2016 NetExIP-HyperIP Security Enhancement Update

NetEx/IP® and HyperIP® Today

Network Executive Software, Inc. (NESi) brings high performance file transfer technology to the industry-standard IP environment with its NetEx/IP and HyperIP software products.

NetEx/IP is many times faster than TCP over long distances, which makes it the ideal solution for moving massive amounts of mission- or time-critical data across the country or across the globe.  As proven by our long-term users, NetEx/IP has the highest throughput rates over long distances with no degradation of performance because of its efficient bandwidth utilization and mitigation of the effects of packet loss and latency. In fact, NetEx/IP and its predecessor product NetEx/HC (HyperChannel) have provided solutions for moving data for global corporations and US state and government agencies for more than 30 years.

For existing TCP applications, the premier solution is NESi’s low cost HyperIP.  HyperIP transparently implements NetEx/IP in the data path to provide all the NetEx/IP improvements, plus compression of data, on a virtual machine without having to modify existing applications or operating procedures.

The Challenge: Securing the Data

With an increase in hacking and breaches of sensitive databases in recent years, many corporations (especially those in the financial, government, or health sectors) and US government agencies are looking at ways to better protect data transiting between sites and the databases themselves.  Data security is also of utmost importance for those customers utilizing shared/public networks.

NetEx/IP Security Enhancements

NESi recognizes this concern for data protection and is therefore planning to enhance NetEx/IP and HyperIP over the next year with standards-based security technology like Transport Layer Security (TLS) to significantly increase the security of the data being moved across the computer room, the country, or globally.

TLS is a cryptographic protocol that secures data as it is transmitted, focusing on authentication, data integrity, and data confidentiality. With TLS, keys are generated uniquely for each connection and are based on a shared secret negotiated at the start of a session, providing security between two applications using NetEx/IP or HyperIP.  Adding TLS to our NetEx/IP products will also provide improved security for our BFX & PFX utilities, which interface upward to customer applications.

In addition to data security, adaptive block compression of data will also be added to NetEx/IP, thus decreasing WAN bandwidth usage and effectively increasing the application data throughput over the network.

Solving WAN Challenges of Workload Mobility Using HyperIP

IBM released a whitepaper on Leveraging the Cloud to transform Test and Development. As companies implement software in the cloud on an on-premise platforms for workload sharing, challenges emerge in the movement of that workload between the customer premise and the offsite destination of that data. Does development become hindered if I move that workload offsite or does it have to be in my LAN? Can I move it offsite so workload mobility, flexible system and software configuration, and continuous provisioning be leveraged as a cost effective solution? IBM’s Smart Cloud solution and HyperIP’s WAN Acceleration Virtual Appliance ensures that customers can leverage workload mobility over the WAN, without suffering the performance problems caused by the WAN.
Customers leverage many techniques for moving the workload between the test/dev environment and the customer’s developers. vMotion, Live Migration, FTP, RSYNC, TSM, ProtecTier, etc. All of these applications require the workload to traverse the WAN. TCP/IP has limitations on the movement of big data. HyperIP removes those limitations to significantly improve performance of workload mobility, in excess of 10-12x faster by providing a WAN Acceleration technology that removes packet loss, latency, and out-of-order packets from task. HyperIP then implements block-level data reduction algorithms to significantly reduce the time to move that workload to or from the cloud hosting facility. This all translates to cost effective network transfers and connectivity.

HyperIP Supports a Large Number of Backup & Replication Applications

There are many WAN optimizers in the market today. So many that it becomes confusing to decide which ones to use for specific applications. HyperIP WAN Optimization virtual appliance is focused on moving BIG DATA over wide are connections and does so by minimizing the negative effects of TCP over distance. Specifically HyperIP does a very good job at mitigating the effect of latency and packet loss which can seriously degrade application throughput. HyperIP is the only WAN Optimization product on the market today that focuses on these types of storage applications. To see a complete list of the applications supported by HyperIP please visit our website: http://www.netex.com/hyperip/supported-applications.

