- Dedicated hardware acceleration provides a Zero packet loss architecture
- Filtering of traffic so that each monitoring or inline security tool receives exactly the right data
- SSL decryption to quickly detect emerging threats encrypting exploits within application traffic
- Dynamic filter compiler handles all filter rule complexities automatically – no overlapping filter rule headaches
- Aggregation of traffic from multiple TAPs or SPAN ports
- Load-balancing of traffic to multiple analysis tools
- L7 application awareness efficiently allows for packet processing based on unique applications
Keysight visibility solutions provide real-time, end-to-end visibility, insight and security into physical, virtual, SDN and NFV based networks, delivering the control, coverage and performance in a seamless fashion to protect and improve crucial networking, data center and cloud business assets.
Industry leading Keysight Network Packet Brokers (NPB) deliver intelligent, sophisticated and programmable network flow optimization providing visibility and security coverage to business assets and help IT teams quickly resolve application performance bottlenecks, trouble shoot problems, improve data center automation, better utilize expensive network analysis and security tools and help better business execution because of the improved understanding of the network and data center.
Keysight's best-in-class Vision portfolio of network packet brokers are easy-to-use, perform under pressure and offer true application intelligence.
Keysight's Network Packet Brokers
Scalable, lossless visibility solutions for all your network needs.
|Vision E40||Vision E100||Vision E10S||Vision E1S||Vision ONE||Vision X||Vision 7300|
|CHASSIS AND PORTS|
|MODE OF OPERATION|
|Simultaneous Inline and Out-of-Band||X||X||X||X||X|
Stack up Keysight’s leading visibility intelligence features to optimize your traffic analysis and security tool performance. Used with a network packet broker, virtual or cloud platform, the extensive set of intelligent features allows you to modify, mold and transport traffic specific to tool needs. Moreover, we provide industry-specific, specialized capabilities. Each feature is executed with a purpose-built design to ensure you get the best performance whether in a physical data-center or in the cloud. To learn more, click on each stack.
Keysight offers an easy-to-use, intuitive click-and-drop NPB interface to allow operators to make connections from taps or SPAN ports to their connected tools. The configuration of filters is streamlined and easy, with overall setup requiring minimal time and effort, even for large shops and complicated networks. No professional services or expensive training is required to learn and implement the Keysight visibility solutions. This eliminates the need to use time-consuming command line interface (CLI) or web user interface (WebUI) dialogs, or invest hours or days designing complex logic.
Keysight Fabric Controller (IFC) is a SDN controller for visibility that allows multiple network packet brokers to work collectively within a single pane of glass. IFC extends a full set of API controls and integrates with Cisco ACI, as well as other SDN architectures.
Network Visibility – Ease of Use Matters
Visibility Inline vs Out-Of-Band
There are two different ways to deploy network packet brokers: Inline Security and Out-of-Band Monitoring
Inspect live traffic before it hits your data center network. Tools are grouped serially before traffic enters your production data center enabling real-time traffic inspection and active threat prevention.
- Intrusion prevention systems (IPS)
- Firewalls and next-generation firewalls (NGFWs)
- Data loss prevention (DLP) systems
- Unified threat management (UTM) systems
- SSL decryption appliances
Provides passive traffic inspection, detection, and recording for routine analysis. This model is used extensively in detailed threat analysis, but does not enable any active prevention safeguards or countermeasures.
- Intrusion detection systems (IDS)
- Forensic tools
- Data recording
- Malware analysis tools
- Log management systems
- Packet capture (PCAP) tools
Network Packet Broker Capabilities
Zero Packet Loss
We have instrumented purpose-built dedicated hardware in our physical packet brokers to ensure zero packet loss, which ensures that your tools receive 100% of the packets they need to perform their job. Our packet brokers will NOT drop data due to congestion regardless of what features used or packet size.
Unlike many competitor solutions where many features such as SSL decryption, NetFlow generation and packet trimming can’t work together in the same module, Keysight provides line-rate guarantee on any combination of features.
Active-Active is the predominant use case for inline security tool deployment. It performs load balancing during normal operation, and offers safe cut-over on failures.
Network Visibility – Feature Compatibility Matters
Drag and Drop User Graphical Interface
We offer an intuitive graphical user interface that allow users to easily define the connections and filter rules between network ports and tools. Configuration of the network is a simple point and click, drag and drop interface, where users can visually represent their network connection needs within minutes.
Handles Filter Rule Complexities Automatically
When it comes to creating and managing filters, Keysight's Dynamic Filter Compiler that takes care of the all the complexities of filter rules, allows users to tie any network port to any tool port without being concerned about existing filter logic in any other filter rules. This means that new filter rules can be added at will into existing filters and the Ixia Dynamic Filter compiler takes care of overlap resolution behind the scene.
Three Levels of Filter Logic
When creating filter rules, you can add them at three levels: the ingress network ports, a dynamic filter in the middle, and tool filters at egress. This multiple level of filtering offers natural AND and OR logic thus allowing complex Boolean logic to filter traffic in the stringiest way to protect expensive tools from being overloaded.
No Limits on Filter Types
Finally, when managing filter rules, there are not restrictions to the advanced filtering features that can be utilized together. This means users can worry less about what they can and can not do, and focus more on their tools, and what they need to perform at highest levels.