Do you remember the 1973 Bruce Lee movie Enter The Dragon? The movie opens with a martial arts competition. The competition is fierce and brutal. During the competition, our hero discovers a dark underbelly of unsavory activity. As the fight to clean up the mess progresses, more and more challenges confront the good guys. The stakes are high and there is no room for failure.

This scene may also sound familiar if you have ever tried to deploy security or analysis appliances with TAPs using Command Line Interface (CLI) or a typical GUI with a hierarchical structure. At first, things don’t seem so bad. Perhaps you are attaching a sniffer to look at email traffic. No problem. You enter the string of commands to filter all traffic except email, connect the appliance, and done. Everything is working well until your boss comes in and says, “We need to monitor web traffic more closely.” Then he comes back in a half hour and says, “I am concerned about ransomware vulnerability. We also should add on some Data Loss Protection and Intrusion Prevention Systems. Complete network security is our top priority!”

You call your local VAR and purchase some of the best performing security appliances. Now, it is time to deploy and you realize you have already filtered out all the traffic downstream from the email analysis device you just installed. Now, none of the new appliances can see any of the packets they need to do their job. No problem, just reprogram the TAP.

This is where things become very interesting. With hierarchical devices, once you have filtered certain types of packets, you can not get them back. So now you have to take all your appliances and write a detailed mathematical plan. What appliances need to see what packets? Then create the hierarchy so that packets that are filtered out early are never required by another appliance downstream. Also, you don’t want to send too much information to the upstream appliances reducing their efficiency. This is a difficult and time consuming task that gets more complex as more appliances are needed.

You are smart, however, and work your way through it with a well thought out and very detailed filtering and port-mapping plan. After you deploy it and test for accuracy you will find some issues where you have blocked data that should have been passed. You re-write the plan and fix the bugs. Turn it all up and it works! As you are celebrating with a half-caf latte, your boss comes in and has an idea. “Here is a data sheet on a new appliance that actually learns traffic patterns and can help prevent attacks before they cause network damage. I want you to add that to our security stack.” You suddenly realize that you have to re-write your filter and port map plan from the beginning because the hierarchy must be pure end-to-end.

Enter the Drag ’n…or Drag-n-Vu™ that is. Network Critical has defeated the dreaded hierarchy. Through years of brutal research and development, Network Critical engineers have created a TAP and Packet Broker deployment plan that does all the math for you in the background. This new program provides independence from complex hierarchical commands with the simplicity of drag and click mapping.

With Drag-n-Vu™, there are no commands. There is no hierarchy. Instead, there is a clear visual map of the ports. The network administrator simply decides which network tool plugs into which port, then drags the cursor from the input ports to the output ports. Filters are simply created and stored so they can be dragged and dropped to whatever port combinations are needed. Best of all, the filters are independent. For example, if http traffic is filtered out in map number one but required in map number two…no problem. Different traffic types can be filtered and reused anywhere in the process and as many times as needed. This ingenious new development not only simplifies deployment planning and installation, it also allows for simple and fast changes. In the tech world, changes happen quickly so it is critical to be able to be able to adapt to changes with utmost efficiency.

Drag-n-Vu™ also improves accuracy, reducing the potential for mapping errors that can drop links or create bottlenecks. With simple drag and drop deployment, it is easy to see what traffic is going where so the plan is deployed with complete confidence the first time. In fact, the process is so simple, it actually can be managed by network administrators, freeing up engineers for other more complex tasks. This saves OPEX in a budget-conscious world.

Since the entering of the Drag-n-Vu™ by Network Critical, the dark and looming menace of hierarchical port mapping and filtering has been defeated. The bright and colorful graphical user map from Network Critical is the bright star of security and appliance deployment. You can see the trailer to the Drag-n-Vu™ movie at

Posted: 12/04/2017