NetEx Repost of IBM TSM Storage Blog

Enabling TSM Unified Recovery Management Replication

Maria Huntalas | Today 3:25 PM

In the IBM Thought Leadership Whitepaper, 10 Ways to Save Money with IBM TSM, “IBM Tivoli Storage Manager Suite for Unified Recovery simplifies and streamlines storage management, helping organizations control both the risks and costs of data protection and recovery.” This blog post visits the savings NetEx’s HyperIP offers by running TSM Replication, a feature of Tivoli Storage Manager Extended Edition and Tivoli Storage Manager Suite for Unified Recovery, over the WAN.

Previous blog posts talk about the performance improvement of TSM replication over HyperIP (http://www.netex.com/blog/?p=206). The following chart describes the true performance of replication over HyperIP (data provided by NetEx):

HyperIP enables TSM replication to see near wire speed, over any distance, even over lossy WANs. With HyperIP’s block level compression, throughput can literally exceed wire speed by as much as 6x; with lossy WANs, over 12x. This means a replication window that moves GB’s of data can be reduced from hours to minutes, without having to increase the bandwidth of the WAN links between remote TSM server nodes. Bandwidth savings alone can return the HyperIP investment in less than 3 months.

For more information, visit http://www.hyperip.com or contact your IBM Business Partner for more information on Tivoli Storage Manager replication over HyperIP. Stay tuned for upcoming co-sponsored webinars with the IBM Tivoli team and NetEx. NetEx is a proud exhibitor at Pulse 2012.

Author: Steve Thompson, NetEx (steve.thompson@netex.com)

Author: Steve Thompson, NetEx (steve.thompson@netex.com)

Link to the IBM Tivoli Storage Blog

Continuation of TSM 6.3 Replication testing over HyperIP

We recently had an opportunity to test IBM Tivoli Storage Manager (TSM) release 6.3 replication in our HyperIP lab. IBM just released this feature as part of their TSM 6.3 release in November. As stated in our previous Blog entry about TSM Backup testing, http://www.netex.com/blog/?p=175, it is important to first determine the overall limits of the native application before WAN acceleration.

Our test configuration included two HyperIP WAN Optimization virtual appliances, two windows servers running TSM 6.3, and a distance simulator for the WAN. The WAN simulator has the ability to inject packet loss, network latency, and other network conditions over various bandwidths that can degrade replication performance.

Like many other applications, replication is designed for the datacenter – to – datacenter movement of corporate data. Most replication applications perform very well when moving data over short distances, or in a metro environment. Customers running TSM Replication, in many cases, will need the remote site to be extended over the WAN, to an internal DR site, DR Service Provider, or Cloud Storage Provider. Any time distance is needed, network conditions such as latency and packet loss can significantly degrade application performance and become a huge impact on the throughput and application efficiency.

In our lab when latency and packet loss is experienced TSM native replication performance slowed by over 80% due to the typical inefficiencies of the TCP transport and not necessarily the fault of the TSM application. When HyperIP was added to the configuration, TSM Replication was able to achieve throughput equivalent to native performance and no delay. In fact HyperIP was able to help TSM Replication achieve near native line speeds at distances represented by 40 ms RTT, 80 ms RTT, 320 ms RTT all the way up to a 1 second RTT. TSM Replication over HyperIP proved to perform quite well at any distance, even with a significant amount of packet loss. In some cases HyperIP will accelerate TSM Replication by 6X. If 2:1 compression is possible then the TSM acceleration with HyperIP may approach 12X. Check it out for yourself. Download HyperIP by clicking on the big orange box above.

HyperIP Series – You Asked About WAN Acceleration of Encrypted Data…

A customer recently asked a question during a webcast, “How does HyperIP accelerate encrypted data?” The answer is, it depends.

In the case where the data was encrypted when it was written to disk, as is required in most financial institutions, encryption poses problems for WAN optimization controllers who need to inspect the data to perform their optimization techniques:

1. Compression and deduplication on the network can no longer be applied to a secured/encrypted packet, so data reduction algorithms are a moot point.

2. Data security is paramount, so movement or transport of that data over the IP network requires the datagram to be intact, not un-encrypted, then re-encrypted putting data security at risk. That now means data pattern caching in disk or memory is no longer applicable.

3. Payloads in the encrypted data block can be quite large requiring a data streaming technology to meet window requirements and aggressive RTO’s to be adhered to.

So how can HyperIP WAN Optimization Virtual Appliance from NetEx accelerate encrypted data?

