Providing Out-of-Band Connectivity to Mission-Critical IT Resources

The Definitive SD-WAN Security Checklist for Enterprise Networks

sd wan security checklist

Software-defined wide area networking, or SD-WAN, has made it possible to efficiently control highly distributed WAN architectures using software abstraction and automation. SD-WAN adoption is increasing, partially due to the rise in remote work during the pandemic, with experts predicting a compound annual growth rate (CAGR) of 26.2% between 2022 and 2028. However, while SD-WAN solves a lot of remote, edge, and branch networking problems, it also introduces security concerns that must be addressed. This definitive SD-WAN security checklist highlights the most important challenges and provides solutions for overcoming them. 

The definitive SD-WAN security checklist

Keeping an SD-WAN architecture secure requires several features to be successful. It’s vital to consider this comprehensive list. 

1. Frequent security patching

Outdated operating systems create a significant security risk. According to a 2016 Voke Media survey, about 80% of breaches or failed audits could have been prevented by patching outdated software or updating device configurations. An SD-WAN router with an outdated OS is more likely to have vulnerabilities, and the longer it goes unpatched, the more likely a hacker is to find and exploit those vulnerabilities.

However, SD-WAN architectures are often multi-vendor and highly distributed, making it challenging for administrators to monitor for vulnerabilities and stay on top of patch schedules. There are two primary ways to overcome this difficulty:

  • Centralized SD-WAN management platforms provide a single pane of glass from which to monitor and update device software. The right platform is vendor-agnostic, so administrators can easily patch any and all vendor devices from one common interface.
  • Automated patch management software helps keep OSes up to date by automatically applying new updates based on a predetermined schedule. Some solutions even perform automatic vulnerability scans or can monitor environments for missing patches and apply new updates that fall outside of the usual patch schedule.

Your ability to keep SD-WAN device software secure ultimately depends on the vendor’s patch schedule. Some providers are sluggish to patch known vulnerabilities in their software, either because they think they can keep said vulnerabilities a secret or because they don’t want to dedicate the time and resources needed to keep the OS up to date. That’s why you should look for SD-WAN hardware and software vendors who are transparent about vulnerabilities and who work diligently to release frequent patches and updates. 

2. Zero Trust Provisioning

SD-WAN platforms are software-based, but they still require underlying networking hardware at each remote site for connecting to the enterprise network. Deploying this hardware can be difficult, especially when SD-WAN sites are in hard-to-reach locations such as offshore oil rigs, remote weather stations, or nations experiencing disasters or active conflicts. Often, organizations opt to pre-stage devices in their home office and then ship them to remote sites so they can avoid costly or dangerous travel.

Pre-staging creates a security risk because a pre-configured device could be intercepted by hackers and used to access the enterprise network. Zero Touch Provisioning (ZTP) reduces the need for pre-staging by deploying new device configurations over the network. ZTP-enabled devices provision themselves by using DHCP or TFTP to find and download configuration files, which means administrators can ship factory-default hardware that doesn’t contain any exploitable information about the enterprise network.

However, ZTP also introduces some additional security challenges. Once they’ve created the configuration file, administrators generally don’t monitor the entire automatic provisioning process, so there’s a chance that a mistake in the configuration file could create a security vulnerability that goes unnoticed. And, since one ZTP configuration file is usually applied to multiple devices, a potential security vulnerability could affect several systems or locations without anyone knowing. In addition, hackers could intercept the transmission of the configuration file over the network if the connection isn’t strongly encrypted.

These challenges are overcome with a secure ZTP solution that follows zero trust security principles. This type of solution is often referred to as “Zero Trust Provisioning,” and it includes hardware-based security like TPM, BIOS protection, encryption modules, and an onboard firewall which protects the software layer (secure boot) and management layer (two-factor authentication). In addition, the ideal Zero Trust Provisioning solution supports integrations with automated configuration management tools like Chef and Ansible which can be set up to test and monitor ZTP configurations for mistakes and security vulnerabilities.

