Aviatrix aims to bring multi-cloud networking, security, and operational visibility capabilities that enterprises customers require. Aviatrix software leverages public cloud provider APIs to interact with and directly program native cloud networking constructs, abstracting the unique complexities of each cloud to form one network data plane, and adds advanced networking and security features.
N/A
Cisco SD-Access
Score 8.9 out of 10
N/A
Cisco's Software-Defined Access (SD-Access) provides automated end-to-end segmentation to separate user, device and application traffic without redesigning the network. Cisco SD-Access automates user access policy so organizations can make sure the right policies are established for any user or device with any application across the network.
This product offers simple ways to manage network routing between public cloud, on-prem, and external network. It has built-in options to secure network traffic, as well as option to direct traffic to 3rd party security products for a more advanced traffic inspection. The core function works and is easy to operate. On the other hand, I am unable to give it more than 7-star because some useful features are lacking. This includes lack of customization in email alerting, IPS policy management, and temproarily admin-down of an established site to site VPN connection.
It's well suited in our corporate offices, where all our business users resides and where we can control all their accesses. What doesn't really fit well is when we have our branch fronts, where all the software domain access features aren't utilized to its fullest, due to the fact that customers and users don't really need to have all the security features that SDA provides.
With a few very easy steps to establish routing between AWS VPC
Easy procedures to establish site to site VPN connection with external parties.
Provide network access control on routing traffic using its own build-in firewall inspection or directing traffic to 3rd party NGFW for full stack inspection.
The core function of the product works very well. It really makes network traffic management easy in public clound, as well as crossing different public and private cloud platform.
It is difficult to start using the product due to its unfamiliar name and acronyms. ,The task should be accomplished in a specific order to ensure success
As far as my experience with SD-Access -I'd say things that can be improved are - better functionality with ISE, ease to understand licensing and better documentation for configuration (add-ons, etc), and licensing.
I rated the training an 8 because overall, it was well-structured, and the instructor was highly knowledgeable on the subject matter. The content was relevant, and I appreciated the clear explanations of complex topics. However, I felt that some sections were covered too quickly, making it difficult to fully absorb the information before moving on. Additionally, I would have liked more time dedicated to Q&A, as there were moments when I had questions but didn’t get the opportunity to ask them due to time constraints. Adding more interactive discussions or hands-on exercises could further enhance the learning experience and make it even more engaging
We initially tried using the native routing funcitons in AWS (transit gateway) and in Azure (virtual network). While those native options worked, it became difficult to opeate when we tried to impose security inspection on the routing traffic. This leads us to the Aviatrix solution.
Automation, pushing template-based configuration to multiple devices in one push saves time and manpower. Assurance helps trace issues related to devices, clients, and provide the troubleshoot as the best practices. Segmentation, with the use of the SGT tags, we are able to achieve segmentation and micro-segmentation securely.
Reduce labor hours for network admin to manage public clound network routing policy.
Build-in security features may be good enough for small/medium size companies, and thus saving money from full funciton NGFW solution.
The Cost-IQ feature enable one to capture traffic volume of each VPC. This provides one way for the enterprise to perform cost charge back to various business funcitons at the VPC level.