

Investigating Incidents with ConversationIn a demo, he showcased the two interfaces in different scenarios.

Selector Copilot welcomes users with a clean portal and a search bar for typing queries. One can ask any question in English, and it fetches results in seconds.

Kumar gave a couple examples to elaborate. In a scenario where retail stores in a particular region are encountering issues, Copilot can surface contexts – what could be causing the issue, what internet services are down in the area, and what applications are likely to get impacted.

Copilot puts together simple topology maps, color-coded visualizations and incident summaries to make complex investigations super-simple. “The manner in which this information is presented is very human-like,” he says.

The interface also offers historical perspectives by showing users before and after pictures.

Follow-up questions can be asked as one proceeds with the analysis. All outputs can be saved and organized in a custom canvas on the left-hand side of the UI for troubleshooting sessions.

Information found by interrogating Copilot can also be found pre-bundled under alerts at the alert layer. The biggest selling point of Smart Alerting is alert consolidation. Instead of pushing out “onesies and twosies – one event, one alert” that is distracting and counter-productive, Smart Alerting encapsulates information of tens of alerts into one notification for wider observability and low noise. The ready analytics help users dig deeper into an issue and track down the origin in the shortest time possible.

The alerts also have various workflows. “You can create an incident around it. You can create a PagerDuty incident or a ServiceNow incident, and teams downstream can then take care of that,” Kumar adds.

The Framework BelowUnder the hood, a software layer acts as the bridge connecting the on-prem infrastructure with the cloud services.

Network data is collected from far and wide in the network through collectors deployed across regions.

“Collection of the data itself is a big problem,” Kumar notes. “You need to be able to know the devices that you want to go to. There’s the crawling aspect, mechanisms that discover all the devices in the subnet or a particular region, do the last mile connection, and start SNMP polling.”

Adding to the problem, this data has no one format. “There’s no single format that’s going to be applicable to all infrastructures, and we need to embrace the diversity, not run away from it,” Kumar exclaims.

Selector has a built-in layer that transforms all the different schemas into one universal format. This is a homegrown data compiler called Data Hypervisor.

“Just like compute hypervisors abstracted details of compute and storage from applications, the Data Hypervisor hides the formats of the underlying data and presents it in a uniform way.”

The data is saved in data stores which serve as a single storage layer for this mixed corpus. It is subsequently processed, and analyzed by the Selector LLM deployed close to on-prem.

Results are published via a variety of third-party interfaces that include, but not limited to Slack and Teams.

Don’t miss the Selector Platform demo and other deep-dive presentations by Selector from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Rapid Investigation and Response with Selector’s in-Platform LLM

View Details

Electronic trading, from an investor’s perspective, is a one-click buy and sell process. But the network behind e-trading platforms that matches the buy and sell orders cannot be more complex.

“This is where they get the orders to buy and sell. This is where the decision is being made,” said Ron Nevo, chief technology officer of cPacket, at the recent Networking Field Day event in California.

A Network to Match Buyers and Sellers in Real-TimeExchanges hold the power to influence the economy. Traders and brokers across the globe make transactions trading securities round the clock in various marketplaces.

A multi-cast IP network is used to send data downstream to the investors.

“Each trader is registering for a specific stream that carries specific movements or tickers that they care about. They will get the information and make the decision to buy or sell based on this information,” Nevo explained. “There are no retransmissions. You either get a packet or you don’t get it.”

Market movements occur every second. Hence, every packet of data traveling through the network must reach its destination, without fail or delay. At the bare minimum, this requires a lossless and ultra-low latency network. But there is a wrinkle.

When a data packet is transmitted from one interface to another, it makes several hops on the way before it arrives at the destination. During these hops, data is temporarily held in the memory before being sent on its way, a phenomenon called buffering.

In an extremely low-latency network, the aim is to send as much data as possible in the shortest time. To achieve that, large number of packets are queued and transmitted in rapid bursts. This causes short spikes in the traffic, often referred to as microbursts.

Microbursts lead to buffer overflows resulting in packet loss. The bursts create frequent bottlenecks making packet delivery slow and intermittent.

The situation is like an infant chugging milk too quickly to keep up with a fast flow. Some of the milk goes down, and some of it flows back out. This effect, in electronic trading scenarios where every packet matters, can spiral into big losses.

With low-latency switches transmitting GBs of data every minute, buffer overrun occurs in milliseconds.

A Neat TrickRemedying this problem demands a new delivery architecture that prevents bottlenecks by default. cPacket has a uniquely distributed design that puts programmable ASICs and FPGAs together.

This purpose-built hardware is distributed across all ports turning them into FPGA-based smart ports. With dedicated silicon and FPGAs present on every port, packet processing happens at wire speed simultaneously on the ports. Traffic flows directly from the port to the FPGAs, without ever touching the CPU.

cPacket’s Advanced Packet ProcessingA combination of cPacket solutions delivers high-resolution packet capture, and line-speed packet delivery: cVu, a packet broker, cStor, a packet capture appliance, and cClear, a visualization dashboard.

Through REST APIs, cVu and cStor report data back to the central command and control software. cClear exposes the analytics about the nature of microbursts on its dashboard. These include the size of the burst, what caused it, frequency and length, and so on.

Not all microbursts lead to packet loss. So cClear does not automatically create an alert every time a microburst is detected. However, it provides administrators the flexibility to configure an alert system, if they prefer it.

Both the cPacket packet broker and packet capture solutions are agentless, and can be run anywhere, no specialized software required.

The products run lossless packet capture and inspection continually in the hybrid multi-cloud. The analytics they bring home give operators a chance to inspect and identify unusual traffic patterns, and carry out speedy root cause analysis in high-frequency trading networks.

For more, be sure to check out cPacket’s presentations from the recent Networking Field Day event at the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Detecting Microbursts in High-Frequency Financial Trading Networks with cPacket

View Details

Managed services are proving their pull in IT. These services handle a range of IT processes and functions, keeping internal resources free for core processes, and budgetary expenses low.

Managed services have their roots in outsourcing. Beginning of this century, big companies started delegating off IT operations and business processes to external vendors. But the risks and cost considerations were significant.

The ascent of managed services replaced expensive outsourcing deals with easy, consumable, and precisely-calibrated services. Instantly, they became an attractive option for companies that cannot hire resources internally, or when their teams are stretched thin.

A Managed Kubernetes Service by Google CloudGoogle Cloud has a diversified portfolio when it comes to managed services. All its services are designed to take complex infrastructural tasks off of the hands of IT personnel.

The services come in various shapes and sizes, and promise big payoffs. One such solution is Google Kubernetes Engine, or GKE. GKE is a managed Kubernetes service on GCP that promises a serverless Kubernetes experience. Google Cloud describes it as the desired Kubernetes that everybody wants to have.

“I often advice people to not necessarily focus on making simple tasks simpler, but making complex tasks possible,” said William Denniss, product manager at Google Cloud, while showcasing GKE Autopilot at the Cloud Field Day event in Silicon Valley.

Kubernetes has been a disruptive technology, both in good and bad ways. On one hand, it has presented the rare opportunity to sweep away operational tasks around container management that both complex and time-consuming. On the flip side, it has architectural complexity that intimidates even the most gifted developers.

With GKE, Google Cloud lowers the learning curve, allowing teams to leverage Kubernetes with little to not expertise.

It takes full responsibility of the control plane. “You just get an API point. Google would create the worker nodes, do the upgrades, and would even automatically repair them,” said Denniss.

This model lowers the skill bar, encouraging enterprises without a big workforce to tap into Kubernetes. However, GKE by itself, is not a wholly managed solution for a couple reasons. First, it lets users have full access of the worker nodes.

That leaves a fair bit of configuration for customers to handle. “You basically have Kubernetes as an API, the cloud platform where you have to configure worker nodes, and underneath that are the actual VMs.”

Additionally, for security and associated things, he said, users have to, “at least be on some level” involved.

The nodes are on a shared responsibility model which is to say that the responsibility of protecting them falls equally on the vendor and the customer.

“The better API would actually just be the one that people came for – just the Kubernetes part without the rest of it,” he said.

Doubling Down on Serverless with AutopilotTo make it a fully hands-off operation, three years back, Google Cloud released GKE Autopilot.

Packaged as an operations mode within GKE, Autopilot is designed to shrink down the API surface to a bare minimum. This allows users to manage the underlying compute without any configuration or monitoring work.

For example, if a worker node is experiencing issues, in GKE Autopilot mode, Google Cloud is on the hook for fixing it.

Creating a cluster in Autopilot is super-simple. It involves a few easy steps – naming the cluster, picking a region, and choosing the network – and a cluster is ready to deploy within moments.

“You could literally run a Fortune 500 Black Friday ecommerce site on it now,” says Denniss.

GKE takes care of all the underlying provisioning, configuring and management of resources.

Users can entirely bypass provisioning each instance individually with the pre-defined specifications. “Autopilot takes that specification and uses that to provision the node resource.”

However, there is one caveat to note. Certain workloads are off-limits on Autopilot mode because of the deep abstraction it offers. “There are certain workloads that will not run in Autopilot mode because you are trading off that privileged access,” Denniss reminds.

Customers who prefer to customize the nodes by hand as opposed to using ready ones provided by Google Cloud, must consider using GKE without Autopilot.

Since it went public, Google Cloud has tweaked and re-tweaked GKE Autopilot to make it more open and extensible. Over the past three years, it has added partners like Data Dog and Aqua Security through certified partner programs to extend its compatibility with external solutions.

“We’re constantly trying to give you as much control as possible without compromising the whole point of the product which is managing stuff for you.”

To know more, watch Google Cloud’s presentations from the Cloud Field Day event at Techfieldday.com.


© Gestalt IT, LLC for Gestalt IT: GKE Autopilot for a Completely Hands-Free Kubernetes Experience with Google Cloud

View Details

Discussions about AI are everywhere you turn. The speed at which AI initiatives are emerging makes it difficult to distinguish genuine innovation from mere hype. At the AI Field Day event, the quest was to uncover the reality of use cases and technologies. A panel of very competent delegates posed eager questions and observations around the growing relevance of AI across industries.

The Launch of Private AI and A New Era of Innovation In the wake of its acquisition by Broadcom, VMware is undergoing significant transformations, marking a new era for the company. The VMware Private AI solution is a testament to the company’s ambitions to becoming a key player in the future landscape.

As Frederic Van Haren pointed out, VMware is moving up the food chain from a traditional technology provider to a solution provider. With the launch of the Private AI, VMware by Broadcom steps into a promising phase of innovation and growth.

Before the official rollout, VMware has already engaged 60 customers in an early adoption program, functioning as a private beta testing environment. This initiative is driven by a mix of curiosity and recognition of the need for an AI solution that values privacy and customization.

ScreenshotBenefits of Industry-Specific Private AIAt the core of industry-specific Private AI models lies a deep commitment to enhanced data privacy and security, and the ethical use of data—principles that are paramount in today’s digital landscape. VMware has proactively established an AI Council to address the evolution in AI governance.

“We’ve had governance practices that we put into place. It’s an area where we feel we’re ahead of a lot of our peers in the industry that haven’t even set up that type of governance yet. It’s a work in progress, but there’s a lot happening in this space,” shared Chris Wolf, Global Head of AI and Advanced Services, during his session.

The significant improvement in result accuracy and operational efficiency of industry-specific AI models is another step in the right direction. It makes it possible for organizations to achieve more relevant and precise outcomes by refining the models to process and analyze data pertinent exclusively to particular sectors like healthcare.

This specificity not only boosts the effectiveness of AI applications, but also simplifies the process of tuning the models to better meet the unique needs and challenges of that industry.

The customization of AI models to focus solely on industry-relevant data has the added advantage of requiring fewer computational resources. Smaller, more focused models are less demanding in terms of processing power, which translates to reduced operational costs. For businesses, this means the ability to leverage AI technologies becomes more affordable, enabling a wider adoption across sectors with varying budget constraints.

Self Service Portal for Data Scientists The foundation of VMware’s Private AI offering is VMware Cloud Foundation (VCF), a platform it runs jointly with partners like Intel. VCF is a comprehensive operating model designed to ensure that organizations can build a highly efficient and optimized environment.

Justin Murray’s presentation shed light on the transformative aspect of VMware’s approach: The self-service catalog. He describes this feature as the “Nirvana” of the solution, aimed at empowering data scientists by providing them with the easiest and quickest way to access their necessary tools and platforms.

According to Murray, the essence of this service is to strip away the common complexities that data scientists face, such as navigating through networking issues, or worrying about disk space. The goal is to place the focus squarely on enabling them to get their tools up and running with minimal friction.

ConclusionBy prioritizing privacy, customization, and ease of use, VMware’s Private AI solution is setting a new standard for enterprise AI deployments. As we look forward, the implications of these advancements extend far beyond operational efficiencies, promising a future where AI is integral to solving some of the most pressing challenges faced by industries today.

If you want to know more about VMware Private AI, watch the VMware sessions from the recent AI Field Day event. You can also learn more about VMware’s AI initiatives on their website.


© Gestalt IT, LLC for Gestalt IT: Running Enterprise Industry Specific Private AI with Intel, and VMware by Broadcom

View Details

Vendors have long promised a self-driving network that can do all the under-the-hood tuning and adjustment without human assistance. But what enterprises seem to truly want is a network that is low-tech, and low-touch, like the cloud.

Hedgehog, a networking startup, has a solution that they might be looking for.

Low-Tech Equals Low-EffortDigital environments have grown infinitely more complex, and the solutions that have landed on top of them have only made the job harder for operators.

The complexity of the tasks is on an upward climb, and in practice, the myriad principles and solutions aimed at making networking processes low-effort all feel like different paths leading to the same place – a growing operational burden.

“A lot of products in the past have tried to do intent-based networking,” said Mike Dvorkin, co-founder and CTO of Hedgehog. “Intent is amazing, but what is going on underneath is always the challenge.”

The Hedgehog Open Network Fabric sidesteps a lot of the challenges resulting from technical complexity in the hybrid and distributed cloud by making operations hands-off. This makes things a lot simpler for people with no or little networking expertise like the DevOps and SREs.

“The whole thing is designed to provide a hands-free operation. You bring it into the environment, set up your rack, press the power button on and it just comes up. This way when you’re deploying things at the edge or data edge where you cannot have a dedicated networking personnel, it works,” he explained as he and the team showcased Hedgehog Open Network Fabric to the audience at the recent Networking Field Day event in California.

Hedgehog has two clear goals in sight: to deliver a network that is nimble and responsive to the customer’s use case – be it AI, ML or data analytics – and to make networking everywhere look and feel like the public cloud.

The Hedgehog Open Network FabricThe Hedgehog Network Fabric is easy to understand and demands very low skill. It is a software-driven solution that is deployed on top of Kubernetes. Similar to public cloud, the Fabric is built on VPCs or Virtual Private Clouds. VPCs are private virtual environments hosted within public cloud that provide isolated and highly scalable computing environments to customers.

Hedgehog VPC delivers multi-tenancy in hybrid cloud. Tenants can seamlessly run their virtual networks with their unique private address namespaces.

“Those VPCs are like network containers. You build a lot of services around them. We’re peering across VPCs and to the outside and a lot of exciting stuff is coming later,” Dvorkin told.

Operators, through a multi-tenant API, can define network intent for connectivity and isolation, and count on those to get pulled into the configuration of the software appliances and switches.

“It’s super-simple to operate. People who understand networking can dive under the hood and know what’s going on with the network without having to struggle with obstructions,” he said.

Hedgehog does not put customers on a vendor lock-in when it comes to appliances. They are free to use any whitebox or graybox Broadcom-based switches, SmartNICs/DPUs and CPUs from other vendors.

The software on the switch too is not proprietary, but an open-source NOS, SONiC. SONiC comes pre-bundled with Hedgehog, but customers have the additional flexibility to choose other distributions.

The Hedgehog Fabric uses Kubernetes API to control and manage its resources.

“The way we’re treating the network because of the Kubernetes control plane, would basically turn the entire Fabric into a huge Kubernetes cluster. So every switch, every NIC or DPU, every gateway becomes part of the cluster.”

Kubernetes has a reputation of being notoriously complex. To ensure that users do not have to experience the operational complexities, Hedgehog abstracts away all management tasks.

“If you don’t want to struggle with Kubernetes and learn new things, it’s completely hidden away from you – completely self-managed.”

Hedgehog’s networking infrastructure services include zero-touch provisioning. ZTP makes deployment super-simple. Operators can design the fabric based on what they need, and following the diagram, Hedgehog bootstraps and configures the devices automatically.

“Each of the switches that we support, there is a piece of metadata that normalizes it so we can work with it.”

Dvorkin highlighted front-panel booting, a feature that lets switches to be booted on front-panel ports, eliminating the need for a separate management network. Chainbooting on Hedgehognallows operators to boot the network from the nodes that are up. Down the line, the company plans to add switch-level caching to allow nodes to be booted from neighbor nodes.

Hedgehog supports multiple topologies – collapsed core, CLOS networks and small mesh environments.

“If you have a small enough network and you don’t want to waste money on spines, but just hook things up in the mesh, you can hook up gateways to that and watch your compute gear,” he said.

Hedgehog does not rely on a separate out-of-band network. Everything is managed in-band.

“We police and control management and protocols traffic because you’re now sharing things with tenant networks. We also do full-on isolation and not just from a performance perspective, but also from security perspective.”

Going forward, Hedgehog will introduce new features and functionality making it a complete networking platform.

For more, be sure to check out Hedgehog’s presentations from the recent Networking Field Day event on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Hedgehog – A Low-Tech Network Fabric for the Hybrid and Distributed Cloud

View Details

There are many times we don’t truly realize the power technology wields in our lives. From the cars we drive, to the restaurants we frequent, technology is everywhere. Take AI for example. AI has been game-changing the last few years, transforming operations and ramping up innovation worldwide.

One company in particular, has taken AI to the next level. Nature Fresh Farms, a greenhouse farm in Ontario, is leveraging AI to produce the freshest and sweetest berries in the market.

Nature Fresh Farms scaled and transformed their operations using Intel-powered AI. At the most recent AI Field Day 4 event, they spilled the beans about their AI stack.

Bigger Undertakings for Bigger Yields Nature Fresh Farms started as a 16-acre greenhouse many years ago. It was designed with a data-forward approach using one computer. Over the course of time, the overall operations and the behind-the-scenes IT stack have expanded hand in hand.

Their goal is to grow more crops per meter square, and increase the yield year-over-year, said Keith Bradley, VP of IT and Security.

It is no secret that Intel sets the standard for distinguished computer hardware in the market. So, leveraging Intel’s solutions is a no-brainer, he said.

Starting initially with a 3-node cluster, the team soon realized that more power and efficiency would be required to get to the goal. Upgrading to the Intel Gen3 processors and adding more compute, they knew would be the differentiator, to get AI to generate better results and move on from reactive farming to getting ahead of the weather patterns.

With the stack in order, Nature Fresh Farms taps into data. The company captures data through rows of sensors planted across the greenhouse that monitor soil moisture, temperature density, CO2, vegetation growth and a range of other factors. The data is fed into the primary datacenter at the edge for processing.

The defining factor is a host of AI models, 32 till date, that is used to crunch this data and flesh out insights.

These technical changes have amounted to consistent and impressive increase in yield year-over-year. But more importantly, the ability to leverage CO2 emissions to help stimulate overall plant growth is exactly what Nature Fresh Farms needed to see continued success in their operation.

There are still ways to go as within the greenhouse, manual intervention is still key to performing many of the daily tasks. But the team is optimistic that strategic adjustments like this will get them to where they want to be.

AI for the Future and BeyondAnytime we see powerful tools like AI being used in real-life situations, it sparks excitement and optimism. If organizations can continue to build on what LLMs have started, and utilize more hyperconverged systems within the organization, the possibilities will truly be endless.

It’s little wonder that more businesses are leveraging Intel hardware regularly for these kinds of deployments. The continued growth of both Nature Fresh Farms and Intel is nothing short of spectacular. Watching Intel rise continually to the top of the game and change the way AI is deployed is all the more remarkable.

For more, be sure to check out Nature Fresh Farms’ presentation with Intel from the recent AI Field Day event.


© Gestalt IT, LLC for Gestalt IT: Nature Fresh Farms Leverages Intel and AI to Maximize Yield

View Details

People at the top assume that networking professionals working in the tiers below are fully informed about the network, and are weighing their options methodically while making decisions. This assumption is slightly off because in reality, those professionals are only working with the information available to them.

When a failure is chronic, for example, they draft reusable plans and tune the network. But there are corners they cannot see around, and in those situations, they are left to respond with logic and instinct. The problem is, logic, spread across multiple personas and roles, become varied and conflicting.

“At scale, the bottleneck for automation are humans,” remarks Eleni Palkopoulou, engineering architect at Cisco, during Tech Field Day Extra at Cisco Live US 2024.

The goal of automation is to tune up efficiency by offloading the burden from humans. But it has limited decision-making skills.

Talking about network operations lifecycle, Palkopoulou says that every process boils down to a series of decisions and subsequent actions. Automation principally targets the latter. The toolsets available to us all aim to reduce human input and autocomplete the actions. But decision-making is still a people’s burden.

Steering the Course of AutomationCisco is changing the premise by adding decision-making to the scope of automation. At Cisco Live US 2024, Cisco launched Crosswork, a network automation solution that assists with both decisions and actions.

The vision is set on strong foundations. Cisco’s long legacy lays the groundwork for it. “We’ve become the oracle of the networks,” says John Lehane, engineering product manager. “We understand exactly what’s happening on the network.”

Crosswork brings to offer a complement of tools, each designed to automate an individual process in the network operations lifecycle. Notably, Crosswork automates the steps leading up to the decision-making part so that operators can make better and faster decisions.

“What we wanted to do is automate the information-gathering which is the data part, and codify the knowledge and the reasoning as well,” says Palkopoulou.

Crosswork Makes It Better with AIAutomation is a great way to even out variability in human performance, but it is neither proactive, nor predictive. “With AI we can make this better,” she says.

AI’s human-level intelligence, logic and perfection are integral to delivering safe, reliable and consistent outcomes. Key to that is application.

“AI is a toolset and as with all toolsets, it’s very important to know what tool to use for what job. You’re not going to use a drill when you must use a hammer.”

Crosswork is powered by AI algorithms, and creative optimization techniques that are individually assigned a primary, a secondary and tertiary objective.

Central to Crosswork is the network model.

“Many people pass this by, but the network model is a very fundamental thing. It’s the foundation to any sort of predictive analysis, and your view of the world,” Palkopoulou emphasizes.

Crosswork leverages an AI-produced mathematical clone of the network. This digital twin provides visibility into all future states and predicts failures and threshold violations in advance.

The goal is to simulate what-if scenarios, she says, so that operators can see what a failure will look like and in what ways it will impact its radius, well before it happens.

Crosswork’s sim analysis tool can sequentially fail every link through every circuit mapping out the impact clearly.

“We’re doing this all in the abstract. We’re not doing it on the production network,” says Lehane.

Crosswork touches a series of use cases. In a multi-vendor, multi-domain network, it provides visualization of topology and inventory, bandwidth optimization, service provisioning, local congestion management, zero-touch onboarding and more.

AI-led designs provide at-a-glance view of the network, and color codes point to the problem parts.

Two blocks in particular dialed into focus during the session – planning and optimization.

Network planning entails inventorying assets, predicting future network behavior and planning to address any changes. Optimization is primarily keeping the KPIs tuned to make the network function better. But a large part of it is ensuring a resilient operation that enables administrators to respond quickly to fast-changing conditions.

Countless data points are required to answer the questions that pop up in the planning stage. “These are the questions that operators and planners grapple with daily,” says Lehane.

The optimal solution should provide answers to these questions, and on a daily basis, help gain network performance and improve human efficiency.

Cisco Crosswork combines low-code automation workflows, heuristics packages and an optimization engine. These provide automated network assurance, while trimming down costs through elimination of unnecessary over-provisioning.

A plethora of automation tools unlock low-touch operations for the most complex processes. These include tooling for path optimization, parameter optimization, metric optimization, capacity planning, failure analysis, demand deduction, and migration between network model instances.

Be sure to check out the Cisco Crosswork demo shown in this session at the Tech Field Day Extra at Cisco Live US 2024.


© Gestalt IT, LLC for Gestalt IT: Cisco Redefines the Scope of Automation with Crosswork Solutions

View Details

Cisco is pivoting from traditional networking towards software-defined networking, and its target market is the industrial IoT sector.

A Paradigm ShiftSince the last decade, use of IIoT in verticals like clean energy grids, smart cities, utility, road and railways, have been blowing up, attracting investments from big corporations. A lot of these companies require capabilities like auto-VPN, next-generation firewall, cellular connectivity for remote sites, and in some cases, advanced routing.

“The industrial IoT customers are not using bleeding-edge technology. For them, what is important is availability,” said Emmanuel Tychon, Sr. Technical Marketing Engineer at Cisco.

When it comes to IIoT, there are three things that make the top of the list for networking vendors – operations at scale, security and ease of use.

But customers are willing to take a chance and sacrifice their security needs, if the trade-off is availability.

“The supply chain and even manufacturing plants are ready to balance a little bit of the security to make sure that the network is running all the time,” he noted.

The capabilities of SD-WAN align well with the demands of these sectors including smaller use cases like ambulance, fire trucks and police departments.

Back in 2018, Cisco started entering the SD-WAN space by making support available on a small, regularized platform with the IR1101. As SD-WAN gained prominence, Cisco expanded support, including other models from the portfolio.

A Dissection of Software-Defined WANThree elementary units make the SD-WAN – the underlay or the hardware infrastructure that provides basic IP connectivity via virtual tunnels, Service VPN that is responsible for natural segmentation and isolation, and the overlay that brings the two components together on a single plane and route traffic automatically.

“The overlay runs in software on top of the normal router and is building a software fabric. This fabric is a bunch of IPSec tunnels running between the edge routers,” Tychon explained.

These very capabilities compliment the set of requirements common across IIoT use cases.

“What is perfect for our OT case is that we want those routers to communicate with each other or with a hub with no configuration whatsoever. Who wants to configure IPsec tunnels manually?” With SD-WAN, it happens automatically

But SD-WAN, in its current form, is not equipped to meet all requirements to a tee. At Tech Field Day Extra at Cisco Live US 2024 Cisco talked about the ways it is working to improve SD-WAN’s applicability for IIoT use cases.

An SD-WAN Tailored for IIoT Use CasesThe Cisco SD-WAN solution packs targeted capabilities designed to meet the unique requirements of industrial networks. It brings countless capabilities to one dashboard and provides simplified and centralized management of edge devices.

Tychon highlighted security policy implementation. Pushing policies to the edge devices is a protracted process.

“If you want to run a security policy across a number of edge devices, even in autonomous mode, you’ll have to configure routers manually one by one, maybe use zone-based firewall, which is good, but there’s really no way to manage that from a central place, and also, it’s only just a firewall.”

The management plane for Cisco SD-WAN is the Catalyst SD-WAN Manager, formerly vManager. It’s a highly customizable dashboard that lets you see across the network, get intelligence and insights, leverage automation, and implement security policies based on threat data.

The Catalyst SD-WAN Manager uses NETCONF/YANG to talk to the data plane. “The advantage of a YANG model is that when you tell the router a new configuration, it is smart enough to just apply the difference and change one line or one IP address between the two.”

With CLI, it’s a much more complicated process.

The next-generation firewall offers a breadth of advanced security capabilities like signature scanning, malware detection, deep packet inspection, intrusion prevention and application awareness, that traditional firewall does not cover.

The integral component delivering these capabilities is Unified Threat Defense (UTD), a feature built into Cisco’s network operating system (NOS) IOS XE. Packed as an application in the NOS, UTD automatically loads and deploys on the router. The UTD appliance scans all traffic on the router, performing repeated security checks and enforcing policies.

The AlternativeAll said and done, one can’t deny that SD-WAN is a novel paradigm that advocates a way of networking. It takes unlearning of the old ways and wisdoms, and breaking old habits to embrace it. With a “fear of change” culture dominating many organizations, this is an unsurmountable barrier for some.

“Not all customers are ready to move to SD-WAN. They’re not willing to redesign the network and would like to keep their existing configuration as much as possible,” told Tychon.

Cisco SD-Routing is a solution for those customers. A subset of SD-WAN, it is often referred to as the SD-WAN non-fabric. Unlike SD-WAN that constitutes multiple solutions, SD-Routing subsists on a single solution – the SD-WAN manager software. This provides the same operational agility and reduced OpEx for traditional routing deployments.

The only difference is the fabric and the functions that come with it. “The routers do not join the fabric.” SD-Routing runs IOS XE in autonomous mode, instead of controller mode..

Cisco SD-Routing makes a fitting solution for customers unwilling to take the leap for a few extra features, and can do without SD-WAN’s signature segmentation and auto-VPN capabilities. For them, it offers easy management, deep visibility and unified threat defense delivered in one solution.

Don’t miss Cisco’s other presentations from the Tech Field Day Extra at Cisco Live US 2024 at the Tech Field Day website. Also check out my colleague, Tom Hollingsworth’s article – The Legacy of Cisco Live – that captures the popularity and fervor of the event and the Cisco community in a short and engaging read.


© Gestalt IT, LLC for Gestalt IT: Cisco Shifts Direction with SD-WAN for Industrial IoT

View Details

“Organizations, now more than ever, are looking for diversity in terms of where they’re hosting their workloads,” noted Martez Reed, director of technical marketing at Morpheus Data, a cloud management software company, during a presentation at the Cloud Field Day event in June.

As companies look to cut costs and spend more frugally while wrestling with a growing diversity of workloads, they favor cloud platforms that would replace point solutions with broad and holistic choices.

Approximately 92% companies use a mix of public and private clouds to host workloads. Half their production workloads are divided between various public cloud platforms, and the remaining half stays in private data centers.

“In this world, [companies] are looking for a platform to help provide some sanity and rationalization across all of these different platforms in which their workloads may end up needing to run,” he said.

A Continually Expanding FootprintMorpheus Data is working on making it easier for enterprises to navigate the vagaries of this hybrid multi-cloud world. The Morpheus Platform is a hybrid cloud management solution that provides a breadth of capabilities aimed at infrastructure provisioning, cluster management, runbook automation, and cloud visibility and optimization use cases.

The platform provides extensible support for public and private cloud platforms like AWS, Azure, OCI, Nutanix, OpenStack, vSphere, and more. Out-of-the-box, it offers a complement of codeless cloud integrations, but the extensibility allows more names to be added continually.

“It provides us the ability to tap into new clouds as they come up, without having to do a lot of heavy lifting from a native integration standpoint, and allows us to work with third-party development teams, services partners and technology alliance partners to develop new plugin integrations,” told Reed.

Reed explained that the cloud plugin integrations make calls into the APIs that are exposed by the underlying technologies, right away ensuring compatibility.

Forces and Factors Effecting ChangingThe market dynamics, in the recent years, have heavily impacted customer behavior, reshaping the demand curves in multi-cloud. Many companies have reset and resized their offerings to fit the new economy.

Morpheus Data has found a way to ride the volatility by tuning the product to best address the need of the hour.

“Over the last 18 to 24 months, there’s been a number of market dynamics that have greatly impacted us, as well as the broader industry.” Reed pointed to the distinct events that have most influenced their product engineering.

Broadcom’s acquisition of VMware is one of the most consequential and publicized acquisitions of the recent times.

“What that has caused is for customers to look at options. It doesn’t mean that they are going to move off of VMware right this instance, or even anytime in the future, but they’re at the point where they’re looking for alternatives whether that be Nutanix, OpenStack, or any other solution that might be thrown into the ring.”

In the geopolitical landscape, sovereign clouds are the newest development. With rising geopolitical tensions and red tapes around data, these clouds are seeing a surge in adoption.

“Outside of North America, organizations love for their data to stay within their country and their boundaries.”

Sovereign clouds allow organizations to store data in local data centers, thereby fulfilling their digital sovereign obligations.

Another trend that is quietly taking shape in full velocity for a while is workload repatriation.

“Whether we think it’s real or not, people are seriously looking at whether it makes sense to move workloads out of the public cloud into on-prem or hosted colo environments,” Reed remarked.

This is driven by concerns like data locality, evolving cyber threats and the rising costs in public cloud.

Topping these, the overarching theme dictating the market is AI. The AI revolution has occasioned tidal shifts, bringing ashore fresh problems to solve.

“[AI] is a continually emerging use case, and in many ways, it’s creating a challenge of how we think about where workloads are deployed and how they’re deployed, particularly when you look at things like data gravity that comes with AI/ML workloads.”

A Highly Resilient ArchitectureIn addition to its broader suite of features, Morpheus also offers capabilities addressing the requirements emerging from the market shifts. The cornerstone of the Morpheus Platform is its distributed architecture which is the secret to its seamless handling of platform diversity, an ever-growing trend worrying CIOs about piling tech complexity.

The platform supports geographically distributed deployments by leveraging what is called distributed workers. These are lightweight agents that give the platform the ability to reach into diverse infrastructures, particularly on-prem and colo environments, without a VPN or direct connect. The worker to the Morpheus Platform is what MID Server is to ServiceNow, said Reed.

Using this capability, service providers and OEMs can hook into customer data centers and manage and provision workloads via Morpheus.

When it comes to AI, Morpheus Data has a distinctive approach than most vendors. “Morpheus is not an AI platform or an ML platform,” Reed stated.

However, it does have capabilities built into it that Reed said “are extremely valuable” when deploying workloads that leverage AI/ML capabilities.

For example, the platform’s ability to tie into Kubernetes, VMs and hypervisors both on premises and in the cloud opens it up to a whole ecosystem, enhancing users’ reach into a lot of solutions.

Additionally, Morpheus offers a self-service catalog that allows platform engineers, data engineers and developers to congregate in one place and build and request resources on demand.

The platform’s integrations enable easy workload orchestration via solutions like Ansible, Chef and Puppet. Teams can build repeatable templates for AI/ML workloads using these.

The plugin framework is particularly helpful for AI workloads as it lends additional extensibility to tap into AI and GPU-centric insights.

“The plug-in architecture provides the ability to extend it beyond what’s included out-of-the-box, and tap into things like IPAM, DNS, CMDB, task automation that the platform doesn’t natively support. It allows us to work with various third-party providers and other organizations,” he said.

As part of the plugin architecture, Morpheus offers a developer’s portal where documentations about plugins are viewable in a centralized location. Plugin Scaffolding and Plugin Exchange are other places where information about plugins, and existing plugins from Morpheus and other vendors can be found.

Don’t forget to watch the Morpheus Data presentations from the Cloud Field Day event to get a deep-dive and demo of the platform.


© Gestalt IT, LLC for Gestalt IT: Morpheus Data Platform – Extensible to the Specific Demands of Every Multi-Cloud Enterprise

View Details

The recent AI Field Day event focused three days on the topic everyone is contemplating – the meteoric growth of generative AI, and how it brings new challenges and opportunities for innovation to infrastructure providers.

Intel hosted an entire day of the event, and brought powerful friends with them, including Google Cloud. The audience was looking forward to hear Google Cloud’s perspective on the AI opportunity, and to say it mildly, presenters, Brandon Royal and Ameer Abbas did not disappoint.

Google Cloud’s Proven AI LeadershipGoogle is one of the foundational players in the AI arena. Their DeepMind team is behind some of the world’s most impactful innovations in the industry. Brandon describes their vision of AI as a complete platform shift for the industry, and likens this moment to the introduction of the Internet and mobile eras.

Generative AI is driving change faster than even these predecessors, powered by sweeping adoption of AI models for business transformation.

Open Software at the Heart of Google Cloud’s StrategyAs the infrastructure provider for 70% of the world’s leading generative AI organizations, Google knows something about the speed of change. It supports the AI revolution through a combination of hardware and software innovation. This starts at the heart of the software platform for which Google Cloud has released Gemma, an open source model developed by DeepMind for delivering GenAI applications.

Gemma is based on Google’s Gemini software which is their in-house stack for AI applications. It has been delivered upon the model of Kubernetes release based on Google’s Borg software. Gemma offers a 2 billion and a 7 billion parameter model with base and instruction tuned versions, and broad support across programming languages. Gemma is on the watchlist for broad adoption, given the known depth of skill of its creators.

ScreenshotGoogle Cloud Taps the Broadest Range of AI SiliconNext is the hardware infrastructure, and Google had a lot to say about platform requirements for both training and inference. Google’s AI services are built around their Kubernetes Engine, and a foundational platform for AI. This platform is quite extensive in terms of flexibility of processor choice as well as scale which they call out as being the highest performing in the industry. They offer a combination of CPUs, NVIDIA GPUs, and Google’s own TPU platforms.

Clear guidance is provided on use of CPUs for low-cost and small to medium model inference, GPUs for medium to large model inference, fine tuning, and medium to large model training, and TPUs for everything from medium model inference to large model training.

The presentation gets deeper into CPU platform capabilities and points to Intel AMX technology for providing fantastic support for applications, including natural language processing, recommendation engines, image recognition, object detection, and media and video analytics.

Intel has invested in the unique acceleration of AI models, and AMX is the latest differentiator for them.

Google is also making a major play on their own TPU technology, as one of the earliest cloud providers to invest in custom-grown silicon. Next generation cloud TPU v5p is on tap for this year with scale to 9K chips with distributed shared memory, driving support for training of the largest AI models and setting Google Cloud apart from competition.

ConclusionBased on the depth of discussion of the heritage and roadmap for TPUs, it’s obvious that Google is making a huge play in differentiated services with the delivery of TPU and Gemma, and hoping to gain market share as generative AI ignites across enterprise verticals. Google remains committed to offering customers a choice, and their CPU and GPU instances demonstrate that they will deliver to customer requirements instead of trying to force-fit everything into a TPU.

Customers are highly likely to respond well to the clear guidance on instance offerings, and hopefully a good customer uptake will follow on Gemma as a core tool in the AI toolbox. While competition from other cloud service providers will be fierce no doubt, the generative AI era will certainly aid in delivering advancements for Google’s service offerings with customers.

Check out Google Cloud’s presentation from the recent AI Field Day event to get in the weeds of their AI infrastructure and solutions.


© Gestalt IT, LLC for Gestalt IT: Google Cloud Re-Architects Infrastructure for AI Era

View Details

In the realm of artificial intelligence (AI), the spotlight often shines on cutting-edge accelerators like GPUs and specialized chips. But, amidst this fervor, a quiet revolution is unfolding within the CPU market. As AI applications grow and evolve at a rapid pace, CPUs are carving out a distinct niche for themselves in the landscape of inferencing.

Industry experts shared insights about this at the AI Field Day event in February, where Intel hosted a full day of presentation. Ro Shah, AI Product Director at Intel, presented a session on the evolving dynamics of AI inference, with a particular focus on the role of CPUs.

ScreenshotA Paradigm Shift in Deployment“When discussing AI, we often traverse the entire spectrum from data processing to model training and deployment,” said Shah. “I’d like to specifically zoom in on the inference phase, where CPUs are increasingly proving their mettle.”

Traditionally, CPUs have been synonymous with data processing tasks, while GPUs have taken the lead in AI model training. Shah’s remark highlights a paradigm shift in the deployment scenarios. Increasingly, CPUs are gaining traction in AI tasks owing to their improved versatility and efficiency gains.

Delving deeper into the nuances of AI inference, and the diverse customer usage models, Shah commented, “We observe a bifurcation in deployment scenarios that range from AI-centric applications with large cycles, to scenarios where a mix of general-purpose and AI cycles converge.”

There are clear-cut reasons for this shift. “Customers are increasingly turning to CPUs for inference due to several key factors,” Shah said. “We consistently hear that CPUs meet critical requirements, enable ease of deployment, and offer compelling total cost of ownership (TCO) benefits for a wide array of workloads, including general-purpose and AI tasks.”

Shaw presented data that shows the improvements in AI workload processing, including advancements in CPU architecture. These datapoints indicate that modern generations of CPUs can handle AI workloads with unprecedented efficiency.

CPU and Accelerator DynamicsWhile there is a growing ecosystem of accelerator alternatives targeting diverse AI applications, Shah highlighted that one must also recognize their limitations in handling extremely large language models.

He outlined the thresholds where CPUs can shine, and tasks where accelerators become indispensable. “For models below 20 billion parameters, CPUs can meet critical latency requirements, offering a compelling choice for many enterprises. Beyond this threshold, accelerators come into play, addressing the burgeoning demand for processing power,” he explained.

It’s evident from the discussion that CPUs, fueled by advancements in architecture and a growing demand for versatile computing solutions, are making a breakthrough in AI. While accelerators will no doubt continue to dominate certain niches, CPUs are poised to rake up a significant market share, bringing to the shelves a compelling alternative for a wide array of AI workloads.

Wrapping UpAccelerators hold undeniable advantages in handling colossal models and specialized tasks. The resurgence of CPUs underscores the importance of versatility and adaptability in AI deployment. As businesses navigate the complexities of AI adoption, a nuanced understanding of the strengths and limitations of both CPUs and accelerators will be the key to unlocking the true potential of AI. The secret lies in striking a balance, leveraging the strengths of what might be the most suitable hardware for the workload on hand.

For more, be sure to watch Intel’s full presentation from the AI Field Day event, and other resources on Gestalt IT.


© Gestalt IT, LLC for Gestalt IT: Unveiling the Role of CPUs in AI Inference and a Growing Trend of Accelerator Alternatives with Intel

View Details

The tech industry is enamored with the idea of productizing public cloud services and making them available for private data centers. Many vendors have toyed with the idea, but have remained largely unsuccessful in replicating cloud’s infrastructural resiliency at scale. One company has unveiled a solution that can set a course entirely on its own.

At the Cloud Field Day event in California, Oxide Computer Company gave a presentation of the Oxide Cloud Computer. This, they say, will transform on-premise data centers, once and for all.

A Trailblazing TechnologyA garage start-up story is everyone’s favorite. Numerous heavyweights in the tech industry have had humble beginnings. Their stories have inspired self-starter entrepreneurs and bootstrapped startups globally.

Founded in 2019, Oxide Computer Company is one of those Silicon Valley companies that is poised to inspire an entire generation of IT shops.

Late last year, Oxide launched its first commercial “cloud computer” designed on cloud principles. Out-of-the-box, the cloud computer provides massive hyperscale benefits to on-premise data centers.

At the presentation, Steve Tuck, co-founder and CEO, gave the audience a firsthand look at the product. It is a tall rack packed with sleds, and surprisingly no cables.

“The on-premises IT landscape today looks vastly different than what resides in the data centers of cloud hyperscalers,” Tuck stated.

The cloud hyperscalers seem to have accomplished one thing better than others. It is putting together an elastic infrastructure that can be scaled at a moment’s notice. This is in sharp contrast to the situation on premises where, to this day, set-up time is measured in months.

But the cloud retains control of what it sells you. Tuck and his partners were convinced that enterprises too can own and run an infrastructure like cloud on-premises. After delving into the hyperscalers’ playbook, they came upon a startling discovery. Many hyperscalers have redesigned their racks, and are no longer following the rack and stack style of deployment.

The rack and stack technique is just another name for kit car, only for severs, Tuck points out. A kit car has to be assembled part by part to turn it into a fully functioning vehicle. Likewise, the rack and stack method takes a piecemeal approach to deploying racks and cabinets. It is agonizingly slow, and as result, detrimental to the developers’ output.

The latency is glaring, but it only the morning mist. Tuck pointed to the heterogeneity of the ecosystem as a major stumbling block in data center operations.

“You have to pick a server vendor, a storage vendor, a networking vendor and enterprise software vendor, and some sort of software management tooling.”

In the data center, each vendor is its own island, and this divide imposes a heavy burden of overheads on the IT staff, invariably impacting developer velocity and operational efficiency.

“At every one of these boundaries, we hit inefficiencies that cost us around performance, availability and inability to debug the system. This is not how the hyperscalers do it.”

The HardwareGiant companies like Meta leverage a hardware and software co-design for their systems. Emulating the same principles, several years ago, the team at Oxide set out to build a computer from ground up that encapsulates the three core tenets of cloud computing – a rack-scale hardware software co-design, a baked-in control plane, and built-in networking and security.

This called for modification of the rack architecture. Compute sleds are constrained by the horizontal geometry. Oxide traded off the horizontal design for a vertical integration. This gave the rack a compact design, and much greater density. In the horizontal model, each sled can hold up to 64 CPU cores, totaling to 2000 cores, 1 TB of DRAM, and 30TB NVMe.

For better cooling, the Oxide computer uses 80mm fans. These fans offer better air circulation, and by tweaking the minimum speed to 2K RPM, Oxide made the racks ultra-quiet and supremely energy efficient.

“25% of the power in a standard rack in an enterprise data center goes to the cooling of the fans, the chassis and AC power supplies.”

Oxide’s rack design brings it down to 1.2%, which is a 12 times improvement from the standard. Tuck said that the power footprint of Oxide is the same as racks with half its number of CPU cores.

Power consumption is further controlled with techniques like power capping and dynamic power orchestration, thanks to its custom Power Shelf Controller (PSC). Having a proprietary remote monitoring unit (RTU) also affords Oxide the ability to capture all telemetry data on energy utilization, and analyze it through the software.

But is it truly cableless? It is not a fully no-cable rack, but through blindmating, Oxide has been able to remove the cold-aisle cabling at the front of the rack. This modular design affords operators the ease to snap in compute sleds as required, without cabling them in.

The SoftwareCentral to Oxide’s solution is its software. “A lot of what is built in here is in software. We’re doing more in software than hardware,” Tuck said.

Oxide can dropship appliances to customers overnight, but it is the software that makes them ready for immediate use.

“You can snap it into the system and the software will take care of the rest. It will do its security attestation, and make sure that it’s a known good sled.”

The software pools the capacity of the NVMe drives and serves it up as an elastic storage service that operators can provision from the integrated control plane.

Networking and security are designed in. “The thrust of this is to give developers self-service, allowing them to control their infrastructure environment so they can do their virtual firewalls, manage the virtual IPs, and be able to go at a much faster pace than they have previously had on-prem.”

The networking stack is fully programmable and leverages a P4 (programming language) compiler. It produces a latency graph for all packets, finding the lowest congestion path to send packets down.

Wrapping UpThe Oxide Cloud Computer makes using core resources surprisingly simple in on-premise data centers, if “not quite to the level of swiping a credit card and going in the cloud”. As Tuck said, it is infinitely quicker and times more convenient than setting up a stack of servers which from customers’ accounts, takes anywhere between two to three months before developers start deploying instances.

“With Oxide, you can apply network, and power, and developers are productive within hours.”

For more, be sure to check out Oxide’s presentations from the Cloud Field Day event on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Owning a Cloud Infrastructure on Premises, with Oxide

View Details

In tech, no other buzzword has caught on the way as the word “convenient”. Vendors, over decades, have deployed it to describe products and solutions, spreading its appeal far and wide across the industry.

Into that came public cloud with its white-glove service and zero-housekeeping, deepening the enticement to an irresistible degree. For the first time, users could add things on the fly on rented infrastructure without bothering with the technicalities.

Since cloud, user convenience has become an obsession and a mantra for technology vendors.

Now as corporations are plowing money into building glitzy AI data centers, the technical struggle is getting real, leaving them yearning for the same frictionless quality that is the hallmark of public cloud.

The expectation has also gone viral among organizations repatriating workloads from public cloud to private data centers. In the last three years, more than 93% companies have engaged in cloud repatriation projects, making it evident that private infrastructures are making a comeback.

The work they have on their hands is markedly inconvenient. “The workloads, the applications, the use cases we are trying to drive out of modern data centers are pushing scale to a ridiculous level,” remarks Nick Davey, director of product management, at Juniper Networks. “We see complexity and connectivity like we’ve never had to provision before in data centers.”

Cloud companies have made billions of dollars by reducing the behind-the-scenes effort of building and managing colossal infrastructures down to the click of a button. Now the question that is on everybody’s mind is – can the cloud experience be replicated over to on-prem?

Ready Templates to Build Network FabricsHistorically, networks have hand-wired by network engineers. But that process has been the source of innumerable problems. Errors and fails are rife in manual processes, besides it being a more difficult and time-consuming way of working.

Juniper Networks is working to replace the manual work with an easy, hands-off, cloud-like experience that does not get network engineers deep in the weeds of the infrastructure.

There are many great examples of products that are low-complexity and low-effort on Juniper Networks’ portfolio. The mission to make the job of building massive data center networks trivially easy, however, is a high aim. But the company has a history of amazing advances to fall back on. For example, the AI Juniper Validated Designs (AI JVD) is a great place to start for enterprises looking for a light and easy experience with planning and designing large-scale networks.

JVDs are standards-based fabric designs for data centers – pretested and validated network diagrams, configs, protocols and encapsulations – that make a quick work of deploying large data center networks. The designs tell you where a product fits, its targeted use cases, and the best practices.

“We took all of the science and all of the research that we’ve come up with in our labs, all the testing and qualification that we do around our products and our use cases, and we packed those into a set of validated designs,” Davey says.

Juniper Networks describes these as the “guide to deploy the most complex networks”.

“We included one more important thing and that’s the automation actually required to make these things spring out of the box and come to life,” said Davey.

JVDs help users take advantage of years of learned experience and put it to work. The readymade templates help bypass the usual complexities and risks of deploying network solutions at scale.

But by no means is it a one-size-fits-all solution. To make JVDs universally handy, Juniper Networks tailors the designs to a multitude of use cases, and separate them based on the network size. They call these T-shirt sizes.

“The dimensions or the physical hardware making up these AI data centers, all of that gets packed in as parameters into our automation so that you can tweak and tune your AI JVD to match your networks requirement.”

Automating the ManualApstra is Juniper Networks’ solution for multi-vendor fabric management. It is is an intent-based networking software that automates tasks from Day 0 through Day 2, making it easy to manage networks of any design and topology like cloud.

“Operators and application owners are very used to clicking a button and receiving the thing that they asked for. They don’t go into a protracted set of meetings, or open tickets. They just push a button or slide a credit card and get the thing they want.”

Apstra is developed to deliver that fuss-free click-button experience. Apstra covers all three bases of design, deployment and operations in networking. At a high level, it is the central point of control for the entire data center fabric. Think of it as having a cloud-like API to consume all physical resources in the data center, Davey says.

While designing Apstra, Juniper Networks has embedded the common principles of network engineering into the architecture. Apstra offloads all of the backend designing and planning works from the whiteboard over to a virtual instance where teams can design, tweak and pre-stage a network and get a complete preview of the model.

“Until you click “Build”, it doesn’t assume that you have hardware,” he says.

Once a mockup is approved, the team can assign physical resources to it, plugging them in one by one.

Davey highlights that the hardware could be Juniper QFX switches, or any other equipment from vendors that Juniper Networks supports.

Using zero-touch provisioning, all of the hardware are brought up into the configured fabric.

Through Day 2 and beyond, Asptra monitors and manages all assets making sure everything is tuned optimally and running in perfect condition.

“This is the day-to-day work that carries on for years on end.”

Apstra leverages a fleet of probes and monitoring tools for this. “We’ve built a set of probes and optimizations that monitor all of the various cues and flows in a network and can optionally tune that network based on its observed values.”

This is a vital function for operating and maintaining of large-scale AI networks. “In AI, the scale of deployments that we need to bring in terms of both complexity and number of fabrics, and the demands of the workloads, we don’t want to do this by hand.”

AI JVDs borrow concepts from Apstra and embed them in the reference architectures.

“It’s already baked into the blueprints. Load the JVD into Apstra and then you can start from that foundation and tweak and tune it to match what you want it to be.”

The designs work equally for all kinds of data center fabrics. “We’re pre-staging all of the configuration for a typical EVPN data center fabric, but we’re mixing in all the sugar and spice required to make it a data center that can carry AI workloads, that means all the sets of configurations that make a fabric reliable enough to run AI workloads.”

Apstra makes it really simple to visualize the network topology and get a one-glance view of all the assets. But it’s harder to effect changes in bulk.

“The ultimate consumable interface is where you can order up your infrastructure just the same way you would order any other IT service.”

To give Apstra users the same power and flexibility, Juniper Networks is building integrations with automation tools on top of it.

A Terraform provider is now available to automate and streamline provisioning. “We view Terraform as the power tool, the universal remote if you will. Its job is to let us do bulk operations at AI data center scale with the happy coincidence of meeting the expectation of our cloud users.”

This is now connected to a ServiceNow workflow. When a ServiceNow request is raised, it calls the Terraform projects that then connect to Asptra and instantiate the network type requested.

The Terraform provider for Apstra is up on GitHub. You can also scan the QR code shown in the presentation to go to the links directly.

Watch more Juniper Networks presentations from the Cloud Field Day event at the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Running Private AI Data Centers Gets Easy like the Public Cloud with Juniper Networks

View Details

The heatwave seems like it’s here to stay but that means more time to enjoy the great presentations at Networking Field Day 35. We’ve got a great lineup of presenters and delegates ready to discuss the hottest trends in the networking industry live for our community July 10 and 11. It promises to be an exciting event filled with great conversations and wonderful technical content.

Networking Field Day Presentation ScheduleWe kick off our event on Wednesday, July 10 with a first-time presenter to the event, Hedgehog. They’re showing off their exciting cloud networking solution for our delegates and fielding their questions. After that, we’re going to hear from Intel. The IPU team is ready to show us the power of accelerators and the use cases that define how they can be used to increase performance. It promises to be an exciting session. We round out the day with a fan favorite delegate roundtable discussion. This is the chance for our delegates to share their perspectives on divisive topics in the community and why you need to understand them.

Thursday morning starts up with another first-time presentation from cPacket. They’re very excited to show off their analytics solution for our delegates and get real-time feedback from the live video audience. Afterwards we are going to get an update from Arrcus. It’s been a while since we’ve heard from them and the networking landscape has changed in that time so it will be good to hear what they’ve been developing to address the needs of modern data center networking. Our final presentation at Networking Field Day will be from Selector AI. It’s been a year since we last saw them and they’re ready to wow the crowd with all the features!

Join the Conversation LiveWe will be streaming all the Networking Field Day presentations live on the Tech Field Day website as well as on the Networking Field Day event page. We will also be streaming live on our LinkedIn page in addition to our sister site Techstrong.tv. Make sure to join us on social media to make your voice heard by using the event hashtag #NFD35. And once we’ve wrapped up you can check out the on-demand recordings on the Tech Field Day Youtube channel.

Stay cool and tune in July 10-11 for the hot Field Day content!


© Gestalt IT, LLC for Gestalt IT: Summertime Fun with Networking Field Day 35

View Details

The perfect can be the enemy of the good,” said Bobby Allen, cloud therapist, while presenting Gemini Cloud Assist at the Cloud Field Day event in June.

The context was AI. Generative AI has an undeniable talent and natural ability to do things fast. That has triggered the most intense and widespread interest, enough to break the internet.

But the technology is an unlikely early winner, say experts. For all the things it can do, there are many things GenAI cannot do. But specialists and developers remain convinced of one thing. In its current state, artificial intelligence can help businesses.

That’s why Google built Gemini. Gemini was born out of a thirst to capitalize GenAI for companies that are casting about for ways to enhance productivity and profit.

Now a thriving ecosystem, the Gemini portfolio represents “Google’s most capable AI”. Google describes it as “extensible intelligence” because of its versatility to assist with a plethora of tasks.

“This extensible intelligence is going to be woven throughout the entire Google Cloud platform. So the large language model is going to supercharge everything that people are doing,” said Allen.

Naturally, Gemini comes in many flavors – Code Assist, Gemini in Security, Gemini in BigQuery, Gemini in Looker, Gemini in Database, and so on.

Allen demonstrated Gemini’s solution for application lifecycle management – Cloud Assist.

Time Is of EssenceOne of the ways Google Cloud applies Gemini’s intelligence is with a smart assistant that makes managing applications within the multi-cloud environment easy and intuitive.

The problem Cloud Assist addresses is that of employee time and training. Studies have shown that the IT staff spends longer than average time designing and deploying applications in the cloud.

An application of medium complexity takes about 600 to 1200 hours to build. Deployment adds more digits to that. Ostensibly, a sizeable chunk of those hours goes into learning things that are outside the skillsets of the engineers. Some examples are finding best practices, tracing patterns and trends, triaging issues and working out the most efficient steps to troubleshooting.

It’s a highly inefficient approach considering that these secondary tasks each take extra hours, and the individual productivity score takes a direct hit because of that.

With only a finite amount of time, attention and energy, professionals delving in things outside the main scope of work are often robbed off the opportunity of gaining genuine excellence in any particular area.

Retraining and reskilling employees is one of the most resource-intensive processes, and they aren’t always helpful, Allen highlighted. “When you took that class, you packed everything you could into your brain. But it’s going to be stale two days from now, and you’re going to be behind the curve.”

App Insights from All across Multi-CloudGemini Cloud Assist is a ready solution for engineers to use. It touches three broad use cases – app building, app optimization, and operation.

Cloud Assists picks up information from different applications and visualizes the data in one place. The UI breaks down the information and presents it under three classes – Health Insight, Upgrade Insight and Cost Insight.

“One of the biggest things we need right now because there’s so much coming at us, is efficiency,” said Allen. “We can’t afford to have the same level of technical debt and inefficiency that we had before. We don’t have time to explore.”

Cloud Assist clubs together all the information that IT personas need to accomplish their tasks, without needing any inputs from them.

Under Upgrades, Cloud Assist shows users the problem areas, and suggestions to set them right. These include contextual information on issues, troubleshooting commands, and best practices.

“Gemini is not going to take the action, but it is going to get you as close as you can to minimize time and surface,” he said.

All FinOps data is stacked under Cost Insights. Here, users can see opportunities for cost-savings, for example, clusters that are low on utilization, or those that can be put on auto-pilot, and the cost benefits that can come from taking the recommended actions.

Health Insights offer information about the conditions of all elements in the project. Users can zoom into and investigate the insights individually.

Ask Gemini a QuestionLike the insights in the console, the chatbot too is resource and contextually aware. When a user types in a prompt concerning a particular resource, Gemini’s response is based on its most current state.

Gemini can also handle open-ended questions. Its answers come, not from the Internet archives, but Google’s internal databases that include documentations, blogs, best practices, and datasets that Google priorly sourced from external locations.

Insights are open to access for all personas in the project. “We don’t have RBAC or different roles at this point, but the default is you’re only able to look at or ask questions about things that are in your project that you have access to,” said Allen.

Gemini Cloud Assist is in private review, and open to early access. Scan the QR code at the end of the presentation to sign up and get a free trial.

Be sure to watch Google Cloud’s presentations from the Cloud Field Day event for more on Gemini. Also check out the CTO Advisor review of Google Cloud Vertex AI in this video.


© Gestalt IT, LLC for Gestalt IT: AI-Powered Insights at the Fingertips with Gemini Cloud Assist

View Details

Artificial intelligence has helped large corporations mint billions of dollars of revenue. But one aspect has been overlooked until recently – failures and mistrust.

AI’s trust issues are growing at an alarming rate. Surveys indicate that many models lack the solid foundation for making accurate predictions.

But the problem is not that one model is superior than the other. It is the developers’ inability to anticipate and control how the models will and won’t work that has led to confidence gaps in the users.

Qlik took notice. Sharad Kumar, regional head of Data Integration & Quality introduced a new framework – the Qlik Trust Score for AI – at the Tech Field Day Experience at Qlik Connect 2024 aimed at improving trustworthiness in models.

Trust and Transparency in AI Starts with DataThe key to trustworthy AI is data readiness. The trusted data foundation for AI stands on three legs – AI-ready data pipelines, improved data quality and AI-augmented outcomes. Together, they provide a dependable basis for inference for the models.

Qlik utilizes traditional ML with GenAI capabilities to accelerate and automate a lot of the data engineering capabilities on its platform. So to ensure that the AI systems that underpin the solution are fair, reliable and trustworthy, it extends the Trust Score for AI feature inside Talend Cloud to build a stand-alone capability called the Qlik Trust Score for AI.

The system is aimed at measuring the trustworthiness of AI at data level. Qlik Trust Score looks at datasets and score them based on the overall data quality.

The scoring system is based on a winning set of dimensions, namely, data diversity, security, timeliness, accuracy and discoverability. The individual scores reflect the overall AI-readiness of the datasets in question.

Sharad explained that siloed data tends to produce biased results. For a model to have high trustworthiness, it must be trained on a diverse corpus. “You must make sure your data has all the different patterns and nuances that are applicable to the problem. So it has to be wide to be diverse.”

Only accurate data yields accurate results. Routinely, the data fed into the AI models has to go through quality checks for accuracy levels.

All sensitive information in the data must be surfaced from get-go, Sharad emphasized. Things like personally identifiable information (PII), financial details, and proprietary information, must be flagged and mapped to a protective tier and layered with additional security before data is shoveled into the model.

An AI-ready dataset is easily consumable by AI systems, and fully discoverable by the IT personas using it.

Data that is rich in metadata and business semantics is the best data to use, says Kumar. It is then that “business users and data scientists can find, understand and know the right context to use in the model.”

A System to Measure TrustworthinessThe Qlik Trust Score for AI is available with the new Qlik Talend Cloud. The dashboard displays the said metrics and the LLM-readiness of datasets in one view. Administrators can individually select assets like data sources, databases and table names, to see how they score in the framework.

Clicking on the metrics takes them to a detailed view of each dimension. Tim Garrod, head of Cloud Data Transformation & CDC, showed an example of the subset used to analyze data accuracy. They included semantics tagging, trust score validity, trust score completeness and duplicate count.

Trust Score for AI rates assets as high, medium or low. Anything that is marked low is accompanied by AI-generated recommendations for how to improve it.

The scores are based off of customers’ own unique environments. It is not specific to one regulatory body or geographical location, said Garrod, and as a result are very different for every environment.

A screenshot of the Qlik Trust Score for AI consoleThe framework is fully customizable and offers users complete control over what metrics to focus on. “We can extend the trust score and the framework to fit with the customers’ explicit requirements and datasets. So if you’ve a dataset in Kafka or in S3 or an API, we can plug that into whatever you need to, and then drive it into this framework,” Garrod said.

Many regulatory bodies have mandated data locality to ensure data protection. Qlik complies to geographical data clauses by having a fleet of remote engines. These engines allow users to deploy jobs locally in any region. “You can deploy as many of these engines to as many geographical places as you need,” he said.

To help organizations achieve the trust and transparency required for AI models to reach their full potential, Qlik also introduced Qlik Data Products. These are reusable data assets curated to address specific business use cases. The data products form the foundation for AI models and recommendation systems to yield reliable results.

These productized datasets are available in the Qlik data product marketplace where they can be searched and found easily. Users can request access to particular data products, ask for enhancements, build trust in them, view other users using them, and ultimately use them for their intended use cases.

For more, be sure to check out Qlik’s presentations on the Qlik Trust Score for AI from the Tech Field Day Experience at Qlik Connect 2024.


© Gestalt IT, LLC for Gestalt IT: Qlik Rolls out Trust Score for AI Aimed at Elevating Low Model Trust

View Details

AI workloads are set to put datacenter networks through the wringer. With their need for ultra-fast throughput and lossless data transfer, this new generation of workloads has caught many enterprises flat-footed. Can Ethernet pass the test?

At the Cloud Field Day event in California, Praful Lalchandani, product lead for AI Data Center at Juniper Networks, answered the question.

Myths and misconceptions about Ethernet have clouded perceptions of common users for a long time. The ascent of AI has added more insult to the injury. The misgivings deepen every day, getting between the technology and its potential takers.

Lalchandani refutes the old assumption that Ethernet cannot compete with InfiniBand in performance.

The AI Network FabricA short gist of the AI application development lifecycle will level-set the discussion.

The AI pipeline embodies a highly complex set of processes. At the beginning, data is scraped and assimilated from disparate sources. It goes through rounds of processing during which it is reformatted, broken into chunks, streamlined and made free of biases. When it’s ready to go into the AI model, the training commences.

During training, the model learns to identify patterns in the data. A cluster of GPUs work together to train a job over the course of a few hours to several weeks.

There are two types of AI training – foundational model training where a model is trained from the scratch. Some examples of foundational models are GPT-4, GPT-5, Llama 2 and Llama 3.

To train the weights and biases of an uninitialized model based on selected data, it takes tens of thousands of high-end GPUs. The process costs a scathing amount of time and money.

The other type of training, which is relatively less resource-intensive, and as a result is gaining traction among most adopters, is fine-tuning. This is where a pre-trained model is trained on task-specific datasets to perform specific tasks. It does not require large real estates of compute, but it is still GPU-dependent.

But the real action does not happen until after the training. “The rubber hits the road when the model is packaged into an application, deployed for inference, and it starts to make predictions based on new user inputs,” Lalchandani said.

Like training, inference too happens at different scales. Single-node inferencing involves using a single GPU or alternatively a CPU, and is preferred for less-demanding AI workloads. When the model is too heavy to fit into a single accelerator, multi-node inferencing is performed.

A technique often invoked to improve the quality and accuracy of inference is retrieval augmented generation or RAG. This works on small sets of supplemental data, and requires high-speed access to the storage over a fast network.

The system that powers training and inference unpins the same components – GPU clusters, a dedicated high-performance storage, and the network.

The network combines three separate fabrics – the backend high-speed GPU training network over which GPUs communicate with each other, the middle mile which connects GPUs with storage, and the frontend network that connects the system to the Internet and orchestration platforms.

The key metric for training is job completion time (JCT) and throughput for inference. For both of these, network is an essential enabler. AI workflows thrive on data parallelism. In plain speak, it is a way to perform parallel computation across several compute nodes. The progression of the nodes can be held back by delayed flows and bottlenecks.

An Ethernet Network for AI Datacenters“While GPUs are the currency for the AI revolution, building even a small cluster of just 8 to 16 nodes can lead to a CAPEX investment of 5 to 10 million dollars,” Lalchandani highlights.

Juniper Networks’ innovations around AI networking are geared at three long-term objectives – to build a network that provides unparalleled performance and unlocks the full potential of AI, is easy to operate, and has lower TCO than any proprietary technology. Their choice of network is Ethernet.

Juniper Networks takes a page out of the playbook of the largest cloud providers to make Ethernet work for AI. Recently Meta published a report about its Ethernet RoCE clusters. According to the report, the performance gained with Ethernet interconnects was equal to InfiniBand.

To test this out in practice, Juniper Networks created the AI Innovation Lab. Inside this lab, real training and inference jobs are run on GPU clusters on an Ethernet network and the time to completion is compared with InfiniBand benchmarks.

The infrastructure in use comprises 64 A100 GPUs and 32 H100 GPUs, together with a dedicated high-performance WEKA storage system and a shared storage for everything else. The backend GPU network, Lalchandani highlighted, featured a leaf and spine design that connects the A100 servers over a 200G Ethernet fabric, and the H100s over a 400G fabric.

The systems are connected via a rail-optimized topology borrowed from NVIDIA’s SuperPOD design. “The reason for this rail-optimized design,” he explained, “is to minimize the number of hops through your fabric.”

The only thing Juniper Networks has done differently is swap out InfiniBand switches for Ethernet ones.

Busting the Common MythsModels like Bert-Large, DLRM, Llama2 and GPT-3 were ran on the system, and the results were nothing short of shocking. The JCT achieved on the A100 GPUs for Bert-Large was 2.6 minutes, which according to MLCommons benchmark, is between 2.5 and 3.3 mins on InfiniBand.

For fine-tuning, it was 7.9 mins on the H100s which maybe slightly under InfiniBand, but Juniper Networks is hopeful about the numbers because the test was ran on half the number of GPUs as that of the closest InfiniBand benchmark.

Lalchandani cited an independent research conducted by ACG that shows that over a time horizon of 3 years, InfiniBand’s TCO is 122% greater than Ethernet. A big reason for that is Ethernet is open and GPU-agnostic, and InfiniBand is not.

It is believed that a lossless network is essential for the backend GPU fabric. Again Lalchandani addressed it with evidence-based argument.

“There are some scars from the HPC world where losing a packet was really bad and they have carried those scars into the AI world,” he remarks.

Turns out, packet loss in AI training does not have the same implications as in HPC.

Lalchandani explained that Ethernet does network congestion control differently than InfiniBand. It uses a combination of two techniques – Explicit Congestion Notification or ECN and Priority-based Flow Control or PFC. Together they can create a fully lossless network.

But is it an absolute necessity for AI? To find the answer to that, Juniper Networks initiated model training with either and both features turned on. In the first scenario, packet drops were noticed, and in the latter, there was none. But quite shocking, they evidenced an 8% degradation in performance in the lossless scenario.

“A job doesn’t fail. There’s some retransmissions that can happen,” he said. “Maybe in the HPC world, there was some different behavior but here our job doesn’t fail.”

Juniper AI Lab is open to all customers interested to test out their models confidentially, and for them, it serves as a design lab for architecting AI networks.

“All the best practices and learnings feed into Juniper Apstra so that users can get our learnings from the lab into designs they deploy for AI clusters.”

Wrapping UpWith Ultra Ethernet in the works, Ethernet is poised to lose its meh image, and in the not too distant future, stand shoulder to shoulder with its biggest competitor. Juniper Networks makes a strong business case for Ethernet for AI innovation. Not only is it substantially more cost-effective, and simpler to operate, but with the right network design and architecture, it can be a technology as good as InfiniBand for AI networking, if not better.

For more on this, be sure to watch Juniper Networks’ presentations from the Cloud Field Day event.


© Gestalt IT, LLC for Gestalt IT: An Ethernet Network Fabric for AI, with Juniper Networks

View Details

As workloads evolve, industries are experiencing huge surges in compute needs. Data indicates a 10x growth in computing demand in enterprises.

The most dominant workloads driving this need are those that are AI-driven like language, vision, speech and recommendation systems. Other categories include cloud-first workloads like serverless and containerized, and enterprise workloads such as SAP, VMware and Microsoft.

“The challenges that we are seeing in the field today are exemplified by what AI is bringing to the table, that is dramatic increases in the compute requirements, in order to meet customers workloads,” noted Jeff Welsch, product management leadership at Google, during a Google Cloud presentation at the Cloud Field Day event.

In the category of CPU performance, Moore’s Law is failing. The law which states that transistor density on the chip will grow at 2x rate each year is now a questionable theory as we see the graph flattening out.

“5 to 10 years ago, we could all ride Moore’s Law that transistor counts are going to double along with the performance, and price is going to drop pretty regularly. We are still seeing transistor counts double but we’re not seeing a performance impact as such.”

For all types and tiers of workloads running on GCP, Google aims to offer top-notch performance, security, cost and sustainability benefits across the board.

“We bake these into the infrastructure from ground-up,” said Welsch.

But besides the default features, customers also require a purpose-built, customized infrastructure optimized for their workloads. Welsh introduced Titanium, a platform tuned for workloads of all shapes and sizes.

Balancing Heterogenous Workload Requirements with Titanium Titanium presents a new generation of technical infrastructure on Google Cloud that is optimized for cloud.

“If you will break out of the server box, the sheet metal, where, at times, we find ourselves limited by the compute power or the I/O power. We’re trying to expand that and really disaggregate our performance capability,” Welsch stated.

Unveiled at Google Cloud Next last year, the platform underpins Google’s line of new compute instances and Hyperdisk block storage. Titanium provides compute and memory resources dynamically to enterprise workloads, meeting customers just where they are.

The secret sauce is offload processing. With the CPU juggling sundry computing, networking, storage and security tasks, workloads are left competing for resources. Titanium boasts of a new architecture that combines capabilities that are embedded in the larger Google platform, with features tailored for cloud use cases.

“Our approach is to offload within our underlying infrastructure that provides Google capabilities for all the properties.”

Titanium offload processors (TOPs) offload I/O and network processing from the host hardware and distribute them to silicon devices across the datacenter.

“Within the host, we have the standard offload capabilities. We’re going to offload your SSL encryption, the jumbo packet, segmentation, etc. But if we limit ourselves to the capacity of a smart NIC for example, there’s a set amount of finite capacity that a Smart Connect can do in terms of throughput.”

Augmenting on-host offloads, the tiered scale-out offloads take the infrastructure performance to the next level. The new tier runs outside the host CPU, adapting flexibly to the changing workload needs. Adjusting to the shifts and spikes, the system delivers the best performance required to run a workload optimally.

Titanium shows 80% performance improvement in CPUs for real-time workloads. “Because of this tiered offload, we can actually now tune not just the host, but our backend systems as well and so we’re able to deliver to our customers a 200,000 improvement in IOPS on Hyperdisk.”

Titanium leverages hardware root of trust that embeds infrastructure security in the servers. Workloads are protected by offloading security from the host.

New Virtual Machine Series Powered by TitaniumWelsch showcased the newest virtual machines for running general-purpose and specialized workloads.

“Google has a long history of hardware engineering,” he said, and the C4 and N4 VMs are its latest innovation.

The latest C4 VMs are specially optimized for high-performance, mission-critical workloads and come with a “controlled maintenance experience.” Welsh stated that C4 instances can deliver up to 25% better price-to-performance numbers compared to the previous generation.

The N4 family of VMs are optimized to support flexible workloads, and unlocks significant cost benefits through dynamic resource management capabilities.

Currently in preview and releasing later this year are Google’s Axion-based processors. Axion is Google’s Arm-based processors built to support general-purpose enterprise workloads. The new family of Arm-based C4A VMs are up to 50% more performant and 60% more energy-efficient than the comparable current-generation x86-based VMs.

Be sure to watch Google Cloud’s presentations from the Cloud Field Day event to learn about the experience GCP offers for Microsoft and VMware workloads. For more coverage on this, catch this episode of Gestalt IT Rundown where Stephen Foskett and Krista Macomber provide an overview of Google’s enterprise cloud offerings.


© Gestalt IT, LLC for Gestalt IT: Google Cloud Optimizes Compute Infrastructure for General-Purpose and Specialized Workloads with Titanium, and New VM Families

View Details

As generative AI is finding its way into the heart of every business, the store of the future looks different. AI tools are transforming industries, boosting productivity and profit at an unseen scale. But experts raise alarms about using the technology without checks and balances.

Turns out, GenAI has a dark side, and it is riddled with errors and hallucinations. Large language models tend to spew out wrong and made-up answers when a question is outside its scope of knowledge.

At Qlik Connect 2024, Qlik announced Qlik Answers, a brand-new GenAI solution that puts an end to the problem of hallucination. It’s one of Qlik’s new self-service AI solutions from the Qlik Analytics stack.

GenAI Has an Achilles HeelIt may be that we have been using the GenAI technology wrong so long. Contrary to what many believe, it is rather simple to prune the errors, and tune an LLM to give back correct answers. It just needs to be directed to good data.

