Nile Introduction: Going Beyond NAC with Campus Zero Trust
Nile recaps the reason why it set out to build campus access network as a service to break the status quo in the industry, eliminate complexity and drive outcomes. Take a peek into all the different add-on services Nile offers on top of the access service. This section also covers the shared responsibility model between Nile, customers and the partners.
Presented by Suresh Katukam, CPO and Co-founder. Recorded live at Mobility Field Day 13 in Santa Clara, CA on May 9, 2025. Watch the entire presentation at https://techfieldday.com/appearance/nile-presents-at-mobility-field-day-13/ or visit https://techfieldday.com/event/mfd13/ or https://www.NileSecure.com for more information.
Transcript
In the last few meetings, as Tom said, we talked about many things about Nile. One of the things that we covered is how is Nile delivering network as a service, right? What's unique about it?
The guaranteed performance, how simple it is. Then we talked about our AI automation, the closed loop automation, where we guarantee that using our AI automation center, we're able to deliver guaranteed performance. Then we also discussed in the past about day minus one to all the way to day and operations, how we eliminated lots of those operations, how we simplified, how we automated it, what's our responsibility?
What's your responsibility as a customer? And we'll spend some more time on that one. Today, we'll go beyond that topic.
We'll focus on the security over the last 18 months. You know, customers loved our network as a service and the guaranteed performance, but we consider that stable stakes, the AI and the delivering the guaranteed performance, eliminating the net network issues. We consider it's a table stakes.
Now, we notice that many enterprises, large enterprises, financial firms, leaning on Nile because of the enhanced security that we have within the network. So we will focus a lot, and we also got requests a lot from, from jj. So we're gonna be spending a lot of time on the security in today.
With that, we have an, you know, again, based on the inputs, based on the feedback we created this agenda we shared with some of you. So we will go into under the cover, you know, you guys wanted to understand how does a Nile architecture works? What's underneath it?
What's the technology behind it? So it's not a magic sauce. We'll go into the details and talk about that and show you how the whole network comes up and starts working.
And more importantly, you know, we believe NAC is, you know, pretty much, you know, broken because, you know, it's foundationally on a broken network. And, you know, foundationally you have broken technologies and trying to fix nac and NAC has been developed over the last 20 years, as you guys know it, right? The cus enterprise security needs have evolved over the last several years, and it does not meet customer needs any longer.
So we'll focus on how the campus Euro test, uh, goes beyond the NAC and addresses and enables multiple use cases for the customers. Then we have a pretty cool service called, uh, guest service, secure guest service. So depending, we'll go into more details on that.
And it's a very simple service that guarantees that end users are, uh, the corporate devices are secured from the guest users. And then we'll talk about, you know, we have an amazing customer who loves, you know, the Nile, but more importantly, you know, they're working on a cool stuff and they'll, uh, challenge the status quo. They push the boundaries and they look for, you know, new frontier.
So he's gonna come in and gives an opportunity for you to ask him questions and see why they, you know, bought Nile. How is the experience after they bought the Nile as well. With that, you know, we have a great lineup of speakers, but the usual suspects, they shi and depend and shi and depend.
You know, they joined Nile almost four plus years ago. Even today, they works as if it's day 1 60, 70, 80 hours a week. The reason is they're passionate about the problem that we solve, and they challenge the status quo, push the boundaries.
They never push the complexity to the customers. They never, you know, they take, they always take on the complexity, simplify it, eliminate it, automate it, make it easier for the customers. Then we also have, Avinash is a founding engineer, and he, he leads our security.
Prior to joining Nile, he was at, you know, leading vendor, networking vendor where he built the NAC solution, you know, one of the most famous NAC solution. And he realized that, you know, that's broken. It doesn't meet the customer needs.
So he came over here to fix the, you know, what has been created in the past with that, let me, you know, you owe the last two days you heard from all the vendors and you keep hearing all types of cool agents, AI, and you know, all types of features, knobs and all of that, but none of them address the core needs, core challenges that we have. We are still doing exactly the way we have done for the last 30 years. Let me walk you through it today.
What happens, even with all the tools and everything that we talk about, once that site survey is done, but it's a predictive on site, however the site service is done, you still have to do the network design. You still have to do the understand over list, under under list layer two, layer three, what kind of network topology design I need to do it. You still have to choose 50 different access points from each vendor out there.
