Reinventing Critical Network Services with Infoblox
Mukesh Gupta, Infoblox EVP and Chief Product Officer, introduces the Infoblox Universal DDI Product Suite. This suite offers groundbreaking solutions for unifying critical network services management across hybrid, multi-cloud environments, providing in-depth visibility and insights with infrastructure-free deployment.
Infoblox, a leader in DNS, DHCP, and IPAM (DDI) services, simplifies network management to enhance responsiveness and cybersecurity. Organizations adopting hybrid, multi-cloud infrastructures face challenges like human errors, increased costs, and security vulnerabilities. Infoblox addresses these with innovative solutions that improve efficiency, consistency, and resiliency.
The presentation highlights Infoblox’s journey since 1999, focusing on uniting networking and security. Key features include Universal DDI Management for efficient service delivery, Universal Asset Insights for comprehensive network visibility, and NIOS-X as a Service for modernized, infrastructure-free deployment.
Infoblox’s approach to network automation and transformation ensures seamless cloud networking and modernization, enhancing overall network performance and security.
Presented by Mukesh Gupta, Infoblox EVP and Chief Product Officer, Infoblox. Recorded live in Santa Clara, California on February 19, 2025 as part of Cloud Field Day 22. Watch the entire presentation at https://techfieldday.com/appearance/infoblox-presents-at-cloud-field-day-22/ or visit https://TechFieldDay.com/event/cfd22/ or https://www.infoblox.com/products/universal-ddi/ for more information.
Transcript
So, my name is Mukesh Kta, uh, lead the product team, uh, here at Infoblox. Um, I'll give you a little bit of my background. I joined the company about one and a half years ago.
Uh, before this, I spent four and a half years at, uh, Palo Alto Networks. Uh, I was leading the software firewalls business there. Uh, spent about six years at a company called Illumio, uh, that does microsegmentation.
Uh, before that I was pretty early, uh, employee number 14 at Lumio. So built that product pretty much from ground up, uh, and long history of Nokia checkpoint firewall, juniper, net screen firewalls before that. So that, that's my background.
We are gonna talk about, uh, how we are reinventing critical network services, uh, today. So here's the, uh, agenda. Uh, I'll start with a little bit of company overview.
If you don't know what we do, uh, a little bit of history, I'll talk about, you know, the customer trends and challenges that we, we hear from our customers when we talk to them. Um, when I joined, we put together, you know, this, uh, brand new platform vision. I'll walk you through that.
Um, and, you know, universal DDI product suite that came out of that vision and work, uh, which we launched last September. So I'll give you a quick overview of that. I'll switch gears to talk about our unique approach to DNS security and how, how we are helping our customers, uh, protect themselves.
Uh, and believe it or not, I'll try to finish all of that in 35 minutes. Uh, and then we'll dive into, uh, the demos, which is the most interesting part of the session. Uh, so I'll run through that and Glen and Jason will give you a little bit of deeper dive, uh, on universal DDI and give you live demos so you can see the product in action.
Okay. So what are these, uh, critical network services that we, we do? Um, it's called DDI, it's an interesting acronym of acronyms.
So what it stands for is, uh, D-N-S-D-H-C-P and IAM, that's DEDI. And each one of these, uh, acronyms, stand for its own acronym. So, DNS is domain name systems.
Uh, as he said, it's a foundational service. com. The first thing that happens on the network is the network needs to resolve this name into an IP address, and that's what DNS does.
So that's the first critical service. Nothing works without DNS. Everything requires DNS to work.
The second one is DHCP. So when you bring any device on the network, uh, it needs an IP address so it can connect to something. And that DHCP is the protocol that assigns that IP address.
So, dynamic Host configuration protocol is what it ST stands for. Um, and, and that's what it does. It gives you the IP address, you can connect to the internet.
Uh, the third one is IP address management. So all devices on the network need an IP address. Uh, if you're a large enterprise, then you, you can have millions of these ip.
So how do you manage them? Uh, IP addresses need to be unique most of the times. Uh, so you need a whole system to manage these IP addresses across your enterprise.
So that's what it stands for. That's what, uh, Infoblox does. There's a little bit of history.
The company started in 2000. Before that, uh, customers used to run D-N-S-D-H-C-P or either, uh, open source stuff like D-H-C-P-D or find, uh, or on Microsoft. And they managed their IPAs with Excel sheets or text files.
And, and that's how they lived Before Infoblox was born, Infoblox made it really easy. Launched a company in in 2000, uh, when IPO, uh, so we were a public company in, uh, in 2012, we went IPOA bunch of stuff. And, uh, around 2017, uh, Vista took us private.
Uh, so we became a private, uh, PE owned company. Uh, we launched our security, uh, capabilities that, that I'm gonna talk about in 2019. I'm just touching on some of the milestones.
Uh, we were sold half of it to Warburg in, uh, 2020. So we are now own 50% by Vista and 50% by Warburg. Uh, our new CEO Scott Harrell came from Cisco and joined the company in 2023.