If the data is encrypted prior to HyperIP compression won’t be possible but HyperIP will still be able mitigate network issues that degrade WAN performance. SSL data payload, certificates, and keys will all passed through HyperIP’s accelerated transport at or near wire speed. No matter the distance or latency, no matter the packet loss on the WAN, no matter the amount of network congestion or out–of-order sequence issues, HyperIP will maximize the throughput of the application.  This allows for complete data security, no modification of the SSL-encrypted block of data jeopardizing the integrity of the payload, transparent to both the application and encryption.

If the traffic is encrypted with a Taclane KG encryptor, HyperIP takes the unencrypted data from the source, optimizes the transport of that data to near wire speed, then compresses the data blocks to reduce traffic on the WAN, then hands that data to an encryption appliance. This is the preferred solution in most Department of Defense implementations, where specific encryption gear is required. This solution allows for complete WAN Acceleration of the block of data before it is encrypted. Global replication and backup of data now leverage HyperIP’s value and complete data security with government approved encryption on the WAN links.

HyperIP Series – You Asked About vMotions Over Global Networks….

Storage vMotion is different from “vMotion” where your storage stays the same and you change hosts, or “live storage vMotion” where the host is the same and you change the datastore. The storage vMotion I’m talking about is changing both the host and datastore. Storage vMotion works great on a LAN, but performing it over a WAN is a whole different story.

If you have ever tried to Storage vMotion your virtual machines over a WAN, I’m guessing it didn’t work so well. Most who try to do this are not able to. Why, you ask? Because over a WAN the native TCP stack on your ESX(i) hosts will start to back down. You’ll be lucky to complete a small storage vMotion over moderate distance in several hours, if at all. We have several customers who have tried this natively and have run into problems.  Now they use HyperIP WAN Optimization virtual appliance to mitigate performance issues making long distance vMotion a reality.

One of our customers, a large ‘financial’ enterprise level corporation, has been using HyperIP for their storage vMotions for well over a year now. When they first realized they had a need to migrate VM’s over their WAN, they would start a storage vMotion at the end of the day, expecting it to be completed when they came into the office the next day.  What they found is that in almost all attempts, the vMotion failed. They installed HyperIP and instantly they were vMotioning thousands of VM’s over their WAN between data centers. Last time we spoke to them, they had storage vMotioned over 1200 VM’s using HyperIP. They now do this on a regular basis. Before HyperIP they were lucky to get a single vMotion to finish.

Being able to move a VM at high speed anywhere in the world at anytime can have a profound impact on the way you do business and the way that your IT infrastructure is built and managed. You can build and configure VM’s locally at your corporate IT data center and HyperIP storage vMotion them out to where they need to go. If you are consolidating data centers or branch offices, you’ll need to move those VM’s over your WAN, or even a small internet link. If your organization is building dozens, hundreds, or thousands of VM’s, you’ll want to use HyperIP to move them.

In conclusion, HyperIP is downloadable, easy to implement, has a very small VM footprint, is inexpensive, and most important of all is absolutely necessary to storage vMotion your VM’s over a WAN. Download HyperIP now to start your free 30 day evaluation to take advantage your new ability to storage vMotion your VM’s anywhere in the world. Click the big orange box above to start the download process.

HyperIP Series – You Asked About TSM Testing with HyperIP..

We recently had an opportunity to test IBM Tivoli Storage Manager (TSM) Client to a TSM Server in our HyperIP lab. When doing any kind of application verification or performance testing it is important to first determine the overall limits of the native application with and without WAN acceleration.

Lab testing in an emulated environment is a good way to test applications because you can mimic certain network topologies and characteristics. In our case the HyperIP lab consists of two HyperIP WAN Optimization virtual appliances, two windows servers, and a distance simulator for the WAN. The simulator has the ability to inject packet loss, network latency and other network conditions over various bandwidths that can degrade application performance.

The main objective with any test is to try to validate whether the HyperIP can accelerate the application over various distances with varying latency and packet loss scenarios. Every application has its own performance characteristics and limitations. The same is true for WAN networks. They are about as unique as fingerprints.

Like many backup applications TSM was designed for the data center and performs very well when moving data short distances. Since we are truly becoming a global society is it important to be able to move data over longer distances which is clearly a requirement of cloud storage environments.