Which access point do I need? Which switch models do I need? Do I need stacking?
Do I need, you know, MA, do I not need MA? Do I need routing protocols? What kind of knobs do I need to do?
You still going through all of that, and you also have to choose the accessories. You still have to, and more importantly, you have to test all of that to see does it work together or not, right? The APS and the switches, the software, do they all work together or not?
Then you go and install it and if the issues at the installation only God knows what, all the ways we can discover it. And more importantly, after that, that's where the day to nightmare starts. Network tickets, lifecycle management, software, upgrade piece search, end of life, end of support, configuration, backup optimization, all of these is starts and by the time you're trying to do it and the refresh starts.
So these are the found foundational issues. Nobody's trying to address it. And we talked about how we address in the last sessions, right?
So this is a picture that gives a good idea of what Nile does. We offer today wired and wireless land as a service, as all of you know it, but we are also extending at the bottom of it. If you look at our architecture, we call Nile service block.
This is the hardware that we deploy at your site. It's a access point, it's a sensor, access switches, distribution switches, and we are also adding edge services. So with the edge devices, you can directly terminate the Nile ISP links on Nile switches or Nile products.
So we can cover the end to end within a single site. So this is the enterprise grade hardware, and more importantly, we'll go into more details on this. This is the unified wide and wireless architecture.
How many years has it been? We've been talking about unified wire and wireless. How many EO has it been?
We're talking about identity based access. We went back to in a clean slate. We built the hardware and the software identical.
Whether you're a wire user, wireless users, your policies, everything is identical across wide and wireless. That's the first thing. Second is, you know, we talk about vlan even today, 2025, we talk about the AI coming in, identifying missing VLAs.
We talk about how the AI can, you know, fix the VLAN issues. We completely eliminated that. This is a layer three architecture.
It's a fabric and it's automatically comes up, which is what she is gonna go through it. And, but more importantly, it's a high-end enterprise grade hardware. So it's not, you know, low end by enemies.
Then second one is AI automation. You know, there's been a lot of interest. We talked about it last time and let's talk more about it today.
And when you think of ai, it's frankly, it's not about giving you more insights, more dashboards, more you know, data. Instead, it should be really doing the closed loop automation. It's fixing the issues for you.
So we'll give you some examples. You know, we've been out for last three years, more than a little more than three years. Uh, out of stealth mode, we have hundreds of customers.
So one of the customer deployed almost three years ago. We have zero calls from the customer. That's because our AI in the background continuously fine tuning the network.
There was another customer wanted to talk to one of our existing customers, Stanford, uh, computer science building, and, and said, Hey, how is it to work with Nile? How many times have you logged into Nile portal and tried to, you know, figure out the problems? You know, what the customer said and they'll be happy to connect you with them.
It's been two years I logged into the Nile portal. The damn thing just works. This is what we hear.
So when you think of ai, it should be, it should be just working for you in the background. It's not about giving you more agents. And I'll give you one more data point.
So we build a product to run the product. We did not just, uh, build a product and give it to you. So when you build a product so that you can run the product and guarantee the service, the approach is entirely different.
So about three years ago, we created a very small team called production Network engineering team. This is the team. If something hits a fan, jumps into, uh, what we call our automation center where we have all the data and fixes the issue.
It's been three years. We added hundreds of customers and hundreds of several hundreds of locations, and in 15 countries, we did not add even a single team member to that. In fact, we did just one the headcount in the team.
That's the proof point of AI Automation Center. If you have any questions, feel free to ask me along the way. And the next one is the services.
So the accessories, which is a wide and wireless land service. That's what we started with. And we had guest service, you know, which we will go into more details where the secured guest service guarantees your guests are isolated from corporate resources, completely isolated.
And best part of it is it's beautiful where you don't have to do anything. You enable the guest service. We hand out the IPO to your client guest that come to your site, and we take care of paneling all the traffic to the internet.
We have pops and traffic goes to the pops and go to the internet. Neither you need to do anything or we need to do anything, anything. It just comes out of it.
Then extending our service with edge so that we can terminate directly the internet links so that you have the end-to-end, uh, offer from Nile for a given site. On the right side, you see it, radio service, you know, like as part of the, uh, JIRA Trust, you know, that was one thing and now we had it, but now we are actively delivering and it'll be available in next month. And this is a pretty cool service.