Zero Trust Provisioning is a key part of the SD-WAN security checklist because it prevents branch networking hardware from being intercepted and used in a cyberattack. It also ensures that automatic provisioning occurs over a secure, encrypted network connection, and allows integration with configuration management tools to prevent errors from introducing additional vulnerabilities. 

3. Secure out-of-band access

Many organizations use out-of-band (OOB) management to configure, control, and troubleshoot remote network infrastructure. OOB management uses a separate management plane, so resource-intensive network management and orchestration workflows don’t affect the performance or reliability of the production network. This may involve using a jump box to access an OOB network, which is an entirely separate management network architecture that runs parallel to the production network. However, a simpler solution is to use an OOB console server to achieve the same goal without the hassle of deploying a separate architecture.

OOB management improves the performance and reliability of production networks, and provides an alternative path to remote infrastructure (typically via cellular modem) in the event of an ISP outage or a network device failure. The issue with OOB management is that jump boxes and console servers are attractive targets to hackers. If a malicious actor manages to compromise the OOB network, they’ll gain complete control over the remote infrastructure.

To keep SD-WAN devices and other remote infrastructure secure, it’s best to use an OOB console server with advanced encryption for both the hardware and the management connections. In addition, the OOB solution should include Zero Trust features like MFA (multi-factor authentication) and RBAC (role-based access control). Just like the SD-WAN hardware, the OOB device(s) should run a fully patched OS and support Zero Trust Provisioning. For even greater protection, choose an OOB solution that supports integrations with third-party security solutions like next-generation firewalls (NGFW).

A secure out-of-band management solution gives network administrators 24/7 access to remote infrastructure on a dedicated, encrypted network connection using hardened OOB console server devices. This ensures that hackers can’t use the OOB network to hijack production infrastructure while also giving administrators the ability to quickly recover from outages, hardware failures, and cyberattacks.

4. Cloud-based security technology

As we’ve discussed above, it’s possible to run SD-WAN solutions on hardware with onboard firewall features. However, these basic firewalls often lack the advanced functionality needed to protect enterprise networks from sophisticated cyberattacks, which is why most organizations also use some form of stateful firewall or NGFW that resides in a central data center. This works well for a single, centralized enterprise network, but the addition of remote sites can create performance issues.

For the centralized firewall to inspect and protect SD-WAN traffic, that traffic must be backhauled through the central data center, even if the request is ultimately destined for the web. This inefficient routing causes bottlenecks, performance issues, and even dropped connections for on-premises and remote users alike. The obvious solution to this problem would be installing physical or virtual firewalls in each remote location, but this is expensive and disruptive and creates more management complexity for network administrators.

A better way to protect remote traffic while improving performance is through the use of cloud-based security solutions, such as Security Service Edge (SSE). SSE relies on SD-WAN’s intelligent routing capabilities to separate remote traffic that’s destined for web, cloud, and SaaS resources. This traffic bypasses the firewall and is instead routed through a cloud-based security stack, reducing the load on the enterprise network.

Ideally, the SD-WAN solution will tightly integrate with the SSE platform. This combination of SSE security with an SD-WAN on-ramp creates what’s known as SASE, or Secure Access Service Edge. This is most easily achieved using vendor-neutral branch networking platforms which can host or integrate with a wide variety of SD-WAN and SSE solutions. An integrated SASE architecture ensures comprehensive security while providing remote users and systems with fast, reliable access to cloud resources.

Nodegrid checks every box on your SD-WAN security checklist

Only one remote network management solution provides everything you need to keep your SD-WAN architecture secure: the Nodegrid platform from ZPE Systems. Nodegrid’s vendor-neutral routers, such as the 5-in-1 Hive SR branch gateway, can directly host or integrate with your chosen SD-WAN solution. Whether you enable SD-WAN with a Nodegrid device or by using ZPE Cloud’s SD-WAN application, you’ll get seamless access, centralized management, and state-of-the-art security.

1. Secure, up-to-date SD-WAN device OS

Nodegrid’s branch gateway routers run on the vendor-neutral, x86 Linux-based Nodegrid OS, which is constantly monitored for vulnerabilities and frequently patched to ensure security. Plus, with the ZPE Cloud orchestration platform, you can monitor and update all your SD-WAN devices from one convenient management portal—even if that hardware comes from another vendor.