“A large language model as a stand-alone piece of technology is not an enterprise-grade GenAI solution,” says Ryan Welsh, field CTO for Generative AI at Qlik, debunking the most prevalent myth.

Presenting Qlik Answers to the audience at Tech Field Day Experience at Qlik Connect 2024, he explained the other parts which make GenAI whole.

LLMs can be directed to sift through massive volumes of information and answer questions from the data. But they tend to perform at a suboptimal level when the data used for the job is low-quality and stale. They can’t help but get things wrong, and to overcorrect, they fabricate information.

“We’ve found that people typically spend about 20% of their time looking for information or answers in unstructured text data. If you actually calculate that, that’s about one day a week,” he points out.

In an enterprise scenario, that dominoes into project delays, operation slow-downs, and poor content management, among other things.

Results and Answers, Not the SameOld-fashioned search bars are still around to help find information from large datasets, but the results they pull up are generic, a far cry from the smart, targeted answers that mainstream GenAI tools whip up in seconds.

“Traditional search is broken,” Welsh says. “There is complete difference between a search result and an answer, and now everyone who has had the experience of using ChatGPT understands that.”

GenAI seizes the mantle by delivering the most eloquent phrases and informative narratives that people now have a taste. Only there are perpetual flaws in them. Some errors aren’t so obvious, as Welsh demonstrated through a sample ChatGPT response to a question that was outside its scope of knowledge.

“[It’s] completely unacceptable that you have software in an enterprise that generates 10 to 20% of answers just completely made-up.”

But wouldn’t it be much simpler if chatbots could just say “no” to questions they cannot answer?

Experiments show that when LLMs are trained to use information from trusted sources, they can answer questions with elevated degrees of accuracy.

But good data alone won’t cut it. The team at Qlik knows that to get LLMs to provide highly personalized and fully accurate responses that are cut-out for respective users, GenAI needs something more. Implementing Retrieval Augmented Generation (RAG), an NLP technique that makes relevant corpus of data accessible to LLMs, provided that missing piece.

“We believe every search bar in every enterprise is going to have RAG or an answer engine behind it at some point in the next three to five years,” Welsh predicts. “We’re seeing a massive switch from search bars that deliver a list of results that users need to click through, read, and Ctrl + F their way to the relevant portions of the text to find the answer, to just being able to ask natural language questions and get personalized and direct contextually relevant, trustworthy answers.”

Qlik Answers: Customized and Correct Answers AlwaysHead of AI practice, Kyle Jourdan, demoed Qlik Answers to the delegates. It is a simple plug-and-play solution that puts a smart, AI-augmented, knowledge assistant on top of any application. Just ask it any question from the domain-specific unstructured data it is directed to use in natural language, and within a flash, it types out a perfectly personalized answer.

“This tool lives where the people are looking for the information, whatever that might be. It’s embeddable in all different places,” Jourdan says.

For a super-smart application, Qlik Answers has a simple architecture. At one end, are enterprise connectors or data sources that it ingests data from. Users can create connections by selecting data sources, or import files directly from Qlik Catalog. The accumulated data serves as the knowledge base for the model. You can expand it by bringing in more sources and datasets as you go.

Before the data turns into insights, it is indexed in the background where datasets are broken down into chunks, embeddings are performed, and stored away in Qlik Cloud.

“All that happens in the background in a matter of a couple seconds,” he says.

At the opposite end, APIs push out results displaying them in the apps it is embedded to.

Qlik Answers’ superpower is not its 100% accuracy, but its ability to say no when required. It only works when it has contextual data to work with, Jourdan confirms.

So when a question is outside its scope of content, it plainly replies that it doesn’t have the answer.

“What we didn’t want to happen is for someone to go ask a question and get the wrong answer from the internet that is not relevant to the policies of that organization.”

Qlik Answers references all results for maximum reliability. Sources are displayed in a separate tab in the same screen.

The search history affords users granular visibility of the prompts and answers that introduces scope for improvement. A feedback system lets users leave a review of whether or not an answer was helpful.

Qlik Answers will be made available to the public July 30th onwards.

Be sure to check out Qlik’s presentations from Tech Field Day Experience at Qlik Connect 2024 to get into the weeds of its self-service AI stack.


© Gestalt IT, LLC for Gestalt IT: Qlik Answers: Swapping out Generic Results with Smart, Curated Responses

View Details

A permanent gap has existed in IT between what teams need today and what they will need down the road. FOMO and an intense pressure to futureproof has led many organizations to accrue more solutions in hopes of closing this gap. But seldom does the journey end favorably for the people involved.

There are several downsides to having too many tools in the box, notably, surging costs and complexity. The situation has left many enterprises grappling with growing technical overheads.

Extending Product Longevity through Continual EvolutionCisco is one of the few names that have the record of continually evolving their products to fit the changing requirements of users and help control product glut. The company strongly is pushing for networking solutions that are self-driven and holistic, reminding us that a great solution is one that provides value today and tomorrow.

At Tech Field Day Extra at Cisco Live US 2024, presenters, Chris Weber and Chris Pacheco announced and demoed some of the newest updates around the Cisco MX platform, that re-establish the company’s drive for simplicity and resourcefulness.

Autonomous Updates on Meraki MXThe first feature Cisco introduced is firmware-independent autonomous upgrades. Everybody can agree that firewall lifecycle management is a major inconvenience, and that is doubled by the planned downtimes they accompany. Cisco Meraki’s push-button firmware updates make things considerably simpler. But taking it a step further, Cisco is now introducing cloud-delivered firmware updates.

Pacheco explains that the MX platform’s multi-core data plane constitutes several service blocks, namely, routing, QoS, firewall, Meraki SSL Decrypt and Meraki Application Platform. Sitting on top of the last block are two cybersecurity solutions – Snort3, an IDS/IPS system, and ThousandEyes, a user experience monitoring tool.

Both the components are outside the data plane. “The reason that they are out there is so that we can update these two containers from the cloud without any need to update firmware. It’s just automatically pushed from our cloud, directly to the devices at the edge,” Pacheco says.

When the Cisco Snort team releases an update, they distribute it across the cloud platforms. Each cloud can consume the updates independently, testing it against their nodes, and eventually upgrading to the next version.

In the last 12 months, Cisco has pushed over 5 firmware upgrades autonomously without involving the customers, Pacheco informs. All of the existing 700,000 MX nodes world-wide can be upgraded to the next version of Snort within 24 hours with this new feature.

MX-OS Gets a MakeoverNext, co-presenter, Weber, gave a walk-through of a new modular architecture for the MX-OS. This architecture spans the entirety of the MX portfolio, and is designed to unify two of Cisco’s decades-old solutions – the Cisco Meraki and the Cisco Vector Packet Processing (VPP).

Cisco VPP is a software data plane known for its fast packet processing. Platforms like Webex leverages it to handle high volumes of packets and data.

“Nothing can forward packets faster than VPP on Intel servers,” says Weber.

Cisco leverages VPP for its SSE/SASE solutions, and with the new architecture, it is debuting the solution for MX firewalls at the edge.

The Meraki data plane, as noted, has blocks of features and components in the service channel along with the Meraki Application Platform. Underneath that, Cisco has introduced a new layer which is the “software ASIC” layer powered by VPP.

This is how the flow path looks in the new model. As the first packet of any flow comes up from the hardware layer, it passes through the VPP before entering the “slow path” where it moves through the different components of the service chain in the Meraki data plane. Security and routing decisions are made at every hop, and the packet is pushed down into the VPP layer. This will allow the rest of the flow to go directly to the VPP bypassing the slow path and arrive at the destination faster.

Two new products leverage this architecture – the vMX-XL for AWS and the MX650. The vMX-XL delivers 10 Gbps of IPSec performance and 10,000 tunnels on a single 8-core instance.

The MX650, a security and SD-WAN appliance, that is a top-of-the-line product in the MX portfolio, also delivers significant performance and protection throughput gains leveraging the new architecture.

“We’ve over doubled the performance on VPN throughput on this platform and we’re getting significant performance improvements on the threat protection throughput as well, all thanks to this architecture design,” Weber informs.

Unifying SOC and NOC with Meraki and XDR IntegrationThe third feature on the list is the Meraki and XDR integration which creates SNOC, a combination of NOC (Network Operations Center) and SOC (Security Operations Center).

The Meraki dashboard which features ThousandEyes and Umbrella will now include the new XDR. This will allow both security and networking teams to look at all flows from the Meraki Dashboard.

By signing into the XDR account, they can pull XDR incidents into the dashboard. “You can view them, or you can manage them,” Pacheco says.

In the traditional path, packet is received by MX, passed through traffic analysis and other features before getting transmitted to the destination. The integration allows telemetry from MX devices to be imported directly to the XDR by the way of Meraki Cloud, without using a flow collector or sensor.

All the networks send their data to the Meraki Cloud from where copies are created and sent over to the XDR data lake. The flow, as it passes through traffic analysis, is captured in the kernel and sent over to the user space. An application in the user space handles TLS and encryption.

It transmits data to the cloud every 60 seconds or less. “I say 60 seconds because if the oldest flow is 60 seconds old, we’ll send it out. But it could happen sooner when you have a lot of flows going through and you can’t send them all in one packet out to XDR. It the buffer is full, or it hit that 60 second mark, we’ll send the traffic out. From the MX, it’s a separate TLS connection going to the Meraki Cloud.”

XDR applies AI/Ml and advanced analytics to crunch through that data and detect malicious behaviors and indicators of compromise (IOC).

Following this, XDR creates an incident page that displays all the threat details.

“We’ll show the incidents in the Meraki dashboard. We’re doing that all via API. We’re not storing any XDR information in the Meraki dashboard. Any of the incidents that you actually see there is being pulled via API.”

As a result, any changes made in the Meraki dashboard gets collected and populated in the XDR incident page.

For more, be sure to check out Cisco’s presentations from the recent Tech Field Day Extra at Cisco Live US 2024 event in Vegas.


© Gestalt IT, LLC for Gestalt IT: Cisco Revamps Meraki MX Platform with New Features, and Enables SNOC with XDR Integration

View Details

Keep us with the latest from our Delegates from Aruba Atmosphere, now part of HPE Discover. You can watch the Networking Field Day Experience at Aruba Atmosphere 2024 presentations live on the Tech Field Day website and later on YouTube.

Dispelling the myth of what happens when @HPE acquires companies…#CashCow#AI ? #HPEDiscover #ArubaAtmosphere #TFDx pic.twitter.com/WIZG5CjoWZ

— Troy Martin (@troymart) June 18, 2024

. @AntonioNeri_HPE thanks #Airheads for joining #HPEDiscover for the first time. #ArubaAtmosphere pic.twitter.com/mb5TcLJU4r

— Troy Martin (@troymart) June 18, 2024

Security First
AI First (#AINative)
Customer First

I’m not sure first means, what we think it means…#TFDx #ArubaAtmosphere

— Troy Martin (@troymart) June 18, 2024

Using @HPE_Aruba_NETW , #TDBank delivers:
??Network segmentation at the edge
?? Networks that are easy to use
?? More automated management tools
?? 4 hours cutovers reduced to 40 minutes per branch site – now 30 sites completed per night.#ArubaAtmosphere #TFDx

— Troy Martin (@troymart) June 18, 2024

TDBank uses generative AI to support customer service and help customers faster with solution suggestions.

In the FUTURE it could be used with network operations and generating design documents. #TFDx #ArubaAtmosphere

— Troy Martin (@troymart) June 18, 2024

TFDx #ArubaAtmosphere Phil is talking all about #ZTNA right now, with #SWG and #CASB for #SASE. If you know, you know. If you don't, watch the @TechFieldDay sessions later today!

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

https://www.linkedin.com/posts/markhoutz_hpediscover-arubaatmosphere-tfdx-activity-7208904899286245376-oFMq/?utm_source=share&utm_medium=member_desktop

Mark Houtz

Screenshot

Wondering if the #WiFi7 access points powering #ArubaAtmosphere power down at night to conserve power and reduce burden on the environment??#TFDx #AIdriven

— Troy Martin (@troymart) June 18, 2024

At @UHouston – Staff & students wanted better #WiFi experience. Opportunistic coverage not enough, pervasive deployment needed.

Swap old vendor with a new design and massive expansion.

Result: Happy staff & students!
50K users, 160+ devices, 900 acres#TFDx #ArubaAtmosphere

— Troy Martin (@troymart) June 18, 2024

Traditional #P5G solutions have been riddled with complexity.@HPE_Aruba_NETW claims a comprehensive #WiFi and P5G solution.?

Unified management dashboard.

Bring your own #RAN #ArubaAtmosphere #TFDx

— Troy Martin (@troymart) June 18, 2024

https://www.linkedin.com/posts/shaunneal_arubaatmosphere-hpediscover-tfdx-activity-7208903255106441217-ZiXM?utm_source=share&utm_medium=member_desktop

Shaun Neal

Screenshot

ArubaAtmosphere #TXDx Aruba have put 2x more memory in 730 series access points.

— Peter Mackenzie (@MackenzieWiFi) June 18, 2024

Wifi network view from the #GeneralSession at #hpediscover #arubaatmosphere #tfdx working great for me 3 feet from the AP.. not so much for everyone else pic.twitter.com/kr56UToMjV

— Mark Houtz CWNE 5??0??0?? ? ? (@marko_with_a_k) June 18, 2024

TFDx #ArubaAtmosphere Aruba Central can put APs into a deep sleep mode that can reduce power consumption but up to 80%. That keeps them from consuming resources when they're just sitting idle.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

TFDx #ArubaAtmosphere #AI realtime comparisons of behavior to find imposters and keep them from wreaking havoc on your network from @HPE_Aruba_NETW

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

https://www.linkedin.com/posts/markhoutz_arubaatmosphere-hpediscover-activity-7208901902892171264-m1mm?utm_source=share&utm_medium=member_desktop

Mark Houtz

Screenshot

TFDx #ArubaAtmosphere The University of Houston supports research so they have to be innovative in their network to ensure their faculty and students are able to accomplish their goals.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

https://www.linkedin.com/posts/markhoutz_private5g-hpediscover-arubaatmosphere-activity-7208901191827668992-YlvR?utm_source=share&utm_medium=member_desktop

Mark Houtz

Screenshot

.@HPE_Aruba_NETW suggests #WiFi7 certified equipment is required to take advantage of AI. ?#TFDx #ArubaAtmosphere

— Troy Martin (@troymart) June 18, 2024

https://www.linkedin.com/posts/markhoutz_private5g-hpediscover-arubaatmosphere-activity-7208899693928435712-g1By?utm_source=share&utm_medium=member_desktop

Mark Houtz

Screenshot

.@HPE_Aruba_NETW suggests #WiFi7 certified equipment is required to take advantage of AI. ?#TFDx #ArubaAtmosphere

— Troy Martin (@troymart) June 18, 2024

TFDx #ArubaAtmosphere some #AI stats. pic.twitter.com/r0kndhU6wg

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

TFDx #ArubaAtmosphere Private 5G is great for large outdoor areas like ports or public spaces. And also for challenging radio environments, like factory floors.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

https://www.linkedin.com/posts/markhoutz_wifi7-activity-7208899299286347778-xvrx?utm_source=share&utm_medium=member_desktop

Mark Houtz

Screenshot

TFDx #ArubaAtmosphere Private 5G is going to live beside Wi-Fi for use cases.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

TFDx #ArubaAtmosphere The @HPE_Aruba_NETW 730 AP is tri-band, which has 30% more traffic capacity. And it has a barometric sensor for pinpoint location.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

A view of the Wi-Fi connection during the #ArubaAtmosphere keynote room…

Using an app Analiti – #TFDx #HPEDiscover pic.twitter.com/qaMkpbHXwA

— Keith R. Parsons (@KeithRParsons) June 18, 2024

TFDx #ArubaAtmosphere Aruba Central can detect strange behaviors from IoT devices and ensure they are doing what they're supposed to do and not acting as entry points into your network.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

TFDx #ArubaAtmosphere Camera, edge sensor, and motion detectors are just some of the new IoT devices that @HPE_Aruba_NETW can connect.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

And now for the General Session! #TFDX #ArubaAtmosphere pic.twitter.com/hn0A3w8eOH

— Jennifer Huber (@JenniferLucille) June 18, 2024

TFDx #ArubaAtmosphere The future of farming is analyzing individual nutrition needs and growing what we need to survive and thrive.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

.@HPE_Aruba_NETW – Delivering security first, AI-driven solutions today.

Also investing $14B in AI acquisitions. Hoping to start integration late 2024/early 2025.#AIPowered#ArubaAtmosphere#TFDx

— Troy Martin (@troymart) June 18, 2024

.@HPE_Aruba_NETW – Delivering security first, AI-driven solutions today.

Also investing $14B in AI acquisitions. Hoping to start integration late 2024/early 2025.#AIPowered#ArubaAtmosphere#TFDx

— Troy Martin (@troymart) June 18, 2024

Phill Mottram kick stating the general session at #ArubaAtmosphere talking about the benefits of the @JuniperNetworks acquisition. #TFDx pic.twitter.com/i2KnKWMGbX

— Peter Mackenzie (@MackenzieWiFi) June 18, 2024

TFDx #ArubaAtmosphere Why is it so important to connect rural areas? 1% of the world's population feeds the rest of us. If they can thrive we can end worries about food security.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

TFDx #ArubaAtmosphere Edge computing? How about managing thousands of cows with sensors to ensure the quality of their milk and the health of the animal.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

HPE Aruba Networking is adding Juniper/Mist to their portfolio so they can move forward with even more go to market capabilities. #TFDx #ArubaAtmosphere #HPEDiscover pic.twitter.com/puSt5ZE8dD

— Keith R. Parsons (@KeithRParsons) June 18, 2024

And now for the General Session! #TFDX #ArubaAtmosphere pic.twitter.com/hn0A3w8eOH

— Jennifer Huber (@JenniferLucille) June 18, 2024

TFDx #ArubaAtmosphere Phil welcomes Teddy Bekele, the CTO of Land O'Lakes to talk about how they're using @HPE_Aruba_NETW technology in their #agriculture business.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

.@PMottramAruba explains the impact of COVID and edge networking on his life. When COVID started Phil:
1.Stopped going into office
2.Wife stopped being happy
3.She stopped being wife

Hoping networking side has a better outcome….#ArubaAtmosphere #TFDx

— Troy Martin (@troymart) June 18, 2024

TFDx #ArubaAtmosphere Phil welcomes Teddy Bekele, the CTO of Land O'Lakes to talk about how they're using @HPE_Aruba_NETW technology in their #agriculture business.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

Kicking off the General session for Edge and Networking at #ArubaAtmoshpere is @PMottramAruba #TFDx

…starting off to list what hasn’t changed…#Airheads

— Troy Martin (@troymart) June 18, 2024

TFDx #ArubaAtmosphere Networking for AI means Ubiquitous Coverage and Low Latency.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024

https://www.linkedin.com/posts/markhoutz_hpediscover-arubaatmosphere-activity-7208895434109382658-JOzG?utm_source=share&utm_medium=member_desktop

Mark Houtz

Screenshot

Phill Mottram – EVP/GM HPE Aruba Networking. –#HPEDiscover #TFDx #ArubaAtmosphere kicking off the Aruba General Session. pic.twitter.com/7Gx3Gm6DDC

— Keith R. Parsons (@KeithRParsons) June 18, 2024

TFDx #ArubaAtmosphere There are over 200,000 #Airheads and more than 2,000 at #HPEDiscover.

— Tom Hollingsworth (@NetworkingNerd) June 18, 2024


You can watch the Networking Field Day Experience at Aruba Atmosphere 2024 presentations live on the Tech Field Day website and later on YouTube.


© Gestalt IT, LLC for Gestalt IT: Aruba Atmosphere 2024 Live Blog from HPE Discover

View Details

Network blackouts are eating away at business turnovers. Worldwide reports of service outages indicate that of the 100 outages that occur yearly, 20 are high-profile ones that cause complete shutdowns, while smaller incidents create short-lived service disruptions for users.

In either cases, every minute of downtime translates to reduced user experience and revenue loss for businesses, because when a service goes down, the impact is widespread.

A New Era of NetworkingPlaces of work have moved outside the familiar confines of offices, while businesses have penetrated overseas markets by means of digitization. The expectation of anytime, anywhere access grows stronger every year among users and employees alike.

Ideally, every user and site should have a dedicated service desk to call for tech support, but that’s an unsolved problem right now. The closest thing available to enterprises is an out-of-band network or OOB network. This gives network administrators remote management capabilities over an alternate network through outages and disruptions.

Opengear, a leading name in remote access and infrastructure management, recently rolled out some cool new features for its out-of-band solution which takes OOB management to the next level. At Tech Field Day Extra at Cisco Live US 2024, sr. manager of product and strategy, Jeff Blyther, showcased the new releases, followed by a live demo given by co-presenter, Daniel Cecalacean.

In business for over two decades, Opengear is an out-of-band management company. Its specialty is OOB solutions that allow network professionals to oversee network health efficiently and deploy, manage and remediate resources from anywhere.

“Our claim to fame,” said Blyther, “is failover to cellular. Even if the whole network should go down, we still can get you in over cellular and allow you to connect to any device on that network.”

Failover to Cellular (F2C) provides connectivity through high-speed 4G and 3G networks during primary link outage. This works like a secondary network that administrators can log into to access devices and bring them back up and running.

Out-of-Band Management with OpengearOpengear OOBM primarily constitutes two building blocks – network appliances, and a management portal called Lighthouse. Opengear describes the Lighthouse software as “the linchpin of the entire solution”.

Opengear positions the OOBM solution as an operators’ companion for the first day, worst day, and every day. But as customers’ needs are slowly shifting, they are now hungering for a true management network that can get them access to everything – not just console ports, but IP addresses, and management portals too.

This presented the opportunity to up-level Lighthouse and give momentum to long-term goals. The vision with Lighthouse is to make it a solution that requires the bare minimum human intervention, Blyther shared. On Day 0, it should get new networks up and running automatically, and in the subsequent days, be the single source of truth for all connected resources.

New EnhancementsIn 2023, Opengear announced a new and upcoming solution which at the time was named Remote Management Fabric. The Opengear team built it up from proof-of-concept to a real-life solution.

In February, the company unveiled Smart Management Fabric (SMF), a unified management framework that caters to personas like network engineers, system administrators and support staff.

“The idea is to stitch together all infrastructure equipment, all your teams and their tools to get access to anything anytime in a management network scenario,” said Blyther.

The framework provides access to any IP-based resources, physical or virtual, and allows provisioning, monitoring and management of IP endpoints through automation tools. “This will allow you access from one network to the other to another through the Opengear fabric.”

Resources must be provisioned behind remote Opengear appliances through a provisioning tool. That template will ensure that the node is a part of the SMF network.

“We provide a wide-open pipe all the way across to your network for whatever you want to do – joining it to IP addresses, pushing down firmware, and configurations – we’ve got that whole fabric open for you now,” he said.

Communication between Opengear nodes and the Lighthouse is secured by an open VPN tunnel. The tunnel is doubly secured with a WireGuard tunnel through which all SMF and OSPF traffic is routed.

A second feature added to the Lighthouse is Connected Resource Gateway or CRG. CRG allows clientless access to any IP address or GUI on the other side of the Opengear device. This simplifies access and management of resources while enhancing security through role-based access control (RBAC) permissions and tags.

So far, assets were deployed on to Lighthouse using Opengear’s low-touch enrollment solution that consisted of an USB stick and an LH script. A new portal called the Lighthouse Service Portal or LSP makes enrollment a zero-touch affair.

Usually used in conjunction with Lighthouse, LSP is a cloud-based SaaS solution that automatically discovers and inventories assets, and acts as the single source of truth in the network.

Every customer is given an LSP account through which they can view and deploy assets instantly into Lighthouse.

“You could buy 5 assets or 500. They’ll all be in there. You can create a bundle and that information will get sent down to the Opengear devices through an X.509 certification. The Opengear device then has everything it needs to enroll itself into the customer’s Lighthouse Portal.” explained Blyther.

Blyther gave a high-level overview of how things happen behind the scenes. First, Opengear appliances call home to the Lighthouse Service Portal and enroll themselves. During enrollment, the SMF template is pushed down to the appliance. This brings up the fabric creating a direct connection between two separate networks. Communication with devices on the other network is thus enabled.

To learn more, be sure to catch the demo in the second half of the Opengear session from the Tech Field Day Extra at Cisco Live US 2024 event.


© Gestalt IT, LLC for Gestalt IT: Opengear Issues Critical Updates for Its Out-of-Band Management Solution

View Details

We’re very excited to be back in Las Vegas for Networking Field Day Exclusive at HPE Discover! While this is the first time we’ve done an event at HPE Discover it’s not the first time we’ve worked with their team. That’s because we’re focusing on the big news from HPE Aruba Networking as their former Atmosphere conference is now a learning track during Discover. We’re thrilled to see what they’ve been working on and share all the details with you.

Networking Field Day Exclusive ScheduleWe’re going to have a packed day on June 18th. We start off with the keynote from Antonio Neri in The Sphere. We’re getting a lot of updates and announcements and a special guest, Jensen Huang of NVIDIA! I’m sure it’s going to be a delightful discussion that everyone will be talking about. After the keynote we’re headed over to talk about the Future of Networking with Phil Mottram, Executive Vice President and GM of the HPE Intelligent Edge business, which includes HPE Aruba Networking. Our delegates will be live blogging the session so make sure you’re following our media to learn more.

After lunch, we’re kicking off three great sessions with HPE Aruba Networking. We’re going to get discussions around SASE and SD-WAN, Wi-Fi 7 and Private 5G, and Aruba Central. We’ve got three hour-long sessions packed with content and great presenters that you’re not going to want to miss.

We’re also going to be recording an on-site roundtable that we’ll be publishing after the event. It’s a chance for us to talk about all the cool things that we’ve seen and discuss the future direction of HPE Aruba Networking as they continue to power the innovation in the HPE Intelligent Edge business.

Follow Along LiveWe will be streaming our presentations live on June 18th at TechFieldDay.com as well as the Networking Field Day Exclusive event page. You can participate in the fun by jumping on social media and using the hashtags #TFDx for our sessions and #ArubaAtmosphere for the whole conference. That way we know that you’re excited about the big HPE Aruba Networking content and can’t wait to see more. You can also catch our recordings on the Tech Field Day Youtube channel.

We hope to see you online for HPE Discover!


© Gestalt IT, LLC for Gestalt IT: Discovering New Things at Networking Field Day Exclusive

View Details

Since the early days of cloud migration, the fear of legacy applications going obsolete has plagued business leaders. Their distress deepens as cloud-native applications rapidly populate the stack intensifying the pressure to modernize their older counterparts. Some companies are going for wholesale modernization, and some, squeezed by runaway costs, are getting creative.

Paul Nashawaty, practice lead at The Futurum Group, and the delegate panel at the AppDev Field Day event explore why, in order to gain the most return on investment, enterprises should focus on the reasons to do it, than getting obsessed with the hype. The conversation describes how they can enact the change that most benefits the business and its people in a way that actually works.

Something More ModernThe concept of app modernization is often misconstrued and viewed as the goal rather than a means to an end. Like all transitions, application modernization comes with both opportunities and challenges that organizations cannot absorb or overcome frictionlessly.

Questioning whether the effort will actually benefit the business is an essential first step.

“It’s never just a technical decision,” says Mitch Ashley, Techstrong Research analyst. “There’s a reason behind what you are modernizing and why, and what you want to get out of it, rather than just refreshing technology. Oftentimes a lot of those things live forever. We don’t always get away from them.”

Undoubtedly, there is benefit in repatriating some legacy applications to the cloud. But trying to do so for every old application in the stack can inadvertently hurt the business. “Part of the challenge is you never have enough time or money to rebuild it all,” he continues. “One of the strategies is identifying what part of the app could really benefit the most from the flexibility and adaptability of the cloud.”

A Thorny ProblemThere are several hurdles to software modernization at enterprise scale. Rebuilding is a messy process riddled with hiccups. The turnaround is slow and, and it frequently spirals into a horror show.

Deciding what needs to be refactored is another worry. It’s not a walk in the park when you have tons of old-fashioned applications, and they are all working as expected.

Demonstrating the value in refactoring is essential to optimizing investment. The argument most leaders put forward is that there’s a technical debt attached to legacy applications.

Calvin Hendryx-Parker, co-founder and CTO of Six Feet Up, agrees. There are two drivers that propel the decision of refactoring, he says. Tech debt, and user/developer experience.

“End users have higher expectations for usability inside of these applications because of what they experience on their own devices. They want the same level of interactivity,” he says. “From developers’ standpoint, those who know about heritage apps are going to become scarce eventually, and it’d be difficult to entice new developers to come and work on these old applications.”

There is no straightforward way of quantifying the losses from either of the scenarios. “It is hard to put a cost around it other than you’re going to lose talent and users, and ultimately, your edge,” he adds.

Not All Legacy Applications Are Made EqualAccording to a Futurum Group research, 67% enterprises believe that app portability is vital. Cloud is the new paradigm, and with edge emerging as the next stop, portability is imperative to application longevity.

But not all legacy applications need to be refreshed from ground up. Sometimes, getting them to a cloud-ready state is enough to repatriate them. engineer and content creator, Michael Levan, insists that enterprises should base their decision on the choice of destination.

“If you want to decouple applications, turn them into microservices, containerize them, your application stack needs to have the ability to do that. Some application stacks simply don’t because it’s how the code is written. A lot of Windows-based containers are for legacy-based applications, for example. So if you don’t have a destination to run your current stack on, you have to refactor if there’s some type of need for it. You have to either figure out a destination where it’ll work, or have to do some type of refactoring.”

Although in many scenarios, refactoring is the ideal thing to do before plucking an application from on-premises and catapulting it into the cloud and beyond, and companies would be all for it if money was free, the reality is a bit different, says Kati Lehmuskoski, entrepreneur and author.

“In reality, what is happening at companies is that there are these apps that provide competitive edge, like a customer portal. Those get refactored first. And then there are applications that are working fairly well for companies and there’s no mandatory need to replace them until the technology gets very very old, and they become a security question.”

There is also a heavy cost burden to it. “When you look at individual applications that organizations own, it gets cost-prohibitive and time-intensive to really refactor for altruistic reason,” points out Josh Atwell, IT veteran turned developer relations leader. “Today’s innovations are tomorrow’s technical debt. So, it’s really hard to get ahead of that wave and actually get an application, especially a meaningful one, refactored and modernized.”

But that is not to say that organizations are not looking at application modernization as a realistic and workable goal. A small number of businesses have gone through with it with relative success.

“The organizations that have looked at applications and done refactoring in a meaningful and complete way are those who have repeated services and multiple applications that they need to simplify into shared services – extract them from large applications and create shared services for things like payment processing, inventory, customer loyalty programs, etc.”

In the end, it should create value, or none of it is tenable. Alan Shimel, founder and CEO of Techstrong Group says, “Without a compelling economic ROI that is business talk at the C-level or board-level, you are not going to be able to push through a large-scale app modernization because it’s cool. It’s dollars and cents today, and it’s got to make business sense.”

Modernizing at scale is unnecessary when old applications are working well. “A constant effort to simplify prevents the mounting of the complication and that’s where companies are at. Each one of these new waves demands a new style and approach and a new set of applications and capabilities, but it doesn’t get rid of the old immediately,” says Guy Currier, chief technology officer.

Innovation Vs OperationThe age-old contention between innovation and upkeep casts a long shadow on organizations’ modernization efforts. Nashawaty pointed to another Futurum research that indicates that developers spend more time maintaining the applications than they do innovating, and given a choice, they’d like to invest more time in the latter.

“AppDev and apps don’t exist in a vacuum, but to support the goals of the business,” Jack Poller, cybersecurity industry analyst, comments. “When we go to refactor applications, there has to be a clear understanding of what it is and how it will support the business,” he insists.

After cost and complexity, cybersecurity is the next big concern. Typically, monolithic applications have a wider attack surface that makes them ripe for cyberattacks. Refactoring often slims down the surface, making the applications inherently more secure.

Alan Shimel speaking at the AppDev Field Day roundtableBut Shimel predicts that security is not going to be the driving force. “Security does not come until customers demand it. So, for a lot of this stuff, security is playing catch-up and is bolted on. When we first started moving stuff to the cloud, we called it cloud washing. All too often that’s what happens,” he comments.

For really old technologies, the primary concerns are security vulnerabilities and end-of-life components. Hendryx-Parker insists that vendors should tighten their belt and be clear out the gate about the implications of using such technology.

“Vendors have to be willing to say the hard thing to buyers that they need to update and refactor and stay patched, or the seller is not going to be responsible for what happens because of their poor decisions.”

Wrapping UpKeeping a fleet of old-fashioned apps that are a burden to maintain translates to unhappy stakeholders and snowballing technical debt. The opposite scenario is a full and complete overhaul that costs a fortune, has major technical challenges, and does not necessarily yield the expected value. The answer that enterprises are looking for is in the middle. Being guided by facts and goals, rather than by the impulse to chase a fleeting trend, application modernization can be the change that solves a lot of enterprises’ problems and produce happy users and employees. But a measured and calculated approach is a must to reach that destination.

Be sure to listen to the entire conversation from AppDev Field Day on the Tech Field Day website. Also check out Alan Shimel’s article on AppDev Field Day presentations, and Paul Nashawaty’s coverage of the Google Cloud session.


© Gestalt IT, LLC for Gestalt IT: App Modernization, a Measured Exercise or a No-Brainer?

View Details

In commerce, digital experience is synonymous with brand experience. Whether a company is selling cars, coffee, or candy, providing a positive customer experience is a non-negotiable part of the deal.

Faced with non-stop competition, enterprises across sectors are trying hand over fist to create the most personalized experiences for their end users. But their good intent is challenged by an obstacle course of unpredictable factors.

In the digital realm, anything can reduce the quality of user experience and precipitate revenue loss. A second’s delay in loading, for example, can drive potential customers away from a website. Or a slow-functioning checkout navigation can give buyers reason to abandon their shopping cart before completing purchase.

“Slow is the new down,” Brandon DeLap, Sr. Solutions Engineer at Catchpoint Systems, comments during a session at the AppDev Field Day event in Silicon Valley. “People don’t necessarily complain on Twitter about a complete DNS failure page, but they do complain if a page is taking 20 to 30 seconds to load, or log in”.

The Inside ViewModern digital environments are a wilderness of vendors, applications, services, and devices. Across the service delivery path, these components cross paths and share touch points.

“Stack applications rely on several different layers and services within those layers,” DeLap says.

In the same breadth, the dependencies make the applications more efficient and secure, as well as unpredictable. While a company’s own applications are its own responsibility, the performance and behavior of third-party apps are not.

“Unfortunately, users don’t know that you don’t have control over those, and it’s very important to be able to have an at-a-glance view into any of those providers at any given moment causing an issue to the end user experience,” he emphasizes.

Internet Performance Monitoring with CatchpointA leading monitoring solutions provider, Catchpoint has developed a solution that can curve the most efficient and least painful path to a richer user experience.

At the recent AppDev Field Day event, the company introduced Catchpoint Internet Performance Monitoring (IPM), a holistic platform to measure and monitor the experiences of not just customers, but also the workforce around the world.

Catchpoint IPM is designed to provide observability leaders a complete picture of the states and health of services across the Internet in a glimpse. The idea is that they have a ready auto-discovered list of issues, the moment they pop up.

DeLap described what the day in the life of a DevOps manager looks like when using Catchpoint IPM.

IPM welcomes all administrators with a default live view of all digital services in the Internet stack, and their current health. These include dependencies, Internet sonar, issues and their severity levels, and alerts.

The IPM platform leverages a spectrum of monitoring and visibility products off of the Catchpoint portfolio to provide this detailed view. These include Internet Synthetic Monitoring, Real User Monitoring (RUM), Internet Sonar, BGP Monitoring, Endpoint Monitoring, WebPageTest and Tracing. This allows it to show simulated feeds, as well as gather actual experiences in terms of service reachability, website speed, and so on, as users are experiencing them.

Internet Sonar is a global heatmap of all third-party services in the stack. When teams are faced with experience-impacting issues, the Internet Sonar serves by providing a deeper look at them.

A heatmap displays the regions of outage in real-time. Catchpoint’s Global Observability Network provides data for this. With data collected from 2600 nodes from 300 providers across 80 countries, it brings back live information and ready analytics. Administrators can selectively pick areas of internet from an adjustable outage timeline to drill down on particular providers or services.

“We include status page updates if the vendor posts it – you’ll see that alongside our telemetry – to let you know that the vendors are working on the problem and potentially, you don’t need to reach out and bug them because they already know about it,” says DeLap.

To provide status updates on users in real-time, IPM has a global heatmap of all users interacting with the sites. “This is a JavaScript tag on your site. It’s loaded asynchronous, so it’s not impacting the actual load time of your site which is extremely important,” he emphasizes.

RUM measures experiences through real-world metrics captured from browsers and devices of users in different geographies. Their states are marked in green and red for easy viewing. Business indicators like page views, conversions and bounces can also be viewed and tallied over time, from this view.

Troubleshooting begins by drilling into BGP routing issues and running DNS tests for reachability. IPM offers a smartboard that provides a converged, AI-powered visualization of the web layer, network layer and BGP layer, for a quick sift-through.

“You don’t have to click through multiple dashboards,” highlights DeLap.

Out-of-the-box, IPM offers 40 synthetic test and monitor types that include API, DNS, Traceroute, BGP, etc. – and unlimited bring-your-own options.

“That may seem a lot, but synthetic monitoring is not just a simple ping or a web check,” he points out. “It’s much more. There are a lot of different protocols that you must test individually from the entire picture or that end user experience, so that you can detect quicker and quicker. The dedicated monitor would alert and notify you of the issues so that you don’t have to go and bug other teams.”

Tracing is helpful to verify issues. “With our Tracing feature, through OpenTelemetry, you can click into a view similar where we’re actually tracing every individual call from the application perspective – database calls, web service calls – and we are able to let you know exactly what happened in that instance or in those synthetic events.”

With IPM providing a one-dashboard view of all elements, dependencies and issues, the entire operation takes less than 5 minutes.

Using these inputs, the front-end development team can then leverage WebPageTest, an open-source product and part of the Catchpoint dashboard since last week, to run tests and find areas to improve and optimize.

Wrapping UpWhen administrators wake up to inboxes filled to the brim with alerts from monitoring solutions, it hardly prompts immediate action. Not all of that information is valuable, and without a streamlined view, it is a hunting and pecking game. A platform like Catchpoint’s cuts the clutter, offering pinpointed inputs with granular details. The information is well-targeted, fleshed out and plainly visualized for easy and quick consumption. The deep visibility enables operators to deploy quick fixes to existing problems, and watch over and enhance every customer’s experience across every interaction, around the clock. In the long run, that translates to personalized user experiences for all, and uplifted ROI for the business.

Check out Catchpoint’s sessions from the AppDev Field Day for more on this. For more interesting reads, check out Sam Holschuh, Alan Shimel and Paul Nashawaty’s stories on Catchpoint.


© Gestalt IT, LLC for Gestalt IT: Incident Analysis Under Minutes, with Catchpoint Internet Performance Monitoring

View Details

A new category of AI apps is relieving the burden of grunt work at workplaces. We know them as AI assistants. The ones that are high in sophistication can provide helpful answers to questions in real-time and handle a pile of tasks on behalf of employees.

Juniper Networks’ Marvis is one such smart assistant. It is intelligent and efficient, and over time, has become a trusted tool for experiential optimization.

Ensuring Top-Notch Experience at Both Operator and User EndsMarvis is baked into Juniper Networks’ AI-Native Networking Platform. It combines artificial intelligence and automation to help network engineers manage operational tasks and boost user experience. Its immediate focus is to reduce the busywork and give operators some breathing room in their schedule.

Through the years, Marvis has accumulated many new features which have made it a great tool to measure user experiences and reduce trouble tickets. At the recent Mobility Field Day event, Bob Friday, chief AI officer, announced the newest updates for Marvis that besides tuning up its efficiency, also provide experience assurance for end users.

“Marvis is our crown jewel,” says Sudheer Matta, GVP of product management. Juniper Networks dedicates a lot of resources to augment its capabilities to further the vision of a self-driving network.

“The reason why we started Juniper Networks with access points is because we wanted to make sure that we are going to get the data we needed to answer the question of why you’re having a bad mobile experience,” says Friday.

Marvis is anchored across APs, switch and SD-WAN to deliver on this. It enables Marvis to scrape more data closer to the device used – user state, Layer 3, application data – and hammer out granular insights around root causes.

Extending Marvis to WAN routers introduces more WAN features into Marvis. “When you look at what’s going on in your network, it’s usually not the wireless problem. The other big airfare is the WAN connectivity. When something goes wrong, half the time it’s somewhere in that WAN router in the mobile operator network that’s connecting you to the internet.”

Digital Experience Twin, a New Integration, and More UpdatesA couple of recent updates that have made Marvis even sharper and more efficient are Zoom integration and Marvis Minis.

Information about things like packet loss, latency and service jitters are critical to ensuring uninterrupted experience on video conferencing apps. Integrating Zoom with Juniper Mist opened doors to collect these information from Zoom cloud and learn about call drops and audio/video degradations in real-time. Marvis uses the corelated data from Mist to drill into the causes of interference and provide real-time answers.

“Wireless has gone from nice-to-have to business-critical, and customers want to make sure whatever critical apps they put on the network – whether it’s a consumer app or a robot – that that is going to have a great experience. We need to really start focusing on why users are having a bad experience,” reminds Friday.

Marvis Minis is a digital twinning technology for wireless experience which launched earlier this year. Aimed to make Marvis even more proactive, Minis simulates user connections via unsupervised machine learning. This allows operators to learn about problematic network config changes that can negatively impact user experience, drill into context and identify the scope of issues, all ahead of time. Minis proactively highlights interferences and failures, and resolves them, overall reducing the number of tickets.

A data science team continuously oversees Marvis’ responses and works on the complex questions that are outside its current scope. “We review these with the data science and support team once a quarter, we go through a list of all the questions we can’t answer, and then we make pie charts of why we can’t answer them. What you quickly find out is we’re getting to the bottom of the barrel,” Friday informs.

Wi-Fi troubleshooting is now made easier with AI-Native Dynamic Spectrum Capture. This new feature provides enhanced visibility into RF spectrum helping trace the roots of wireless network interference accurately. This allows for speedy remote troubleshooting reducing the number of site visits.

In the upcoming update, Marvis Minis will be extended to wired connections. This will allow it to proactively identify switch authentication issues and generate prescriptive workflows to correct them before they affect user experience.

Marvis VNA is also available for the datacenter now. It provides proactive alerts and prescriptive actions working with Juniper Apstra, an intent-based networking software, to help operators stay on top of all issues. Additionally, through its conversational interface, operators can make queries in natural language in real time.

“This is really furthering the branch and datacenter better together story. This is for business-critical apps like point of sale, that you have running in your branch. When they go down, you need to immediately identify what layer of the network is causing the problem,” he says.

Marvis Application Experience Insights provides a deep dive into Zoom and Teams user experiences. Marvis leverages continuous learning and the Shapley data science model to learn from data across billions of user experience minutes. This enables Marvis to pin-pointedly predict issues in call quality during meetings.

Watch the complete Juniper Networks presentation from the Mobility Field Day event for a live demo of all the capabilities. Also check out Ron Westfall’s roundup of the Marvis updates in his article – “MFD11: Juniper Choreographs AI-Native Networking Breakthroughs” – at The Futurum Group website.


© Gestalt IT, LLC for Gestalt IT: Juniper Networks Rolls out Important Updates for Marvis

View Details

The digital world used to be a keyless black box for most of the world. Data cracked it open, ushering in a kind of transparency that broke precedent. Suddenly opportunities, previously dismissed as ludicrous, were on the horizon.

Modern businesses are obsessed with data because they see opportunity knocking. As AI algorithms penetrate aspects of society, the possibilities have quadrupled.

Today data can tell you the location of a place down to the precise coordinate. It can inform you about events that haven’t happened yet. It can alert you about fraudulent activities happening on an online account while you are away. And the expectations grow every day.

But data also costs money. The banal tools of yesterday are redundant for threshing intelligence from data. It takes expensive third-party services to convert raw information into insights.

Mezmo, a fast-growing Silicon Valley startup, is enabling enterprises to collect and analyze their data within their own walls. At the recent AppDev Field Day event in California, CEO, Tucker Callaway, demoed the solution to the audience.

The Mezmo observability platform centralizes telemetry data from other observability platforms, inspect and enrich it, and accelerate response to intelligence.

The Struggles of Harnessing Telemetry DataTelemetry data refers to a varied corpus consisting of performance data, metrics and operational data. “In the context of Mezmo, it is your typical MELT metrics – metrics, events, logs and traces – any data that is created by machine,” says Callaway.

IDC released a report that stated that data volume is growing at a rate of 23% year-over-year. But by contrast, observability adoption is down at 10%.

“That necessities a shift in the way people think about observability and cybersecurity. That ultimately plays a role in how we think about telemetry data fueling an LLM.”

A plethora of challenges stand in the way of harnessing telemetry data. There is unprecedented amount of diversity in data format with data coming in from numerous sources and silos. Poor data management translates to a low signal-to-noise ratio which frequently leads to cost blowouts and alert fatigue.

Efforts are being made to put this pool of data to good use, but a rift in communication between teams is making it harder for enterprises.

“People who are controlling the data, who generate a lot of this data, oftentimes, are application developers and the people who are trying to manage the end are platform engineers and SREs. They lack the ability to communicate between themselves, and we find them stepping on each other quite a bit,” Callaway reveals.

Many a times, the skill that affords a high level of data inspectability is missing. “There’s this notion to enrich, transform or reduce data that’s predicated on the assumption that you understand your data. We found that the biggest bottleneck in enterprise isn’t a lack of desire to optimize. The ability to understand data is just not there.”

With data showing no sign of stopping, enterprises are faced with a difficult choice: to turn data over to third-party vendors for analysis and lose control and ownership, or accept the risk that comes with poor visibility.

Callaway argues, “Organizations need to own their own telemetry data. They no longer need to advocate that ownership to the vendors they work with. You can’t just keep it in the vendor-format and have them collect and manage it for you, and store it in their cloud. You need to take control of your data so you can do the things with it that are the most useful to you and your company.”

Mezmo predicts that a shift is underway where cost of telemetry data will grow linearly in the next five years.

Faced with this scenario, teams benefit from an approach that converges telemetry data streams from various sources into one broad pipeline. This pipeline then aggregates and normalizes the data before passing it on to different personas – operations and security – within the organization, in required format.

Observability Maturity with Mezmo“We take the control point and route the data to the right location. We can manage, normalize, enrich, transform, route and do all the things with the data that matters to your enterprise and that you’re beholden to these vendors,” Callaway says.

Mezmo achieves this by periodically profiling data and detecting repetitive and redundant patterns in it, pointing to possibilities of optimization and insights.

An open platform, Mezmo integrated with a large number of observability solutions at both ends. It ingests telemetry data from platforms like Kafka, Prometheus, Kubernetes and OpenTelemetry. Data is transformed and enriched within the Mezmo Telemetry Pipeline before being routed to various output points like Datadog, Amazon S3, Elasticsearch, Splunk, and Grafana.

Mezmo ensures that insights are distributed without delay, so that teams can make decisions and respond to alerts faster.

One of the key jobs of the Mezmo platform is to increase control of telemetry data and enhance security through analytics and insights. In the process, it reduces cost and overheads of data management, significantly reducing resolution time.

Where optimization decisions happen in the early stages making post-event changes tricky, Mezmo lets operators make responsive changes dynamically after the fact based on the context.

These may sound like what OpenTelemetry does, but Bill Meyer, principal solutions engineer, dispels the confusion, “When it comes to operationalizing the collection of telemetry and operating on it before sending it out to telemetry tools, Enterprise Mezmo helps pick up where OpenTelemetry is currently situated.”

After 2 years in the works, the Mezmo Telemetry Pipeline is at its best today. There are some new capabilities on the horizon that Callaway hopes will drive the solution further into the AppDev world.

One of them is in-stream analysis. Ordinarily, data is brought to a central repository where it is computed. Mezmo’s in-stream analysis will perform correlation and cross-stream analysis on data in motion. In-stream alerts will soon be a function on the platform as well. This will identify variations in data while on the go, based on metrics thresholds, and alert about events that didn’t take place.

Simulation is a capability that will facilitate real-time data operations.

“One of the things really hard about setting up a pipeline is you’re interrupting mission critical data flows.”

Mezmo will have a Simulation mode for creating tests, samples and alerts. This will allow engineers to test the data stream all the way from source, through the processors to the output point in advance before streaming live operational data. This helps them decide the best change management strategy and put controls in place without interrupting the data flow.

Mezmo can be deployed in edge environments where it can be managed from the SaaS control plane with data staying local.

Wrapping UpThere is a lot of value in mature observability practices, but extrapolating is not simple. For companies that struggle to derive insights from their telemetry data, Mezmo is a great tool to have. It homogenizes streams of data, detect unseen patterns in them, and spits out contextualized insights, enhancing visualization, and reducing time to resolution, all within the enterprise perimeters.

Watch Mezmo’s presentations from the AppDev Field Day event for more details, and to see the solution in action, be sure to check out the demo in the following session. Also check out Sam Holschuh and Paul Nashawaty’s takes on Mezmo.


© Gestalt IT, LLC for Gestalt IT: Mezmo Telemetry Pipeline – Aggregate, Transform, Distribute

View Details

The modern cloud is evolving rapidly, encompassing AI, hybrid-cloud, and advanced IT infrastructure. Cloud Field Day 20 will feature presentations on private AI data centers, workload orchestration, unified platforms, AI integration, networking, and more. Presenters include Juniper Networks, Google Cloud, Morpheus Data, and Oxide Computer Company. Our next Cloud Field Day event will be broadcast live on the Tech Field Day website and LinkedIn Page as well as on Techstrong TV June 12th through 14th. Here’s a quick overview of what to look forward to.

Cloud Field Day Event Schedule:Cloud Field Day live broadcasts will begin at 8:00AM Pacific Time Wednesday and Thursday and 9:00AM on Friday, with more presentations throughout the day. All of our sessions will be recorded and posted to the Tech Field Day YouTube channel soon after in case you miss anything. Wednesday kicks off at 8:00AM Pacific with a leadership session from Juniper Networks. Their presentation will cover a range of topics addressing the challenges of creating a private AI datacenter, including strategies for designing, deploying, and managing AI clusters and innovative methods for network and congestion management in AI data centers. In the afternoon starting at 1:30PM Pacific, Morpheus Data will return to explore the criticality of platform thinking in 2024. Amidst changes in hypervisors and cloud providers they’ll discuss the orchestration of AI workloads and training jobs, provide updates on their unified platform framework and its plug-in model and offer a sneak preview of MVM, their new embedded KVM cluster deployment engine.

All day Thursday is dedicated to Google Cloud, featuring three segments throughout the day. The first session from 9:00AM to 11:30AM Pacific will focus on Google workload optimized infrastructure. In the afternoon from 1:00PM to 3:30PM we’re going to delve into AI integration, including Gemini Cloud Assist, Gemini Code Assist, Vertex, and Cloud Run. Google Cloud will wrap up the day with a summary session from 4:00 to 5:00PM.

On Friday we’re excited to visit Oxide Computer Company starting at 9:00AM. They’ll present an overview of their company, introduce the Oxide Cloud Computer, explain the advantages of hardware/software codesign, and share real customer use cases, concluding with a live demo of VM provisioning for the first time.

Following the pandemic, all of our sessions are held on site at various locations throughout Silicon Valley. We sincerely appreciate Juniper Networks, Google, and Oxide Computer Company for hosting these Tech Field Day presentations.

Tune in to Cloud Field Day 20All of the sessions will be broadcast live on the Tech Field Day LinkedIn page, website, and on Techstrong TV. They’ll also be recorded and shared on the Tech Field Day YouTube channel soon after the event. We welcome participation on X/Twitter, on LinkedIn, and on Mastodon using the #CFD20. You can learn more about the event and the panel of independent technical influencers, podcasters, and analysts from The Futurum Group by visiting the Cloud Field Day event page. Thanks for tuning in to Cloud Field Day 20 live June 12th through 14th.


© Gestalt IT, LLC for Gestalt IT: Looking at the Rapidly Evolving Modern Cloud at Cloud Field Day 20

View Details

Customer experience is top of mind for a whopping majority of enterprises competing in 2024. Notably, the focus is sharpening on digital experience. 64% of digital-first companies are actively working towards their digital experience goals, polls show.

The Secret to Delivering Outstanding Digital ExperienceThe most successful brands put experiential optimization before all commercial goals, because in commerce, the formula for success lies in the point of interaction between customers and the company.

One of the leading tech companies that has been steadfastly committed to delivering truly good digital experience is none other than Cisco. At the Mobility Field Day event in Silicon Valley, the company introduced Digital Experience Assurance (DXA), a solution in private beta. DXA is set to unlock unrestricted and ubiquitous visibility of digital experiences across the network and can potentially guide network operators towards achieving next-level customer experience.

“What we call Digital Experience Assurance encompasses all of the different assurance tools that we have at Cisco, namely the Meraki Assurance, the Catalyst Assurance, ThousandEyes, all of that,” says Tauni Odia, Technical Marketing Engineer.

Over the years, Cisco has developed a spectrum of experience monitoring and visibility products to provide users means to screen and refine customer interactions with solutions and services at their end. DXA tightly couples those solution to provide a consistent and all-encompassing view of the topography.

“We are aggregating all of the data and bringing it into one place to give our customers and our users that one-stop shop to look into, and identify and remediate problems on the network,” Odia says.

This will bring to the attention of operators aspects that are in need of improvement, and those that are likely to degrade in the near future.

The goal of DXA is to enable organizations to see, understand and optimize digital experiences across network domains, for every user alike. Already, the Catalyst, Meraki and ThousandEyes products offer seamless views of user experiences in their ecosystems. Combining them makes all the data accessible through one solution.

Cisco tops this off with Splunk integration after acquiring Splunk Inc. in March, further boosting visibility.

The combination unlocks a pool of data coming in from endpoints, wireless, routing, internet, datacenter, cloud, and applications – now visible from a single viewpoint. This view is a sum-totality of how customers are interacting with the network, anywhere.

“We’re bringing in information from each of those domain controllers and make insights across those controllers, individual domains and even third-party domains, whether it’s all the way down to server-level or third-party infrastructure,” says Stephen Orr, Distinguished Solutions Engineer. “So trying to give a more holistic view from an AIOps perspective into the customers’ network.”

Broad data collection of this kind is key to sniffing out all traces of problems in the network. But without action, companies may still be far from reaching their digital experience goals.

Cisco DXA takes it to the next level by implementing AI and closed-loop operations. It prescribes intelligent recommendations for fixing service hiccups.

Cisco DXA will complement the Meraki Dashboard. Embedded as a left-nav item on the dashboard, it will provide a one-click navigation to the network health report.

Cisco adopts a top-down scoring approach when inferring the network health. DXA combs through client experiences from all vantage points – clients, network devices, infrastructure connectivity and applications – to get a measure of the QoE at every point. Based on the discoveries, a score is provided every day.

DXA also looks at network trends to analyze the what, where and how of an issue. Odia provides an example. “Let’s say you had a config change and now all of a sudden it’s gone wrong. You’ll be able to see that and pinpoint the timing of when it occurred and where, so that you can determine if you need to revert back to the old config because this one didn’t work.”

For comparative analysis, DXA offers before and after views of states down to every hour, day and week.

Features Coming SoonSeveral new features are being added to Cisco DXA to elevate the app’s functionality. One of the capability Odia highlighted is the new Org Alert Page. With DXA, alerts are always a click away. The quick-navigation button that appears on the right-hand side of the screen takes operators straight to the alert hub where all notifications are now logged and stacked under one page.

“Now alerts are not on every page. They’re in one location for you to be able to see all of the notifications so that you don’t have to go hunt and peck for different alerts or different things that could potentially be wrong. This way, we are really trying to build efficiencies into workflows and our troubleshooting process to be able to make it very simple for everybody,” Odia emphasizes.

Users can choose to receive alerts through any preferred medium of communication – email, SMS, Webhook and so on.

In a recent update, Cisco added centralized management of the alerts. This affords users a chance to drill into trends, filter down the list, isolate and dismiss unimportant alerts, and see the most problematic areas to start troubleshooting in one place.

Alert RCA is in progress and will offer much deeper insights into root causes of issues. This will be accompanied by guided workflows, and snapshots for that one-page view.

Two more features – Wireless Health Tab and Switching Health Tabs – are coming soon by end of 2024.

Wrapping UpIn the fast-changing digital landscape of today, service snarls are inevitable. The only way companies can fully dodge them is by meeting customers’ expectations to the T. Cisco’s Digital Experience Assurance dislodges the wrench from the gears by giving companies the means to observe the reality at the user end and hone in on the most fine-grained aspects of their experience. DXA’s guided workflows make sure that the data is followed by action. Combined, they can pay big dividends by forging the path for exceptional digital experience.

For a free trial-run of the Cisco Digital Experience Assurance, scan the QR code shown in the presentation. For technical details, be sure to watch the full session, and other Cisco presentations from the recent Mobility Field Day event.


© Gestalt IT, LLC for Gestalt IT: Elevating User Experience with Cisco Digital Experience Assurance

View Details

The blueprint to success for any business is a short time-to-market. Whether it is an emerging outfit, or an established corporation, the topmost priority is to launch deliverables through the fastest route possible. In IT, that route is through developer experience (DX or DevEx).

Developers are an asset to organizations, and their experience is intertwined with its innovation and progress. They are the people responsible for building software programs that run digital applications and services. Their roles primarily entail writing code, designing and testing software, debugging, maintenance, and so on.

The more efficiently developers can do these tasks with fewer obstacles and distractions in their way, the better is the business outcome. If developer productivity suffers, the bottom-line suffers with it.

Lately, a lack of focus on developer experience has slowed these professionals down leading to unusually long go-to-market timelines. Aside from essential tasks, frequently, developers are required delve into the underlying infrastructure and make fine-grained decisions, a chore that is neither quick, nor painless, and is a constant source of frustration in the developer community.

At the AppDev Field Day event in California, Google Cloud showcased Cloud Run, a developer-centric compute platform that flips the script. Cloud Run is designed to automate infrastructure management, and ensure a top-notch developer experience.

It Takes a Village to Run ITThe day-to-day execution of sundry things is the result of crossovers and collaborations between teams. “There are usually a lot of different stakeholders, security team that’s worried about centralized security policy, network team that sets network policy, etc. Developers want to move fast, but they want to do so within the boundaries sets by the organization,” says Sridhar Venkatakrishnan, Engineering Manager.

A fully managed platform helps developers bypass these secondary responsibilities and have more time to focus exclusively on writing and deploying code. This is why Google Cloud has developed Cloud Run.

“Cloud Run is our fully managed platform. You can provide it a container and it abstracts away everything else underneath the hood. You don’t have to think about Kubernetes, orchestration, networking or any of it,” Yunong Xiao, Director of Engineering explains.

Xiao likens the experience to taking an Uber ride. Uber takes care of providing passengers their vehicles of choice, finding the most efficient route, and drivers to drop them off safely to their destinations without having to worry about a thing.

Large corporations in different sectors use Cloud Run for this easy, hands-off infrastructure management. Some names include IKEA, L’Oréal, LangChain, Nasdaq, BBC, Ford, Airbus and Colgate.

How Cloud Run Forges a Positive Developer ExperienceGoogle Cloud positions GCP as an AI-first product, and everything within it is focused on DX. “From console to development tools to the way that we structure our APIs, all of it makes it very very easy for developers to get started and continue past the day one experience,” says Xiao.

Keeping with that core element of simplicity and enhanced experience, Cloud Run presents a developer platform so easy to use that developer velocity is guaranteed. Cloud Run is fully featured, and demands very little from users. Developers can run their code directly on top of Google Cloud without getting their hands dirty in the manual infrastructure work.

The corollary, developers spend less time on nonessential activities, and more time writing code.

There are two ways to run code on Cloud Run – as a service, and as a job. Services are for code designed to respond to a particular event or request, and jobs for code meant to do a particular work and stop after completion.

Tasks like scaling, configuration, and resource allocation happen automatically under the hood. Set-and-forget policy management allows networking and security teams to define the policy and enable automatic enforcement for every job.

Cloud Run scales out on demand, meaning it can go to a thousand instances or more when requests come in.

“Cloud Run is serverless. We maintain and manage all the existing infrastructure for you at planet scale,” Xiao informs. “You simply give it a container which is your workload, and it’ll scale off for you. You don’t have to worry about the auto-scaling policies or any of that existing infrastructure.”

Conversely, when demand is low, Cloud Run intuitively turns off idle containers to minimize utilization. Users can set the max number of instances to ensure that the service does not go over it.

Cloud Run supports most coding languages, frameworks and libraries. Developers can build their own containers or let the platform build it for them based on the best practices for the language concerned.

Container images can be automatically created from source, and batch data processing can be performed leveraging parallel-running instances. Scheduled jobs can be run to completion for up to 24 hours.

“The product teams can move very fast, and build their containers. It’s a very simple interface and they can work with skills they can handle. If you’ve got a CPU or memory- hungry app, that works just fine too, and whether it’s one service, a hundred services or a thousand – Cloud Run scales really fast,” Venkatakrishnan says.

New Product UpdatesVenkatakrishnan gave a rundown of the new updates soon to come to Cloud Run. The first on the list is a newly announced feature called Volume Mounts. Currently in preview, this feature allows integration between cloud-native apps and shared data storage like NFS and cloud storage buckets. “It’s great for read/write use cases as long as you’re not using something that requires concurrent writes to the same file,” he highlights.

The second feature, also in private review, is Automatic Security Updates. This feature aims to release a patch under 48 hours of detection of a CVE (Common Vulnerabilities and Exposures).

“We’ve been doing this for App Engine for more than a decade, and we’ve brought that technology to cloud. There are lots of issues that show up especially with the supply chain being what it is these days, and the use of open-source products. You want a way to very quickly patch things when CVE occurs,” he elaborates.

This feature is available for multiple languages, and runtimes.

The third capability is Multi-Region Services. With a single command, developers can deploy a service to multiple regions. This takes Cloud Run from being a regional service to a multi-region one.

“If you provide a domain, we’ll automatically set up a global endpoint for that domain so that when traffic gets to that end point, it will get routed to the nearest Cloud Run region and that provides you with a multi-region service with location-based routing with a single command.”

There is no flat fee for using Cloud Run. Google Cloud only charges for the resources used, rounding it up to the nearest 100ms. The free monthly tier resets start of every month.

Be sure to check out Google Cloud’s presentations from the AppDev Field Day event for the technical nitty-gritty. Also give Paul Nashawaty’s coverage on Cloud Run from AppDev Field Day.


© Gestalt IT, LLC for Gestalt IT: Optimal Developer Experience with Google Cloud Run, and New Product Updates

View Details

Not too long ago users upgraded to Wi-Fi 6E tapping into significant speed and performance upgrades from the previous standard. As 2024 rolled in, the 7th generation debuted bringing with it promises of even faster connections and ultra-low latency.

There is a lot of noise and excitement around it, and for good reason. Wi-Fi 7 marks a major milestone in the evolution of connectivity. Not only is it fourfold faster than Wi-Fi 6 and 6E, and can support a lot more devices and connections, the new standard also packs a lot of clever upgrades.

At the recent Mobility Field Day event in California, Fortinet showcased the FortiAP K-series, their line of Wi-Fi 7-enabled access points (APs).

One of the industry’s first to launch APs supporting Wi-Fi 7’s bandwidth, Fortinet has been at leading edge of technology for years providing enterprises smart and secure connectivity.

From the outset, Fortinet has been a big proponent of security-driven networking. The converged networking and security approach has many benefits. “More than 50% of our global shipments are all firewalls. The same firewall can also be a wireless controller, switch controller, or the extended controller. There are a lot of options enabled for no additional cost. For a business case, it translates to lower cost of ownership because it is all integrated.” says Sumanth Gorajala, Senior Director of Wireless Product Management.

For Wi-Fi 7, the vision is the same, but to bring it the edge with security-enabled wireless devices. The idea is to provide intelligent and secure connectivity for everybody from top to bottom, says Gorajala.

Notable Wi-Fi 7 UpgradesThe biggest factor about Wi-Fi 7 that distinguishes it from its predecessors is that it offers more lanes and highways. What does that mean for users? Simply put, the 7th generation offers four times faster speeds and improved latency than Wi-Fi 6E.

There are some clever manipulations at work here. Cellular networks transmit data through radio waves. The waves travel at varying frequencies and are grouped into bands. Each band comprises of multiple channels. For example, the 2.4-GHz band has 11 channels of 20 MHz each. Wi-Fi 7 uses three bands – 2.4-GHz, 5-GHz and 6-GHz. In the 6GHz band, these channels expand to up to 320 MHz. With three such ultra-wide channels on a dedicated 6-GHz band, the available bandwidth is twice that of the previous generation.

A modulation scheme used for sending and receiving data in Wi-Fi communications is Quadrature amplitude modulation or QAM. The potential benefit of that is to be able to embed more data in each signal. Wi-Fi 6E supports 1K-QAM, which Wi-Fi 7 upgrades to 4K-QAM. The difference is a jump of 20% in data rate.

Typically Wi-Fi standards establish connections between devices strictly on a single band. For the first time, Wi-Fi 7 presents multi-link operation (MLO), a capability that averts bottlenecks and enables efficient movement of data by intelligently choosing the best channel. Instead of devices connecting over a fixed channel on one band, MLO can decide to use multiple frequencies concurrently. The decision is made by the router while connecting with a Wi-Fi 7 device.

FortiAP 441K and 443KGorajala showcased FortiAP models – 441K and 443K, both high-performance enterprise-grade indoor Wi-Fi 7 APs with same specs list.

With support for all the aforementioned Wi-Fi 7 features and access to all the three bands – 2.4GHz, 5GHz and 6GHz, the FortiAP 441K and 443K are among the industry’s first Wi-Fi 7 APs.

It packs four radios, three for the three bands, and a fourth dedicated to security. “We have moved the dirty job from the three servicing radios to the fourth so that it can dedicatedly do scans, look for rogue APs and clients, detect sweeps and so on. All that will be done on the fourth radio.”

The devices have two 10 GbE ports that can be aggregated to get a combined speed of 21 Gbps, or used individually.

All the K-series models have Unified Threat Protection (UTP) enabled on the device. The UTP module includes capabilities like antivirus, intrusion prevention, application control, web filtering and anti-bot net.

“Everything will be on the app level so that when the wireless client connects with this feature enabled, all the traffic goes through the IPS engine and then passed on to the Ethernet side of it,” he explains.

Users also has the option to port from one Fortinet management solution to another as their needs change. Whether it is FortiOS, FortiLAN Cloud, or FortiSASE, users can manage, automate and orchestrate devices equally from all platforms.

“The same wireless AP can be managed by any of the solutions. It is easily portable, and as your business needs grow, you can move from one management solution to another with ease,” says Gorajala.

Wrapping UpWi-Fi 7’s extreme throughput and super-low latency can power the most bandwidth-intensive and low-latency applications. When considering switching, enterprises must look at access points that are not just Wi-Fi 7-supported, but also come with capabilities to tap into the technology’s most significant enhancements. At the same time, setting-up should be easy and quick. Fortinet’s access points look ready meet Wi-Fi 7’s throughout demands, while offering the added aspect of security and management for seamless connectivity.

Be sure to check out the demo at the end of the video and other presentations by Fortinet from the Mobility Field Day event.


© Gestalt IT, LLC for Gestalt IT: Tapping into Wi-Fi 7’s Extreme Performance with the Fortinet FortiAP 441K

View Details

Cisco Live has been going strong for the past 35 years! It’s always a fun way to spend your summer speaking with the brightest minds in the networking industry and see how companies like Cisco are advancing technology. This year will be another exciting adventure, thanks in no small part to Tech Field Day Extra at Cisco Live US 2024.

Tech Field Day Extra ScheduleWe’ve got two great days of announcements, technology updates, and partner presentations. Tuesday, June 4 kicks off right after lunch with a special introduction from Cisco VP Juan Vela. He’s going to highlight the key innovations that Cisco has been making in the networking space. After that we kick off with Cisco Meraki and Cisco Industrial IoT. They’ll be covering a variety of important enterprise topics. After that we’re going to get an update from Cisco Networking. They’ve been making some big strides in the secure connectivity department and this year will be no exception. We finish the day on Tuesday with a presentation from Cisco ThousandEyes talking all about digital experience assurance.

Wednesday starts bright and early on the west coast with a 11:00am presentation from Opengear. They’ll be updating us on the latest news from the remote console access space as well as the interesting ideas they’ve been working on to expand their presence. After lunch we’re back with more Cisco presentations. The first is from the Mass-Scale Infrastructure Group. Make sure you’re watching to learn more about fabrics and Nexus as well as some other new product news. After that will be a session with Cisco Security with the latest in XDR and AI. The final presentation of the day is from Cisco Innovations. Tim Szigeti is a rock star presenter and his topic is something you’re not going to want to miss!

Cisco Live Community ConversationWe’re going to be streaming live on June 4 and 5 at our website at TechFieldDay.com. We’re also going to be streaming live on our Tech Field Day LinkedIn page as well as at TechStrong TV. If you want to learn more about the schedule or the delegates at the event, make sure you bookmark the Tech Field Day Extra event page. If you want to participate on social media and join the conversation you can use the hashtag #TFDx as well as #CiscoLive. Both of those will get our attention as well as get you involved in the wider Cisco Live community. If you miss any of the presentations you can always check them out later on the Tech Field Day Youtube channel.

We can’t wait for Cisco Live and we hope to see you online!


© Gestalt IT, LLC for Gestalt IT: Nerdy Summer Camp with Tech Field Day Extra at Cisco Live US 2024!

View Details

From AI to robotics to smartphones, the success of any technology hinges on the speed and stability of the connectivity. As the Internet economy shaped out before our eyes, applications have become critical to businesses. Overnight, their latency tolerance fell, and a new crop of apps is born. For this breed, high frequencies and fast speeds are non-negotiable.

The 5th generation of cellular network rose to the occasion giving users up to 10 Gbps faster Internet speeds. Faster connections equal faster downloads, but 5G also supports more simultaneous devices than LTE does.

“The key advantage that we are seeing is uplink-heavy traffic,” says Prince Jose, Director of Product Management at Celona, during their presentation at the recent Mobility Field Day event in Silicon Valley. “A lot of deployments with cameras, and some of the robotic applications are very very latency sensitive, and need more uplink. The 5G gives you almost 20 to 25 milliseconds of latency. The LTE is more in the 30s level.”

That milliseconds’ difference is critical for use cases where the slightest lag in signal transmission can lead to life-or-death situations. Think telesurgery or autonomous driving.

But it’ll be years before private 4G LTE is completely taken over by private 5G wireless service. Infrastructures of mobile carriers need to be expanded and upgraded, and the ecosystem has to reach maturity before 5G’s wider pipelines and super-fast lanes start to accelerate innovation. And although it is indubitably the standard that will power the technologies of the future, like delivery drones and self-driving vehicles, 4G LTE is here to stay a little longer.

Some companies still find 4G connections sufficient for moderate latency use cases. In fact, at the low end, 5G is not much different from 4G. When it operates on low-band, 5G offers relatively low speeds, compensating for it with long coverage.

Shifting to 5GWith the release of each new generation of cellular network, businesses have a new challenge on their hands – doing a hard switchover from the previous standard to the new standard. With the debut of 5G, the same problem persists. Cellular infrastructures are not backward compatible, and with 5G promising 10 times faster Internet than 4G LTE, it demands significant upgrades. Alternatively, one can’t stay locked in with LTE connections, and not be left behind.

Many CTOs find it reasonable to start off with 4G, before migrating to 5G. Celona can see them through this transition with a frictionless experience. It involves no reinstalls, no extended downtimes.

At the presentation, Jose presented the Celona AP 20. One of their high-performance access points, AP 20 has a special feature built in, a multimode to support both LTE and 5G. Simply speaking, the device can operate in both modes, depending on how it is configured. This allows enterprises to seamlessly toggle between LTE and 5G when they need to, no matter how big a fleet of APs they have.

AP 20 features both 4G and 5G radios. In 4G mode, it supports only 4G devices, and upgraded to 5G NR, it supports all 5G devices.

“Devices like iPhones and Zebra tablets, they are 5G but 4G-compatible. They will connect to AP 20 in 4G mode, and the transition happens with the touch of a single button, and move over to 5G radios,” he says.

Touch-Button SimpleComing to the process, as noted, the switch from 4G to 5G with Celona AP 20 involves no re-installations, or hardware upgrades. The devices can deploy both generations of cellular network alternatively. The Celona Edge has a converged core, and the Celona Orchestrator supports converged 4G/5G operations. So the transition happens at the software level.

The multimode feature can be found in the Celona Orchestrator. Under “Sites” where all details are stored, is the Access Point option. Users simply need to select the bandwidth options from the Radio Technology under it to make the switch. The Orchestrator will ask to confirm the update and perform the switch to the chosen radio technology. With the same ease, users can upgrade multiple access points at once.

“In a real-world deployment, once you do the switch on a site-level, it will be done at the maintenance window, and you relinquish all that spectrum.”

Under the hood, Celona’s Self-Organizing Network (SON) algorithms that are responsible for matching frequency channels to the regulatory specifications of a region, recalculate the channels and the power of the site, before getting the spectrum back and reallocating it to the APs.

A simultaneous mode is on its way. Celona expects is drop it in the second half of this year.

Wrapping UpThe ecosystem around 5G is about to get real. Speeds unheard of, and broad coverage will bring never-before live experiences to users’ fingertips. If a business is to be a part of this revolution, they need to futureproof their investments with APs that can support both LTE and 5G. With AP 20, Celona lends a helping hand to enterprises to make that jump in their own time, without any bumps.

Be sure to check out the demo, and other presentations by Celona from the Mobility Field Day event to stay abreast of all their latest developments in 5G.


© Gestalt IT, LLC for Gestalt IT: One-Button Upgrade to 5G with Celona AP 20

View Details

As businesses embrace cloud computing, it has given free passes to users to access IT resources from anywhere. Employees need access of the corporate network and work apps to get their job done. But the cloud provides anywhere-access indiscriminately. For example, to external parties like contractors, vendors, partners and customers. Meaning with a device connected to the Internet, any of these entities can access corporate applications and data from any part of the world.