So it's about two years now. Uh, I joined the company in August of 2023, and, and we are trying to transform the company now for this hybrid multi-cloud world that most of our customers live in. Uh, and last year we launched Universal DDI.
So those, those are the, some of the milestones that the company has gone through. So we are about 13,000 customers. Most of the Fortune five hundreds, uh, are running on Infoblox.
Uh, and we are pretty critical, uh, service for them. Uh, if we go down, then their entire enterprise goes down. So, uh, we literally provide like electricity, uh, you know, to these companies.
So, um, what are the market trends I hear about from, from customers when I talk to them? It's these three. So the first one is, most of the customers that I talk to are on their multi-cloud journey.
Uh, most of them end up with at least two to three clouds, AWS, Azure, GCP, and they have their on-prem footprint. So most of them end up with this hybrid multi-cloud situation. Most of them are trying to go SaaS first, cloud first, trying to get rid of infrastructure in cloud in branches.
VMware acquisitions suddenly accelerated this. I I hear a lot from customers. They're trying to get rid of VMware now, uh, and, and just put everything in cloud.
Uh, the third one is the costly security breaches. Most of the customers that I talked to are worried about this. Uh, they've invested a lot in security.
Uh, but the cyber attacks, you know, I look at it in three dimensions. Uh, the number of attacks, and that's going up, the sophistication of attacks that's going up, and the impact, you know, all three dimensions. It's just things are getting worse and worse, and most of our customers are worried about that.
So those trends result in these specific problems around DDI and security. So I'll just touch on them quickly. Uh, when you move to cloud, each one of the clouds have their own DDI, so D-N-S-T-H-C-P and IPAM built into the cloud.
So the cloud teams love to use those because they're native services. Uh, what that does is most customers end up with four to five different DNS systems. Now, TNS is trying to connect things.
So if you have to log into four different UIs, uh, the probability that you make a mistake goes significantly higher. And if you make a mistake, because TNS is such a foundational service, you know, things can go down. Uh, so the, the example that I used is one of the banks in New York, uh, allowed the cloud teams to use the native services.
Uh, one time someone was servicing a ticket, creating some DNS entries, made a typo, brought the entire bank down for four hours. Uh, and this, the bank processed trillions of dollars of transactions every day. So it was a huge event.
So that's what could happen if you end up with four or five different, uh, DNS systems. What the next thing that most of the customers look into is, oh, you know, people log into these UIs and trying to make things work, uh, you know, is, uh, is costly and could cause outages. So we are gonna just put our selfer portal or a Terraform ible layer on top of it.
But when they try to do this, because you are dealing with four or five different APIs, four or five different Terraform providers, uh, Ansible cookbooks, just the cost of automation, just building it, how long it takes and how long it takes to maintain, it just goes significantly higher. So that's the second problem most of the customers want into, because these APIs are different and they keep changing, you know, over time as well. Question, I know we're talking a lot about multi-cloud and hybrid cloud, but to confirm, let's say an organization doesn't go the multi-cloud route.
Maybe they're gonna do multi-region instead because of the expertise in house, they can still use your product. Absolutely. Just with one cloud.
It doesn't have to be multi and hybrid cloud. They can, and even if they don't go to cloud, uh, sometimes they end up with, you know, info blocks in some places, Microsoft or Bind in other places, even on-prem, sometimes you acquire companies and they were running on Microsoft. So even within on-prem, you end up with this, these problems.
Got it. Cool. Thank you.
Yeah. The third problem is around how you manage IP addresses. So what I constantly hear from customers is the cloud teams keep asking for more and more subnets for their cloud environments.
Uh, and the network team has no visibility into how these subnets are being used. Uh, so it results in suboptimal usage. And, and IP addresses are precious resources for enterprise.
So if you're wasting them, uh, you can run out of them. Uh, so that can cause a problem. Even bigger problem is sometimes the cloud teams would start using subnets without even asking the network team.
And that results in conflicts, routing, uh, issues, and that that can cause outages. So that happens a lot as well, just because the network teams and the cloud teams are not collaborating effectively. Uh, the fourth problem is around still DNS records.
So when you create an application in cloud, uh, you have to create DNS records and, and point that to either an IP address or an S3 bucket. Uh, what happens is the cloud teams sometimes destroy these applications, but they forget to remove these DNS records. Uh, and now you have DNS records pointing to IP addresses or S3 buckets that have been released.
And in public cloud, someone else can acquire them. So an attacker could take over, and now they're running a gambling site on your domain by taking over this S3 bucket. So unfortunately, I've heard that story from a lot of customers.
It's not that uncommon. So that, that's a big problem. And the last one is just everybody's worried about ransomware, zero day threats, uh, costing them millions of dollars.
Um, most of the customers tell me they've deployed all the tools available in the world, but they just keep getting more and more alerts, and they still are not, you know, feeling protected. So those are the problems that come up. I'm curious about that last point, the ransomware and threats.