It's a cloud based. You know, when you think of radio service and moving to the cloud, you have to think of rad sec, the security, it's all built in from I service block. It is securely connects to our radio service that's in the cloud.
So you don't have to deploy, you don't have to manage it, monitor it, and you just use it. And it has some cool features where it easily integrates with your intune or crowd stacks of the world with any of the external agents that you may have services. We can integrate with those and say, only when these policies are met, the user is allowed to get on the network.
The next one is the DCP service, the cloud-based DCP service. We are the only one in the industry is able to deliver the cloud-based DHV service. And the last one, but not the least, is the trust service.
This is our campus zero trust. This is how we deliver our, uh, zero trust. So let me give you a few things.
First, by design of the trust service, the infrastructure is secure. It's like a black box from external hackers perspective, you cannot discover anything in the network because when a device gets contaminated, comes to the network, connects to the network. First thing is it discuss the network topology.
Second is it discuss all the resources connected to the network. Then it starts propagating malware. We eliminate the opportunity for the hackers to discover the network, the topology or any of the devices on the network.
And we isolate by design. Every user and device has to be authenticated, authorized by design. You don't need to go and configure the pv, LANs or any of those one X on that codes.
We guarantee that every user and device has to be authenticated authorized, which will go into more details and a continuous authentication. As you know, the uh, uh, JIRA test is really about continuous authentication and more importantly, isolation. We isolate every user and device by default, and we give you microsegmentation capabilities, and we give you fine granular controls where you can say, Isha has no reason to log into a printer, but sure can, uh, print.
That's the level of capabilities we provide you. So whether it's IT or OT or users or the employees or the, uh, guests, we have the security code for all of them with our campus zero trust. More importantly, let me clarify this.
We are not an MSP. We are not an outsource company. So you're not outsourcing it.
This is your service, you control it. So let me clarify. It's, we are not an MSP.
A lot of people think, Hey, we are outsourcing to Nile. You're not. You still have the complete control and visibility using Nile Control Center.
You customize how the service should be working. Think of a cloud. When you acquire a cloud, you create a VPC and you customize it.
The underlying hardware and software is taken care by someone else in terms of software upgrades, keeping it up to date and everything, and making sure the underlying data centers are managed by cloud providers. But you customize how the service should be working for you. So you have complete control on how this service should be control, uh, uh, how this service need to work for you.
With that, what do we deliver? I think many of you know it, but let me take, uh, talk about few things with only one in industry delivering the secured cloud services, whether it comes to gas, whether it comes to DHCP, where it comes to Radius. And we are the one delivering the zero trust out of the box.
It's built into the hardware and the software. It's not bolt on solution, which we will go into more details and it's about time. 2025, we got rid of VLAs.
So it's a vlan free microsegmentation. There's no more vlan, there's no more where you connect, you know, uh, Sam is Sam. No matter whether you connect wired or wireless, no matter which floor you connect to, what port you connect to, Sam is Sam, your policies go along with irrespective where you connect.
So it's not based on vlan port level configuration. All of that is gone. And we talked about ai.
It's frankly, we can go into as many details as you want. So today, as I said, we do not have a traditional network operations center. We have business critical, uh, customers.
We have universities, we have higher eds, and we have, you know, K through 12. We have enterprises, large enterprises. We also have distribution centers across 15 countries without having a network operation center, people monitoring instate, our AI automation center is constantly fine tuning the network.
As I said, we have a very small team, if you ever need to jump in, they'll fix it. And they roll out, roll out the fix to every customer. Ssh.
This could be an opportunity to drill down a bit more on who you're talking to, uh, with the customers. Uh, is it more, uh, decision makers from say the AI team that's driving, you know, the adoption, uh, is it, you know, mostly IT teams, et cetera? Sure.
So can you clarify the question again? Yeah. Who talking to at the organizations that are adopting Nile, what are their personas, their, uh, job titles?
So, sure. Thank you, Ron. So the question, you know, is about who is really, you know, understanding and who are we addressing when we talk to the customers, and frankly, it's the CIOs and CSOs.
These are the leaders. They're looking at how, how do we, uh, adopt ai? And these are the guys looking at, hey, how do we really leverage AI to empower my teams to focus on much bigger things than focusing on smaller, you know, bits and bytes.