2. Zero Trust Provisioning for branch networks

All Nodegrid devices support Zero Trust Provisioning, and they can extend this capability to any third-party devices managed by Nodegrid. That means administrators can securely configure all the multi-vendor devices in a remote branch network without the need for travel or pre-staging. Nodegrid ZTP is considered Zero Trust because it protects the hardware, software, and management layers with advanced security features like:

  • Password-protected BIOS
  • Current cryptographic modules
  • SSO with SAML (Duo, Okta, Ping, and ADFS), MFA, and remote authentication
  • Geofence perimeter crossing detection
  • Onboard firewall, IPSec, and Fail2Ban intrusion protection
  • Fine grain RBAC with strong password enforcement

Nodegrid also supports integrations with automated configuration management solutions like Ansible, Chef, and Puppet, so you can ensure every device is provisioned correctly.

3. Gen 3 secure out-of-band management

Nodegrid services routers provide reliable, Gen 3 OOB management access to any connected devices, including those from other vendors. This access is protected by a patched OS, onboard hardware security features, and current encryption modules. Plus, Nodegrid’s hardware and software can host or integrate with third-party security solutions like NGFWs for comprehensive OOB security. 

4. An SD-WAN onramp to SSE

The Nodegrid branch networking solution provides the ideal SD-WAN on-ramp to leading Security Service Edge providers. That’s because Nodegrid is a completely open platform that can host or integrate with any SSE and SD-WAN offering to provide a single, unified SASE solution. This gives administrators complete control over every aspect of branch network management and SD-WAN security from one convenient portal, reducing complexity and improving your security posture at the same time.

Wondering how ZPE’s Nodegrid solution checks all the boxes on your SD-WAN security checklist?

Contact ZPE Systems today to learn more

Learn More

What Is Hybrid Cloud Infrastructure: Expectations vs. Reality

what is hybrid cloud infrastructure

Hybrid cloud deployments allow you to combine the best features of public cloud, private cloud, and on-premises infrastructure. But what exactly goes into hybrid cloud infrastructure, and how is it achieved? In this blog, we’ll compare the expectations of a hybrid cloud to the realities of implementation and provide advice on overcoming these challenges.

What is hybrid cloud infrastructure?

Hybrid cloud infrastructure involves using a combination of public cloud, private cloud, and on-premises data center environments. True hybrid cloud architecture allows you to move workloads back and forth among these environments safely and securely.

  • A public cloud is what most people think of when they hear cloud computing. Public cloud services are decoupled from the underlying infrastructure and delivered as a web-based application or platform. The actual compute resources are shared amongst many other customers. Examples of a public cloud include Microsoft 365 and Google Apps.
  • Private cloud infrastructure is owned and managed by a third-party provider, but other customers do not share the hardware you use. You rent dedicated storage and compute resources, but have no physical access to or control over the infrastructure. Examples of a private cloud include Microsoft Azure and Amazon Virtual Private Cloud (VPC).
  • An on-premises data center is a data center that your organization has complete control over. It may or may not be on the same premises as your headquarters office. Not all hybrid cloud infrastructures include on-premises environments—only public and private clouds are required.

The public cloud offers many benefits for enterprises, such as scalability and cost savings. However, organizations frequently need greater control over certain data and resources. For example, any company working with healthcare information, or providing services to the federal government, must follow strict privacy and security regulations. That’s why many organizations opt to keep some of their resources in on-premises data centers or private clouds.

That said, keeping these resources isolated from your public cloud services, applications, and data is not always feasible. There’s a need for interoperability and orchestration of workloads among mixed architectures. In a hybrid cloud infrastructure, there is a virtual service that acts as a managed “bridge” between different environments. This allows you to move workloads, applications, data, and other resources around as needed to ensure peak performance without compromising security.

Hybrid cloud infrastructure: expectations vs. reality

The expectation for hybrid cloud infrastructure is that all of your systems, services, and applications will work together seamlessly. Your data and other resources will be portable, so you can move them from one cloud to another without compatibility issues or other headaches. Most importantly, you’ll have a centralized, web-based platform to orchestrate workloads across your heterogenous environment. The reality of hybrid cloud, however, is often much more complicated.

