Title: Allot Network Intelligence
1Allot Network Intelligence
- Tomás Gómez de Acuña
- tgomez_at_allot.com
2AllotAt-A-Glance
Company Status
Public company traded on NASDAQ ALLT
Employees
250
RD and Operations
Israel, Hod Hasharon
Americas MN, CA, NY, TX, AZ, BrazilEurope
France, UK, Germany, Italy, Spain, Scandinavia
Asia/Pac. Singapore, Japan, Australia
WW Sales and Support
Founded
1997
More than 9000 units sold in 118 countries More
than 700 service providers More than 2060
enterprises and educational inst.
Track Record
3Allot Network Intelligence Solution
Internet Access
Internet
WAN
RED LAN / CORE
VPN/Leased Line/MPLS
4Network Intelligence Solution Main Features
- Network visibility Network Intelligence
- Network troubleshooting
- Layer 7 Firewall
- Signature Base, DPI (Deep Packet Inspection)
- Connection Control
- Connection limitation per rule
- Badwidth assignment per connection
- Data center protection / DoS protection
- DDoS and Malicious Traffic Control (Service
Protector) - P2P Control
- Application Control
- QoS Bandwidth Management
- Video Caching (MediaSwift)
- Block of Illegal Webside URLs (Websafe)
- Managed Services. Virtual Traffic Control
- Subscriber Management. Traffic Control per
Subscriber - Accounting and Billing
5Allot Product Family
6NetEnforcer Products
NetXplorer
SMP
AC-400
AC-800
AC-1000
AC-10000
AC-2500
Service Gateway
Ancho De Banda
2 a 100 Mb
45 a 310 Mb
155 Mb a 1 Gb
310 Mb a 2,5 Gb
5 Gb a 40Gb
4 Gb to 20 Gb
Politicas
4.000
28.000
80.000
80.000
400.000
400.000
Internet Access,Local ISPs Pymes y SMB
Tier 1, 2Carriers, ISPs
Tier 1, 2Carriers, ISPs, EnterpriseUniversidades
Tier 1, 2Carriers, ISPs, EnterpriseUniversidades
Tier 2-3 Carriers,ISPs,EnterpriseUniversidades
EnterpriseISPs Universidades
Clientes
7NetEnforcer Enterprise / Medium SP Platform
8NetEnforcer SP Carrier Platform
9AC10000
10Service Gateway
11The Service Gateway Vision
Network Subscriber Management
3rd PartyServices
FutureService
...
DPI Engine
Open platform enabling integrationof
best-in-class services
12Service Gateway Redirecction
- Caching
- URL Filtering
- IDS
- Firewall
- Contect Inspection
- Reponse Time System
Third Party Product
RED LAN / CORE
- Centralized DPI System
- Reduce System Investment
- Better Traffic Control
- Really Intelligent (L7) Forward
131 2 links Topologies
Two Links. Different Networks
One link
Two Links. Redundant Configuration
- 10/100 Ethernet NE 402/802
- 1 Giga NE 802/1010
- 10 Giga NE 10100 / SG
- 10/100 Ethernet NE 404/804
- 1 Giga NE 804/1020/2520
- 10 Giga NE 10200 / SG
- 10/100 Ethernet NE 404/804
- 1 Giga NE 804/1020/2520
- 10 Giga NE 10200 / SG
144 links Topologies
Four Links. Redundant Configuration. Fully Meshed
FourLinks. Different Networks.