So those are the audience. We are talking to them and it goes extremely well. And more importantly, they're also very, you know what, you can gimme all the AI tools, but what if it automatically solves the problems?
That is what they're accepted about when we talk to the customers. Very helpful. And this one, based on your feedback from LA in the last time and continued engagements, I, we created this slide, shared responsibilities.
So this is your network. Let's clarify it. Am as we said, we are not an MSP, we're not an outsourcing.
In fact, you know, we were talking to Wall Street Farm and they said, Hey, today we outsource it a large, you know, provider with Nile. We are gonna insource it. We don't need that many resources to monitor and manage the network because you guys take care of it.
We can, we still have the control today when you outsource it. I have to talk to the outsourcing company. If I want to create a vlan, if I wanna change a policy, I have to talk to them with Nile.
If they're able to insource it and they're able to control it. So you have complete control and visibility when it comes to how the Nile service should be working for you. So we are not an MSP, we're not an outsourcing.
In fact, we are able to allow you to do insourcing with limited resources, right? So let's, let's go a little deep. So if you look at on the right side customer, it, you know, first of all, you know the, uh, you guys have a lot of experience in with your environment.
What do you need for your environment? So you probably already have the site service done. You might have predicted site service.
So we work with you understand the site service, the, uh, site information from you guys. Alright? So it's a wild site survey, wireless set survey.
That information comes to us using a simple mobile app. And once that comes in, we automated the entire network design. We created digital twin to begin with, how the network should be, how many aps, how many switches, who should be connecting it.
The entire network architecture and design is automated. So we start with the digital twin and we automatically create the bill of metal, including the transverse cables and the mounts, and we automate the cabling plan. If the cabling is not done already, or if you need additional cables, we give you the cabling plan that's all automated.
Then we ship the equipment to the customer site and customer has two options. Customer can go and rack and stack and bring it up, or you can leverage one of our partners or certified partners. They can come and do the rack and stack and bring up the network.
Once that is done, as I said, we handle everything in the hardware, the software end of life, end of support piece, search software upgrades, the network optimization, all of that is something that we handle. But you have complete control on how should the network for you work for you. How should the users get on the network?
What kind of authentication? What kind of controls do you want to have? You have the complete control on users, devices and applications.
You'll be able to deny a specific client. You'll be able to disconnect it, whether it's wire wireless, it can kick out a user, a device, whether it's IT device or an OT device. So you'll have complete visibility and control and you have lots of, lots of tools to bring it in instead of outsourcing with a limited set of resources.
And on, uh, digital twins, uh, great to hear Nile does it's, uh, digital twin exercise beforehand, handing it over to the customer. Just curious, you have customers who ask, uh, to run it on say their own digital twin. Are there scenarios where that happens?
Sure. So Ron, uh, first of all, you know, we take that information that they have, you know, they have most of their digital twin, frankly is in the spreadsheets. It's not in anywhere else.
You know, they have their own maps, they have the visual, they have the, that's where they have the digital twin. They don't. So I would call more of a pictorial view of the network, not truly a digital twin.
We create from that, the real digital twin. So we call as designed the digital twin, but when you go and deploy it for some reason, let's say you're not able to deploy as we design it. So we call as deployed digital twin, but after that, let's say, you know, somebody, uh, remote the cable so they don't want any longer that part of it.
Or there is a remodeling that happens. So things can change even after deploying it for various remodeling reasons. So we continue to update the digital twin based on the changes, but we make sure it is in line with what we expected.
If not, we work with the customer and say that, hey, there is a change and is it permanent? It's not a permanent. So I'll give you an example.
We had a deployment at a customer site right here. And once we deployed it, things were working well. They added a lot more employees and they moved the employees to one side of the building.
Our system was able to identify that you need two more access points at this location automatically. That's the power of AI and the closed loop automation. And we worked with the customer ship the two access points, and we were able to deploy those and take care of it.
Now we updated the digital twin because things have changed from the time we design. So we have the continuous, you know, uh, updates to the digital twin as well. That's good to know.
You're the digital twins, uh, source of truth. Yeah, exactly. And the best part is you got rid of all your spreadsheets, you got rid of all the visuals and all the tools that you have.
Now you have the full information online anytime for you to see what we design versus where we are. And, but when it comes to project deployment, we work with you. We have what we call service delivery manager.