Yeah. How does proper management of DNS and IPAM alleviate some of the ransomware attacks? Yeah, I will touch on that.
So we, uh, you could use DNS as a shield around your entire organization, and it's not just ransomware. It can protect you against all sorts of attacks. And, and I'll spend some time towards the, I'm in trouble connecting the dots, so I'm curious.
Yes. I will connect the dots for you. Okay.
Okay. So, as I said, we started with, you know, our original DDI solution called nios and IOS. That's the, the original solution.
Uh, what that did is it had a grid management console that allows you to manage DNS and DHCP servers at scale, uh, for an enterprise. And then you have physical or virtual D-N-S-D-H-C-P servers. Uh, but what happened over time, as I said, you know, people started moving to cloud and ended up with this hybrid situation of, you know, AWS Azure, G-C-P-D-N-S, uh, and nios, uh, or Microsoft or bind.
And you end up with this, you know, uh, all these problems that I talked about. Uh, about five years ago, we launched, uh, and we were the first one that launched a SaaS managed TDI solution. Uh, so the management plane was offered as a SaaS service, so you could just log into it.
You didn't have to install anything, and you could use that. Uh, and we provided, you know, DNS and DHCP servers, uh, in physical or virtual form factors. So that's where we were about two years ago.
Um, one of the problems that we created for our customers is the nios DDI solution. And the blocks 1D DI solutions didn't interoperate together, which means they were already suffering from multiple DDI solutions. And we kind of contributed to that and made it worse, right?
So that's, that's the mistake we made. So about one and a half years ago, we realized that, you know, the critical problem that our customers are suffering from is this proliferation of DDI, different DDI siloed solutions. And they really need a consistent cohesive management for that.
And our new platform vision basically was born out of that. So here's what we, we came up with. We said, this is what our customers have.
They have, you know, know data centers and branches, they have users, iot, OT devices, they have multiple clouds. So how do we solve these problems for them? How do we become a unified platform for networking and security for this hybrid environment?
And we said, we wanna offer protocol servers. So D-N-S-D-H-C-P servers in many form factors. Sometimes you need a hardware server, sometimes you need a virtual server.
Sometimes you want D-N-S-D-H-C-P as a cloud service. So we should be offering all three solutions to them. And for whatever reason, if they want to use a third party like Route 53 or Azure DNS, we should embrace that.
We should force them to replace it. We should embrace that and help them manage it. Uh, so we adopted that, uh, strategy for the protocol servers.
On top of that, we said it's really critical to have comprehensive asset visibility. And I'll tell you, you know, how asset visibility solves some of the problems I, I talked about. And we want DDI management that runs across this hybrid enterprise.
And then I'll connect the dots on how we protect, uh, using DNS. Uh, so we wanted to create this, what's your cycle between asset visibility, networking, and security? Uh, so we put that as part of our vision, uh, and no matter what they're using, we should have cohesive management, uh, across this, you know, hybrid environment.
So that was, you know, on top said, the entire platform needs to be powered by ai. So we can help our customers, you know, with their operational stuff on the security stuff. We need to integrate it with ecosystem, uh, that we partner with ServiceNow, CM tools, vulnerability management tools, and we provide these supported integration systems so our customers don't have to do the system integrator work.
We do it for them and we support it properly. We also said, uh, everybody's trying to automate using Terraform, Ansible, Python, SDKs, and we should provide all of those things to our customers as well. Uh, so they can automate across this.
Uh, one of the critical decisions we made when we, uh, launched Universal DDI is, we replicated the APIs that we had from nios, uh, to Universal DDI. So because, uh, you know, thousands and thousands of customers have built automation with those APIs, we wanted to make it easy for them to just point those APIs to Universal DDI, and it just works. Uh, so that was one of the, the big investments we made in automation.
And the last one is the platform needs to provide flexible consumption so they can use different parts of the platform in a flexible manner. So that became, you know, our, uh, platform vision and Universal DDI came out of that. So I'll touch on what are the new parts of Universal DDI.
Uh, what you see on the left is the regional nios, uh, the grid management console, and the virtual and physical servers. What you see in the middle is the Universal DDI. So the, the big thing that, uh, was new is this Universal DDI management.
What that means is if customers are using Route 53 and Azure, DNS and G-C-P-D-N-S and and Blocks and Microsoft, we want provide universal DNS management so they can log into R UI and they can manage all of these systems from one place. Uh, and Jason is gonna show you a live demo of that, how we can, uh, manage dot 53, Azure, DNS and gcp DNS. Uh, we are working on, uh, adding support for Microsoft CloudFlare Akamai Bind.
So no matter what DNS they want to use, they have full freedom to use those, but they can manage it consistently from one place. Uh, from RUI, our API, our Terraform provider, they can use, uh, any of those DNS systems. Uh, same thing for, for DHCP, uh, even though the proliferation of tools doesn't happen on DHCP as much as on DNS, uh, but nonetheless, if you're using Microsoft or Infoblox, you should be able to manage those, you know, consistently from one, one ui, one API.