Vendor lock-in

One major hurdle to implementing a hybrid network environment is closed ecosystems. Vendor lock-in can prevent your legacy on-premises solutions from interoperating with cloud hardware and software, and vice-versa. Data and applications designed for traditional infrastructure may be incompatible with cloud platforms. And not only do these systems all need to communicate and work together, but you also need an orchestration platform that can dig its hooks into disparate vendor solutions and control them equally.

Issues with vendor interoperability could force you to rebuild your entire stack just to enable hybrid orchestration. To get around this expensive and time-consuming challenge, you need a hybrid cloud infrastructure orchestration platform that’s based on an open architecture for true vendor neutrality. This will allow you to manage workloads across cloud and legacy environments without replacing the systems and software already in place.

Infrastructure complexity

Hybrid cloud infrastructure reduces the number of physical servers and storage devices you’re responsible for, so you might assume this will reduce the complexity of your network operations. This isn’t necessarily the case. The virtual and physical hardware responsibility is shifted to the cloud vendor, but your team will still need to know how to configure, monitor, and maintain all your cloud services.

In a hybrid cloud infrastructure, there are often many different platforms from different vendors. That means you need people who are experts in all these systems. Plus, you’ll also need a more complex network architecture to support a seamless hybrid cloud environment. That often means purchasing more boxes from more vendors, which your team must also learn to configure and maintain.

One way to reduce the complexity of your hybrid cloud infrastructure is by consolidating your networking stack. For example, you can use high-density serial console switches that provide out-of-band (OOB) management interfaces, network failover, environmental monitoring, and network switching. Similarly, you can look for modular, multi-function devices that allow you to create a custom box that includes all the specific hardware and functionality you need.This will reduce the number of devices in your rack and provide administrators with a single platform to manage all this functionality.

Spiraling costs

Cloud services are often less expensive to deploy and scale than on-premises infrastructure. Instead of a large up-front cost to purchase and install new hardware solutions, you typically pay a smaller recurring fee. When you need more resources, you simply upgrade your services for additional cost without needing to buy and configure more hardware.

The issue is that these recurring fees can begin to snowball over time, especially if you keep increasing your contract. Many cloud services often come in bundles or packages, meaning you can’t just pick and choose the functionality you need a la carte. So, you could end up paying for features you don’t even need.

Plus, you’ll incur additional costs if you need to rebuild part or all of your on-premises stack to enable hybrid cloud orchestration. The same goes for the networking technology that’s required for hybrid integrations. These expenses can be reduced by following the advice above—using a completely vendor-neutral hybrid cloud orchestration platform. Plus, consolidating and streamlining your infrastructure in as many ways as possible, such as with the hardware itself, but also with the software and management layers. For example, an OS allows you to easily/seamlessly integrate many different solutions, and a management platform allows you to manage everything from a normalized UI—rather than having to spend money on many different specialists.

Implementing a hybrid cloud infrastructure is often more challenging than organizations expect. However, by using vendor-neutral solutions and consolidating your tech stack, you can avoid vendor lock-in, reduce the complexity of your infrastructure, and keep costs in check.

Ready to simplify hybrid cloud infrastructure?

The Nodegrid infrastructure management solution from ZPE Systems enables true hybrid cloud orchestration. Nodegrid’s open architecture and vendor-neutral hardware can get its hooks into all your legacy, on-premises, and cloud solutions, so you have total control over your hybrid environment. With the ZPE Cloud management platform, you can monitor and orchestrate your entire infrastructure from behind one pane of glass.

Plus, Nodegrid’s consolidated networking hardware can help you reduce the complexity of your tech stack while still delivering all the features and functionality you need. Some of the world’s biggest tech companies are benefiting from this, by using Nodegrid to deploy and manage their hybrid infrastructures.

What is hybrid cloud infrastructure, and how can Nodegrid help you achieve it? 

Contact ZPE Systems to learn more.
Contact Us

What Makes a Gen 3 Serial Console?