This on one hand has unlocked tremendous opportunities of collaboration and coopetition, but on the other hand, it has unspooled chaos at the security front. With the rise of BYOD, the number of digital identities and online accounts of users have exploded, amplifying risk to data. For an average-size enterprise, managing millions of global identities in a way that access to corporate applications is maintained, while still being in control of sensitive company data, is a growing burden.

At the 2023 Mobility Field Day event, Arista Networks showcased their cloud NAC solution, CloudVision AGNI. Short for Arista Guardian for Network Identity, AGNI packed many useful security features that advance zero trust security in a perimeter-less environment. This Mobility Field Day event, Arista Networks returned with some significant enhancements that they say take CV AGNI to the next level.

Sriram Venkiteswaran, Director of Product Management, and Parul Sharma, Sr. Technical Marketing Engineer, jointly demoed the solution and the new capabilities to the audience.

The Zero Trust Journey Starts with AGNIAt the foundation, Arista’s Zero Trust Network architecture has AGNI for access control. It provides continuous authentication, frictionless onboarding, and profiling of endpoints for identity management.

All communications happen via a TLS-based RadSec tunnel which is highly secure and encrypted, and offers maximum protection across distributed networks.

“All our infrastructure components use RadSec to talk back to our NAC in the cloud. Underneath RadSec is the standard RADIUS protocol, and the best part is it works on any third-party infrastructure as long as it supports RadSec,” he says.

For devices that don’t support RadSec, Arista switches can behave as RadSec proxies with just an additional module.

AGNI integrates with Arista’s Microperimeter Segmentation Services (MSS) framework, a newly launched solution that works by implementing group-based security policies in the network based on AGNI’s inputs.

“The way we do segmentation is we don’t have any proprietary tags. We don’t modify the packets or the headers. It’s network agnostic and works obviously on top of our infrastructure, but also in multivendor environments,” says Venkiteswaran.

Inside Arista Networks’ Zero Trust ArchitectureThe last mile is covered by Arista NDR (Network Detection and Response), a platform that performs continuous threat monitoring of all wired and Wi-Fi devices in the network to deliver diagnostics for threats and anomalies.

Arista NDR works through an army of software sensors that are deployed on network switches. These sensors work natively scanning every packet passing through the switch and pulling their flow information. This it shares with the AVA Nucleus, an AI/ML engine that analyzes the behaviors of entities and alerts operators about suspicious changes, anomalies and threats.

Through integration with AGNI, Arista NDR can send back alerts after cranking up the threat profile of the suspect device. AGNI then takes over and enforces the required policies which include quarantining the device, blacklisting it, change the ACLs and so on.

During the demo, Sharma also highlighted AGNI’s two-step guest onboarding with U-PSK. The self-registration workflow entails entering the client email address at the kiosk which generates a QR code. To connect to the network, all they need to do is scan that QR code. All guest devices will be automatically granted guest network access without redirections.

Broad Integration with External SolutionsAn API-first approach allows AGNI to integrate with all of Arista Networks’ products as well as a whole ecosystem of third-party solutions with which it can exchange client and user context, telemetry and protection status of endpoints.

When interacting with customers, Arista learned that a majority of the customers do not implement NAC despite paying for the licenses. “Setting up NAC policies in an existing environment is a PHD project – it’s super complex,” Venkiteswaran informs. “Also, customers don’t want to touch their networks because they fear they’re going to break something.”

To make the process simple, Arista Networks has built integrations with a suite of Concourse Apps that are both native and external services from which AGNI can receive feeds and notifications. Among them is CrowdStrike, a leading cloud-native, AI-powered threat hunting solution.

When CrowdStrike picks up anomalous behaviors, it can send the alerts back to AGNI. “The workflow is very similar. We take feed from CrowdStrike, say about a device that is non-compliant, and we go back and take actions on the network.”

Among things that are new, AGNI now supports TACACS+ for device administration for customers that are looking to migrate legacy NAC solutions to AGNI. “Essentially, at a high level, one of the switches acts as a gateway that terminates TACACS from all the infrastructure components and at the back end, talks to AGNI to complete the authentication,” explains Venkiteswaran.

Wrapping UpIdentity is the new perimeter, and ensuring secure identity and access is the biggest priority of enterprises. Arista CV AGNI offers top-notch convenience in accomplishing this daunting task. Around the clock, it vets entities before granting them permission to enter the network. Arista Networks’ goal to make it an adaptive solution is fulfilled through its broad integration with the rest of the Arista portfolio and external vendors which enables it to dynamically receive threat intelligence, evict bad actors, and secure resources by going beyond the known enterprise boundaries.

Be sure to watch Arista Networks’ demonstration from the recent Mobility Field Day event to watch CV AGNI in action.


© Gestalt IT, LLC for Gestalt IT: Arista Networks Refreshes CloudVision AGNI with New Feature Set

View Details

Imagine a network that is never down, and everything inside of it operates at full efficiency. Demand and downtimes are anticipated well in advance, and all probable variations and movements are taken into account at the time of the conception of the design.

This is not a fiction. Nor does it have to be the work of accomplished engineers. The networks of tomorrow will be de facto optimized to deliver maximum output by harnessing the force of artificial intelligence (AI).

A small startup based out of Brooklyn, New York, is turning this vision into a reality. eino has developed an AI platform that holds the key to designing smart networks with minimum effort and expense. Its superpower is optimal planning and resource distribution without human expertise.

At the recent Mobility Field Day event, eino debuted their solution to the Tech Field Day audience. Cofounder and CEO, Payman Samadi, offered a walkthrough and demo of all that eino can do across three use cases – Wi-Fi, outdoor private cellular and fixed wireless.

The Guesswork in Network DesigningNetwork planning and designing has become increasingly complex and cumbersome with the multiplicity and growing criticality of applications. Telecommunication vendors say it is difficult to precisely provision new networks, and draft a design that is spot-on right from get go.

The main problem is hiring expertise for the job. The more brains are involved in the planning and dimensioning, the closer the design will be to the final result. Longer planning cycles and cost blowouts are inevitable with this approach.

Another potential risk is presence of errors and inaccuracies in guesswork. “It’s key to make sure that the initial estimate and the final design are as close as possible, and we started thinking how we could simplify this such that from get go, you don’t need to have the most amount of expertise to be able to get the layout or the outdoor area, but it’s good enough to be used for your final design,” Samadi says.

eino’s two founders saw a way to steer away from the potential outlays associated with planning and dimensioning by making use of AI. Whether one designs a Wi-Fi network, private cellular, or LoRaWAN, or a combination of all three, AI can automate the process and produce finely tailored solutions.

Sharing the Work with AIAI can autocomplete certain tasks with great finesse. But in the past, enterprises have found it a foolish idea to blindly trust AI’s skill and judgement, and turn over every job to it. Fall back on it for what it does best – completing the repeating tasks, sharing knowledge and making recommendations – is a much smarter approach.

“The idea is not that we give everything fully to AI, but let it take it to 80% to 90%, and then we take over from there,” says Samadi.

AI-Assisted Network Design with einoDesigning with eino starts with generating a digital 3D replica of the design. As you upload a layout on eino.ai, the algorithm will analyze the image and produce a 3D replicate with all its attributes and behaviors. Now you have a near-exact reflection of the project to work with.

Depending on the size and complexity of the layout, generating the digital twin could take about a minute on average, says Samadi. Inside eino’s labs, the model is continually trained on arrays of layouts to do swift and increasingly precise image processing.

This 3D layout is fully editable, and operators can adjust the dimensions and materials using sidebars to fine-tune things like wall types, doors, etc.

Alternatively, if a user does not have a ready layout, the AI assistant can generate it on the spot drawing from the industry use case they are looking into.

For outdoor projects, one needs to start by drawing a perimeter around the chosen area in the satellite view of the terrain to prompt the AI assistant to process and analyze its features. Post-processing, it turns out information about the elevation, and obstructions in the area.

eino sources clutter data from public repositories and image maps. Alternatively, it also lets users import their own clutter data should they want it.

A question that they often get is, what does it mean designing with AI. “You want to say put an AP every 40 sq. m. but the use case is different, the frequencies are different, Wi-Fi 5, 6, private cellular, how does that work?”

Within an environment, there could be endlessly different scenarios, fluctuating demands and attenuation from area to area. To address the unique needs of use cases and and behaviors of environments, eino lets users get a preview of the demand. Based on your selection of use case and environment, it can simulate the demand. Users can get coverage and capacity plans based on the estimation, including the number and placement of APs, expected number of users and so on.

eino.ai is a SaaS platform and can be opened from any browser.

Be sure to check out eino’s demo presentation from the recent Mobility Field Day event to get a look under the hood.


© Gestalt IT, LLC for Gestalt IT: Automated Network Resource Planning and Optimization with eino

View Details

From small coffee shops to corporations with global footprints, modern businesses depend on Wi-Fi for connectivity and continuity of operations. With Wi-Fi 7 offering up to four times faster Internet, enterprises are all set to upgrade to significantly faster, more stable and efficient connections. But first, they need a full-stack solution that can cleverly leverage Wi-Fi 7’s improved performance.

In the world of Wi-Fi, Ubiquiti is synonymous with fast speeds and broad coverage. At the recent Mobility Field Day event, Ubiquiti showcased UniFi, their “one-stop pane of glass for networking”, and shared their roadmap for 2024.

“Our goal is not to be number one on the specs list or the best of the best,” says Craig Wojtala, Head of Strategic Partnerships. “Our goal is also not to be the cheapest solution out there either. We really pride ourselves on giving you the best price-to-quality ratio.”

For Ubiquiti, the path to delivering that value goes through a holistic solution, one that constitutes three essential pieces – quality hardware, one interface for management, and full-stack support.

UniFi for a Unified End-User ExperienceFrom dominating the consumer and prosumer space, in 2024, Ubiquiti is shifting gears and pivoting towards the enterprise space. “We want to get involved in larger, more complex environments,” says Wojtala.

As part of their enterprise strategy, the company is launching a new line of hardware, their first Wi-Fi 7 access points (APs). The UniFi 7 lineup consists of U7 Pro, a ceiling-mounted Wi-Fi 7 AP with 6GHz support for interface-free connection and 6 spatial streams for large-scale environments. Next in line is the U7 Pro Max which offers elevated user experience with 2 extra spatial streams, and spectral scan radios with 4×4 MIMO.

Specially geared towards large outdoor venues and high-density applications is the WiFi BaseStation XG. It is a Wi-Fi 5 AP with three 5GHz radios, 12 spatial streams, and a phased array antenna system. The device can provide coverage over 5000 sq. ft. of open space, and support over 1500 connected devices.

During the presentation, Wojtala gave a walk-through of the feature-set of the Ubiquiti Enterprise Fortress Gateway that is also set to join the enterprise portfolio. The gateway is designed to manage over 500 UniFi APs and switches, and support approximately 5000 concurrent clients. Built-in security and networking features include signature-based threat management, anti-malware, ad blocking, SSL decryption, sandboxing, WAN load balancing, dynamic routing, and one-click teleport VPN.

“Stack two of these on your network, when one of them goes down, it will seamlessly fail over. If you’re on a Teams meeting, you won’t even notice,” he assures.

A Distinguished Business PhilosophyUbiquiti is aware that in a competitive landscape, customer-centricity is the secret to long-term success. This understanding echoes in their customer-first model of business and heavy investments in R&D.

“Our products, they have a really incredibly thoughtful industrial design, and it extends beyond just the hardware, even down to the packaging. We really think of the whole user experience,” emphasizes Wojtala.

The company takes a different approach to selling. “Unfortunately, a lot of vendors out there use the cloud to tether devices to their own licensing server and ultimately holding your network hostage, so you have to continue to pay these fees.”

Ubiquiti breaks the stereotype with a no-license model. Users can make upfront purchases of equipment without the obligation of signing up for a plan. Their UniFi solution features network switches, internet gateways with security and routing capabilities, and the UniFi Site manager that offers full visibility and control of all sites and devices.

Customers can deploy the UniFi software flexibly. The solution can be hosted on customers’ own hardware, with Ubiquiti on their servers, or on a third-party infrastructure. “You can even airgap it and turn off the cloud altogether,” he tells.

Ubiquiti focuses on bringing to the users actionable analytics through its UniFi dashboard. A complete and detailed breakdown is made available at the fingertips of operators for all issues.

“If clients are having trouble connecting to Wi-Fi, we are not just going to tell you that client can’t connect. We are going to tell you what it is – is it a problem receiving DHCP or is it a problem reaching your RADIUS server,” explains Wojtala.

Expanding on it, the team is currently developing augmented workflows for APIs and integrations. “This is where we are working now and see ourselves moving for the rest of the year,” he informs.

Where support is scarce with other vendors, Ubiquiti prides on a robust customer support service which includes expert pre-sales consultation and assistance for mega-size projects, and white glove service for enquires and deployment guidance. A 24-hour hotline is open to all US users, and it is working on bringing the same coverage for its UK and European customers.

Under UI care, all customers are offered priority and free-of-cost return merchandise authorization. Additionally, all products are covered under an unlimited 5-year service plan.

To learn more about what Ubiquiti is doing in the Wi-Fi 7 space and to get a closer look at some of its upcoming solutions, be sure to check their presentations from the recent Mobility Field Day event.


© Gestalt IT, LLC for Gestalt IT: Ubiquiti – Foraying into Enterprise Networking with Wi-Fi 7

View Details

Once you move beyond IT operations platform engineering and DevOps, you reach the realm of application development. That’s the newest Tech Field Day topic and we’re excited to be kicking off our coverage of this space with AppDev Field Day on May 29th and 30th. Tune in live on the Tech Field Day LinkedIn Page, DevOps.com, or Techstrong TV, and check out the AppDev Field Day event page for the complete schedule. We have also partnered with Paul Nashawaty, Practice Lead for Application Development and Modernization at The Futurum Group, to organize the AppDev Field Day event series.

Things kick off at 8:30AM Pacific Time on Wednesday with an introductory discussion led by Paul Nashawaty to set the stage for the entire event. Then we’re live with Google Cloud at 10AM Pacific. You might have heard about Google Cloud run at Google IO and we’re going to get an update on that followed by a deeper discussion about building generative AI applications on cloud run, including retrieval augmented generation or RAG.

After lunch we’re going to be welcoming Mezmo back to the Tech Field Day stage at 1PM Pacific. Mezmo specializes in Telemetry data and will demonstrate how DevOps and security teams are building data pipelines to optimize observability. We’ve got more surprises coming Wednesday afternoon as well.

We’ll begin Thursday at 8Pacific with Catchpoint. They can monitor the entire application stack and visualize customer experience with IPM as code. Then we’ll wrap up the event with a special guest presentation at 10AM.

All of our sessions are broadcast live on LinkedIn and Techstrong TV as well as the Tech Field Day website and our partner DevOps.com. The presentations are recorded and shared on the Tech Field Day YouTube channel as well as the Techstrong TV library. We welcome participation on X/Twitter and Mastodon using the hashtag #ADFD1 as well as LinkedIn. You can learn more about the event and our panel of independent technical influencers by visiting the AppDev Field Day event page. Each of our delegates has their own blog, podcast, or social media platform where they share their thoughts on Enterprise technology. Thank you for joining AppDev Field Day live May 29th and 30th on our social media channels. While you’re on YouTube, please subscribe to our channel for more great Field Day content. Follow us on X/Twitter or Mastodon and follow our LinkedIn page for more Field Day all the time.


© Gestalt IT, LLC for Gestalt IT: Moving Beyond Platform Engineering and IT Operations at AppDev Field Day

View Details

Organizations face significant headwinds as networks continue to grow, bringing home disruptions on various fronts. This is driving the need for operational resiliency, and a unified experience akin to the cloud.

At the Tech Field Day Extra at Cisco Live EMEA 2024, Cisco announced Cloud Monitoring for Catalyst Wireless. Following the launch of Cloud Monitoring for Catalyst Switching support a year back, this release expands on it offering Catalyst users a holistic, cloud-managed IT experience.

“Operating networks can be time-consuming and cumbersome. So we want to be able to simplify many of the functions of network operations and do a single platform with dashboard,” said Scott Irey, Sr. Technical Marketing Engineering at Cisco.

An Integrated ApproachOver the course of a day, network operators are required to dabble in miscellaneous tasks. These include but are not limited to event monitoring, problem analysis, performance monitoring, and incident response.

Cisco is adopting a cloud strategy for its Catalyst portfolio, and as a first step towards that, it has merged Catalyst and Meraki allowing Catalyst customers to monitor and manage their gears on the Meraki Dashboard.

“Two features are coming very soon to switching and we will have them in wireless,” Irey announced. One of them is Configuration History which will be available on the dashboard. “For your Catalyst devices, we’ll be able to take backups of your running configuration and store those in dashboard. You’ll also be able to see diffs of those configurations and restore them quickly and easily with a copy button,” he explained.

There is a rich set of pre-built packet capture features available within IOS-XE. But it entails using commands through CLI. Cisco has been working on bringing features like it to the dashboard, making them readily usable with just a few clicks.

After several changes and tweaks to the architecture that caused the Meraki tunnel to extend to connect Catalyst devices and switches, the integration now allows for easy onboarding of Catalyst devices as well as live telemetry collection from devices.

The integrated view on the Meraki dashboard translates to unified visibility of state, configuration and troubleshooting features. For easy distinction, the Catalyst devices show up marked as “Monitor Only”, but apart from that, they function same as their Meraki cousins.

Cloud Monitoring comes available at no extra cost to the users. It is bundled with the Cisco DNA licenses, Essentials and Advantage. Irey notes, “The only difference is Advantage gets you client traffic analytics. So we get the inbar data from the controller, grab that data and display it in the dashboard that requires the Advantage.”

To find out how it works, check out the demonstration in the second half of this Cisco session from Tech Field Day Extra at Cisco Live EMEA 2024.


© Gestalt IT, LLC for Gestalt IT: Operations Made Simple with Cisco Cloud Monitoring for Catalyst

View Details

One of the many consequences of having a network that spans multiple vendors and domains is that it makes providing end-to-end service assurance a formidable chore. There are unanticipated challenges at every turn, and operators must learn to expect the unexpected as they go through the motions.

At the Tech Field Day Extra at Cisco Live EMEA 2024, Cisco demoed a solution that helps operators overcome these challenges consistently, and deliver flawless quality of service (QoS) to the users. Cisco taps into the capabilities of Crosswork and Accedian to provide teams managing massive-scale multivendor, multi-domain networks freeway to automated network assurance.

Monitoring Differentiated Services in a Complex NetworkToday’s customers operate in an environment that spans geographies and networks, and they depend on the highest level of QoS to function.

“Every operator’s bread and butter is ensuring that they can deliver on enhanced SLAs and offer better customer experience so that they can maintain their market share and reduce customer churn,” says Rana Kazamel, Director of Product Management at Cisco.

Maintaining continued service performance and QoE in a complex network where the traffic footprint grows everyday has a series of speedbumps. These can be at any front – triaging a problem as it happens, making correlations and mapping it back to the network, or working out the fastest way to troubleshoot.

CSPs must monitor the services every minute and measure the real results so that when something breaks, the promised level of service is still maintained.

An intent-based approach to network assurance that is fully customized for the environment unlocks significant opportunities. “It means that you’re actually starting from the service intent, the metrics within the SLA that you need to be able to deliver on that service. We take that as our source of truth to ensure that we’re always monitoring on that,” Kazamel points out.

Cisco Crosswork and AccedianOrdinarily, network assurance solutions pick up bits and bytes of data and turn it over to the operators to make sense. But Cisco strays from the playbook. “Instead of flooding you with alarms and alerts that you get from the network and try to figure out what those mean, and how a fault impacts a service, you don’t need to do that anymore.”

Cisco Crosswork and Accedian do all the work for the operators – pulling up information, making correlations and turning it into insights. In a simplistic view, the dashboard tells operators the overall health of the services, what service is down, why it may be experiencing problem, and what are the steps to remediate it promptly. This flow of information is streamlined and made readily accessible for all teams starting at the SOC, to NOC to domain SMEs.

Cisco Crosswork Network Controller is designed to visualize performance metrics of heterogenous environments in a single dashboard that operators can look at, and receive alerts in real-time about SLA violations and service drops. Through integration with the Accedian Skylight Platform, it now collects end-to-end service performance data. Skylight probes capture the data and send it over to the network controller to investigate and find issues proactively.

Granular results are achieved by running Skylight’s diagnoses through Crosswork Network Controller’s deep analysis.

As reports are passed down from the SOC to the Network Operation Center (NOC) for further drilling down, the teams can leverage the Crosswork Hierarchical Controller (HCO) to get deeper visibility into the origins of the problems through active topology maps.

When the insights finally reach the Subject Matter Experts (SMEs), they can quickly isolate the problem parts and make fixes adroitly.

Be sure to check out the full presentation and demo from Tech Field Day Extra at Cisco Live EMEA 2024 to see the solution in action.


© Gestalt IT, LLC for Gestalt IT: Cisco Integrates Accedian into Crosswork to Deliver Uninterrupted Service Assurance

View Details

With cyberattacks paralyzing organizations one after the other, CEOs are turning to cyber insurance companies for protection. Following a barrage of costly data breaches in the past few years, the demand for specialized cyber insurance policies has gone up by 21%, the New York Times reports. But with the demand, premiums too have shot up leaving many companies without coverage.

In this Delegate Roundtable recorded at the Security Field Day event in Silicon Valley, Tom Hollingsworth and the attending delegates talk about pricy premiums, the pains of cyber claims, and the market driving adoption of new technologies.

“We Are Reducing Risk One Bite at a Time”Sophistication of cyber incidents and their financial impacts have been on a slow and sinister rise. Every year the numbers hit a new high with companies sustaining big losses in the forms of damage to the brand, lost revenue, and sometimes, full and final closure of business.

The general liability policies typically don’t protect against these kinds of risks. The losses are intangible, and therefore not readily quantifiable.

“We have certain kinds of insurance that are set up to protect life and limb. But what happens if a company finally gets to the point where it has collected so much data that the likelihood of a breach could materially impact the lives of every person in the world?” asks Tom Hollingsworth.

As a way to protect against the potential impacts of such attacks, it is critical for every organization to be on a specialty plan that provides coverage against emerging threats.

The market has shifted significantly since companies started purchasing cyber insurance policies. Trends show that between 2022 and 2023, cybercriminal gangs purposely targeted cyber-insured organizations for easy payoffs.

Indiscriminate claim flows from organizations hit by cyberattacks have caused carriers to tighten their belt and mitigate losses.

Insurance carriers work with underwriters that actively look for ways to throttle claim payouts. “The underwriters started pushing back on the companies saying you can’t just issue these policies with any hope that they’ll never pay off. They will and you need to put some basic protections in place,” he says.

One of the ways they’re doing this is by setting up stricter requirements which includes adoption of certain security technologies. “Lately we’re seeing more and more detailed attestation almost to the level of an audit. It reminds me of HIPAA compliance, and this is driving customer adoption of technologies. Before, they would do the cost-benefit analysis of whether a technology is going to slow the business down, or anger the users. Now it’s not a question,” says Ben Story, Network and Cybersecurity Engineer.

These requirements incrementally mandate the use of DNSSEC, SOC, SIEM and such technologies as the baseline to qualify for cyber risk coverage.

SEC’s New Discloser RulesFor carriers, up until recently, there wasn’t enough data to analyze the likelihood of an attack or what it’d cost, but recently, the U.S. Securities and Exchange Commission (SEC) passed a rule that requires organizations to disclose a breach within 4 working days after the incident is determined.

Over time, this will help provide more visibility into the threat landscape, and help make better risk assessment.

In the current landscape, cyber insurance is an essential element of the security posture, but it is not made mandatory yet. Experts worry that escalating premium prices may make purchasing difficult for smaller companies.

Max Mortillaro, industry analyst, points out that having cyber coverage, if one can afford it, is a great addition, but it is not a silver bullet. “It’s more of an add-on to make sure that you have this extra buffer rather than something which is going to save you because the cost, if you want to embed everything into such a policy, is going to be astronomical. So, it doesn’t make sense economically.”

Be sure to catch the full discussion, and many other interesting presentations from the recent Security Field Day event.


© Gestalt IT, LLC for Gestalt IT: Cyber Insurance Premiums Rise Amid a Flurry of High-Profile Cyberattacks

View Details

One of the things that have caused a shakeup throughout the IT world is the mass relocation to public cloud. The promise and perils of cloud computing have impacted the biggest corporations to the smallest startups, starting a maddening shuffle among IT teams.

The new swanky style of networking, cloud’s fancy word salad, and the rise of an army of cloud engineers, have started a niche battle in which old ways are being met with skepticism. For networking engineers, the new ways that originally spun off of the old methods are questionable.

At the recent Networking Field Day event, Tom Hollingsworth, Event Lead, and the panel of attending delegates, sat down to settle if cloud networking is just a misnomer for traditional networking, or is it a new discipline ready to take IT by storm.

A Problematic Approach“Networking by itself doesn’t really sell. “Cloud” is a more marketable term,” points out David Varnum, Network Engineer, Architect and Blogger.

Cloud services are intelligently developed. They are intuitive and hyper-personalized to meet business outcomes. The behind-the-scenes working of it too is different to a significant extent.

But on the inside, cloud operations is being handled in an alarmingly cavalier manner. The roles are muddled up, and there are way more generalists than specialists. “Apparently, there are database experts, storage experts, computer experts, whom we were relying on to configure security groups with Internet-facing stuff correctly.”

This is precarious considering the security risks. “I’m not sure that I have expertise in all of those. I’m pretty sure most of the people setting up, as well as the other people in my company, don’t either. The problem becomes how do you get oversight of that?” he argues.

There is a new-found appreciation for clear-cut roles, or niches, among the networking teams. In cloud organizations where roles are overlapping, employees are compelled to take on unfamiliar challenges outside their sphere of comfort and that isn’t always beneficial. Along the way comes the inevitable moment where something breaks and sends everything into a tailspin.

For damage control, there is a number of how-to guides, templates and runbooks for handholding, but without the basic understanding, one can only go so far. “A lot of cloud engineers that are cloud engineers first, don’t really understand all of the concepts, the background of networking which is a dangerous thing. They might be setting things up, but not really know what it’s doing because they’re only clicking. They might not have the education,” says Rita Younger, Network Engineer and Architect.

Errors are rife as a result, and there is normally a dollar amount associated to that. In the cloud where resources cost a fortune, that is not a small dent. IT blunders cost businesses thousands of dollars in losses, not to mention undo FinOps’ efforts of cost-containment.

Silos Are Good SometimesIT is a niche domain, and in the datacenter world, that translates to silos. “Everyone has their own little fiefdom, and that’s why we haven’t seen the success of on-prem products that are supposed to be used to manage the cloud environment,” adds Younger.

While everybody stays inside their own area of specialty, the network is the fabric that connects all individual disciplines. “I think it’s a cultural issue. Really it comes down to no one wants to let anyone else touch their little domain,” says Dakota Snow, IT veteran.

The downside of doing things by template without having deeper knowledge of it is that troubleshooting becomes that much more difficult.

“You don’t have to have those skills to be able to start. If you really want to make this a long-term career and grow and make big dollars, you’re going to have to know those things,” says Snow.

Where the rest of the cloud army chooses fast and easy, it falls on the networking team to pick up the mess left behind from taking shortcuts. “It’s all about doing the most amount of work that you can as quickly as possible and using the least amount of resources,” says Hollingsworth, former network engineer.

Organizations have started looking for multiple competencies in recruits, giving rise to a trend called full-stack engineers. With skills spanning multiple domains, these professionals can work both at the front and backend indiscriminately, understand the bigger picture and resolve issues in a heartbeat, gaining time, and enhancing efficiencies.

But frankly, the idea of building a resilient workforce where everybody possesses multidimensional skills is a tad fantastical. The trend has decimated the desire for specialization, and instead go for a generalized understanding of everything.

Wrapping UpIt pays to harmonize different approaches and foster a culture of cross-functionality within the organization so that collaborative development is the prominent spirit. Such an approach breaks down departmental boundaries and siloed mindset, and encourage individuals to merge ideas and insights, take on more challenging tasks, and make decisions consensually.

Cross-functional teams translate to one overarching cross-functional unit where every professional, irrespective of their domain and level of proficiency, fits in. And the cornerstone for that is to sign up for new skills. It might seem like a chore, but learning new things along the way only helps reduce the struggle to keep up and make one more prospective to organizations.

For more, watch the Delegate Roundtable and other interesting presentations from this past Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Dissecting Cloud Networking

View Details

Grab your rabbit’s foot and your four-leaf clover because we are back with Mobility Field Day 11! We’re going to be talking about all kinds of lucky things, like lucky number 7, in addition to the hottest technologies in the wireless and mobility space. We’re even going to be talking about AI!

Mobility Field Day Event ScheduleWe have two action-packed days full of great content. Wednesday, May 15 kicks off with a presentation from Juniper Mist. They have three hours to talk about their latest advancements in all areas of networking. Be sure to tune in to hear what they’ve been up to. The afternoon on Wednesday kicks off with Fortinet, who will be talking about Wi-Fi 7 as well as some other exciting fortuitous developments on their product side. Wednesday wraps up with a presentation from Celona. They’ll be showing off their vision for 5G LAN and how companies can take advantage of this hot new tech.

Thursday, May 16 starts up with a presentation from our friends at Arista. They’ve been one of the most popular presenters of the past at Mobility Field Day and there are sure to be lots of questions for their team. They are followed by Cisco who had an incredible outing last fall and will be bringing top-tier presenters to the lineup once more. After lunch we will be getting a special introduction session with eino, a brand new company matching wireless design with AI to produce some amazing results. Make sure you are ready for that ride! The final presenter on Thursday is one of the most requested in Field Day history: Ubiquiti! We finally have them sitting down with our delegates to discuss their approach to wireless and networking and show off their features.

Join the ConversationMobility Field Day will be streaming live May 15-16 on the Mobility Field Day event page. You can watch the video stream and leave live comments on the Tech Field Day LinkedIn page as well. If you want to connect with us on X/Twitter or on Mastodon, make sure you’re using the hashtag #MFD11 to make your voice heard. And if you miss any of the excitement bookmark the Tech Field Day Youtube channel and subscribe to be notified when the replay recordings are live. We hope to see you at Mobility Field Day!


© Gestalt IT, LLC for Gestalt IT: Mobility Field Day 11 Is Your Lucky Day!

View Details

As artificial intelligence is rapidly advanced and deployed, the infrastructure supporting training and reference data has emerged as a critical foundation for success. Advanced storage solutions are required to support the intensive demands of AI applications for speed, efficiency, and scalability. This gives rise to the concept of “AI Data Infrastructure,” storage and data platforms required to support AI applications. Throughout 2024 we are exploring the relationship between AI and storage, from a series of articles following AI Field Day through a season of the weekly Utilizing Tech podcast through the summer, to a Tech Field Day event focused on AI Data Infrastructure in October. We are learning about AI data infrastructure from our peers, key companies like Solidigm and their partners, and end users deploying modern AI solutions.

The Crucial Role of Storage in AIAI applications are notorious for their extreme I/O demands, requiring robust and responsive storage solutions to function optimally. Jim Czuprynski in his article highlights the complexity of AI workloads and their storage needs, particularly emphasizing the economic impact of underutilized resources: “An idle GPU is one of the highest infrastructure debts in the enterprise AI computing landscape.” This truism came up throughout season 6 of Utilizing Tech as well, where the conversation frequently returned the need for storage that not only keeps GPUs continuously busy but also handles different data access patterns efficiently.

The performance of AI systems is directly linked to the efficacy of the underlying storage technology. Efficient storage systems ensure that AI models operate without interruption, a critical factor in environments where downtime can mean significant financial losses. Jeffrey Powers notes that “storage needs to run efficiently, and at speed, so that GenAI models can run optimally without stopping even for a second.” The emphasis on speed and efficiency reflects the direct impact of storage performance on the overall effectiveness and reliability of AI applications.

Advancements in storage technology, particularly through companies like Solidigm, have been pivotal in meeting these AI demands. As discussed in Ben Young’s article, NAND flash storage devices (SSDs) are preferred due to their large capacities and efficiency advantages over traditional hard disk drives: “Big storage capacity ensures that there is enough space to house the burgeoning datasets that are utilized in the AI workflow.” Expansive and scalable storage solutions are required to accommodate the growing data requirements of AI systems.

Integration of AI Data InfrastructureThe management of AI workloads requires a structured approach to data handling, which is facilitated by advanced storage architectures. Andy Banta details how Supermicro and Solidigm address these requirements through a tiered system architecture that optimizes data flow from ingestion to processing and long-term storage. This structured approach ensures that each phase of the AI workflow is supported by appropriate storage solutions, enhancing the efficiency and speed of AI operations.

Sustainability is an important aspect of modern IT infrastructure, and this is especially true of power-hungry AI deployments. The partnership between Supermicro and Solidigm focuses on creating environmentally friendly datacenter solutions. These solutions not only meet the demanding requirements of AI workloads but also significantly reduce energy consumption and physical space requirements, aligning with broader environmental goals.

As Colleen Coll discussed, the relationship between AI development and storage technology is complex. As demonstrated throughout Solidigm’s presentation at AI Field Day, each phase of the AI pipeline (from data ingestion to inference) has specific storage demands. Storage isn’t just a repository but a dynamic component that must be tailored to support the intensive and varied data handling requirements of AI systems.

Diving Deeper Into AI Data InfrastructureLooking ahead, we will continue to explore the role of AI data infrastructure through Season 7 of Utilizing Tech as well as at our upcoming Tech Field Day events. As AI applications grow more complex and data-intensive, the need for innovative storage solutions that can handle massive datasets, ensure high-speed data access, and provide reliable and sustainable operations will only intensify. The insights from the Utilizing Tech podcast and the contributions of Solidigm and their partners will be crucial in navigating these challenges.

The integration of advanced storage solutions into AI data infrastructure is fundamental to the success and scalability of AI technologies. Efficient, scalable, and sustainable storage solutions are not merely supportive elements but are central to the operational excellence and innovative potential of AI systems. As AI continues to transform industries, the evolution of AI data infrastructure will play a pivotal role in enabling these technologies to reach their full potential, driving forward the next generation of technological advancements.

For more on Solidigm and their products, head over to their website. You can watch their AI Field Day presentations on the Tech Field Day website. Solidigm is also featured on our current season of Utilizing Tech and will cohost our next season beginning June 6, 2024.


© Gestalt IT, LLC for Gestalt IT: The Critical Role of Advanced Storage in AI Data Infrastructure

View Details

Since the advent of cloud, experts have been working on figuring out ways to secure data in the cloud estate. Several practices and technologies have been put forward, but security in the multi-cloud era remains a costly venture, one that is both complicated and cumbersome.

“You can have multiple touch points in the cloud. It’s not only your application that’s utilizing your data. There could be external entities accessing it too. Or, you could have multiple internal services, instances or users that are utilizing the data. The identity control plane is vast,” says Vinayak Shastri, Product Line Manager at Palo Alto Networks, at the recent Security Field Day event.

Sensitive Data Assets Are Scattered Across the Cloud EnvironmentCloud data stores are frequently the target of cyberattacks. “Each application or a microservices app has at least ten different data stores, and within a product, we’re talking hundreds and thousands of applications,” Shastri explains.

The math is simple. When each application touches several data stores, and given the prolific number of applications organizations own today, the sum total is massive. The cloud stores lack dedicated security solution making them vulnerable to data exfiltration threats and tactics.

The question that is becoming increasingly pivotal is how can one sidestep the intricacies of cloud and keep data safe while still ensuring that it is easy to access.

With cloud storage tightly integrated in all aspects of business, organizations are syncing more data than ever before. Stats show that about 40% of cloud resources are data assets, and every enterprise keeps approximately 20+ types of data assets.

With Prisma Cloud, Palo Alto Networks offers cloud-native security for applications. “We’re able to correlate risks across the application lifecycle so that you’re able to take what you know today, correlate it back to secure everything from code to cloud,” says Mohit Bhasin, Sr. Product Marketing Manager of Prisma Cloud.

As far as keeping data secure, Prisma Cloud does a dandy job of containing risks and keeping secrets secret. But more is required to prevent the ultra-sophisticated data-related crimes of now.

Bhasin reminds, “It’s not enough to know where the risk is in production because, at the heart of most breaches, attackers are looking for data and trying to exfiltrate it.”

Data-Centric Security with Palo Alto NetworksTo complement the existing feature-set, Palo Alto Networks recently integrated two critical capabilities, DSPM (Data Security Posture Management) and DDR (Data Detection and Response). Its acquisition of a company called Dig Security that specializes in Data Security Posture Management (DSPM) marked the first steps to it.

“Everything maps back to data,” says Shastri. “Data is your crown jewel and application is your level-1 information.”

In the cloud environment, the most failsafe way to prevent or minimize data loss is by enhancing visibility and putting controls in place that ensure effective posture management.

Palo Alto Networks’ is a no-agent, no-proxy solution that discovers data stores across the cloud and identifies various data types. Its core function is to provide visibility of all data assets including shadow data that exists outside the purview of IT teams.

“We don’t need an administrator to provide us a temporary password to databases. We can automatically read the data in the database as we get more information.”

Palo Alto Networks’ DSPM goes beyond the policy level and reviews access controls and configurations showing where in the cloud vulnerable data exists and how it is being utilized. “Say you come up with a set of risks, how do you prioritize severity and what is of value and what data should you be saving.”

This is backed by the second piece, Data Detection and Response. DDR enhances DSPM’s capabilities with real-time monitoring and alerting. SecOps can avail a single threat model across various environments to discover insider threats and respond swiftly through prioritization of issues based on severity.

To learn more about Palo Alto Networks’ DSPM and DDR capabilities, check out their presentations from the recent Security Field Day event. Also be sure to give Krista Macomber’s review a read on The Futurum Group website.


© Gestalt IT, LLC for Gestalt IT: Palo Alto Networks Enhances Cloud Data Security with DSPM and DDR

View Details

A feeling of impending doom looms as cybercriminal gangs take companies out one by one in the wake of AI explosion. Ultra-sophisticated threats have begun to emerge propelling their nefarious schemes forward.

At the Security Field Day event in California, the attending panel of delegates saw a solution in action that thwarts attempts of attack with the highest degree of confidence.

The Problem with One-and-Done SolutionsCISOs are responding to the growing cyber risks by allocating bigger budgets to tools meant to contain the damage. But as ransomware and malicious attacks become everyday menaces, increasingly businesses need a technology that can protect the perimeter as well as it can protect itself.

Often a one-and-done solution quietly turns vulnerable to manipulation and abuse by bad actors. Index Engines’ CyberSense puts an end to that risk. Jim McGann, Vice President of Strategic Partnerships at Index Engines, showcased this groundbreaking technology that can discover malicious code in the stack with 99.5% accuracy.

Signature Scanning Is Not AdequateThe biggest cyberattacks in the history all started with an oversight. Cybercriminals slipped in rogue software in the data. The intended purpose of the program was to evade detection and bide time. Like a ticking timebomb, this virus made the most impact when enough time had passed.

The common methods of discovery rely on signature-based detection, a technique that has proven effective only 50% of the time. Signature scanning involves looking for malicious footprints matching against a predefined repository of signatures known to the tool. But with threats reaching an overwhelming volume, it proves ineffective in spotting the newest and the sneakiest strains.

“Realize that folks that are bad actors have a bag of tricks. They have this whole shelf of stuff that they can use, and with the help of GenAI, they can modify and create new ones,” McGann says.

The stealthiest, most clever threats to exist today – the AlphaLocker, a new ransomware family, and WhiteRose, a ransomware-type virus that can evade detection owing to its ability to perfectly camouflage, are examples of this.

These programs execute corruption in a slow and methodical order that light-weight analysis tools and techniques fail to catch.

A category above this are the ultra-sophisticated variants like Xorist, Chaos and LockFile. These don’t leave behind fingerprints the way most viruses do, and are hence, devilishly harder to spot. “They represent about 60% of the variants that are being used,” he informs.

CyberSense for Maximum Detection AccuracyCyberSense provides in-depth defense against small breaches to shockingly large ones. Notable for its ML-based detection and depth of inspection, CyberSense analyses and detects corruption hiding deep within the data. It can sense atomic malicious changes as easily as the conspicuous ones that operatives can never spot.

“We can’t do manually what CyberSense does,” says McGann. “It needs automation, intelligence. It processes millions of data points.”

A misinformation companies are told often is that databases don’t get attacked. The reasoning being, corrupted databases cannot run and administrators will know at once that they are under attack. That’s not remotely accurate, says McGann. Databases too can be the hiding ground for suspicious objects that let it run as usual without giving away signs of attack.

CyberSense performs deep inspection of everything, starting with databases to the core infrastructure. It observes data, snapshots and backups, over time, to spot signs of corruption like encryption, mass deletion and suspicious changes.

“CyberSense is looking for corruption, not necessarily ransomware.”

For razor-sharp detection, CyberSense relies on machine learning. Its defining characteristic is broad training data and continual upgrades. Internally, Index Engines uses online subscription services like VirusTotal that analyzes suspicious files to diagnose the type of virus. This is topped with global research studies and anonymized customer data.

On the customer side, it scans files and databases in depth, meticulously inspecting all elements – the header, content and metadata. This produces millions of datapoints that provides fuel for the CyberSense AI engine to turn to insights.

Inside the CyberSense Lab where all the processing and analysis happens at the backend, ransomware behaviors are studied and classified into 5 categories based on their core behaviors. Latest ransomware variants are picked up from Index Engines’ dirty network and user data.

CyberSense Analysis is applied to this data. The ML operating behind the scenes runs through over 200 content-based analytics, and performs pattern recognition pushing out analytics.

“With CyberSense, when you scan data, every file, whether it be a PDF or Word document or the actual ransomware, gets a signature assigned to it so that when you’re in the recovery process, you could upload signatures into the CyberSense index and it’ll tell you if any of those signatures exist in the backups.”

As CyberSense detects a corruption, alerts bubble up on the dashboard with a complete post-attack forensics report attached showing details about the attack scale and blast radius. To accelerate recovery, the report also contains a listing of the last-known good backup to initiate recovery to.

For more, be sure to watch Index Engines’ presentation on this from the recent Security Field Day event. Krista Macomber’s report provides insights on the market trends and detection capabilities around ransomware that can be read on The Futurum Group website.


© Gestalt IT, LLC for Gestalt IT: CyberSense’s AI-Based Detection for Maximum Confidence

View Details

Business trends have expanded the attack surface, creating new vulnerabilities in the network. Cybercriminal gangs are rapidly adapting their techniques to tap into these vectors. The emerging risks prompt next-generation countermeasures that can close security gaps at source.

For the past fifteen years, Aryaka has built a robust network that provides reliable connectivity and guaranteed performance to businesses across continents. Now they have layered in security to provide a unified solution that delivers security-driven networking.

At the recent Security Field Day event, Aryaka presented Aryaka Unified SASE as a Service. With this solution, Aryaka promises to provide customers agility, simplicity, performance and security, all in one package.

Security Tool Sprawl, and the TradeoffsWhen fighting novel threats, organizations quickly turn to new tools and technologies. A downside of that strategy is snowballing complexity debt. Too many point solutions that are loosely integrated cause operational complexity and friction. The debilitating effects include deployment slowdowns and subpar user experience. Specialized skills and consulting services are required to navigate these on a day-to-day basis.

“You may build some amazing technological things from a security perspective, but unless you can actually be in the traffic and do the enforcement, none of it matters,” says Renuka Nadkarni, Chief Product Officer.

Aryaka Unified SASE as a ServiceTo get the tool sprawl under control whilst guaranteeing security, Aryaka proposes converging network and security technologies. This vision came to fruition in the Aryaka Unified SASE as a Service solution.

This framework brings together a highly performant network and tight security controls in a cloud-based model. The solution combines in-depth security capabilities. Typically, miscellaneous solutions deployed in the network, like, secure web gateway (SWG) and Cloud Access Security Broker (CASB), collectively achieve three common outcomes – access control, threat protection, and data protection.

“It’s not that we don’t have enough security technologies available. Access control, threat protection, and data leakage prevention have been around for more than a couple of decades. The problem to solve for is how do we make them enforceable and effective,” Nadkarni points out.

Aryaka Unified SASE as a Service covers all three bases of networking, security and observability. This is accomplished via a trifecta of solutions, namely the Aryaka OnePASS Architecture, the Aryaka integrated security network and observability services, and the Arkaya delivery options.

At the core of this solution is the Aryaka Zero Trust SD-WAN that forms the underlying network. A global private network, this zero-trust backbone delivers performance through the first, middle and last mile.

“We call it zero-trust because you cannot get on our backbone infrastructure unless we know who you are. There is an implicit zero-trust concept because we provide global connectivity for users.”

Having a performant and reliable connectivity layer that offers guaranteed bandwidth for its users provided Aryaka a solid foundation to build a complete SASE solution on. “From the security standpoint, there’s only a finite number of things that you can do. If you are actually the network layer, the plumbing, and you can look at every single packet that comes to you, the amount of things that you can do is limitless,” Nadkarni says.

Zooming in on the ComponentsPowering the Unified SASE as a Service solution is a key component called the Aryaka OnePASS Architecture. PASS stands for performance, agility, simplicity and security. This is a purpose-built architecture that comprises a unified control plane for configuration and observability, a distributed data plane across datacenter, branch, SaaS, etc, and single pane-of-glass management.

OnePASS allows every data packet to be inspected and processed extensively in one pass, without going through screening twice. It’s Run-to-Completion Model ensures that every flow runs through all SASE functions – Firewall as-a-service (FWAAS), SWG, Cloud Access Security Brokers (CASB), anti-malware, IPS and more – through a single SSL decryption, thus delivering maximum security end to end. Policies are enforced completely at the branch without any performance impacts.

Integral to the single-pass design is the Aryaka Network Access Point (ANAP), their edge appliance line. The APs aggregate several WAN connection, and offer networking services like deep packet inspection, traffic management, and encryption, in a bundle.

A defining feature of the Unified SASE solution is the Aryaka hyperscale Points-of-Presence (PoPs) infrastructure. The PoPs are distributed strategically across six continents to provide users optimal access to cloud, datacenter and SaaS applications.

End-to-end visibility is rendered via a co-managed portal that collects insights and alerts in real-time, bringing together a full picture of things including configuration, management, performance and risks.

These are topped by Aryaka’s unique delivery model that offers businesses flexible ways to consume the solution.

Nadkarni notes, “Sometimes customers know what the problems are, but they have a skill shortage, or budget constraints, or deployment problems in remote locations.”

That’s where Aryaka really shines. “ We hold customers’ hands through the SASE journey, helping them deploy these security controls and design best practices, as well as manage them.”

Aryaka’s Lifecycle Services make all the difference in adopting and integrating SASE easily in the existing infrastructure. These include everything from design to implementation, orchestration and management.

Aryaka’s implement choices include self-managed, co-managed and vendor-managed options. Customers can deploy Aryaka products and services exclusively, or use a mix of Aryaka and third-party solutions based on deployment requirements.

To get a deep-dive of the Unified Aryaka SASE as a Service architecture, make sure to check out Aryaka’s presentations from the Security Field Day event.


© Gestalt IT, LLC for Gestalt IT: Aryaka Launches Unified SASE Delivered as a Service

View Details

In a rapidly evolving tech landscape, the intersection of AI and storage is becoming increasingly pivotal. The storage infrastructure plays an outsize role in optimizing AI workflows. From efficient checkpointing mechanisms to scalability, to high throughput, a good storage solution provides all the imperatives to tap into artificial intelligence.

To delve into this intricate overlap of the two domains, Roger Corell, Director of Solutions Marketing and Corporate Communications at Solidigm, and Subramanian Kartik, Global VP of Systems Engineering, for VAST Data, sit down for a chat. Their conversation explores the multifaceted phases of the AI pipeline, and the corresponding storage demands.

The Five Phases in an AI Pipeline“Storage plays a pivotal role in the efficiency and performance of AI workflows, encompassing the diverse phases from data ingestion to inference,” comments Kartik.

There are five distinct phases in the AI workflow –

  • Data Ingestion: It is a critical process where raw data is pulled from multiple sources for processing and analysis. This phase involves heavy inbound writes. Data is typically sourced from cloud repositories or internal databases.

“Efficient handling of large datasets is crucial to ensuring smooth operations,” says Kartik.

  • Data Preparation: In the second step, the data is cleansed and normalized before being pumped into the model. “Data tends to be dirty and needs to go through normalization of some kind,” Kartik explains.

It is predominantly CPU-bound, and despite substantial reading, the volume of data written back is significantly less at this stage.

  • Model Training: This where the learning begin. Model training necessitates random IO patterns to prevent model memorization. Optimal batch sizes and GPU utilization are key factors influencing model convergence.
  • Model Checkpointing: The neural network’s weights and other parameters need to be preserved periodically as training continues so that it can be rolled back to a previous state if anything goes sideways. This phase involves large block sequential writes. Efficient IO operations are critical in minimizing downtime and data loss. The caveat though, is, checkpointing doesn’t always work. “Bad things happen,” says Kartik.
  • Inference: If everything goes right, at this point, the model should be able to make inferences from data. Primarily IO-bound, inference demands high-throughput reads, especially with larger datasets. Efficient storage performance is essential, particularly for tasks like image generation.

The significance of a robust storage solution in optimizing these phases is undebatable. Notably, Solidigm’s architecture provides certain unique advantageous in handling AI workloads’ asymmetric demands. Designed to support data and read-intensive workloads, its superior read capabilities, high capacity, endurance, and overall efficiency, are key to enhancing processes like checkpointing and inferencing.

ScreenshotSSDs for AI Data StorageUnderstanding and addressing the storage challenges inherent in AI pipelines is critical for organizations in the frontline of innovation. At the AI Field Day event in February, Ace Stryker and Alan Bumgarner built on Kartik’s point in their presentation that underlines the need for a robust storage to handle AI’s data explosion.

Their presentation highlights SSDs as game-changers for AI workflows – from data ingestion to real-time inferencing – echoing Kartik’s insights on scalable architectures and efficient checkpointing.

ScreenshotWrapping UpIn the realm of AI-driven transformation, Kartik’s breakdown paints a clear picture of how computational power and storage go hand in hand. Each AI phase has a mix of hurdles and opportunities, which underscore just how crucial storage is in the making or breaking of the workflows.

Businesses need top-notch storage that can handle this flood of info. Whether it’s gathering data, or making sense of it all, AI’s success hinges on storage that’s tough and flexible. And as deployments get more intricate, companies need to rethink how they approach storage altogether.

Give the conversation a listen at Solidigm’s website. For a technical deep-dive, be sure to watch Solidigm’s presentation from the recent AI Field Day event.


© Gestalt IT, LLC for Gestalt IT: The Intricate Relationship of AI and Storage

View Details

Organizations all over the world are getting hit by ransomware. A cyber threat report published by SonicWall states that over 300 million ransomware attacks were recorded in just the first half of 2021. Although the number tumbled slightly in 2022, attacks went back up in 2023 by a shocking 37%. The volume of double extortion and repeat attacks too is spiraling.

Zerto is one of the companies in the cybersecurity front that is keeping the fight against ransomware going with increasingly sophisticated security solutions. At the recent Security Field Day event in Silicon Valley, the company showcased two solutions within the Zerto Platform that isolate and lock data from bad actors, making recovery swift and unfussy.

Zerto’s Core DR TechnologiesAfter an attack has run its course, it takes a tremendous amount of cleanup to get things back to the former state. It is a slow and punishing undertaking. Just conducting a thorough investigation alone takes weeks. The hardest part of all is to push the recovery efforts in a level-headed manner.

Zerto takes a proactive approach for dealing with ransomware crisis. It believes that there is value in keeping data in. As a disaster recovery solution provider, Zerto leans on data replication. Data is continuously copied and written to a storage in a secondary location. This allows granular recovery, ensuring little to no data loss.

To take it a step further and provide continuous data protection and enable recovery to any point in time, Zerto offers journaling as opposed to traditional snapshots. Zerto journals are dynamic logs of changes happening at the VM level. A user can set up the journal history to up to 30 days, and Zerto will automatically checkpoint the data at an interval of 5 to 15 seconds. Journaling tapers down the storage expense, which is typically high with snapshots, and allows full recovery of files to sites within seconds.

Zerto Public Cloud Isolation and ImmutabilityBut once attackers make their way into the environment, they can seize control of the journals, and make recovery extremely complicated. So, as an extra line of defense, Zerto offers Public Cloud Isolation and Immutability. This capability produces immutable copies of the journals and saves them in public cloud.

The copies are taken straight out of production VMs, and therefore no impact is made on the workload performance.

“It doesn’t impact the production workloads because we are not stopping them to pause to snapshot. We are taking it out of a copy that we already own in our environment on a secondary or local site,” says Sr. Technology Evangelist, Chris Rogers, during the presentation.

This copy is secured with an object lock. “It’s your last line of recovery. It’s probably not something you are going to do every 10 minutes,” reminds Rogers, “But you can. It’s completely down to the customer.” The standard frequency is once every day.

Marked as immutable on a different format of storage, this repo comes handy when data needs to be recovered. The repo can be remounted to a clean infrastructure, where all the VMs can be pulled back from that point in time.

“In this case, the RPO will obviously be longer than a few seconds because Zerto is taking those copies on a periodic instance, but if you can’t recover using the journal, this is a great option, and it is relatively low cost,” he says.

This repo can be optionally disconnected to prevent infections.

The capability comes at no extra cost to the users. It is bundled with the Zerto license. The only thing they need to pay is for storage in public cloud.

Zerto Cyber Resilience VaultThe second feature is the Zerto Cyber Resilience Vault, a fully isolated, air-gapped and immutable data vault that keeps data safe from ransomware. Leveraging Zerto’s data replication and journaling technologies, the Cyber Resilience Vault is customers’ “last resort in worst-cast scenarios”.

“This isn’t bolting on other bits and pieces in our existing platform that we had. This is purpose-built for cyber recovery. The vault is for the most sophisticated and large-scale attacks,” says Rogers.

Unlike a backup appliance, the vault sits on a production-based infrastructure architected with HPE Alletra and ProLiant for storage and compute, HPE Aruba Networking, and the Zerto recovery software on top. “It’s not slow and low and deep-capacity. This is all-flash hardware.”

ScreenshotRogers offered a quick peek of the architecture which comprises a landing zone to land the data in, and a collocated vault zone, which is a clean room where data is stored with no access to the Internet or the production network.

Restores are hands-off for maximum convenience. Located at the bottom left side of the UI is the Failover button that lets users start the failover by selecting the VMs or applications and the exact point in time they want to recover to. Zerto automatically sets up the VMs on the chosen storage on the network with the right IPs.

DR testing is undisruptive in Zerto’s on-demand sandbox. “We failover VMs while production is still running, in an isolated environment, then attach the replica disks to those, and create a scratch volume which is a temporary volume. Users can go can do whatever they need to do in this massive sandbox environment.”

Rogers informs that customers perform over 18000 DR and cyber resiliency tests in them monthly. The average RTO they experience is 3 minutes and 19 seconds, which is massively time-saving.

“We still maintain that 5 to 10 seconds RPO across all of those virtual machines that are testing at the same time,” says Rogers.

Additionally, the sandbox can be used for patch testing, vulnerability scanning, data analytics, and data forensics.

For more, be sure to watch Zerto’s in-depth presentations and demos from the recent Security Field Day event.


© Gestalt IT, LLC for Gestalt IT: Zerto – Ransomware Protection through Data Isolation

View Details

AI’s complex workloads require extreme computing, the kind that only the fastest accelerators are known to provide. It is little surprise that GPUs (Graphics Processing Units) have emerged as the holy grail of compute as AI gains ground. But exorbitant pricing and scarce access, not to mention heavy power consumption and cooling requirements, raise barriers for enterprise adoption.

What if IT shops truly didn’t need these silicon beasts for the bulk of their AI works?

An Affordable Alternative for AI Workloads below 20B ParametersIntel has closely followed the GPU trend over the past few years. To gauge the depth of need of GPUs for AI workloads, the teams have run a series of trials, and they’ve arrived at an interesting conclusion. Based on their findings, CPUs can accommodate almost all AI workloads, with the exception of the insanely intense ones.

For example, the most intense large language model (LLM)-based AI workloads, like Meta’s LLAMA2, typically fluctuate within the range of 7 and 30 billion.

Figure 1. The Reality of AI: GPUs Are Needed Only For Insanely Intense Workloads Intel found that a majority of AI workloads remain below 20 billion parameters. The Xeon chipsets meet almost all latency requirements for the general-purpose workloads in that category. There is rarely the need to leverage the massive acceleration of the GPU technology for these AI workloads, Intel says.

Intel shared benchmarks from real-world scenarios to back this up. In one example of an inference-heavy AI implementation, a customer used Intel Xeon CPUs to perform extremely rapid image processing. The Xeon CPU family was able to scale from a not-insignificant scanning speed of 400 frames per second (fps) using 24 AVX2 CPUs, to over 19,000 fps using 64 cores of their AMX-powered Emerald Rapids processors.

The test results revealed that the newest AMX chipsets engineered with power efficiency kept the 64-core configuration’s energy consumption even with the 24 AVX2.

Figure 2. Same Wattage, Dramatically Increased Workloads: 24 AVX2 Cores vs. 64 AMX Cores Another real-world use case Intel shared is of a customer adding speech translation and real-time transcription services to an existing video conferencing offering. Intel engineers put together a solution with just a few additional servers using Intel CPUs.

Figure 3. Handling LLM Demands: Response Time Latencies Kept Below 100 ms (1/10th of a second)This configuration was particularly interesting because it had to deal with two different AI workloads. Imagine translating the phrase “Pleased to meet you, sir!” to Spanish. The latency for the first word returned in the sequence – “Mucho” – tends to be compute-bound because the AI model needs to find exactly the right word. However, retrieving each of the next words that would be returned in the phrase may also depend on contexts, like the formality of the greeting (e.g. ?Mucho gusto! versus ?Mucho gusto, a sus ordenes!) and tends to be a memory-bound operation.

Intel’s hardware solutions work well for complex AI workloads like the above. Intel has heavily invested in native software support for OSS solutions for data analytics, like Pandas, NumPy, and Apache Spark. Likewise, their commitment to support popular machine learning and deep learning toolsets like PyTorch, TensorFlow, and AutoML (Figure 4) go a long way to extend support to the userbase.

Figure 4. It’s Not Just the Hardware: Intel’s Array of Software Support For Analytics and MLTo GPU, Or Not To GPU?Intel positions its current array of Xeon CPU chipsets for organizations that are grappling with the pressures of providing adequate compute power for AI workloads. Only the most intense AI workloads – specifically, those north of 20 billion parameters – require GPU-level computing power. For everything below that, Intel’s offerings appear to fill the bill. Additionally, their deep support for software compatible with common analytics, machine learning, and deep learning requirements, make their hardware a compelling choice.

Be sure to check out Intel’s presentations on CPUs for AI workloads from the recent AI Field Day event to get a technical deep-dive.


© Gestalt IT, LLC for Gestalt IT: Are GPUs Essential for Every AI Problem? Intel Says, No.

View Details

As AI deployments continue to dominate the business scene, companies are recalibrating and adjusting their backend infrastructures to support AI’s lofty demands.

At the recent AI Field Day event, VAST Data presented a Showcase of their newly unveiled DASE (Disaggregated Shared Everything) architecture that cleverly offloads storage services on to DPUs. DASE is an AI cloud architecture that is built on the NVIDIA BlueField Networking Platform. The solution, VAST says, provides extreme performance and QoS for the AI factory.

Powered by the DASE architecture, the VAST Data Platform is a high-performance solution that brings together the best of parallel file system and network-attached storage (NAS). It is aimed at accelerating high performance computing (HPC), and is deployed at many notable organizations, including names like NASA, Harvard Medical School, and NIH.

John Mao, VP of Technology Alliance at VAST Data, and John Kim, Director of Storage Marketing for NVIDIA, gave a quick flyover of the new architecture and its highlights.

Inside the New VAST DASE ArchitectureUnder the hood, the VAST DASE architecture constitutes CNodes for compute, and DNodes for performance and capacity. Disaggregated, they can be scaled independently based on business requirements.

In the new architecture, the VAST CNodes are deployed on the 3rd generation NVIDIA BlueField DPUs residing inside the NVIDIA servers. This brings to life a holistic solution, that, for one, is mind-blowingly simply to operate, and for another, deliver tremendous cost savings.

“We’ve been fortunate to work with a lot of cloud service providers over the last months. We’ve had this idea in the works for quite some time now. We’ve customers like CoreWeave that have deployed this into production” Mao informs.

DPUs are becoming increasingly common in hyperscale infrastructures of late. “When you have a very large-scale cloud infrastructure where every server wants to have accelerated networking, storage, virtualization and encryption, DPUs make sense.”

An equally advantageous attribute of DPUs is functional isolation. DPUs afford these cloud providers the rare ability to offer a host of management and diagnostic functions off of them, without the use of additional container management systems. For tenants renting bare metal servers, “they can make that capability available without interfering with the tenants’ use of the server,” says Kim.

Parallel Data Services for Unprecedented QoSThe VAST architecture uses BlueField-3 DPUs. NVIDIA calls the platform “infrastructure-on-a-chip”. The DPUs provide a software-defined, hardware-accelerated infrastructure connected via Ethernet or InfiniBand. The BlueField DPUs work by offloading and isolating pieces of storage, networking, security and management functions, delivering much-improved efficiency all around.

“This solution, working together with VAST, is one way of bringing that storage and that data right to the compute layer where the GPUs are,” says Kim.

The VAST architecture design entails putting a dedicated NVIDIA DPU inside each GPU server. This allows storage and data processing to be embedded directly in the server unlocking linear data services available inside the client’s own PCIe bus, that can be scaled across thousands of GPUS. By letting each server have its own parallel storage and database container, the contention for data services is entirely bypassed. There is no sharing of the DPU with other machines. The dedicated parallel data services amount to unprecedented QoS.

By design, this architecture offers enhanced security. With data and data management isolated from the host operating systems, the software delivers a protected environment with data and access isolation. It can run NAS, object and database services off of the DPUs, without exposing the underlying protocols and platforms.

The existing VAST Data Platform CNodes are based on x86 hardware. Porting them over to the NVIDIA DPUs frees up a chunk of them that users can either rip out or use up. The free CPU cycles can be used to run AI or other management tasks unrelated to the storage, says Kim.

Trading the x86 servers for the NVIDIA DPUs instantly drops the overall physical and energy footprint of the VAST infrastructure by 70%. When compared to deploying NVIDIA-powered supercomputers with VAST, “the overall the energy savings nets out to be somewhere around 5% of datacenter power which when we are talking in megawatts, is not nothing. It’s a lot – hundreds of kilowatts that you could save by moving to this architecture and deployment model,” says Mao.

Be sure to watch the VAST Data Showcase with NVIDIA from the AI Field Day event for more information.


© Gestalt IT, LLC for Gestalt IT: VAST Data Releases New DASE Architecture Based on NVIDIA BlueField-3 DPU

View Details

Artificial intelligence workloads are taxing traditional datacenter infrastructure in unexpected ways. Their need for faster compute, denser memory, and more direct access to GPUs is breaking the limits of what most platforms are capable of offering.

Supermicro, in collaboration with Solidigm, is taking on this challenge. Their mission is to deliver single-sourced, highly efficient, rack-sized storage solutions for AI workloads. March of this year, they made a joint presentation at the AI Field Day event in California, where Wendell Wenjen and Paul McLeod, elaborated on how they are maximizing storage density in datacenter chassis.

What AI Workloads Look LikeThere is a variety of workloads that falls into a single AI workflow. It starts with data ingestion in which raw data is fetched from a variety of different sources. This includes generated data, media content, telemetry from an array of sensors, and so on. This data can be characterized as unstructured, and growing over time. A scale-out object storage solution is ideal for gathering this data.

ScreenshotIn the next step, data is cleaned and transformed to make it usable. This is often a distributed and iterative process. The storage needed for this is high-speed, indexable, and must offer shared access, like a distributed filesystem.

Once groomed, data is poured into the models, and the training process begins. For the learning process, high-performance access to a variety of concurrent processes is a must, prompting the need for a parallel variant of the distributed filesystem.

Inference cycles are performed on individual nodes drawing on their own dense, speedy storage.

Finding a Method in the MadnessIn a survey conducted by WEKA, a majority of the respondents said that data management is the biggest pain they face for AI and machine learning (ML).

Supermicro and Solidigm have conceptualized a platform that can handle the different AI workloads and meet their changing needs efficiently. It’s a three-tiered arrangement, with GPU-laden servers up top doing the grunt work. These servers make heavy use of High Bandwidth Memory and very fast solid-state drives, courtesy of Solidigm (An example might be the D5-P5430 covered in this article).

The second tier is an all-flash, high-speed storage stack for handling transient working sets for AI and ML solutions. Less compute and inference-intensive than the top tier, these however need much more storage. Once again, Solidigm to the rescue.

ScreenshotThe bottom-most tier is a data lake. This serves as the repository for the source data, if it isn’t culled from other sources (like sensor data, not something scraped off of the Internet). Archived and intermediate results that aren’t being crunched also end up here. This tier may not necessarily be all-flash, but it uses some flash drives for caching.

Making the Dirty Work Clean and GreenHigh on the agenda of Supermicro and Solidigm, is to make AI datacenters green. Solidigm SSDs are already known for their industry-leading physical and power density. These solutions shrink physical footprint by almost 90%, and reduce power consumption by 77%, says Solidigm.

Supermicro is also building systems with incrementally more cores, more PCIe channels, and higher EDSFF drive slots. Additionally, they are running an industry-wide green computing adoption which they predict might save $10B in energy costs each year.

Supermicro platforms now offer GPUDirect storage in which GPUs have DMA capabilities with storage. Combined with higher efficiency processors, these are making power-hungry AI workloads relatively affordable.

ScreenshotSupermicro projects its turnover to reach $14B in 2024, which is double the $7.1B recorded in 2023. In the talk, they attribute this growth to the rising need for AI and ML engines.

ConclusionAI and ML introduces a new and steep set of requirements around processing, memory and storage. Supermicro and Solidigm are making good on their efforts to provide compact, power-efficient, and environmentally cleaner solutions that meet those needs squarely, making infrastructures ready for the future.

Supermicro and Solidigm have a lot more to say on this subject than is covered in this article. So be sure to check out Supermicro’s complete set of AI storage solutions, and for technical details, read their whitepaper on Accelerating AI Data Pipelines. Also check out Solidigm’s presentation on AI storage from the AI Field Day event.


© Gestalt IT, LLC for Gestalt IT: Solidigm and Supermicro Put “Green” in Greenfield

View Details

The rapidly-evolving field of AI relies on powerful computing for tasks like training and making predictions. Up until now, Graphics Processing Units (GPUs) have been the go-to hardware for these workloads. They are powerful, robust and capable of handling complex calculations. But for a minute, let’s explore a viable alternative – the Central Processing Unit (CPU).

CPUs offer significant advantages in cost and availability compared to GPUs. And some new generations of processors packs enhanced compute power to process certain AI applications reliably. But as with most things, there is no one-size-fits-all solution.

ScreenshotDon’t Rule Out the Humble CPU Training AI models typically involves massive datasets and complex calculations. The muscle behind the models, GPUs, have hefty computational and parallel processing prowess to handle this. But now CPUs too are rising through the ranks. It turns out that the modern crop of CPUs proves fairly reliable for a process called inferencing.

Inference deals with using trained models on new and smaller sets of data. The overall computational load is far lower than the training process. CPUs, being more affordable and ubiquitous than GPUs, can be thrown at these smaller problems, especially where the models have been optimized for inferencing on CPU accelerators.

Making the Right Pick is KeyThe choice between a CPU and a GPU for AI inference comes down to three key factors:

BudgetAcquisition costs for CPUs is significantly cheaper taking into account that companies already use CPU accelerators in other aspects of their applications, and they can perform both general compute and inferencing of smaller models or applications with infrequent tasks on them. In the long run, leveraging a single accelerator for varied workloads unlock significant cost-savings.

Workload SizeWhen evaluating workload size, the complexity and size of the model are key considerations. Smaller models have fewer parameters which CPUs can handle efficiently. North of 14 billion, and reaching the trillion parameter range, a GPU is a more suitable alternative.

The frequency of inference is also a deciding factor. For one-time tasks or something that occurs less frequently, CPUs are adequate. But for continuous inference cycles, and applications processing a high volume of users or data streams, GPU’s ability to handle multiple tasks simultaneously is critical.

LatencyRelated to workload size, but more specifically aligned with the application requirements, is latency. CPUs can sufficiently support applications that can tolerate slightly slower processing (inference time), and have proven, for certain workloads, to exceed latency requirements for common user experience guidelines. However, GPU is your best bet if the applications have very low latency thresholds.

The takeaway here is, CPUs are cheaper and more than suitable for trained AI models, especially lighter ones requiring less frequent tasks. By comparison, GPUs are faster, and therefore better suited for highly complex models, big data loads, and situations requiring ultra-fast turnaround.

Intel Is Committed to AIA longstanding leader in accelerators, Intel has big AI ambitions. The company has recently launched its 5th generation of Xeon processors. This isn’t a minor update. Xeon 5th generation reflects a strategic focus that goes much wider than just the generational gains on the silicon.

The 5th gen Xeon is purpose-built for AI workloads from the edge to the datacentre. It delivers a massive 36% performance improvement for specialized AI workloads, unlocked by the Advanced Matrix Extensions (AMX). AMX handles the matrix math operations essential for training and inference. Already proven with large language models of up to 20 billion parameters, it optimizes and accelerates deep learning, delivering impressive vision model performance.

Intel’s commitment to the broader AI ecosystem is equally noteworthy. The company actively collaborates with a growing pool of software vendors and projects to ensure that developers can easily harness the power of the Intel AMX instructions. Their open-source OpenVINO toolkit simplifies AI deployment by optimizing models from popular frameworks like TensorFlow and PyTorch, for diverse hardware platforms.

By actively supporting developers and prepping software for hardware, Intel demonstrates a comprehensive AI strategy that builds upon the strengths of their 4th Gen Xeon processors (Sapphire Rapids) to deliver a powerful silicon-to-software solution for future AI.

Wrapping UpWhile GPUs remain the holy grail for complex AI training, CPUs offer a compelling alternative for the lighter inference tasks. Their affordability, efficiency, and advancements as seen in Intel’s 5th generation Xeon with AMX instructions, make them a strong contender for AI workloads. But the choice between the two boils down to the users’ specific needs, budget, workload complexity, and latency requirements.

For more, be sure to check out Intel’s presentations with partners at the recent AI Field Day event.


© Gestalt IT, LLC for Gestalt IT: Intel Xeon CPUs – How Efficiency Makes It a Top Contender for AI Inference

View Details

It is not news to anyone that AI workloads occasion dramatic surges in compute demands. But there is an even bigger price to pay. Behind the hype and excitement, the hidden truth that IT shops partaking in the AI race know all too well is that the workloads also effect fivefold increase in storage, and massive swells in energy consumption.

The AI Data Snowball Effect“There is nary an area of personal life that isn’t already touched by AI,” remarks Ace Stryker, Director of Market Development at Solidigm, at the recent AI Field Day event in California.

AI has penetrated every sector, and enterprises are bending over backwards to guarantee a rich customer experience.

To make room for AI workloads, big tech companies have announced infrastructure overhauls. Smaller companies too are following their footsteps, expanding infrastructures, on occasions, rebuilding them.

Stryker points out that AI is not monolithic, and these details are dictated by the deployment size and the applications, but one can’t look away from the fact that AI models have become more complex and sophisticated over time, and as a consequence, applications have diversified across lines of businesses.

The bigger AI models are now in the range of trillion parameters, and the data being fed into them has grown commensurately.

“Datasets are growing logarithmically”, says Stryker. “If you’re doing a large language model, a lot of those are built on the common crawl corpus which are web scrapes every three or four months. They’ve been doing it since 2008. Today, the total body of text is 13 or 15 petabytes and rising.”

AI Needs More than Just CapacityThe massive increase in data volume prompts investing in bigger and bolder storage solutions, but there are more considerations besides space. You can always pay for extra capacity, but a better storage makes an infinitely smarter addition to organizations’ bourgeoning AI efforts.

A white paper published by Meta and Stanford University states that storage consumes 35% of the entire server power footprint. That’s not an insignificant number. AI models run on expensive accelerators like GPUs. The bigger the model, the bigger the real estate. Storage feeds data directly into these GPUs giving them the raw material for compute. Any delay in the transfer snowballs the total cost of ownership (TCO) without producing desired outcome.

The stages in which AI happens behind the scenes look something like this. Raw data is culled from various sources and written to the drives. This data is cleaned, normalized and tokenized through an ETL process, before being presented to the model for training.

To make sure that the model can be rolled back to a good previous state in the event of failure, checkpointing is performed periodically. Inputs are fed into the trained models in the inferencing stage.

Across these workflow stages, storage demands rise and fall owing to the workloads’ varying I/O profiles. Some are write-heavy, while others are read-intensive.

Not only do companies need a storage that is affordable to handle this tremendous data influx, but they need one that is souped up for intense performance. This storage can significantly ramp up model development, by enhancing GPU utilization through speedy delivery of data into GPUs.

Currently, HDDs account for the bulk of storage hardware in core datacenters. Big on capacity, these are less expensive and offer access times measured in milliseconds. But HDDs’ bandwidth and latency cannot support the high I/O demands of the AI workflow. Drives running tasks like training, checkpointing and data prepping, in parallel across multiple pipelines, require to be primed for concurrency and multi-tenancy.

To make up, storage teams overprovision the drives, leading to acquisition of more drives to meet the capacity needs.

High-Density QLC StorageSolidigm’s goal is to deliver an industry-leading storage portfolio to the market that not only offers flexible scaling and operational efficiency from core to edge, but also makes AI storage cheaper. Partnering with companies like Supermicro, CodeWeavers, VAST Data and NVIDIA, Solidigm is designing groundbreaking solutions that can set a course all on their own.

Solidigm’s solutions are built with deep capacities and power optimizations. The D5-P5336 comes with a capacity of 61TB, fitted inside a slight 2.5” form factor. Because of their slim forms and high density, datacenters require up to 5.2 times fewer drivers, which amount to 9 times fewer servers, and 9 times smaller rack footprints.

The top-tier storage solutions on Solidigm’s portfolio provide the best performance numbers for massive-scale AI deployments. Data shows that for a 10PB AI data pipeline solution, the D5-P5336 high-density QLC SSDs provide 4.3 times lower energy costs compared to an all-HDD array that translates to a 46% lower TCO across 5 years.