Uh, and the third one is the Universal ipam. Uh, so we provide IP address management across all clouds and on-prem infrastructure so they can manage, because it's really important for the IPAM tool to be, you know, consistent across the hybrid enterprise. Otherwise, it doesn't work if you, if you can't detect all the IP addresses and you can't manage them cohesively.
The fourth piece that's, uh, new on top on that management layer is the Universal Asset Insights, uh, which is super critical. If you wanna know, uh, how your IP blocks are being used, uh, you really need real time visibility, uh, into these environments. Uh, so we have had on-prem, uh, network visibility tools, uh, with nios.
Uh, so we, we are of course using that to feed the on-prem visibility. We can scan all the devices, you know, on-prem, in data centers, in branches, you know, uh, uh, endpoints like laptops and feed that into the ipam. But now with Universal DDI, we can also scan the AWS environment, the Azure environment, the GCP environment, uh, so our users can see that these are all the subnets that they're using, and here are all the assets in those subnets.
So how these subnets are being used, we show them utilization, uh, which again, Jason will show you. The other thing it does is if someone decides to create their own subnet without asking the network team, we can scan that and bring that too, that, Hey, here are some of the subnets that you're not aware of. And those subnets could be overlapping with some other environments and could cause, you know, conflicts and outages so proactively we can scan all of that and bring it in.
Uh, the last thing that the Universal Asset Insights does for customers is, uh, you, we have the DNS records. Once we scan the assets, we can figure out, oh, you have this dangling DNS record that is pointing to an IP that doesn't even live in your environment anymore. It's pointing to an S3 bucket that your cloud team decided to delete, and we don't see it anymore.
So that's, uh, you know, ticking time bombs, somebody could acquire that, uh, uh, S3 bucket and now host, you know, a gambling site and bond site, and who knows what on your domains, which will destroy your brunt, uh, and cause alterna problem security problems for you. So that's what Asset Insights does. Yes.
You mentioned that it can, you know, understand like if there's gonna be a conflict that occurs, right? Like you have, you know, two subnets that are sitting on the same side or whatever. Yeah.
Is that, that's happening in real time. Yep. There's like a specific trigger that like, let's say, you know, I'm an engineer and I wanna set it up, like scan it every five minutes or every 24 hours or something.
Yeah. Or is it just occurring on your own triggers? No, you configure a discovery job.
Got it. Okay. And then we are scanning, you can adjust the frequency of that as well, and then we keep scanning and bring things in.
Gotcha. Now when we find, uh, conflicting things and we show you that, and we'll show you some of that stuff. Okay.
Uh, so you can detect it. Got it. And, and so from a monitoring perspective, we can see everything that's happening in real time.
That's right. From an observability perspective, is there any action that you can take, like a default action if there's a conflict in the subnets, like shut down one subnet or whatever, something like that. Right.
Like real, like real time automation to, to, uh, uh, resolve the conflicts? Yeah. So, um, resolving the conflicts on subnets is something that the customers would have to do, because if, if we do something that may cause, you know, side effects Mm.
Um, but we are building, uh, actions for, let's say we show you a bunch of dangling DNS records. Yep. Uh, we allow them to say, go, oh, go delete this, you know, DNS record and clean things up.
So, So there is like automatic remediation that you can implement. Um, You can, the customers can, uh, but we just need to be careful again, because DNS is the foundation. If we do something automatic, it could bring things down.
Sure. So we just need to be careful how much we automate versus how much control we give to Customers. Makes sense.
Okay. Because the idea is that you want to increase the signal to noise ratio so that you ensure that what we're sending you, so you could send it to a seam or to some other, whether it's a ServiceNow or some other place where people are commonly, that's their admin portal. Because that's how, whenever I see like Universal, universal implies that that's the one place you go.
But it's more like this one place where action happens. How often would people be in Infoblox versus in their native consoles? So in this case, um, DNS is, you know, where we are saying we are, the universal management, uh, the way we have done it is, uh, it's a two-way sync.
So if the cloud team prefers to log into AWS Route 53 console, and they want to do things from there, or they have developed their own Terraform automation, they can continue to do that. We don't want to slow them down. What we are doing is we, we will sync that with the, uh, Infoblox console portal, so the networking team can also see the latest stuff, uh, real time.
And if they want to create something, then we again send it back to top 53. So the cloud, TMC, it, so you can operate on any console, it gives you centralized visibility and management, but we don't force them to just be on one console. Okay.
Oh, sorry. Go ahead. Okay.
Thank you. Uh, I think you mentioned that today you can manage Route 53 and support is coming for some of the other third parties. We Manage Route 53, Azure, DNS, and gcp DNS.
Okay. All three today, The big three. Okay.
Yes. And you will see that, uh, the support for Microsoft, uh, CloudFlare, Akamai and Wind is coming in next six months. Okay.