NSCPDDC

The Gen 3 serial console is the latest innovation in out-of-band management.
But what exactly is it, and where did it come from? In this post, we’ll briefly cover the basics of serial consoles and why you need them, and then dive into the evolving needs that brought about the Gen 3 serial console.

What is a serial console?

A serial console is a multi-port device that you connect to the console port of other devices. This allows you to gain management access to each device via one serial console, instead of having to individually connect to each separate device.

If you have a data center or other location with lots of IT equipment, a serial console is a must-have. It doesn’t just give you convenient access to your device stacks; the serial console is also a foundational component of out-of-band management. Out-of-band means having a completely separate network that you can use to manage your equipment, instead of having to rely on your main production network.

Why do you need out-of-band management?

Imagine relying on your production network to troubleshoot and manage your device stacks. This jeopardizes your security since it exposes you to any bad actors lurking on your network, and significantly increases this risk if directly connected to the Internet. Security risks aside, how are you going to remote-in to a server or router if your network suddenly goes offline?

With out-of-band, you have a management network that’s completely separate from your production network. This drastically shrinks or eliminates your exposure to threats, and also lets you access your assets even if there’s a main network outage. If a server needs to be rebuilt or a router needs to be power cycled, out-of-band lets you gain access through your serial console to perform these tasks independently of your production network.

Out-of-band has been around for a couple decades, and is now going through another evolution in which its requirements are changing. We’ll cover these evolving needs in the next sections, but here’s a quick breakdown to give you an idea:

ZPE – Serial Console Gen
Each generation requires a serial console that brings additional capabilities to network management. Now let’s take a look at these evolving needs, starting with Gen 1.
Gen1

Gen 1 Serial Console:
All About Remote Access

The main requirement of Gen 1 out-of-band was the need for remote access to infrastructure. Most vendors built a serial console to provide this simple connectivity.

Gen 1 serial consoles are suitable for gaining remote access to devices, but this is where the benefits begin to drop off substantially. That’s because they offer minimal scripting capabilities (if any at all), which means you’ll still spend plenty of time manually provisioning and troubleshooting your environments. When you want to automate fixes and repetitive work — like pushing firmware updates or configuration changes — this generation of serial console will leave you seriously underequipped. And when it comes to security measures and the growing need for Zero Trust Network Access (ZTNA), the Gen 1 simply lacks the internal components and open architecture required to enable Zero Trust controls.

The Takeaway:

Gen 1 serial consoles do a good job eliminating truck rolls and on-site troubleshooting. But if you’re looking to reduce your workload through automation or meet the latest requirements for Zero Trust Security, the Gen 1 won’t get you there.

Gen2

Gen 2 Serial Console:
More Automation, Less Hands-on Troubleshooting

With admins and engineers able to remotely access their infrastructure, it became natural to wonder, “What added features could make the job easier?” This brought about a new set of out-of-band requirements focused on automating troubleshooting, and the Gen 2 serial console was born.

The Gen 2 features the same remote access capabilities as its predecessor, but brings more value to troubleshooting by expanding the automation toolkit. This serial console generation enables scripting and automation for more than just basic tasks. For example, if your servers were manually installed and configured but you recently discovered a bug, the Gen 2 allows you to script a fix and automatically push a new bug-free configuration across the environment. On the more advanced side, you could automate provisioning, feature delivery, and device recovery — but only if you have the right amount of resources and tenacity at hand.

Although Gen 2 serial consoles offer more automation capabilities than Gen 1 devices, most vendors limit how far you can extend your automation. Many of these serial consoles feature closed architecture that integrates only with specific vendor devices or APIs, meaning your automation eventually stops at some point. They also require you to learn certain programming languages like Python, or support only a limited set of workflows or Ansible playbooks.

On top of this, many claim to have added security features, but this can give you a false sense of security. Some use the Trusted Platform Module (TPM) but don’t properly integrate it, leaving you without a secure root of trust that makes you vulnerable when implementing new hardware and software. Vendors also often stop supporting their devices after a few years, meaning you don’t get an updated OS or the latest security patches.  Because Out-of-Band devices have access to your entire production environment, an adversary can take over of our OOB also gives them access to your in-band systems and ultimately your business.  Therefore the correct security implementation is even more important requirement in OOB deployments as it has a major impact on business continuity. 

