Aviatrix aims to bring multi-cloud networking, security, and operational visibility capabilities that enterprises customers require. Aviatrix software leverages public cloud provider APIs to interact with and directly program native cloud networking constructs, abstracting the unique complexities of each cloud to form one network data plane, and adds advanced networking and security features.
N/A
Trellix Network Security
Score 8.6 out of 10
Enterprise companies (1,001+ employees)
Trellix Network Security (formerly FireEye Network Security and Forensics products) combines network traffic analysis and network forensics for attack analysis .
This product offers simple ways to manage network routing between public cloud, on-prem, and external network. It has built-in options to secure network traffic, as well as option to direct traffic to 3rd party security products for a more advanced traffic inspection. The core function works and is easy to operate. On the other hand, I am unable to give it more than 7-star because some useful features are lacking. This includes lack of customization in email alerting, IPS policy management, and temproarily admin-down of an established site to site VPN connection.
It’s a dedicated Network Advanced Threat Detection and Prevention solution. Easy maintenance and low operating costs fit perfectly for SMEs. Variety of appliance selection makes NX the perfect choice for large enterprises. As it’s a dedicated solution with its own appliance, price is higher compared to NGTP add on solutions. FireEye is an ecosystem therefore when you’ve the EX or HX vice versa, you should be looking to NX. Otherwise, you’re missing the threat intel exchange on the network side reverse is the true. Sizing is important before the purchase, if you select a low end model for a busy network you lose your initial investment. For multiple NX deployments I highly recommend CMS. Without CMS you’ll lose the threat intel exchange and this will negatively reduce the risk scores.
With a few very easy steps to establish routing between AWS VPC
Easy procedures to establish site to site VPN connection with external parties.
Provide network access control on routing traffic using its own build-in firewall inspection or directing traffic to 3rd party NGFW for full stack inspection.
The core function of the product works very well. It really makes network traffic management easy in public clound, as well as crossing different public and private cloud platform.
We initially tried using the native routing funcitons in AWS (transit gateway) and in Azure (virtual network). While those native options worked, it became difficult to opeate when we tried to impose security inspection on the routing traffic. This leads us to the Aviatrix solution.
FireEye NX is a solid product. It gives you sustainable security throughout the organization. NX detection engines are more capable compared to others. Its catch rate is higher, FP rate is lower, [and] speed is awesome. NX can work for highly regulated environments with 1 way solution. Operation costs are much lower. Software quality is very good. It may have bugs, but these bugs do not compromise the security in general. SOC team loves the FireEye NX for its pinpoint detection capabilities. Local and partner support is exceptional.
Reduce labor hours for network admin to manage public clound network routing policy.
Build-in security features may be good enough for small/medium size companies, and thus saving money from full funciton NGFW solution.
The Cost-IQ feature enable one to capture traffic volume of each VPC. This provides one way for the enterprise to perform cost charge back to various business funcitons at the VPC level.
As [a] financial company on the digital markets, we need to be safeguard for 0days and targeted attacks. FireEye NX provides the best updated protection with its enhanced capabilities.
Security score based on detection/prevention metrics [is] very high ensuring the highest level of security.
APTs in our region successfully detected and mitigated by the NX.
For the ROI, in a six month period FireEye is paying off its [investment].
One negative thing, especially with increasing network bandwidths, [is that] you need to make [the] investment every two or three years.