So when you say Microsoft, you're talking about like traditional Windows, DNS, windows DNS. That's right. Okay.
Gotcha. Believe it. No, not, uh, thousands and thousands of customers are running their DNS on Microsoft as a, Uh, a former active directory.
Okay. I believe it. Yes.
Get rid of it. Get rid of it, is what I'm hearing. Perfect.
I've got one. Do you manage my Excel spreadsheet filled with IP addresses? That's how a lot not yet.
Yeah. Upload, there's an upload box for that there. Uh, Eric, there you go.
For this real quick, I, I've got one question. Like, um, how many customers do you see that are integrating like Infoblox with like something like NetBox or not abo, something like that for what you said as far as like a two-way sync? What are you seeing from that as far as adoption?
I have Heard some customers use that, but I haven't talked to enough of them to, to give you what percentage. But I definitely have heard of, uh, not about, uh, and, and some of the customers are using that. Okay.
What, what kind of artifacts do you generate for this? Is it like, like is there a js ON output? Is it a Kafka stream you could subscribe to?
Is it just like, what are the ways in which a data and information comes from here to an external system? Is it push, is it pull? Like what are, how much can you interact with it in, depending on how you want to receive that information?
So, Standard Rest, JSON, um, we also have, uh, streaming logs. We have, you know, on demand actions, so we create tickets to ServiceNow. So it's all of the standard things that you do.
Uh, we also have Terraform providers, sensible cookbooks, Python s STKs, and so, uh, CLI, so you can interact with, you know, uh, the platform however you want to. Nice. Yeah.
So, just a quick question, and I apologize if you mentioned this, but if you look at the stack Below the SaaS, are you, are you hosting the solution, or where are you hosting? So I just talked about the management layer, and that's hosted in AWS uh, we have a one region in US and one region in eu. We are working on, uh, hosting in that management plane in other clouds as well, because we have customers that say, if you host a service in AWS, we can't use it because we compete with it Amazon.
So, so we are working on extending that. But the management plane right, right now lives in AWS the server plane that I'm gonna talk about next, that nios as a service can run on AWS or GCP because that's the data plane. So we, we have worldwide regions where you can launch it, and that, uh, we are using both AWS and GCP for it.
So would you have any part of the, uh, below the stack with that is platform agnostic? Is there something that they don't need to see that you abstracted above that? So the management plan, they don't need to see, uh, just because you asked, I I told you and SaaS, I, I tell them, but they're logging to SaaS behind the scenes, whether we run it on AWS or, you know, uh, on our data center or GCP or, or, uh, Azure, they shouldn't care.
It's just a SaaS service for them. Do you have an on-prem appliance that you deliver? Uh, yes, we do.
So that the original, you know, grid management console, uh, is, uh, an appliance. Okay. Yeah.
And we offer our physical appliance as well as virtual appliance, but the, the universal TDI product suite, the management is only SaaS. The servers can be hardware, software, or as a service. Thank you.
Yeah. But that on-prem piece, that's just the data plane. That's not the management layer that's putting in.
Okay, got it. Got it. Makes sense.
So it's, it's literally like a Azure local box or AWS outpost or whatever, like it's a box that you're putting in your data center to, um, collect everything from your on-prem environment and to the management console. That way you, you can have true hybrid cloud observability and monitoring and such. Okay.
And so it's not just for collecting, it's for serving DHCP and DNS as well. Got it. Okay.
Uh, uh, a lot of times, you know, you have sites where you need local resiliency, like a hospital can't go down when the internet goes down. So they want a DNS server sitting right there, um, because they want local resiliency. Right.
So in those cases, they would put that box, um, software box appliance, uh, in their local environment, like stores. Uh, they can't go down when the internet goes down. So in those cases, they put a server, if it's knowledge workers, when the internet goes down, the whole thing goes down anyway, then they would prefer to use that nsac as a service, which is a hundred percent cloud service.
They don't need to deploy any appliances. And we serve DN at CHCP protocol, uh, from a cloud service, which again, we will show you. I apologies.
I think maybe Ned might have touched on this already, but like, let's say I, I have a couple Windows boxes running on-prem. They're doing DHCP, they're doing DNS. Yep.
Will info blocks integrate in with what you already have? Correct. So that's, uh, what I, uh, you know, said that's on the roadmap.
And what we will do is we allow you to, uh, install an agent on those, uh, Microsoft servers, and then we will pull all your D-H-C-P-D-N-S configuration to our SaaS management. And now you would be able to manage it, uh, from, uh, info blocks. If you wanted to move the server itself from Microsoft to info blocks, then you can do that later.
Okay. Got it. So I can do a full consolidation.
I can shut down those boxes and everything. Info blocks. Got it.
A lot of our customers do that, and we are in process of doing that. But if we trying to provide a bridge so that it's not a big disruptive, you know, operation, you start by managing it, uh, that, you know, makes it easier. And then once you're ready, then you can start flipping the servers As well.