The Takeaway:

Gen 2 serial consoles help you with remote troubleshooting and can reduce some of your manual work through automation. But if you strive to maximize uptime, site reliability, and security, the Gen 2’s rigidity and vendor lock-in will only hold you back.

Gen3

Gen 3 Serial Console:
End-to-end Automation, Security, and Control

Many enterprises realize that Gen 2 serial consoles don’t provide the flexibility for them to automate what they need to. There’s growing business demand for availability (i.e. everything needs to work 99.999% of the time), and also more attack vectors that hackers can exploit. In short, the network simply needs to work — from installation through refresh. That’s why we worked with many enterprises and the world’s tech giants to gather the latest out-of-band requirements and create a blueprint for the Gen 3 serial console.

The Gen 3 serial console comes with beefed-up capabilities in remote access and automation, along with added layers of security that enable true ZTNA. Here’s how this serial console meets Gen 3 out-of-band requirements:

Full Pipeline Automation

The Gen 3 serial console helps you minimize human intervention using full pipeline automation. This can only be achieved using an open architecture and rich API libraries. With a Gen 3 serial console, you can automate deployments with Ansible, Chef, Puppet;  run own own tools in VM, Docker or Kubernetes; create complex workflows using any APIs you need; and interoperate with other systems in your enterprise ecosystem.  Gen 3 addresses the requirements for Immutable infrastructure and NetDevOps.

The Takeaway:

Gen 3 lets you automate what you need not just what you can, without vendor lock-in getting in your way. You can use your existing expertise along with human-readable commands, instead of having to learn new programming languages and skills. Faster response times and fewer failures makes it easier to achieve 99.999% availability or more.

Enterprise-grade Security

The same ZTNA principles need to apply to the OOB infrastructure both at HW, SW and management level.  Gen 3 system have enterprise-grade security features like UEFI secure boot, encrypted disk, properly implemented TPM 2.0 security, and ongoing swift patches. These give you a sturdy foundation on which to build your automation, so you can maintain a secure root of trust, segment your network, and integrate the variety of Zero Trust controls you need.

The Takeaway:

Gen 3 security seals backdoor vulnerabilities by checking the integrity of hardware and software that you integrate. Its open architecture also allows you to implement Zero Trust policy tools, Identity and Access Management solutions, and safeguards of your choice.

In-depth Remote Control

Gen 3 serial consoles enable out-of-band that gives you complete access to all connected equipment. This includes the typical servers, switches, and routers, but also PDUs, IPMI devices, environmental sensors, and other physical or virtual assets. The Gen 3 can host all the tools your automation needs for virtual remote presence and also serve as your crash cart when humans want to log in.  Centralized cloud management and out-of-box playbooks also helps Gen 3 enable true zero trust provisioning of entire environments.

The Takeaway:

Gen 3 enables remote out-of-band control of your entire infrastructure, as if you were physically at each location. And it serve as the right device for your automation journey by being the first device in the rack as the bootstrapping target, and also as your crash cart for automated or manual troubleshooting and management beyond Day 0.

Access our trade-in program and switch to Gen 3


Our trade-in program gives you money back for every device you trade in. If you have devices from Avocent, Cisco, Opengear, or other vendors, you can benefit from upgrading to Gen 3 through this program:

  • Get money back for every device you trade in
  • Improve uptime and cut workloads with Gen 3 out-of-band remote access and automation
  • Bonus: Get access to ZPE Cloud for intuitive, browser-based global fleet management

Watch agile networking in action with these Nodegrid demos

title_demoreel

Watch agile networking in action with these Nodegrid demos

 

ZPE® Systems Network Solutions Architect Rene Neumann shows you how easy it is to enable agile networking. See Nodegrid and ZPE Cloud first hand with our collection of demo videos. You’ll learn how to:

 

  • Use true zero touch for automatic deployments
  • Fully set up environments using rich orchestration
  • Remotely configure and manage edge workloads

