Media
FDMG Cuts Costs, Revolutionizes Mobile Experience by Replacing MPLS and Mobile VPN
Separating WAN from Remote Access No Longer Makes Sense for FDMG
For years, enterprises connected locations via wide area networks (WANs), and remote users via concentrators and other remote access technologies. Keeping networking and remote access separate might have made sense when offices were the rule, and mobility was the exception, but in todayβs mobile world, such distinctions only complicate mundane IT tasks. Just ask Jerry Cyrus.
As the technical team leader and information security officer at FDMG, Cyrus knew all too well the complexities and costs of separate remote access and networking solutions. FDMG had many journalists working in the field as well as physical locations. Separate security policies were required for fixed and mobile users; user provisioning was also cumbersome.
And then there were the cost and scaling limitations of MPLS and, for that matter, remote access concentrators. MPLS bandwidth is notoriously expensive, particularly for multimedia companies such as FDMG, where stories involve video and other large data formats.
As for remote access, Cyrus was generally pleased with the concentratorβs functioning but tired of the concurrent-user problem. βWe would have 50 concurrent users, and once you wanted to add that 51st, you were stuck,β he says.
Cyrus could have upgraded the concentrator, but that would have impacted the business.
βWeβd have had to take down the concentrator for about two hours, which wouldnβt have sat well with journalists filing breaking stories from the field,β he says. βTwo hours is a lifetime for them. In the past, many drove to one of our offices just to work β not a very good way to experience IT.β
Instead, Cyrus realized that solving both WAN and remote access problems would reduce costs and a whole lot more. βBy consolidating security management, we could give users a better mobile experience and simplify firewall and security system operations.β
FDMG Evaluates Cato Cloud
Cyrus considered replacing MPLS with an Internet-based, site-to-site VPN. That would have lowered his bandwidth costs, but it would also have been a βbig head-breaker,β he says. βIn some cases, weβd have to upgrade concentrator hardware; in others, weβd have to set up new firewalls, configure the necessary tunnels, and deal with a lot more headaches.β
Cyrus had heard how Cato Cloud converges security services, SD-WAN, and mobile access onto an affordable MPLS alternative. With Cato Cloud, he could connect and secure his entire enterprise β offices, mobile users, and cloud resources β with one seamless network.
βAfter doing some research, I knew Cato Cloud would fit right in,β he says.
But Cyrus had to deal with internal concerns about working with a new company. βAt first, people were a bit scared of moving forward with Cato Cloud,β he says. βThey were familiar with vendors, such as Palo Alto and Cisco. Cato was new to them. After several conversations with Cato and showing the product, people became much more comfortable.β
Catoβs ability to be rolled out incrementally also helped Cyrus address those concerns. He started small, proving viability by adding a Cato Socket, Catoβs zero-touch SD-WAN appliance, in the Amsterdam hub and connecting a few users with Catoβs mobile VPN client. Both Socket and the mobile client automatically connect to the closest Cato point of presence (PoP), where the Cato software secures, optimizes, and dynamically directs traffic to the Internet or the optimum path across the Cato Cloud network.
Having validated datacenter access, Cyrus connected an internal AWS site to check Cato Cloudβs connectivity. Once successful, he began converting production sites to Cato. Branch offices with more than ten users received a Cato Socket; freelancers and other external users were equipped with Catoβs mobile client.
FDMG Converges Security, Mobile Access, and MPLS with Cato Cloud
With Cato, site installation has been fast and easy. βCato gives me βno-hassle setup.β I connect the Socket, and weβre online and secured,β he says. βI donβt have to configure firewalls, establish dozens of security rules, or anything.β
Moving sites has also become trivial. βIβm going to be moving one office to another floor, and the only thing I need to ask is if thereβs an Internet connection. If so, weβll be up and running instantly.β
The newfound agility has not gone unnoticed. βSomebody asked me how long it would take to move the team to a new office. When I told him about ten minutes, he was shocked.β
As for performance, Cyrus says users havenβt missed a beat. βCato Cloudβs latency, packet loss, and uptime have been basically the same as MPLS β but, of course, much less expensive and more flexible,β he says. βIf I want to scale up, itβs easy with Cato. With MPLS, I would need to make all sorts of arrangements.β
Thatβs not to say there have been no hiccups. βAny new technique encounters some configuration issues, and Cato was no different. Early on in the deployment, Cato upgraded one of our Sockets without our knowing. They resolved the problem quickly, and since then I havenβt had an issue.β
In fact, Cato support has been one of the biggest eye-openers for Cyrus. βCato is not your typical provider,β he says. βThe product is flexible, and support is good. If we have modifications and questions, Cato support is always eager to listen and either adjust or recommend a solution to the problem.β
Cato Improves Mobile User Experience and More
Cost savings might have initially driven FDMGβs WAN transformation, but itβs the operational benefits of increased usability and agility that became particularly compelling. βIn the early days, users had to open a browser and navigate to our portal, log in, and only then launch an application to get a VPN connection up and running as if they were in the office,β Cyrus says. βThere were so many steps, which not only frustrated users but meant more helpdesk calls for support.β
With Cato, Cyrus sets the policies determining the applications and resources available to users and user groups. Mobile users join the Cato network directly, not a separate remote access solution, making network access much cleaner.
βNow users just push the slider on their mobile device, and theyβre authenticated right into the network.
Visibility and ease of security operations have also improved. βNot only do we have greater insight into whoβs logging into which application across our network, but our security toolset has become much easier to use,β says Cyrus.
βWe decide which users can connect to which resource without having to configure different firewall rules.β
FDMGβs Bottom Line: Itβs More than Just the Bottom Line
FDMGβs initial goal was to reduce WAN costs, and Cato certainly did that. βWeβre spending about 10 percent less with Cato than with MPLS,β says Cyrus. βOur savings are even greater if we factor in the licensing, installation, and management costs associated with the VPN concentrator.β
But more than just costs, Cyrus has gained value. βWith Cato Cloud, I increased bandwidth, replaced two things with one solution, improved user experience, maintained performance and uptime, and made IT more agile. Thatβs what I call a huge win.β