Yeah. Puts a customer's mind at ease too. 'cause they're not like, uh Right.
Getting rid of everything. Right. They, they still hold onto a little bit of the, the good stuff.
Yeah. Got it. Yep.
Do you have anything right now for, oh, sorry, Alison, you were, It's okay. No worries. I'll wait patiently.
Um, I, I know we've kept you on this slide for a long time. Um, I know you released this product in the fall of last year. Are you going to share in your presentation what customer response has been?
Sure. Uh, I can talk about it. The response has been, uh, way more positive than we even expected.
Um, so Fortune five Company, one of the Fortune five companies is already bought and they're in process of deploying it. Uh, we have large SaaS retail, uh, SaaS providers, um, like pretty big brand names. We have airlines that have, uh, purchased it and, and are deploying it.
So a huge, uh, interest. Uh, and in Universal DDI, now, one thing I like to mention is, uh, I talked about that blocks 1D DI, that platform itself is about five years old. Mm-hmm.
Um, universal, DDI has some new parts in it, but the basic SaaS platform was built five years ago. Right. So it's pretty stable and, and we had hundreds of customers using it as well.
Uh, so, uh, that's why customers don't feel like it's brand new. Some pieces are new. Mm-hmm.
Uh, but the overall platform is not new. Got It. And that puts them at ease because these, you know, large customers, uh, wanna wait for years before they adopt something new.
So, uh, the reason they're able to adopt it is because the, the core platform is not done yet. Thank You. Mm-hmm.
It's just question on air gaps. Uh, 'cause I know this is the question that eventually we have to ask is how do you deal with air gap environments? And given that you are potentially now a Bastian entry points to an air gap environment, what are the risks and protections you have for making sure that your stuff is protected other than just being SOC two certified?
Yeah, so the, the nios, uh, solution is completely on-prem, so you can use it in air gap environments. Uh, for SaaS, of course, the server part can be in the air gap environment, but the SaaS management is of course, a cloud service. So that, that can't be, but we, we have nios as a, as a solution that we are continuing to invest in because we know a lot of customers can't use SaaS for variety of reasons.
So we'll continue to invest in nios as an on-prem solution for that. Back to the appliance, do you have partnerships with various hardware vendors, or do you just have one and it's all, um, So we have our own hardware, but we are, uh, also moving towards, um, like we have a partnership with Dell, uh, so we can run on Dell boxes and, and that's the direction we are going in. It doesn't make sense for us to keep building our own hardware.
So, but we have our own hardware right now migrating towards general purpose hardware. Quick, quick Question on the universal ipam, is that similar to the DNS where you're actually pulling in information from other IPAs? Or is it just you use our ipam?
Oh, good question. Um, the, uh, universal IAM, uh, is we are scanning the environments and providing the know the IAM, but AWS and Azure both have actually built their own ipam. Yeah.
So a lot of customers are using those and they want to keep them. Uh, so we are also integrating our IPM with AWS IPAM and Azure ipam. In some cases, we hear that they want to get rid of AWS and just use us.
Uh, in some cases, the cloud team says, Nope, I want to use the AWS one. And the network team wants to use Infoblox once we are integrating. So, uh, our goal here is to provide them as much flexibility as we can.
Uh, so they don't have to worry about us. We fit into their environments and whatever they wanna do, we wanna make it work for them. And is there the same kind of two way sync?
So if I am, it will push things back Yep. To AWS ipam, for example? It's the primary thing is we will be the authoritative, uh, IAM and what they want is, when AWS runs out of subnets, they want AWS to talk to info blocks and get more, uh, from the pool.
Okay. So we are the bigger pool, AWS is gonna be a smaller pool, and they'll just pull from us and then they use locally. Okay.
Yeah. And they don't, they, they, the network team doesn't want any subnets being used in cloud unless they came from Infoblox just to avoid the bring your own subnet problem. Okay.
The last one, the nios X as a service is basically a hundred percent cloud service. Uh, if customers don't want any infrastructure, they can just launch a cloud service. And we serve DNS and DHCP, you know, on, on top of that using IP sac tunnels just like you do in, in a Sass e or sdwan architecture.
So that's universal. DDII promise that I'll touch on DNS security, so I'll touch on that now. Uh, so what most people don't realize, uh, and, and you were asking, you know, creating that connection between DNS and and security is no matter what kind of attack you're dealing with, uh, there is always that first DNS query that happens.
So let me give you a few examples. You get a phishing email, or you have a, you know, text with a, a bad link in it, or this new thing called phishing where you're scanning QR codes, and that takes you to some bad place. In all those cases, when you click on those links, the first thing that happens is a DNS query, uh, before you go there, right?
The second example, uh, people talk about vulnerability exploits. So you exploit a vulnerability, you get into a laptop or a cloud workload or a data center server, the first thing the attackers have to do is connect back to a command and control center so they can download ransomware or malware. Now, when they do that, there is again, that first DNS query that happens before they can download that thing, right?