Demo: Deploy Networks Fast with ZPE Cloud’s Zero Touch Provisioning

Demo: Fully Provision Edge Network Workloads with Nodegrid

Demo: Orchestrate Branch Network Devices Using Nodegrid

ZPE Systems Announces Nodegrid Serial Console Plus, a High-density, Cellular-enabled Serial Console for Datacenters and Critical Remote Locations

NSCP2
NSCP

Fremont, CA, June 22, 2021 – ZPE Systems adds to their lineup of datacenter infrastructure management solutions with the Nodegrid Serial Console Plus (NSCP). Like previous generations of Nodegrid Serial Console, the NSCP is a high-density appliance that streamlines infrastructure management at scale, now with the added benefits of built-in 5G/4G LTE cellular and Wi-Fi for increased availability. Organizations can stop juggling separate cellular and out-of-band devices, and can instead get these capabilities in one NSCP device.

Featuring up to 96 serial ports, built-in 5G/4G LTE and Wi-Fi capabilities, 2 SFP+ and 2 GbE ports, and Intel x86-64bit CPU, the NSCP gives network admins, service providers, and customers reliable, centralized management of their large-scale datacenter environments and critical remote infrastructures.

The world’s largest tech and financial companies already use the Nodegrid Serial Console Plus, and organizations implementing the NSCP can expect secure deployments using the hardware-encrypted disk; automated and simplified management that scales to millions of nodes; and increased availability through optional Wi-Fi and 5G/4G LTE backup connections from their choice of carriers.

“Nodegrid Serial Console Plus is the perfect solution for adding resilience to datacenters, colocations, and critical remote infrastructure locations,” says Arnaldo Zimmermann, Co-founder and CEO of ZPE Systems. “Our customers — including the largest companies in the world — love how easy it is to deploy one solution that gives them everything needed for refreshes or new installs. There’s no shopping for additional failover or out-of-band devices. The NSCP puts all that into a single, 1U box.”

NSCP is four times faster than the previous generation of Nodegrid Serial Console, and includes Nodegrid OS v5.2, the latest version of ZPE’s secure, Linux-based operating system.

Nodegrid OS v5.2 automates scaling with support for zero touch provisioning and containerization using Docker, Kubernetes, and LXC containers. The operating system also accommodates failover and out-of-band management through a variety of link types, including via the built-in 5G/4G LTE module. Nodegrid OS v5.2 improves upon previous releases with features that include:

  • Flexible automation via Ansible Server native integration, with support for Ansible, Chef, Puppet, Python, and RESTful scripts in addition to CLI options
  • Added security via enhanced UEFI Secure Boot with self-encrypted disk in all platforms
  • Easier extensibility via improved management of guest operating systems, NFV layer, and Docker containers
  • More traceability via geofencing, with self-guard notifications and actionable protection
  • Better connectivity via support for WireGuard tunnels, in addition to IPsec
  • Improved accessibility via new cloud applications available on ZPE Cloud

Nodegrid OS v5.2 also seamlessly integrates with the company’s management products: Nodegrid Manager, for centralized control of datacenter clusters; and ZPE Cloud, for secure, cloud-based management of distributed remote networks.

Nodegrid Serial Console Plus and Nodegrid OS v5.2 are now available. To place an order or learn more, visit the Nodegrid Serial Console Plus product page.

About ZPE Systems, Inc.

ZPE Systems frees enterprises from today’s networking challenges.

Nodegrid’s Intel-based serial consoles & modular services routers deliver power to datacenter & branch applications, while the Linux-based Nodegrid OS replaces vendor lock-in with limitless flexibility. With ZPE Cloud for fast & secure provisioning, this platform streamlines networking using virtualization, prevents downtime using automation, and offers convenience via remote management capabilities.

Intel-based serial consoles & modular services routers deliver unparalleled power to datacenter & branch applications, while the Linux-based Nodegrid OS replaces vendor lock-in with limitless flexibility. With ZPE Cloud for fast & secure provisioning, it’s the only networking platform to streamline the stack using virtualization, prevent downtime using automation, and offer convenience using in-depth remote management capabilities.