“You’re saving on your server footprint, your datacenter footprint, and your power envelope as well. All of these things feed into great cost savings over the life of the hardware,” says Stryker.

Performance is amplified by the Cloud Storage Acceleration Layer (CSAL) which is an open-source write shaping software developed by Solidigm. “What it enables us to do is take incoming writes and direct them intelligently to one device or another. It appears to the system as one device, but under the hood, CSAL is essentially directing traffic,” he explains.

To achieve max performance and GPU utilization, Solidigm recommends using a combination of the Solidigm D7 – P5810 SLC SSDs for high combined read/write performance, and the D5-P5336 for capacity. This will obviously be topped with CSAL or any equivalent software that can help maintain the high application write performance.

Be sure to watch Solidigm’s presentations from the recent AI Field Day event to get a technical deep-dive. Also check out other Gestalt IT coverage on Solidigm for experts’ insights.


© Gestalt IT, LLC for Gestalt IT: Solidigm SSDs for the AI Era – Small Size, Big Value

View Details

Big, fast, and efficient storage makes the foundation for powerful and adaptable AI systems. It allows you to train on massive datasets, optimize resource allocation to expensive GPU clusters, and prepare for the future demands of AI.

Why Is Big, Fast and Efficient Important?AI models learn and improve through a process called training. It is just one step in the typical AI workflow. Training involves ingesting and processing massive datasets such as text, images, videos, or other formats relevant to the task.

Big storage capacity ensures that there is enough space to house the burgeoning datasets that are utilized in the AI workflow. With traditional hard disk drives (HDDs) topping out around 30TB, NAND storage devices have emerged as the preferred choice. They are over double in size, and have a significantly smaller physical footprint, making a sizeable difference in how storage systems are scaled within the datacentre.

Performance is key in AI. The faster a storage can access and deliver data, the quicker the AI models can train and make predictions. This efficiency is crucial for real-time applications, such as fraud detection, where time-sensitive decisions need to be made. It is equally important during the training phase where large checkpoint files are stored and retrieved from the disk. Slow data access can cost serious money in this cycle due to lost training time. Technologies like NAND storage have significantly faster data retrieval speeds compared to HDDs.

Efficiency is twofold, as it relates to energy-friendly operations, as well as efficient use of space. HDDs rely on spinning platters and magnetic recording heads. The physical size of these components limits how much data they can store in a given space, and the amount of energy they consume. NAND flash storage don’t have spinning platters which translates to lower power consumption and higher energy-efficiency.

NAND flash memory utilizes flash memory chips that are incredibly small, and allows for a much higher density of data storage per unit volume compared to HDDs. This poses a significant advantage for large AI deployments that require constant data access.

Solidigm, a Leader in NAND SolutionsA relatively young company, Solidigm was established in December 2021. With roots running deep in the world of memory and storage, it emerged from a strategic partnership between two industry giants Intel and SK Hynix. Intel’s NAND and SSD business division brought decades of experience in developing innovative flash memory and solid-state drive technologies to which, SK Hynix, a leading South Korean semiconductor manufacturer, added global reach and tremendous manufacturing prowess.

This fusion created a powerhouse in the data storage landscape. Today, Solidigm is a key player in the evolving data storage landscape, and is extremely well-positioned to develop advanced storage solutions. Already the portfolio boasts a large number of market-leading products and solutions. Supermicro, a leading name in high-performance servers, is a top adopter of its SSDs.

ScreenshotSolidigm’s QLC Portfolio for AI WorkThe Solidigm QLC SSD portfolio is designed to meet the demands of capacity and performance needs of AI workloads, all whilst providing crucial performance in workflows like checkpointing and data ingestion and processing.

In particular, the D5-P5336 is a preferred solution for AI tasks. Available in capacities of up to 61.44TB per drive, it comes in a slim E1.L 9.5mm form factor. To give you a sense of the density that can be achieved in this form factor, a 2U configuration can accommodate a whopping 64 disks. That translates to around 3.93PB of raw capacity. There is no getting near to this amount of capacity in such a small footprint when using HDDs. The ruler saves significant money in expensive data centre real estate and related costs like network ports.

The small footprint, however, does not impact performance at all. The D5-P5336 QLC SSD boasts some serious performance numbers to keep those AI workflows running optimally. It offers up to 7,000 MB/s sequential read and 3,000 MB/s write bandwidth. This translates to better user experience and cost-savings which traditional HDDs can’t compete with.

Wrapping upThe exponential growth of AI workloads demands robust storage solutions that are capable of handling massive datasets, and delivering lightning-fast performance. This demand for infrastructure efficiency will push QLCs to the forefront. Solidigm expects QLCs to account for 30% of the drives shipped in 2024.

As AI applications become more complex, and real-time decision-making becomes prevalent, high-density, high-performance storage like Solidigm’s QLC SSD line will take the center stage. By adopting Solidigm’s advanced storage solutions, businesses can gain competitive advantage and significant cost-savings in the AI race.

Faster training times, bumpless real-time operations, and optimized resource allocation contribute to more powerful and adaptable AI systems, and paves the path for ground-breaking advancements in the fields of healthcare, finance, automotives, and more. Solidigm, with its innovative solutions and commitment to pushing boundaries, is well-positioned to be a leader in this exciting future.

For more, be sure to check out Solidigm’s presentations from the recent AI Field Day event.


© Gestalt IT, LLC for Gestalt IT: Solidigm – A Bigger, Faster, and More Efficient Storage for AI

View Details

Artificial intelligence has been the biggest driver of efficiency of our time. The barrage of AI tools and services hard launched in the wake of the success of ChatGPT, speaks to businesses’ eagerness to leverage it for just about anything. But to move AI directly into the enterprise, there needs to be a solution first that provides the foundation-level support.

No other company in the market knows digital infrastructure better than VMware by Broadcom. In the multi-cloud world, VMware is everywhere where businesses are. Amid the worldwide GenAI shakeup, last year, they announced VMware Private AI, a solution that promises to transform the way businesses do artificial intelligence.

VMware Private AI – A Secure and Optimized Digital Foundation for AIVMware by Broadcom has two clear objectives – to democratize GenAI, while addressing the privacy and control concerns around it. VMware Private AI is a product ecosystem that provides the foundation to enable four key enterprise use cases, namely, code generation, IT operations automation, contact center resolution, and advanced information retrieval.

The first code generation use case VMware took on was with an open-source model for the ESXi kernel. “We want to try the most difficult use case with our most opinionated software engineers,” says Chris Wolf, Global Head of AI and Advanced Services, during a presentation at the AI Field Day event in California. “When we started using our internal solution based on the StarCoder open-source model, we had an acceptance rate of 92% software engineers,” he informs.

The advanced information retrieval is particularly useful in call center resolution use cases, in the sectors of healthcare, legal and sales. “Being able to allow your support technicians to get answers more quickly has real business value,” Wolf says.

Wolf outlines the value proposition, and the reasons why people should adopt VMware Private AI. For starters, customers can choose from a wide selection of hardware and software. “Different lines of business have different priorities, or there are different services that just work better for them. Because of that, singular investment in infrastructure allows them to better optimize performance moving across.”

The solution is supercharged for AI workloads. “We offer 5 to 6% better performance than bare metal,” Wolf declares. “That’s strictly attributed to our scheduling algorithms and what we can do there, but you can get all the benefits of generative AI, virtualizing and sharing your GPUs without sacrificing performance,” he adds.

VMware Private AI is also a standout solution where deployment flexibility is concerned. “On the deployment side, we’re doing things that nobody else is doing. We can stand up an AI cluster with your models preloaded into memory in about 3 seconds,” he says. “You can’t do that in the public cloud, not anything remotely close on bare metal. We’ve seen from industry partners that it takes 5 to 7 minutes on bare metal.”

VMware by Broadcom is working with a broad pool of partners to make the concept of open ecosystem a reality. “We are really looking to include our group of partners, and you’ll see more big logos added, going forward this year,” Wolf says.

Circumventing Privacy and Control TradeoffsAs businesses cull vast amounts of data to feed into AI models, fresh concerns have emerged around data privacy and control. Companies are wary about the amount of privacy and security they are giving up in exchange for adopting AI. Accidental data exposure, lack of control, and privacy issues are the top tradeoffs.

The VMware Marketing AI Council is an initiative geared at alleviating these concerns. Promoting ethical and responsible use of GenAI through AI literacy, the council has created a series of guidelines to steer its global marketing team towards responsible engagement.

“We’ve had governance practices that we put into place. It’s an area where we’re ahead of a lot of our peers in the industry that haven’t yet set up that type of governance,” Wolf shares.

The VMware Private AI solution builds on that effort. Under Private AI, VMware currently offers two solutions. VMware Private AI Foundation with NVIDIA is a turnkey solution that provides the foundation for fine-tuning and inferencing workloads. It includes both GenAI software and accelerated computing for maximum performance.

“We’re focused on fine-tuning and inferencing use cases where you gain the biggest benefit from virtualizing and slicing GPUs,” says Wolf.

Anybody starting with the VMware Cloud Foundation (VCF) can layer the add-on capabilities on top of it. “Everybody needs a vector database for RAG applications. That’s going to be the added benefit. You get that full NVIDIA software stack as well. Everything is well-integrated.”

The second solution is the VMware Private AI Reference Architecture for Open Source. It is an architectural blueprint that allows users to leverage all the best-of-breed models, frameworks and open-source projects to address a broad set of business needs.

“Customers can use our reference architecture if they want to take a more DIY approach. We have all of the prescriptive guidance for them,” says Wolf. “But going forward, we want customers to run a really competent IAS first, which is VCF, and then start to layer Private AI on top of that, bring in GPUs, and run AI services. We want to first make that environment super-optimized and efficient.”

There is a host of integrated VMware security features that customers can tap into to ensure privacy and security of their AI models. Solutions like vSphere and NSX present security features like virtual TPM, VM encryption, secure boot, micro-segmentation, advanced threat protection and integrations with VMware and third-party identity managers, for tighter security and better access management.

Aside from NVIDIA, VMware by Broadcom is also partnering with Intel and IBM on the Private AI initiative.

For a more in-depth look, watch VMware by Broadcom’s presentations, or their joint appearance with Intel from the AI Field Day event. Also check out Alastair Cook’s article on The Futurum Group website for the analyst’s take.


© Gestalt IT, LLC for Gestalt IT: Building a Future-Proof AI Foundation with VMware Private AI

View Details

Over three decades, big advances in networking have led the architecture from a foundational 3-tier switching infrastructure to AI-powered predictive troubleshooting. But each step of the evolution has also brought new headaches which have manifested at both the hardware and software levels.

The complexity of the modern network is not defined by how hard or easy the underlying tech is to use. More often, networking professionals are tripped by the sheer number of solutions in the network. The more products there are, the harder they have to work to manage the day-to-day operations.

“For the last 20 plus years, we’ve seen a lot of product-centric innovation. Every single problem that we discovered, whether it comes to wired security, wireless coverage, or integrated deployment management, we’ve thrown a new product at it. That has generally been the motto of innovation,” notes Suresh Katukam, Co-founder and CPO of Nile, at the Networking Field Day event where the company presented its newly unveiled solution architecture for the Nile Access Service.

A Slow-Burning Complexity CrisisToday, a confounding number of self-contained technologies make up the network. Each of these solutions begets a brain-numbing number of overheads, learning curves and subscription costs. The complexity has reached a point where the human mind cannot handle it anymore.

“If you look at an enterprise networking portfolio, you will see multiple generations of products, each running its own software stack. Each software stack requires a different configuration or best practice guide,” Katukam points out. “Trying to stitch together these multigenerational products into an existing facility, you probably need some more instructions.”

The cycle of challenge further escalates the proliferation of services. “Ongoing software and maintenance require some support contract. If you don’t have the IT staff in your team, you might want to sign up to consulting and professional services from your favorite channel partner, or from your favorite vendor. And if you don’t have the capital budget, you might want to sign up for a network-as-a-service offer, maybe even go to a managed service provider.”

An Architecture Designed to Guarantee Network PerformanceNew enterprise networks must guarantee performance outcomes, but incremental product innovation does not necessarily lead to that. For Nile, the new requirements prompt building a next-gen network, but before that, a new solution architecture needs to be designed to deliver it.

“We think that the ten plus steps between innovation and realization are a bit much. We want to shrink that down,” says Katukam.

Nile’s vision to bridge the growing gap of innovation is fulfilled by bringing the principles of cloud delivery to networking. Like cloud, the Nile Access Service is offered as a service for easy consumption. It provides broad automation and observability by leveraging AI, and is zero-trust by design.

The Nile architecture guarantees connectivity, capacity and coverage, ensuring much improved quality of service (QoS). The solution constitutes the Nile Service Blocks that are each a group of physical Wi-Fi switches and access points. Variable in size, these blocks can integrate over ten products each, and can be consumed as a service.

ScreenshotThe second component, the Nile Services Cloud provides deep and real-time observability of the health of the wired and wireless connectivity, and eliminates the potential for future problems. It takes actions predictively to remediate and optimize, ensuring the best state. All of this is covered under a service-level guarantee.

Nile automates the whole middle mile operations. It has automatic activation, and can perform lifecycle network operations.

“Software upgrades, end-of-life, end-of-support – we considered all of those aspects as part of the hardware and software so that all of those challenges are eliminated.”

The solution can identify atomic deviations, and resolve problems proactively, thereby greatly reducing the number of tickets and support workflows.

Nile is deployed on proprietary hardware and software. Nile owns and manages the entire fleet of products. It offers a no-touch software maintenance that eliminates the bulk of operational overheads. Management functions like software upgrades, patching and repair works are taken care of, by default.

Out-of-the-box, Nile offers two AI Apps -Nile Copilot and Nile Autopilot that take charge of things like installation, intent-based provisioning, and the manual functions of the network operations center.

“We have taken the configuration part and moved them into our hardware and software design such that it eliminates the need for you to configure the network level switches, APs, radios or protocols,” informs Katukam.

And unlike most products that have security slapped on as an afterthought, the Nile architecture has security woven into its design.

For more, be sure to check out Nile’s demos from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Guaranteed Performance Outcomes with Nile Access Service

View Details

In this Tech Field Day article from VMware Explore 2023, Sulagna Saha discusses AMD's solution for infrastructure migration. There is more than enough reason for enterprises to modernize legacy infrastructures. With VAMT, now there is a way to tap into the perks of a modern setup without making it a full-time job for the operators, or counting losses through downtimes.


© Gestalt IT, LLC for Gestalt IT: Modernizing Aging Legacy Systems without Cost Creep with AMD

View Details

In this Tech Field Day Extra article from VMware Explore, Sulagna Saha discussed VMare's NSX+ Network Detection and Response Service. Communication gaps between teams and a prevailing lack of context in security policies, further increase vulnerabilities within the system in the form of operational inefficiency and unaddressed threat vectors. Thanks to its correlating capability, NSX+ NDR can visibly reduce the alert overload. From the thousands of events it absorbs from IDPS and NAT solutions in the network, it prioritizes notifications based on relevance and category, and shares the results with the SIEM solutions. SOCs can export both atomic and campaign events to the SIEM solutions for threat investigation and troubleshooting. This not only makes scoping and hunting threats surprisingly simple, but also reduces the volume of alerts, improves accuracy and minimizes false positives.


© Gestalt IT, LLC for Gestalt IT: Rout Intruders with All New VMware NSX+ Network Detection and Response Service

View Details

In this Tech Field Day Extra article from VMware Explore, Sulagna Saha discusses how VMware delivers smart migration with HCX+. The biggest stumbling block that faces organizations’ multi-cloud aspirations is adoption complexity, a thing that is at the root of every new innovation, and hence, is inescapable. With solutions that help abstract away complexities and facilitate uptake, technologies like multi-cloud can enjoy greater adoption. HCX+ is, without a doubt, a key solution for companies trying to walk down the multi-cloud road, going from traditional datacenters to modern cloud platforms. It extends the legacy of HCX, enabling enterprises to cleanly lift and shift workloads to where they perform best, sans the usual troubles and crisis of migration.


© Gestalt IT, LLC for Gestalt IT: Smart Migration with VMware HCX+

View Details

As companies expand their digital footprints, many have fallen on multi-cloud as their go-to strategy. Multi-cloud has opened doors for companies to explore more options, and acquire competitive pricing between cloud service providers, whilst enjoying the best-of-cloud amenities.

Although a winning strategy, multi-cloud is not easy to tap into. It takes training and bandwidth, and even the most well-funded and motivated organizations face surprising standstills along the way. The reason being that multi-cloud migration is fraught with skill gaps, lack of organization, and an ever-widening knowledge gap as more and more cloud vendors pop into the scene.

At the recent Tech Field Day Extra at VMware Explore US 2023, VMware launched a new solution that is designed to iron out of these kinks and unlock a rapid and persistent transition to multi-cloud.

What Does Multi-Cloud Look Like from the Inside?“Multi-cloud is no longer aspirational. It has become a reality. Companies are growing their workloads in their on-premise datacenters, as well as in third-party cloud-managed locations, in native public clouds and retail edge sites,” commented Pooja Patel, Sr. Director of Technical Product Management of NSX, VMware’s flagship network virtualization and security solution.

One of the biggest pains of multi-cloud is lack of standardization. On multi-cloud, every platform has its own set of bespoke capabilities. This causes policy and operations to be fragmented, security controls to be inconsistent, and migration, a nightmare.

These are more than just early inconveniences. Studies have found IT silos to be at the root of operational complexities and security breaches. Companies need to operate off the assumption that these gaps will create significant headwinds in a matter of time.

“When we talk to customers, they’re looking for an easy way to see what is going on in their network, visualize how the security policies are configured, the way flows are going across different clouds, and all this is only possible if you have a common cloud operating model, a product or an offering that provides a single pane of glass to connect, observe and secure all these different silos,” said Patel.

NSX+ is designed in the likeness of this. Building upon the capabilities of NSX, NSX+ brings to offer consistent multi-cloud networking and security delivered as a service. The result is easy multi-cloud consumption through comprehensive cross-cloud visibility, multi-tenancy, persistent security, and most importantly, centralized operations.

NSX+ is VMware’s foray into SaaS-based cloud managed services for the NSX networking and security portfolio, said Patel. “What we are trying to do is help our customers achieve multi-cloud network and security standardization as they go on this journey.”

Multi-Cloud Standardization with NSX+NSX+ brings to the table five key capabilities, aiming to provide one cloud operating model for maximum multi-cloud resiliency, starting with NSX+ policy management.

NSX+ policy management provides a common policy framework to manage multiple NSX locations. Repeatable network designs, centralized policy management and consistent operations are delivered from a single console, ensuring speedy deployment of network across cloud platforms. Users can manage policy configuration of things like distributed firewall, gateway firewall and distributed intrusion detection and prevention service (IDS/IPS), centrally from the console. Built-in network operations inside the console allows operators to see and search cross-site alarms, and perform lifecycle management tasks like upgrading and licensing.

A feature Patel highlighted is multi-tenancy which allows NSX+ users to define tenants spanning multiple NSX sites. “NSX has traditionally provided some form of multi-tenancy, but we did not have true object-level multi-tenancy in the past. With the NSX 4.x release, we have the ability to define multiple tenants, and delegate those tenants to different lines of businesses.”

This is complemented by NSX+ Intelligence, a service that provides visibility into cross-cloud traffic, on-demand access to security management and analytics, and policy recommendations. By offloading overheads and complexities from security operations, this makes it easier to plan and implement security policies.

The visibility is topped with NSX+’s Network Detection and Response (NDR). A threat prevention service, NSX+ NDR threshes intelligence from massive amounts of network data – mapping anomalies and correlating events – providing security teams visibility into attack chains and anomalies, and helping triage threats based on the MITRE ATT&CK framework.

NSX+ ALB (Advanced Load Balancing) Controller Cloud Services reduce complexities in Day 0 to Day 2 operations by mapping applications to infrastructure and simplifying tasks like configuration, upgrades, autoscaling and DR.

The last service on the list is HCX+ which is an application mobility solution offering a set of capabilities that allows transparent migration of workloads across cloud locations.

Wrapping UpThere is one rule that is always safe to play by in IT – keep adapting to the changes, and right now, the biggest change happening is the transition to multi-cloud. VMware NSX+ with its latest features, opens up a direct ramp to multi-cloud, free of complexity and chaos. NSX+ bypasses the passive approach of managing silos which is limiting, and frankly no-longer sufficient. To keep the digital transformation going uneventfully, supporting technologies need to evolve in advance to meet customers’ changing requirements, and VMware is champion for that. With NSX+, it provides a complete solution that gives organizations the tools, the strategy and ultimately, the skill to embrace multi-cloud in a clean and consistent fashion.

Be sure to watch the full presentation for a demo of NSX+. For more interesting presentations from VMware, be sure to check out Tech Field Day Extra at VMware Explore US 2023 at Techfieldday.com.


© Gestalt IT, LLC for Gestalt IT: Adopting a Standard Operating Format in Multi-Cloud with VMware NSX+

View Details

We've been attending VMware's in-person conferences for over a decade learning more about VMware's products and technology every year. We also look forward to connecting with their ecosystem partners and building connections with the vibrant community there. We're happy to arrange interviews, record videos, and even host Tech FieldDay sessions on site with our fellow attendees, including presentations from VMware and AMD. Watch for some great Tech Field Day content on Tuesday August 22nd and Wednesday August 23rd.


© Gestalt IT, LLC for Gestalt IT: Things are Heating Up for Tech Field Day Extra at VMware Explore

View Details

In this Networking Field Day article, Sulagna Saha how Nile has designed the most complete solution to date. By employing automation from scratch, Nile has shrunken the multi-month process of spinning up a new network to just a matter of a few clicks. With features like self-tuning and continuous site surveys running on top of it, NSB ensures that the network is always on and operating at its fullest capacity. Being a full stack solution makes performance predictable, and the engineering teams working behind the scenes do not have to deal with a numbing amount of technical complexity. In its attempt to pull out configuration errors by the root, Nile has designed the most complete solution one could have asked for.


© Gestalt IT, LLC for Gestalt IT: Cloud-Style Networking with Nile Service Block

View Details

In this Networking Field Day article, Sulagna Saha writes on Edge Networking and how it potentially could have the same or bigger impact than edge computing.


© Gestalt IT, LLC for Gestalt IT: Life on the Edge – A Roundtable Discussion

View Details

In this Networking Field Day article, Sulagna Saha discusses how Broadcom’s specialized solutions for AI processing bypass the imposing challenges that stifle enterprises’ AI/ML initiatives. The fabrics greatly reduce networking time with maximum I/O, creating an opportunity for organizations to accelerate training time and ensure faster job completion. In the process, they unlock substantial savings not typically achievable with AI training.


© Gestalt IT, LLC for Gestalt IT: Accelerated Model Training with Broadcom Jericho-3AI and Tomahawk Family

View Details

In this Networking Field Day article, Sulagna Saha discusses how Anuta Networks' Anuta ATOM sobers the demands of automation and helps it reach all corners of the business without seeking big financial commitments. As enterprises look ahead to a future where automation leads the way, they need a tool like ATOM that unleashes its full potential, and help automation be the groundbreaking technology that is meant to be.


© Gestalt IT, LLC for Gestalt IT: Getting Past the Barriers of Cross-Domain Automation with Anuta Networks’ ATOM

View Details

In this Cloud Field Day Tech Note presented by RackN, Adam Fisher discusses how RackN provides IT Ops with a powerful platform to bring infrastructure provisioning up to speed with the demands of modern enterprise IT. The ability for IT Ops to manage infrastructure with cloud-like efficiency powers innovation for the applications that drive a business. The true value of RackN isn’t just for IT Ops or developers; it’s the snowball effect of improved collaboration between groups that ultimately leads to a better bottom line. Digital Rebar is a key to unlocking that value.


© Gestalt IT, LLC for Gestalt IT: Unlocking Developer Efficiency With Self-Service Dev Portals and RackN

View Details

In this Cloud Field Day Tech Note presented by RackN, Adam Fisher discusses how RackN empowers IT Ops with the consistency, efficiency, and flexibility required to manage modern data centers. Multi-site management in Digital Rebar provides IT Ops with a centralized catalog for all infrastructure deployments. Infrastructure stacks can be deployed across different environments with operational control and security, all managed from one platform.


© Gestalt IT, LLC for Gestalt IT: Infrastructure Pipelines Become Reality With RackN Digital Rebar

View Details

In this article from the Security Field Day Roundtable Discussion, Sulagna Saha writes on how companies can systemically remove obstacles and reduce internal frictions that security specialists face daily so that organizations’ cyber resilience is assured at the end of the day.


© Gestalt IT, LLC for Gestalt IT: Ways to Amplify Unvalued Security Teams in Organizations

View Details

In this interview, Tom Hollingsworth welcomes Roy Chua, the founder and Principal at AvidThink, as one of our newest Tech Field Day delegates. Roy shares his background starting as a network software engineer, moving into product management, and eventually transitioning into the analyst space. He discusses the challenges of staying up-to-date with the rapidly evolving technology landscape and how his company focuses on more targeted and cutting-edge areas to add value. When asked about his dream job, Roy expresses a fondness for books and mentions that running a small bookshop would be a really fun job for him. Thanks for joining us at Security Field Day, Roy!


© Gestalt IT, LLC for Gestalt IT: Meet Field Day Delegate – Roy Chua, Founder and Principal at AvidThink

View Details

The summer edition of Networking Field Day is shaping up to be a scorcher! We've got some hot companies presenting and cool delegates ready to join the conversation both on-site and remotely. Make sure you're ready to go for all the excitement.


© Gestalt IT, LLC for Gestalt IT: Summer Field Day Fun at Networking Field Day 32

View Details

In this Security Field Day article, Sulagna Saha discusses NetAlly's CyberScope, a handheld site survey tool that elevates awareness of vulnerabilities, warning users against threats, and helping security teams to manage and minimize risks at minimum impact. Ruggedized for outdoor use, handy, and with a battery life that lasts all day, CyberScope is an instrument designed for smart hands who are out in the field, doing site to site inspection, enabling them to do security scans in one sweep.


© Gestalt IT, LLC for Gestalt IT: Performing On-Site Security Sweeps with NetAlly CyberScope

View Details

In this Security Field Day article, Sulagna Saha discusses boosting observability with Cisco Multicloud Defense and how this solution affords users clear visibility and maximum control, no matter where their applications are. There is no need to drive blind, or settle for siloed solutions that only protect assets in one place. Cisco Multicloud Defense makes the multi-cloud black box transparent and tenable.


© Gestalt IT, LLC for Gestalt IT: Ramping Up Multicloud Visibility with Cisco Multicloud Defense

View Details

In this Cloud Field Day Tech Note presented by RackN, Adam Fisher discusses how RackN changed the infrastructure mindset with Digital Rebar as it enables IT to treat bare metal infrastructure as a disposable commodity. Uptime used to be a metric that proved a server’s usefulness and longevity but as systems run and are patched with layer after layer of updates, sometimes a fresh start is better for overall performance.


© Gestalt IT, LLC for Gestalt IT: RackN Brings Bare Metal Into The Cloud Age

View Details

In this Security Field Day article, Sulagna Saha discusses how Commvault Metallic ThreatWise brings to enterprises a workhorse of a tool that provides the forceful combination of insights and observability which quantifies to effective risk management and broader protection by surfacing threats accurately and early in the chain that other tools overlook and underestimate.


© Gestalt IT, LLC for Gestalt IT: Commvault Metallic ThreatWise – Discerning the First Signs to Quell an Attack Early

View Details

In this Security Field Day article, Sulagna Saha discusses HashiCorp Boundary and how it provides a way to sharpen organizations’ identity metrics, allowing them to standardize a least privileged access model that dynamically authenticates, grants and revokes accesses with the end goal of protecting user identities within and without organizations, and the data and resources in the network. In a time when organizations cannot afford to give in to the temptation of skipping past access security, Boundary offers a simplified way to embrace security automation that covers all connection points and entities with a solid, zero-trust security.


© Gestalt IT, LLC for Gestalt IT: Executing Zero-Trust Security and Building a Protective Perimeter with HashiCorp Boundary Enterprise

View Details

In this Security Field Day article, Sulagna Saha discusses Cribl Search and how it lets organizations get value out of their data without losing dollars. It presents a sustainable way to search a subset of data bypassing the unprofitable and sloppy method of making new copies and taking up expensive storage space every time someone decides to type in a question. Whether data is in public or private infrastructure, this may be the default choice of users.


© Gestalt IT, LLC for Gestalt IT: Querying Data at Source with Cribl Search

View Details

In this Security Field Day article, Sulagna Saha discusses how Noname Security's Active Testing v2 is a clear winner because it enables teams to integrate security organically in the CI/CD processes, and in doing so, it makes it possible to weed out all culprits in the earliest stages of application building, nipping any chances of API exploits in the bud.


© Gestalt IT, LLC for Gestalt IT: Embedding Security in the Code with Noname Security’s Active Testing v2

View Details

In this Cloud Field Day Tech Note presented by RackN, Adam Fisher discusses why Digital Rebar from RackN is such a powerful product. It can be the glue for IT Ops to empower developers to focus on driving business value while providing a consistent infrastructure management platform. In the following posts, I will highlight how the bare metal provisioning, infrastructure pipeline, and self-service portal backend use cases for Digital Rebar prove that RackN has brought infrastructure provisioning to the modern age.


© Gestalt IT, LLC for Gestalt IT: RackN Bridges the Gap Between People and Platforms

View Details

In this Tech Field Day article from Cisco Live, Sulagna Saha Secure Network Analytics and Cisco XRD. Cisco’s twin solutions allow operators to have the resources that they need to monitor the network and its assets in real time. By refining and enriching data through aggregation, correlation and prioritization, they make the job of security professionals a lot easier, driving them to swift decision-making and prompt response, and making adoption of high security standards involuntary. With their pinpointed detection, it is possible to find weak links and cloaked threats easily, and prevent jeopardy of the entire stack.


© Gestalt IT, LLC for Gestalt IT: Fast-Tracking Decision Making and Incident Response with Cisco’s Secure Network Analytics and XDR

View Details

In this Tech Field Day Extra article from Cisco Live, Sulagna Saha discusses the Cisco Data Center Networking Blueprint for AI/ML applications and how it provides a reference architecture for achieving that reliability and connectivity to support this new wave of innovation at highest efficiency and lowest friction.


© Gestalt IT, LLC for Gestalt IT: Designing a Lossless AI/ML Network with Cisco Data Center Networking Blueprint

View Details

in this Edge Field Day Tech Note presented by Mako Networks, Brian Chambers discusses how segmentation is key to operating at scale and how Mako Networks has made a successful implementation of an edge computing solution. 


© Gestalt IT, LLC for Gestalt IT: Segmentation is a Key Edge Building Block with Mako Networks

View Details

In this Tech Field Day Extra at Cisco Live article, Sulagna Saha discusses Cisco Security Policy. Having a standard security policy is infinitely more efficient than a siloed, multi-vendor situation that only adds to the complexity and cost. The road to better security is not through adding more or fewer products, but putting in place a standard model of enforcement like Cisco’s that spans the enterprise, so that the policy follows the software wherever it goes, and not the other way around.


© Gestalt IT, LLC for Gestalt IT: Achieving a Consistent Policy across Enterprise with Cisco Security Group Tag

View Details

In this Cloud Field Day Tech Note presented by Forward Networks, Justin Warren discusses that in today’s climate, enterprises need to be equipped to handle a diversity of environments without being constantly bamboozled by complexity. An eye to distinguish necessary and valuable variation from the insecure or dangerous ones helps build this ability. With its high-fidelity observability, Forward Networks helps them get the benefits of the new and the old, without making security an impossible task.


© Gestalt IT, LLC for Gestalt IT: Seeing through Hybrid Multi-Cloud with Forward Networks

View Details

In this Tech Field Day Extra article from Cisco Live, Sulagna Saha discusses how Cisco’s Lightspin CNAPP does more than pointing towards a vulnerability. It highlights the criticality of that vulnerability, the past and present events that correlate to it, and at the same time, put together the steps to address it. IT team can now see the series of exploits that exists in the environment before they lead to the ultimate attack.


© Gestalt IT, LLC for Gestalt IT: Thwarting Malicious Cyberattacks with the New Lightspin CNAPP from Cisco

View Details

In this Tech Field Day Extra article from Cisco Live, Sulagna Saha how ThousandEyes added Meraki MX to the list of integrations that already includes the Catalyst and Nexus Series to widen visibility. Commonly deployed in small and large size branch offices, the Meraki MX is an excellent source of data from those sites.


© Gestalt IT, LLC for Gestalt IT: Drilling Down into the Invisible Parts of the Network with ThousandEyes

View Details

In this Tech Field Day Extra article from Cisco Live, Sulagna Saha discusses how Cisco’s new Catalyst IE9300 Rugged Series delivers excellent coverage and consistent performance, making them ideal for harsh outdoor settings. With their feature set and economics, there is hope on the horizon for industrial users to tackle the usual problems of outdoor deployments in an easy and cost-friendly way.


© Gestalt IT, LLC for Gestalt IT: Cisco Rolls out Industrial Ethernet Catalyst Switches for the Most Rugged Outdoor Deployments

View Details

In this Storage Field Day Tech Note presented by StorPool, Chris Childerhose discusses how StorPool disrupts the storage scene by unlocking effortless implementation, deployment, maintenance and upgrading, for the first time, all without the slightest service interference to the clients and employees. It’s time to change the way we think about storage!


© Gestalt IT, LLC for Gestalt IT: StorPool – Storage Delivery with Commodity Hardware the Right Way!

View Details

In this Cloud Field Day Tech Note presented by Forward Networks, Remington Loose discusses how Forward Networks helps newly-joined teams work better together, regardless of their chosen platforms or deployments. The reduction in risk to both the overall environment and individual changes can smooth and accelerate the combining of two networks. Given how much technical debt is commonly incurred in these situations, the product can help to avoid the permanent, short-term solution.


© Gestalt IT, LLC for Gestalt IT: Easy, Verified M&A with Forward Networks

View Details

In this Tech Field Day Extra article from Cisco Live 2023, Sulagna Saha discusses Opengear's newly introduced enhancement to the Smart Out-of-Band called RMF, (Routed Management Fabric), a network overlay that Opengear hopes to be the foundational piece of what they offer.


© Gestalt IT, LLC for Gestalt IT: Out-of-Band Management for Day 0, Day 1 and Day 2 Operations with Opengear Smart OOB

View Details

In this Tech Field Day Extra article from Cisco Live, Sulagna Saha highlights how with BackBox, the learning curve is nil, and operators are at the advantage to exploit the technology without having a fair amount of experience with it. It is technically superior, and offers a low-tech version of automation that is highly coveted among IT professionals. By performing sophisticated networking tasks reliably and consistently with low to no involvement from operators, it provides a smart workaround whose benefits far outweigh the manual procedures. In doing so, it achieves the seemingly unachievable feat of establishing confidence in automation solutions.


© Gestalt IT, LLC for Gestalt IT: Infusing Automation in EveryDay Networking Tasks with BackBox

View Details

It's been a busy year for security companies and teams dedicated to keeping users safe. The way that attackers are choosing to exploit companies are evolving and IT security platforms need to evolve as well. We're excited to showcase just how companies are responding to this changing landscape with two days of great presentations at Security Field Day 9.


© Gestalt IT, LLC for Gestalt IT: Safe and Sound at Security Field Day 9

View Details

In this Cloud Field Day article, Sulagna Saha discusses how RackN takes a radically different approach with its Digital Rebar architecture built with the assumption that the environment is likely going to be variegated.


© Gestalt IT, LLC for Gestalt IT: Making Infrastructure Lifecycle Management Painless with RackN Digital Rebar

View Details

In this Cloud Field Day article, Sulagna Saha discusses how the Morpheus platform’s extensibility feature enables users to bypass using too many solutions to get the desired feature set and altering their business needs and ways of working to make it work. Built with usability and agility top of mind, it serves organizations in the way they need and not the way it can. The long-term viability of a solution like this is unquestionable.


© Gestalt IT, LLC for Gestalt IT: Tapping into Software Extensibility with Morpheus Data

View Details

In this Cloud Field Day article, Sulagna Saha discusses how Zerto's Zerto 10 strikes at the heart of the ransomware scourge with advanced and real-time capabilities. With real-time detection, Zerto 10 continuously scans and searches for signs of encryption, enabling swift discovery and speedy action.


© Gestalt IT, LLC for Gestalt IT: Preventing Attack Escalation with Real-Time Encryption Detection in the New Zerto 10

View Details

In this Storage Field Day Tech Note presented by StorPool, Jim Czuprynski discusses how radically different StorPool's storage model is. By standardizing storage nodes on commodity hardware, and concentrating on provisioning capacity in an as-a-service orientation, it’s much simpler for storage to become and remain what everyone in IT wants - always on, non-disruptive, reliable, and performant.


© Gestalt IT, LLC for Gestalt IT: Getting Off the Storage Refresh Treadmill with StorPool

View Details

In this Networking Field Day Tech Note presented by Catchpoint, Peter Welcher discusses how Catchpoint can monitor and display valuable BGP information over time, allowing staff to keep an eye on, spot problems in, and troubleshoot global or large scale routing.


© Gestalt IT, LLC for Gestalt IT: Catchpoint BGP Monitoring

View Details

In this Cloud Field Day article, Sulagna Saha discusses how Capella from Couchbase and how the database platform addresses the inefficiencies of traditional databases and embraces a new approach that drives value of applications. It impresses by delivering the speed and scale that otherwise take several legacy databases to match, making other contemporary databases look archaic.


© Gestalt IT, LLC for Gestalt IT: Building Better Applications at Reduced Cost with Couchbase

View Details

In this Cloud Field Day article, Sulagna Saha discusses how enterprises have been dreaming of a solution like HYCU R-Cloud for years that would bring new smarts to the anachronistic field of data protection. R-Cloud not only saves data from potential jeopardy, but by extending pervasive data protection to assets anywhere in the distributed environment, it lets SaaS vendors to offer data protection as native service. SaaS users can granularly enable data protection, review their protection status and analyze their posture using an automation framework that is simple, reliable and works equally in all environments.


© Gestalt IT, LLC for Gestalt IT: Integrating Native Data Protection to Any Infrastructure Codelessly with HYCU R-Cloud

View Details

In this Tech Field Day article, Denny Cherry discusses how any company that is worried about ransomware should regularly scan their enterprise for ransomware. CyberSense by Index Engines can do that scanning for them, detecting all signs of corruption before a full-scale attack unfolds.


© Gestalt IT, LLC for Gestalt IT: Ransomware is a Real Threat but CyberSense From Index Engines Can Help

View Details

In this Cloud Field Day article, Sulagna Saha discusses how JetStream delivers extended protection to data, be it in the public or private cloud. But more importantly, by delivering the service over software, it spares users the troubles of engaging with the mechanics of DR and the costs of investing in questionable solutions. It is ready-to-use, automatic and offers the best of cloud economics.


© Gestalt IT, LLC for Gestalt IT: DR as a Service with JetStream Software

View Details

In this Mobility Field Day article, Sulagna Saha discusses how Cisco, with the kind of observability it has achieved through the Meraki Dashboard, is aiming to unlock incredible transparency and control over deployments and consumption and find signals in the noise, making networking easy and future-proof.


© Gestalt IT, LLC for Gestalt IT: Cisco Wireless and a Common Management Strategy with Meraki Dashboard

View Details

In today’s rapidly evolving digital landscape, maintaining a robust and secure network infrastructure is crucial for businesses. Network observability – which is the ability to gather updates with each collection contextual data and draw out valuable inference – plays a fundamental role in ensuring secure network operations.

However, achieving observability is especially challenging in multi-cloud environments, where disparate cloud providers offer varying levels of visibility.

Network Observability: Unveiling the TruthThe foundation of network observability lies in visibility and validation. Visibility provides existing information about network operations, enabling identification of anomalies. Observability, on the other hand, goes a step further by streaming real-time contextual data, facilitating in-depth analysis and uncovering new insights within specific domains.

Simply put, observability serves as a measure of validation, ensuring that network operators’ beliefs about the network’s performance align with reality. The greater a team’s ability to answer network-related questions and validate its state, the higher the level of observability achieved.

Hybrid Multi-Cloud ObservabilityWhile cloud providers by default offer a certain degree of visibility within their own environments, the problem starts when dealing with hybrid multi-cloud scenarios. Cloud vendors each possess a unique scope, scale, and format of observability, none of which provides holistic solutions for network visibility, security, and policy configuration. This creates a void making comprehensive observability across the entire network landscape, both within and across cloud platforms, impractical.

Recognizing this challenge, Forward Networks took a proactive approach. Extending their cutting-edge digital twin technology into the public cloud domain, they now provide digital twin observability for all major cloud platforms such as AWS, GCP and Azure. The technology is also available for on-premises networks.

The digital twin provides deep observability of distributed network devices and compute resources across cloud platforms. Tailored to fit the distinctive characteristics of cloud environments, it encompasses critical cloud resources like VPCs, gateways, transit gateways, web accelerators, and workloads themselves.

Multi-Cloud Security: Strengthening the DefensesIn the past year, Forward Networks has seen a significant surge in the adoption of their Cloud Modeling solution. While many customers utilize it for service assurance – ensuring proper connectivity and configuration – Cloud Modeling offers much more.

It serves as an excellent tool for verifying security policies and compliance in the cloud. This additional layer of functionality improves attack surface management and cloud security posture.

Within Forward Networks’ toolbox, three tools stand out in providing multi-cloud security through deep observability: Paths, Posture, and Blast Radius.

  • Paths: Think of it as a supercharged traceroute tool. Instead of just showing the data path, it reveals all possible paths between two network nodes in a vendor agnostic format. Users can walk that path, hop by hop, and verify ACLs and configurations along the way. At every hop, they can drill into specific devices or functions and access crucial details, including the configuration itself.

  • Posture: This tool gives users a matrix view of network segmentation, telling them how things are interconnected. It considers layer 2, layer 3, and layer 4 aspects, all in one comprehensive view. With Posture, users can gain a deep understanding of their network’s structure and connectivity.

  • Blast Radius: Imagine having the power to see what a compromised host or node can connect to. Blast Radius provides visibility into potentially compromised hosts, helping users contain and mitigate security breaches proactively.

Crucially, Forward Networks’ solutions extend beyond native cloud provider devices and functions, encompassing third-party integrations through APIs. This ensures complete observability across a diverse range of network assets.

The Bottom Line: Security through ObservabilityNetwork observability serves as a linchpin for maintaining a secure and resilient network infrastructure. In the realm of multi-cloud, achieving that observability is even more challenging due to the absence of unified visibility across cloud platforms. Forward Networks has risen to that challenge by extending their digital twin technology to major cloud providers.

Their solutions not only deliver deep observability, but also enhance security through tools like Path, Posture, and Blast Radius. With Forward Networks’ comprehensive approach to multi-cloud observability and security, businesses can unlock the full potential of their networks, and ensure a robust and protected digital ecosystem.

To learn more, check out the Forward Network presentations from the recent Cloud Field Day event.


© Gestalt IT, LLC for Gestalt IT: Multi-Cloud Security Requires Multi-Cloud Observability with Forward Networks

View Details

Anybody with a first-hand experience of building products within a service provider knows how hard it is to create a true “as-a-service” offering. Start sprinkling external certifications on top of this, and what was a lot of work quickly becomes a grind with real challenges of its own.

Mako Networks checks this by being a vendor that produces its own hardware and software that are sold as-a-service on monthly subscriptions. On top of that, Mako technology is also PCI-certified making it the only network vendor to truly make such a claim. Propelled by this, Mako Networks has made huge inroads into the distributed retail enterprise (i.e service stations, car parks, QSRs) business in North America and Europe. The PCI certification extends across both the hardware and software layers. It is fully transferrable into customer networks making it in a no-brainer when accepting payments across the network.

What Does the Ecosystem Look Like?The Mako ecosystem can be broken down into two elements – the Mako CMS, and the network devices.

Mako CMS (Central Management System) is the brain of the solution. It is a cloud-based, multi-tenant management portal where all network devices are managed and monitored. Built in-house, it provides a rich set of functionalities.

Network devices include secure gateways with built-in wireless and cellular failover, VPN concentrators, access points, managed switches – everything needed in a modern network.

When customers purchase any of the Mako Networks devices, they are onboarded onto the Mako CMS which is included as part of the as-a-service offering. There are no hidden additional fees or add-ons for it.

No matter how distributed the network is, customers manage their entire network here. Mako secures the devices and achieves the coveted PCI certification by sidestepping local management. With no factory reset switches on the devices, it delivers advanced physical security as well as network security.

ConfigurationWith centralized configuration, users can access all Mako devices via the CMS, and enforce changes from one place. The real power though is the bulk configuration functionality such as enterprise templates which can be rolled out to potentially thousands of devices at once.

As part of the service offering, Mako also provides a set of PCI-certified templates which can be used on all Mako devices on the fleet, and demonstrated to auditors.

Enabling the PCI-certified templates allows devices to have change control activated which prevents a single person from making changes to the network without approval.

Software UpdatesAs Mako makes new software revisions available, customers can choose to stage these updates to their devices. Updates can be staged into a lab first before rolling out to production. Rollout progress can be monitored across the estate.

SecurityThe way Mako has structured the devices within the CMS makes it very easy to restrict user access via RBAC. Some users could have complete control of all devices, while others may only have access to certain devices and a restricted set of functionalities.

Monitoring and AlertingCentralized reports and diagnostics provide visibility into the health and performance of the entire network. With support for NetFlow, email, SMS and Webhooks, users can subscribe anyway they like to an ever-growing number of events, from firewall issues to device or port health that might occur on their network.

The real hero is the Webhooks functionality that enables real-time data transfer following an occurrence in the network. Webhooks can be integrated with almost any application. Users will most likely want to have these pushed into ticketing or on-call paging solutions, but a flow of events can also be streamed into Microsoft Teams or Slack channels.

What type of organizations make a good fit for Mako Networks? Any organization that requires a feature-rich set of network devices and centralized management could use Mako as their network vendor. Organizations with a desire to procure via a cost-effective, scalable OPEX model for their network devices would find their as-a-service model profitable.

ConclusionHaving PCI compliance taken care of at the network layer is a massive burden for organizations and often a stumbling block in maintaining compliance. Mako Networks help offload that with ready compliance. Its centralized management reduces infrastructure workloads while saving time with the ability to push out templated policy changes and software updates through a single portal.

Mako themselves maintain that their product starts making absolute sense for any organization with around 50 devices or more. However, they assured that users will start seeing value around 10 devices or more.

See all of Mako Network’s videos from Edge Field Day 1 on the Tech Field Day website. Find out more about their products on the Mako Networks website.


© Gestalt IT, LLC for Gestalt IT: Mako Networks – A World-Class PCI-Certified Network-as-a-Service Ecosystem

View Details

For a long time, Arista Networks has watched as new-fangled network access control (NAC) solutions from other vendors have made their way into the market, stoking public imagination with the potential for zero-trust security.

But in April, the company stepped off the sidelines and launched its own AI-driven NAC solution, rounding off its campus product portfolio with the one remaining missing element. CloudVision AGNI will expand Arista’s flagship CloudVision solution with features like secure onboarding, dynamic access control, AI-driven policy enforcement, and much more.

Bhagya Prasad NR, Director of Engineering, who has actively been part of the engineering team that designed CV AGNI, and Suparna Dam, Solutions Manager, jointly unveiled the solution to the audience at the recent Mobility Field Day event.

CV AGNI stands for Arista Guardian for Network Identity. Built on top of CloudVision, AGNI realizes three highly-coveted attributes – simplicity, scalability and security.

A Tricky DanceIn addition to wired and wireless, the third and final element that completes a network security portfolio is a NAC solution. But not all vendors have their proprietary NAC product. For those that don’t, integrating with the customers’ existing NAC solutions is the way to deploy their solutions at enterprises.

Through years of working with NAC solutions from other vendors, the team at Arista faced a complicated picture and a swirl of headwinds.

Largely, NAC solutions run on legacy infrastructure on premises. In the age of cloud-first, this is already a step backward. The characteristic complexity of the solutions further makes it is painful and painstaking to configure, scale and maintain them.

To get the most of network access control, NAC solutions need to be cloud-native, simple for the most part, and automated where possible, easily scalable and on par with the industry security standards.

“We felt that that was a gap in our product portfolio as we went and offered the solution to our customers in the campus. We also felt that building our own solution that is natively integrated with our wired and wireless, we’ll be able to provide much more value and a compelling solution for our campus customers,” said Sriram Venkitestwaran, Director of Product Management for Cognitive Campus at Arista Networks.

Arista Guardian for Network IdentityBuilt from the scratch, AGNI was born in the cloud, and embodies modern cloud-first principles. This makes cloud flexibility characteristic to it.

CV AGNI has a modern microservices architecture that delivers elastic scalability – from tens to thousands of devices – in a few clicks.

“When it is made-up of microservices architecture, each microservice can be spawned depending on the load. You can go up or scale down depending on the density of the traffic” explained Mr. Prasad.

Additionally, high availability, and improved fault isolation of the microservices architecture help address the rigidity in legacy solutions with monolithic designs.

CV AGNI has geo-redundancy built into it “just to take care of some of the scenarios where it is necessary to route the traffic from one location to another,” said Mr. Prasad.

In the modern perimeterless network where identity policy management is a life-long process, CloudVision AGNI sidesteps the inherent complexities with AI. All administrative functions can be performed from the solution’s centralized UI which features a natural language processing (NLP) chat interface that responds to queries by producing helpful answers in complete sentences.

The Arista CloudVision AGNI DashboardThe UI allows self-service style onboarding for wireless with single sign-on (SSO), AI-driven policy enforcement, automated certificate management, streamlined deployment and faster troubleshooting, reducing average deployment time from weeks down to hours.

Continuous security posture is enabled with CV AGNI’s integration with Arista NDR. When an untrustworthy device is spotted in the network by NDR, it works with CV AGNI to swiftly isolate it, and limit its access level.

CloudVision AGNI resolves traditional NAC solutions’ lack of compatibility with a growing number of identity stores with broad native integration.

Wrapping UpCloudVision AGNI’s wide set of features allows it to carry out security processes quickly and competently that’d take operators with fair amounts of experience a lot longer. Leveraging ML models and a modern architecture, it makes identity enforcement and management less harrowing, and incrementally streamlined, showcasing the real power of AI.

For more information, be sure to check out Arista Networks’ deep-dive presentations of CV AGNI from the recent Mobility Field Day event.


© Gestalt IT, LLC for Gestalt IT: Overcoming the Uncomfortable Aspects of Network Identity Management with Arista Networks’ CloudVision AGNI

View Details

“Great wine starts with great grapes. Great AI starts with great data,” said Bob Friday, Juniper Networks’ CTO and Chief AI Officer, while presenting at the recent Mobility Field Day event in California.

One of Juniper Networks’ biggest story this quarter is updates around its AI assistant, Marvis. The company announced that it is expanding Marvis with Zoom data and ChatGPT, further augmenting its ability to respond to complex networking questions.

Errors and DisconnectionsVideo conferencing apps like Zoom are some of the most widely used applications running on corporate networks. A workday calendar packed with Zoom meetings is business per usual for the distributed workforce. As we are filling our calendars with more virtual meetings than we did in normal office settings, it is vital that the platforms hosting these meetings run flawlessly.

Contrary to the expectation, Zoom and many other conferencing apps are often failing, freezing and crashing frequently, often several times a day.

“Video applications are probably the hardest applications to run on a network. If anything’s going to break first, it’s going to be your real-time video collaboration experience,” noted Mr. Friday.

Such errors can stop important collaborative sessions mid-way, hurting productivity, and slowing down innovation. Owing to poor call quality, a quick half-hour meeting can stretch to hours without satisfactory results. It is a frustrating struggle for employees, as many of them are working this much out of office for the first time.

An even bigger puzzle is identifying the root of the problem. An application outage can happen for a myriad of reasons – poor Wi-Fi, overworked devices, software errors, service downtime. Having to figure out the origin of the problem does nothing to move the real work forward, and only adds an extra layer of stress.

Turning the PageAIOPs has come a long way with helping companies turn the page on distracting technical errors. It is making already headlines with how easy it has made leveraging everyday technologies.

AI algorithms are trained on billions of datasets that allow them to mark and magnify nuances, nipping a problem off before it becomes an anomaly that diminishes the user experience.

“AI is the next evolution in automation. We’ve always been doing automation with scripts. AI is just taking that automation to the next level, doing things on par with humans,” commented Mr. Friday. “The paradigm shift is around AIOPs moving us from client to cloud tradition. We want to make sure that the connection is good,” he added.

Core to AI’s success is good-quality data, which allows algorithms to process an input efficiently and produce definite diagnosis. This requires cycles after cycles of training, state-of-art infrastructure, and a stellar data science team behind the whole operation.

Juniper Networks’ AI JourneyAbout some years back Juniper Networks debuted Mist AI, a solution that combines AI, ML and data science. Fundamental to all of their subsequent AI initiatives, Mist AI furthers the goal to expedite operations and optimize user experience.

The Mist journey started when Bob Friday was still working his 9-year-old job at Cisco as the VP.

“We were hearing from some of our very large customers that they wanted us to have the controllers stop crashing. They wanted to get things moving quicker, and a space to innovate faster and keep up their digital transformation. But most importantly, before they were going to put anything critical on the consumer device, like an app, or on the network, they wanted to make sure that it was going to be a good experience,” he remembered.

Ensuring this requires a lot of data. To get customers that data that they need, Juniper Networks built its catalogue of APs with Mist AI integrations. The new Marvis updates take that work forward.

“When we started the journey, we started with the wireless access points because that’s what allowed us to answer the question of why you are having a poor internet experience. What you saw us do at Juniper was basically extend that across the access point to switch, and the router” said Mr. Friday.

Likewise with the Zoom data, Juniper Networks is taking steps towards understanding and answering questions specifically about Zoom user experience.

“This is basically going to let us to start leveraging technologies like ChatGPT and taking terabytes of data, training models that can actually predict user performance, and start to understand why you’re having a poor experience,” he said.

Continuous LearningWith the goal to reduce barriers and defeat more difficult problems, Juniper Networks has constantly experimented with AI models, refining training and inferencing to achieve better results. Ingesting Zoom data on Marvis is part of that effort.

Up until recently, Marvis had two key components – the conversational interface which provided answers to queries in natural language. Juniper Networks recently expanded this by integrating with ChatGPT. The second is Marvis Actions, a self-driving feature that proactively highlights user-impacting issues by automatically creating RMA tickets.

The third and the brand-new element is continuous user experience learning. This lets Marvis consume labelled session data in real-time from public cloud applications – in this case Zoom – at the rate of per-minute, and continually monitor its user experience. This labeled data helps create models that can predict the performance of applications in machine learning.

This runs natively in Marvis giving operators feedback of the Zoom experience in real time.

“This is where we’re leveraging ChatGPT. We’re taking these deep learning models with terabytes of data, and training them to predict your Zoom audio-video latency, and performance. We’re getting down to predicting Zoom latency, plus or minus 5 milliseconds 90% of the time,” informed Mr. Friday.

Juniper Networks distills down the AI findings with Shapley that tells which network feature is responsible for the problem.

“The good news is when we get data from Zoom, they give us information about the client. Turns out a lot of the problems have nothing to do with the network at all. It has to do with downloading a video while on call, an overloaded CPU, etc.”

Mr. Friday emphasized that the key difference with Marvis is not the algorithm, but Juniper Networks’ robust data science team that is working behind the scenes. The company has recently expanded its in-house data science team, adding new members, paving the path to faster innovation.

Customers can talk directly to the support team when they have a problem. The support team works closely with the data science team at the back end. They meet weekly going through the existing tickets and deciding which ones AI can help resolve. This helps improve the models’ accuracy and optimize user experience leading to fewer support tickets.

Wrapping UpWith consistent improvement of AI solutions, and integration with other breakthrough technologies, users are on the cusp of using AI as an everyday tool across domains and disciplines. Marvis is a fine example of that. The new feature will serve to make Zoom user experience so much more predictable and consistent. Thanks to its AI-powered predictive observability, thousands of hours of painstaking rooting around is an effortless push notification.

For a demo of the new feature, be sure to watch Juniper Networks’ presentations from the recent Mobility Field Day event.


© Gestalt IT, LLC for Gestalt IT: Elevating the Zoom Experience with Juniper Networks’ Marvis

View Details

We’re thrilled to be back in sunny Las Vegas again for Tech Field Day Extra at Cisco Live US 2023. There is a lot of excitement around some of the big announcements Cisco is preparing and our group of delegates will be there to give you all the information you need to know about what’s in store.

We have a packed schedule of presentations from several companies that you’re not going to want to miss.

Event ScheduleTuesday, June 6 is the first day of Tech Field Day Extra and kicks off with our friends at Opengear. They’re back once more to share updates with us and show us how they’re continuing to provide value to operations teams in need of console solutions for a variety of unique applications. The afternoon features Cisco presentations from Enterprise Networks, ThousandEyes, and Cisco Security.

The second day is Wednesday, June 7 and we’re featuring another great presentation from our friends at BackBox. They’re fresh off an appearance at Networking Field Day 31 and they have so much more they want to show our eager delegates. The second half of the day will feature more great content from Cisco, including IoT presentations, Cloud and Compute, and a discussion around secure policy.

Be A Part of the ActionMake sure your calendars are set for June 6-7. You can find the full event schedule at TechFieldDay.com as well as at the Tech Field Day Extra event page. If you miss any of the exciting announcements you can always catch the on-demand sessions at the Tech Field Day YouTube channel. If you prefer to watch your live streaming video on LinkedIn make sure to follow the Tech Field Day LinkedIn page. We will be using the hashtag #TFDx for all our social media presences for you to join the conversation and follow along. You can also tag your questions with #CiscoLive to share with the rest of the conference.

We can’t wait for more great fun with Tech Field Day Extra and we hope to see you there!


© Gestalt IT, LLC for Gestalt IT: Excitement In the Air with Tech Field Day Extra at Cisco Live US 2023

View Details

We live in a world where AI drives imagination and utility. AIOps has proven to be extremely useful for businesses, and we are starting to see the beginning of its real-world applications.

Among the companies in the frontline that are working at a frenzied pace to solve grand operational challenges with AIOps, Fortinet is a notable name. After FortiAIOps, the company is on track to release the next iteration of the solution featuring a combination of augmented insights and advanced troubleshooting.

In a presentation that combined a walk-through of the new features and a technical demo, Alex Vizzari, Sr. Director of Product Management, detailed the capabilities that are arriving soon in FortiAIOps, and features that are on the roadmap, at the recent Mobility Field Day event.

One Is Better than TwoFor a typical network that spans datacenter to edge, Fortinet offers a bundle of solutions, namely FortiManager, FortiAnalyzer and FortiAIOps to help operators navigate and perform complex networking and security tasks.

“A lot of customers have multiple branches that we call the SD branch. Data within this branch is managed by FortiGate – the switch, the APs, the 4G/5G connectivity being the extender – all going into the datacenter where they have the FortiManager. We also have an analytics and a reporting engine, the FortiAnalyzer and FortiAIOps inside the datacenter” said Mr. Vizzari.

For monitoring, troubleshooting and insights specifically, Fortinet offered FortiWLM and FortiAIOps. The company has merged the capabilities of these two into a single solution to create FortiAIOps v2.0.

“It’s good to have two different products, but customers want to have everything in a single pane-of-glass management. They want to go back and forth between monitoring, seeing different things and switching sites. So knowing that we had two different products, we came up with a solution merging monitoring, troubleshooting and AI insights inside a single platform,” said Mr. Vizzari.

The new FortiAIOps brings with it the deep monitoring and troubleshooting of FortiWLM with the swift diagnostics and analytics of FortiAIOps that companies need on a day-to-day basis.

New GoalsFortiAIOps v2.0 furthers three key goals of its makers – to provide faster root cause analysis, ensure improved network and application availability, and make advanced troubleshooting tools available.

“With wireless, switching and potentially SD-WAN, it’s really tough for people to go deep into an issue. We know that to be experts, to know all the different gears of the vendor – be it Fortinet or anyone else – is hard for an IT person,” noted Mr. Vizzari.

With the new FortiAIOps, Fortinet dials down the requirement of technical expertise for operators by amplifying the solution’s innate RTA capabilities with suggested answers to address issues, delivering faster MTTR.

FortiAIOps 2.0 aims to optimize network and application availability by providing users data on key performance metrics and highlighting negative trends, so that they can be on top of issues the moment they show up, and ensure users a higher level of experience.

New FeaturesFortiAIOps 2.0 provides a holistic view of the network that includes wireless, switching and SD-WAN, ensuring that operators do not have to shuttle between multiple solutions.

“With the ability to go from top to bottom within a few clicks – from the FortiGate level to the switch to the APs and the stations – it drives the IT guy towards the problematic stations,” said Mr. Vizzari.

The AI piece is built into the solution. “There are a few additions like troubleshooting tools and the full LAN and WAN view from a single platform,” he informed. With the improved AI, it can cross-correlate events and data from across the deployment providing deeper insights.

A set of built-in troubleshooting tools validate deployment at all network levels ensuring reduced MTTR. Advanced tools like route checks, process monitor, heatmaps, VLAN probe, cable diagnostics and RF perf statistics augment its troubleshooting capabilities.

In terms of scalability, Fortinet offers three models – low, medium and high, depending on the type of network. Customers can start with a small number of devices and can go up to thousands.

As of right now, the FortiAIOps v2.0 is a virtual machine. Mr. Vizzari said that it is fully relying on the Fortinet Neutrino framework.

Mr. Vizzari informed that Fortinet is working on dedicated hardware which will be released in the future.

FortiAIOps v2.0 is a subscription-based solution that is available in a flexible licensing model. It comes in an annual per-device subscription model. Monitoring and insights are offered both separately, and in bundles.

“We see that some customers want just monitoring, while some want insights. Some want a bundle of both, and others would want the full lot with SD-WAN,” said Mr. Vizzari.

Wrapping upTraining humans to code has been one of our biggest successes so far. Solutions like the new FortiAIOps flip the script by training computers to do the heavy-lifting with AI, thus relieving the pressure off of IT personnel. FortiAIOps massively broadens their access to effective monitoring and troubleshooting, and instant insights critical to delivering even network performance and improved quality of experience, regardless of the operators’ technical abilities.

For more, be sure to watch the demo in the second part of Fortinet’s presentation from the recent Mobility Field Day event.


© Gestalt IT, LLC for Gestalt IT: Fortinet Takes on Even Bigger Challenges with FortiAIOps v2.0

View Details

In this Mobility Field Day article, Sulagna saha dicscusses how NetAlly’s CyberScope is an all-in-one tool for Wi-Fi site assessment. It provides deep dive into device attributes, points out unauthorized endpoints, and alerts operators about errors and failures, making it possible to spot outliers efficiently on a walk-through. Designed to both survey the network, and collaborate with smart hands in the field, it provides the data required to perform proactive and reactive activities, keeping the network secure at all times.


© Gestalt IT, LLC for Gestalt IT: Analyzing Wi-Fi on Site with NetAlly CyberScope

View Details

Raymond Hendrix is the owner of Wi-Fi Wise International and one of our newest Field Day delegates. He started in IT after obtaining a degree in economics with a focus on databases. Raymond served in the Dutch military, where he gained expertise in electronic warfare and expanded his IT knowledge through training. His interest in RF and antennas stemmed from his experience operating a powerful jamming vehicle. Raymond’s favorite aspect of his work is making Wi-Fi solutions seamlessly function for customers. However, a significant challenge he faces, along with other Wi-Fi engineers, is obtaining clear communication from clients. Raymond acknowledges that effective communication skills are crucial in his field, even though IT professionals tend to be more focused on technical aspects. Attending Mobility Field Day, Raymond looks forward to exploring the latest advancements in the industry, assessing their practicality and real-world use cases. When asked about an alternative career, he expresses an interest in forestry work and even reveals a talent for axe throwing. You can see more of Raymond and Mobility Field Day 9 on the Tech Field Day website or YouTube channel.

Connect with RaymondRaymond Hendrix is the owner of Wi-Fi Wise International. You can connect with Raymond on Twitter or on LinkedIn. Find out more about what he does over on the Wi-Fi Wise International website.

Transcript from the InterviewRaymond Hendrix: I’m Raymond Hendrix, owner of Wi-Fi Wise International

Tom Hollingsworth: All right Raymond you’re one of our new delegates here at Mobility Field Day and we’re very excited to get to know you a little bit better. So why don’t you tell me a little bit about who you are and what you do right now

Raymond: so who I am, as I said I’m the owner of Wi-Fi Wise which is a company which focuses on the RF side of things of communication. So we we started in in Wi-Fi now transitioning into other technologies as

well like WAN, but we try to stay clear of all the other layers. We do need to know of course about, for example, DNS because it’s always DNS when stuff doesn’t work. We try to focus on the wireless side of things.

Tom: So not everybody starts out doing IT. How did you get into the IT space?

Raymond: Well I did start out in the IT space but I… after I did my, well I think a bachelor-ish a degree, um for economics and which I had an in-depth I think the English word is in IT so it did databases and stuff. And then I got drafted in the Dutch military so and I kind of liked it so I stuck around for six years. I did training and did electronic warfare over there and then expanded my IT knowledge, military paid for a lot of training. I did my MCC so started with NT35 back in the day, learned about token ring networking, but in electronic warfare I had this big vehicle which was a jamming vehicle and it had 16 kilowatts of EIRP. So I always tell students as well like 16,000 Watts we heat our food with a thousand Watts now we’re doing Wi-Fi with a hundred milliwatts so different in power but that is what got me interested in RF, in antennas, and so that’s why I got started in IT.

Tom: So what’s your favorite thing about what you do?

Raymond: That for the customer it automagically works.

Tom: I like that! But obviously making it work magically doesn’t happen every time the same way. What are some of the challenges that you face in what you do?

Raymond: I think the biggest challenge, but that’s not just for me but probably every Wi-Fi engineer, is getting clear requirement from the customer.

Tom: Now I’m assuming that requires a lot of communication skills being able to ask the right questions but also being able to understand that maybe the answers aren’t where you need to be and find a different way to ask that question?

Raymond: Yeah and as IT people we’re kind of autistic, right? So communication might, even though we’re in in wireless communication, people to people communication might not be our strong suit so getting that information from the customer is most challenging.

Tom: Right and a lot of communication happens here at Mobility Field Day when we get our presentations. What are some of the things you’re most excited to see while you’re here?

Raymond: Um well I’m just excited to be here and to see the the newest and latest and greatest and just soak it all in. But also um trying to clear the marketing fluff and get down to, okay, what’s the actual use case can we use it and is it usable

Tom: Yeah, that’s kind of what we do around here and I’m glad that that’s something you’re kind of interested in. Now let’s just step back for a minute, if you weren’t doing this job, if you weren’t involved in IT, what would you be doing?

Raymond: I always thought forestry work would be nice, a lumberjack or like, yeah, stuff like that.

Tom: Yeah it’d be fun. You learn how to swing an axe, fell a tree.

Raymond: Yeah I’ve done that at when we had a trainer as an account trainer at GT Hills Place, we threw axes and turns out I have a talent for it so.

Tom: That’s impressive not only are you great at training wi-fi people but you might be able to use an axe in creative ways if you have to.

Raymond: I can.

Tom: Well, Raymond, thank you very much for being a part of Mobility Field Day we’re very excited to have you here. If you’d like to see more interviews like this, you can head over to our website at gestaltit.com and if you’d like to learn a little bit more about the interview that Raymond and many other people are involved in head over to techfieldday.com and look for Mobility Field Day 9 which will be streaming live May 17th, 18th, and 19th. We’ll see you there.


© Gestalt IT, LLC for Gestalt IT: Meet Field Day Delegate – Raymond Hendrix, Owner of Wi-Fi Wise International

View Details

Kerry Kulp, a founding partner at Velaspan, is one of our new delegates for Mobility Field Day 9. Speaking with Tom Hollingsworth, Kerry discusses his various roles in the company, including business leadership, business development, and consulting. He shares his journey into the IT industry, starting with computer training while studying criminal justice and sociology in college. Kerry reminisces about his early days in the wireless and mobility industry and the advancements that have taken place since then. He expresses excitement about attending the event, particularly to hear presentations from the companies on products he is both familiar and unfamiliar with in his day-to-day work. Kerry also talks about the challenges faced at Velaspan, such as searching for the right people with the depth of knowledge in wireless, networking, and security. When asked about his dream job, Kerry jokingly mentions cutting grass but expresses a continued interest in technology, particularly in the field of cybersecurity. Thanks Kerry for being a part of Mobility Field Day 9! You can catch all of the videos from Mobility Field Day on the Tech Field Day website or YouTube Channel.

Connect with KerryKerry Kulp is a founding partner at Velaspan. You can connect with Kerry on Twitter or on LinkedIn and find out more about Velaspan on their website.

Transcript from the InterviewKerry Kulp: I’m Kerry Kulp, founding member of Velaspan.

Tom Hollingsworth: And I am Tom Hollingsworth, event lead for Mobility Field Day. We’re here with Kerry, he is a brand new delegate to Mobility Field Day and we are very excited to meet you. So why don’t you tell us a little bit about who you are. What’s your job role and what do you do?

Kerry: That’s a great question. I wear a lot of hats. As a founding partner of Velaspan I still have to fulfill some business leadership roles, business development roles, presale goals. I have a team of my own that I lead. Also still handle consulting, so some of the more technical side of things. It’s definitely the definition of a man with many hats.

Tom: How did you get into IT?

Kerry: So I started in IT doing computer training. I was actually in college for, of all things, criminal justice and sociology. Had every intention of going into the criminal justice field, planned to be a cop, maybe the FBI or Secret Service, something like that. I kind of always had a knack for IT and things like that and I had the opportunity to do some computer training, and I was good at it. From there I went into network engineering at a local ISP. From there, all the way back in 1998, is when I got my first job in the wireless and mobility industry.

Tom: That’s back in the day, that’s kind of around when it started.

Kerry: I was very much around when it started. That was still proprietary radio systems, we were doing a lot of prox and range LAN, deployments in hospitals. It was kind of crazy, we to deploy a proxem access point and put a proxem radio card in the device. Those were the days.

Tom: You’re taking me back. Now what are you most excited to see at the event this week?

Kerry: besides the people, because I’ve gotten to know, at least, a handful of the folks, the other delegates. I’ve known them for many years. Besides that I am just really excited to hear the presentations, learn more from, some of them that I know a lot about, like Cisco, Juniper, some of those. But maybe more importantly some that I don’t spend as much time with. I think those are going to be the really interesting ones, and that’s the Fortinets, the RUCKUSes (RUCKUS Networks), things like that that I just don’t spend that much time with on a daily basis.

Tom: That’s awesome. You’re in a very unique role in Velaspan, what are some of the challenges that you face regularly?

Kerry: Some of the challenges… We’re lucky. A couple of my partners that run our service delivery team have done a tremendous job of building a process for onboarding new resources so they have a tremendously successful process to bring in really green engineers, folks that might not have any experience in the industry and then build them very quickly into folks that can go out and do site surveys, do some basic design. Obviously some higher level leadership to guide them and mentor them, but they do a great job on that side. On my side, the kind of the consulting and managing services side, we really haven’t figured that part out as well yet. It’s a little bit harder to find the folks who have the depth of knowledge to kind of roll right in and start doing things meaningfully. So really its personnel, right now, and it’s trying to find folks that have enough experience on both the wireless side, networking side, security side, ranging across so many technology platforms and vendors, its just hard to find.

Tom: I like that approach because it cultivates the right mindset, it cultivates the right training set to someone to where they need to be in their career. It lends well to the fact that so many people speak highly of the work that you do. Putting yourself in a different set of shoes, If you weren’t doing this, what would you be doing, what is your dream job?

Kerry: Wow that is a tough one. I tell people I cut grass, but I do that because if I tell them what I really do, they always have home network questions that they want answered so when I say I cut grass, nobody really has any questions. But that would probably rank pretty highly up there as something I would like to do. It’s kind of, it’s immediately rewarding. You take a messy grass field and turn it into something nice. But all kidding aside I would probably still do something in technology. We’re branching out a little bit into some cybersecurity stuff. We’ve always kind of done it for you know, probably about two thirds, three quarters of Velaspan’s history. We’ve been doing some cybersecurity stuff but not formally. We’re formalizing that now. It’s kind of got me excited. I’d probably still be doing a lot of the same things, just maybe with a cybersecurity focus. And that’s if I’m not cutting grass.

Tom: I appreciate the time today Kerry and thank you for teaching us a little bit about who you are and a little bit about what you do. For those of you out there that are interested, you can check out more of these Meet The Delegate interviews on our website at Gestalt IT dot com. If you want to learn more about the event that Kerry will be attending, check out Tech Field Day dot com and search for Mobility Field Day and we’d love to see you online.


© Gestalt IT, LLC for Gestalt IT: Meet Field Day Delegate – Kerry Kulp, Founding Partner at Velaspan

View Details

Amid record adoption of automation in factory floors, enterprises in industrial sectors are increasingly considering private 5G LAN. Ostensibly, a 5G LAN provides what no other network has before – coverage without blind spots or service drops.

At the recent Mobility Field Day event in California, Celona showcased the Celona 5G LAN.

A Silicon Valley startup, Celona was formed four years ago by founders of mixed pedigree in cellular and Wi-Fi. As a result, from get go, the focus has been on the private wireless sector.

Backed by Tier-1 investors like Qualcomm and NTT, the company is growing at a fast pace with its wireless solutions gathering interest of a growing worldwide audience.

In the presentation, Celona showed how it has hardened its offering to better serve the customers.

A Trend Impacting IndustriesAcross industries – from healthcare to education to utilities – there is a prevailing lack of consistent network connectivity in outdoor spaces and extended areas, particularly in parts where signal reception is poor. This is increasingly driving industries towards private wireless alternatives for mission-critical use cases.

“A lot of the need for private wireless within the enterprise, in the last three years, has been driven by what, internally at Celona, we call “uncarpeted or non-carpeted enterprise”. These are industrial verticals like manufacturing, logistics, transportation, construction, oil and gas – where you require to provide connectivity typically in a large outdoor setting where the RF environments are not very friendly. Hence the existing solutions that they have just don’t cut it,” said Puneet Shetty, VP of Product Management at Celona.

