Please wait while the page is being loaded Skip this advertisement >
Sunday | 7 September, 2008
ARN
Riverbed adds optimization of SSL traffic
Riverbed adds SSL support to its Steelhead WAN optimization appliances
Tim Greene (Network World) 02 March, 2007 11:10:24

Related Stories
  • +

    ARN's A-Z guide to networking 19 December, 2007 14:50:54

    As business needs change, so do the requirements for the business backbone. ARN looks at networking trends and technologies and reports on predictions for 2008 and beyond.
  • +

    Review: Software push the WAN performance envelope 18 January, 2008 10:36:19

    Version 1.0 of the software client brings huge performance gains to CIFS file transfers, though HTTPS and NFS are not supported; Version 4.1 of the site-to-site solution shows overall performance improvement over Version 3.0, while adding key features, including HTTPS support
    I sometimes wonder why there aren't any movies made about IT superheroes. Sure, there's always Superman (able to leap tall buildings in a single bound) and Batman (the caped crusader), but what about WANman -- the IT superhero that accelerates high-latency traffic and saves the company from additional Internet bandwidth costs? Well, the tights and cape might not go over well (except on casual Fridays), but any IT staffer that can give enterprise users more performance is well on their way to superhero stardom.
  • +

    The interconnectedness of things 07 November, 2007 11:59:38

    Server-based applications, remote access and mobility are just three trends upping the ante for the long-suffering backbone that links it all together.
  • +

    Networking's greatest debates in the Data Center 29 October, 2007 07:34:19

    All time classic debates include Mac Vs PC, Tape storage vs. disk storage and AMD vs. Intel
    A look at the greatest all time Data Center controversies in the history of the networking industry.
  • +

    IPv6 Will matter to the enterprise in five years 10 November, 2007 08:30:12

    Routing guru Jeff Doyle says there's no need to move to IPv6 now, offers design tips for OSPF nets, discusses Layer 2 vs. Layer 3 routing and shares more advice with attendees of his live Network World chat.
    Welcome to Network World Chats. Our guest today is Jeff Doyle, celebrity author, Cisco Subnet blogger and networking guru. He has come prepared to answer your questions on all things routing.
Additional Resources
ARN Library

Newsletter Subscription

Sign up for our ARN newsletters!
The premier provider of daily news to the IT channel, covering business, technology, products, and services.
RSS Feeds

Riverbed Technology is adding SSL support to its Steelhead WAN optimization gear, making it possible to accelerate a potentially large volume of network traffic that the equipment couldn't get at before.

With an upgrade of Riverbed's RiOS software, the Steelhead appliances terminate SSL sessions, optimize the traffic, then re-encrypt the traffic as SSL. Before, the devices did not terminate SSL sessions so they could not access the payload to optimize it, the company says.

"There's a lot of encrypted traffic out there," says Zeus Kerravala, an analyst with the Yankee Group, and it is increasing. Since traffic is encrypted because it is considered important, not optimizing it could slow down a business's most important transactions, he says.

As SSL traffic increases, the accelerating effects that WAN optimization gear has will decrease unless the equipment can proxy SSL sessions and optimize the traffic, Kerravala says.

Blue Coat Systems proxies and optimizes SSL traffic, and Juniper Networks says it has plans to add SSL support to its WAN optimization appliances.

Riverbed says it protects SSL keys and certificates that reside within servers by ensuring they don't leave the data center. The certificates and keys are transferred to a Steelhead appliance in the data center, and it intercepts SSL requests headed for the servers. It then establishes SSL sessions with another Steelhead applianceĀ across the WAN using temporary session keys. The two Steelhead devices talk to each other, the data center-side Steelhead device talks to the servers and the remote appliance talks to client machines trying to access the servers.

Also with the RiOS 4.0 software upgrade Steelhead appliances improve the performance of HTTP traffic by more efficiently retrieving objects that make up Web pages that have been requested before. When a page has been requested through a Steelhead appliance, it stores what objects are needed to build the page. On subsequent requests for the same page, the device asks for groups of objects all at once rather than one after another, saving the time it takes to gather all the necessary objects. This works for HTTP/S traffic as well.

Riverbed claims this boosts the speed of HTTP traffic between seven and 20 times more than RiOS 3.0 software did.

RiOS 4.0 introduces a new technology called Maximum Speed TCP, or MX-TCP, which can ensure that large bandwidth WAN links and links transferring large amounts of data are used efficiently. Standard TCP builds slowly up to maximum speed then drops off when it encounters congestion, then builds up slowly again, making maximum use of bandwidth difficult.

MX-TCP uses Steelhead QoS capabilities to dedicate a guaranteed amount of bandwidth on a connection to certain traffic. The devices then start sending at that maximum bandwidth immediately, rather than building up to it gradually as standard TCP does. The Steelhead appliances also manage the traffic going over the dedicated bandwidth and work in retransmissions of lost packets, the company says.

Riverbed customer Wright-Pierce, an engineering firm, uses QoS upgrades in RiOS 4.0 to limit bandwidth available for sending particularly large files from certain servers. Large aerial color photos, for example, could clog up the T-1 line between headquarters and a branch, making it difficult to do any other business over the link until the photo passed, says Ray Sirois, the firm's IT manager.

The QoS mechanism can limit bandwidth per IP address, he says. "I could do this with QoS on my Cisco routers, but it's just much more complicated," he says.

Blue Coat addresses video

Meanwhile, Blue Coat is making alliances with video vendors so its equipment can prioritize corporate-sanctioned video based on authorization issued by the person publishing the video on the network. Partners include Media Publisher and Jubilant Technologies. Blue Coat gear can then prioritize video, to give sanctioned traffic priority, throttle back unsanctioned video and block forbidden video, the company says.

In other WAN acceleration news, Expand Networks is announcing that infrastructure vendor Huawei-3Com will license Expand's software and sell it on router blades by the end of the year.

Market Place

ARN Member Login

 
Panel Sessions
  • ARN Panel Sessions: Day 3

    The last of our panel sessions recorded live at CeBIT 2008. Today, the topic is storage. Data is growing at an enormous rate, so what does the future hold?

Play
ARN news Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

Download the Freeform research report on high availability and disaster recovery and sell more effectively in this space

A new research report from Freeform Dynamics, 'Risk and Resilience' reveals customer pain points as a result of application downtime. The reality is that today's global businesses cannot tolerate downtime for essential applications yet many do not have an effective solution in place. This creates an opportunity for high availability and disaster recovery solutions. To understand more about this opportunity download your free copy today.

Sponsored Links