- 10/100 Ethernet NE 808
- 1 Giga NE 808/2540
- 10 Giga SG 8 x 10G
- 10/100 Ethernet NE 808
- 1 Giga NE 808/2540
- 10 Giga SG 8 x 10G
158 links Topologies
Eight Links. Different Networks
- Service Gateway 8 links of 1 giga
16High Availability
17SMP Arquitecture
18SMP Features
Subscriber Monitoring
Tiered Services
Quota Management
Portal
19NetXplorer Provisioner Arquitecture
Managed Services Virtual Traffic Network
Intelligence
Authentication
NetXplorer Server
RADIUS Server
Users
Policy Modifications and Data Collection
Back-end control
Front-end Provisioning and Monitoring
Internet
Users
NetEnforcer
NetXplorer Provisioner
Network Operator
20NetXplorer Provisioner (NPP)
21NetXplorer SMP Arquitecture
GUI Client
GUI Client
OSS RADIUS/DHCP
Mediation / Billing
NetXplorer Server
Subscriber Management
NetXplorer DataCollector
NetXplorer DataCollector
NetXplorer DataCollector
22Netxplorer Features
Main Features
- Network Visibility
- Real Time Monitoring
- Long Term Monitoring
- Auto Application Discovery
- Centralized Policy Management
- QoS definition
- L7 Firewalling
- Port Redirection
- DoS control
- Reports Creation
- Reports Scheduling
- Events Alarms
23Netxplorer Drill Down Capability
24Rich Set of Graphs
- Statistics
- Utilization
- Distribution Graphs
- NetEnforcers
- Lines / Pipes / VCs
- Protocols
- Hosts / Int / Ext /
- Conversations
- Subscribers
- Average Protocol Popularity
- Typical Time
25NetXplorer Most Active Graphs
Three Dimensional Graphs
26NetXplorer Data Selection
Date Time Range
27NetXplorer Report Creation
Multiple Format Output Reports
28NetXplorer Report Scheduling
29Events Alarms
30QoS Optimization Control
With Allot
Without Allot
P2P Upload P2P Download
Visible and Managed
VoIP WebTV Video Conferencing
Unmanaged
Gaming email
Allot NetEnforcer
31NetXplorer Policy Definition
32Superior DPI technology
- New dedicated H/W offers scalability
upgradability - Based on Allots Next Generation DPI engine S/W
with native APU (Allot Protocol Updates) support - Advanced Proactive Learning System for finer
identification of sophisticated P2P Apps - Leader in real time and internet protocols
33Service Catalog
34Improvement of QoS features
- 3-level policy control
- LINE, PIPE Virtual Channel
- Expedited Forwarding for real time applications
- Assured Forwarding for video streaming
- Drop Precedence for effective BW management
(short term peak traffic) - Tailored QoS behavior per Application
- Per Flow Queuing mechanism
35QoS Catalog
36DoS Connection Control
DoS Control
Connection Control
37ServiceProtector
- Protects against DDoS attacks network attacks
worms subscriber zombies spambots - Behavior-based ADS (Anomaly Detection System)
- Facilitates surgical isolation at the network or
subscriber level
- KEY BENEFITS
- Reduce customer complaints
- Reduce OPEX
- Avoid email blacklisting
- Enhance network mgmt
- Improve network stability
- Protect key customers
- Protect revenue streams
38ServiceProtectors Main Features
- Signature free DDoS, Spam and Zombie detection
- 0 day detection
- Fully based on traffic behavior
- lt5 false positives, gt95 rate true positives
- Fast attack identification. Normally less than 5
min from begin to mitigation - On-Fly attack signature creation
- For Mitigating the attacks
- Easy and transparent installation
- Distributed system
- Multiples sensors with one management console
- Independent solution
- No help needed from routers
- Fully integrated with NetXplorers Network
Intelligent System - External server or a ATCA blade
- Up to 10Gbits real-time detection per sensor
38
24 February 2012
39Network Behavior Anomaly Detection (NBAD)
- Network attacks disrupt network behavior and the
normal relationship between network statistics
- Uses TCP/IP statistics to build behavioral models
- Identifies disruptions in absolute and relative
network statistics - Connectionless, sessionless, stateless
- Detection speed inversely proportional to
magnitude of attack - Invariant to normal peaks and troughs
- Sensitive to attacks