The data exfiltration. So once they get in, they try to exfiltrate your data, guess what? They're connecting to a server where they're uploading all this data.
So there is that first ENS query that happens, right? Even in the AI world, people are talking about prompt injection attacks. Uh, even if you do that, there is that first ENS query that connects to something bad.
So no matter what kind of attack you're talking about, there's always that first DNS query. So our thesis here is if somehow magically you could figure out, um, you know, and block that first DNS query, you could literally stop all types of attacks, uh, no matter what kind of attack you're dealing with. And this is the connection between DNS and, and cyber attacks.
Now, what happens is DNS is there in any enterprise, and it's serving pretty much all kind of devices. Your laptops, your mobile points, uh, your iot or T devices, your cloud workloads, your, your data center servers, everything is already connected to DNS. So if you could turn this on, uh, on your DDNS server, you don't need to install any agents.
You don't need to install any, like, new appliances. You can just flip a switch on your DNS server, which is already serving DNS to everybody. So it's really easy, uh, to deploy.
And because DNS is the first thing that happens, if you start blocking those bad queries, it reduces, uh, a load on your network. So this is something we were surprised by. First time we heard about this is one of the customers turned on our DNS protection, and they panicked because the load on their firewalls and the routers went down by 40%.
So they literally thought something had gone wrong, and why are they seeing the significant reduction of traffic? So they panicked, they started, you know, freaking out, and then they realized because they were blocking those first DNS queries, uh, all the following traffic never went on their network. So that's just the network went quiet.
So it wasn't a problem. It was, you know, really good. And once they realized that, then when I talk to customers, I hear 20 to 35% reduction when they turn this on, which is huge, because now you don't have to buy more firewalls, more switches, routers, uh, the number of alerts that your SOC team gets goes down significantly because your endpoints are generating alerts, your firewalls are generating alerts.
If you just block that DNS query, everything goes down. So significant reduction on the operational overhead, the infrastructure costs, so huge benefits of blocking things at DNS. Now, the magic is, because it's DNS, if you block a, a good DNS query, you're gonna make people unhappy, right?
So you really need to be good at detecting bad domains and good domains. And how do you do that? So, um, I explain, you know, our unique approach using this, this analogy.
So if you have a drug problem in a city, you could take two approaches to, you know, deal with that drug problem. The first approach would be you go after the drug dealers and there'll be many drug dealers in the city. You would be, uh, you know, at every street corner in colleges and universities, and you'll have to find the drug dealers.
And as you arrest them, eliminate them, the ones will keep popping up. So you just keep playing this game of vamo. If you're going after the drug dealers.
The second approach is to go after the cartel, uh, and may have one or two. Generally they keep their territory so you don't have to deal with a lot, and it's much harder a cartel. But once you eliminate that cartel, then the entire city gets clean, the drug dealers go away automatically, right?
So it's a much more strategic and impactful approach. So let me give you an example of such a cartel in cyber world. Everybody knows what Bitly is.
You know, you probably use it for shortening the URLs. Uh, now attackers are also sending all these, you know, phishing emails. So they need a URL shortening service too, but Bitly doesn't offer that service to them.
So where are they getting their URL shortening service? Uh, there is a company, a big company, they make millions and millions of dollars serving all the attackers with this URL shortening service. And guess what?
They're wanting huge infrastructure. They need DNS. Uh, so we can actually track that cartel.
And we, we hired, uh, Dr. Renee Burton. She was running, uh, uh, she was working at NSA and running this DNS based, you know, cyber, uh, detection service at NSA.
She joined in Infoblox and brought all that knowledge. Uh, and we built this. So using, uh, her unique approach is we are tracking these cartels, so we call it prolific Puma, because they don't publish their name.
It's a company that has acquired 75,000 unique domains just in last one and a half years. So all the other tools in out there, they're trying to detect these bad domains. When they see a phishing campaign or they see a malicious website that's a drug dealer approach.
As soon as that domain get blacklisted in Palo Alto or Cisco umbrella, they just buy a new one and then start doing, you know, bad things with that domain. Uh, what we are doing is we are tracking their infrastructure. So as soon as they buy a domain, we know it's bad, right?
Because what's the probability that they're gonna do something good with it? They run the bad business. So that's just one cartel.
There are a whole bunch of others, and we were the first company, uh, publishing research on all these cartels because we are tracking them down and we, you know, tracking their infrastructure. So that's our unique approach. We're going after these cartels using, you know, DNS as the the thing.
Uh, what it allows us to do is few things. Uh, first of all, because we are tracking them, uh, as soon as they buy a domain, we start blocking it. And that gives us almost two months lead before the, the world knows about that bad domain.
So we start blocking it almost 63 days earlier than the industry. Uh, and we have research on this. We would say, Hey, this domain is bad.
And then two months later, virus total would say it's bad. Um, and everybody else will say it's bad, but we were blocking at two months in advance. 0002% false positive rate.