Inside offices, Wi-Fi has provided fast-paced, reliable connectivity for people sitting at screens. But those working on factory floors have, for the most part, been lacking the technology to keep pace with their corporate peers.

But now the OT workforce is set to experience digital growth of their own. Advances in sectors like AI, IoT and robotics have changed consumption patterns of technology in critical industries, indicating an industrial automation boom in the horizon.

Demands for robots and other automation solutions in factories and warehouses have soared, and companies running these environments, are overwhelmingly falling off the non-automotive wagon. AI-powered cranes, health-monitoring sensors, augmented reality shopping, etc. are rapidly changing the landscape.

“Warehouses and manufacturing floors are going through a level of automation that requires them to introduce devices and applications that ask for a certain level of predictability, reliability, and SLA that their current network infrastructure is not able to provide – unless they actually wire these things. But in terms of automation, they’re really trying to cut the wire as much as possible,” noted Shetty.

Problems like poor outdoor coverage, service disruptions and ineffective roaming have made existing networks “ a burning platform” to deploy advanced technologies on, “leading companies to look at alternatives such as private 4G and private 5G.”

Celona 5G LANLeveling the playing field for these industries is Celona. As a pioneer in private wireless, Celona’s goal is to provide a network that is easy to bring up, use and manage at scale. The result is a 5G LAN that provides uninterrupted mobility, strong wireless security, and consistent coverage across noisy and unfriendly outdoor locations, and operates like the corporate Wi-Fi.

Celona’s 5G LAN is engineered to deploy in extended outdoor places, production environments, and uncarpeted areas that make low-quality RF environments.

Celona has assembled a fairly broad 5G portfolio since their last year’s presentation at Mobility Field Day. The list includes physical and digital SIMs, indoor/outdoor APs, a 5G LAN operating system, and the Celona Orchestrator for LAN operations.

“We have built a solution from scratch that has all the different pieces that you need to run and operate your own private wireless network,” said Shetty.

Celona has recently added high-performance 5G access points to its portfolio. Available in both the US and global markets, the APs provide interference-free 5G coverage in both indoor and outdoor locations.

Celona’s 5G APs promise the same ease of deployment and deterministic performance that rings through all of Celona’s portfolio, making them the perfect devices for rugged industrial environments.

The Latest Version of Celona OrchestratorAcross the board, Celona’s products have the Celona software footprint enabling a coherent operation model, akin to a Wi-Fi network’s. The Celona Orchestrator, which is the brains of the platform, offers a breadth of administrative capabilities for easy and effortless deployment, management and operations of the LAN.

The Celona Orchestrator DashboardThe latest version of the Orchestrator includes one-click inventory onboarding and zero-touch bring up from day 1. It has a built-in channel planning tool for bringing up the cellular network in the orchestrator. Device Experience Analytics provides a holistic view of the state of the overall network, combined with device analytics.

One of the most notable changes that Celona is bringing to the platform is turning over more control to the customers. In response to a growing demand for autonomy in MSPs that serve enterprises with low or no on-site skills, the new Orchestrator offers advanced troubleshooting, easy configuration, diagnostic tools and self-service workflows. These allow users to be high touch with the solution without the support and assistance of field experts and engineering teams.

Wrapping UpA bulk of the world’s economy balances on digital transformation, and it ties directly to wireless networks. In industrial environments where there is a burst of noise and signal reception is weak, a private 5G LAN augments the network, providing 10 times more bandwidth, ultra-low latency for faster compute, and blazing fast speeds. In plain-speak, all these amount to high-quality Internet access necessary for OT adoption. Celona’s private 5G solution promises all these with lower deployment and maintenance hassles, and a lower housekeeping. It is designed to serve a wide variety of use cases and accelerate time-to-market, enabling a rapid-paced digital transformation.

For more information on Celona’s private 5G solution, be sure to watch Celona’s full presentation and the demo in the following session from the recent Mobility Field Day event on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Adopting Private 5G in Industrial Environments with Celona 5G LAN

View Details

Be ready for a broad overview of modern enterprise cloud technology as we’re delighted to invite you to tune in to Cloud Field Day 17 taking place May 31 and June 1, 2023. In an era where the cloud has revolutionized industries, cyber security, platform operations, data protection and true integration take center stage. At Cloud Field Day we’ll immerse ourselves in the world of cloud technology along with independent technical content creators and pioneering companies.

Event ScheduleThe event begins Wednesday, May 31 at 9AM Eastern with HYCU, who’s hosting us at their Boston office. Join us as we delve into HYCU Protégé, data protection as a service, and Rcloud, the first low-code development platform for data protection. We’ll see how HYCU brings data protection everywhere including key platforms like Atlassian, AWS, and Google Cloud. Continuing the journey at 11:30 AM, Morpheus Data will share their expertise on the transition from cloud management to platform operations. Discover how Morpheus fosters enhanced connectivity across developers, security, operations, and finance teams, unifying hybrid private cloud environments, and spanning VMware, Nutanix, AWS, and Azure. At 2:30 PM, RackN will take the stage, shedding light on the operations side of platform engineering. Gain valuable insights into ensuring reliability, availability, and speed with RackN Digital ReBar Infrastructure as Code.

On Thursday, June 1, we start out at 8AM ET with Zerto, a Hewlett Packard Enterprise company, presenting an exciting session on real time detection and protection against ransomware. Learn more about the recently launched Zerto 10 Platform for an innovative solution that combines cutting edge technology with robust data security measures. At 10:30 AM, Couchbase will bring National Cloud Database Day to the audience with a discussion on their groundbreaking Capella platform, architecture insights, and compelling customer stories. We’ll also get a live demo showing the Couchbase Cloud Database platform. Then at 1:30 PM JetStream Software will demonstrate the cloud’s transformative impact on disaster recovery and cost-effective data storage. Learn about the seamless integration with Microsoft Azure VMware services and Azure NetApp files empowering organizations to optimize resources and enhance operational efficiency.

Watch the Sessions LiveAll of our sessions are broadcast live on LinkedIn with recordings available there all week long. For those of you unable to join us live, all of our sessions are recorded and shared on our YouTube channel. Engage with us and the rest of the cloud community by joining the conversation on Twitter, LinkedIn, and Mastodon using the #CFD17. To stay informed and explore the expertise of our independent technical experts, we invite you to visit TechFieldDay.com. Subscribe to the YouTube channel for a wealth of Field Day content. For real time updates and thought provoking discussions, Follow us on Twitter, Mastodon, and LinkedIn.


© Gestalt IT, LLC for Gestalt IT: Elevate your Cloud Knowledge at Cloud Field Day 17

View Details

E.S.G. or environmental, social and governance is part of the mainstream thinking, and at the core of every leading organization. Trillions of dollars of yearly investments that take into account E.S.G. concerns are proof of that.

But E.S.G. initiatives are in a similar position to where climate change was a few years ago – not ready to affect extreme changes at all levels.

The widespread deployment of technology – IoT being the most prominent example- has a way to change this. Tech companies making notable strides in enterprise IoT believe that Internet of Things can be the key to close the Pandora’s box of concerns that unsustainable business practices have opened up.

At last week’s Mobility Field Day event in California, Ruckus Networks demonstrated an analytics platform that provides bespoke application-level solutions that power organizations’ E.S.G. efforts, and serve some very important real-world use cases.

The presentation showcased Ruckus IoT Insights, “an application-level data processor” that is part of the Ruckus IoT Suite. Ruckus is building a catalogue of applications on it to solve real-world problems at enterprise level, and “deliver outcomes for end users”.

Assessing ImpactsTo be E.S.G.-focused, organizations need data to draw intelligence from. By tapping into the reserves of data flowing in through IoT devices, enterprises in any vertical can become good corporate citizens, and fulfill certain E.S.G. goals.

Ruckus Networks recognizes that with the quick rise and implementation of IoT across sectors, there’s sufficient data to power E.S.G. practices. But lack of analytics has left a majority of organizations unable to quantify this data to environmental and social parameters.

With its eyes set on a range of vertical-led applications, Ruckus Networks is trying to solve this problem with the IoT data that is processed by the IoT Insights platform.

The Ruckus IoT Suite comprises a set of technologies designed to enable IoT adoption in enterprises. It comprises IoT gateway access points that connect devices to the Ruckus management platform – the IoT Controller.

The IoT Controller is the central management server that does security, management and connectivity of IoT network and deployments. Inside the Controller, the IoT Insights is a program that performs application-level analysis and logging of events.

The Ruckus IoT Insights DashboardFocused on app-level solution, IoT Insights features an intuitive display which constitutes a floor plan, and events metrics shown in the form of diagrams. Sensors in the building show up on the map, changing color as they trigger.

The platform can pull up data from all available IoT devices, from very simple to advanced sensors. “Our Insights platform brings in real world data from a whole range of different access points and sensors into our platform,” said Andy Barnes, Sr. director of Product Management, Ruckus Networks.

Real-World ApplicationsThe Solution Panel features all the solutions that Ruckus is offering. These include energy management, water management, environmental monitoring, space optimization, building health and environmental carbon footprint.

“The solutions are next-generation. These are the things that people are interested in, because IoT is all about the data,” said Barnes.

He demonstrated some of the solutions that Ruckus has built on top of its IoT data.

Energy management is a priority in almost all the verticals Ruckus Networks plays in. With energy costs spiraling out of control, this is a solution that most deserves a spot on the list.

“When you’re running very large buildings in education or hospitality, where you have huge energy consumption bills, if you can get an understanding of how much energy is being used, where and when it’s being used, you can start to get to grips with it, and reduce your energy usage,” said Barnes.

This in turn helps curb carbon emissions and manage the overall CO2 footprint of the building.

“When we’re developing solutions and working on how those solutions are going to be integrated into our platform, we look at it from a very wide range about how we are going to solve things for environmental and social governance,” informed Barnes.

Ruckus’ solutions enable smart energy management with insights on metrics like power consumption, power cuts, distribution and utilization.

Ruckus also has a host of safety and tracking solutions like Staff Safety, Medical Assistance and Location Services.

Ruckus IoT InsightsData is fed into the IoT Insights platform by connected IoT devices deployed in different locations. “We’ve mapped those locations into our IoT ecosystem,” informed Barnes.

Depending on the application, IoT Insights analyzes the data and sends out insights matching the use case. For E.S.G. use cases, the application cranks out insights on things like power consumption, space utilization, water usage, plumbing pipe bursts, mold growth, the health of residents, CO2 levels, air quality – all of which are critical to the overall health of spaces and their occupants.

For a safety solution, the application produces different insights using the same data, such as location of an employee, movement of assets, events like gunshots and fire breakouts, and triggers an alarm in real-time.

The events are captured and logged quickly into the system. When an alert shows up, it is geolocated for the operator to know the exact location where the event is happening. If there’s a camera nearby, they can pull up the footage, see what happened, and use the data for auditing.

Wrapping UpAt its core, E.S.G. is just common sense. It is doing more with less, and saving costs in the process. Ruckus’ solutions are aimed at meeting long-term E.S.G. goals, and empowering verticals like hospitality, education and rental real estate. Even if a solution does not produce immediate effects for a customer, in the long run, it will help realign with the rising urgency for sustainable practices, and secure substantial cost benefits.

With a few changes consistently applied, it maybe possible one day for even the smallest organization to become a green business. Ruckus’ solutions provide the push and pace critical to powering E.S.G. uses cases and elevating awareness, and in the recessionary economy of today, where E.S.G. sometimes takes a back seat, it helps organizations of all sizes adopt it.

For more information on the solution, and for all their latest updates, be sure to watch Ruckus’ presentations from the recent Mobility Field Day event on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Managing ESG Impacts with Application-Level Solutions on Ruckus IoT Insights

View Details

I recently wrote about Catchpoint’s presentation at Network Field Day 29, That blog compared Catchpoint to some competing products or at least other products that include some similar capabilities. Catchpoint’s stated goal is to be the Best at Internet Resilience.

This article provides a mildly deeper dive into products’ relative capabilities, and then looks at Catchpoint from the Internet Monitoring and Resilience perspective, trying to answer the question: What are the top differentiating capabilities Catchpoint provides for Internet Monitoring, etc.?

We’ll finish up with a Troubleshooting Use Case walk-through, looking at how the readily available reports in Catchpoint solved an actual SaaS app slowness problem.

Network/App Response Monitoring ProductsIn the network and application performance monitoring (etc.) space there are several products. There are overlaps in some or many capabilities, but it can be hard to tell the products’ capabilities apart. However, Catchpoint differs in that it’s a solution that monitors your entire internet stack, rather than just applications and network traffic. To that end, it’s focused on the experience of the user through the entire digital service delivery chain.

Take a Closer Look with Catchpoint: Synthetic Monitoring Live Demo – Networking Field Day 29Catchpoint’s PositioningCatchpoint’s intent is to be the best at Internet Resilience (including monitoring and reporting) overall.

That’s quite a goal! The word “resilience” suggests “fast troubleshooting” to me, but in this context it’s about developing a comprehensive monitoring strategy that enables predictive insights, contingency planning and continuous improvement over time. A company with a resilient internet should be able to proactively deal with issues before they impact their users and be able to implement alternative paths that prevent outages. We’ll take a look at how they do that below.

Why Best at Internet resilience? Well, just about everything lately depends on the Internet. Especially delivery of Internet application content to customers and WFH staff. Or Internet access to office apps from home or while travelling.

Datacenter, CoLo, and Cloud traffic between apps and data storage may travel over dedicated links. But dedicated links are subject to much less variability. So, the entire Internet is the bigger challenge, and requires an application focus. Catchpoint of course handles other types of links as well.

What are the Top Catchpoint Internet Capabilities?I asked Catchpoint about this: what are the top Catchpoint capabilities regarding Internet Resilience?

The answer:

  • Catchpoint has the most global monitoring points for customers to leverage. At the time of this writing, (2022) Catchpoint has over 2000 vantage points across the Internet, including monitoring points in China which makes them less impacted by the Great Firewall.
  • Catchpoint can do outside-inwards monitoring/troubleshooting, e.g., from the desktop of a user travelling in Dubai having problems accessing corporate apps or SaaS. This can provide data on problems invisible to competing products.
  • Catchpoint provides focus: monitoring, reporting, and alerting on issues you care about. E.g., the latency of an application to, say, 3 locations. It does RUM (Real User transaction Monitoring if desired. It also does synthetics. I’ve been cautioned that “synthetics” means different things to different vendors. Catchpoint can do basic RUM (web URL request components: DNS, connect, SSL establishment, wait time, etc.). Or “synthetics 360”: deeper dive diagnostics, providing developer support. (For more on this, see also this set of web pages.) Catchpoint monitors key statistics Google uses to score websites. And Catchpoint has plug-ins for the Chrome and Edge browsers that can capture additional useful data.
  • Catchpoint reports “User Sentiment” – monitoring third parties for user comments, down detection, etc. In other words, reporting on external perceptions of performance as well as the hard network performance data points.
  • Catchpoint includes an Internet Weather Report and can monitor as much or as little of the Internet as the customer wishes (and wishes to pay for).
  • Catchpoint is independent, not tied to a hardware vendor or other functions. It is agnostic about your network, server, cloud, CoLo, and other brands.
  • Expertise. Catchpoint includes consulting services by a value engineer and a customer service engineer to new customers. This ensures identifying key use cases, setting up data collection, and demonstration of how to use the various relevant reports Staff augmentation or further consulting services are also available.

What else makes Catchpoint different aside from its enormous global observability network? One item mentioned is finer data granularity, with no limit on retention.

Note also that Catchpoint has a lot of basic to intermediate documentation about various skills relating to monitoring and troubleshooting. This includes some good how-to documents.

About Catchpoint’s MeasurementsCatchpoint’s “web RUM” allows monitoring of the various components of a web-based application. Consider that such an application might have multiple global users accessing micro-services scattered around various sites.

Public-facing web apps require many Internet services. That starts with DNS, but includes Content Delivery Networks (CDN’s) as well. If their response is slow, the application experience will be degraded. One common potential problem is mis-configured global CDN services, where a user is hitting a CDN in remote location, rather than a closer one.

Another key set of measurements relate to Internet path. What path is a given user’s or site’s traffic taking, and is some segment of that path performing poorly?

In relation to Internet path, BGP is of course of major interest. Monitoring BGP peering, Internet paths for various IP prefixes, etc. is important. Catchpoint’s capabilities around BGP and Internet paths will be discussed in a follow-on article.

Catchpoint does also provide end-user WiFi and other monitoring for user-centric problems. But that’s a topic for another time and article.

The reason we use networks is of course applications, in the broad sense. Catchpoint can monitor:

  • DNS
  • CDN’s
  • BGP
  • Voice (VoIP) and video quality
  • SaaS apps (like Salesforce)
  • Cloud apps (like Teams and Zoom)
  • API’s

To sum up, Catchpoint monitors web application and component performance.

One valuable use of Catchpoint is working with the application owners to determine the slowest components to load, with the objective of speeding up page loads.

The following example walks through troubleshooting an actual problem. One consequence of finding the cause might be a change in the web page to improve performance under adverse conditions.

Take a Closer Look with Catchpoint: BGP Monitoring Live Demo – Networking Field Day 29Internet Troubleshooting ExampleI’m a classic techie: show me some details! I hope you feel the same way. Let’s look at some detail!

Catchpoint walked me through a real-world example. They have a SaaS CRM app that we won’t name used by some of their staff. (Note: all of their staff is WFH, Work From Home or wherever.)

The app had some problems. This section showcases the data provided by Catchpoint. We start with an overview page.

Notice the first “tile”, top-left in the following screen capture (I added the red rectangular border).

Catchpoint measures the availability of applications from different vantage points. It provides insight directly on the backbone of Internet from Data Centers and ISPs all over the Globe. Many times SaaS applications are available from the vendor’s perspective but users are still unable to access them. This gauge represents the reachability to actual end user devices regardless of their location.

Looking at the two bottom left tiles (see below for close-ups), red is bad, as usual: higher page load times and page load failures.

The bottom left tile shows synthetic monitoring from the end user device, the next tile to the right shows actual real user experience as rendered in the browser. If you home in on the time (x-axis), the left tile shows problem onset before the middle one: apparently there were no real users of the app at 9 AM.

Then there’s the right bottom tile:

The bottom right tile shows synthetic testing response times as measured from the Enterprise Nodes. These would be agents on nodes in the organization’s network, but dedicated machines with no user workload. They can do browser emulation.

So why are the red datapoints on the right lower? Answer: failure is faster. Those web page loads failed to complete and timed out.

The upper world chart tile shows real user performance, color-coded.

This helps you quickly see where affected real users are.

Hovering over a data point, brings up some additional data. (Not shown here.)

But there’s even more data readily available!

Clicking on a data point and then on the 3rd icon on the left side bar brings up a different set of information, shown below.

The top shows a timeline of measurements. Selecting one shows further data below the timeline: What the web page looked like, and various statistics. The bottom “filmstrip” shows what the web page looked like at various times as it rendered. This can help you see where things slowed down or failed.

If you look again at the top set of data points over time, notice that some successful page loads were twice as fast as others. This suggests some random delay somewhere.

Scrolling down provides more information, a waterfall chart of objects loaded. The highlighted line shows a moderately long wait for that object.

Clicking on that brings up more details:

Scrolling further down, we see:

The video in row 32 is taking about 4 seconds to load. Slow!

And that was the actual problem: the web page includes a MP4 video clip. It is larger content and was taking a longer than usual time to download and render.

This provides the basis for an informed decision. You (and any other parties involved) might consider:

  • Do you put up with occasional page fails (timeouts) due to the video clip when some sites or regions are experiencing congestion and slowness?
  • Or do you remove the video clip, or reduce its resolution to reduce the number of bytes transferred, etc.?

That also gives the flavor of how this might be used in developing or maintaining a web app: use the RUM data to optimize web page load times, etc. Additionally, it allows you to hold SaaS Vendors accountable for content on their sites. Catchpoint RUM data shows how many times a page was loaded over time so quantifying the impact that a slow page has on employee productivity is easy!

If you go back to the original screen and then scroll down, there was more data available there.

The upper right tile clearly shows a spike in average load times.

The bottom left tile breaks out load times by ISP, with the small squares representing one user. This helps spot where there is an ISP problem. The bottom right tile summarizes the per-ISP data in text form.

Catchpoint’s Day 1 SupportI’m seeing a growing trend in networking and IT awareness that buying software or doing automation can result in “shelfware”. Staff needs to know how to use the new tool and have a good reason to do so.

As part of its process, Catchpoint includes services by a “value engineer” as well as a “customer success engineer”. The value engineer’s job is to understand top use cases and get the customer set up to monitor what is needed and understand the reporting.

Deeper dive and site staffing are also available for a fee.

ConclusionCatchpoint provides a lot of reporting out of the box. I’ve found myself somewhat overwhelmed by fast presentations (e.g., at Network Field Day). Catchpoint staff walking me through the above use case helped, and I’ve tried to share that in this article.

My hope is that sharing that experience with you, the reader, will help you envision how Catchpoint might be useful for monitoring your Internet stack as well as other applications, re-engineering them to be more tolerant of slowdowns, and respond to outages more rapidly through well-organized pre-analyzed data. Catchpoint makes your Internet more resilient which requires more than traditional application or network performance monitoring. The breadth and depth of monitoring capabilities shown to me suggest that they can do just that.

Watch all of Catchpoint’s videos and demos from Networking Field Day 29 on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Catchpoint Excels at Internet Resilience

View Details

Summer is fast approaching but the world of wireless and mobility is heating up May 17-19 in Silicon Valley thanks to Mobility Field Day 9! This packed event will bring the most respected voices in the community together with the minds working on the most exciting technologies to create an experience unlike no other.

Mobility Field Day Presentation LineupOur event starts off on Wednesday, May 17 with a three-hour presentation from Juniper, powered by Mist AI. They’re introducing a major new product category and talking about some of the significant advancements they’ve made in AI networking. They’re followed by Fortinet, who will be talking about AIOps, SASE as a part of the access layer, and a full lineup of their famous product lines. We’ll wrap up on the first day with a roundtable discussion featuring our community tackling some of the hard questions in the space today.

Thursday, May 18 starts off with Cisco. They’ll be talking about their differentiation in the 6GHz wireless space as well as some discussion around AIOps. Next up will be NetAlly who will be jumping into the cybersecurity space to discuss their recent launch of the CyberScope! The final presenter on Thursday will be Ruckus Networks with an update on their technology since we spoke to them last year.

Friday, May 19 opens with another great presentation from Arista. They’re coming back once again to discuss the integration of their wireless edge technology into the amazing campus fabric they’ve been building. The final presenter on Friday is Celona, one of the pioneers of private LTE and private 5G, who will be giving us an update on the state of the technology.

Be A Part of The Live ActionMobility Field Day 9 will be streaming live at our website at TechFieldDay.com as well as on the Mobility Field Day event page. You can check out our live stream on the Tech Field Day LinkedIn page as well. If you miss any of the presentations or need to watch them again on-demand be sure you’re subscribed to our YouTube channel. If you’re on social media and you want to talk about what you’re hearing or ask a question to one of our delegates make sure you use the hashtag #MFD9. We can’t wait to see you at Mobility Field Day and hear from you!


© Gestalt IT, LLC for Gestalt IT: Making Mobility Magic at Mobility Field Day 9

View Details

With uncertainty rife in the world today, businesses need resiliency in order to survive and move forward. Polls say that while almost all businesses believe that resilience is critical, less than half say that their organization is resilient.

A business faces many costly interruptions in the form of cyber-attacks, natural disasters, and failures all of which accumulate to downtimes accruing huge loses. But production stoppages and revenue losses aren’t always caused by unplanned downtime. Scheduled downtimes too mount to millions over time. Although anticipated in advance, planned downtime for routine upgrades breaks continuity, and set businesses up for losses.

Thankfully, technologies have come a long way to enable business continuity. HPE Aruba is one of the companies in that front pioneering ways to ensure continuity. One of the ways Aruba promotes business resiliency is through software redundancy.

At the recent Networking Field Day Experience at Aruba Atmosphere 2023, HPE Aruba demoed its zero-downtime software upgrades with the Aruba CX 6400 switch series. Ed Chang, VP of Campus Switching and TME, Yash Nagaraju, Sr. Manager, TME Global Wired Enterprise Switching, and Anup Mehta, Product Line Manager gave a joint presentation that explained how the CX 6400 series minimizes, even eliminates downtime during software upgrades, and provides always-on networking.

Ways to Build a Resilient Network There are many ways to build a business resilient network. Resiliency can be ensured through operation of assets, such as configuration, deployment and monitoring . Having physical redundancy within switches like the power supply too provides resiliency. The physical network itself can be made resilient by deploying a dual system where a secondary network provides connectivity when the primary network goes down.

Redundancy is also achievable through routing protocols like multipath routing where alternative paths are used through the network to route traffic ensuring fault tolerance and better bandwidth.

At the software level, upgrades typically entail a downtime during which firmware are downloaded, codes are refreshed, and switches are rebooted, and that has a cost to the company and its users. Software redundancy ensures continuity of performance through these upgrade windows.

Aruba CX 6400“Aruba 6400 gets deployed all the way from access, aggregation to core. Each one of this upgrade process has to be zero-downtime, because they deploy in hospital environments,” says Mr. Nagaraju.

Aruba CX 6400 switches power mission-critical networks that have zero tolerance to downtimes. So maintaining high availability around the clock is non-negotiable.

Inside the ArchitectureThe secret to the always-on availability of 6400 switches is the CX software operating system – AOS-CX – that is built within all HPE Aruba switches.

“It is a common operating system across all of our portfolio, from campus to datacenter, and there are some key tenants that help us enable this high resiliency to help customers when they want to do upgrades,” says Chang.

AOS-CX has a modular, database-centric, microservices architecture. With microservices, entire applications are broken down into smaller parts that run independently. State synchronization ensures all states are synced in the database for users to access.

“We have separate databases that keep information on state, as well as performance series database that keeps information about what’s going on within the switch,” says Mr. Chang.

Although running independently with their own realm of responsibility, the services are accessible to each other, and at the same time available to the users for monitoring, configuring and managing.

“It really leverages the databases as well as the independent microservices,” says Mr. Chang.

The switch architecture allows for physical redundancy with cluster and stacking, hot-swappable ports and always-on PoE. Built-in analytics provide additional management and configuration controls for added redundancy.

Upgrade without DowntimeHPE Aruba looks at the full scope of frequency, cost, cause and consequence of planned downtime to minimize the same. Currently, it provides two services for this – hot-patching and in-service software upgrades or ISSU.

Hot-patching offers targeted, customer fixes for specific defects, bugs and vulnerabilities. Customers can report isolated issues, and get patches for them when the goal is to avoid a physical reboot. Aruba TAC updates the code, and delivers it directly to the customers. At the customer end, all they need to do is deploy the fix.

“The process is simple – they call in, we identify it, create a patch, and give them an image. They update this,” says Chang.

All hot patches are automatically re-applied to future reboots and rolled into future releases.

Customers prefer hot-patching as it has a quick turnaround, and is non-disruptive – it does not affect the network or the traffic when applied.

The second is in-service software upgrades. This too is an interruption-less upgrade that includes bugs as well as feature updates. ISSU ensures rapid software upgrades within a release, without any traffic interference.

“Typically in an update of a software, there is a maintenance window, and some downtime scheduled. To help customers in the chassis-based systems, we allow updating that software without a reboot of the system itself.”

Benefits of ISSU include increased availability, continued connectivity with end-points and applications, and a fully working data plane, through the upgrade process.

“We roll this to future releases so that customers can use the ISSU process to update again,” said Mr. Chang.

Wrapping UpUpgrading a fleet of network switches is never easy. All devices must stop working when an upgrade is underway. Aruba’s zero-downtime upgrade provides a way to download a version or hot patch without having to take the system offline. The upgrade process neither interferes with the availability of the switches, nor diminishes their performance. If anything, it makes sure that bugs and vulnerabilities are timely fixed, and new features are installed non-disruptively. By rolling updates into future releases, Aruba ensures that systems perform with maximum efficiency, and at minimum risk.

For more information, check out Aruba’s demo of this from the recent Networking Field Day Experience at Aruba Atmosphere 2023.


© Gestalt IT, LLC for Gestalt IT: Zero-Downtime Software Upgrades with Aruba CX 6400

View Details

Businesses are set to modernize their IT infrastructures, turning to cloud and edge computing as they move out of datacenters.

To shift from the static datacenter to a more dynamic and geo-distributed setup, they wind up using a mix of cloud services, colocation datacenters, and edge facilities. This move that has set in motion a series of changes in the network topology, and unlocked a floodgate of data, opening them up to vulnerabilities from within.

At the recent Networking Field Day Experience at Aruba Atmosphere 2023, one of the solutions HPE Aruba showcased was the Aruba CX 10000 Series. Designed for modern distributed datacenters, the CX10000 represents a new category of switches that enable a network fabric immune to legacy limitations.

Designed jointly with AMD Pensando, CX 10000 is a switch engineered for data-first modernization. Director of Data Center Switching PLM, Todd McDole gave an overview of the market context, while Sr. Manager TME Global Wired Enterprise Switching, Yash Nagaraju demoed the product making it visual to the audience.

Opportunities and ChallengesThe evolution of network over the years happened at a cadence of ten years. If you rewind the clock back to 1990, this was the era of first-generation datacenters. Flat networks and layer 2 switches made the basic construct.

Cut to 2010, datacenters have entered the third generation, which is characterized by hardware appliance and software agent-based security, emergence of spine-leaf architecture with its twin layers of access switches, and microservices applications, among other things. The legacy architecture did not lend well to this wave of modernization.

Although the third generation is a gigantic leap forward, the design has several drawbacks. The way that third-generation datacenters are built is a combination of units of compute – the racks – and a spine-leaf topology that houses bolt-on applications like firewall and load balancers, that are added on an ad-hoc basis.

As microservices causes containers to talk to each other, the usual north-south traffic – that simply enters and exits the network – is now joined by a rush of east-west traffic that move laterally from server to server. This causes enterprises to use a technique called hairpinning in which packets make multiple hops and traverse the network twice, to get security checked.

“It’s a really inefficient use of this very elegant scale up, scale out spine-leaf architecture,” pointed Mr. McDole.

More hops introduce latency, and takes a heavy toll on performance, making the design inefficient, and complex, not to mention costly.

A Different PathHPE Aruba is doing things differently. In 2021, Aruba started a new category of distributed services switching. The architecture takes bolt-on services from the service leaf, and places them in their logical place in the network – inside the rack itself.

Powered by the AMD Pensando P4 processor, HPE Aruba CX 10000 offers the best of L2/3 switching for modern datacenter fabrics.“You already need a leaf switch within every rack. So why not logically move these services into that top-of-rack switch? We’re essentially providing a firewall behind every port on the switch,” said Mr. McDole.

Aruba CX 10000 SeriesShipping since 2022, the CX 10000 resembles a typical top-of-rack switch, but has a major point of difference. The new architecture allows services to be applied where the workload is running.

It provides 800G of stateful layer 4 through 7 packet processing. Software-defined stateful services such as firewall, DDoS, telemetry, encryption services and network address translation (NAT) can be deployed inline, as and when the services are required.

The racks can be scaled linearly to match the growing capacity, as opposed to adding a new firewall every time capacity is exceeded, thus saving cost and administrative burden.

The CX 10000 uses the Pensando Elba P4 DPU. “It’s a fully programmable pipeline. It has lots of additional capabilities that can be added over time directly into the switch through software, instead of adding in additional appliances dedicated to a singular function in the network,” says Mr. McDole.

By enforcing security at the network access layer edge, the CX 10000 enables security implementation within the rack, saving traffic multiple hops and significantly improving latency. Services are delivered inline across all ports.

In many scenarios, customers are “seeing an 83% decrease in cost versus how they’re doing things today with the traditional 3rd generation model,” says Mr. McDole.

The CX 10000 platform is managed centrally via the Aruba Fabric Composer. The orchestration layer provides automated configuration and unified security policy management across the fabric.

The platform integrates with a broad ecosystem of security and network performance solutions like the GitHub Advanced Security.

The CX 10000 Series mounts in any EIA standard 19-inch rack or cabinet, on horizontal surfaces only. 2 and 4-post mounting kits are sold separately.

Wrapping UpThe CX 10000 pioneers a new era of switching that elevates the present-day architecture by defeating its limitations. Cut for the changing network topology, it unlocks new levels of performance and efficiency. Most importantly, it fuels a new generation of datacenter fabrics that can support modern applications infinitely more efficiently and cost-effectively.

For more information on the Aruba CX 10000, be sure to watch the full presentation from the recent Networking Field Day Experience at Aruba Atmosphere 2023.


© Gestalt IT, LLC for Gestalt IT: Deploying the Next Generation Datacenter Fabric with Aruba CX 10000 Series

View Details

In the always-on digital world of today, businesses have inherently low tolerance for operational downtime. To avert halts and outages, many resort to AIOps to manage, monitor and troubleshoot their networks. AIOps leverages AI/ML algorithms to automate triaging, root cause analysis, and closed-loop remediation of events. Its value comes from using artificial intelligence to automatically resolve growing management pains that emerge as the network expands.

At the Aruba Atmosphere 2023, HPE Aruba launched the next generation of Aruba Networking Central. A product already widely used for a spectrum of monitoring and management capabilities, the new generation builds on it with advanced AI-powered visualization and closed-loop remediation.

At the recent Networking Field Day Experience at Aruba Atmosphere 2023, VP of Aruba AIOps, Jose Tellado, and Director of Product Management, Frank Jas, showcased the new features, and gave a demo of the solution.

The Anatomy of AIOpsTypically, AIOps maturation happens in a series of stages. At the data level, it starts with basic data collection, cleaning and enrichment of data at source, and building siloed data lakes which accumulate into a global data lake, before reaching the ultimate data federation.

The models that learn from this data too evolve alongside – going from basic statistics and alerting to anomaly detection and finding correlations. In later stages, the models can go across multiple dimensions finding patterns and making recommendations. At maturity, they can be deployed in a set and forget fashion. The models’ lifecycle needs to be continually managed with routine refreshes, making sure that the metrics are not getting anonymized as that can degrade the outcome.

The most interesting part is how the progression at the lower levels ties together at the customer end. For customers, they start with the basic alerting functions which require the IT teams to handle the deeper details of the anomalies. As the models evolve, they are able to perform root cause analysis (RCA) on their own, aggregating and correlating data, and making appropriate recommendations. At the final stage of AIOps maturity, customers can leverage self-driving AI algorithms for automated troubleshooting.

Global AIAruba has a mature AIOps model that constitutes a global data lake streaming data through data federation as a single source of data, AI models that can tell users what or where the problem is, and lifecycle management support for all models.

In the presentation, Mr. Tellado offered a look under the layers showing what the workflows currently look like. At a high level, the production clusters are where all the AI models are run and trained. Although running in a shared production environment, the models don’t learn from each other, but from individual customer data. They are trained and inferred locally, so that they can detect anomalies based on the particular customer trends to enable predictive maintenance.

Data from the production clusters is PII anonymized and streamed into the Global AI Data Lake that carries stats, states, flow and model metrics. “This global data lake trains models that apply to all customers based on anonymized data,” says Mr. Tellado.

Aruba takes this a step further by allowing customers to enrich the data coming in from production clusters by injecting it with complimentary data such as device capabilities and security vulnerabilities. Customers can additionally ingest support cases and Aruba documentation.

This creates a model “that mixes up telemetry from the devices” with Aruba’s internal data, and in addition “pushing models to the production clusters that are based on this multidimensional data to actually create internal use cases.”

The models then go into the clusters for individual customers.

With the models running globally across Aruba’s 200,000 customers and 2.5 million devices, it makes it possible to find fine-grained anomalies like interoperability issues between clients and software versions, or silicon partners.

“We could also find new use cases to actually push to customers,” informs Mr. Tellado.

The Next Generation Aruba Networking CentralIn the new generation of Central, Aruba made a breath of enhancements. The changes take effect across multiple dimensions including AI and analytics, visualization and configuration.

The new design presents AI and analytics in a different view. This is backed by a new data processing pipeline in the cloud which offers improved latency, allowing the analytics to run faster and fetch quicker responses for users.

“Mostly on the redesign of the user experience, you’re going to see a completely different look and feel with the new Central,” said Mr. Jas.

The Solar System is an entity-centric navigation tool that allows users to choose what parameters they want to focus on, and view changes around it.The new Central can be activated with a single click from the Central dashboard. Just visually, the interface looks markedly different from the older display. One of goals of changing the design is to make sure that all the data that Aruba Central has access to across numerous customers and devices are easily navigable to the customers, and that operators can pan into relevant information granularly.

Aruba calls the new navigation tool Solar System in keeping with its planetary mapping style. Data is visualized in contexts and sub contexts with the thumbnails displaying summarized information that operators can click on to get more details.

One of the features highlighted in the presentation was the new Firmware Recommender introduced a month back. With it, customers can get data-driven recommendations for the best firmware for every device in the environment.

“The reason we did this is because we were already clustering algorithms in our support database, and we found out that 10% of the support cases were related to programs, whether it was the upgrade of the firmware – given the topology of mix and match devices types, customers put the wrong firmware – or they’re wondering what’s the next firmware for them, given their desire,” explains Mr. Tellado.

With a model running on top of it, the Firmware Recommender can run through a wide range of metrics such as popularity, client topology, config, security vulnerabilities and bugs, and come up with the best recommendation. This eliminates guesswork and errors, and ensures fewer support calls while enabling better performance and faster fixes.

The new Central will also have more feature releases on a monthly basis with hitless upgrades.

“We are changing our development process to follow a more continuous integration, continuous development process, doing releases on a monthly cadence. That’s much more frequent than we support with Central. That will mean that features roll out continuously, as we improve the infrastructure,” said Mr. Has.

Other enhancements focused on the platform’s operator experience include improved AI efficacy with fewer false positives and false negatives, unified telemetry pipeline, richer actionable insights, and easily executable intent-driven automation.

To know more about the new HPE Aruba Central, be sure to check out Aruba’s presentation from the Networking Field Day Experience at Aruba Atmosphere 2023.


© Gestalt IT, LLC for Gestalt IT: Improved Visualization and AI Efficiency with New Aruba Central

View Details

More than 70% IT leaders acknowledge that incorporating automation has helped save employees 10 to 50% of their time. Across industries, enterprises and startups are building increasingly automated value chains, achieving unimaginably low housekeeping and faster time-to-market. Gartner says that the adoption will continue to quicken as companies head into the later quarters of this year.

In the Delegate Roundtable recorded at the recent Networking Field Day event in California, attending delegates picked apart the automation revolution. The discussion reveals automation’s close connection to another corresponding trend – observability.

Data Is the FuelThere’s been some exciting advances in the networking space over the last decade, and a lot of it has been propelled by automation and visibility. Automation and visibility both rely on data.

“Automation is only as good as the data we’re feeding it. We have to get much better at getting that data, which is why we’ve seen a huge rise in the number of companies that are providing visibility into our network. It turns out that the data has been there all along. We just didn’t know how to see it. Companies that we’ve talked to here at Networking Field Day, and many others are trying to pioneer ways to identify data that we want to see and do something with,” says Tom Hollingsworth, former network engineer.

IntertwinedIf you think about it, automation and visibility are two sides of a coin – one relies on quality data input to function, while the other outputs quality data. There is an opportunity for automation and visibility companies to collaborate and solve each other’s problems.

As Steve Puluka, Server and Network Administrator, points out, one way of looking at it is that automation and visibility are a two-step process. Automation churns out new things, whereas visibility provides the ability to monitor and ensure that it is working as planned.

“The real opportunity in this is that observability and monitoring companies have the ability to see when something happens, and therefore send a request to an automation system to correct that issue,” he said.

If this symbiotic association can be fully leveraged, automation can play an outsize role in the remediation of network equipment failure, and other potential causes of network outages.

Low Confidence in MachinesNetwork Engineer, John Herbert noted that a barrier that stands in the way of holistic incorporation of automation is that humans have inherently low confidence in it.

There’s no guarantee that an automated system will take all the right decisions in every given situation. Like all computer programs, its decision-making skills are limited to what it knows, and that is always less than a human counterpart.

Chris Grundemann speaking at the Networking Field Day event.For some, leaning on a system like that is like blindfolding themselves and waiting for a disaster to happen, which could otherwise be preemptively spotted and sorted in a manual operation.

Human BiasEngineers fear that when automation is fragile, the scale of what can go wrong far exceeds just a security risk. But interestingly, where professionals resist trusting a system that is built by some of the best people in the job, they’re quick to put their trust on entry-level workforces who have barely begun to learn the job.

This begs the question about the real reason why we are opposed to, and in some cases, simply unwilling to trust automation? Is it because as human beings, we are inherently afraid of changes because the outcomes are unknown to us? Is it our natural tendency to be risk averse?

Hiring more skills isn’t a one and done solution to the possible errors of automation. On the contrary, bringing in more people after a certain point only introduces noise and fragility into the system.

Referring to an early presentation, Mr. Hollingsworth reiterated, “In a given system, adding people will reduce the fragility of a system to a point, and once you’ve passed that point, no amount of human interaction will make the system any less fragile, and will, in fact, make it significantly more fragile.”

Lexie Cooper, Network Engineer, chimes in that even in industries like aerospace where the smallest mistakes have big consequences, often involving lives of people, automation is woven into the DNA of the network because automation does the work that humans can’t.

Lexie Cooper speaking at the delegate roundtable at the Networking Field Day eventOftentimes, the real reason for resisting automation is because we like to see a face in the firing line to point fingers at. After all, it is infinitely easier and within our comfort zone to put the blame on a human being than a mute machine.

“In a lot of the cases, we’ve tied our identity, maybe too closely, to the CLI and to the things we do day-to-day versus the actual intent of what we’re trying to do, and I think as an industry, we’re at that point where, if you can learn how to use an assembly line to build your network instead of building everything by hand all the time, you’re going to be in the driver seat for the next generation of networking,” says author and technologist, Chris Grundemann.

Enabling Automation with ObservabilityTo tie it back to the visibility piece, automation by itself is not whole, if it is not accompanied by good visibility. Automation and observability are joined at the hip, because to build trust in automation, professionals need observability of its inner workings.

Good automation does not seize control but enables it. By piecing together automation and observability, vendors can provide operations teams the ability to look inside a complex system and understand its internal state well enough to trust it to do what it’s meant to do.

Wrapping UpThe promise of automation far outweighs its perceived perils. This Roundtable discussion gives special point to that. We are living in an era where automation plays a star role in driving digital transformation across industries. With the network expanding at an unforeseen scale and velocity, IT professionals need all the help they can get to keep up. Automation makes it possible to eliminate the drudgery and quotidian tasks. With proper implementation, it can help build an independent system that relies less and less on humans, and can do more with less. If automation and visibility companies join forces, automation can become the view of progress that it’s meant to be all along.

For more, be sure to watch the Delegate Roundtable – Visibility and Automation Should Be Working Together – from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: The Amazing Way Observability Shapes Automation

View Details

Businesses are increasingly turning to automation as a way to effectively control and maintain hybrid infrastructures, and it’s clear why. Infrastructure automation provides IT teams the ability to do more with less, and makes their daily lives easier and less stressful.

Bringing easily consumable automation to the fingertips is HashiCorp, a company that has become a household name in the infrastructure automation space. Their signature product, Terraform – is a staple in organizations that are on their cloud adoption journey. At the recent Networking Field Day event in California, HashiCorp showcased how Terraform unlocks new ways to streamline and tune up infrastructure operations.

Getting AdjustedIt is no secret that hybridization has brought both exciting opportunities and unprecedented challenges. The move to cloud may long be over, but organizations face headwinds as they get to grips with the new and formerly unseen obstacles of the new ecosystem.

The shift from a static datacenter infrastructure to one that is a mixed pool of public and private cloud consumed from a variety of vendors has made APIs the standard way of interacting. This, in no small parts, has its roots in the new patterns and principles that hybrid infrastructures have introduced at the core layers of networking, security and provisioning.

The fundamental building blocks of operations have been shuffled and rearranged overnight. Where engineers had to go through lengthy processes of filing a ticket and wait to spin up and provision an infrastructure, they could do the same with infrastructure as code (IAC) by just calling an API that would set it up and provision/de-provision it much faster. Similarly, IP-based security was replaced with identity-based security.

The Standard MOOrganizations follow a standard blueprint in their adoption of the new cloud operating model. This blueprint constitutes three phases, the first of which is tactical cloud. This is where engineering teams rebuild their tech stack based on what they need to implement the changed principles around provisioning, networking and security. An otherwise logical step to continue on their path for innovation, it is where things fall apart.

“For the provisioning layer, you might have Terraform open-source, or cloud-native tools like Azure Resource Manager or CloudFormation or just a variety of things that are already out there in the market. What happens out of this is that you have multiple different workflows because everyone really chose what was best suited for their needs,” said Melar Chen, Manager of Product Marketing, during the presentation.

The problem of inconsistent workflows across teams is further exacerbated by the fact that team members are now in scattered addresses, disparate workloads are on the sprawl, and there is no central means of knowledge transfer (KT). Not knowing which infrastructure has been provisioned opens them up to vulnerabilities, said Ms. Chen.

In stages 2 and 3 companies, companies move to having a cloud program run by a central team whose job it is to create “a central service around provisioning, security, networking and connecting services with the ultimate goal of building applications.”

Terraform for Infrastructure AutomationCatering to over 3,600 customers globally, including 180 Fortune 500 companies, HashiCorp’s mission is to fulfill the need for standardized shared services across all stages of cloud adoption.

Terraform is designed to offer the full suite of provisioning and management capabilities that home-grown solutions seldom have. It allows for a unified workflow management, policy enforcement, risk management and compliance, and visibility across infrastructures.

It bridges the gap of unmet needs of platform teams – while also keeping a cloud system of records that provides information to help tune up management efficiencies.

Standardizing Infrastructure AutomationIn her presentation, Ms. Chen gave a walk-through of Terraform’s infrastructure provisioning capabilities. “The goal with infrastructure provisioning is to have an infrastructure as code platform that becomes a shared service to the rest of the organization so that teams are be able to easily provision cloud, private datacenters, and SaaS.”

Terraform offers just that. Engineers can leverage an IAC platform to provision and manage infrastructure through its lifecycle with Terraform. As a result, they can use the same workflows for networking for all private and public datacenters, and SaaS applications.

Terraform boasts of a deep and broad ecosystem that comprises 3000 providers and 20 run task partners. The Terraform registry is the central repository for all of their ecosystem.

“Terraform is able to do automation consistently because we have over 3000 different providers in our registry. So, it is really fair to say that Terraform can do infrastructure as code for any type of infrastructure you’re working with,” informed Ms. Chen.

As an infrastructure automation technology, Terraform offers many benefits to its users. It enables faster time-to-market by taking the heavy-lifting out of provisioning, and leaving teams with a self-service infrastructure that have all the security fixtures in place.

Terraform allows teams to collaborate effectively and reuse the building blocks in the modules featured in the registry, giving them a way to work around lengthy sign-offs and approvals.

Terraform unlocks cost optimization by helping companies manage overprovisioning. “They can use Terraform to implement guardrails, policy-as-code to prevent any overprovisioning, and also embed best practices into modules that developers can reuse,” Ms. Chen explained.

Provisioning from a central platform unlocks visibility into resource utilization giving teams the opportunity to monitor and optimize utilization.

Most importantly, using Terraform can help lower cyber risks. Scattered workflows fused into a shared and consistent one that works for all infrastructures and teams, reduces chance of misconfiguration, a known cause of vulnerability.

“We have modules that experts on the cloud team can create for those with less expertise to consume, without accidentally opening your organization up to risk,” said Ms. Chen.

Terraform provides drift detection that preemptively alerts teams about infrastructure changes based on what’s reflected in the state file.

Wrapping upIf mastering agile operations is the end goal, consistency and coherence must be maintained across infrastructures and teams. Terraform drives agility by leveling the differences between infrastructures with a shared provisioning system that stretches the horizons of infrastructure as code, and standardizes a smart and intelligent approach to infrastructure management and provisioning. Adding a driverless dimension to the provisioning and management tasks makes sure that engineers don’t need to get down and dirty with the technicalities every time, while also giving companies a core competency essential to thrive in a competitive digital paradigm.

For more information, check out HashiCorp’s in-depth presentations of Terraform from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Automated Provisioning and More with HashiCorp’s Terraform

View Details

The network brings the world in a computer. With everything at the tip of the finger, one of the challenges businesses face is edge to edge visibility.

The network is bursting at the seams with countless devices and solutions deployed on its fabric. With its perimeter constantly shifting and expanding, it is becoming increasingly important to maintain a clear sight of everything to keep the network and its assets working as they should.

At the recent Networking Field Day event, one of the companies that dug deep into observability was Kentik. A startup with a network observability pedigree, Kentik is determined to unlock true observability of the increasingly complex, hybrid network of today.

Justin Ryburn, Vice President, Global Solutions Engineering, gave a briefing of the Kentik Network Observability Platform explaining its capabilities and inner workings.

For Kentik, observability is not just another new buzzword that is having its moment. Kentik defines observability as the ability to “answer any question about any network”. According to them, two key things make for true observability – a centralized repository of network data, and data enrichment.

Challenges of Being in the KnowNetworks were a lot more intelligible when decades ago, companies used to have their own datacenters and colocations, and the edge of the network used to be a branch office. A small team of network engineers would build, configure, and maintain everything. With the exception of the Internet and some carrier circuits that a company may be leasing at the time, businesses had control over all of their network.

But things rapidly changed as cloud, and edge entered the picture. Visibility went from obstructed to obscure, and suddenly the networking team is buried under a landslide of minutiae and metrics.

The shifting dynamics and realities of hybrid network make it close to impossible for teams to watch over every digital asset and interaction. The whole network operation takes a hit because of this.

The Kentik Network Observability PlatformKentik Network Observability platform offers a way for network teams to see deep into the heart of the network, and have information at their fingertips. Built on the needs of organizations on hybrid multi-cloud, Kentik watches all networks core to edge – the cloud, WAN, edge, the Internet and containers.

“We may either be delivering applications through a CDN, or have users on the enterprise network that are consuming applications through a CDN. So connectivity to the internet and those CDNs is critical for good user experience,” said Mr. Ryburn.

“We’re not a point solution that just looks at the datacenter or the SD-WAN, or a particular public cloud provider. Our mission is to be able to provide a platform that can look across all the various different networks that network engineers in the modern enterprise are tasked with looking after,” he added.

The highlight of the solution is data collection at full fidelity. The platform’s ability to measure the internal state of the network lies in its ability to collect all types of telemetry.

For deep observability, Kentik uses flow and VPC, streaming telemetry, hosts, and SNMP, additionally synthetic tests for active monitoring.

With a lot of good information buried in flow, Kentik started its journey by focusing on flow data, but soon realized that when dealing with distributed systems, no one type of telemetry answers all questions. So, they designed the platform to collect data like logs and streaming telemetry to help teams get to the root cause of issues faster.

Most enterprises face challenges planning for seasonal spikes. Kentik performs active monitoring with synthetic tests, through which it puts synthetic traffic on the network via an agent to test out the performance of the network giving engineers a way to be ahead of the game.

Kentik unlocks complete observability of the network, the parts you own and the parts you don’t.The platform integrates with a lot of data sources – Datadog, Sumo Logic, Splunk, Amazon S3, Kafka, and Google Cloud to name a few. On the output side, it pushes notifications out through ServiceNow, and send the data off to other systems including Splunk, Amazon S3, InfluxData, and Prometheus.

Inside the Kentik telemetry pipeline, data from disparate sources are aggregated and normalized, enriched with context, and transformed into deep analytics before published for a single view.

A key capability is fast and flexible query with context. The analytics Kentik provides drawing on the large volumes of telemetry data it ingests, enables teams to query back answers quickly.

More Features on the WayThe Kentik Network Observability Platform takes visibility to the next level providing teams meaningful information that helps monitor and troubleshoot the network. But Kentik is always testing new ideas and moving the research forward.

During the presentation, Mr. Ryburn informed that Kentik is currently working on building a full-on metrics platform to amend its light SNMP support. This will give operators a chance to dabble in the metrics, perform sophisticated comparisons and detect problems faster. Another capability that its working toward is events for correlation.

A project already in the works is adding a cloud topology for GCP. “For a while we’ve had some cool visualization for AWS and Azure. They can show you your regions, zones, how your network is actually built and designed in the public cloud,” said Mr. Ryburn. Seeing that the customers love those topology views, Kentik is now working on building out such view for GCP.

Wrapping upWith the network expanding in size and complexity every day, companies can’t afford keep their fingers crossed and hope for the best. Before they find themselves in the crosshairs, they need to proactively invest in a solution like Kentik’s that redefines visibility, making it easier to explore data out of the box, and delivers faster, accurate and rapid insights for directed troubleshooting.

For more information, be sure to check out the Kentik deep-dive presentations from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Observability at Full Fidelity with Kentik Network Observability Platform

View Details

For many companies, automation of business processes is business as usual. Impacted by cloud, enterprise networks have grown increasingly complex and chaotic. There’s an ever-growing number of devices, tasks, processes, and more vulnerabilities to defend against. Without automation, innovation would be stuck in low gear.

Companies are working at a frantic pace trying to push out automation to the fingertips of users. One such company is Itential. At the recent Networking Field Day event, Chris Wade, CTO and Co-Founder of Itential gave a presentation of the Itential Automation Platform.

Mr. Wade explained how the software can help companies get out of heavy-lifting, and reap the benefits of automation already available to them so that they are able to serve up self-service automation to their users.

Water, Water Everywhere, Nor Any Drop to DrinkExperts predict that the rapid infusion of automation in off-the-shelf technologies will usher a barnburner era of self-service network automation. Repeatable tasks will be offloaded to automated systems, and users will have the control to consume automation independently at their end.

But despite widespread availability, many companies are still unable to take advantage of automation to tune up efficiencies of their tasks and processes. Those before automation may call this something of a happy problem, but it can potentially accrue huge technical debt in the long run.

To address that, there is a growing ecosystem of tools and technologies that broadly, or narrowly takes on the automation challenges of networking and development tasks.

“The ecosystem is consolidating. There’s been so much innovation in the last few years within the networking space, probably more so than in the ten previous years. We’re seeing both a variety of networking things, but also consolidation in the ways to automate it which we think today spells it out. It’s a great opportunity for us to take advantage of,” noted Mr. Wade.

The Automation Maturity PathA company’s natural progression to automation typically happens in three stages. Every company on the automation journey starts at ground zero where they rely on time-intensive, manual processes that are open to errors.

Once they start down the road, they typically begin automating repeatable tasks to save time and effort. This takes a concerted effort that entails extensive scripting and development. At this point, automation is strictly siloed, and scattershot.

“When you look at the network layer, a lot of times we talk about datacenter by itself or firewalls by itself, and a lot of the organizations managing network and network automation are really siloed off like this,” said Mr. Wade.

As they progress to process orchestration, these disintegrated pieces of automation are woven together to enable organization-wide automation of processes to save time.

“End users are deploying applications and connectivity, moving things across hybrid multi-cloud. So, a lot of the services cross these silos, and it’s really breaking how we think of task-centric automation,” he said.

This is where most companies are at in their automation journey, finishing with task-based automation and going more into process automation.

Next stop is self-serve networking where customers can do everything autonomously. The self-serve networking borrows from the cloud computing model and optimizes ease of consumption.

To make self-serve networking a reality, users need to have a full and complete understanding of the system. So Itential put in place all the granularity, visibility and controls required to take advantage of the automation already existing in solutions.

The Itential Automation PlatformItential’s is a SaaS platform that combines the capabilities of multiple point solutions on Itential’s portfolio. It integrates, automates and orchestrates hybrid multi-cloud infrastructure for NetOps and DevOps teams enabling automation for individual personas, teams and end users.

Itential integrates automation into NetOps and DevOps operations helping companies reach automation maturity through self-serve networking.The platform boasts of robust integration capabilities which allow users to integrate any service or capability, no coding required. On Itential, integration happens in two ways. The platform can automatically make connection by ingesting Swagger specifications from interfaces with APIs, and generating adapters. There is no need for a system integrator to do this manually. Teams can load services in the system, and automate them right away.

“Historically, you’d have to wait on your favorite vendor six months to build something. You might have to code something up yourself, but the ecosystem is such today that we can take advantage of it immediately,” reminded Wade.

For systems that don’t have an API, Itential has the Automation Gateway module for direct plug-in and integration.

Itential offers low-code orchestration end to end. The platform leverages two homegrown products for this – Automation Studio, a drag-and-drop builder which makes it easy for NetDevOps to collaborate around automation, and Configuration Manager that builds golden configs for CLI and API devices. Teams can test and validate automation and configs in lower environment making sure that everything is working as intended.

Itential enables self-service consumption with capabilities like automated report and analysis, single view of management, real-time notifications, and easy integration with self-service portals. These make sure that useful information is at the fingertips, and automations are executed at minimum effort.

Wrapping UpThe Itential platform ties up the loose ends providing companies a demonstrably easier way to incorporate and leverage automation. It takes the small things off of the hands of network engineers and developers, and helps them pay attention to the bigger dynamics, making a more nimble NetDevOps team. By enabling self-service networking, it provides end users the opportunity to save time and improve the overall quality of service.

For more information, check out Itential’s detailed demonstrations from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Democratizing Automation for NetOps and DevOps with Itential Automation Platform

View Details

IT teams have had a nice run doing things manually a long time. But the recent tech sprawl and a tight labor market raise skepticism about whether the manual approach is anymore the appropriate approach in IT.

Typically, companies rely on operators to run maintenance and upgrades on network and security hardware. An overwhelming majority of network engineers and cybersecurity professionals have confirmed that this approach is inefficient.

A network device goes through countless upgrades during its lifecycle, putting increased pressure on operators. Making matters worse, the manual way introduces delays, and elevated risks of misconfigurations, which are the root causes of vulnerabilities.

BackBox rethinks this approach with a smart solution. At the recent Networking Field Day event, theyshowcased the BackBox Automation Platform that offers a smart way to push updates to firewalls and network devices without the grunt work. Senior Product Manager, Perry Greenwood, and CTO, Josh Stephens gave several demos of the solution showing how BackBox makes it easy to perform task and upgrades with no-code automation.

Inside the BackBox Automation PlatformBackBox features tens of adjustable, device and context-aware scripts that can be modified and reused to run upgrades on a full fleet of devices. By making changes to the variable, the scripts can used to run commands on different devices.

“When it comes to programmability, we think about it in two terms. There is the programmability where you can extend scripts and then there’s the programmability where you want to integrate with outside services, sources or whatever homegrown system you have in your IT department,” said Mr. Greenwood.

BackBox replaces error-prone management with reliable script-less automationHe assures that BackBox does not require deep Python expertise to operate. Knowing CLI and a little knowledge of Linux is all it takes to use the platform.

As device maintenance windows are typically in the wee hours, BackBox allows users to schedule upgrades ahead of time so that the routines do not interrupt their sleep. Both one-time and future upgrades can be pre-scheduled from the platform, and the system will keep the upgrades going at the set hours.

BackBox can handle upgrades for both common and complex equipment. The platform can run pre-checks to ensure that all routing and traffic conditions are ideal, making sure that an upgrade goes through successfully. When an upgrade fails, BackBox can bring the device back up using a remediation script.

The BackBox platform features an intelligent notification system that can be customized to whatever makes sense for the operators. Notifications for successful updates can be made to arrive by email during regular office hours, whereas urgent alerts can be prioritized to be sent out in real time on collaboration channels.

Designed for multi-vendor networks, BackBox currently supports 180 vendors. The platform is deployable on prem, in the cloud and in a customer-managed model.

Complimentary Professional ServiceThe BackBox platform has 47 built-in OS upgrade automations that users can choose from. If a customer is not on the list, they can request the professional service team to add it at no extra cost to them.

“We provide network automation team as a service as part of our offering. We’re not expecting our customers to have their own automation teams of Python experts to write those. We do that in house,” said Mr. Stephens.

As part of their subscription, BackBox also offers complimentary product enhancement services allowing users to fine-tune the capabilities to fit their use cases. Anything below an extended enhancement is covered by BackBox.

Wrapping UpThe recent wave of automation indicates that we’ve reached an era where technologies can reliably replicate human processes. And a few times, even surpass humans at their game. The BackBox Automation Platform is one such example. It brings operators peace of mind by keeping devices up to date without them having to oversee and install upgrades. With no scripting involved, there is near to no adoption curve, and administrators do not need to feel their way about.

For more information, be sure to check out the BackBox demos from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Automating Device Upgrades with BackBox Automation Platform

View Details

It’s time once again for the annual tradition of Aruba Atmosphere! We’re back at the event once more with a great group of delegates ready to learn all about the new technologies on display and the anticipation of what comes next.

Networking Field Day Experience Presentation ScheduleFor Aruba Atmosphere we are bring the full experience to the table. Our delegates will be attending the keynote sessions from Antonio Neri and David Hughes. They’ll be taking over the Aruba social media accounts to give you their perspective on all the exciting news. You’ll get up-to-the-minute info on what’s important in the networking, mobility, and security spaces.

After the Tuesday keynote we’re diving right in to the Networking Field Day sessions! We’re going to be hearing technical presentations from the data center networking team, wireless group, and even some security discussions as well! Make sure you check out the event page for a more detailed lineup of presenters so you know when to tune in. The presentations will run from 10:45am through 4:15pm Pacific time.

Follow The Experience LiveYou can watch the presentations live at TechFieldDay.com as well as the Networking Field Day Experience event page. If you miss the sessions you can always catch them later on our YouTube page. We’ll be watching the social media platforms for your questions using the conference hashtag #ArubaAtmosphere as well as our own #TFDx tag as well. We hope to see you online or at the show!


© Gestalt IT, LLC for Gestalt IT: Excitement In The Air At Aruba Atmosphere 2023!

View Details

Data protection technologies have come a long way over the past decade, making protection consistent across infrastructure. Technologies developed for data protection have effectively safeguarded business information not only in regular sectors, but also in government and regulatory industries.

Transforming some of the elite data protection technologies into a solution that has already over 105K users, AWS is modernizing data protection with the ability to protect exabytes of data across AWS resources.

This solution was in the spotlight in the AWS presentation at the recent Storage Field Day event in California. Head of Product, Ajay Dankar, and Head of Growth, Palak Desai gave a quick overview of the key capabilities and use cases of AWS Backup, and explained the drivers that led to designing it. Their presentation was followed by more in-depth sessions that offered a peek under the hood.

AWS defines AWS Backup as a fully-managed service that automates and centralizes data protection across tons of AWS resources. At the core, it is a solution designed to squarely meet the specific asks of users around data protection.

Balanced FeaturesToday, any business bigger than a lemonade stand needs data protection. But data protection is not just about protecting data integrity from malware and malicious manipulation. Across customers, data protection means different things. Among those, a few requirements rise up becoming the common expectations of users.

“The most important thing what we heard from our customers is that they are looking for a centralized backup or data protection solution across multiple AWS resources,” said Mr. Danker.

Drilling further into it, he explained that most users expect data protection to be first and foremost, automated. Over the past decade or so, data protection technologies have had some triumphs and tragedies, but continued innovation has helped spark new technologies, many of which have greatly benefited users.

Immutable backup is one of those disruptive technologies. Unsurprisingly, modern businesses – even the smallest outfits – are set on putting their data under lock and key, preferably in digital vaults where it is fully secure.

Immutable backups provide a way to do that. It locks data in its original state allowing it to be neither altered, nor deleted.

Another key user requirement that AWS found while researching is data resiliency and continuity. Irrespective of any change or disruption in digital technology, data needs to be available, and accessible whenever required. Users expect to have full control over how their data is used.

A requirement typical to businesses operating in the regulated industries is data governance. With the growing complexity and volume of regulations, achieving compliance in certain critical sectors is extremely challenging. It entails establishing and enforcing data management policies rigorously and in that, governance plays a major role.

AWS’ SolutionAWS tames the beast with three granular capabilities that define AWS Backup. First and foremost, it is centrally managed, and designed to make data protection at scale possible. Users can configure, manage and govern all backup operations across AWS resources, – instances, databases and volumes – accounts and regions from one place.

In tune with the increasing data needs, AWS Backup provides policy-driven protection that is fully scalable. “We give companies a centralized and policy-driven interface that can scale as they bring in more resources, or as they start backing up more and more data – the interface scales as the needs grow,” said Mr. Dankar.

AWS Backup provides automated, cloud-native backups across AWS regionsAs soon as administrators have backup plans ready to go with all the parameters defining their backup requirements such as backup frequency and retention policies, administrators can start tagging resources to them, and the service takes over managing the backups as intended.

Data resiliency is improved with AWS Backup, allowing users to copy secondary data across accounts and regions using AWS’ cloud administrator, AWS Organizations. Cross-account copies of backed up resources can be used to restore data quickly and effectively when required.

Among the things that AWS does around data governance and compliance, a key piece is audit and report. AWS Backup Audit Manager helps organizations audit compliance of their backup policies against set definitions. This is particularly helpful for regulatory industries as it not only helps keep a close eye on what active resources and practices are compliant and what are not, but it also generates an audit trail, publishing reports periodically or on demand, that are often required for legal purposes.

Best FeaturesDuring her part of the presentation at Storage Field Day event, Ms. Desai called attention to two features in particular. One of them is AWS Backup Vault Lock. AWS Backup stores backups in secure containers called backup vaults. Vault Lock is an optional feature that extends the control and security of these vaults.

Users can activate a lock on each vault enforcing immutability. In compliance mode, the lock is irremovable, which leaves the vault configuration unchangeable even after the expiration of the grace period. The vaults can only be modified in Governance mode by those who have appropriate permissions.

“AWS Backup provides the capability of vault locks which allows customers to lock their backups into a vault and define lifecycle management for it. This provides customers the ability to write once and read multiple times making the data immutable,” said Ms. Desai.

She also touched on the service’s centralized data governance feature with emphasis on reporting capabilities. The AWS Backup Audit Manager monitors, assesses and reports the health and state of backup compliance. By automatically tracking all backup activities, it ensures that all controls and compliance of policies are aligned.

Wrapping UpA company’s progression to full and complete data privacy can be messy. An initiative to implement broad data privacy across resources can typically fall into chaos or cause nonsense. A balanced solution like AWS Backup can help sidestep this cumbersome exercise. AWS Backup delivers automated data protection across resources both on AWS, and now on-premises, making protection consistent. By constantly keeping track of compliance at the back end, it can potentially prevent legal trespasses and reputation issues. Add-on features improve data resiliency and help perform faster recovery.

For more information on AWS Backup, check out AWS’ in-depth presentations on the solution from the recent Storage Field Day event.


© Gestalt IT, LLC for Gestalt IT: Elevating Data Protection with AWS Backup

View Details

Have you ever thought about how a search function operates? On the surface it sounds pretty easy. You take a dataset and you look for things in it. I’m sure that Google and Microsoft will tell you that it’s a lot harder than that but we’ll keep it simple for now. How do you know what’s in the dataset? You have to look at it before you can search through it, right? That means ingesting the data before you can perform operations on it.

When the dataset is just the contents of your phone or your laptop that doesn’t sound like a difficult proposition. When the dataset is petabytes of information in the cloud or the entire Internet it’s an entirely different animal to tame. Setting aside the whole issue of algorithms and ranking for now you have to consider some even more basic challenges. How do you ingest a petabyte worth of data? How long would it take to transfer the data to your search platform? If this is happening in the cloud will you be paying to get that data to the destination just to return smaller results? Why should you have to pay to move something only to leave it there?

Searching SmarterIf you’re scratching your head and wondering why search feels backwards you’re not alone. Cribl is a company that has asked those same questions and figured out a better answer. I had the chance to sit down recently with Nick Heudecker and talk about the latest quarterly release, Cribl 4.1. Cribl search especially got some new enhancements in this version that got my attention.

Cribl’s flagship product is Stream. Stream is an observability pipeline that lets people see what’s going on in the data. You need to feed Stream in order to observe things and the product has been growing by leaps and bounds. But you also need to winnow down the data that you’re seeing and that’s why Cribl built Search late last year.

Search is a federated query engine that lets you look through datasets, with a specific focus on security. Nick told me that Cribl specifically focuses on customers that don’t want to run two different environments to separate observability and security.

Cribl Search launched last year and here’s a great video introduction to it that happened at Security Field Day:

In Search 4.1, Cribl is getting even smarter. There’s a new S3 destination that can be added to the pipeline. There’s also a new send operator that allows Search to send data to Stream. This is one of the pieces that I think has the potential for a massive impact on the way that observability platforms operate. Rather than ingesting a huge amount of data and then combing through it you flip the whole idea around. Cribl Search looks in the data where it lives and returns results you want. Those results are then fed into Cribl Stream for your operations teams to make decisions.

While I was talking to Nick about the impact this could have on the way we consume data, he had a quote that stuck with me:

We have no more empathy for our compute infrastructure. — Nick Heudecker

That’s a pretty accurate assessment of the way that most organizations treat their data lakes. Just keep feeding it and eventually something will come out that is important. However, with the traditional search model your attempts to search that data lake are going to look more like a dam bursting. You have to move all the data into the search platform which means paying the costs to get that data out of the cloud. If you haven’t checked recently you might be shocked to see what Amazon wants to charge you to get that data back into your organization.

By using Cribl Search instead you can ensure that only the most interesting parts of the data are sent back. You can make decisions based on what you want to see and not have to pay for the rest of the uninteresting parts. More importantly, you can then use Search to find other things and feed them back into Stream. You have the flexibility to keep looking without moving the data around over and over again. That leads to reduced costs and a reduced carbon footprint over time. You get your precious minutes back and you can work on saving the planet at the same time.

Bringing It All TogetherCribl has committed to a quarterly release schedule, which is something I really like. By having a cutoff for features to make it into the release they can go out when they’re done, not when a deadline needs to be met. Incremental improvements in new tools like Search can be rolled out to help augment mature products like Stream. The rapid build process also allows Cribl customers to request new data types for ingestion. That means the platform is always on the cutting edge for their customers. I’m excited to see where Search will be in the next six months.

For more information about Cribl and their newest release, make sure to check out https://Cribl.com. To see more of their presentation at Security Field Day you can go to the Cribl presentation page.


© Gestalt IT, LLC for Gestalt IT: Rethinking Search with Cribl

View Details

This is post 103 of 103 in the series “Meet Field Day Delegate Series”

  1. Meet Field Day Delegate – Chris Arceneaux
  2. Meet Field Day Delegate – David Ball
  3. Meet Field Day Delegate – Alex Neihaus
  4. Meet Field Day Delegate – Denny Cherry
  5. Meet Field Day Delegate – Keith Townsend
  6. Meet Field Day Delegate – Brian Gleason
  7. Meet Field Day Delegate – Adam Post
  8. Meet Field Day Delegate: Nico Stein
  9. Meet Field Day Delegate – Tricia Howard
  10. Meet Field Day Delegate – Evan Mintzer
  11. Meet Field Day Delegate – Stephanie Ihezukwu
  12. Meet Field Day Delegate – Wes Milliron
  13. Meet Field Day Delegate – Shaun Bender
  14. Meet Field Day Delegate – Michael Davis
  15. Meet Field Day Delegate – Matt Callaway
  16. Meet Field Day Delegate – Scott Driver
  17. Meet Field Day Delegate – Dave Benham
  18. Meet Field Day Delegate – Manon (“Mae”) Lessard
  19. Meet Field Day Delegate – Haydn Andrews
  20. Meet Field Day Delegate – Timothy Dennehy
  21. Meet Field Day Delegate – François Vergès
  22. Meet Field Day Delegate – Jennifer (“JJ”) Minella
  23. Meet Field Day Delegate – Wences Michel
  24. Meet Field Day Delegate – Josh Fidel
  25. Meet Field Day Delegate – Chris Williams
  26. Meet Field Day Delegate – Kati Lehmuskoski
  27. Meet Field Day Delegate – A.J. Murray
  28. Meet Field Day Delegate – Josh Warcop
  29. Meet Field Day Delegate – Jeremy Schulman
  30. Meet Field Day Delegate – Micheline Murphy
  31. Meet Field Day Delegate – Scott Morris
  32. Meet Field Day Delegate – Remington Loose
  33. Meet Field Day Delegate – Stefan Fouant
  34. Meet Field Day Delegate – Bart Heungens
  35. Meet Field Day Delegate – Markus Leinonen
  36. Meet Field Day Delegate – Greg Ferro
  37. Meet Field Day Delegate – Gina Rosenthal
  38. Meet Field Day Delegate – Vuong Pham
  39. Meet Field Day Delegate – Ruairi McBride
  40. Meet Field Day Delegate – David Samuel Penaloza Seijas
  41. Meet Field Day Delegate – Faisal Khan
  42. Meet Field Day Delegate – Mary Fasang
  43. Meet Field Day Delegate – Kim Pedersen
  44. Meet Field Day Delegate – Tony Efantis
  45. Meet Field Day Delegate – Robb Boyd
  46. Meet Field Day Delegate – Jason Beshara
  47. Meet Field Day Delegate – Glenda Canfield
  48. Meet Field Day Delegate – Ben Mason
  49. Meet Field Day Delegate – Pieter-Jan Nefkens
  50. Meet Field Day Delegate – Tony Bradley
  51. Meet Field Day Delegate – Jim Jones
  52. Meet Field Day Delegate – Neil Anderson
  53. Meet Field Day Delegate – John Deegan
  54. Meet Field Day Delegate – Andy Thurai
  55. Meet Field Day Delegate – Calvin Hendryx-Parker
  56. Meet Field Day Delegate – Lariana Luy
  57. Meet Field Day Delegate – Kyle Jenner
  58. Meet Field Day Delegate – Dr. Avril Salter
  59. Meet Field Day Delegate – Shala Denise
  60. Meet Field Day Delegate – Jerod Santo
  61. Meet Field Day Delegate – Ben Story
  62. Meet Field Day Delegate – Chris Hildebrandt
  63. Meet Field Day Delegate – Scott Bollinger
  64. Meet Field Day Delegate – Phillip Sellers
  65. Meet Field Day Delegate – Steven Cortez
  66. Meet Field Day Delegate – Jason Collier
  67. Meet Field Day Delegate – Deirra Footman
  68. Meet Field Day Delegate – Jason Gintert
  69. Meet Field Day Delegate – Jamie Phillips
  70. Meet Field Day Delegate – Wolfgang Stief
  71. Meet Field Day Delegate – David Klee
  72. Meet Field Day Delegate – Chris Cummings
  73. Meet Field Day Delegate – Bryton Herdes
  74. Meet Field Day Delegate – Kerstin Stief
  75. Meet Field Day Delegate – Marc Staimer
  76. Meet Field Day Delegate – Demetrios Brinkmann
  77. Meet Field Day Delegate – Dan Jones
  78. Meet Field Day Delegate – Peter Mackenzie
  79. Meet Field Day Delegate – Mike Wade
  80. Meet Field Day Delegate – Rocky Gregory
  81. Meet Field Day Delegate – Landon Foster
  82. Meet Field Day Delegate – Firas Shaari
  83. Meet Field Day Delegate – Girard Kavelines
  84. Meet Field Day Delegate – Betty DuBois
  85. Meet Field Day Delegate – Craig Rodgers
  86. Meet Field Day Delegate – Tim Bertino
  87. Meet Field Day Delegate – Rati Jokhadze
  88. Meet Field Day Delegate – Vince Schuele
  89. Meet Field Day Delegate – Brian Knudtson
  90. Meet Field Day Delegate – Jim Czuprynski
  91. Meet Field Day Delegate – Lexie Cooper
  92. Meet Field Day Delegate – Martin Duggan
  93. Meet Field Day Delegate – Jordan Villarreal
  94. Meet Field Day Delegate – Dan Kelcher
  95. Meet Field Day Delegate – Paul Braren
  96. Meet Field Day Delegate – Chris Hayner
  97. Meet Field Day Delegate – Troy Martin
  98. Meet Field Day Delegate – Falko Banaszak
  99. Meet Field Day Delegate – Chris Reed
  100. Meet Field Day Delegate – Jay Stewart
  101. Meet Field Day Delegate – Charles Uneze
  102. Meet Field Day Delegate – Eric Stewart
  103. Meet the Field Day Delegate – Greg Grimes We’d like to welcome one of our newest delegates to the Tech Field Day community: Greg Grimes! Greg is a Senior System Engineer focused on networking and security He will be attending Networking Field Day 31 as a delegate and took a few minutes to tell us a little about himself.