ZPE collaborates with best-in-class technology partners, to add value by integrating with SD-WAN, firewall, IoT, and other solutions. The world’s top companies trust ZPE Systems to provide advanced out-of-band management, Secure Access Service Edge (SASE) platforms, and SD-Branch networking.

Top companies trust ZPE Systems to provide advanced out-of-band management, Secure Access Service Edge (SASE) platforms, and SD-Branch networking.

ZPE Systems is based in Fremont, California with offices worldwide. Visit ZPE Systems website at
www.zpesystems.com.

ZPE Systems Announces the New Edge Transformation Partner Program

Edge Transformation Partner Program

Fremont, CA, March 31, 2021 – ZPE Systems, Inc., a leading innovator of network devices and cloud-based infrastructure management solutions trusted by the world’s top companies, officially launched the Edge Transformation Partner Program. This program is designed for enterprise solution providers and integrators interested in differentiating their offering for distributed branch, edge, campus, and colocation applications.

In order to expand an already growing partner ecosystem, this program features a drastically different engagement model and incentive structure to help partners build a profitable Nodegrid practice.

According to ZPE Systems’ CEO and Co-Founder Arnaldo Zimmermann, “Together, Palo Alto Networks virtual’ firewalls and our Nodegrid SR solutions give customers a secure and streamlined infrastructure, with centralized management that puts everything in one place — firewalls, servers, routers and even power controls.”

ZPE Systems is a customer first culture, so driving partner and customer success is the cornerstone of the Edge Transformation Partner Program. ZPE Systems emphasizes partner quality over quantity, with recruiting practices based on technical competency and strategic commitment. In return, partners leverage proven differentiators for cloud and edge networking, and can deliver customers the highest ROI.

As enterprises continue to expand beyond the data center, they must retire legacy solutions and optimize performance at edge networks. ZPE Systems’ Nodegrid platform helps partners modernize customer networks, with all-in-one solutions that are easy to deploy, secure, and manage — a growing requirement at the edge. Delivering the best ROI is a top priority, and partners can unlock endless value-add opportunities using Nodegrid’s modular hardware, extensible software, and integrated ZPE Cloud platform.

Partners can take advantage of emerging, best-in-class technologies thanks to ZPE Systems’ strategic alliances. These include partnerships with industry leaders such as Intel, Palo Alto Networks, Cisco, VMware, and others who help guide networking into the future.

“Our channel strategy is to recruit a small number of solution providers and strategic partners who are interested in developing their brand and capabilities around ZPE Systems’ Nodegrid ecosystem,” says Steven Jehring, ZPE Systems’ head of Channel and Strategic Partners. “Our priority is to create the best customer experience, and our enterprise edge platform makes this simple. It enables solution providers to offer complete implementations that are fully integrated with leading technologies from our strategic partners and alliances.”

For complete details of the Edge Transformation Partner Program, or to submit an application, please visit partners.zpesystems.com.

About ZPE Systems, Inc.

ZPE Systems frees enterprises from today’s networking challenges.

Cumbersome environments, frequent downtime, and inefficient management are no match for ZPE Systems’ Nodegrid, a vendor-neutral platform that lays the groundwork for open networking. Created by visionary engineers, Nodegrid’s patented hardware, software, & cloud offerings empower companies to transform their networks into business value creators.

Intel-based serial consoles & modular services routers deliver unparalleled power to datacenter & branch applications, while the Linux-based Nodegrid OS replaces vendor lock-in with limitless flexibility. With ZPE Cloud for fast & secure provisioning, it’s the only networking platform to streamline the stack using virtualization, prevent downtime using automation, and offer convenience using in-depth remote management capabilities.

ZPE collaborates with best-in-class technology partners, to add value by integrating with SD-WAN, firewall, IoT, and other solutions. The world’s top companies trust ZPE Systems to provide advanced out-of-band management, Secure Access Service Edge (SASE) platforms, and SD-Branch networking.

Based in Fremont, California, and with offices in Ireland, India, and Brazil, ZPE Systems is ready to help enterprises take the work out of networking.

Visit the ZPE Systems website to explore Nodegrid.
www.zpesystems.com