With the case of IBM TSM, we started off testing with a simple delay of 10 ms round trip time (RTT). At this relatively short distance TSM slowed by 80% compared to its native performance. This is typical application degradation due primarily to the inefficiencies of the TCP transport and not necessarily the fault of the TSM application. When HyperIP was added to the configuration, the TSM application was able to achieve throughput equivalent to native performance and no delay. In fact HyperIP was able to help TSM achieve near native performance rates at distances represented by 40 ms RTT, 80 ms RTT, 320 ms RTT all the way up to a 1 second RTT. This is a testament to how well TSM and HyperIP interoperate together.

Many applications have internal limitations such as outstanding operations, queue size, or queue depth that artificially restrict the application’s ability to maximize throughput. That was certainly not the case with TSM. TSM can certainly pump data over the network when it is not encumbered with TCP performance issues. When operating TSM with HyperIP, the two combined can sustain the same throughput rates whether running across town, across the ocean, or around the world. That was very impressive. TSM over HyperIP brings LAN-like performance to WAN-based remote backups.


A Blog about a Blog, Is that Allowed?

This weeks blog is about a blog post by Justin Paul, a systems engineer from SMS proTech who focuses on virtualization, storage, and backup applications.

Justin was recently working with a customer who was trying to replicate large amounts of data with limited replication windows and a limited amount of bandwidth.  The customer was using Veeam’s Backup & Replication software.

The big question they were confronted with was whether to add more bandwidth to meet the increasing data demands of replication or as an alternative leverage a WAN Optimization solution with the Veeam application in order to better utilize the existing WAN infrastructure.

Fortunately for the customer, they decided to try HyperIP WAN Optimization Virtual Appliance software with Veeam’s Backup & Replication software. The results speak for themselves.

Here’s a link to Justin’s IT Blog post, we thought it was well written and very informative.

Justin blogs are personal in nature and do not reflect the views of SMS proTech.   Can’t be all that bad for a guy who collects vintage Mustang cars, makes his own beer and is not a stranger to putting in long hours and hard work. Here’s more about Justin’s Bio.

We appreciate the blog….


HyperIP Series – You Asked About Multiple Interfaces….

Everybody tells me this is going to be easy so I’m finally going to try HyperIP. Now let me see again where is the HyperIP website. Okay I’ve downloaded the OVF file, now what? Oh yeah, I need to watch the HyperIP Support Tutorial videos on their website. Very cool, these HyperIP guys sure try and make it easy for us rookies. I like that.

Now what’s next? Oh install the Virtual Appliance on my virtual platform (VMware ESX or Microsoft Hyper-V) and start configuring. Makes sense. Wait a moment it looks like I need management and data ports. I only have one NIC on my server. Hmmm… what do I do now?

We’ve heard this type of story a few times and want to take this opportunity to clarify some interface points. HyperIP has two interfaces; a data and management port. The data interface is used for all traffic using the HyperIP tunnel and may also be used to manage HyperIP. The management port is available when a separate management network is required. If the management interface is used, be sure to set up routing in the HyperIP so traffic takes the proper path.

Okay I have my management and data ports configured and am having trouble sending any traffic, what’s up? The most common issue we’ve seen here is from the interfaces being on the same network. The management and data ports cannot exist on the same subnet. If a second subnet is not available, use only the data port in your configuration.

Okay I have my management port pointing out the WAN and the data port on the LAN, why aren’t the HyperIPs able to communicate? The HyperIPs only talk to each other on the data interfaces. No traffic flows between the data and management ports.

Okay I have the two interfaces configured on the networks that will be sending traffic across HyperIP and only some servers can communicate. Why is that? HyperIP acts like a one-armed router where traffic using HyperIP comes in, and is sent out, on the same data interface. The data interface will be used for servers and storage that will utilize HyperIP. If the HyperIP cannot be placed in the same network as the servers and storage, routes or access lists can be used in routers to direct traffic at HyperIP.

Alright I have both interfaces configured to the same VLAN and one NIC card. That should work shouldn’t it? The data and management interfaces cannot be on the same network. In this situation, only use the data interface for traffic and management. You will need to set user access to allow a browser on the data port.

Well I think that has answered my management questions.
Thanks very much HyperIP.