Check Greg out on Twitter @Thespis377 or on the Tech Field Day Website.

How did you get into Technology and IT?My dad brought home a Tandy TRS-80 CoCo in the late 80s. I fell in love while learning Basic at the age of 12. A few years later he brought home a 486 PC. I have never stopped learning about computer systems since then.

What do you do now? Tell us a little about your current role.I’m a Senior Systems Engineer with a VAR. I do pre-sales and post-sales engineering. I am mainly focused on networks, but also work on some security designs.

What are your biggest challenges?Currently my biggest challenge is learning the sales side of this industry. I have almost 20 years of experience sitting on the other side of the table, and less than 1 year on the sales side.

Where do you see IT going in the next 3-5 years?I see a lot of Cloud in the future, but less IaaS as cost causes more of the industry to move back to on-prem for non SaaS. I also hope to see more SD-Access in the enterprise to tackle some of the security challenges of moving those IaaS systems back on-prem.

What was your first computer? What was great about it? What is your go-to computer now?Tandy TRS-80. I loved it because I had to learn how to program it in Basic. My go-to now is a PC with a lot of RAM. I prefer Linux over any operating system.

How do you manage your work/life balance?It can be difficult in my current role. I do a lot of travel as a sales engineer. I’m still learning how to balance this job. I do have the pleasure of working out of my home. So, when I”m not traveling I am at home with my family more than I was at previous jobs.

If you weren’t working in IT, what would you be doing instead?Dive instructor maybe. It’s hard for me to think of not doing something in IT or with computers.

What do you do in your spare time? Do you have any hobbies?I am an avid SCUBA Diver. I’m a certified Dive Master and used to help teach students how to dive.

What are you most excited about seeing at the event?I think I’m most excited to see what Backbox has to offer. I’ve been doing automation since the mid 2000s. Started with Perl way back then.

What is the coolest thing you’re working on right now?I’m currently designing a wireless network for the state parks in Mississippi. We are helping design outdoor wireless coverage for their RV parks as well as indoor lodge areas. It’s challenging and every park is different.

Who inspires you?One of my directors, Jeremy Sanders. I am always in awe of his insight and knowledge.

As a child, what did you want to do when you “grew up”?I wanted to be an officer in the Air Force and do something with computers. I eventually enlisted in the AF, but even though I scored exceptionally high on the ASVAB they put me in the Security Forces career field.

What super hero movie character would you like to be and why?Ironman or Batman. Mainly because they don’t have super powers and use their brains to save the day.

What is your favorite thing about what you do?I love meeting new people and getting to know them. I also really enjoy building new systems.

If you won the lottery and could retire, what would you do with your time? I’d probably get a PHD and teach somewhere. I really enjoyed teaching SCUBA. I also really enjoyed my Master’s courses at MSU when I would get to teach a class on a specific topic.

Thanks for sharing, Greg!
Be sure to see Greg as a delegate at
Networking Field Day 31 April 12-13!


© Gestalt IT, LLC for Gestalt IT: Meet the Field Day Delegate – Greg Grimes

View Details

This Storage Field Day event saw a mixed pool of presenters – big players and some fast-growing, high-octave companies from the traditional storage world. The technologies they brought into focus revealed the dominant market demands and evolving customer interests. So we asked the delegates what their key takeaways were, as far as industry trends are concerned, and what their thoughts were on the solutions.

Block Storage Is BackBlock storage has returned with the rise of stateful applications that demand high-performance storage. “We’re seeing block storage reviving as a common industry trend. A couple of vendors I know who are working on new product lines, specifically for distributed block storage, also solve use case for distributed SQL databases which are coming into market. A lot of startups are also working in that area,” said Rohan Puri, Storage System Developer.

Rohan Puri speaking at the delegate roundtable at the Storage Field Day eventDespite the wind blowing in favor of object storage lately, block level storage still retains its favorability with customers, as was made evident with solutions like StorPool Storage.

But as one delegate pointed out, its relevance was never really lost, because when it comes to the physical architecture, block is the core underlying implementation of how data is stored in any type of storage.

More of the SameIt rang clear at the presentations that some of the new solutions entering the market today bear reminiscence of those from years back. This is not a coincidence, but a confirmation that at the architecture layer, not much has changed with storage in the past decade.

Most of the innovation in recent years have been concentrated to the overlaying data services. “In a lot of the presentations we saw, the vendors were more focused on the value of the solutions that they do, because at the end of the day it is commoditized,” pointed out Max Mortillaro, datacenter consultant.

He added, “When I’m looking at storage solutions nowadays, I’m more trying to look at the adjacent capabilities that they offer because in the end, these are the capabilities that help organizations drive better value out of the solution, whether it’s technical specification, or ransomware protection and so on.”

Divergent ToneWhen marketing their products, companies fall into two camps. For one set of vendors, the value proposition is the storage-adjacent features that are built on top of storage. These extra features add value to the product. On the other hand are companies that are wholly focused on the core capabilities of storage itself, such as performance, scalability and availability.

“It dictates what you do as a customer, the choices that you make because when you manage to solve one or two problems, you want them to be solved in the best way possible. In other cases, you need to solve a ton of different problems and you want to solve them perhaps well enough or just well enough. The vendor which is selling those solutions that are able to cover everything across a larger scope is not doing it badly, but customers will have to do some tradeoffs,” reminded Mr. Mortillaro.

An Outstanding ProductThe solution that delegates were most impressed with was CyberSense by Index Engines. It’s a known fact that storage has many vulnerabilities. Part of the problem is that vendors do not always acknowledge how serious a problem cyberattack is.

Ray Lucchesi at the Storage Field Day eventIndex Engines is one of the few vendors to step forward and say the problem out loud, and design their solution around it. Their doing this may nudge some of the frontline companies to integrate detection and respond capabilities into their storage products for default protection.

“Storage vendors now have to really start embedding some of this intelligence and scanning capabilities, heuristics, like Index Engines, perhaps even licensing their technology for such an event as part of their offerings, like Dell is doing for their cyber resiliency services today,” Glenn Dekhayser, Storage and Security veteran, opined.

Big PictureA change is in order. Vendors must keep the innovation going to meet the emerging and evolving market demands. In Ray Lucchesi’s words, “There’s a transition going on today. Cloud is a major aspect of what’s forcing that transition, but the hardware technologies that are starting to come online are going to make significant changes to what storage does and how it looks.”

For more, be sure to listen to the conversation – Delegates React to Storage Field Day 25 – from the recent Storage Field Day event.


© Gestalt IT, LLC for Gestalt IT: Takeaways from the Recent Storage Field Day

View Details

We’re back once again with more great presentations at Networking Field Day 31! The enterprise networking industry is hot right now and more great presenters are ready to show off all the great things they’re working on and how it will impact your ability to provide connectivity for your users and customers.

Networking Field Day Presentation LineupThe event will be taking place April 12-13, 2023 in Silicon Valley. Wednesday kicks off with Kentik. They’re returning to Networking Field Day to talk all about data-driven observability and how it can solve application issues. They’re followed by Itential. They’ll be showing off their Itential Automation Platform for DevOps and NetOps teams and how it can integrate the entire development and deployment lifecycle for testing and validation.

Thursday starts with a new presenter, BackBox. They’re joining Networking Field Day for the first time to highlight the work they’re doing with automation to enhance network security and remediate issues in the enterprise. The final presenter for the event will be HashiCorp. They’re returning to give us an update on the platforms they’re integrating into modern workflows that help leverage DevOps ideas and make they work for networking teams.

Follow the Field Day Action LiveNetworking Field Day 31 will be taking place April 12-13. You can watch it live on our website at TechFieldDay.com as well as the Networking Field Day 31 event page. We will also be streaming the video live on our LinkedIn page. If you miss any of the exciting discussion you can always watch the replay on the Tech Field Day Youtube channel. If you want to discuss the event in real time through social media make sure you use the hashtag #NFD31. We’re excited to hear from the community!


© Gestalt IT, LLC for Gestalt IT: Networking Field Day Returns This April!

View Details

If you were to go back in time ten years, you’ll see an enterprise storage industry that looked vastly different than it does today. The big players in storage business still dominated the market, and the discrete purchase-and-deploy model was the only consumption model that mattered. Companies had their own private infrastructures cut out to meet their unique needs.

Big ChangesIn the last ten years, big changes have transpired. The evolution of storage to a large part owes to the emergence of cloud.

Cloud with its breakthrough pay-as-you-grow economics and world-class service levels has made the other kind of storage look antiquated. Since then, the traditional purchase model has come to feel outdated. The fancier, more economical everything-as-a-service model has taken over the hearts and minds of the buyers.

But as perfect as it sounds, the cloud has its disadvantages, and traditional storage is not to be superseded by it.

This was the premise delegates drilled into, at the recent Storage Field Day event when they gathered for the customary Delegates Roundtable conversation post-event. This time, the topic was the future of the storage industry. And like all discussions about the future, this too started in the past.

A New IdentityHost, Stephen Foskett kicked off the discourse by setting the context – “It’s an interesting time. Storage as an industry has changed. There are very few storage startups right now. Those that are there frankly don’t want to be known as storage. They want to be known as something else other than storage.”

For a while now, storage vendors have been distancing themselves from the one-dimensional identity of a storage company by adopting other areas of focus, such as data and analytics, security, etc. This change was spurred by a shrinking market share.

“We had a big tidal wave of companies that did cloud-first. Companies needed to get out of the datacenter business, and that was the big motivation. It wasn’t that they wanted to go to cloud, but their only option was public cloud,” reminded Glenn Dekhayser, Enterprise Storage Consultant.

Keeping SpeedAlthough companies moving away from the four walls of the datacenter has brought some challenges for legacy storage vendors, through them have come new opportunities.

When it comes to competing with big cloud players, companies follow one of the two strategies. One is to try to bring cloud-like simplicity, resilience, and fuss-free experiences to their products and services.

At the other end of the spectrum are companies that are carrying on the good work by furthering innovation, rolling out superior storage products that rival and upstage cloud storage.

Elastic StorageThe advent of elastic workloads changed data and the way it needs to be stored. Increased production of large-size media files turned companies towards the more affordable and capacious object storage.

With a mix of data and media files in their buckets, companies need storage to be elastic, one that can be sized up and down as and when required. Cloud provided a ready infrastructure for that.

To deliver better economics, public cloud vendors have busted the restrictive consumption model of the past, showing the world that storage can be consumed flexibly and on-demand.

There’s a chance for storage companies to maneuver in the same direction and bring that same consumption model into storage arrays, something Pure Storage pioneered with Evergreen. Pure Storage Evergreen frees customers from the obligation of doing expensive overhauls, and gives them full liberty to choose how they want to consume storage.

Better AlternativesA lot of legacy storage vendors have already seized the opportunity to devise workarounds which can help customers avert the limitations of public cloud storage like loss of control and lack of tailored features.

“I’m seeing a lot of shift with a number of storage vendors where they’re starting to adapt and work around some of the limitations of storage in the public cloud. Relational databases and these things can just destroy storage with IOPS demand, low latency requirements, and when you start hitting managed disks on any of the major cloud providers, a lot of times they just can’t keep up,” commented David Klee.

The latest high-performance storage products from traditional vendors are made to order for some of the most bleeding-edge, mission-critical workloads out there.

Cost-Per-TBAnother point to break into the market is cost-per-terabyte. Where economics is concerned, public cloud with its zero CAPEX and low OPEX design is winning by a wide margin. But cloud storage is not cheap, and if traditional storage vendors can undercut cloud providers, over time they can regain their market share.

Additionally, storage vendors have an advantage that cloud providers don’t. With traditional storage, customers know exactly where the data is.

With ransomware attacks sweeping through businesses, knowing the location of the data at all times has become a top priority for industries. It’s an important part of the recovery and restoration process, which having your own storage infrastructure makes it easy.

The SnagAlthough over the past few years, public cloud has provided big thrusts to innovation, it has also brought a lot of unpredictability.

“There’re services from which you need to choose, and it’s complex to navigate across that, because those vendors are addressing very broad use cases and very different personas within your organization. So, if you are the person who just needs to go and consume and swipe a card, it’s easy. But at some point in time, someone in the organization needs to be accountable for all of that, and understand who’s consuming what, what was the use case and so on, and it becomes almost impossible to untangle all of that,” said Max Mortillaro, Datacenter Consultant, and Analyst.

He pointed out that by contrast, on-prem infrastructures have a natural extensibility to the cloud which provides greater freedom and flexibility.

As for innovation, Mr. Mortillaro reminded that in public cloud, innovation is happening mostly in the periphery – in data protection, data management and such services. Very little innovation is actually happening at the core architecture layer.

The Winner Takes It AllSo who wins the battle between on-prem and cloud? As Rohan Puri, Graduate Research Assistant, pointed out, cloud and on-prem have co-existed through the last decade borrowing from and influencing each other, and in the end, improving storage for customers. But it remains to be seen what market share each holds going forward, with edge now a part of the picture. Cloud’s greatest strength is not storage, but lights out management. If traditional storage providers can catch up to that, on-prem storage will win its lost mojo back, and stand shoulder to shoulder with cloud.

Check out the full conversation – The Future of Enterprise Storage – Storage Field Day 25 Delegate Roundtable – recorded at the recent Storage Field Day event.


© Gestalt IT, LLC for Gestalt IT: Enterprise Storage Enters a New Age

View Details

From spammy email links to rogue software gone wild, a company faces many cyber threats. Although not all threats are high-profile, companies must keep their guard up against the most vicious to the lesser-known variants out there, because as far as data and privacy are concerned, any bug or bot can cause serious damage.

At the recent Storage Field Day event, we had a company among us whose mission is to bring organizations the agency to look out for all kinds of perils in the digital wilderness, and not get caught out. Index Engines presented CyberSense, an AI-powered security solution that serves as organizations’ “last line of defense”.

Fighting Data CorruptionExperts categorize data corruption into three levels. The basic kinds are corruption by appending certain file extensions to metadata, or making large changes to file size, both of which are pretty easy to spot. The advanced sneakier kinds corrupt file structures and use valid extensions for disguise. The third and the deepest level of corruption is where a malicious program hides inside the content, dwelling in the environment for months on end. This is the kind that is raging around the cyber scene.

Studies show that at the moment, the levels of corruption are the worst they have ever been. It is made worse by low reliability of tools. Ensuring data integrity in a fast-paced hyperconnected time takes inspecting every single datapoint – IP, passwords, files, databases, what have you – round the clock.

Few tools cover that many grounds. Most solutions scope out core files and data, and roll out a disproportionate number of alerts with high false positives which amount to a weak oversight at best. In the scramble, thousands of dollars are lost, and the level of corruption remains steady at an eye-watering level.

CyberSense Looks at EverythingIndex Engines seeks to change this harrowing reality with a solution based on full-content analytics. It’s strength – data observation and analytics. CyberSense detects advanced variants that hide their tracks with highest accuracy, and provides a high level of confidence.

Jim McGann, VP of Marketing and Business Development at Index Engines explained, “We layer on top of different applications. We’re not backup, we’re not storage. We’re just software that sits on these environments and adds a layer of intelligence.”

CyberSense is different from other security tools by its sheer depth and width of coverage. The only product to inspect files, core infrastructure as well as databases for signs of infection, it combs through all blind spots, and tracks down the most sophisticated threats.

The Who, What, Where and When of What HappenedCyberSense relies on deep inspection of data to detect threats hiding inside them. But instead of relying on thresholds to guess malicious changes over time, it studies every replication of data by comparing snapshots hourly to weekly to understand the changes. It constantly validates metadata properties to confirm reliability.

Deep analytics is performed through full-content analytics. Stealth threats are detected with over 200 content-based analytics that examine contents of the data and skim out hidden abnormalities.

CyberSense has advanced machine learning models built into it that provide 99.5% confidence in detecting corruption. The algorithms are trained in all common and many rare variants of trojan and ransomware, and can process analytics rapidly to discover any tampering or modification done to the core infrastructure, backups, databases or user files.

CyberSense has the unique ability to minimize false positives and negatives down to one in every 50, 000 backups. Administrators are alerted only on confirmed suspicious behaviors and threats.

Mr. McGann informed that CyberSense has enabled clients to recover in a heartbeat without any data loss. The CyberSense post-attack dashboard displays the last clean version of files. The post-attack forensics report provides insights on the details of the attack, and information on the files that enable quick and effective restoration.

Wrapping UpWhen living in a fast-changing, perilous digital landscape, the usual rules of staying safe do not apply. Organizations need to be very wary of the threats out there, and have their guards up 24/7. With a tool like CyberSense, they can be absolutely certain of the threats dwelling inside their environments, and eliminate them early in the chain. By sniffing out cloaked payloads from deep within the data, it gives teams a chance to trust their tools. High accuracy ensures that common alerts that can be dismissed without a thought do not become a distraction for the important jobs.

To catch a demo, and for deep-dives on CyberSense, check out Index Engines’ other presentations from the recent Storage Field Day event.


© Gestalt IT, LLC for Gestalt IT: Index Engines CyberSense – Detecting Data Corruption with Maximum Accuracy

View Details

In business-speak, investment translates to competitive advantage. If wielded right, it has the power to deliver value beyond material costs. And yet colossal IT spendings do not always yield positive outcomes. Because more than life-changing investments, organizations need the right stack of technologies, that besides making the investments pay off, become profit streams themselves.

At the recent Storage Field Day event in California, StorPool presented their core offering, StorPool Storage, a high-performance, scalable primary storage platform that sounds like a solution that provides high ROI.

During the presentation, Alexander Ivanov, Product Lead, highlighted the problems that enterprises typically encounter with storage systems, and explained how StorPool helps IT teams do storage right.

Defects of a Modern ModelA 2022 article published by Horizon Technology on datacenter hardware says, “The hyperscalers have long proven that commodity hardware is good enough to run industrial-grade workloads. The trick is in applying the right software layer to get the most out of the available hardware.”

When you zoom into the hardware bit, you get to see exactly where the problem begins. One of the key issues reported in the recent years by companies using traditional arrays is performance inconsistency. To avoid that, they have to keep buying more and more infrastructure leading to what is called an infrastructure sprawl.

This storage model has several flaws. It has a fixed overhead. Although the pay-per-use consumption model supposedly busts the flat-pay problem, it typically amounts to a fixed monthly pay. Vendors lure customers in with promises of deep discounts which is often offset with raised MSRPs, with cost of things like support services included in the pricing. This translates to very little profits for customers.

This is followed by a complex and expensive system lifecycle management that includes expensive licensing and time-consuming modernization of hardware.

If you are wondering why companies voluntarily go through this loop every few years, it’s because it’s the only way they know how to ensure measurable ROI. StorPool calls this the “storage game”.

For companies to guarantee fast application response times, they need a supporting high-performing block storage. If the block storage is not performing as it should, it starts a chain reaction impacting app response times and user productivity, increasing time-to-market which is directly linked to the revenue.

Reports have shown that slow app response times cause productivity to decline and costs to shoot up. The opposite happens when application response time soars. Users’ productivity goes up, applications are deployed faster, and revenue starts to grow.

During the Storage Field Day presentation, Mr. Ivanov listed down the key problems that contribute to performance degradation. They include inefficient capacity utilization, drive failures and rebuilds, sloppy software stacks, mismatching system interconnects, synchronous replication over long distances, and disruptive cleanup processes.

Workarounds, for example – application splitting and database sharding, using faster direct-attached storage (DAS) like SSDs and PMEM, faster interconnects and newer storage systems, typically have a snowball effect on the cost, which brings companies back to the original problem of the infrastructure sprawl.

StorPool StorageAbout 11 years ago, StorPool started on the mission to upend the storage game and make it right. The goal was to give customers a hyperscaler-like block storage on premises, the cost of which aligns with the value it provides. StorPool offers this with the pay-as-you-grow model but with their plan, the price varies as the usage varies.

StorPool does not attempt to entice customers with hollow deals that only blow up the cost. But, they make sure that users are served no unpleasant surprises during billing, and with them, the 24/7 support is truly included in the license, out-of-the-box.

StorPool tops this with an easy and non-disruptive lifecycle management which takes the pain out of the equation. Users can build their systems with datacenter-grade commodity hardware that are cheap and read-intensive. Performance and capacity can be scaled up and down by simply adding or removing drives and servers. As vendors roll out new generations, users can modernize and upgrade their arrays accordingly.

Mr. Ivanov highlighted two core strengths of StorPool Storage that have made the fuss-free lifecycle management possible – consistent performance under massive parallel I/O, and easy workload consolidation with minimum infrastructure.

Consistent performance is ensured with no single point-of-failure, uniformly low latency, linear scalability, and parallel services for thousands of workloads.

Referring to a client story, Mr. Ivanov showed that StorPool helps organizations maintain their service quality with five-nines availability, maintenance included. Low-friction lifecycle management ensures zero downtime or disruptions for when hardware and software changes are made. Commercial off-the-shelf (COTS) hardware supports all environments and enables cost optimization.

Wrapping UpThe cost and complexity of managing new technologies cyclically drain capital and ground operations. StorPool’s strategic maneuver from the usual approach contributes to lower total cost of ownership (TCO) for clients. For those struggling to get storage right on a limited budget, it offers a way to avoid big storage expenses with a balanced and easy system that enables new applications and services and does not ask too much in return.

For a technical deep-dive on StorPool Storage, be sure to check out StorPool’s presentations from the recent Storage Field Day event.


© Gestalt IT, LLC for Gestalt IT: Staying Ahead in the Storage Game with StorPool

View Details

It was merely a few years ago that AI/ML first hit the tech scene for mainstream use. In the beginning, select companies dabbled in it, and those that did had to devise and roll their own implementation using whatever resources were available to them. But as AI/ML enjoyed broader adoption, the market around it started to grow.

Gartner predicts that in 2023, AI/ML will be among the top workloads to drive infrastructure decisions. At the heart of this is rising storage needs which remains a major stumbling block preventing AI/ML from becoming prevalent.

At the recent Storage Field Day event, IBM gave a presentation that outlined the storage challenges that are slowing adoption of AI. Dough McGuire, Global Director of Sales in Storage for AI, Big Data, introduced Storage Scale, IBM’s fastest growing segment in the data and AI storage portfolio, and explained with customer success stories, how it makes handling of massive unstructured data cost-effective and simple, and sets companies up for AI success.

Barriers to AI AdoptionThe state of data in 2023 is vastly different than it was before. In the past ten years, the amount of data created, captured, copied and consumed globally has tripled and quadrupled. This has both a good, and a bad side. On one hand, the compound annual growth rate (CAGR) at which data is growing has presented an opportunity for enterprises to tap into the wealth of information that is locked in it. But, hot on the heel of that has arrived the predicament of storing and processing all of that data.

80 to 90% of the data created and collected is unstructured, and companies employ point solutions to handle it. This has only deepened the divide in the infrastructure, creating innumerable islands of data and technologies. Access and management of these silos with the overflowing amount of data that is coming in, is the biggest struggle for 95% of the companies.

As AI/ML entered the scene, enterprises were given an elegant way to churn value out of their data. But the effort of deploying AI/ML workloads on enterprise infrastructures is met with the shortcomings of traditional storage systems that are not cut to handle their sky-high performance and scaling needs.

A Global Data FabricAn organization’s ability to draw maximum value out of its data and conquer the ascent of AI/ML rests on squarely meeting the data challenges. To avoid falling behind in the AI race, companies must use an architecture that first and foremost acts as a superhighway for large-scale workloads, but concurrently offers great support for general-purpose workloads which most enterprises have. This is everything that Storage Scale brings to offer.

IBM’s Storage Scale System is a software-defined object and file data storage system that is built to readily support the performance and scaling needs of AI/ML workloads. But Storage Scale is more than just a high-performance enterprise storage. It deploys a global data fabric for AI that fosters geo-distributed collaboration through elimination of data silos and management pains, and most importantly, enables easy access of data with a common data plane that spans the enterprise.

Serving High-Profile Use Cases with IBM Global Data PlatformMr. McGuire referred to an array of client success stories while explaining the key benefits of the Storage Scale offering. He informed that IBM’s Global Data Platform attracts large numbers of research companies and banking organizations that have a high bar for regulatory compliance and cyber resiliency.

The Global Data Platform serves those clients by enabling them to set up two production sites that can share data between themselves. With caching services running in between, the platform maintains a single source of truth for data, decimating silos and saving companies top dollars by not having to move petabytes of data to public cloud where storage is typically cost-prohibitive.

Through transparent sharing of data and workloads across public and private clouds and the edge, the Global Data Platform significantly shrinks cloud storage footprints. Caching services between sites ensure that there are no stale data copies.

For businesses wrestling with data in scattered addresses, the Global Data Platform offers a way for applications to reach and use them no matter where the storage is located, or what interface is being used. The platform allows speedy and consistent access of a single copy of data from any storage system, reducing the need to make and keep multiple copies in different locations.

The Global Data Plane provides a high availability environment where organizations can create high-performance tiers for AI/ML use cases and run concurrent workloads.

At the heart of the platform is cyber resilience that organizations, especially regulatory industries ask. With a breadth of security and ransomware capabilities based on the NIST framework built into it, the platform identifies, protects, detects, responds and recovers, giving data active protection from all kinds of threats.

Wrapping UpIBM’s Global Data Platform offers two key things – performance and access – that are paramount to adopting AI/ML and harnessing the value of data. It provides an agile, secure and available environment where data can move freely without the constraints of silos. The common data plane ensures swift and uninterrupted access to the same data from various interfaces and locations. Its high performance is vital to optimizing workloads, and making possible a wider adoption and maturity of AI.

For more information on IBM’s Storage Scale offering, check out IBM’s deep-dive presentations and demos on the solution from the recent Storage Field Day event.


© Gestalt IT, LLC for Gestalt IT: Consolidating Distributed Data with IBM’s Global Data Platform for AI

View Details

Imagine that a syndicate of cybercriminals breaks into an enterprise network and gains access to restricted business data. They go straight to manipulating the data, and in a moment, unsuspecting users around the world are using doctored information.

For such cases, snapshots are an ultimate game-changer. A copy of the point-in-time (PIT) data, snapshots prevent previously existing data to be modified or tampered with.

But don’t relax too soon. Snapshots have their limitations as well. For example, they do nothing to protect against data loss caused by a security infiltration, a disaster, or a simple hardware failure. When the storage fails, the snapshots disappear too.

Reimagining SnapshotsAmazon Web Services took this disadvantage and turned it around with the Amazon Elastic Block Store (EBS) Snapshots. During their presentation at the recent Storage Field Day event, AWS presented Amazon EBS Snapshots, a data protection service that makes it possible to revert data loss.

Presenter, Kirill Davydychev, Solutions Architect, explained how EBS snapshots are different from snapshots in traditional storage environments.

“When you take a snapshot in EBS, all of the data in the background is copied to Amazon S3.”

AWS uses service-owned S3 buckets that customers do not have direct access to.

Users can take multi-volume snapshots that are synchronized and crash-consistent. This can be done with one instantaneous API call. Once created, snapshots are then copied to the S3 bucket.

The time to copy depends on the size of the batch. Once the process is complete, snapshots can be restored to another EBS volume.

Snapshot TypesAWS offers two tiers of EBS snapshots – Standard Snapshots and Snapshots Archive, for short and long-term retention. Standard Snapshots are stored incrementally which ensures that customers pay only for the changed blocks.

“You repeat as you take multiple snapshots of your particular volume. Only the changes are synchronized to S3, and they are stored there using what we call chunks. So those chunks can have a different block size to your actual volume block size,” said Mr. Davydychev.

Standard Snapshots are typically used for backup and recovery, application refresh, disaster recovery and ransomware protection use cases. They have a restore time of a few seconds.

The second variety, EBS Snapshots Archive, is best fitted for compliance use cases where customers need to store data for long terms for regulatory reasons. 75% more affordable, it does not offer real-time access to the data. It takes anywhere between 24 to 72 hours to restore the largest set of snapshots.

“When we archive a snapshot, we have to essentially fully hydrated it and store it as a single object in a lower S3 tier.”

Lifecycle ManagementEBS Snapshots integrate with Amazon Data Lifecycle Manager (DLM). It is an UI-based scheduler that enables lifecycle management with features like policy-based snapshot creation on hourly to yearly basis, flexible retention, copying and sharing and more.

Users can set up automatic backup scheduling and retention management for a chosen set of volumes. Policy-based deletion on the lifecycle manager allows expired snapshots to be removed automatically.

Deleted snapshots are sent to a Recycle Bin where they are retained for a set period of time before being permanently removed. Quick recovery allows all accidentally deleted files to be restored back to production with a single click or an API call before expiration.

Wrapping UpSnapshots are an excellent way to meet recovery-point objectives that are measured in minutes or hours. Amazon EBS Snapshots eliminate the risks of single point-of-failure. By copying snapshots to a secure and restricted S3 bucket, it offers a convenient way to backup EBS volumes, and enable disaster recovery at a lower cost.

To know more about Amazon EBS Snapshots, check out AWS’ presentations from the recent Storage Field Day event.


© Gestalt IT, LLC for Gestalt IT: Enabling Disaster Recovery with Amazon EBS Snapshots

View Details

I started creating server build automation during a change freeze, immediately after New Year’s 2000, the Y2K bug apocalypse date that didn’t quite eventuate. Ever since that start, I have much preferred automated build processes to relying on people following a list of manual steps. One of the reasons for that is the principles of IT infrastructure automation fit nicely with the DevOps culture that enables faster application development.

I create build automation designed to have a human watching over, mainly watching for errors. Building automated error handling and verification is complicated and time-consuming. Watching that build process is acceptable when building a small lab. It was also great when three or four engineers built a couple of dozen servers for doctors’ surgeries.

The problem is that human operations are costly to scale, particularly to many locations spread over a wide geographic area. This is what is defined as the far-edge location. These locations might be retail stores, or delivery trucks, often places where business staff do their day-to-day work, interacting with the customers and directly generating revenue.

Increasingly, technology is either making the staff at these sites more productive, or adding ways to generate more revenue from the customers that visit these sites. But this technology has a cost, and business owners need to control those costs to turn that revenue into profit.

Control Far-Edge CostsOne of the important ways to control IT costs for the far edge is to ensure that one never needs to send a skilled IT engineer to sites. Everything that goes to the sites should be able to be installed and connected by the onsite staff, whether they are the driver of the truck or a checkout supervisor at the store.

Once the hardware is physically installed, every other part of deployment and management must happen from a central console where the IT team can manage groups of sites and remotely resolve faults. Ideally, the platform used should automatically fix as many faults as possible, which brings us neatly to Scale Computing and its background in self-healing computing infrastructure.

Zero-Touch ProvisioningScale Computing has always designed SC//HyperCore HCI to look after itself as much as possible. SC//Platform extends to edge deployment and is the basis for Zero-Touch Provisioning (ZTP) of SC//HyperCore clusters at a grand scale.

ZTP was the centrepiece of Scale Computing’s recent presentation at the Edge Field Day event in San Francisco. In the live-streamed presentation, four clusters were deployed from a central console to five Intel NUCs. The “onsite” deployment was connecting power and ethernet to the appliances. Everything after that was achieved using the SC//Fleet Manager console, which had been pre-populated with the hardware IDs of the physical nodes.

In actual deployment, these hardware IDs are harvested from the fulfillment system that delivers the appliances to the site. SC//Fleet Manager is easily pre-populated with the IDs before the devices are delivered to the site. Once the appliance is powered up, it phones home to SC//Fleet Manager over the Internet and appears in the customer’s view of the console.

Application PlatformsSC//Fleet Manager handled a lot of configuration and initial setup for users, deploying the latest version of SC//HyperCore to the nodes, and deploying a set of standard initial VMs. The initial VMs might be the standard edge site servers with locally installed applications, or home to cloud-managed applications using platforms such as Google Anthos or Azure ARC-enabled applications.

SC//Fleet Manager can drive updates of SC//HyperCore to the clusters, and Scale Computing has an Ansible collection for managing multiple clusters over time. The Ansible collection is Red Hat certified and available on Galaxy for easy installation.

Scale Computing Removes ProblemsScale Computing’s approach of removing the burden of routine tasks and fault remediation from customers is widely liked. ZTP is an excellent part of continuing the story where Scale Computing can deliver large numbers of cost-effective clusters, or single nodes, to deployment at the far edge.

The Intel NUCs, using specific models that incorporate feedback from Scale Computing, make a great compute node to deploy in far-edge locations. Scale Computing also has its data centre-specific models for less constrained environments.

Scale Computing showed its commitment to partners by having Avassa and Mako Networks present at the Edge Field Day event in their offices.

Be sure to watch the Scale Computing presentations from the recent Edge Field Day event, and keep up with what the other delegates think at TechFieldDay.com.


© Gestalt IT, LLC for Gestalt IT: Scale Computing Removes Problems at the Edge

View Details

Over the past several months, the industry has observed the growing exuberance surrounding a new disruptive technology called CXL. Known for introducing pliability and composability to server architecture not witnessed before, it’s been stoking the public’s imagination with the potential for AI/ML.

This Tech Field Day event in March, we had had the honor of having Siamak Tavallaei from CXL Consortium join us for an exclusive presentation on the technology. CXL Advisor to the Board of Directors, Mr. Tavallaei gave an immersive talk on CXL that follows its journey from birth to the most recent specification, CXL 3.0.

The CXL ConsortiumMr. Tavallaei started the talk by introducing the audience to CXL Consortium, the body behind the technology. CXL Consortium was formed in 2019 by some of the industry’s heavyweights who are now its board members.

The 15 companies that brought the consortium to life and now runs it are Alibaba Group, AMD, Arm, Cisco, Dell, Google, HPE, Huawei, IBM, Intel, Meta, Microsoft, NVIDIA, Rambus and Samsung. Currently, the Consortium is 240 members strong, and has 9 promotor companies and several contributor companies associated with it.

Mr. Tavallaei announced that Larry Carr, VP of Engineering at Rambus, has been elected the new President of the CXL Consortium.

The consortium operates through workgroups that include the technical and marketing wings, and the board of directors. When a certain use case is identified, members and contributors present their proposals that are considered and compared, and based on that, a solution is developed.

The Genesis StoryMr. Tavallaei shared the story of the origination of CXL Consortium with the audience. In the past, proprietary interconnects were used to expand resources within servers, but their limited compatibility got in the way of a wider adoption. From that, the idea of a universal interconnect was born.

Several big companies came together to build a set of vendor-agnostic specifications that can be universally used. From that initiative, CXL was born. In the March of 2019, CXL 1.0 was rolled out. As it garnered attention, other manufacturers joined the project, and continued the effort. A year later in 2020, CXL 2.0 was announced. At the 2022 Flash Memory Summit, the most recent CXL 3.0 was released.

New UpdatesAt the event, the other announcement was that OpenCAPI Consortium, a near-memory CPU interconnect group that designed an open interface architecture that connects any microprocessor to accelerators and I/O devices, signed the agreement to merge with CXL.

Early in 2022, another group, the Gen-Z Consortium that designed open-systems interconnect closed merger with CXL Consortium transferring their assets and specs with CXL.

The CXL ApproachMr. Tavallaei laid out the CXL approach which began with a simple, but compelling object – do no harm to any existing technology. The founders meant for CXL to power modern interconnects, not take away from them. So, they built it on top of the PCIe infrastructure.

CXL leverages three dynamically multiplexed protocols. One of the protocols, CXL.io, Mr. Tavallaei informed, is the same as what PCIe does.

“It is participating in bus on a device enumeration, configuration, DMA moving memory similar to what DMA engines do as part of PCIe,” he said.

CXL additionally brings two high-speed, low latency protocols, namely CXL.memory and CXL.cache. Each of the protocols addresses a certain use case. While CXL.mem and CXL.cache aims to move data fast (under 200 nanoseconds), CXL.io. moves bigger blocks of memory at a slower rate. Mixing and matching these protocols allows for a wide range of use cases.

CXL 3.0CXL 3.0 builds on the capabilities of CXL 2.0, with emphasis on scaling and resource utilization. Expanding the logical capabilities of CXL, it enables flexible memory sharing between CXL devices, and introduces new access modes.

Mr. Tavallaei highlighted the data rate in CXL 3.0. At 64 gigatransfers per second, it is double the rate of CXL 2.0.

The latest version has enhanced switching capabilities, including peer-to-peer direct memory access which allows devices to directly access each other’s memory and be informed of their states without going through a host.

It introduces support for multi-level switching. While CXL 2.0 allowed only a single switch, 3.0 allows several layers of switches to reside between a host and its devices, thus extending support for more complex network topologies.

Combined, the new memory and fabric capabilities are what is called the Global Fabric Attached Memory or GFAM. GFAM further disaggregates memory from the host such that a GFAM device is its own memory pool that both devices and hosts can access as required. It can have both volatile and non-volatile memory, such as DRAM and flash together for example.

CXL 3.0 has full backward compatibility with the earlier CXL 1.0+ and 2.0. Hosts and devices can be flexibly downgraded to what the rest of the hardware chain has. However, downgrading will cause loss of new features and speeds.

For more information on CXL and CXL 3.0, be sure to watch the full presentation from the Tech Field Day event. For a prescient discourse on CXL, check out the Delegate Roundtable – Considering the Impact of CXL, also recorded at the event.

Watch our episode of Utilizing CXL from season four of Utilizing Tech with Siamak Tavallaei on the Utilizing Tech website or on YouTube or listen on podcast services.


© Gestalt IT, LLC for Gestalt IT: A Game-Changing Approach, New Mergers and a Disruptive Technology with Siamak Tavallaei from the CXL Consortium

View Details

As organizations embrace edge computing, they seek the ability to deploy technology to deliver new capabilities to business operations, and open new avenues for revenue generation. So far, the focus has been on the delivery of infrastructure for static workload management. But a long-time goal of edge adoption has been to dynamically control workloads from afar, making application updates, deploying new services, and keeping edge points secure both feasible and cost and time-efficient.

Stepping UpScale Computing, a long-time leader in HCI infrastructure for a variety of edge environments, has had great success in deploying edge solutions.

Amassing thousands of customers during their fifteen-year history, their reputation for delivering solutions that work out-of-the-box has earned them over 100 points on CRN’s vendor product quality score, a historic high for the publication.

As the edge has matured and customer requirements have become more advanced, Scale Computing has upped its game with software development to ensure a full lifecycle of remote oversight of infrastructures. It’s in this work that the company rests its opportunity for continued market advancement as the momentum of edge proliferation grows.

Full Lifecycle ManagementThe foundation for this full life cycle management is Scale Computing’s Autonomous Infrastructure Management Engine (AIME), custom-built software that sets Scale Computing deployments apart.

AIME is built deeply into the hardware telemetry to oversee everything from BIOS and firmware health to hardware states, environmental measurements, network state and more. With always-on oversight, Scale Computing is aware of infrastructure issues well before its clients, and can timely trigger remediation.

When you consider the diverse landscape of edge environments and the relative skillset of edge-based employees, this capability is a gift to organizations, to deploy with confidence, and mitigate risks of truck rolls for hardware troubleshooting. AIME’s sophistication also ensures that data is properly mirrored, and any impact of loss is minimized.

Scale Computing has built on hardware control achieved in AIME with the newly released zero-touch provisioning (ZTP) in SC//Fleet Manager. ZTP allows Scale Computing to pre-load software on edge devices so that setup at the edge is simplified to plugging equipment to the location. This is when SC//Fleet Manager takes over and enables remote initialization of each cluster, deployment of initial configuration, and application of the cluster name.

The combination of SC//Fleet Manager and AIME also de-risks initialization errors such as a device plugged into a wrong location with seamless re-boot and re-provisioning of the cluster. For organizations wishing to deploy fleets of edge devices in environments with limited or no local technical support, the cost savings that ZTP offers expand the opportunity for edge device deployment.

With ZTP and AIME, Scale Computing has achieved initial deployment and cluster oversight of its edge solutions. But customers want more. They want the opportunity to update software across their edge fleet as efficiently as possible, and for this capability, Scale Computing has developed their SC//HyperCore Ansible Collection.

These Red Hat certified open source-based playbooks are provided to enable IT administrators to provision clusters, deploy applications, and update security and compliance with central, automated control.

This technology’s elegant approach extends the value of edge infrastructure by enabling organizations to deploy new services on existing hardware, and extending the value of edge deployments for business evolution. It’s also reflective of the broader direction of edge computing delivering more sophistication of workload opportunities to monetize data at the edge.

ConclusionOrganizations that seek an edge infrastructure provider with seasoned experience deploying fleets of equipment across edge environments should seriously consider Scale Computing’s offerings. Its software portfolio reflects a deep understanding of the unique capabilities IT organizations require for remote site deployment. Its engineering investment in hardware telemetry and software oversight ensures that central IT operations can effectively oversee remote deployments. Lastly, its investment in SC//HyperCore Ansible playbooks makes sure that organizations are not limited to appliance like edge devices. Scale Computing also lives up to its name in being able to support a broad scale of devices and types of configurations to suit a wide array of workload and environmental requirements.

To learn more about the company’s offerings, visit Scalecomputing.com and request a free demo, or check out the presentations from the recent Edge Field Day event at TechFieldDay.com.


© Gestalt IT, LLC for Gestalt IT: Achieving Dynamic Provisioning and Control at the Edge with Scale Computing

View Details

Compute Express Link, popularly known as CXL, is poised to change the way we do computing. The CXL interconnect is leading datacenters away from the classic server computing architecture, with one that supports pooling, expansion and sharing of memory, laying the groundwork for some of the world’s most cutting-edge workloads with true composability.

At the recent Tech Field Day event, MemVerge brought CXL to the audience. MemVerge is one of the frontline companies paving the way for implementation of CXL. During the event, Sr. Software Architect and Product Manager, Steve Scargall showcased two core CXL products – MemVerge MemoryViewer and Memory Machine, that MemVerge has brought to the market to enable software adoption of CXL.

An Unexpected ProblemOne of the great things about CXL is that applications do not require code changes to consume CXL memory. It behaves like standard memory, and can be used as is. Users can provision CXL two ways, user-managed where the user allocates memory independent of the DRAM, and Kernel-managed, where the Linux kernel manages the allocation.

Although neither has any bearing on the application, the heterogenous nature of the memory environment can affect its performance. In such an environment, NUMA nodes mapped to the applications can have widely different latency or bandwidth characteristics, based on the type of memory they are using, or the physical distance between hardware. The varying memory characteristics of the nodes can pose a problem for unmodified applications and VMs that are not equipped to handle this diversity.

MemoryViewerMemVerge’s innovation is around enabling applications to choose the best NUMA nodes based on the workloads. At the Tech Field Day event, Mr. Scargall showcased two solutions to demonstrate this.

The first is the MemVerge MemoryViewer, a Linux-based free software solution that provides comprehensive visibility of the physical memory resources, and their utilization.

“The intent of MemoryViewer is to show you as a user, what your applications are doing,” said Mr Scargall. “The key question for heterogeneous environments is how much of the memory is actually hot, and how much of that is cold, i.e., could we under memory pressure situations, move that to a lower tier without the application having to do that for you?”

MemoryViewer features System Topology that shows memory configurations in real-time, allowing system admins to check their correctness. Application Memory Heatmap displays memory behavior, usage patterns and insights, with the help of which administrators can tailor and optimize the configurations to better support the applications.

Memory MachineThe Memory Machine is a solution designed to address the growing need for in-memory computing. MemVerge calls it the “Big Memory Software”. At the core, the Memory Machine virtualizes DRAM and persistent memory, making them compatible to access for all existing applications. To the applications, it appears as DRAM, and can be consumed without any modifications.

The solution intelligently tiers hot data to the DRAM fast tier, and puts warm data in the persistent tier. This allows for better performance, and maximum utilization of both the memories.

“With thin provisioning of memory, you can overcommit and once you hit the threshold, we’ll just give you the memory that you really need. That’s a cost-efficiency saving for the infrastructure guys, or potentially for the cloud guys as well if they want to offer that,” said Mr. Scargall.

Memory Machine also supports blazing fast crash recovery. With ZeroIO memory snapshot technology, it provides the ability to clone terabytes of data from PMEM in just seconds, and requires no IO to storage.

Wrapping UpCXL is the key to attaining 100% composability in datacenters, and for that, MemVerge’s solutions are both well-timed, and vitally important. They offer a way for applications to access CXL memory unmodified. Intelligent memory management open ways to achieve rightsizing of compute and memory for workloads, while enjoying cost-benefits. With MemoryViewer and Memory Machine, MemVerge hands enterprises the means to explore their AI/ML ambitions.

To check out the demos, be sure to watch the MemVerge presentations from the recent Tech Field Day event.


© Gestalt IT, LLC for Gestalt IT: Implementing CXL with MemVerge

View Details

Nurturing an ever-expanding network in a way that it is up and up 99.999% of the time is a harder problem than it appears. Network teams working behind it know the harsher reality because they have to get around the pitfalls that lay in the way of the 5 nines uptime every day at work.

At the recent Tech Field Day event, Kentik presented Synthetic Testing, a capability they included not long ago to the Kentik Network Observability Platform. Kentik Synthetics helps network teams stay ahead of problems by simulating network behavior, and proactively evaluating variables and the health of the network.

An Incomplete PictureThe language around network monitoring has evolved at a faster pace than the technology itself. In the last couple years, vendors have swapped out the older and outdated “monitoring” with the more scientific sounding “observability”. And although “observability” has become the stamp of distinction for vendors, under the hood, the technology has remained the same, give or take.

Teams still base their decisions on flow records when that data, in and of itself, is not valuable without context. Looking at one piece of data and drawing conclusion out of it is not the savviest way to infer the health of a network as complex as those today. Without context, one can very easily make wrong, or even ridiculous deductions.

A Richer DataContextual data, on the other hand, is the cornerstone for making confident decisions. But there’s an even better way to bolster observability. With proactive monitoring, engineers can weigh the digital experience of the users before it is delivered.

Monitoring tools that do not function proactively doesn’t help avert outages, nor help improve the Quality of Experience (QoE). It’s an important lesson, CTOs have learned through frequent network disruptions, and that’s why there’s a keen and growing interest in proactive network monitoring.

Achieving Observability of Digital ExperiencesKentik does not need a lengthy introduction in the context of network monitoring. It’s high rating and heaps of reviews on popular platforms like Gartner for example, confirm its golden reputation.

For Kentik, observability is to be able to answer any question that network engineers might ask. So when it saw a growing void in the performance monitoring capabilities coming from certain hardware vendors, it embraced synthetic testing to stop that gap.

Mike Krygeris, Enterprise Solutions Architect, informed that proactive monitoring is not a common feature-set in network hardware. “A lot of routers and switches don’t want to take on that sort of workload in order to get performance data,” he explained.

The Kentik Network Observability Platform ingests data from data sources, adds context to it by enriching it with metadata from the network, and presents it to the teams. Delivered as SaaS (Software-as-a-Service), the platform is vendor-agnostic, and can gather data from any source in the network.

The other function that Mr. Krygeris drew attention to is low-latency query. Kentik Network Observability Platform allows users to query data at a fast speed, so that information is always at the fingertips. It also provides automated insights for easy troubleshooting.

Kentik SyntheticsMr. Krygeris walked the audience through the capabilities of Kentik Synthetics. Kentik deploys agents all over the network, be it cloud, or on-prem, that watch the network from different vantage points in the environment. Users can schedule synthetic tests from the Kentik UI. Tests can be scheduled at a frequency of a few seconds to every minute or longer.

Kentik Synthetics Test Control Center provides several options for users. They include but not limited to Network Meshes and Grids for monitoring with agent-to-agent meshes, Network and Routing Tests for monitoring with one or a set of agents, and Web Tests for measuring the response time of Web servers.

Kentik covers a lot of grounds when it comes to performance monitoring. Mr. Krygeris named some of the testing that Kentik does, such as ping, traceroute and jitter tests, TCP and UDP, DNS testing, app testing and Internet health and BGP monitoring.

Kentik Autonomous Tests analyze flow records and correlated traffic data, triaging problems on auto-pilot. Through these tests, teams can keep up-to-speed with the network performance, and application response times, while closely watching the supporting infrastructures, with just a few clicks. High traffic and path awareness ensures swift Root Cause Analysis (RCA) and shorter Mean Time to Repair (MTTR).

Wrapping UpOrganizations are fast embracing new cloud environments and that is making the network topology a little more complex every day. Companies that continue to latch on to older techniques of monitoring, waiting for problems to surface are already too late. The modern networks require tools that can proactively probe into the components and interact with them just as a real user would, and spot the problems before they do, leaving no mystery for the teams. The Kentik Network Observability Platform with Kentik Synthetics is one such solution that measures digital experience from the point of view of the users, and provide teams the 360-degree visibility they require to achieve the 5 nines uptime.

To check out the demo, be sure to watch the above presentation till the end, or view other deep-dive presentations by Kentik from the recent Tech Field Day event.


© Gestalt IT, LLC for Gestalt IT: Synthetic Network Monitoring with Kentik

View Details

Data from studies show that technical debt can stymie digital transformation. With a majority of organizations extending their digital footprints, especially transforming to multi-cloud and edge, this is just bad news.

At their first-time appearance in the recent Tech Field Day event, Men&Mice presented a solution that may help organizations pare down technical debt. Lauren Malhoit, Head of Growth and Product Marketing showcased Micetro, an award-winning DDI (DNS, DHCP and IPAM) management and orchestration solution that seeks to turn the complex task of multi-cloud DDI network management into a simple, stress-free and streamlined experience.

A Twofold ProblemTwo problems have been identified at the root of technical debt. Organizations are increasingly consuming services from networks outside their own. This is true for any business that has a network. On one hand, it has expanded their footprints to remote clouds, and on the other, it has increased their burden of digital asset management, especially for services like DNS, DHCP and IP Address Management (IPAM), collectively called DDI. Both have a snowballing effect on technical debt.

The second problem is the rip and replace approach to IT modernization. As their current technology stacks age, organizations embark on the process of ripping out older tools and embracing the newer ones. Repeated over and over, the process has made sure that organizations stay on the cutting edge of technology. But on a flip side, the accumulating costs have led to spiraling technical debts that inevitably slow down their digital progress.

The personas most impacted by this are the IT teams. To their frustration, they need to upskill, retool and reculture cyclically, every few years to keep up with the change, all on a tight budget.

Ms. Malhoit noted, “We get stuck in this rip and replace mentality, and the analysis paralysis of moving forward. Our IT teams have no time to get trained on new services. They’re constantly at a loss, working from behind.”

Men&MiceMen&Mice makes migration to new clouds sustainable. By making IPAM and DNS administration simpler, it cuts down the need to have more skillset to manage newer technologies. Founded in Reykjavík, Iceland, Men&Mice has a customer-first mindset which reflects in its simple company vision – to make the complex management of DNS, DHCP and IPAM simple and easy.

To that end, they make use of a popular IT principle – abstraction. Micetro is a software-defined overlay that enables unified DDI management and orchestration of a wide variety of networks, of sizes ranging from those of Fortune 500 companies to small and medium businesses (SMBs).

Men&Mice are experts in network management. Ms. Malhoit said, “With our overlay design, our product teams, developers and support people really have to understand the underlying services that you might connect with in order to run the best DIY environment for your use cases. So that requires a lot of knowledge, and expertise to help our customers set things up for best practices, and to really make things run in a performant way.”

MicetroMs. Malhoit highlighted two things that set Micetro apart from other solutions. “Men&Mice is not the first to figure out abstraction, or to talk about overlay architectures, but we are bringing it to the DDI environment,” said Ms. Malhoit.

“Micetro is a non-authoritative and non-disruptive DDI (DNS, DHCP and IPAM) solution,” she said.

As a product, Micetro does not interfere with neither the services, nor the network structure. Users can unplug Micerto if they want to, without disrupting either. Despite this flexibility, Mice&Men enjoys 95% client retention.

Ms. Malhoit gave a sneak-peek of the overlay architecture in the presentation. The solution includes Micetro Central which is a unified UI that provides a single source of truth (SoT). Configurable for high availability, it is what Men&Mice calls the “brains of the operation.”

“It gives you one UI or one API, depending on what you’re trying to do, to create and maintain processes and workflows. This is no matter where your workloads reside, whether they’re in the cloud, or on premises, or you’re using some sort of managed DNS service, it’s one place to go.”

Users have the same workflows everywhere, whether its AWS, Azure or on-prem, as workflows go through Micetro “making the underlying services quite fungible.”

As soon as Micerto connects to the services, the DDI environment pops up in the UI providing visibility across teams. It eliminates the need to have specialized skill to navigate and manage multiple services.

Micetro has a backend database where data from connected services are accumulated and organized.

Built for modern architectures, Micerto provides users a break from the infamous lock-in that proprietary systems often put users in. “We don’t rely on resource-hungry appliances to achieve scale, or the ability to be in the cloud, on-premises, or multi-site. We will give you appliances if you want to use them, but we do not require them in any way. This helps our customers avoid the financial burden of unnecessary resource and administrative costs, that come with the more closed systems that we see a lot in our space,” said Ms. Malhoit.

Wrapping UpTechnical debt may sometimes be hard to pin down or measure, but it is a reality for all organizations. More than game-changing investments, and a rip-and-replace drill every few years, teams need the right set of tools that not only make investments pay off, but become a barrier to escalating costs by outlasting other solutions. Micerto is one such product that not only has the power to bring down tech-debt costs, but also eliminate the constraints imposed by legacy solutions organizations have so long relied upon.

To catch a live demo of Micerto, be sure to check the other presentations by Men&Mice from the recent Tech Field Day event.


© Gestalt IT, LLC for Gestalt IT: Unified DDI Management and Orchestration with Men&Mice

View Details

Our next Storage Field Day event is here, coming to you live on LinkedIn and the Tech Field Day website March 22 and 23, 2023 or watch the recordings shortly after each presentation. Here’s a quick overview of what to look forward to.

Enterprise Storage continues to advance even as cloud computing, ransomware, security, and data management have shifted the focus of the industry. We’re going to spend a few days looking at storage with some of the top thought leaders from leading companies in the industry. The event is broadcast live on TechFieldDay.com starting at 9 AM Pacific Time on Wednesday and 8 AM Pacific on Thursday with presentations throughout the day.

Storage Field Day begins with a Delegate Roundtable live at 9 AM. The discussion will be centered around the many ways storage has changed and the emerging trends being seen in the industry today. Index Engines will present CyberSense at 10:30 AM. CyberSense scans backup data in snapshots to validate the integrity and identify malicious changes indicative of a cyber attack. When an attack occurs, CyberSense provides forensic reporting to diagnose and recover to resume normal business operations. IBM Storage is the next presenter at 1:30 PM. They’ll give us an overview of the new IBM Storage landscape as well as deep dives into IBM Storage Scale and IMB Storage Fusion. We will wrap up Wednesday with a presentation from Amazon Web Services at 4 PM. We’ll dive into AWS Block Storage, backup, and data protection services which have emerged as a leading platform for enterprise data in the cloud.

Thursday morning kicks off with StorPool at 8 AM. StoragePool will be presenting their parallel multi-node shared nothing primary data storage architecture built for highly automated environments dynamically provisioned with self service UI’s where thousands of users can simultaneously manage their workloads. The event will wrap up with a retrospective Roundtable Discussion giving delegates time to consider what they’ve heard and predict the impact of these new technologies.

All of our sessions are broadcast live on LinkedIn and the Tech Field Day website. They are also recorded and posted to the Tech Field Day YouTube channel shortly after the event. We welcome participation on Twitter and Mastodon using #SFD25. Thank you for joining us for Storage Field Day March 22-23 on our social media channels.


© Gestalt IT, LLC for Gestalt IT: What’s New in Storage at Storage Field Day 25

View Details

The key to business success in this decade is in the ability to organically absorb new technologies and render positive user experiences. This was the message that rang through all the presentations at the recent Edge Field Day event.

In February, at our first-ever Edge Field Day event in California, we invited companies and delegates to gather under one roof and talk edge computing. The attending companies – Scale Computing, ZEDEDA, Opengear, Avassa, Mako Networks – presented a plethora of solutions targeted at the edge market.

Before the final wrap up, delegates, Ben Young, Alastair Cooke, Brian Chambers, Carl Fugate, and Josh Warcop joined Stephen Foskett in a roundtable discussion for a quick recap. Reflecting on the dominant themes and technologies from the presentations, they shared their impressions on edge computing, and spitballed new ideas for the future iterations of Edge Field Day.

Zero TouchHost, Mr. Foskett, hit the ground running with the question of what in their opinion the overarching themes of the event were. Security was top of the mind, Mr. Young recalled. And like any discussion concerning the edge, this too started with Zero Touch Provisioning.

Zero Touch Provisioning is the way to set up thousands of devices within minutes, securely and automatically. Mr. Chambers elucidated, “The reason behind it is probably just a recognition that if you’re going to deal with the edge, you’re going to deal with so many copies, and footprints of whatever you have, whether it’s network or compute.”

More importantly, the edge involves people, and that makes rooms for security issues, whether it’s through human error, negligence, or malicious intent.

Too often, companies tend to fall back on manual methods as their default approach instead of adopting new processes. At the edge, this approach poses several problems, and barrier to enforcing security is one of them.

Mr. Chambers noted, “We had a theme that being able to automate and have a really good control plane for the entire network of devices is just essential.”

A Shift in MindsetAutomation has revolutionized the way organizations think security. Now CTOs are coming to recognize the outsize role it can play in edge transformation. The edge is expanding at a speed not witnessed before, and only automation can give organizations the means to catch up to it.

It was made clear in the presentations that for organizations to be able to keep up with edge’s scale and speed, automation is a necessary tool. Without it, companies are fighting a losing battle.

To enforce security at the edge, automation can help organizations eliminate manual burdens, and the vulnerabilities associated with it.

Alastair Cooke points out that the first step of upscaling is to adopt new approaches and new mechanisms. And shifting from the traditional mindset, in this case, to an automation-first mindset is vital.

“Your tools and your approach, your whole mindset has to change to cope with that difference in scale and that was a really significant element that draws through all of these,” said Mr. Cooke.

UpcyclingAutomation at the edge is different from the kind of automation organizations are used to. According to Cooke, at that scale, automation needs to be more policy-driven than procedural.

With a majority of the business world taken with the cloud operating model, businesses are keen on taking what they have learned in the cloud and reusing it at the edge. But it takes more than just hauling toolchains that are used in cloud out to the edge, or building an edge version of them.

Carl Fugate highlights, “This concept of just taking the solutions that I’ve already had in the datacenter don’t necessarily translate very well to the edge. In a lot of cases, there were very similar technologies and I think, especially in the automation space, at least conceptually, those things absolutely have to follow and be in support of the edge transformation. They’re not one for one.”

He added, “What I did with Kubernetes on-prem doesn’t necessarily look or feel the same once I push it out to the edge.”

Does this mean that moving to the edge entails building a toolchain from the ground up? Not necessarily, but there needs to be solutions that can remove the barriers to using the same technologies from cloud to the edge.

“Treating the cloud as a north star, and trying to apply as much of the cloud paradigm in terms of how we think about things and operate as possible is an interesting aspiration. But obviously there’s a massive set of constraints that you don’t deal with in the cloud, that are unique to the edge. I think that it’s just interesting to continue to dive in, and explore deeper and see what sort of solutions can make some of those constraints feel like they’re not there as much as possible, knowing that there’s going to be some that are just inescapable.” said Mr. Chambers.

New MeaningsThis brought the discussion to the core meaning of “edge”. There are multiple interpretations of the edge that influence organizations’ choice of technologies. The panel highlighted that edge takes on a new meaning with every vendor and every use case, and that was one of the things that echoed through the presentations.

As Mr. Warcop pointed out, “There are a lot of different definitions of edge, and different buyers and personas.”

He noted that a lot of the solutions that the companies presented were aimed at compressing the functions of legacy business units and deliver them at a remote site.

Wrapping UpWhatever the meaning of the edge may be to a certain vendor, it is clear from the discourse that it requires a different breed of technologies that can either be developed from existing concepts, or built from scratch, something that a lot of the presenting companies are already doing, or has in their agenda.

Hear the delegates drill deeper into the premise and come up with ways in which vendors can build and enhance existing solutions to unlock the full potential of edge computing in this Gestalt IT Delegate Roundtable from the Edge Field Day event.


© Gestalt IT, LLC for Gestalt IT: Unraveling the Key Themes of Edge Computing – A Roundtable Discussion

View Details

Rapid digital acceleration sets the tone for modern businesses in the advent of edge. IT teams tasked with overseeing infrastructures at the edge are under tremendous pressure to keep up with the non-stop innovation. The path of least resistance in the status quo is to find an equilibrium between rolling out smart applications, rapid time-to-market and always-on availability.

At the recent Edge Field Day event in California, Carl Moberg, CTO and Co-Founder of Avassa showcased the Avassa Platform, an application management solution that makes operating at the edge as simple as public cloud. The Avassa Platform empowers teams to create a positive customer experience through rapid deployment, consistent monitoring and seamless management of distributed on-site edge applications.

Performing Under PressureIT teams tasked with building edge infrastructures face many a challenge. They need to move fast, constantly evaluating the infrastructure against the long list of expectations foisted on them by cross-functioning teams.

For starters, it needs to have the gold standard 5 nines uptime. It must align with the organizational security posture, and not make it vulnerable. At the same time, it should offer a no-fuss, self-service style of operation like public cloud that everybody by now has grown so used to.

Mr. Moberg in his presentation, introduced two user personas that the Avassa Platform effectively targets – platform engineers and application developers. Despite complementing each other, the two teams have dissimilar goals and interests, which begs a unifying solution.

MisadventureBorn in Sweden, Avassa is a software-only company with a background in distributed systems automation and orchestration. Avassa has been following the breadcrumbs for some time, doing its own research, talking to IT teams about their experiences with operating at the edge.

Mr. Moberg shares his understanding – “The assumption is that the edge is owned by whomever is using it.” “So, think of retailers, industrial shop floors, quick-serve restaurants that you love. Think about things you own, on-site, or on-prem edge environments,” he urged.

The companies in Avassa’s survey were organizations that were using a mix of public and private cloud at the time. When asked to extend their capabilities to on-site edges, mayhem ensued as they found out that their current stash of tools was redundant in the new infrastructure.

“Particularly, the application teams had gone through a very long and arduous journey to the cloud. They had reorganized, recultured, and retooled themselves, and they were pretty proud of the agility they had for the public cloud,” Mr. Moberg noted.

Re-shifting workloads to the edge was a whole new ordeal. After hearing from the horse’s mouth, Avassa realized that there’s “a horrible tooling void for applications running on their on-site edge. There’s almost no reuse of their CI/CD-centric environment, and the platform teams’ tool set.”

The Avassa PlatformAvassa’s is an application management and orchestration platform for on-site edge. Moberg explained that the architecture consists of two core pieces of software – the Avassa Control Tower, and the Edge Enforcer.

The Avassa Control Tower is a software-as-a-Service (SaaS) solution that serves as the central management platform for distributed edge applications and resources. The Control Tower presents both edge cloud management and application lifecycle capabilities.

“It provides the features you need in terms of managing a fleet of infrastructure. So it has to do with sites, applications that you deploy, monitor and observe, and of course event streaming and all kinds of support stuff,” he said.

It can be used to observe the health and behavior of applications, sites and hosts, and deploy and upgrade distributed applications. The Control Tower also has a central repository of secrets that it manages and allows for selective distribution to applications. The Control Tower can also be installed on-premises.

The second piece, which is the Avassa Edge Enforcer is a software agent that is installed across hosts running in on-site edge infrastructures.

“This Edge Enforcer calls home to the Control Tower and tells it the environment that it sees and now you can start deploying applications while monitoring the IT infrastructure from the Control Tower,” said Mr. Moberg.

The key capabilities of the Edge Enforcer are local cluster management and application scheduling. It performs scheduling and placement of applications, in addition to providing zero-touch host registration and edge-native services for secrets management and event streaming.

“It manages local clusters. At the heart of it is, of course, a pretty sophisticated application scheduling mechanism, but it also has things like event streaming, secrets management and other things that must be produced at the edge because we want to be resilient for upstream outages,” said Mr. Moberg.

Wrapping UpMoving to the cloud was an exacting routine of modernization of architectures, tools and processes. Now as organizations take the next step towards the edge frontier, they need more vendors like Avassa that are committed to making the journey a breeze. The Avassa Platform offers the much-needed break from the back-breaking regime of deployment, configuration and lifecycle management. It essentially lends to businesses at the edge the same cloud operating model that will make living on the edge so much easier.

To watch the Avassa Platform in action, be sure to check out Avassa’s presentations from the recent Edge Field Day event.


© Gestalt IT, LLC for Gestalt IT: Managing Applications at On-Site Edge with Avassa

View Details

Edge computing continues to grow as demands for low-latency, disconnect-friendly, privacy-conscious applications swell. But even though edge computing accommodates new and creative architectures, it does not come without its costs.

Edge environments face numerous constraints that are foreign to the cloud computing world: brittle network connections, poor bandwidth, unreliable power, constrained physical spaces, and limited hardware resources to name a few.

This problem domain is not foreign to me as we navigated similar architectural challenges while provisioning and clustering 2,500+ K3s clusters on bare metal Intel NUCs across all Chick-fil-A restaurants in North America.

The Challenges of ProvisioningOne of the many challenges with edge computing that is easily forgotten is the absence of on-site technical support, especially in remote locations (think oil fields), or retail environments.

Enter zero-touch provisioning (ZTP), which enables devices to be automatically provisioned with the necessary configuration for their environment without any human interaction.

CNCF defined this key principle for edge-native solutions in a recently published Edge Native Report as: “Edge native requires a mix of remote and centralized management and zero touch provisioning of hardware and software. Staffing at the edge may be untrained, untrusted, minimal or even non-existent”.

Organizations considering large-scale edge deployments will likely find ZTP essential to their success, since manually provisioning hundreds, thousands, or tens-of-thousands of devices is too slow, cost prohibitive, and mistake-ridden to do with a human team.

Achieving zero touch provisioning requires solving several challenges. Devices must be imaged and assigned to customers, shipped to the correct locations, and tracked throughout provisioning. Device trust must be established.

Provisioning failure states must be considered, accounted for and managed, including scenarios such as loss of power or the network during provisioning. Most importantly, “bricking” (the process of turning a functional computer into a non-functional brick) devices—and especially fleets of devices—must be avoided at all costs.

Zero Touch Provisioning with Scale Computing At the Edge Field Day event, Scale Computing announced the launch of their Zero Touch Provisioning capability which provides a solution to this. A customer can select a device from the available fleet, that includes everything from lower-capacity devices like Intel i7 NUCs with 64GB RAM, to powerful machines with GPUs, providing a lot of flexibility on compute power and physical form factor.

Scale Computing images and ships these devices to the site, where they simply need to be plugged into power and ethernet. From there, Fleet Manager and the zero-touch provisioning take over.

Scale Computing’s architecture revolves around a proprietary state machine that is built into their HyperCore product, which is present on the initial image shipped to the site. This state machine tracks a node’s progress through its initialization process. This approach handles failure states well, and prevents in-field “brickability”.

Here is how it works. When a device is connected, it checks in with SC//Fleet Manager, which delivers a configuration file that tells the device what to do. Devices are pre-assigned to a particular customer before shipment to establish a basis for trust, and enable the devices to be discovered for configuration within the Fleet Manager portal.

Scale Computing doesn’t know what the customer wishes to do with the node at this time; they simply provision it and ensure that it initializes successfully. Provisioning is quick, taking around 10 minutes.

Once a device is initially provisioned and clustered, Scale Computing provides an Ansible-based capability to configure whatever is desired on the cluster of nodes, such as Google Anthos, Azure Arc, Avassa, or Kubernetes.

Cattle, Not PetsIn cloud computing, DevOps teams are encouraged to treat their compute resources as “cattle, not pets”. “Don’t bother with naming your servers or getting to know them, because they could be gone any moment,” they say.

While the edge development paradigm is quite different than the cloud, this principle still works. This is especially true for deployments with low-cost hardware, such as the Intel NUC (which was exceedingly popular at the Edge Field Day, and is available from Scale Computing).

With the right architecture in place, it is possible to treat edge nodes as cattle instead of pets, too. As Craig Theriac of Scale Computing stated, we could think of these edge devices as “disposable units of compute”. Should a problem arise, we simply “shoot the cow” and drop-ship a replacement knowing that the workloads/service remain available on the remaining nodes even while waiting for the replacement to be added.

Assuming ZTP is a capability, this makes a lot of sense in many edge deployments as shipping a replacement device is inexpensive and reduces operational troubleshooting toil and the need to deploy a human technician. Failed nodes can be shipped back, validated, and either, be re-entered into the fleet or disposed of.

Having a mature process for “wiping” a deployed node back to its original arrival state and re-creating it is another pragmatic way to avoid costly human troubleshooting. Manually supporting issues becomes problematic at the edge scale, and requires a cattle mindset, but it is only supportable with automation.

ConclusionEdge is a frontier, and at times a wild one. Remote locations, low-trust environments, unreliable networks, and data privacy laws are real challenges, but businesses and consumers demand these frontiers be conquered to create the high-quality experiences they desire. Zero Touch Provisioning and a “Disposable Units of Compute” philosophy are two approaches that can power the acceleration of successful, scalable and manageable edge deployments. Scale Computing’s Zero Touch Provisioning and Sc//HyperCore solution appear to be great building blocks that organizations can place at the foundation of this new chapter.

Be sure to check out Scale Computing’s presentations from the recent Edge Field Day event to know more.


© Gestalt IT, LLC for Gestalt IT: Scaling the Edge with Zero Touch Provisioning and Scale Computing

View Details

Infrastructure modernization has caused the biggest changes for small and mid-level organizations. They are faced with a prolific amount of data, and a tremendous load of administrative chores that their in-house teams are ill-equipped to handle.

At the recent Edge Field Day event in California, Scale Computing presented SC//HyperCore, a self-healing platform that provides IT teams a break from tedious, time-consuming processes. The HyperCore identifies and troubleshoots errors in real-time, reducing long manual processes down to minutes. Its goal is to optimize the workforce without overburdening them.

Scott Loughmiller, Chief Product Office and Co-Founder at Scale Computing gave a sneak-peek of the Autonomous Infrastructure Management Engine (AIME), the technology that is the brain and brawn of the SC//HyperCore platform.

AIME has been a part of Scale Computing’s portfolio a long time, powering its technologies from behind the scene.

A company that prides itself on delivering simplified solutions to customers, Scale Computing has remained number one on the CRN scoreboard for 34 years in a row. The company boasts a rating of 102.4 in the Product Quality and Reliability category which is the highest ever. Scale Computing credits their Autonomous Infrastructure Management Engine for this.

AIMEWhat is it? Mr. Loughmiller provides a plain-speak gist of AIME: “A sort of hand-built model of the environment the cluster is running in.”

The AIME is to the environment what a digital twin is to a network. It models the realities of the environment, and extrapolating from the data provides automatic monitoring and maintenance of the hardware and the software.

Mr. Loughmiller informed that AIME deeply integrates with the hardware no matter the configuration, pulling information such as hardware error, CPU temperature, and software glitches that tell the state of the cluster, and using them to build a model of the same.

Mr. Loughmiller highlighted the AIOps functionality built into AIME. “It incorporates all this cross-domain information – networking, hardware, environmental stuff. We’re pulling all of this information in, and building a model of the state of the system that allows us to predict and prevent issues, identify root cause and then automate remediation.”

Unlike most hardware-agnostic vendors, Scale Computing manages all the hardware, from upgrading to maintenance. The company owes its award-winning support service to AIME that provides the support teams all the information they need to offer swift resolutions.

Inside the Workings of an Autonomous EngineHere’s how it works. AIME relies on great-quality data only to produce intelligence. Mr. Loughmiller described the functions in three steps. It starts with collectors, or small packets of code that go out into the environment and collate information from various components in the system. This includes the temperature of the CPU, state of hard drives, disk space, system load, VM status and such metrics.

The data is then double-checked with something called Checked Values. The function of Checked Values is to check the data for validity, freshness, scope and such parameters. Based on the readings, it decides if the data is valid and reliable.

Mr. Loughmiller likened it to an instrument panel on an aircraft that besides pitching information, also provides warning flags indicating failures, when there is an error in the data. In this case, Checked Values tells users when the data is expired, unreliable or erroneous.

At the third stage – Conditions – real intelligence is delivered about undesirable conditions detected in the system. The data here is represented in Boolean value- Set for a problem, and Clear for no problem.

“The great thing about that is, now with the SC//Fleet Manager, that’ll bubble all the way up to the top. You see those conditions, and correct them,” said Mr. Loughmiller.

It also shows historic data, query-able via simple command lines. Checked Values are available cluster-wide and shared across multiple subsystems.