40Deployment
- Availability of Service Protector blade to be
announced expect mid-late 08
41 MediaSwift
- Intelligent Media Caching maximizes network
efficiency - Accelerates content delivery and provides highest
QoE - Reduce delivery costs and improve service quality
- KEY BENEFITS
- Transparent caching of all bandwidth-intensive
protocols - Reduce OPEX
- Reduction of upstream bandwidth
- Wire speed data delivery
- Preserves functionality for all Internet services
- Scalable multi-gigabit bandwidth generation
42Bandwidth Control Media Acceleration
Internet
HTTP Traffic
- Manages traffic and BW growth
- Produces BW savings
- Fastest downloads possible
- Best Quality of Experience (QoE)
- Satisfy user demand for media
- Competitive advantage over other ISPs
MediaSwift
ISP Core Network
P2P Traffic
ISP Access Network
Subscribers
HTTP Video
P2P Peer
Email, HTTP
VoIP
43How it Works
MediaSwift Blade
SG-Sigma
ISP User
Internet User
44WebSafe
- An add-on service for Allot Service Gateway Sigma
- Supports encrypted URL blacklists
- up to 50,000 entries
- Supports Whitelist
- Overrides Blacklist in case of over-blocking
- Up to 10,000 entries
- Multiple enforcement actions
- Redirect or block user
45Referencias
- Administración Pública
- Turespaña
- Catastro
- Servicio Andaluz de Salud
- Oficina de Patentes
- Forum de Barcelona
- Principado de Asturias
- Gobierno de La Rioja
- Gobierno de Canarias
- Gobierno de Navarra
- Gobierno de Cantabria
- Ayuntamiento de Gijón
- Ayuntamiento de Rivas
- Ayuntamiento Laguna de Duero
- Ayntamiento de Torre Pacheco
- Parlamento de Cataluña
- Informática Comunidad de Madrid
- Estrada Dixital
- Hospital Marqués de Valdecilla
- Banca y Seguros
- BBVA
- Banco Sabadell
- Santa Lucia
- Caixanova
- Rural Servicios Informáticos
- Agroseguro
- BBK
- Ibercaja
- Cajasegovia
- Aseval
- Caja Laboral
- Ministero de Sanidad
- Ministerio de Agricultura
- Ministerio de EconomÃa (IGAE)
- Marina Mercante
- Generalitat Valenciana
- Ayuntamiento de Lloret
- Dirección General de Aragón (DGA)
- Sadesi (Junta de AndalucÃa)
- Junta de Extremadura
- ConsejerÃa Educación Junta de AndalucÃa
- Parlamento de Vasco
- Osakidetza (Servicio Vasco de Salud)
- IKT (Gobierno Vasco)
- Autoridad Portuaria de Valencia
- Dirección Gral de la Policia
- Ministerio de Defensa
- Ministerio del Interior
- Gobierno de Murcia (F. Integra)
- Colegio de Registradores
46Referencias
- Operadores
- Unión Fenosa Telecomunicaciones
- Comunitel
- Neo Sky
- Fujitsu ASP
- BT
- Telecable
- R
- PTVTelecom
- Mcctelecom
- CableMutua
- Riosat
- Everbit
- Gemytel
- Más de 10 operadores de Cable regionales
- WifiOnline
- Axartel
- Novatelefonia
- Cable Sur
- Universidades
- Universidad de Oviedo
- Universidad de Las Palmas
- Universidad de Málaga
- Universidad de Burgos
- Universidad de Cantabria
- Universidad de León
- Universidad Alfonso X el Sabio
- Universidad Miguel Hernández
- Universidad de Murcia
- Universidad de Barcelona
- Oxford University Press
- Universidad Pública de Navarra
- Universidad de La Rioja
- Escuela universitaria Galileo Galilei
- Universidad de Jaen
- Universidad de Huelva
- Universidad Politécnica de Madrid
- Universidad de Granada
47Referencias
- Industria y Empresa
- Iron Montain
- ENCE
- Barceló Viajes
- Garden Hotel
- Praxair
- RTVE
- Turespaña
- Agroseguro
- DHL
- Tectotrans
- Marmedsa
- Mundo Social
- Viajes Marsans
- Dorna
- Telemadrid
- Unión Española de Explosivos
- Arias
- La Cope
- Cementos Rohe
- Prosegur
- Algeposa
- Global Interlink
- Azertia
- Garden Group
- Puleva
- Albatros
- Almirall
- Torraspapel
- Iberdrola
- OHL
- Telefónica Soluciones
- Blanco Diagomoda
- AENA
- Radio Televisión Valenciana
- Transportes AZKAR
- MarÃtima Bergé
- Torraspapel
- Redcom
- Spainrep
- Clar
- Roboticker
- Ciudad de La Luz
- Detinsa
- Estrella de Galicia
- Plásticos Ferro
- Forum de Barcelona
- Grupo Urvasco
- Grupo Boluda
- Armillar
- Pipeline Sofware
- Punto Acceso
- Rodio Cimentaciones
- Mtorres
- Schneider Electric
- Trentinort
- Unisono
48(No Transcript)