Why? Because we are not tracking the dealers. We are tracking the cartel.
So as soon as they buy the domain, the probability that it's gonna do something good is pretty much zero. Uh, so again, because of that unique approach, we are able to deliver this lead time to our customers and that super low false positive rate. Um, most of the time, like 75% of the times, uh, our customers, uh, the, we block that first DNS query that I talked about because we were already blocking that domain.
So the first query itself gets blocked 82% times. Uh, we are blocking within first 24 hours. So that's what, you know, our DNS security, which is called threat defense.
That's what that service does. I just wanted to give you that unique approach and the connection to, to DNS and how DNS can be used as a very effective security shield around the entire organization. Does that make sense?
Is that strictly on when it's your DNS server, or do you extend this capability to the other DNS servers that you're integrating with? Right now it's our DNS server. Um, we are working with some of the hyperscalers, um, uh, on making this available through them, but mm-hmm.
That is something future. And just to clarify, so all this, um, security features Yep. Is baked into the universal DDI solution, or is it, so like a Add-on?
So the universal DDI, uh, on that portfolio slide, actually I have it next I guess, or no, um, it, it's an add-on that you can turn on. So can you have the physical, virtual, and as a service, all three options? Uh, you can just flip a switch and turn on, uh, the security service on it, and then we will start protecting, uh, you know, using this approach.
Okay. Thank you. Jason is gonna show you that it's really easy.
Uh, and that's why we're saying, because DNS is already connected to everything. Everything is coming to DNS. It's just literally a switch, you flip and then we start protecting.
Yeah. Yeah. Can I zoom us back out again?
I think I missed the company, uh, piece up front. So how are you structured and how is your, how are your resources deployed? So for example, you talked about hardware not being a good use of your resources, so you're going to phase that out and gonna partner within your groups.
Is it by platform? Is it by, you have network folks, you have security folks? Yeah.
What would be the, the breakdown on that? So we, um, uh, engineering, uh, is organized by, you know, we have a big team of, uh, engineering folks, you know, supporting that nios original TDI solution because we have thousands and thousands of customers, you know, using that. The Universal DDI and the security there is the base SaaS platform because they're connected.
Uh, right. So there are common pieces, there are common teams working on the base platform, and then there are teams that are working on DDI management, asset insights, NEX as a service. Um, and all of it is owned by Glen who's gonna show up here.
And then we have team of, you know, PMs and engineers who are working on the security solution. We also have a threat intel team that's headed by Renee, uh, Dr. Renee Burton.
Uh, they are doing all the threat piece that I talked about and feeding all that intel into the platform. So that's kind of how we are organized. And so where would you be reinvesting the money that's going from, uh, your own hardware development?
Oh, that's a pretty small piece. Is it? Um, we've gone virtual, um, you know, a, a big, uh, piece of our install base is already running on virtual appliances.
Uh, so it'll go in all places. Um, but I think we will have to keep some people for managing like Dell, hp, whatever relationships. But yeah, we are mostly virtual, I'd say 80% right now.
So yeah, not a vague hardware shop already. And then sales and marketing versus engineering and functional pieces, Sales team is all shared. They're selling the entire platform, both nios Universal EDI and security.
But just as far as the resources, how much percentage would you have that are engineering versus marketing and sales? That's a tough question. Um, I would say 30, 40% would be sales go to market teams.
Okay. Yeah. And are you also selling through partners too, systems integrators?
Would there be a reason to do that too? Uh, Yes. We, we have, you know, distributors, uh, channel partners, uh, that sell all of our stuff.
We mostly go through them. Okay. Yeah.
Uh, our engineering sites, you know, our headquarters is in Santa Clara, actually, you know, very, very close from here. Uh, we have a big site in Bangalore, uh, so that's a big engineering site. We have a site in Tacoma, near Seattle, uh, and we have one near one four in Burnaby.
So those are the four hubs. And then of course, we have employees distributed across the world. Um, I think we are about 2300 employees, uh, at this point.
So that's kind of the, the size of the company. I know we're about to jump in. What I'll say is like, obviously visibility is incredibly important because if you don't have visibility and then narrowing down to the right signal versus noise, correct.
That you can't trust taking action against it. Right. How much of your stuff is like, biased towards action, or how much do you want to really become the action portal going forward?
Like, thinking about, do you look for partners to like, Hey, here's an easy way to integrate with this actionable system, or do you want to eventually be the action owner? Uh, that's a great question. Uh, right now, I would say we are for the actions, uh, customers want us to integrate with ServiceNow, uh, type tools because that's where, you know, they take all their actions, um, as we build a lot of these insights that you're gonna see, they are asking, you know, for some of the actions within the platform as well.
Yeah. So I think it's gonna be a mix of both. Um, we can't bring everybody, you know, on our platform because they're used to, you know, their workflows are all built with, you know, ServiceNow and the tools.
So we'll continue to do both. Perfect. Thanks.
Yeah.