An Expert SystemWith these inputs, AIME builds a virtual model in the state machine. Data here is refreshed at near-real-time for high accuracy.

“Data is constantly coming in from the collectors, and anytime new data comes in, that bubbles up, and the state machine will make adjustments based on that,” said Mr. Loughmiller.

And that is how teams can go from the current state to the desired state. “The result is an expert system,” he says.

Scale Computing trusts only high-quality data to build the model, as it enhances the reliability of the intelligence.

Mr. Loughmiller informed, “What we’ve been able to do over the last decade is build a structure that actually models reality, and accurately chooses the right path to fix whatever problem is available. We’ve been tweaking and tuning and adding to the state machine for a decade.”

If you are interested to know more about the solutions Scale Computing introduced at the Edge Field Day event, check out the demo presentations at the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: Autonomous Infrastructure Management with Scale Computing

View Details

Three years ago, this month, the first COVID cases in the country were diagnosed. Just weeks after, the lockdown started, and we all got a new social rule book to play by. While Zoom saved corporate businesses from dying an unnatural death, the retail industry that had until that point thrived on physical presence, suffered a huge blow. That effect cascaded into the economy in the forms of job losses and delinquency in debt repayment.

Now, once again, hopeful phrases like “post-COVID”, “in-person events” and “in-store shopping” have started to peek out from the crevices of our vocabulary, and the world is turning a page on what would be remembered as a dark and harrowing chapter in human history.

So how is retail looking coming out the other end? eCommerce heroically propped the weight of a lumbering retail industry through the pandemic years. But the dust is settling, and customers are slowly going back to in-person shopping. Retail has endured, and in 2023, it is entering a new phase of renewed flourish.

In February, at the recent Edge Field Day event in California, Mako Networks presented a solution curated for distributed enterprises. Simon Gamble, Co-Founder and President, showcased The Mako System, a technology that is doing its part delivering “secure networking to distributed enterprises operating at the edge”, while helping a scrambling retail industry back on its feet.

A Network for Distributed EnterprisesDistributed enterprises run hundreds, often thousands of small to medium size locations across regions. Their networks typically have an exploding number of edge devices hooked to them.

These networks support sundry applications – digital signage, self-service terminals, guest Wi-Fi, and various Internet-dependent processes like credit card and payment processing in real time. These make having a ubiquitous network that is reliable, resilient, and secure, imperative on the premises.

“If you’re sending credit card data, personally identifiable customer information (PII), information about stock levels, into the cloud, or if you’re a gas station and you’re sending underground fuel tank levels, it needs to be treated really carefully and securely. To get information from the edge into a cloud or another network, that data needs to be transferred in a secure and encrypted manner,” said Mr. Gamble.

For this reason, “any company that has credit card data flowing in their network needs to be in compliance with the payment card industry data security standard (PCI DSS).” Without it, a company is liable to pay compensation to its customers for any data theft, not to mention sustain huge damage of reputation.

“Another thing that a lot of people don’t think about is that these distributed enterprises are using technology everywhere in their business, and yet, typically they have no one on-site who knows anything about it,” noted Mr. Gamble.

So while a functional network that can be the carrier for confidential client information is the baseline, enterprises running edge locations also require a team of smart hands always on reserve for networking issues.

Serving the Retail SpaceMako Networks is known for manufacturing networking and security devices and products, specifically for distributed enterprises. With retail as its target industry, Mako Networks’ host of solutions leverage its biggest point of difference, a PCI DSS certification. According to Mako, it is the only PCI DSS certified company in this space.

“As far as I’m aware, we’re the only network vendor in the world that has a PCI DSS certification against the actual technology itself,” said Mr. Gamble.

Where Mako Networks is compliant right out of the box, other vendors go by “PCI compliant” which is nowhere near as rigorous, and only means that they are just complying with the PCI guidelines.

Mako Networks is currently headquartered in the US and has presence all over the world including the UK, Australia and New Zealand. Their client portfolio includes some very big names in the petrol space, such as British Petroleum, CITGO, Circle K and Sunoco, in addition to many food and dining companies and parking garages.

As a networking company, Mako Networks’ mission is to provide a strong foundation network for retail business to deploy the technologies they use every day.

Many retail locations fanned out across the world are outside the reach of traditional private networks that are deployed by phone carriers and are limited by geography. So, Make Networks relies on the Internet.

“A lot of the brands and enterprises that use our platform have locations all over the world. The network that is all over the world is the Internet. So ,our platform is designed to run over that,” said Mr. Gamble.

The Mako SystemThe Mako System is everything that distributed enterprises require, and often don’t have at hand. It is a PCI-certified, scalable solution that is carrier-independent, and don’t require customers to stay locked in with one type of carrier. Customers are free to choose any broadband or cellular service provider available in their individual locations. It also requires zero on-site IT management.

The Mako System consists of a hosted cloud-based Central Management System (CMS), and a selection of managed networking devices, managed switches and VPN concentrators. Built specifically to serve multi-site businesses operating a large number of these small sites, Mr. Gamble informed that the combination of hardware it uses is specifically targeted at this market, and is entirely cloud-managed.

Mr. Gamble gave a short description of how the Mako System is deployed. Internally called “service delivery mechanisms”, the devices enable the delivery of the service into the office location or site where it’s deployed. The device with an OS is set up with the store’s primary broadband.

“We can deliver managed broadband with our service, or we act in what is called a BYOB or bring your own broadband mechanism where we plug into whatever the customer has got,” said Mr. Gamble.

The devices also have a built-in cellular connection which is normally used as a failover connection for times when the broadband is down. Additionally, there’s Wi-Fi built into them to extend the reach of edge at points-of-sale (POSs).

This device is controlled by the central management system which provides real-time visibility into the devices and features to manipulate it. Typically, retailers plug in this device to one of Mako Networks’ managed switches for network segmentation.

Since a site needs to connect to all sorts of online applications like credit card payment hosts, loyalty processing hosts and mobile payment hosts, The Mako System enables secure connection to those hosts.

SecurityOne of the key differences that Mr. Gamble highlighted between Mako Networks’ devices and other vendors’ is physical security. The devices have no local management capability on them, and therefore cannot be logged into and reconfigured by malicious entities. The absence of a reset button further diminishes the risks of tampering.

Centrally managed, the devices can only be controlled and viewed from the central management system, by only IT personas inside the company who have access to it.

“Our platform is designed to be used by everybody, so that a company’s IT group can see their entire estate. Typically franchise groups have technical sophistication and they want to have visibility and control of their estates. But, the brand may not want them to control certain aspects of their sites. For example, the brand might want to dictate how the POS networks are set up, but leave other aspects of the customers network for the dealer group to be able to manage,” said Mr. Gamble.

The Mako System, with the CMS and all the hardware is offered as a service. So, instead of paying a steep upfront fee, customers can pay a lower monthly fee across the tenure of the service.

For more information, check out Mako Networks’ other presentations from the recent Edge Field Day event.


© Gestalt IT, LLC for Gestalt IT: Mako Networks – Secure Networking for Retailers at the Edge

View Details

It has always been a dream of technologists to be able to move computing out of datacenters and take it closer to the users. Edge computing has brought that dream to reality. But edge is a new technology, and like all new technologies, it has some imperfections.

ZEDEDA, a fast-growing software company in the edge space, took the lid off the barriers of edge computing during a presentation at the recent Edge Field Day event in California. ZEDEDA showed the audience how to effectively deal with them. VP of Product Management and Customer Success, Raghu Vatte showcased the ZEDEDA Edge Management and Orchestration Solution, a product designed to beat the biggest edge computing challenges, and unlock its true potential.

A Sea ChangeMany see edge as the answer to all the problems that cloud dug up. But the edge is also a sea change, and often enterprises fail to grasp it before late.

“Most of the time, it’s too late, because you have already invested, you have chosen your vendors, you have chosen your technology, and there’s so much inertia about going back to the drawing board and starting over again. That is the biggest problem right now in terms of what edge poses, and how edge is not same as cloud.”

For all its differences, edge can be a lot like cloud, if you do the right thing, said Mr. Vatte.

Challenges at the edge can be put into three buckets – visibility, security and control, all of which emerges from the same root – the distributed nature of edge. The edge is everywhere, in a posh part of a vibrant city or in the middle of nowhere. Problem occurs when something breaks down in a remote edge location where the chances of finding on-site technicians is next to nil.

Mr. Vatte explained the management pain points from the perspective of engineers who are at the frontline combatting these challenges. Their first responsibility is to keep the hardware, and applications in them available. This is obstructed by a number of factors, of which the diversity of hardware they have to deal with is one.

Because the edge is scattered everywhere, maintaining holistic security, both physical and logical, is also problematic than it is in the cloud.

“You have to look at the layer of security right from silicon, all the way to the apps. But security is not just about the applications, or the hardware out there – security is about everything that is the full workflow, right from the people you hire to the people who operate,” explained Mr. Vatte.

A Competitive EdgeZEDEDA sees opportunity in these challenges. Born in 2016, ZEDEDA identified the preconditions of leveraging edge computing earlier than its peers. In order to operate seamlessly at the edge, organizations require a solution that does not demand truck rolls, or additional app development. The expectation customers carry from cloud to the edge is cloud-like simplicity, and automation of operations at scale.

ZEDEDA knows that enforcing security, visibility and control at the edge completes the vision of edge, and that’s the real challenge that needs to be dealt with.

“There is no one solution that can take care of all this, and that was the thing I was sold on when I joined ZEDEDA,” remembered Mr. Vatte.

ZEDEDA’s mission from the very beginning was to solve these problems at the edge. Having seen these problems coming long before enterprises experienced them, they had begun the work years ahead so that a product is ready by the time the problems are felt.

Along the way, ZEDEDA challenged itself to build a solution that caters widely to the different personas working across industries.

Organizations operating in core industries have a robust workforce that is made up of people of diverse skillsets. Mr. Vatte pointed out, “It’s not enough to create a solution that works. It is equally important that the solution can be handled by workforces of diverse nature.”

ZEDEDA Edge Management and Orchestration SolutionThe ZEDEDA Edge Management and Orchestration technology is a cloud-based solution designed to deliver cloud-like agility at the edge. The solution provides full-stack observability and remote management of all edge hardware and applications.

ZEDEDA Edge Management and Orchestration comprises EVE-OS, a vendor-agnostic operating system from which users can launch, orchestrate and control the security of cloud-native and legacy applications on edge compute nodes.

Mr. Vatte explained that ZEDEDA engineered the platform to be first, intent-driven, and second, fit for multi-roles, so that when creating a deployment, all concerned teams can apply their intent no matter how different. Those translate to fleet-level, site-level and node-level properties that are then implemented to the field hardware.

“The way we architected it right from the beginning is that it has to be intent driven because there are multiple players in this equation. It’s not just about one person sitting there.”

There are no limits to the number of hardware or applications that can be managed via the platform. Users can onboard any number of hardware and manage them remotely. Zero Touch provisioning enables quick and hassle-free deployment of the compute nodes.

This is topped with a Zero Trust security model that counters the risks of perimeter-less environments. The platform offers anomaly detection in the software stack, preserves device integrity with hardware root of trust, protects data with at rest and in-flight data encryption, and minimizes breaches with Role-based Access Controls.

ZEDEDA provides full visibility of all hardware and applications through reports and real-time status updates, alerts and analytics.

For a technical deep-dive, be sure to check out ZEDEDA’s other presentations from their first-time appearance at this recent Edge Field Day event.


© Gestalt IT, LLC for Gestalt IT: Beating the Challenges at the Edge with ZEDEDA

View Details

Getting to Know the MG51 and MG51E Cellular GatewaysI was fortunate enough to be a delegate at the Tech Field Day Extra event at Cisco Live EMEA 2023 in February. These particular events take place right in the middle of Cisco Live so it’s a full-on week of tech and a real busman’s holiday as we’d say in the UK. I got to see some exciting innovation from Cisco and meet some of their most experienced and passionate engineers during the extra event. This was my second time as a delegate, the event was incredibly well run by Tom and the team and we had a great line up of speakers and delegates.

Out of everything I saw during the event what really resonated with me was the Meraki pitch on the unveiling of their new 5G MG51 & MG51E Cellular Gateways (the E version simply means you can connect external Antennas). Here’s where it sits with the rest of the MG family:

To watch the presentation I attended and listen to delegates asking Meraki questions directly just click here Watch on YouTube.

This video is part of the appearance, “Cisco Presents at Tech Field Day Extra at Cisco Live EMEA – Day 1“. It was recorded as part of Tech Field Day Extra at Cisco Live EMEA 2023 at 13:00-17:30 on February 7, 2023.To find out more about the sessions held during the event visit Tech Field Day Extra at Cisco Live EMEA 2023

Disclosure. I was invited to attend the Field Day Extra by Gestalt IT, my travel costs were provided but I was not paid to attend or under any obligation to provide feedback on any sessions or technologies discussed. This post has not been reviewed by Gestalt IT or Cisco / Meraki.


© Gestalt IT, LLC for Gestalt IT: Creating 5G Connected Experiences at Cisco Live Tech Field Day Extra with Cisco Meraki

View Details

It is dawning on providers that out-of-band management has more uses than we give it credit for. Out-of-band (OOB) networks are lifesavers during network outages. They provide an alternative pathway of communication with the infrastructure, one that is physically separate from the production network, and unaffected by its performance, or lack thereof.

At our first-ever Edge Field Day event in California, Opengear outlined the growing importance of smart out-of-band solutions in the era of edge computing. Technical Marketing Engineer, Ramtin Rampour showcased Opengear’s Smart Out-of-Band solution that not only provides remote access through infrastructure faults and service disruptions, but also provides value through the network lifecycle, from deployment through remediation.

A Broader ScopeOut-of-band management has been a staple in enterprises for bringing up devices remotely when a network failure cuts them off, and ensuring business continuity. But as edge computing grows bigger and enterprises have IT infrastructures at the edge, out-of-band management finds a much larger role.

“Traditionally out-of-bands have been affiliated with remediation. It’s there to solve a problem when something happens. But as technology progresses and we see all these use cases at the edge, we realize that we can actually help with the deployment, and long-term managing of all of your equipment over time,” said Mr. Rampour

Out-of-band networks are resilient, always available, secure access to the infrastructure. That is great to have when specialized on-site technicians otherwise called smart-hands are not close by. But the use of such a solution goes far beyond just access and repair.

The Opengear Smart Out-of-Band PlatformOpengear’s Smart Out-of-Band solution is a combination of hardware and software. It comprises Lighthouse which is Opengear’s management software. It’s a centralized, secure access portal that provides access to physical devices using console servers in edge locations. Everyday tasks of deployment, management and access happen from this console. The Lighthouse control center is independent from the primary network.

The hardware comprises a selection of small, medium and large appliances of port density ranging from 4 to 8 ports designed specifically for edge and branch sites, to larger rack mount servers with 16 to 96 serial ports.

Deploy, Monitor, ResolveThe Opengear Smart Out-of-Band solution serves through all the stages of deployment, management and remediation of the edge environment. Mr. Rampour explained that it enables Day 1 when the network is brought up, by making device configuration a breeze with Zero Touch provisioning.

“We can Zero Touch provision our own devices as well as provide Zero Touch functionality for your downstream devices, whether they’re switches, routers or whatever you need.”

Configurations can be done even before the broadband’s been installed. With failover to cellular enabled in the Smart OOB devices, users don’t need to waste time getting things up and running when there’s no network.

“We’re essentially the network when there is no network. What we mean by that is, because we have the cellular functionality, if your broadband connection is not in yet, you’re able to actually utilize our cellular connectivity to bring up the rest of your network, whether it’s a manual effort of connecting in and configuring your devices, or whether it’s an automated effort to essentially have our centralized access portal push down configurations over cellular and bring the rest of your network up,” said Mr. Rampour.

Opengear Smart Out-of-Band also helps with management of edge environments. With an independent connectivity established with the devices, users can manage and monitor their infrastructure continuously which over time results in a much stable environment.

The last part, remediation is what OOB solutions are known for. Opengear Smart Out-of-Band expedites access to all physical and virtual devices during network disruptions and outages. A quick access and prompt repair minimizes the impacts of failure, and keeps the network up round the clock.

Wrapping UpThe Opengear Smart OOB solution shows that customers can do a lot more with OOB than just connecting with the infrastructure during emergencies. For those times, it provides the resiliency required to promptly restore field equipment remotely, and ensure continuity of services. But by leveraging it for day-to-day operations, users can potentially reduce operational overheads, while optimizing resiliency in edge infrastructures.

If you are interested to know more about Opengear’s Smart OOB technology, be sure to watch the above presentation till the end, or check out their other presentations from the recent Edge Field Day event.


© Gestalt IT, LLC for Gestalt IT: Operating Edge Environments with Opengear Smart Out-of-Band

View Details

Tech Field Day is heading back to Silicon Valley on Wednesday and Thursday, March 8th and 9th! Tune in starting at 8:00 AM Pacific time for presentations from exciting Tech Field Day companies Kentik, MemVerge, and Men&Mice, as well as a special presentation on the CXL Consortium.

We’re kicking things off at 8 AM on Wednesday morning with Men&Mice. They are demonstrating Micetro, which makes it simple and easy to manage DNS, DHCP, and IPAM. As a modern overlay solution, Micetro provides full-picture visibility and control over workloads on-premises and in the public cloud, without requiring expensive resource-hungry appliances. Next is a delegate roundtable discussion, capturing their thoughts on the transformative potential of technologies like CXL. We’ll continue with MemVerge at 12:30 PM. They’re bringing new capabilities to manage and exploit system memory, especially now that CXL-based memory expansion is coming to market. Learn the latest about their Memory Machine, from the datacenter to the cloud.

Wednesday closes with a special presentation by Siamak Tavallaei, CXL advisor of the CXL Consortium Board, at 3:30. He will give an update on the state of this transformative technology, which we’ve been covering on our Utilizing Tech podcast series.

On Thursday we will hear from Kentik at 9 AM. Their presenters will give practical examples of using Kentik to solve common application problems. We’ll explore how practitioners serving distributed teams or customer workloads can tighten up policies, impact costs, and unblock their colleagues with cloud infrastructure observability that starts with the network. We’ll finish Tech Field Day on Thursday with another delegate roundtable discussion. Learn the takeaways from the delegates on the Tech Field Day presentations as well as insight into the future of the IT industry.

Check out the Tech Field Day website for more details on Tech Field Day 27 and information on our other upcoming events. You can watch the event live on LinkedIn or join the conversation on Twitter using the #TFD27. All of the videos from the event will be posted soon after the presentations on the Tech Field Day website and YouTube channel. Follow us on LinkedIn and Twitter for the latest updates. See you next week!


© Gestalt IT, LLC for Gestalt IT: Looking Forward to Tech Field Day 27

View Details

What makes buildings smart? Is it automation-enabled indoors? Is it robust connectivity for an infinite number of IoT devices? Or is it low energy demands, and higher cost-savings? For many, smart buildings tick a lot of boxes, because they are literally driving the revolution of smart technology. But besides being vibrant fields of technological innovation, smart buildings are also green, which makes sustainability a distinct possibility for the planet.

When the pandemic forced a lot of businesses’ attention back to workplaces, it became evident that offices need more efficient electrical and mechanical systems, and collaborative workspaces. Most notably, the growing adoption of IoT fueled the drive for green spaces. Spurred by trends like sustainability and convergence of Information Technology (IT) and Operational Technology (OT), the smart building technology was born.

At the recent Tech Field Day Extra at Cisco Live EMEA 2023, we learned about some technologies that are the forces behind several smart buildings around the world. Muhammad Imam, Sr. Director of Product Management, Enterprise Switching at Cisco set the stage by talking about the trends that have taken over in the recent years, and Cisco’s areas of focus. Andrew Lu, Product Management Lead, Smart Buildings & Sustainability, gave a walk-through of the technologies on Cisco’s portfolio that enable smart buildings in real world.

A Shift in ToneIn the past, the focus in smart building technology has been primarily around energy footprint and environmental impacts. But now it’s dawning on companies driving this transformation that it is a partial approach. Contrarily, if they start to centralize data from separate devices into a single intelligent system, buildings start to become even smarter.

“We have a lot of opportunities in how we can optimize energy in our workspaces, our digital buildings, and network is really the catalyst to drive this transformation,” noted Mr. Imam.

The tenets of smart building are few – visibility through more data and insights, more energy-efficient technologies, and better indoor environment quality. Good news is that everything from indoor health to power efficiency to visibility can be improved with the use of right technologies. But the challenge with achieving these is the constant expansion of network which has reached a critical mass of devices, and the existing automation that impedes adoption of smart building technologies.

“The ecosystem is expanding, and we are seeing a lot more endpoints getting connected to the network, be it a light, blinds, or HVAC systems,” said Mr. Imam.

Cisco’s Pillars for Smart BuildingsCisco believes that there is a way that all of these can be translated into intelligent energy savings. Imam says that sustainability for customers can be assured in three areas. In the past few years, the industry has standardized 90W Power Over Ethernet (PoE) which is a big leap from the former 15W PoE. This has enabled a lot of endpoints to be connected to the network, and unlocked substantial power and cost gains. PoE accomplishes the IT/OT convergence, he said.

Second is safe DC power source which inherently provides reduced conversion loss.

Lastly, granular visibility of the environment, in terms of things like occupancy, occupant density, and energy consumption around the building, is key to making smart decisions about utilization.

Cisco Smart Building Technology with Catalyst 9000 SeriesCisco has put together a spectrum of technologies under the Smart Building banner that dramatically reduce energy footprints in offices, hospitals, universities, and such places. Since long, Cisco has been working with a growing ecosystem of partners which includes names like Schneider Electric, IBM, and Honeywell, building sensors that can measure temperature, humidity, airflow, and such things indoors. In the next step, they are stacking them with newer technologies to address a broader set of use cases.

“It’s important to realize that smart building is not a very simple solution. It’s a full stack of technologies that enables a wide selection of use cases,” said Mr.Lu in his opening comments.

At the center of Cisco’s stack is the Catalyst 9000 family that leverages PoE for supplying power and data to the endpoints. Cisco’s Catalyst 9000 Series has the highest 90W port density in the industry which allows cost to be distributed over all endpoints, delivering breakthrough economics.

Cisco Spaces, a cloud platform provides the aforementioned visibility across the network, enabling organizations to power up and power down endpoints flexibly for optimum utilization. Data comes in through the Cisco firehose API that streams large volumes at once.

This is topped with a host of building management systems designed in collaboration with industry partners that provide smart control of devices, and a wide selection of sensors that fit buildings of all sizes and age.

“The important part is that at the center of this, we have a converged network enabled by Catalyst 9000.”

Cisco shared data from one of their flagship Catalyst 9000 enabled smart offices in New York to show how energy efficiency can be optimized by leveraging granular visibility and control delivered by Cisco Spaces. Formerly DNA Spaces, Cisco Spaces offers granular occupancy and environmental data that can be leveraged to improve user experience, and bring down the power consumption of the entire IT infrastructure through waste minimization. Cisco Spaces is compatible with all of Cisco hardware from Catalyst to Meraki and more.

“The second pillar of our benefit of 90w PoE portfolio is safe DC power source. Safety is really important and that’s also what actually adds to a lot of the cost of deployment.”

Mr. Lu noted that PoE can deliver up to 10% savings in CAPEX compared to AC infrastructures. Leveraging DC power source for its efficiency with renewable resources like solar and wind that are typically on DC infrastructures, Cisco’s 90W PoE portfolio promises substantially better cost economics and greater sustainability.

Wrapping UpCisco’s Smart Building technology is vital to achieving net zero in workplaces. It paves the path towards reduced greenhouse emissions in buildings with greater and granular control over energy consumption. By deploying a full stack of technologies programmed to run on auto-pilot, Cisco ensures less human management and control, and greater automation in buildings, new or old. This, however, does not change the experience of our interaction with physical spaces.

For more information on Cisco Catalyst 9000 Series, be sure to check out the video above and other presentations from the recent Tech Field Day Extra at Cisco Live EMEA 2023 event.


© Gestalt IT, LLC for Gestalt IT: Making Buildings Smart with Intelligent Automation and Lower Energy Footprints with Cisco

View Details

Industrial IoT hardware solutions are built differently than their enterprise-grade counterparts. They are rugged, and can stand up to the extreme weather conditions of outdoor environments. They are purpose-built for industry use-cases, and have industrial protocol support and integrations. By contrast, enterprise-grade solutions are designed with security, simplicity and ease-of-use top of mind.

This distinction is consistent across all of Cisco’s IoT portfolio. Just like their hardware, Cisco does not mix their software. The company established this when it presented the Cisco IoT Operations Dashboard at last week’s Tech Field Day Extra at Cisco Live EMEA 2023 event in Amsterdam. Technical Marketing Engineer, Emmanuel Tychon, showcased Cisco IoT Operations Dashboard’s newest capabilities and pointed out why its unique from other dashboards.

Cisco IoT Operations Dashboard“IoT Ops dashboard is the most strategic product currently in the IoT business unit. All or almost all of our services are going to be available in the IoT Operations Dashboard” – said Mr. Tychon in his opening comments.

IoT Operations Dashboard is cloud-only. Mr. Tychon explained that Cisco decided to make it so because of the general public eagerness to move to cloud. Cisco still retains on-prem versions of some of its solutions, but is generally moving with the trend.

The Cisco IoT Operations Dashboard is a management platform designed for easy connection, management and maintenance of devices in industrial networks. Often confused with another network management dashboard on Cisco’s portfolio, Cisco DNA Center, the Cisco IoT Operations Dashboard is anything but a copy.

Mr. Tychon explained that the Cisco IoT Operations Dashboard is created for users of all profile, especially those that don’t possess a high-level of technical expertise. For them, the dashboard offers a way to perform tasks like device onboarding, configuration, monitoring, and so on, without getting into the technical minutiae.

Onboarding devices to IoT Operations Dashboard is greatly simple. Where DNA Center requires direct access to all devices, the IoT Operations Dashboard follows a more stringent approach.

At the time of booting, a new device that has no configuration connects to Cisco PnP Connect over the internet and shares its serial number. The PnP application then redirects the gateway to the Cisco IoT Operations Dashboard where it receives a base config. The device is authenticated with a SUDI certificate integrated in Cisco ACT2 chips that come onboarded in all devices.

The IoT Dashboard then sends back a cloud certificate which the gateway uses to verify the cloud platform. Upon authentication, a secure management FlexVPN tunnel is established between the dashboard and the device. All communication within this management tunnel is encrypted.

With the IoT Operations Dashboard, users don’t need to worry about the IP addresses of devices, which makes it a lot simpler for users, considering that IP addresses are constantly changing in IoT.

“When you’re managing remote and mobile assets, you don’t even know what the IP address is going to be. You could have a dynamic IP address that’s changing as the gateway moves, gets connected and disconnected changing operators. You can’t get access to that gateway directly,” Mr. Tychon pointed out.

What’s New

Recently, Cisco added a host of new security features to the IoT Operations Dashboard bringing the entire Cisco IoT portfolio together. The first one is Secure Equipment Access Plus, or SEA Plus.

SEA Plus enables organizations to open a highly secure channel between a computer and a system in a remote and mobile environment. Using it, companies can grant secure policy-based accesses to both employees and external workers. Remote access is enabled in two ways – browser-based and client-based. It currently supports five access methods, namely SSH, RDP, VNC, https and Telnet.

SEA provides a very simple experience to the users. All it takes for a remote user to gain access is to log into the IoT Operations Dashboard using their login credentials. Once inside, they can select a computer from the ones they have access to, and pick from a selection of remote sessions.

“There is no IP connectivity whatsoever between the remote access computer and the computer we are accessing remotely. There is no way you can transfer files, malware or anything that would harm the computer,” said

Access can further be secured with Multi-Factor Authentication or Single Sign-On. Users that require SEA Plus connectivity must have the SEA Plus App on their local computer.

Another new service that Mr. Tychon highlighted in the presentation is the new Cisco Cyber Vision Service. Cyber Vision is an industrial security solution that extends IT security to industrial networks. Cyber Vision performs traffic analysis and provides real-time visibility into OT assets and processes in the network. The deep visibility it builds helps teams know the network topology down to the component level, and understand the threat actors they’re exposed to.

In addition to providing full visibility into asset vulnerability, Cyber Vision Service also performs threat analysis and ranks them in order of severity, giving teams a composite risk score for each vulnerability.

Wrapping UpThe Cisco cloud based IoT Operations Dashboard is a comprehensive solution purpose-built to serve everyone on the totem pole. It’s a useful tool to have for organizations looking for ways to consolidate and optimize management and monitoring of IoT assets in industrial networks. Cisco’s attention to security elevates it from the league of standard dashboards to a solution that meets the lofty needs of modern IoT environments. It’s a single hub designed for industrial networks in which operational simplicity meets enhanced security.

For more information on the new features that Cisco added to the IoT Operations Dashboard, watch the above video till the end, or check out other Cisco presentations from the recent Tech Field Day Extra at Cisco Live EMEA 2023 event.


© Gestalt IT, LLC for Gestalt IT: Managing IoT Assets in Industrial Networks with Cisco

View Details

Across the Internet, there are thousands of network outages each year. Many of these are caused by delayed mitigation of issues. No matter the size of the business, or the duration of downtime, outages are hugely expensive. According to Gartner, the average cost is roughly $5,600 per minute. That amounts to a loss of $300,000 per hour for businesses, and a detriment to the customers’ digital experience.

About 12 years back, Cisco started to dabble in AI/ML with the mission to enhance its technologies. Having tried their hand at it for several things, last year Cisco applied it to networking to abate unplanned downtime with proactive troubleshooting.

At the Tech Field Day Extra at Cisco Live EMEA 2023 event hosted in Amsterdam, Cisco presented Predictive Networks, a Cisco solution that proactively identifies potential anomalies and issues in the network with the help of AI/ML. JP Vasseur, VP of Engineering, ML and Data Science, showed off the solution with a live demo.

Divergent AttitudesFor the past 30 years or so, operators have run networks reactively, where issues are resolved after they show up. But the modern audience has an especially low tolerance for uneven digital experience, and delays in remediation, no matter how minuscule, is synonymous with poor digital experience. Although, as Mr. Vasseur pointed out, reaction time in recent years has reduced to a matter of nanoseconds, yet we are distant from offering users a consistent network experience around the clock. AI/ML unlocks that possibility by taking remediation to the point of predictive.

But when it comes to AI/ML, Mr. Vasseur noted that people are highly polarized. There are believers who think AI/ML to be the only way to build intelligent systems, and heretics who remain unconvinced that AI/ML is realistic, and has real world use cases. Their skepticism is often inflamed by ludicrous theories bopping around the Internet like AI/ML is a ploy of big tech companies to replace humanity with robots, and is a straight up threat to the society.

The Truth is Somewhere in the MiddleCisco believes that the truth is in the middle. Having an early start than many of its peers, Cisco has been able to test out multiple AI/ML approaches during its decade-long journey. Through a series of trial and error, in the process of which it rolled out several AI-based technologies, the company has acquired the expertise to figure out what works and what doesn’t, and determine if AI/ML is the right technology for a certain solution.

For some solutions, it is the right pick, for others, not so much, said Mr. Vasseur. So, at Cisco, they are very pragmatic with their application of AI/ML.

Reliable PredictionsIn the early phases, Cisco selectively applied AI/ML to build IoT, cloud and security solutions. In the next phase, it is focused on implementing the technology in networking.

Three years back, Cisco started working on a project, the goal of which was to predict network issues. It faced some early resistance because of the general skepticism around the practicality of predicting the behavior of something as vast and dynamic as the Internet. Nevertheless, the teams pushed ahead.

The project had three clearly defined goals – predictive diagnostics, deep telemetry and 100% accuracy.

Teams at Cisco spent a year analyzing paths across the Internet and service provider networks in search of signals that could be used to predict issues ahead of their occurrence. Once they were able to triangulate those, they honed in on the gap that exists between precision and recall, and closed it.

“We all know that there’s a lack of trust sometimes, people are on the fence. So, we thought if we are making predictions, we want to make sure that we don’t have any false positive,” said Vasseur.

Through training and retraining of ML models, the technology was made to learn patterns and identify them from historical data to make accurate predictions about the network behavior.

But proactive networking is not a one-and-done approach. Nor is it the answer to every potential issue. That’s why Cisco advises piggybacking it with the traditional reactive mechanism to leverage its full capabilities.

“The goal was by no means to replace the reactive mechanism. It’s to say for some issues, can I predict them before they happen. If not, then I can fall back on reactive mechanism. So, this is really complementary,” said Vasseur.

Cisco narrowed down the scope to achieve perfection. Instead of building a machine learning algorithm that can predict all issues, but with relatively low accuracy, it designed a system that can concentrate on a small percentage of errors with a high level of accuracy.

Cisco Predictive NetworksWith the mandate to make right recommendations all the time, Cisco built Predictive Networks. It’s a SaaS-based solution that requires neither hardware, nor software. It has a simple architecture constituting a predictive engine in the cloud that gathers telemetry from different data sources that it is connected to, and outputs recommendations.

“You will have a tab that says Predictive Networks. When you click on it, you see all the recommendations. In the second step, you will be able to apply the recommendations that sound good to you, and it will close the loop automatically. It does that for all sites at the same time, looking at the holistic view,” explained Vasseur.

With the help of multiple ML models, Predictive Networks makes sense of the data it ingests. The algorithm looks at all possible paths to the applications, and calculates the probability for a congestion or an SLA violation, for every single path. Based on what it sees, it makes traffic rerouting recommendations to alternate paths.

The models also consume information about application behavior from Layer7 every 10 minutes and categorize them into Good, Degraded and Bad, and use it to make the final predictions.

Predictive Networks’ common data model and algorithm are independent of the telemetry sources. That makes scaling easy. Users can decide how far and wide they want it to look in the network, and change the sources of telemetry without retraining the models.

Cisco is in the process of building an outsize data lake for Predictive Networks that can be fed with its in-house platforms like Viptela, Meraki and ThousandEyes.

Wrapping upPredictive networking technologies are highly effective in detecting and analyzing issues before they happen. Cisco’s Predictive Networks is one of the early specimens of that technology that have a fascinating number of use cases. It is a hero product in its power to identify future issues with zero false positives. Users get structured reports of all recommendations of appropriate actions that makes for easy consumption. Last but not the least, the kind of predictive observability it offers translates to improved digital experience, and enables averting potential risks and losses.

Be sure to check out all of Cisco’s presentations from the Tech Field Day Extra at Cisco Live EMEA 2023 to learn about everything Cisco is currently doing in networking.


© Gestalt IT, LLC for Gestalt IT: Predicting Network Problems with Cisco

View Details

We’re excited to announce the very first Edge Field Day event is headed to Silicon Valley February 22-23, 2023. We hope you can tune in live on LinkedIn or the Tech Field Day website to check out the great lineup of companies presenting at the event. Here is a quick overview of what to look forward to.

It has always included applications running at the edge, but infrastructure and platforms designed for use outside the datacenter are rapidly rising in importance. From Kubernetes to orchestration to networking and storage, we’re seeing a whole new category of products for the edge. That’s the focus of Edge Field Day and we’re thrilled to bring you this new topic. Here’s a quick look at our schedule.

Edge Field Day begins with Avassa at 8 AM US/Pacific Time. Avassa provides an application-centric platform for container management at the edge. In their session, we’ll follow a platform engineer and an application developer on their quest to orchestrate and monitor containerized application on edge infrastructure. Next is Scale Computing, our host for the day, presenting at 10 AM. Scale Computing is a market leader in edge computing, virtualization, and hyper-converged solutions. Their presentation introduces zero-touch provisioning, a new feature of SC Fleet Manager that enhances quick and easy remote cluster staging. Our last presentation on Wednesday will be from first time presenter Mako Networks at 1:30 PM. The Mako System is a PCI certified, cloud managed, carrier-independent networking solution that makes it easy to connect and manage thousands of global sites in a high performance network that is secure, reliable, scalable, and cost-effective.

On Thursday we’ll hear from ZEDEDA, another new Field Day presenter, at 8 AM. ZEDEDA makes edge computing effortless, open, and secure with an orchestration solution that simplifies the security and management of edge applications and infrastructure. Wrapping up the event is Opengear at 11:30 AM. A leader in remote management, Opengear provides out-of-band management and NetOps automation that makes devices at the edge as accessible as those in the datacenter.

All of our sessions are broadcast live on the Tech Field Day website and on our LinkedIn Page. The videos of each presentation will also be available on our YouTube channel soon after the event in case you missed any of them live. We also welcome interaction and participation on Twitter and Mastodon as well as questions for our delegates, just tweet at TechFieldDay and use the hashtag #EFD1. Learn more about this event and others as well as find information about our independent technical influencers over on the Tech Field Day website and sign up for our newsletter to find out more information and upcoming events.


© Gestalt IT, LLC for Gestalt IT: Learn More about Edge Computing in Silicon Valley at The First Edge Field Day Event

View Details

Things are once again shifting in the cloud industry. A change is underway, and it has a name – Cloud Native 2.0. Some years back, analysts prophesied that enterprises that are cloud-native, will eventually double down on digital transformation, and keep the modernization going. What is happening today is sort of a fulfillment of that prophesy. And we don’t need a crystal ball to tell us that. The obvious maturity of Kubernetes, the transformation of applications to microservices, and the growing pains of application networking, are proof enough.

At the recent Cloud Field Day event, Solo.io hit this topic. Christian Posta, Cloud Field CTO explained the application networking challenges facing enterprises at this second stage of cloud evolution. In the following session, he showed off Solo.io’s newly released Gloo Platform that alleviates those challenges, and help companies transition to this new era of service meshes and microservice applications, to leverage its opportunities.

The Trends of Cloud Native 2.0`Cloud Native 2.0 has opened a floodgate of innovation. Microservices architecture has grabbed mainstream attention, and is seeing rapid adoption. There is a higher demand for scalability as a result of that, as enterprises need to add more clusters to manage the sprawl.

Having mastered Kubernetes over the past years, organizations are moving on to service meshes to harness new capabilities. Seeing how often the functions of a service mesh overlap those of API gateways, most users are in favor of having these capabilities combined into a modular architecture.

These trends are a reminder that enterprises need to rethink application networking with a new, Cloud Native 2.0 mindset.

What is Application Networking?To level set, Mr. Posta gave a quick high-level description of application networking at the beginning of his presentation at Cloud Field Day. In plain-speak, application networking is the process of making applications available to each other, and to the users. In a network, applications are constantly connecting with data, devices, and with each other through APIs. As they communicate, their assets get exposed to the network in part or in whole. These assets are then discovered and used by other consumers in the networks.

Problem occurs when this needs to happen seamlessly in a distributed and dynamic environment. In the world that Cloud Native 2.0 has brought upon us, nothing is easy. Things are constantly changing in the network, and applications are spread out across multiple availability zones and clouds, which makes it even harder for services to discover each other and communicate.

“When you deploy an application, you might scale it up or scale it down, or it might become unhealthy. There’re no guarantees on exactly how the distributed nature of these services will behave over the network, and what the infrastructure is going to do,” noted Mr. Posta.

Likewise, observability and security too remain a challenge when deploying applications in a cloud platform. When overlooked, these problems make room for unpredictable failures and security breaches.

Getting a Closer Look at the Solo.io Gloo PlatformSolo.io addresses the complexities, inconsistencies, and overheads that organizations run into when deploying microservices applications onto a cloud platform like Kubernetes.

“At Solo, we think about solving these problems, at the gateway layer, or the edge of a boundary, inside a particular boundary in the so-called East- West direction or service to service direction, and then tying this down deeper into the lower layers of the networking stack.”

Solo.io takes a multi-layer approach to solving the challenges of Cloud Native 2.0. The Gloo Platform, released in the fall of 2022 after 18 months of engineering and collaboration work, brings together service mesh and API management in an integrated solution. The platform constitutes Gloo Network, a Container Network Interface (CNI) for Kubernetes, Gloo Mesh, a service mesh, and up top, Gloo Gateway, an API gateway. These come under the API management of the central Gloo Portal.

The platform’s suite of tools offers simplified operations, automated deployment, zero-trust security and deep observability into Layers 3 to 7.

The Gloo Gateway that is “the only API gateway that’s built directly on top of the service mesh” is built with cloud-friendly technologies. It ties natively to Gloo Mesh allowing users to have consistent policies across networking and security for all traffic.

The second layer, Glue Mesh is an enterprise service mesh that allows teams to transparently add properties like centralized observability, zero-trust security and multi-tenancy without modifying the app code.

The last layer which forms the foundational piece is the Gloo Network. Gloo Network provides connectivity, defense and observability for containerized applications using a Cilium-based CNI.

To get more information on Solo.io’s Gloo Platform, be sure to check out their deep-dive presentations from the recent Cloud Field Day event.


© Gestalt IT, LLC for Gestalt IT: Application Networking in Cloud Native 2.0 with Solo.io

View Details

In 2018, Goldman Sachs, a leading investment banking firm ran into rough weather when an internal struggle erupted around change assurance. The company was looking at a long list of problems that had spiraled out of constant network changes typical to banking. Having an outsize network, these dynamics had become too much to handle internally. Although Goldman Sachs was leveraging some in-house automation at the time, they soon realized that in order to stop these problems from engendering a network outage, the automation stack needs to be refreshed with something new, and better. That was the first time, they used a digital twin.

At the recent Cloud Field Day event in California, Forward Networks presented their network digital twin technology, that pulled Goldman Sachs out of the deadlock and brought them into an era of improved network reliability and security.

Mirror ImageIt has long been a dream of industries to be able to see something before it is brought into being. To visualize something before it becomes a reality is one thing, but to be able to get an accurate picture beforehand was beyond most of our imaginations, until technological advancement spurted out digital twins.

A digital twin is a virtual model of a real-world object. Digital twin networks allow operators to test real-world environments, to understand ahead of time how the network will behave in the given scenario. They are incredibly beneficial for achieving better network performance through predictive maintenance. But that is only a small fraction of what can be achieved with this technology. Its potential goes far beyond maintenance.

Digital twin became a fascination for millions as the world recognized its power to bridge the distances between digital and physical worlds. With it, network operators are able to enhance network designs, improve visibility, and assess and manage change which it did in case of Goldman Sachs. By harnessing network data, it can answer several categories of questions on any topic sent its way.

Forward Networks’ Digital Twin TechnologyCo-Founder of Forward Networks, Peyman Kazemian himself showed off the solution to the panel of technology veterans attending the Cloud Field Day event, explaining some of the use cases, and offering a glimpse under the hood.

Forward Networks launched its digital twin technology in 2017 with the mission to recreate the magic of Google Maps, but for IT. Google Maps, what many don’t know, is a digital twin of the global transportation system. Mr. Kazemian commented that it’s this technology that gave Google Maps “a use case so compelling that there’s no going back.” Powered with three kinds of data – static, live and peripheral, it provides travelers real-time views and updates about traffic, routes and places.

Forward Networks started its journey in the same vein. With a simple mission: to make networks more reliable, agile and secure, it has built its digital twin technology with “broad and deep data combined with analytics”. Static data makes the base, which is then enriched with layers of real-time data.

“We started by pulling in data config in a state from all traditional networking devices like switches and routers and firewalls and load balancers. Then we expanded it to SD-WAN and more software-defined elements like NSX and ACI,” said Mr. Kazemian.

Seeing that organizations are leaning towards a hybrid setup to have their workloads spread out between on-premises and cloud, Forward Networks followed suit and expanded to cloud. In cloud, it began collecting data from all the three major clouds – AWS, Azure and GCP.

“What I mean by pulling data is grabbing information about all the cloud components and constructs that affect how traffic is being delivered to those end hosts, whether it’s subnets and security groups, or transit gateway and VPN gateway, or VPC endpoints and anything that affects delivering of traffic.”

To make it more resourceful, they pumped in more information, focusing on peripheral data like performance metrics and security vulnerabilities. This is done to the point where it can provide network and cloud operators the ability to look at the traffic path and see right away where the congestion is, or what in the network has a critical vulnerability that needs to be fixed quickly.

The information is mapped and correlated, to “provide context to other types of information that are not specifically cloud or on-premises.”

Forward Networks digital twin is deployed at scale in large enterprise networks with over 50, 000 on-prem devices. It supports over 30 vendors and 40 OSs, and a variety of networking protocols. As of today, it is in all the three major clouds.

The Two HalvesMr. Kazemian said that the uniqueness of Forwad Networks’ digital twin technology lies in the way it exposes the data and analytics to the users. To elaborate, he broke down the anatomy into two key pieces- a Network Query Engine (NQE) and “broad and deep analytics”.

The Network Query Engine is a vendor-agnostic query engine that provides “access to raw data that is parsed and normalized.” The engine abstracts and normalizes network information like config, links, device state, routing policies and cloud elements, collected from different environments, and present them through an open-config structure. IT teams can query this information like a database. Regardless of the cloud, the data is browsable to all IT teams.

Mr. Kazemian said, “What we spent a lot of time building is computing the path of all possible traffic through the hybrid environment.” He continued, “If you think about the network, there are several ingress points – at the edge, usually in the datacenters, or in the cloud. They can pump traffic into this black box that we call the digital IT infrastructure. For all those ingress points, we compute all possible ways that traffic can be pumped there, and we precompute that. We index that and make that searchable to users.”

Queries can be made on all endpoint data and network paths with sub-second response times. Forward Networks tops the data with deep analytics, so that teams can have access to complete, accurate and up-to-date models of the infrastructure.

“In order for us to make sure that these models sort of match the reality, we have over 120,000 tests where we configure different cloud elements or on-premise devices into a specific configuration bombarded with packets, to make sure we are generating a perfect model.”

Wrapping UpWith AI and machine learning on the rise, it is not hard to explain the massive traction digital twin has gained across industries. It is changing the game in networking by enabling operators to tune up network performance, and prognostically avoid costly outages. Forward Networks’ digital twin technology further advances these capabilities. It can replicate infrastructures with mathematical precision, with data collected from far and wide, and bring it to the fingertips of teams who need them. Using that information, operators can make accurate predictions and prevent issues, thus closing the gap between user expectations and reality.

To learn about Forward Networks’ digital twin technology in greater detail, be sure to check out their presentations from the recent Cloud Field Day event.


© Gestalt IT, LLC for Gestalt IT: Forward Networks – Transforming Business with Digital Twin

View Details

It is often the narrative in IT that in order to get premium solutions, one needs to pay top dollars. This is especially true in case of cybersecurity. Any change in security spending begets a corresponding change in the security outcomes, and consequently, on the overall posture. But there is a silver lining behind this rather unpopular reality which often gets lost in the noise. A strong security posture isn’t so much about the solution as it is about the strategy. Even in application security, which captures over $6 billion in spending, there is a way to establish consistent security at a very reasonable cost.

At the recent Cloud Field Day event in California, Fortinet presented three solutions that build on this argument. Cloud Security Architect, Srija Reddy Allam, and Global SAP Security Engineer, Julian Petersohn, staged multiple real-world scenarios to demonstrate to the audience how Fortinet’s solutions build an impenetrable front, providing pervasive protection to applications throughout the lifecycle.

Expectations and ObligationsWhen it comes to app security, there are some baseline expectations to meet. First, the solution should be easily consumable, and it should not encroach upon the time or bandwidth of the teams.

Second, and this is a top priority with a majority of the organizations, is that a security solution should be able to manage risks at a minimum cost. And last but not the least, affordable operations that would steer an organization away from costly pitfalls.

Securing the Application Development ProcessFortinet pledges to satisfy all of the above, and more. Fortinet’s policy is consistent end-to-end application security which they believe is the secret to drive up cyber resiliency and pare down spending.

Fortinet’s solutions get to the root, and arrest the threat vectors, limiting the possibilities of an attack. Fortinet’s catalogue features a wealth of solutions that brings enhanced visibility and early mitigation of vulnerabilities. Shrinking down the attack surface, not just in production, but right from pre-production, they say, ensures maximum security.

“Application security in general, falls under two primary focus areas- shift left, pre-production and shift right, the production area. The opportunity in pre-production is in how far we can reduce risk and shrink the attack surface. We can reduce risk and improve our security baseline at the least cost there,” explained Petersohn.

“After the application gets into production, this is the point at which it faces the highest risk. Here, the security must adapt to the user inputs behavior, identify malicious versus benign anomalies, and that, without affecting anything of the usual benign behavior, or making it even more complex to go out there,” he noted.

Fortinet Security FabricAs an industry leader of many years, Fortinet knows better than most how to combat cyberthreats. For Fortinet, the path to complete protection is through a 360-degree approach. Its solutions, when working together, ensure a defense readiness that organizations need to operate in the perilous digital world of today.

For that they offer a holistic solution that is called the Fortinet Security Fabric. Fortinet Security Fabric is a unified solution designed with heterogenous integrated solutions and services. True to its name, the solution deploys as a fabric, protecting environments against the most vicious kinds of attacks, be it in cloud, on-prem, edge, remote or campus.

When weighed against point security solutions, the Fortinet Security Fabric has several significant advantages. Rather than relying on standalone products, Fortinet packs the best of its security solutions into a platform. Being powered by a multitude of integrated tools, services and capabilities, each one of which is designed to deliver a certain kind of protection, this fabric provides the broadest defense.

In the guts of Fortinet Security Fabric is FortiGuard Threat Intelligence, the crown jewel of Fortinet’s security portfolio. It’s where their deep awareness of the real-world threats comes from. Threat Intelligence picks up telemetry via millions of Fortinet sensors deployed worldwide. A constant stream of intelligence from FortiGuard Threat Intelligence feeds into the solutions keeping them up-to-date about the latest threats and trends. Combined into a single solution, these services reduce management complexity and cost overheads.

Fortinet’s is an open ecosystem. Petersohn informed, “We have over 500 solutions in our fabric, which can exchange information with over 350 vendors.”

In short, the Fortinet Security Fabric is a slam-dunk for any organization looking for security to be integrated in way that it does not get in the way of application delivery.

Application Security with the Trifecta of FortiGate CNF, FortiWeb and FortiDevSecDuring the demo, the team brought three products into focus to showcase the strength of protection provided by Fortinet.

FortiGate CNFFirst in line was the FortiGate Cloud-Native Firewall Service. FortiGate Cloud-Native Firewall (CNF) is a fully managed, firewall-as-a-service solution that is designed to relieve security operation workloads and simplify cloud network security. FortiGate CNF comes with advanced features like bad IP and DNS filtering, Intrusion Prevention System (IPS), geo IP policies, and application layer visibility.

All security and authentication features can be put to set-and-forget mode which means that the service to do its job without manual intervention. It allows the security teams to offload the works of configuration, provision and maintenance of the firewall software which automatically brings down the TCO, and leaves them to focus on policy management.

FortiWeb CloudNext up is FortiWeb, a web application firewall whose chief function is to block attacks aimed at exploiting web applications and APIs. Also a SaaS offering, FortiWeb has a host of great features including easy on-boarding, vulnerability scanning, bot detection, and ML-based detection and blocking. ML-based analytics reduces false positives, and enables it to look beyond the conventional security models.

Srija Allam informed, “FortiWeb Cloud can be subscribed from any of the major clouds like AWS, Azure, GCP and OCI. All you have to do is subscribe to the AWS marketplace. From there, it’s like creating a social media profile. Just create a support account on support.fortinet.com, and you can log into FortiWeb Cloud.”

FortiDevSecThe third and the final product that ties it all together is FortiDevSec, another SaaS-based offering from Fortinet. FortiDevSec comes packed with vulnerability detection and management capabilities, but most importantly it has the DevSecOps DNA that allows developers and DevOps to use it alike, without requiring any specialized security expertise.

FortiDevSec is primarily a testing solution that automates application testing in the continuous integration/continuous deployment (CI/CD) lifecycle. With just a few lines of codes, engineers can integrate it natively into their CI/CD process. This is particularly useful in agile methodologies where everything happens concurrently and in iterations, and there is not much room for continuous testing.

FortiDevSec scans things like source codes, open-source, third-party libraries, secrets, and Infrastructure as Code (IaC) for hidden vulnerabilities. It serves up the findings on a consolidated dashboard that offers visibility into all the security risks existing in a web application.

Wrapping UpThe end-to-end security imperative is especially paramount in application security. But cost should not be the Achille’s heel of comprehensive security. The solutions show that Fortinet knows how to embed security in the DNA of app development, and most importantly, to do it without blowing up the TCO. Besides doing the obvious job of helping organizations combat the latest strains threats, the solutions examine vulnerabilities, and weed them out to make applications safer throughout their lifecycle. With this trifecta, Fortinet proves once again that security is truly in its wheelhouse.

If you are interested in the technical details of the solutions, be sure to check out Fortinet’s presentation above from the recent Cloud Field Day event.


© Gestalt IT, LLC for Gestalt IT: Application Security with Fortinet

View Details

Modern industries are powered by some of the most powerful and complex networks ever built. But these advances have made network management an absolute nightmare. Anuta Networks recently launched a new capability – Active Service Assurance (ASA) – for their signature network automation and monitoring platform, Anuta ATOM.

At the recent Networking Field Day event, Technical Marketing Engineer, Sahil Katira demoed this new feature. With ATOM Active Service Assurance, enterprises can greatly reduce monitoring overheads and mean time to repair (MTTR), potentially saving hours, and speeding services to market.

Network Monitoring OverheadsWith networks growing at a pace not witnessed before, enterprises are compelled to drain their resources to keep them up and running 24/7. Even so, their expectations of payoff are often thwarted. Manual styles of management and monitoring get in the way.

Management of these environments entails an endless number of tasks ranging from onboarding to monitoring and maintenance. With the number of domains, devices and clouds at an all-time high, most manual approaches are moderately effective at best, and horribly resource-intensive and error-prone at worst. Factor in the pains of real-time monitoring and it’s a hamster wheel. Experts say that disruptions caused by inefficient management styles and monitoring tools cost companies hundreds of hours of delay in service delivery annually.

Enhancing QoE with Anuta ATOMIt’d be a lot simpler if enterprises didn’t have to rely on engineers to manually scout the network for problems, or do the onboarding and provisioning. Anuta Networks’ agenda with ATOM is to enable IT teams to get through the find-and-fix journey without being hit with one problem after another. This is achievable only when a bulk of the management and monitoring work is handled proactively and at speed, preferably without human intervention. That is Anuta Networks’ mission with ATOM.

Anuta Networks added a prequel session on ATOM to the Networking Field Day presentation of Active Service Assurance to give the audience a quick overview of capabilities of the original platform. Kiran Sirupa, VP of Marketing gave a quick rundown of its functions.

“Anuta ATOM helps with complete network automation, all the way from onboarding the devices to maintaining the lifecycle of the devices, upgrading the software, provisioning, and finally monitoring the health of the services and taking any remediation steps,” said Sirupa.

Anuta ATOM is a software solution that comes with an interactive user-interface where operators can create new workflow designs or implement out-of-box ones, to automate tasks. ATOM offloads a majority of the routine work, and in the process removes the additional hurdles organizations face regularly.

“It supports multi-domain, multi-vendor and multi-tenant networks,” informed Sirupa.

Like many network automation solutions, ATOM leverages closed-loop automation to deliver its capabilities. A closed-loop automation framework enables software-centric networking, requiring little to no manual intervention, and ensures high levels of customer satisfaction.

“We focus exclusively on closed-loop network automation for multi-vendor, multi-domain networks. Our target customers are service providers and large enterprises,” said Sirupa.

Anuta ATOM has three deployment models -on-prem, public and private cloud, and SaaS.

ATOM Active Service AssuranceOver the years, Anuta Networks has made several new announcements during their appearance at the Networking Field Day events. ATOM ASA was the announcement this year. The USP of this function is swift identification of anomalies through automated testing, and remediation.

ASA appears mid-way in the ATOM automation pipeline, following the stages of device onboarding and service orchestration. Using a wide variety of tests and metrics, ASA helps ensure that service level agreements (SLAs) are fully met from day one.

“ASA not only works from day one of service deployment, but can also continuously track the service for any threshold breach for the entire service lifecycle,” said Sahil Katira during the demo.

Active Service Assurance in ATOM uses test agents for automated testing. These agents can be deployed and configured as containers, bare metal servers, VMs and so on. Using these agents to generate synthetic traffic, ASA detects performance issues in the network.

“ASA can execute one or more test suites at the time of service provisioning,” said Katira.

Tests are conducted in three steps – creation, execution, and report and remediation. Operators can choose from a library of pre-built tests or create their own on ATOM’s workflow builder. At the execution stage, the test or test suite is deployed. All test reports are published on the ATOM dashboard.

“The reporting infrastructure is customizable, and the test results can be grouped into KPIs. These tests are measured against defined SLAs, and any threshold breach can be logged as an alert on ATOM.”

In the remediation stage, ATOM’s closed-loop remediation kicks in. Operators can automate a wide variety of remediation actions using the workflows.

Part of ASA’s function is ongoing validation, for which it collects data on Key Performance Indicators (KPIs) such as latency, jitters and packet loss, from the network. ASA can also be used to identify abnormal service conditions to make sure that service SLAS are met and maintained at all times.

Wrapping UpAmid mounting network complexities, ATOM Active Service Assurance is the solution that organizations need to get a handle on service anomalies, and keep performance problems in check. ASA works to ensure that there are fewer failures. Overall, it greatly improves mean time to repair, enhancing quality of experience and speed of service delivery.

For more on Active Assurance Service, be sure to check out the demo and other presentations by Anuta Networks from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Network Monitoring with New Anuta ATOM Active Service Assurance

View Details

As we delve into edge computing, one topic that has come up repeatedly is the applicability of Kubernetes as an orchestration platform. Originally created for large-scale cloud environments, Kubernetes has become popular from the datacenter to the edge. But is it really a good fit? This will certainly become a topic of discussion at Edge Field Day!

Does Kubernetes make sense in small devices running outside the datacenter?Kubernetes and EdgeKubernetes is an open-source container orchestration system that has become popular in cloud and enterprise for managing and scaling containerized applications. Although intended for use in the cloud, Kubernetes can also be used to manage and deploy containers in other environments, including at the edge.

As previously discussed, edge computing refers to the processing and storage of data in a dispersed manner, closer to consumers and sensors. Edge compute can be beneficial for applications that require low latency or have data transmission or processing challenges. By deploying Kubernetes at the edge, organizations are attempting to move containerized applications closer to the source of the data while getting the management and orchestration benefits of the cloud.

Using Kubernetes at the edge has some of the same benefits as in the cloud or datacenter: The ability easily to deploy, scale, and manage containerized applications using a centralized centralized “control plane.” The scalability of Kubernetes is particularly appealing in edge environments due to the number of devices and the amount of data collected there. The “cattle” approach is also appealing, since most edge devices are deployed anonymously in un-supervised environments and often need to be remotely wiped and reconfigured.

Organizations deploying Kubernetes at the edge are typically seeking to integrate with Kubernetes environments in the cloud or datacenter. A wide range of applications can be deployed as Kubernetes-controlled containers, and this has become the standard in modern IT. This includes a wide range of edge-specific applications, such as edge gateways, IoT solutions, and edge analytics platforms.

Kubernetes can also be helpful in terms of security. Security is one of the key concerns when it comes to edge deployments, and Kubernetes can provide security features like role-based access control, network segmentation, and encryption. When used properly, these can help organizations secure their containerized applications at the edge.

Shortcomings of Kubernetes at the EdgeKubernetes brings a lot of benefits for managing containerized applications, but it does have some limitations when it comes to edge environments.

Perhaps the biggest shortcoming of Kubernetes at the edge is its complexity. Kubernetes is complex to set up and manage properly and must be carefully tailored for automated operation in edge environments where human interaction is at a premium. Most edge Kubernetes implementations are designed to be fully “lights out, hands off” but this poses a great engineering challenge. I’ve recently discussed this with Edgegap and recommend reading Brian Chambers Medium post for more. But this is a huge concern.

Another issue for Kubernetes at the edge is network latency and outages. Kubernetes relies on a centralized control plane, and network latency or instability can interfere with proper operation. Considering that edge is all about low-latency processing, such as retail or IoT applications, this is a real worry. But many companies (including Edge Field Day presenter Mako Networks) are developing redundant networking capability to help make sure these applications stay connected.

Limited resources can pose another challenge for Kubernetes in edge environments. Most edge servers have limited system resources (memory, storage, and CPU power) and even “light” Kubernetes can be taxing. I deployed Rancher on a fleet of Atom NUCs in my lab and k3s was taking up more CPU, RAM, and storage than my test applications. So Kubernetes may not be the best choice for very light systems. Luckily hardware advances all the time and we’re already seeing a proliferation of RAM and CPU in devices like the Intel NUC.

My NUC lab is slightly unconventional in appearance…Lastly, Kubernetes (and general-purpose Linux) support for arm architectures and other specialized hardware isn’t quite where we’d like it. This can be a problem for edge deployments that use specialized hardware, especially locked-down special-purpose appliances like routers or storage systems. This is also improving rapidly, however, and many of these devices are bringing better APIs and native Kubernetes support.

It is worth noting that Kubernetes is being adapted to work in edge environments, with solutions like edge clusters, Rancher, and k3s (a lightweight k8s distribution for edge computing). These are designed to overcome some of the limitations of Kubernetes at the edge and make it more compact, easier to deploy, and easier to manage.

Stephen’s StanceKubernetes is a powerful container orchestration system that can be used to manage and deploy containerized applications at the edge. By using Kubernetes at the edge, organizations can easily scale and manage their applications, integrate with other technologies, and secure their applications. But complexity, network latency, limited resources, and support for edge devices are all concerns. As edge computing continues to grow in popularity and support for Kubernetes expands, I expect that it will become a key tool for managing and deploying containerized applications at the edge. Watch for Edge Field Day on February 22 and 23, 2023 as we dive into all these questions!


© Gestalt IT, LLC for Gestalt IT: Is Kubernetes A Good Fit For Edge Computing?

View Details

The world we live in is highly connected. Around us, there is a prolific number of devices and equipment hooked to the network, constantly interacting with each other. This new wave is sure to hasten the pace of technological evolution, but not before it has created a surge of challenges for operators.

At the recent Networking Field Day event, Juniper Networks showcased a solution that tones down operational complexities of wired switching, making Day 0 to Day 2 tasks cloud-like simple for campus fabrics. Abhi Shamsundar, Product Management, AIDE, presented Juniper Mist Wired Assurance, an AI-powered service that borrows from Juniper Networks’ wireless portfolio to deliver improved device and user experience.

Inescapable ComplexityThe campus network is rapidly expanding. In its current state, it has too many operational kinks. With a growing number of switches and routers in the picture, cyclical tasks like onboarding, configuration, integration and monitoring of devices have become a nightmare. Engineers find themselves chasing their tails when looking for the source of a problem, resulting in interminable delays in remediation.

This inside chaos reflects poorly on the overall network performance, not to mention, drives operators crazy. A demand is growing for services that would render low-friction experiences, and make campus fabric management simpler.

Bringing AI-Powered Automation to SwitchingAdministrators can overcome a lot of the user-experience quality and visibility issues if they adopt a cloud-like management model.

Case in point, Juniper Mist Wired Assurance. Wired Assurance addresses the problem two ways. It simplifies wired switching by replacing Day 0 tasks, like onboarding and provisioning with plug-and-play capabilities. It enables auto-provisioning via global configuration templates allowing users to configure switches and site attributes consistently and effortlessly.

“Our focus currently, from a Mist standpoint, encompasses every piece of network equipment, all the way from wireless, wired and WAN, to ultimately give you answers on what the experience is like,” said Shamsundar.

Juniper Networks switches stream in rich telemetry data that gives operators deep visibility into the states of the switches in real-time, reducing root cause analysis and time to repair.

“We have telemetry coming in from Wi-Fi, from wired as well as the WAN portfolio. Our focus is to get the most out of this telemetry and make sense of it,” said Shamsundar.

Wired Assurance combines the power of automation with Mist AI to extract actionable insights out of the telemetry data, and expedite troubleshooting with self-driving actions.

Juniper Mist Wired AssuranceJuniper Mist Wired Assurance is a cloud-based service that is paired with the underlying EVPN-VXLAN architecture. Together, they make the Juniper AI Driven Campus Fabric. The goal of Wired Assurance is to make provisioning, deployment and operations at scale seamless and swift like Juniper Networks’ Mist access points (APs), and at the same time provide a granular view of the fabric on the whole.

Automation of switching operations happens in three stages – Day 0, Day 1 and Day 2. Using single-click activation via Zero-Touch Provisioning, wired switches can be onboarded in groups. Within minutes of onboarding, network administrators are able to view switch metrics and service levels on the dashboard.

“Every single switch that goes out is shipped with a claim code. You can either onboard all of your devices that are part of a particular purchase order in one shot, or you could do it via a mobile app as you go on installing, racking them and stacking them. The goal for us is to make the deployment as console cable free as possible,” explained Shamsundar.

Wired Assurance also brings a host of AI-driven automation capabilities to Day 2 operations, chief among which is Juniper Marvis, a virtual network assistant that draws its power from Mist AI to provide real-time answers in natural language.

Shamsundar said, “Our whole focus when we brought the construct of Service Level Expectations (SLEs) from the wireless world, was to answer the question of how your network is doing from a client experience perspective, and not just the network devices being up or down.”

The dashboard offers detailed analytics on all the metrics starting with switch health to throughput, congestion, interface anomalies and more. This is particularly useful for swift root cause analysis (RTA) and repair.

Juniper Mist Wired Assurance takes observability a step further with Marvis Actions. Marvis Actions provides a client-to-cloud view that Juniper Networks calls administrators’ “morning cup of coffee”. While Marvis brings real-time visibility into network issues on the SLE dashboard, Marvis Actions bubbles up the high-impact problems and makes proactive troubleshooting recommendations.

All the information is automatically filtered out and presented based on category and relevancy, so that administrators do not have to navigate through all of the alerts to get to the important ones. While they can still view the entire health of the organization in one shot, they can also hone in on the top worst sites by just activating a filter. For a more fine-tuned view, they can select the specific metrics they want to look at, to get an even cleaner view.

Wrapping UpFrom the demo given in the presentation, it is obvious that AI-based automation is the brain and the muscle of Juniper Mist Wired Assurance. Wired Assurance fully utilizes it to reduce operational overheads, and really enable cloud-like management of campus fabrics. By alleviating the burden of time-intensive, manual tasks with streamlined, automatic functions, it plays a critical role in killing downtime, improving user experience and making campus fabric management push-button simple.

Be sure to check out Juniper Networks’ other presentations from the recent Networking Field Day event for latest updates on the Juniper AI Driven Campus Fabric.


© Gestalt IT, LLC for Gestalt IT: Managing Campus Fabric with AI-Driven Automation with Juniper Networks

View Details

The last time Cisco Live happened in Europe was back in 2020. The journey back to having the event has met with challenges for sure. Cisco is excited to be in Amsterdam in 2023 for the first edition of Cisco Live EMEA and we’re just as thrilled to be there with them for Tech Field Day Extra!

Tech Field Day Extra Presentation ScheduleOur two-day event kicks off Tuesday afternoon with the first set of presentations from Cisco. We’re going to be hearing all about how they are integrating AI into their products as well as a peek at some of the newest Cisco Meraki innovations around policy and mobility. After that we’re going to jump right into enterprise networking and hear about some exciting new technologies for infrastructure as well as a special peek at some cool new Nexus offerings that will blow your mind.

Wednesday is another full afternoon of Cisco announcements. We’re starting off right at noon with some firewall discussion before the IoT group shows us the latest and greatest in rugged devices for industrial applications. We’ll wrap up the day with a dive into SASE and SD-WAN to learn how this technology is transforming our remote workers to make the more productive in the modern world.

Follow Along On Your ScheduleThe event takes place February 7-8, 2023. The presentations will be streamed live each afternoon in CET on TechFieldDay.com, the event website as well as the Tech Field Day LinkedIn page. For those that want to catch the recordings afterwards on-demand you can find them posted on the Tech Field Day YouTube channel. Don’t forget to follow Tech Field Day on your favorite social media platform to participate in the discussions using the hashtag #TFDx. We look forward to seeing you online for Tech Field Day Extra!


© Gestalt IT, LLC for Gestalt IT: Tech Field Day is Extra at Cisco Live EMEA!

View Details

There’s a common consensus over what make a great technology in IT. It consists of things like consistent performance, low-friction operation, cost-effectiveness, and quick ROI. At the recent networking Field Day event, Cisco presented one such solution. The Cisco Crosswork Network Controller (CNC) lets enterprises exchange operational complexity and cost for Quality of Experience (QoE) and cost advantage.

Room for ErrorThe dynamics of modern networks is complex. Things are changing all the time, making it harder to find and resolve problems systematically. Over time, organizations wind up with arsenals of tools to make sure they have eyes on everything, but instead, end up with islands of visibility with no unifying feature.

Management of the environments is painfully complex as well. It entails endless chores, some of which have themselves emerged as sources of risk. Tasks like provisioning, configuration, deployment, monitoring, and troubleshooting are exacting. They take prolonged periods of time, and have very small margin for error. Even the smallest of human errors can become the number one cause of a catastrophic outage.

Human errors aside, there is an insane number of things that can go wrong in the network just on their own. For example, bandwidth swings can lead to network congestions, negatively affecting QoE.

“On the infrastructure, we have many different services that are running. Some of them are more latency sensitive, some are bandwidth intensive. Of course, we do expect fluctuations in the traffic, but that fluctuation could always cause congestions,” said Deepak Bhargava, Senior Product Line Manager at Cisco.

Enterprises resort to over-provisioning to cope with congestions, but it’s not the answer they need, he said. Over-provisioning inflates the cost, and that extra capacity isn’t always utilized.

In a time when achieving time-to-value is more critical than ever in IT, these are major stumbling blocks.

Cisco Crosswork Network AutomationCNC is a part of the bigger Cisco Crosswork Automation portfolio that constitutes “a breadth of capabilities that helps address functions across a typical operational lifecycle, right from planning and design.”

The idea behind Cisco Crosswork Network Automation is to simplify service lifecycle functions to push-button actions. It leverages closed-loop automation, the strength of which is continuous monitoring and assessment.

Bhargava laid out the three cornerstones of Crosswork Network Automation that form the foundation of all of Cisco’s offerings in that portfolio. They are – visibility, insights and action.

“Visibility is really about understanding the state of the network, how the services are performing. Are they at a risk of failing to meet the SLAs? How are the devices performing? Are there any topology changes, any alarms?” said Bhargava.

Crosswork Network Automation seeks to provide answers to all these questions with data collected from the network over, and offer a comprehensive org-wide view of things.

But visibility by itself is a stressor, if it’s not accompanied by insights. One of the key functions of Crosswork Network Automation is to reduce that data to crisp, accurate and actionable insights. CNC transforms network data into knowledge. Using automation to extrapolate from the data, it predicts issues and identifies patterns where possible, making the segue into action quick and organic.

Crosswork Network Automation can automate certain processes preemptively, preventing warning signs from manifesting into real issues that could impact network performance and availability.

Capabilities of Cisco Crosswork Network Controller at a GlanceThe Cisco Crosswork Network Controller is built for modern networks. It draws its power from two sources – automation and intent-based networking. Leveraging these, CNC undercuts operational and cost overheads, unlocking maximum ROI.

Bhargava explained, “Crosswork Network Controller is an SDN (Software-Defined Network) controller for the IP transport network. It’s really a turnkey automation solution that helps to manage a breadth of service lifecycle functions, right from provisioning, visualization, monitoring, optimization to troubleshooting.”

The goal is to achieve faster deployment and effective remediation at a fraction of the typical cost of operation. CNC realizes these goals by condensing time-intensive provisioning tasks with intent-based provisioning.

“It can be done in an intent-based, automated fashion, where you can express the intent in a service model, and it gets orchestrated across multiple domains.”

Integrated monitoring of service health, and quick mitigation of network congestion ensure optimum QoE for customers. CNC employs a series of optimization techniques to tactically optimize bandwidth during congestions.

“It can quickly react to network fluctuations through its real time monitoring and optimization capabilities, so that you can always be on top of things,” said Bhargava.

The Cisco Crosswork Network Controller streamlines and automates maintenance and troubleshooting tasks, ensuring quick and effective remediation without human intervention.

Furthermore, CNC closes the gaps between data silos with unified visibility. Through a single dashboard that offers a detailed, unified and real-time view of the network topology and services, and integrated maintenance workflows, it improves operational agility.

Wrapping UpCisco Crosswork Network Controller brings with it a host of capabilities that alleviates the pressure of routine maintenance tasks. It shows modern enterprises how operational overheads can be tackled and outages can be limited, while ensuring operational agility with strategic use of automation. With it, a higher QoE can be assured through elimination of manual approaches to provisioning and monitoring. The value it provides is on-brand with Cisco.

Watch Krishnan Thirukonda make the Cisco Crosswork Network Controller visual with a demo in the above session. For more interesting presentations by Cisco, be sure to check out the recordings from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Making Networks More Sustainable with Cisco

View Details

It is hard to make things simpler in technology, especially when everything is tangled in a gigantic web of connectedness. But if made possible, there’s usually good money, or great value in it.

This past Networking Field Day event, Arista Networks made their first Field Day appearance of 2023. At the event, the team showcased Arista CloudVision, a telemetry portal designed to simplify management by delivering network-wide visibility. CloudVision, Arista says, offers a way for companies to manage and monitor networks effortlessly. Let’s dig into that.

A Little ContextEver since the network started to expand its perimeter, and grow tumescent with countless users, devices, systems and applications, operators have been caught in the hellfire of management complexities. This slow burn crisis affects work in every front – root cause analysis (RTA), troubleshooting, operations, compliance management – at times, tailspinning into network-wide outages.

Part of the reason failures in networks happen at a high frequency is because teams tasked with managing the infrastructure are not furnished with up-to-date tools and methodologies. The tried and tested methods of yesterday prove old and hackneyed for the modern cloud-like networks, and as a result, they do not payoff.

IT teams need more solutions that offer low-friction, consistent experiences, and timely approaches like cloud principles, DevOps model, software-first approach, and do-it-yourself automation, to bring up the operational efficiency at scale.

Observability with CloudVisionArista Networks has a clear-cut agenda in that regard. Ryan Madsen, Director, Software Engineering, while presenting the architecture of CloudVision at the Networking Field Day event was direct about it. He said that Arista’s goal with CloudVision is to “make networks simple to manage and monitor.”

“For monitoring, there’re two key attributes that we want to provide to people. One – really great real-time visibility, let people understand what’s happening in the network right away, and second – really great historical visibility.”

It may be an ambitious goal, but Arista is on to something.

CloudVision realizes Arista’s vision with two key elements – telemetry and automation. It offers incredibly nuanced visibility of the network components, device by device. The dashboard offers a per-device view, showing device state like BGP details and peer information, system information, switching in all details.

In the presentation, Madsen demonstrated CloudVision’s real-time capabilities. By clearing BGP sessions on a device, he showed how quickly CloudVision can refresh all information, offering instant visibility by streaming information at a “nanosecond timestamped granularity with an end in latency of an order of 100 milliseconds.” Any change in the device state is updated and displayed in real-time.

CloudVision provides historic device-state data through a timeline at the bottom of the dashboard. This timeline features trends in metrics and queries over time. By dragging the cursor back and forth, users can view the state of a device at a precise time on a particular day, or compare two devices and monitor events.

“This historical visibility is really useful for understanding how your network has been performing,” said Madsen.

When CloudVision was first launched, it was an on-prem solution. Arista has since launched a cloud version of it using the same resilient and robust architecture that enables it to work across all network types, datacenters, branch and campus, and ingest all different data types.

The ArchitectureArchitecturally, it has a simple construct. Data goes in from the devices into the CloudVision platform and comes out via APIs.

Under the hood, this is what it looks like. The devices have a database on board, SysDB, that holds all state. A streaming agent pushes it out of the box and into the CloudVision platform. The platform receives a timeseries of all state elements, which it stores, processes and analyzes via the CloudVision Analytics Engine, and dispatches out the insights to a user interface or client applications.

Madsen elaborated – “This (streaming agent) can be a standalone agent. Some of our largest cloud customers use this agent to ingest the data and analyze it themselves. This is also what powers CloudVision to get really fine-grained data, so everything’s timestamped at the point that it changes on the box, and then streamed out.”

The core component of Arista’s CloudVision is a robust data pipeline that connects directly to the user interface. This is layered on top with a set of applications. CloudVision performs analytic functions like calculating events, aggregating, and normalizing data and so on. A set of provisioning compliance apps makes sure that everything is running on right configuration, and that all software are up-to-date. CloudVision streams this data out through a variety of APIs.

“All this is happening really quickly, from the storage to it being processed, to being stored again, to being shown to the user – all that feels instantaneous from the end user’s perspective,” informed Madsen.

To learn more about CloudVision, and watch a deep-dive on the latest Arista Network Data Lake (NetDL), be sure to check out the Arista presentations from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Network Monitoring in Real Time with Arista CloudVision

View Details

As I recently wrote, edge computing is a technology that allows for processing and storage of data closer to its source. This can be beneficial for applications that require low latency, such as real-time video, retail, or industrial IoT or control, but there are some limits to what works at the edge. All of these will be part of the discussion during Edge Field Day next month.

Cost, Power, Security, and ScalabilityOne of the main things holding back deployment of edge computing is the novelty and cost of deploying and maintaining edge devices. Although individual devices are often inexpensive, the cost of deploying them at scale, covering many remote locations, can quickly add up. The cost of ongoing maintenance and updates must also be considered, along with the challenge of accessing them. And edge computing is still a novelty, requiring investment in training and architecture.

Edge computing devices also tend to be limited in terms of processing power and storage capacity. Although their capability is rapidly increasing, they may not be able to handle large amounts of data or perform complex computations in a reasonable envelope of cost and power. Still, they are likely good enough for basic tasks like image analysis, data filtering, and industrial control. And advances in GPU and xPU technology mean that the next wave of devices will be much more capable.

Another concern about edge computing revolves around security. Since edge devices are located outside the walls of the datacenter they are exposed to many environmental and human risks. Theft, sabotage, and infiltration are a real concern for devices in retail or industrial settings. They are also connected to networks that have different security profiles or might not be secure at all. Encryption, authentication, and tamper sensors are critical.

Additionally, edge computing poses a scalability risk. As the number of devices and the amount of data they generate increases, so does the difficulty of management and analysis. Data must be filtered locally to avoid flooding storage and compute capacity, network links, and centralized services. We have heard stories of 5G-connected edge devices using up their monthly allocation of data in just a day or two when not properly configured.

Stephen’s StanceAlthough edge computing has the potential to improve the performance and efficiency of distributed applications, it also has many limitations. The cost of deployment and maintenance, limited processing power and storage capacity, concerns about security, and the question of scalability all come into play. These are the topics we will be considering as we dive into edge computing at Edge Field Day in February!


© Gestalt IT, LLC for Gestalt IT: What Are the Limits of Edge Computing?

View Details

For most organizations and their workforces, hybrid work is business as usual. Every IT company by now has fallen in line with this new routine. But organizations’ journey to becoming 100% secure, cloud-based entities is nowhere near the finishing line. Remote work may have become a default overnight, but to this day, a majority of organizations struggle to adjust to this new reality because of the security risks it has unleashed.

Fortinet presented FortiSASE at last week’s Networking Field Day event in California. Rami Rammaha, Director of Products and Solutions, SD-WAN, gave an introduction of Fortinet’s Secure SD-WAN, and FortiSASE, and Alex Samonte made it visual with a demo in the following session. Fortinet SASE is a unified solution that converges SD-WAN connectivity with cloud-delivered security service edge (SSE) to protect against evolving cyberthreats and provide secure access to remote workers.

It’s Time to Rethink Our Security StanceWith remote work becoming commonplace, attacks have become inevitable. Enterprise technology leaders are making it a priority to proactively secure the network using a combination of strategies, amid growing cyber incidents. Secure Access Secure Edge (SASE), Zero Trust Network Access (ZTNA), mesh security, are some of the top approaches organizations are adopting to reduce vulnerabilities and bolster their security postures.

But the big question that’s in everybody’s mind is, does deploying all these technologies make them bulletproof? In the era of remote work, the borders that typically separate an organization and its people from the rest of the ecosystem have blurred. So just fencing the network is no longer adequate to prevent a breach. Identity-based security plays a big role in the hybrid era, but the component that comes before that, which enables implementation of security models like zero-trust, is SD-WAN.

Fortinet Secure SD-WANAs noted above, SD-WAN is the foundation upon which models like ZTNA and SASE sit. At the presentation, Rammaha talked briefly about the SD-WAN journey, from being a point solution designed to support user experience, to the platform it has proliferated into. Today, it is the convergence point of networking and security, that minimizes latency and jitters on one hand, and supports secure access for remote workers on the other. But we’ll see SD-WAN play a much bigger part in remote access security in the future.

“Today it (SD-WAN) is transforming and securing the network. Moving forward, we’re looking at SD-WAN being a critical component to SASE architecture, and enforcing ZTNA policy,” said Rammaha.

Rammaha pointed out that Fortinet Secure SD-WAN is backed up by four key components – SD-WAN that is the industry’s only ASIC-powered SD-WAN to use in-house ASICs, a built-in next-gen firewall (NGFW), advanced routing and a ZTNA application gateway. Powered by the common FortiOS, Fortinet Secure SD-WAN has a single fabric management center – the FortiManager – that enables centralized management of configs, policies and changes, and zero-touch provisioning.

Universal ZTNAZTNA is the go-to model for most organizations supporting hybrid work models. It’s an access control method that requires identification and authentication of every user and every device, and provides role-based access to applications.

Zero Trust Network Access (ZTNA) is where Fortinet shines. In his presentation, Rammaha explained that Fortinet offers remote users secure access to applications with two models- Universal ZTNA and Secure Private Access.

Every FortiGate NGFW has Universal ZTNA built into it. It is enabled by default in devices that have FortiOS v7.0 or higher. The work of Universal ZTNA is to authenticate every device and user, and perform a security posture check before access.

Rammaha explained that Universal ZTNA has a software agent, a policy engine, and the ZTNA Application Gateway which enforces the policies. Users accessing the applications from remote locations, branch offices and campus have to go through the ZTNA Application Gateway no matter where the application is. The gateway allows or denies access to resources based on identity. Access is allowed only through SSL encrypted connections.

Fortinet SASE SolutionFortiSASE is a single-vendor solution that combines the cloud-delivered connectivity of Secure SD-WAN with Fortinet’s SSE, bringing to remote employees secure access to the internet, and to private and SaaS applications. Using the capabilities of Firewall-as-a-Service (FWaaS), Secure Web Gateway (SWG), Universal ZTNA and next-gen CASB, it secures these accesses and offers the best of networking and security.

FortiSASE has a simple cloud-based management that enables centralized control of users and applications. FortiGuard AI-powered security services are enabled across devices, users, applications and traffic, to provide consistent protection from the newest strains of threats.

Wrapping UpFortinet’s approach provides a resilient model to monitor and access resources in an increasingly complex and distributed digital world. It packages together the best of Fortinet’s networking and security offerings, to provide multiple lines of defense and an optimal security posture, with a surprisingly simple cloud-based management. It’s a comprehensive package that ensures both the highest level of security, and superior user experience.

To catch a live demo of the Fortinet SASE solution, and for other deep-dive presentations, be sure to check out Fortinet’s presentations from their appearance at the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Integrated Networking and Cloud-Delivered Security with Fortinet

View Details

Converged solutions have been taking root in IT for several years now. When the side-effects of having numerous tools and solutions in the environment were first felt, a desire for a combined solution started to develop among organizations. The awareness that a robust paraphernalia presents unpredictable complications and sloughs away resilience, turned up the urgency to adopt all-in-one solutions that make life easy for everyone.

Last week’s Networking Field Day event saw Aryaka present their all-in-one networking and security as-a-service solution. Hugo Vliegen, Senior Vice President of Product Management gave an overview of Aryaka’s integrated services, and talked about the solution architecture. Senior Director of Product Management, Natraj Iyer and Director Engineering, Anu Chettur, took the floor to offer a closer look under the hood, and a demo of the customer portal.

Holistic SolutionsDespite being two separate disciplines, networking and security are intertwined. Most vendors in these spaces tend to stick to one or the other. An SD-WAN vendor would provide the SD-WAN overlay, and the connectivity and managed services would come from a Managed Service Provider (MSP). This standard multi-vendor approach has some gaps. Essentially, more tools means more training, more siloes and overall more work. Think of the onboarding of the solutions, then the integration work to make them function together synchronously. Information siloes and gaps are another worry. A lot can get lost easily in the mix.

Alternatively, having a converged solution that mashes up networking, security and managed services into one integrated solution has several upsides. Organizations can turn down the technology fatigue from get go. Things will likely be more streamlined than scattered, and employees don’t have to put up with getting used to new features routinely. And at the end of the day, the organization saves money. It’s a win for everybody.

Aryaka Bonds Networking with SecurityThis is why Aryaka’s offering stands out from the rest of the vendors. Aryaka is a managed service provider with an impressive customer service record. As an MSP, Aryaka wears many feathers in its hat. Three-times winner of Gartner “Voice of the Customer” award, Aryaka offers a converged network service that encompasses SD-WAN, SASE and full life cycle management.

“We are a converged WAN service with security embedded, and it’s developed from the ground up. We optimize everything from a customer experience point of view,” said Vliegen.

Aryaka provides a global network anchored in the cloud. Aryaka calls it a “private superhighway” that connects organizations to regions around the world.

According to Aryaka, there are three things where it gets most of the firepower from – its agile network, superior customer service, and an unconventional approach. As opposed to those of other vendors, Aryaka’s is a holistic solution that constitutes the overlay, underlay and a managed service.

“We have a single unified network that has a private core where we can connect in all the offices, the users, the various flavors of cloud, and datacenters,” he said.

Vliegen further explained, “We’re in control of the workflows. We collapse the work of the software developers, the technology players, together with delivering the service. But what it boils down to is that we deliver a better workflow. In terms of agility, all of it is built from the ground up and connected with our technology. There’s not an orchestration layer in between. We have the services and support organization as well.”

Aryaka’s offering of a unified network service is quite unique. But there are several other ways too in which Aryaka delivers value for its customers – cost benefits, secure remote access, network reliability and performance gains among other things.

The ArchitectureAryaka has a zero trust WAN architecture that is the secret to its secure and consistent app experience. Aryaka’s private core layer-2 infrastructure, or what Natraj Iyer called the “middle mile” spans the globe, and comprises of over 40 service points-of-presence (PoPs), strategically sprinkled across regions. These are compute, storage and networking infrastructures that Aryaka has built over the past decade.

Aryaka believes that because of their strategic positioning, there is a service PoP “within 15 to 30 milliseconds of 90% of the world’s knowledge workers”.

Aryaka envelopes the entire architecture with security, from the PoP infrastructure to on-premises, in devices. It also has WAN optimizer built into it.

“We’ve a single architecture where security can live anywhere. The functions can live on-prem, they can live in the PoP, and we can manage them using the same service delivery systems so that all the elements can come together.”

About three years back, Aryaka started working on the security aspect with the goal to build a zero-trust WAN. Today, it has multiple products in the security bucket, the first of which is secure web gate (SWG) for the Internet. Additionally, the portfolio includes cloud access security broker (CASB) and firewall as a service (FwaaS), data protection and threat protection.

Aryaka’s other object of focus is observability. Aryaka provides high visibility of performance-impacting elements in the network, and large amounts of actionable insights. Vliegen informed that Aryaka is working on tuning up the observability with advanced insights in the coming years. Aryaka’s fully managed service also has a co-managed option.

“We have always integrated the convergence factor with lifecycle services to bring this one single experience of delivery that is agile and on-demand. You can completely outsource it to us.”

Everything is manageable from a single control plane which keeps all teams up to speed, no silos whatsoever. The management console has a rich set of security controls baked into it which include URL filtering, content filter and malware blocking.

Wrapping UpAryaka makes a compelling solution for multi-national and mid-market organizations who favor unified, single-vendor solutions. For them, Aryaka provides a fast SD-WAN network with security woven into its architecture, and enables SASE for an optimal security posture. Aryaka’s customers can leverage the trifecta of overlay, underlay and managed services from a single vendor, and enjoy a breadth of capabilities that includes, but is not limited to integrated cloud connectivity, zero trust security, and remote access. Being a unified solution, Aryaka requires little to no integration which further makes lives of engineers easier. Last but not the least, a converged solution like Aryaka’s is a cost-effective alternative to multiple point solutions that require paying several bills for the same functions.

Be sure to check out Aryaka’s presentations from the recent Networking Field Day event to learn more about their unified SASE service.


© Gestalt IT, LLC for Gestalt IT: Aryaka – An All-in-One Solution for Networking and Security

View Details

As networks have grown bigger, operating them has become another worry. Operators in charge running the networks run into all sorts of performance and security issues, and those amount to a lot of problem-solving over the course of a workweek.

Last week at Networking Field Day event, Selector Software addressed this situation in their presentation. VP of Solutions, Debashis Mohanty, showcased the Selector AI platform in an introductory session. Mohanty explained the key capabilities of the solution, and walked the audience through some real-world deployed customer outcomes.

Living with ComplexityNetwork problems all seem to emerge from a common root – an obsolescent technique of operation. In the past, network operators had to navigate through a thicket of unorganized data to find issues to debug. These days, it only takes looking at dedicated data sources to spot an anomaly. There are a ton of monitoring tools in the market that bring this information up to the fingertips of operators.

But in a quite unexpected way, this opens a whole can of worms. Teams running the networks began reporting operational complexity of a never-before kind. With modern networks having far too many problems than those before, operators already spend big chunks of their workdays browsing through data – logs, config, events, metrics, alerts, what have you. Supplied by an array of disparate tools, these data are siloed like their sources. There are as many dashboards to look at as there are monitoring solutions deployed in the network.

But navigating through these disparate sets of data is only the morning mist. The real pain starts with the manual analysis and extrapolation.

“As soon as you get to the right dashboards, you have to write a structured query language or a SQL construct to get the data back, and the folks who are in the frontline trying to figure out what’s happening may not know the exact sequel language to get that insight. So, they go back and forth between these multitude of dashboards and try to figure out what’s happening.”

Once operators have passed that test, the information needs to be handed off to the teams to whom it may concern, and take it from there. This process from start to finish can take anywhere between days to weeks, and during an outage, every second wasted is dollar lost.

Selector Reimagines the Process with AISelector AI is an AI-based observability platform that provides actionable operational intelligence for multi-domain network infrastructures in real time. Using machine learning algorithms to automatically identify abnormal events and failures, and correlate them to the root causes with pre-built workflows, it reduces the Mean Time to Repair (MTTR). In doing so, it eliminates data silos, dial down the alert noise and overall reduces downtime.

“The three main pillars of our product are – collect, correlate and collaborate,” explained Mohanty.

Selector AI coalesces data from heterogenous sources over a variety of protocols. With an AI-based data analytics approach, it speedily performs the grunt work of studying the data and identifying the warning signs arriving at insights. Without wasting any time, it passes the insights on to the teams using collaboration channels like Slack and Microsoft Teams.

ML-Based Data AnalyticsSelector AI seeks to make the journey from data to insights short, swift and less cumbersome. To that end, it has a set of well-defined, realistic goals. The first goal is to provide answers to the roll of questions that engineers may have.

“Our primary focus when we built the product was to provide curated, contextual, effective answers when someone asks the questions.”

The data it ingests includes, but is not limited to metrics, configs, alerts, event logs, flows and tables. Using its robust data integration, Selector AI ingests data in all formats from pre-integrated sources, data lakes, and databases including Splunk, InfluxDB, GitHub and more.

“When we started the company in the middle of the pandemic, everyone was remote, and all company operations were happening remotely. So, we integrated with Slack and Microsoft Teams so that engineers can ask questions and get responses easily. Our bot is a part of these channels, and users can do the debugging collaboratively,” said Mohanty.

Automatic baselining with tons of metrics and KPIs makes it possible to monitor metrics behavior closely and send out alerts quickly with automatic alert notification.

So that operators don’t have to go through their day tackling an alert storm before getting to triage and troubleshooting, the platform ranks the alerts in order of priority. It alerts the teams with the most critical ones for the day, and everything else that is a category behind comes after that.

Selector AI stores the insights so that users can access them later if they need to.

“It’s like a DVR, you can go in the past, see what happened, what things are correlated, and go back and forth.”

Selector AI is vendor-agnostic and comes in a combination of deployment models including cloud, on-premises, hybrid infrastructures, and customer VPC. It is also delivered as a SaaS solution. With the exception of a few dashboards, it is fully managed by Selector.

Selector AI can be bought on a flexible monthly or annual subscription. For anybody interested, there is a free 30-day trial available on their website.

Wrapping UpSelector AI ends the struggle of IT teams managing the network by replacing the manual steps of searching, analyzing and communicating with built-in automation. It visibly improves the process by introducing functions like proactive anomaly detection, identification of actionable correlations, prioritization of alerts, among others. When teams don’t have to spend a bulk of their time looking at data across a plethora of dashboards scattered across the screen, and insights are ready-to-use, it leads to faster and better decision-making. With Selector AI dialing down the complexity that hinders organizational success, teams can take actions and resolve outages much faster, leaving customers happy.

Be sure to watch the Selector AI deep-dive presentation from the recent Networking Field Day event on the Tech Field Day website.


© Gestalt IT, LLC for Gestalt IT: ML-Driven Monitoring with Selector AI

View Details

Our next Cloud Field Day Event is January 25, 2023! Tune in live on Tech Field Day’s website or LinkedIn starting at 8:00 AM Pacific Time on Wednesday. Here is a quick overview of what to look forward to from this event.

Cloud Field Day is our opportunity to look at the next generation of enterprise IT, from the datacenter to the public cloud, up and down the stack. Every Cloud Field Day event shows the many ways that cloud technology is impacting enterprise IT, and that’s certainly the case in January.

We’d like to give a special thanks to Forward Networks who is hosting us at their offices all day long, who will also be our first presentation of the day at 8 AM Pacific time. Forward Networks is presenting use cases for network digital twins in a cloud environment, bringing security, network ops, and cloud ops together as cloud sec ops. Next we’ll hear from Fortinet at 10 AM. The Fortigate cloud native firewall team will demonstrate attacks on a Fortigate firewall in an AWS environment with email and serverless applications. We’ll finish up with Solo.io at 2:30 PM. Solo.io is demonstrating the future of service mesh with cloud native 2.0 application networking.

All of our sessions are broadcast live on TechFieldDay.com and on the Tech Field Day LinkedIn page. These presentations will also be recorded and shared on the Tech Field Day YouTube channel soon after the event. We welcome you to follow along on Twitter using the #CFD16.

Thank you for joining Cloud Field Day live on January 25. While you’re on our website, join our mailing list to learn about upcoming events, see past presentations, and more.


© Gestalt IT, LLC for Gestalt IT: Cloud Field Day Looks to the Next Generation in January

View Details

It’s already a new year and we’re kicking it off in style with another edition of Networking Field Day! The flagship networking event returns for more great discussion and learning in Silicon Valley January 18-20. You’re not going to want to miss a minute of the great conversations.

Networking Field Day Presentation ScheduleWe start the event on Wednesday, January 18 with our first presentation from Anuta Networks. They are excited to give the delegates an update on their technology and discuss how they’ve been deploying it to a wide range of customers. The next presenter is Juniper Networks who is returning once again to discuss the advances they have made in data center networking and beyond. There’s sure to be some excitement! The final presenter of the first day is Aryaka who will be joining Networking Field Day for the first time. They’re a big player in the managed SD-WAN and SASE space and our audience is excited to hear all about it!

Thursday, January 19 kicks off with a presentation from Cisco. They’ll be bringing in a lot of great technology and demos to show off what their customers have been asking them for in the past few months. Afterwards we’ll get an update from Arista and what’s hot in the market for data centers and cloud networking. The Arista team always brings some great discussion to the event so make sure you tune in to see it. We will wrap up Thursday with a special delegate panel talking about the Future of Networking in 2023. This interactive conversation is one of the highlights for our Tech Field Day audience so make sure you ask lots of questions for the delegates to debate.

Friday January 20 opens with our friends at Fortinet who will be talking all about SD-WAN and fabrics and how the two can combine with other great technologies to build a comprehensive solution. The final presenter for the event will be a brand new company, Selector AI. They’ve got an exciting analytics and observability that you’re definitely going to want to see in action!

Follow Along with Field DayNetworking Field Day 30 will take place live January 18-20, 2023. You can follow along on our website at TechFieldDay.com as well as the Networking Field Day 30 event page. For those that want to watch on LinkedIn make sure you check out the Tech Field Day LinkedIn page during the event as well. After the broadcast you can catch the recordings on-demand at the Tech Field Day YouTube channel. If you want to participate live in the conversation don’t forget to follow Tech Field Day on Twitter and use the hashtag #NFD30. We can’t wait to hear from you!


© Gestalt IT, LLC for Gestalt IT: Networking Into The Future with Networking Field Day 30

View Details

As networks got bigger and their estates sprawled, monitoring everything became a task bigger than one team. With the goal to achieve a fuller visibility pushed back, engineers are now faced with elevated risks of network downtime.

At the recent Networking Field Day event, Progress presented WhatsUp Gold, an easy-to-use monitoring solution that observes everything proactively in the network and keeps operators up-to-date with network performance and availability, making complete observability a distinct possibility.

Monitoring a Large Network Is an Uphill BattleThe top responsibility of a network operator is to avert network downtime and crashes. The success of that is predicated on how clear the visibility is. Real-time network visibility and rigorous monitoring have a hand-in-glove relation. The stronger the visibility, the better the monitoring.

With the expansion of networks, network monitoring as a task has amplified in size and intricacies. It involves watching countless devices, applications and systems, and the traffic moving across the network 24/7. In order to monitor network performance, operators must establish baseline performances so that dips and deviations can be caught in real-time.

In a large-scale network, operators’ tasks entail comprehending complex network diagrams and drilling down into multitudes of details in the data generated constantly in the network. Additionally, they need to plan capacity, act to alerts and routinely spot and eliminate blind spots.

The fact that the network is now distributed only introduces more complexity into the picture. Juggling tens of responsibilities is frustrating as it is, but in the long run, it also slackens productivity. This reflects in the revenue, eventually causing organizations to fall behind on their goals.

An All-in-One Monitoring SolutionAt the presentation, Mark Towler, Sr Product Marketing Manager at Progress introduced WhatsUp Gold to the audience as “an award-winning network monitoring and network infrastructure monitoring solution that provides information about the network and its performance at a glance.”

As a solution, WhatsUp Gold is not brand new. It has been around many years, but Progress has kept up with refreshing and enhancing its discovery and monitoring capabilities year on year, packing more power with every new iteration.

Progress took a clean shot at simplifying network monitoring with WhatsUp Gold. The solution focuses on proactive diagnostics and troubleshooting with the goal to prevent issues from impacting the network in any significant way.

Progress seems to have one eye set on making the job of network engineers easy. It designed WhatsUp Gold to visualize the network in a clean and easy-to-read diagram that engineers can glean information from with just a once-over.

But what’s up with the name? It may not click at once, but Progress’ naming of the solution is pretty spot-on. WhatsUp Gold was designed to tell network operators what’s up in the network – more precisely, what is up and what is down. Hence the name WhatsUp Gold.

Progress WhatsUp GoldThe Networking Field Day presentations were delivered by Towler, Jason Alberino, Sr Product Manager and Mark Singh, Sr Sales Engineer. At the session, Towler and Alberino elaborated on the capabilities of WhatsUp Gold, while Singh gave a hands-on demo in a later presentation.

WhatsUp Gold is a browser-based solution that requires operators to log in to access the interface. The initial view as you log in is of a network diagram that shows at a glance what things are running fine and what things are not.

The map visualizes the statuses simplistically so that operators can read the reports and stats at a quick glance – no need to read through a barrage of information. Every view opens as an individual webpage which allows the information to be broken down into simpler and nuanced views.

“The “My Network” tab gives you a quick glimpse into the status of your devices. Anything that is green is up; anything that is red is down. Anything with a red dot simply means that there’s something that is being monitored on the device,” explained Mark Singh, Sr Sales Engineer, during the demo.

WhatsUp Gold is an agentless software that takes literally minutes to set up. Post-download, the product installs and configures on auto-pilot, finding the network instantly with automatic discovery and mapping. It takes less than half an hour for it to be up and running. WhatsUp Gold can monitor over all standard industry protocols.

Advanced monitoring capabilities include NetFlow traffic, virtual infrastructure, wireless and cloud networks. Configuration management allows users to track and manage changes in configurations. A newly introduced feature is integrated log management which enables teams to “track and find log information quickly and easily.”

Towler notes, “The value WhatsUp gold provides is that it gives information in context. You can plug anything into your network, WhatsUp Gold will find it, talk to it, get information and give it back to the administrators.”

WhatsUp Gold is vendor-agnostic, meaning it can discover and communicate with any device or system in the network.

WhatsUp Gold has a device-based licensing which gets users more monitoring coverage for less. Simple pay-per-device model allows users to choose the devices they want to manage and pay by number.

Wrapping UpIn network monitoring, Progress WhatsUp Gold needs no introduction. It’s been around a long time and is one of the established monitoring tools in the market, and certainly one of Progress’ best. WhatsUp Gold makes a compelling product simply by the iterations it has to its name, but for new users, it presents a wealth of strong and intuitive discovery and monitoring capabilities that hit the bull’s eye clean. It is an all-in-one solution, in that it resolves poor visibility by monitoring the full inventory, and delivers non-stop monitoring of all assets, but without storming the operators with a ridiculous amount of alerts. WhatsUp Gold makes the network a safer place, and anybone who cares should invest in such a solution.

For more information on WhatsUp Gold, be sure to check out Progress’ more presentations of it from the recent Networking Field Day event.


© Gestalt IT, LLC for Gestalt IT: Network Monitoring Made Easy with Progress WhatsUp Gold

View Details

The mass shift to cloud has brought with it some heavyweight challenges at the top of which is security. Research indicates that a significant majority of security breaches happening in the cloud are results of leaked secrets. So how can we better manage the secrets in our ecosystem? The answer, once again, is zero-trust security.

At the recent Security Field Day event, HashiCorp presented a couple of their zero-trust security solutions that leverage identity-based security to protect sets of sensitive information from becoming targets of insidious attackers. Among the solutions HashiCorp presented was Vault – a comprehensive secrets manager whose primary function is to encrypt and deliver secrets safely to machines and services.

Poor HabitsModern digital enterprises own a rich diversity of assets running in disparate environments. These distributed resources have one thing in common. They all contain sensitive data, and therefore are under some kind of lock and key. Access to these assets is guarded by certain forms of privileged credentials, aka secrets, that give humans and machines permission to access.

The prolific number of assets and the fast-evolving strains of threats have made it imperative that different types of secrets are used in varying contexts to ensure high levels of security. As a result, any digital authentication credential is a secret, examples – usernames and passwords, tokens and certificates.

High-tech environments are teeming with these secrets and the current attitude around secrets management is negligent. When secrets start to sprawl, they wind up everywhere unencrypted. And without visibility or auditability, they are vulnerable, and therefore portals to the inside. And just like that, what was designed to be the lifeblood of modern infrastructures becomes the cudgel.

Taking ControlFirst things first, companies need strong secrets policies and best practices to keep the sprawl under control. So that from being peace of mind, secrets do not become a source of stress, every last one of them needs to be tacked down and stored in a safe location. The policies should put a stop to sharing secrets between employees and storing them anywhere but the store.

But implementing a consistent policy across the board is not an easy thing. In a situation where every application, every infrastructure has its own cyber model, what companies need is a centralized way to manage secrets, intelligently and automatically, which is more than any policy can achieve.

As noted earlier, Vault by HashiCorp is a secrets management platform that serves as a safe store for secrets and sensitive credentials. At its foundation, Vault has HashiCorp’s zero-trust policy of authentication and authorization. With a surprisingly simple architecture, HashiCorp has managed to fashion an intelligent solution with Vault. Rather than leaving it to employees to manage their secrets, Vault manages their secrets for them.

Nicknamed “identity broker”, presenter Rob Barnes explains that Vault “brokers identity on behalf of your target platforms, be it cloud or a database.” More on that ahead.

The big difference is that Vault is a complete solution that eliminates the need for other similar solutions. It offers encryption as-a-service that people use separate cryptographic solutions for, to manage keys and credentials. So when using Vault, those types of solutions can be averted.

Vault by HashiCorpBarnes, Sr Developer Advocate at HashiCorp gave a deep-dive presentation of Vault at the recent Security Field Day event. He kicked off the session by talking about the key functions. Later in the session, he gave a demo of the solution.

In Barnes’ words, “Vault is a number of different things depending on how you use it.”

Vault operates in two stages- authentication and secrets generation. Authentication on Vault happens via “Auth Methods”. Users can control how they want to authenticate their applications to Vault by picking from the long list of Auth Methods available in Vault.

“You can configure any of the supported options, so that instead of storing the identities on Vault itself, you can keep them managed in that central place, ie., your identity provider, and we can log into those servers and verify the identities of people or machines that are trying to authenticate,” explained Barnes.

In the second stage, Vault generates the credentials. This is the function of a secret engine, and Vault has multiple flavors to support different cloud platforms and databases.

Barnes summed up the process with a simplistic diagram which showed how the action happens. In the first step, applications are authenticated to Vault via the chosen authentication methods. In the next step, Vault brokers a username and password on behalf of the target platform, cloud or database, for its profile API. Vault then returns this credential to the API.

Every credential created has a lifecycle, at the end of which it is wiped out. This ensures that there are not an unmanageable number of secrets in the environment, and that they are not reused by any chance. Administrators can set the credentials’ TTL (Time to Live) from a few minutes up to several days.

While Vault requires returning applications to authenticate at the gate each time, it lends users the flexibility to use the Vault agent which offers a quicker access. Using the Vault agent to authenticate once, they can save the credentials generated in a safe location of their choosing, so that each time the application needs to be connected, it can be automatically authenticated in a quick and reliable fashion.

Vault is currently set up on the HashiCorp Cloud Platform where it is delivered as a fully managed service. The only thing customers are responsible for is the early configuration and administration based on the internal access management protocols.

Wrapping UpManagement of secrets shouldn’t fall entirely on the employees. A big part of it is the company’s responsibility. HashiCorp’s Vault shows how something that is so seemingly complex and tedious can also be done in a smart and easy way. It serves the twin purpose of dynamically generating and safely storing secrets, whilst managing them automatically, relieving users of the burden. Companies should deploy Vault in their ecosystems to not only protect infrastructure secrets but also to ensure an overall improved security culture inside the organization.

For more information on Vault, check out the second part of the presentation and other demos by HashiCorp from the recent Security Field Day event.


© Gestalt IT, LLC for Gestalt IT: Preventing a Secret Sprawl with HashiCorp’s Vault

View Details

Enterprises are competing with each other over tightening supply of cybersecurity skills. The shortage has intensified over the past few years and is now tantamount to 3.5 million unfulfilled positions. Needless to say, hiring is a challenge in this climate. But fortunately, there’s automation to bring closure to the widening talent gap.

In November’s Security Field Day event, security automation was one of the top topics, and Swimlane dominated the conversation with a series of presentations focused on automation. In one of the sessions, they presented their five-level SecOps Automation Maturity Model that is designed to eliminate dependency on skilled workers, and harness the full power of automation.

The Struggle to Woo Qualified TalentThe threat landscape has assumed a dire form in a very short time pressing it upon organizations to reinforce their infrastructures. Wary of the spike in malicious cyber activities, companies turn to the labor market in hopes of finding qualified professionals to expand the workforce, only to find that skills are in short supply.

The only way to overcome the talent gap is to load up on security tools. But contrary to expectations, overloading the arsenal produces very opposite results. Brimming with swanky tools and solutions, companies now have a new problem. Too many tools create an alert storm obfuscating key indicators and obstructing timely responses. So, on top of being short-staffed, they now have SecOps teams that are beleaguered and burnt-out. This has translated to higher employee turnover rates bringing enterprises back to where they began.

Averting the CrisisHaving witnessed the crisis unfold from inside the industry, Swimlane is motivated to forge a solution that’d put an end to the longstanding struggle. Knowing that in cybersecurity, devil is in the data, Swimlane sets out to build a system of record that, for one, gives organizations assimilated intelligence in a central location, and for another, helps identify what’s happening in their environment and what they need to do through various stages of automation.

Swimlane’s is a “low-code” automation platform that provides a full system of record. Fully extensible, it comes with an easy-to-use workflow builder for automating responses. Cody Cornell, Co-Founder & Chief Strategy Officer points out the three building blocks of the platform – automation, integration and visualization.

Cornell says, “A lot of the folks talk about low code but it’s usually a playbook builder or a dag (Directed Acyclic Graphs) that people are going to build from a workflow perspective on how they actually are going to automate. But our low code component actually moves into the user experience as well.”

The platform has a scalable integration fabric that features hundreds of pre-built integrations which takes the pressure off the developers. “It’s tied into hundreds and hundreds of security and non-security integrations that are in our marketplace,” informs Cornell.

Swimlane features landing page for different personas working in organizations to help knock down the silos between departments.

Swimlane’s Security Automation Maturity ModelAt the recent Security Field Day event, presenters Cody Cornell, and Bryon Page, Director of Solutions Architecture at Swimlane, gave a closer look at the Swimlane SecOps Automation Maturity Model and wrapped it up with a demo of Swimlane.

The SecOps Automation Maturity Model is a newly introduced framework that is built to help organizations “understand what they need to do to mature an operations program”. Up close, the model reveals five stages or levels, namely – Foundational Visibility, Enriched Visibility, Automated Response, Automated Prevention and Expanded SecOps Automation.

Focused on security automation, the model is aligned to popular security frameworks like NIST, D3FEND, ATT&CK and C2M2, and industry best practices. Swimlane breaks down the metrics into four broad categories – Case Management, Enrichment and Mapping, Response and Improvement to help organizations evaluate their security posture and locate where they are in the spectrum.

To make the model quantifiable, Swimlane has a set of objectives and goals for each program. For example, for Level 1 which is Foundational Visibility, the overall goal is to assimilate all of the intelligence into alerts and churn out maximum insights out of the data.

As part of alert management, this stage helps determine what measurements and metrics should an organization be looking at and understand how to enrich the data that decisions could be based upon, or used to automate a response in the later stages. A feedback loop provides information to reduce false negatives and enrich the investigation cycle. Since the first two stages are prelude to the automation stage, in preparation, the metrics at this level help sort out the alerts that can be potentially automated.

Cornell elaborated that the five programs and their parameters are all purposed to figure out “what the maturity is typically along these metrics and then map it to all the other frameworks that are out there that enterprises are leveraging.”

Wrapping UpReducing cybersecurity headcount without sacrificing the quality of protection is a balancing act companies are yet to master. Security automation surely presents a solution, but it is still in its early days. With a nuanced security maturity framework like Swimlane’s, the mission to stay compliant and protected from bad behavior through automated security is much closer to enterprises. It shows what security automation can look like if done right, and the way to do it.

For more information on Swimlane’s SecOps Automation Maturity Model, be sure to check out other presentations by Swimlane at the recent Security Field Day event.


© Gestalt IT, LLC for Gestalt IT: The Road to SecOps Automation with Swimlane

View Details

The subscription model is one of the hottest trends around. What began with meal-kit businesses and fitness training centers has fast assumed the scale of an economy with its adoption by bigger industries. The newest party to join the as-a-service revolution are the big guns in automobile. With the intention to dynamize revenue, certain manufacturers are now offering in-cabin features as-a-service for the very first time.

In these times of connected products and services, ensuring trust along the path from a secure device to a deployed service takes more than just buying the best solutions or hiring the brightest minds. Cybersecurity in the era of connected IoT devices is more complex than that.

Micron took a shot at demystifying IoT security. At the recent Security Field Day event in California, Micron presented the Authenta Platform. Labeled the “Silicon-to-cloud trust platform”, Authenta delivers high levels of protection to IoT devices by securing the lowest layers of device software. Micron’s vision with it? Affordable and pervasive protection for all IoT solutions that uses silicon.

Securing IoT in the Subscription EraAs the subscription trend takes hold, a lot of businesses transition from straightforward manufacturers to subscription-based businesses. Over the past few years, a host of smart IoT solutions has emerged to bring to life this everything-as-a-service revolution.

But digital evolution is a double-edged sword. From one perspective it has made IoT solutions smarter, more powerful than was believed possible in such a short amount of time. But from another perspective, it has caused devices and services to deploy into new and unknown environments, posing high levels of security risks to the integrity of these solutions.

Connected devices and services are at a higher risk of compromise as they pass through a diverse supply chain before launching into an ecosystem that is open, fragmented and vulnerable. At any stage of this journey, a bad actor can implant a malware and compromise a device in a heartbeat. OEMs are constantly battling with these looming threats, all the while searching for ways to seal systems end to end from manufacturing through all of the product life.

A Logical Course of ActionLooking at the big picture of cybersecurity, Micron sees IoT security becoming more and more critical in the coming days. Already a leader in the flash memory space, Micron uses its cognizance with silicon to iron out the kinks in modern cybersecurity with a simplistic and logical approach – protection at the roots to the ends.

Led by the vision of a secure foundation for IoT, Micron built a silicon-based security-as-a-service solution – the Authenta platform. Authenta embeds security at three levels – hardware, integrations and delivery ensuring health and integrity of IoT systems from the factory through the to the end of the product life.

Authenta builds security from the ground up with the hardware root of trust that enables silicon-based security activation and control. Further up, it enables manufacturers to securely hand over the flash control to third parties. In the final steps, it provides secure, zero-touch onboarding to cloud. With the Authenta Key Management Service, users can manage and secure deployed services throughout their lifecycle. That’s all the bases covered.

A Closer Look at the Authenta PlatformMicron showcased the Authenta platform at the recent Security Field Day event. Luis Ancajas, Director of Authenta Product Line at Micron, outlined the drivers and gave an overview of the solution. In a later customer blueprint presentation, TrustiPhi explained Authenta’s capabilities and discussed its use cases.

Micron Authenta is a triple-tiered platform that has security woven into its fabric. At the base, Authenta enables always-on security directly in the silicon thus establishing trust in provenance and preventing attempts of tamper at the silicon level. With a combination of device-specific identity and in-memory secure boot, it ensures that devices are authenticated with the host irrespective of the run-time environment.

Authenta is a zero-component solution that requires no additional hardware component. Its security features are built natively into the flash memory. The Authenta-activated memory deploys in the standard sockets and is compatible with a variety of endpoints. Hardware root of trust provides enhance system-level protection while bringing down the cost of engineering.

But where standard hardware security systems save keys and credentials in the hardware itself, Authenta saves them in the cloud. Through a cloud-based Key Management Service (KMS), Authenta saves all secrets securely in cloud keeping them accessible for management throughout the product lifecycle. A trusted partner can avail this feature to validate that they’ve received the product in its mint state.

Above the Authenta root of trust is a suite of integration tools “that can be used to bridge the gap between early manufacturing and deployment, and through the life cycle of the platform,” explained Ari Singer, CTO of TrustiPhi in his presentation. The integration suite allows users to activate security, control endpoints, and configure and personalize. But most importantly, it enables OEMs to transfer keys and certificates via a separate chain which makes a quiet supply chain attack a lot less likely.

The third piece of it, Authenta Cloud, is the delivery of the product or service in a secure cloud ecosystem. “ Our cloud has the ability to send keys and credentials, platform identities, services so that it helps in the facilitation of all of the systems going out into the field,” explained Ancajas.

Wrapping UpMicron’s Authenta makes a compelling Zero Trust IoT security platform. With intelligent implementation of security technologies, it provides protection at silicon level, and through the supply chain from manufacturing to ownership transfers to deployment. Micron’s vision with it was to build a solution that preserves and proves the integrity of the IoT systems at delivery and Authenta does more than that. It gives users the peace of mind that the items they are deploying in their environments are not corrupt or compromised on the way to them, but also gives OEMs the ability to protect their products from malicious supply chain attacks, thus ultimately empowering the subscription business.

For more information on the Authenta platform, be sure to check out Micron’s other presentations on it from the recent Security Field Day event.


© Gestalt IT, LLC for Gestalt IT: Securing IoT Devices Silicon to Cloud with Micron’s Authenta

View Details

Some of the biggest discussions happening in IT right now is around data. Data is generating in a ceaseless flow as infrastructures evolve and scale. As growing masses of data start to fill up the available spaces in storage systems, it brings to fore the matter of searchability of datasets. In the big data world, there are only two ways to go – leverage data by extracting value out of it – for which strong searchability is paramount – or sink under the weight of it.

At the recent Security Field Day event, Cribl addressed this issue that is echoing in IT with organizations amassing data in unforeseen amounts. At the event, Cribl introduced the new Cribl Search – a function that makes it possible to mine petabytes of observability data at the edge.

Data Has Strings AttachedGiven the current state of things, we all can agree on one thing – we have far too much data than we can comfortably handle. New challenges start to emerge as the data balloon continues to grow bigger. The first of them is cost. Organizations are constantly wrestling with the appalling costs of storing data in the cloud.

Even though only a small fraction of the data produced is actually preserved, the problem of having to move data closer every time teams want to query datasets shoots the cost through the roof. Nick Heudecker, Sr Director of Marketing Strategy at Cribl notes, “Even if that data is not valuable, you are paying for every byte you are bringing in from each of your data sources.”

Appended to the problem of excess data is the searchability factor. Without a strong and optimized query function, annotating vast datasets is like going looking for Waldo.

Querying Data at EndpointsCribl takes aim at “the old problem of having to move everything that you want to search before you can actually do anything with it” with Cribl Search. The chief driver for Cribl Search was to find an easier and less expensive way to access data without companies footing huge bills for relocating datasets they need to query. The alternate is not knowing where anything is, and lose value trapped in the data.

Cribl Search was launched in November and is currently available to all users on Cribl Cloud. Cribl Search lets organizations search data easily without having to change their locations. To do that, Cribl Search upends the standard agent model and uncovers a new possibility.

Instead of hauling data back to cloud, Cribl Search lets users search data at the edge before it is moved closer for analysis as opposed to the standard practice of moving before querying. This mitigates the cost problem which encumbers a lot of companies that do not have the wherewithal to move large volumes of data from edge to cloud.

The second set of customers that it is designed for are companies that have data everywhere and could use a global search capability that is compatible with data in different formats and lets them search natively inside their buckets.

The New Cribl Search on Cribl CloudAt the Security Field Day event, Cribl showcased Cribl Search. In a short presentation, Heudecker gave a quick overview of what Cribl seeks to resolve with its new search product and how it does what it does. The presentation was followed by a longer demo that showed off Cribl Search in action.

Cribl Search allows data to be queried at rest, before they are repatriated for closer analysis. With its kind of integration, engineers can query whatever data they want in the observability pipeline, no matter the format. That data could be at the source host, in the data lake, or moving through the pipeline or at the destination. Users can customize it with alerting features to make the search results more pinpointed.

This robust compatibility has been possible because Cribl Search uses Kusto, an open-source query language from Microsoft. Heudecker explained, “You can use this language across each of the destinations whether it’s data at the edge, data flowing through the stream, or data at rest.” This makes it possible to query multiple formats of data.

Cribl Search comes with a central GUI that is loaded with information and capabilities. Cribl customers may already be partly familiar with the interface, but the new UI offers changes beyond cosmetic. The interface is boosted with more options to customize and history capabilities among other things. One of the things Heudecker highlighted during the presentation is its ability to lets users query data in motion as it moves through the Cribl stream.

Cribl Search is system-agnostic and easy to deploy as it is to use. It can federate query to any location, and Cribl will be adding more federated search capabilities to it going forward.

Wrapping UpWith fresh loads of valuable data delivered every day, organizations are competing against the clock to gain value out of it all. Cribl Search benefits by cutting down people hours and costs. Being native to Cribl Cloud, it eliminates the need to use proprietary search tools or hire skilled people to operate those tools. Additionally, by letting administrators query data first, it enables users to move data to cloud more selectively making sure that only data that yields the most value lives in cloud while the not-so-important ones stay at the edge.

Check out the Cribl Search demonstration and other such presentations by Cribl from the recent Security Field Day event.


© Gestalt IT, LLC for Gestalt IT: Querying Observability Data at Edge with Cribl Search

View Details

Most modern cyber-attacks follow a unique pattern – a pattern that repeats itself over and over in every case. It starts with a recon exercise during which an attacker scopes out the exploitable soft spots in the network from the outside. Using one such vulnerability, they get in, arm themselves, transfer the payload, and slowly but surely compromise the target. The key to neutralize an attack? Disrupt the kill chain as early as possible. But what is infinitely less messy and less costly is to block the attack before the sequence starts to form.

At the recent Security Field Day event in Silicon Valley, Fortinet presented FortiRecon, a recently released solution that is designed to help organizations obstruct threat actors at the pre-attack stage, and in case they’re already inside, break the attack sequence early in the cycle.

Mixed BlessingThe network is elastically expanding in all directions, so more things can fit in – more assets, more data, more users. But at the same time, the relentless expansion has caused the boundaries to dissolve and the perimeter to blur. Populated with a growing list of public-facing assets, and with an undefended perimeter, the attack surface is supremely complicated, and exceedingly hard to manage or secure. So, how do we put the genie back in the bottle?

One way to secure the perimeter would be to understand the kill chain – follow the breadcrumbs, identify the moving parts and nip it in the bud before it wreaks network-wide havoc.

Organizations have spent insane amounts of time and money forensically reverse-engineering cyber-attacks to trace the steps and understand the methods of attackers. But that is after the attack has been orchestrated and damages have been sustained. Another way is to review the organizational risk profile from time to time and do what it takes to reduce the risk itself so that the network doesn’t have wide open blind spots for attackers to sneak through.

A Vision Ahead of Its TimeOperating at the intersection of network and security, Fortinet has a sophisticated understanding of the current-day threat landscape. Through years of research and engineering, Fortinet immersed itself in dissecting the anatomy of cyberattacks. And now in the wake of growing cyber breaches, Fortinet puts its learning to work to design practical and intelligent solutions that can block an attack.

Built over the two decades that Fortinet’s been in business, its portfolio is a sprawling list of products and solutions. Its ever-evolving security products deliver a solid defense to any digital environment. Fortinet enjoys patronage of customers around the world and to this day, has shipped out over 9 million firewalls.

The founders of Fortinet saw the fields of network and security converging long before it happened. So, they focused on building security solutions that fortify the the network as it grows and changes.

“Our vision for the company is to be able to put all of these products together into what we term as security fabric, and security fabric to us is a way to make all our products interoperate,” says Carl Windsor, SVP Product Technology & Solutions.

With that objective in sight, Fortinet brought to life a range of technologies whose primary mission is to make sure that the network does not look like an open invitation to nefarious actors. Under the hood, Fortinet has a product for each stage of the kill chain that can potentially check the infection in its tracks.

All of Fortinet’s security products revolve around FortiGuard Threat Intelligence, the information core of the Fortinet Security Fabric. Fortinet’s team of researchers incessantly feed this system with information on the latest strains of threats and vulnerabilities. The Threat Intelligence shares this information across the board, updating the products and solutions in its orbit with the latest intelligence.

Fortinet’s Latest DRP Offering – FortiReconAt the recent Security Field Day event, Fortinet showcased FortiRecon which was announced June of this year. At the presentation, Carl Windsor gave a high-level overview of the cyber kill chain and demonstrated how organizations can detect, prevent and respond to attacks using FortiRecon.

“The idea behind FortiRecon is to give customers and users the ability to see what threat actors are seeing about their organizations.” Simply put, FortiRecon lets you step into the shoes of an attacker and view the open doors in your network through their lens.

According to Windsor, FortiRecon’s “early intelligence” or “early warnings” can help organizations dynamically locate the weak points that entities outside the perimeter can see when looking at the network.

FortiRecon helps tackle an attack in two ways – by helping to “understand the organizations’ risk profile” and to respond to the attack swiftly.

FortiRecon is a Digital Risk Protection (DRP) service, the only solution out there to perform the three functions of External Attack Surface Management, Brand Protection and Adversary Centric Intelligence.

Windsor clarifies that FortiRecon is not a vulnerability assessment tool, but a monitoring solution whose function is to discover new devices, check for security issues and identify changes. It automatically discovers sundry network assets including cloud resources and devices. Upon discovery, FortiRecon scans each asset for security issues like vulnerabilities, exposed services and misconfigurations.

Windsor explained that FortiRecon identifies every vulnerability on the external attack surface that can be viewed by a third party. This includes the big holes like ransomware, configuration errors, unprotected secrets and assets, leaked credentials, but also smaller chinks like fake social media accounts and suspicious mobile apps.

Based on the findings, it curates recommendations and sends them out to the administrators. But instead of blindly firing alerts , FortiRecon intelligently prioritizes them according to risk level before dispatching them so that administrators have a hierarchy to follow.

FortiRecon also provides protection going outside the immediate attack surface. The Brand Protection component covers a wide range of activities pertaining to brands that are happening out on the Internet. It monitors leaked credentials, typosquatting, rogue applications, social media discussions and phishing campaigns. The endgoal of including brand protection in the capabilities of a monitoring solution is to preserve customer loyalty and brand image.

The last piece that Windsor sheds light on is the Adversary Centric Intelligence which is intelligence coalesced from all over the attack surface and formatted to be digestible and actionable.

Wrapping UpThe network with its exploding amount of assets and technologies presents tremendous opportunities for threat actors. Armed with sophisticated weapons and the right tactics, any nefarious actor can sneak in through a blind spot and abuse the system. In this reality, FortiRecon is an indispensable item to have in the security tool kit. It not only makes it possible to block a breach or tightly check its impacts through early detection, but it really addresses the core issue of understanding the organizational risk profile. The custom intel it provides is critical to gauzing the risks and doing away with the vulnerabilities that reveal themselves to an attacker at an pre-attack stage, and finally improving cyber hygiene.

To see FortiRecon in action, watch the demo at the end of the presentation. Watch Fortinet’s other presentations from November’s Security Field Day event for demos of more recently released security products from the house of Fortinet.


© Gestalt IT, LLC for Gestalt IT: Breaking the Cyber Kill Chain with Fortinet

View Details

As computer systems, computer networks, and the data within, continue to grow, engineers fear that the blast radius of even a single component failure can have intense ramifications. Often, the bigger components powering the datacenters are the biggest risks, but the smaller component failures too can potentially be the cudgel, now that everything is twice its size.

In this Delegate Roundtable – Managing the Blast Radius as System Components Get Bigger – recorded in Santa Clara, California at the recent Storage Field Day event, Stephen Foskett and the attending panel of delegates sat down to dissect this premise, and brainstorm ways to limit the scope of impact.

Wide-Spread ConsequencesWhile on one hand, computer processes have shrunken in size, and form factors have lost dimensions, on the other hand, CPUs have gained more cores and we have some of the largest networks in the history. And data inflation – that has been the most staggering of all. The growing size and scale of things thickens the impacts of outages and failures, causing a growing anxiety around the blast radius of such events. Case in point, the epic Amazon outages.

These outages have had multiple causes, but they all had wide-spread impact. In the light of the succession of recent events, it is clear that major outages are hugely disruptive, not just for the immediate businesses that sustain them, but customer businesses and individuals. What is a matter of a few websites going down for a few couple hours translates to thousands of users being cut off from big parts of the internet, not to mention the dire effects on industries like the stock market, banking or healthcare.

And the nightmare doesn’t stop there. A few hours off of the internet would have been a small price to pay, but the impact of an outage frequently tends to cascade from one service to other – affecting innumerable far-removed services – causing widespread problems. This results in more than momentary chaos or unhappy customers – it costs big businesses billions of dollars in losses.

Through a Different LensEnrico Signoretti opines that the problem is a bit different than how it is perceived. As data grows exponentially in volume, in support of that, storage system capacity has gone up to avoid bottlenecks. But that is unrelated to the blast radius. Engineers have always had to worry about the blast radius, even when things weren’t at this scale. According to him, the bigger concern is how fast can something be rebuilt if it’s broken. Given the growing service level expectations, the least time it takes to get things back up, the fewer zeros get added to the net loss.

Glenn Dekhayser posited a differing point of view. According to him, the real problem is “the upfront architecture of the system”. Back when it was only a small amount of data, backing up was easier. But in 2022, companies are dealing with petabytes of data, and backing up that amount of data requires them to have multiple copies in disparate environments. That raises two concerns –economics, and sustainability.

A Common ConcernWhile the panel was divided on their positions on the blast radius, they all concurred where the real challenge is. It’s not about a component failure or the size of it. It’s how fast things can be restored after you lose an array in a region.

Circling back to the topic at hand Moderator, Stephen Foskett raised the question that was at the heart of the discussion- is the blast radius of a bigger system actually bigger than that of a smaller system?

While the answer is evident – the blast radius is in fact bigger now – the reason he cites for that is “enterprises haven’t kept up with the growth of capacity. Essentially our systems are objectively bigger today and that’s driven by external factors and economics that have more to do with the vendors and the producers of those components and the limits of the system architecture, than they have with the use of data.”

Frederic Van Haren ties it to the workloads and what they demand. Today’s workloads, be it data analytics or a less demanding kind, ask a lot more out of the infrastructure than those before, he said.

Dekhayser explains that with data sprawl in full swing, companies have petabytes of data stored in arrays. When one such array goes down, the blast radius of that event gets significantly larger if that exact same data is not stored in another array in another region, and if that data can’t be moved fast enough over a network to bring up a new array. At the current state, that could take months.

Richard Kenyan says “Storage is no longer the bottleneck – it’s the rest of the infrastructure.” He reminded the panel that today high speed networks are inexplicably expensive. Small businesses can’t afford it, and even the bottom Fortune 500 companies don’t have access to it.

Wrapping UpIt is clear that the blast radius today is a lot bigger than it used to be, even if in an adjusted way. That’s all the reason why containment of that radius needs a lot more attention and work. When nearly anything from undetectable defects to silent errors can shut the whole system off and send ripple effects across the board, it communicates the message that we need to find more ways to limit that impact. Even though all conditions are not ideal, we now know that there are a lot of factors staring us in the face that can each contribute to accomplish that end.

Watch the full roundtable above and other similar discussions from the recent Storage Field Day event to get a refreshing perspective on current day storage.


© Gestalt IT, LLC for Gestalt IT: Measuring the Current Day Blast Radius of Outages

View Details

Organizations starting out in the cloud spare no cost in setting up the largest storage for their workloads. But no sooner do they move their applications, than they max out. Cloud is many things – it is resilient, scalable and easy – but one thing it is not is free. Cloud storage costs a good deal, and if businesses are to reduce their cloud bills, the only way forward is to manage their storage requirements efficiently. The rule of thumb for that is to gain clear and total visibility.

At the recent Storage Field Day event, AWS presented Amazon S3 Storage Lens, an observability solution that is designed to provide organization-wide visibility from the broadest down to the lowest level, so that users can keep a close watch on their usage and stay on top of the cost.

The Cost ConundrumLooking at the cost problem in cloud as a whole, it is easy to conclude that cloud is expensive. But quite contrarily, vendors position cloud to be cost-saving. Why are the ground realities different from what’s promised? Because harnessing the cost savings in cloud is the real challenge, not the cost itself.

When we take a step closer, a myriad of factors meet the eye that are contributory to the cost escalation. Those are the problems that organizations need to address first to encounter the flaring cost situation, the first of which is capacity procurement pitfalls.

Overbuying is perpetual in the cloud for two reasons. First, forecasting the storage requirements of applications is tricky business. You can easily go over or under, and rarely ever hit the mark. So, to be safe, companies overprovision. Especially, with unlimited capacity and easy scalability, it is tempting to scale up than to downsize capacity.

20/20 VisibilityA research conducted by Nutanix found that 43% organizations find managing costs in multi-cloud challenging. One way to overcome this challenge would be to separate capacity organizations need from capacity they waste.

AWS is guiding its customers towards better cost management in the cloud with Amazon S3 Storage Lens. Its mission is to help customers “understand storage from an aggregated broad view to a granular narrow view”.

“Amazon S3 Storage Lens is what we recommend as your first stop in getting visibility into your storage because it has the broadest view of your entire organization and account and a wide array of different metrics to investigate,” says Lee Kear, Principal Solution Architect, Amazon S3.

Kear laid out the USP of S3 Storage Lens – “The essence of why customers use Storage Lens comes down to visibility.”

While Amazon S3 Storage Lens provides a holistic view of the organization, Amazon lends users the means to drill down into the deeper and lower levels of their accounts using other observability features, namely S3 Inventory, S3 Storage Class Analysis, S3 CloudWatch Metrics and S3 Server Access Logs. Available at different price points, these features enable users to inspect elements inside each bucket forensically for close monitoring.

Amazon S3 Storage LensAt the recent Storage Field Day event, Lee Kear gave a presentation on the Amazon S3 Storage Lens. She kicked off the session with a rundown of the top features of S3 Storage Lens. Kear followed it up with a live demonstration of the solution to make its capabilities visual.

S3 Storage Lens provides data tailored to 29 metrics. It comes in two flavors- Free and Advanced. The Free version is auto-enabled in all AWS accounts, whereas the Advanced tier is a paid version that requires to be upgrade to. The Free version affords full visibility, but customers want to upgrade to the paid version to avail the additional capabilities of optimizing and automating observability.

The Free version has 15 metrics, and the Advanced, 14, broken down into categories. The metrics available in the Free version include Summary, Cost Optimization and Data Protection. Under Advanced, there’s Activity metric which includes GETs and PUTs, download/upload bytes, retrieval rate and more.

“These are some of the most valuable S3 Storage Lens metrics that you can use to analyze bucket level access patterns such as identifying your hottest buckets or to allocate abandoned workloads,” said Kear.

Starting at the higher levels of organization and account, users can move down the lower levels of Region, Storage Class, Bucket and Prefix for a closer inspection. Kear says “S3 Storage lens is the first tool to provide this with visibility at the prefix level”.

There are three ways users can access S3 Storage Lens. It comes with “an Integrated Dashboard built directly into the S3 console”. Customers enjoy the “Integrated Dashboard experience” because it offers a simplified and organized view of the S3 Storage Lens and other storage-related workflows. The dashboard is pre-configured and needs no installation.

The second access method is Export Metrics. For customers who just want the raw data, the Export Metrics sends data directly to the S3 buckets in their accounts. Users can consume it through directly without viewing it on the UI.

The third option is Amazon CloudWatch, a feature that is now a part of the Advanced tier. Designed with DevOps people in mind that like to tally up the metrics with monitoring metrics coming in from other AWS services, enabling the CloudWatch Publishing option will send the data to CloudWatch where users can be access it via API or CloudWatch native features.

The Advanced version of S3 Storage Lens costs 20 cents per million objects monitored per month. Although it comes at an extra cost, upgrading to the advanced version has its benefits that the Free version does not cover. Kear highlighted granular visibility into the lowest prefix level and the longer 15 months historical range compared to the much shorter 14-day range in the Free version. The CloudWatch publishing feature is the cherry on top.

Wrapping UpIt is tempting to go for a XXL size storage in cloud because why not, after all its unlimited capacity. But when that reflects in the invoice, it rarely inspires anything but alarm. That’s why Amazon S3 Storage Lens is a vital tool to use when struggling with cost escalation from growing cloud footprint. S3 Storage Lens aggregates data from across all accounts, filters it to an easily consumable format, and presents it with analytics through an interactive dashboard making it infinitely easier for IT personnel to keep a tab on storage usage, activities and most importantly, get recommendations on best practices.

To know more about Amazon S3 Storage Lens, be sure to check out the presentation above. Also check out other presentations by AWS from the recent Storage Field Day event to know what’s in store.


© Gestalt IT, LLC for Gestalt IT: Amazon S3 Storage Lens – Tuning Up Cost-Efficiency in Cloud with Full Visibility

View Details

Modern datacenters are nothing like those before AI. Organizations now run a mix of workloads on-premises as opposed to any one kind. These workloads demand different profiles of performance and endurance, and a consistently reliable storage across the infrastructure. This and the proliferation of AI/ML applications have driven up the demand for QLC SSDs in datacenters in the recent years. At the recent Storage Field Day event in California, Solidigm tapped into this discussion while presenting their upcoming QLC solutions for modern datacenters. Their presentations got a lot of attention from the Tech Field Day audience and our peers, and for good reason.

Customers Shouldn’t Have to Choose between Performance and CostIt is a fact that TLC SSDs are mainstream, and they occupy a majority of the market share by the sheer performance and endurance scores, but customers are gradually steering away towards low-cost alternatives, and for that, QLC presents a value replacement.

When measured against the four corners of performance, endurance, capacity and cost, the biggest difference between TLC and QLC products is random write performance. TLC drives for PCIe Gen 4 platform delivers twice the IOPS as QLC. In every other aspect, QLC and TLC drives deliver equal or near-equal speed and performance. So for workloads that are read-heavy, or don’t care about the write perf, QLC has the most cost-efficiency and least perf tradeoffs. For those applications, QLC delivers faster access to data, and that’s what most enterprise-grade AI, ML and data analytics applications seem to want these days.

Where QLC has significant advantage is capacity and cost. QLC are high-density SSDs. They can store four bits of data per cell whereas TLC can store only three bits per cell. Mathematically, that is 33% more density and 25% more cost savings.

Solidigm’s Offerings in QLCSolidigm’s portfolio comprises both TLC and QLC products. In TLC, Solidigm offers standard endurance products, and in QLC products, which are aimed at the market for lower endurance storage, they have two choices coming – Essential and Value Endurance.

The Value Endurance range is the lowest-cost option in Solidigm’s QLC product line. These SSDs offer extra savings on the DRAM and are a good fit for read-heavy workloads. The QLC Essential range is a more cost-friendly replacement of TLC and is the middle tier between HDDs and flash.

When Is One a Better Choice than the Other?While both the SSDs sound promising, when do you choose one over the other? According to Yuyang Sun, Sr Product Marketing Manager, QLC Products, Solidigm, customers who will lean towards the Value Endurance range of QLC drives are hyperscalers who are looking to get the most bang for their buck, and customers whose applications demand really high-density storage. For organizations whose applications are not write-intensive, and are moving to QLC products for the first time, the Essential Endurance makes a more appropriate choice.

Future 4th Gen QLC SSD Offerings from SolidigmAt the recent Storage Field Day event, Yuyang Sun gave a presentation on Solidigm’s future PCIe QLC portfolio. Taking the audience through the two classes of SSDs on the list, she went through the performance numbers and specifications of the drives.

Both the Essential Endurance and Value Endurance SSDs by Solidigm are based on their 4th generation 192-L QLC technology. The Solidigm QLC Essential Endurance has a block size of 4KB and capacities ranging from 3.84TB to 30.72TB. Solidigm calls its Essential Endurance QLC range “a drop-in replacement for any storage solution today.” It has a random endurance of 8KB and lets you write up to 32 PB of data per drive. They come in three form factors, namely E1.S, E3.S and U.2.

Solidigm’s Value Endurance range packs even more power. With a 16KB block size, it has capacities going all the way up to 61.44TB which is twice the maximum capacity of Essential Endurance. Write-optimized, its makers are marketing Value Endurance as the option for “write-intensive and the ultimate cost-saving” use cases. The Value Endurance drives have twice the maximum endurance of the Essential Endurance range, and can write up to 65 PB per drive. The SSDs come in form factors E1.L, E3.S and U.2.

According to Solidigm slides, the Random Write and Read performance of the Essential Endurance SSDs is significantly ahead of other competitor drives with Essential Endurance SSDs providing 24% and 33% higher throughputs and 20% and 26% lower latency when benchmarked with other drives.

Wrapping UpIt looks like Solidigm’s upcoming range of QLC SSDs are set to unlock groundbreaking cost-efficiency and performance points with no significant tradeoffs compared to other options available in the market. Tuned for read-heavy applications, the SSDs are both cost and capacity-optimized for the large-scale datacenter needs, and if the numbers are to be believed, these will make an excellent fit for a wide range of read-centric, performance-sensitive AI/ML workloads.

For more information on Solidigm’s QLC SSD portfolio, be sure to check out the other presentations from the recent Storage Field Day event. Here is another excellent resource to read on this from Blocks and Files.


© Gestalt IT, LLC for Gestalt IT: Low-Cost Storage for Read-Intensive Workloads with Solidigm’s Gen 4 QLC SSDs

View Details

One’d think that the most common reaction to a new software upgrade is about the change in the software’s look and feel, but really, what drives the anxiety around upgrades is the pain of upgrading and its possible impacts on the business. At the recent Storage Field Day event, Pure Storage presented a new Self-Service Upgrade for Pure1 which takes the stress out of upgrading making sure that software upgrades and business outcomes aren’t on a collision course.

The White-Glove Upgrade So long, Pure Storage has offered its customers “white-gloves support” for all appliance upgrades on Pure1. Every time something in the array needed upgrading, the client would sit down with the support team as the team walked them through the upgrades. This is quite a pain-free process in itself, except, it required scheduling an upgrade with Pure’s support team.

Scheduling an upgrade on Pure1 was straightforward as well, and took only a few clicks. On the Pure1 dashboard, under the Software Lifecycle tab was the option to schedule an upgrade. The dashboard showed the list of appliances and their models that users could choose from. Once a user chose the appliance and its model, they’d be asked to select the version they wanted to upgrade to. This’d take them directly to the scheduler where they could select an available date and time. The duration of the session would be clearly mentioned so that users could choose a time that worked best for them. That’s all it took to request an upgrade. The next thing, someone from the support team would get in touch with them to do the pre-checks before the final upgrade.

Time and Other ConstraintsAs easy as the assisted upgrade sounds, it still has the time factor attached to it. For 2 hours on a workday, users must sit down with the team and work hand-in-hand till the systems are upgraded. And as upgrades keep coming, more time needs to be invested.

Although customers loved the “white-glove” upgrade, Pure Storage recognized that there were significant rooms for improvement. But making upgrades self-service wouldn’t have solved the problem entirely because there are always risks of something breaking in the process of upgrade. Without supervision of experts, it could very easily go wrong.

So Pure Storage combined the best of both and introduced a new Self-Service Upgrade that “lets customers upgrade whenever they want”. But Pure Storage didn’t want this new way to be too different from the existing method. So they threw in upgrade assistance to this to complete the package.

The Four-Step Any-Time Storage UpgradeAt the recent Storage Field Day event, Stan Yanitskiy, Sr Product Manager and Matt Bradford, Director of Technical Marketing for Digital Experience at Pure Storage explained how the new Self-Service upgrade on Pure1 works and in what way it’s better than the previous method.

Like it says, the Self-Service Upgrade lets users run upgrades on their own without the supporting team walking them through it. In the new method, users perform the pre-checks themselves, and it’s really easy. All they need to do is check the upgrade readiness of the appliance to make sure that the concerned device is eligible to upgrade to the next version.

Yanitskiy says, “We want to make sure that you’re within a single hop and do not get into a situation where you have to do multiple hops at a time so that it just takes the least amount of time.” The pre-checks are to “make sure that you go from your current version to the target version without any kind of incompatibilities, that the target array is on a compatible version, so you don’t break anything in your environment.”

The pre-checks also include host configurations to avoid breaking the controller and cutting off the communication by accident. The idea behind is to make sure that all conditions are optimal because if they are not, an attempt to upgrade can lead to an outage.

In the next step, the user downloads the code. After this, there will be one final on-array pre-check with live data before the system is upgraded.

But with Self-Service Upgrade, customers won’t be entirely on their own in the wild. The Pure support team will be constantly watching making sure that data availability and performance are not impacted during the upgrade. If a problem occurs, they will step in and smooth it out, or help customers rollback, if required.

Yanitskiy says that the Self-Service Upgrade literally has “no maintenance windows or downtime” and as a result is completely non-disruptive and safe.

Wrapping UpThe new Self-Service Upgrade is different from the former time-consuming assisted upgrade. As opposed to the long-drawn supported upgrades, here support is kept at the ready on the off chance that something went wrong during the upgrade, so that a response can be dispatched without wasting any time. Users don’t need to take time out of their busy schedules, and upgrades can happen during lunch hours or over the weekends. It doesn’t have to be a full-blown session for it to be a success. Pure made sure of that.

For more information on the Pure1 Self-Service Upgrade, be sure to check out the full presentation and other demoes by Pure Storage from the recent Storage Field Day event.


© Gestalt IT, LLC for Gestalt IT: The Self-Service Upgrade Experience on Pure1

View Details

In this Cloud Field Day article, Sulagna Saha discusses how integrating Prosimo into your infrastructure can help make the transition to Mulitcloud easier.


© Gestalt IT, LLC for Gestalt IT: Simplifying Multi-Cloud Networking with Prosimo

View Details

In this Cloud Field Day article, Sulagna Saha discusses how the next generation of Google Hyberdisk will take the storage solution to the next level.


© Gestalt IT, LLC for Gestalt IT: Everything New with Storage this Quarter on Google Cloud

View Details

In this Cloud Field Day article, Sulagna Saha discusses how RackN breaks down the silos that exist between tools, processes and teams in IT, making it possible to share, swap, connect and reuse workflows flexibly.


© Gestalt IT, LLC for Gestalt IT: IaC Automation with RackN

View Details

In this Cloud Field Day article, Sulagna Saha breaks down Commvault's Metallic Threatwise and how its able to fight off attacks and mitigate damages post-attack.


© Gestalt IT, LLC for Gestalt IT: Cyber Deception with Commvault

View Details

In this Cloud Field Day Extra article, Sulagna Saha discusses how a unified data services solution like NetApp Cloud File Services makes consumption of a hybrid multi-cloud infrastructure infinitely easier and ultimate cost-friendly for enterprises.


© Gestalt IT, LLC for Gestalt IT: Tackling Hybrid Multi-Cloud Complexity with NetApp

View Details

In this Cloud Field Day article, Sulagna Saha discusses how an observability solution like Kentik can greatly help with navigating the complex cloud cost landscape


© Gestalt IT, LLC for Gestalt IT: Observing the Cloud Network for Hidden Costs with Kentik

View Details

Find out more about Mobility Field Day 8 coming your way October 5-6, 2022!


© Gestalt IT, LLC for Gestalt IT: Moving Faster with Mobility Field Day 8

View Details

In this Cloud Field Day article, Sulagna Saha discusses the promises of StormForge's Bi-Dimensional Autoscaling with resource utilization and cost management.


© Gestalt IT, LLC for Gestalt IT: Bi-Dimensional Pod Autoscaling in Kubernetes with StormForge

View Details

In this Networking Field Day 29, Sulagna Saha discusses how Juniper Networks' Apstra platform from where operators can observe all elements of a datacenter, study the correlations, and manage them easily with the click of a button with smart intent-based networking.


© Gestalt IT, LLC for Gestalt IT: Design Flexibility, Support for all Network Topologies and More with Juniper Networks Apstra’s Freeform

View Details

In this Networking Field Day article, Sulagna Saha discusses why Broadcom's Tomahawk 5 series is a game-changer for datacenters.


© Gestalt IT, LLC for Gestalt IT: AI/ML Acceleration with Broadcom’s Blazing Fast Tomahawk 5

View Details

In this Networking Field Day article, Sulagna Saha discusses how Opengear’s Out-of-Band management is an essential solution to have to ensure business continuity when the primary network is compromised.


© Gestalt IT, LLC for Gestalt IT: Resilient Out-of-Band Network Management for Everyday with Opengear

View Details

In this Networking Field Day article, Sulagna Saha discusses Kentik's observability capabilities and how it's 24/7 environment scans minimizes downtime.


© Gestalt IT, LLC for Gestalt IT: Attaining a Strong Observability Posture with Kentik

View Details

In this Networking FIeld Day article, Sulagna Saha discusses why the Catchpoint Digital Experience Management Platform is an integral tool to optimize digital experience.


© Gestalt IT, LLC for Gestalt IT: Gauging User Experience with Catchpoint

View Details

Cloud Field Day15 is returning to Silicon Valley September 21-23. It is our opportunity to look at the next generation of IT, from the enterprise to the public cloud and everything in the stack.


© Gestalt IT, LLC for Gestalt IT: Cloud Field Day 15 Returns to Silicon Valley!

View Details

This exclusive Cloud Field Day event with NetApp serves as a deep dive into the reality of the multicloud today with a special focus on NetApp's multicloud file services.


© Gestalt IT, LLC for Gestalt IT: Take Charge of your Multicloud Environment with NetApp: A Cloud Field Day Extra

View Details

In this Networking Field Day article, Sulagna Saha discusses how Graphiant Control Plane enables a secure and low-friction transfer of data through expedited encryption events.


© Gestalt IT, LLC for Gestalt IT: Edge to Edge Security with Graphiant

View Details

In this Mobility Field Day article, Sulagna Saha discusses how NetAlly's AirCheck G3 time efficiency and increased visibility into a network.


© Gestalt IT, LLC for Gestalt IT: Wi-Fi Auto-Testing with the New AirCheck G3