Once the in order comes in, we work with you and the partner and coordinate the timelines and the, and all of those aspects. So it's a joint, uh, responsibility between us and the customer or the partner. Any questions?
Jj, you are No, I'm not. I, I'm listening. I'm interested in the, like understanding the digital twin and, and how that lives.
Like in what format? So it's in, it's in the cloud mainly. I'm right.
So what happens is once your site survey is done, that brings in what we have a tool called customer management portal. So we'll be happy to show you. We did not bring it here, but we'll be happy to show you offline where you'll be able to see the entire network that is going to be deployed at the customer site.
That's the one. Then send second as it changes, as we talked about because of remodeling, or as you add more aps or remote aps for different reasons, it continues to update. So we have complete picture that in our, what we call in our AI automation center.
You'll be able to see all of that because it's continuously fines based on the digital twin that we have. Okay. I have a, just need a further clarification than that because for me it just still sounds like a network diagram.
It's not a physical thing, it's a digital twin. And like I understand you digitally have it there, but how's that still different from me creating a draw io diagram and calling that a Sure, So this is the live representation of the network. Okay?
So it's not just a, you know, diagram, but it's a live representation. So it re represents the exact state and health of the, the device that's on the site and continues to reflect that state. So if you have to make any changes, we can make changes on the digital twin Okay.
And ensure everything is working and then we can roll it out. So you can do, it's a live representation. You can do actual tests on that digital, On that digital twin.
Okay. So It sounds almost like of what were you talking about for the, the container lab and Yeah. Uh, even g like, like you're actually modeling the, the data paths does Yeah.
And you know, when you want to do channel planning, right? Let's think of that as an example. All right?
You want to make sure that it makes sense for that particular environment because every environment is different. So you want to run in that virtual environment client, make sure that it's not just the AP one location where the problem is, but it's improving the experience across the entire site. Because when there is a problem, we try to react and we fix it, but it doesn't mean it improves everywhere.
So, so does that digital twin then also take into consideration like the potential number of clients at that site? So we have a lot of historical data. Okay.
As you can imagine, I'm right. We have it, we have the seasonality, like weekends versus week days. I'm right.
Mornings versus nights. We have all of that information. We take that into account and building that, uh, model for, so you're right, right, when the, you know, whenever you're doing the modeling, what is the purpose of this modeling?
It's to really improve the end user experience, to your point. Alright? And, uh, the IT device, OT device user experience, and this is where we have what we call soft bots, you know, which we talked last time, is how do we know that it improves your experience role, right?
So the soft bots, what they do is they, they look at all the users that were connected prior to making the change. Mm-hmm. They, we look at almost 50 different parameters.
The TX RX latency transmit, uh, the retransmit, the trans and package failures. We look at all of those capabilities, the signal strength. Once we make the change, do you have equal or better experience?
And objectively by looking at all these metrics, yeah, did every device can connect? Are we gonna lose connectivity to some, uh, OT devices, let's say some, you know, older device that's part of that feedback loop, that feedback. And only when soft bots say that, hey, this, it's gonna improve the end user experience and the OT device experience, that's when, you know, we roll out the change.
Okay. Yeah. And other question comes up is ai, you know, hey, do I trust the ai?
Can, you know, can it bring down the network? Frankly, we'll go into the architecture discussions a lot more into that. So first of all, the way we do is we model it.
We have the production network engine team that looks at it, Hey, is it the flow, is the action right after 3, 5, 7, 10 times. Then we say, let the AI take care of the closed loop because you wanna make sure, and in fact, you know, when the AI makes the decision, you know, like it's not like simple LLM the reasoning is important. We show the reasoning why we made that decision, what, you know, what kind of logic, what data it has taken, what kind of flow it went to make the decision.
So we have that information as well. So we'll be happy to have your follow on conversations on the AI front if you wanna continue that. So yeah, okay, there is a problem here.
Yeah. So how are we able to deliver this? How are we able to deliver that?
Always on service, the AI part of it, the security part of it. It really comes down to going back to the drawing board, building the network that really makes sense. So across all our customers, we have single architecture.
There's no layer two, layer three or less underlay, lacs, all sorts of things gone. We a single architecture, it's a layer three fabric, unified wide and wireless across all our customer with, it's a 20 people company where it's a 20,000 people, uh, location. In fact, we have a 200,000 people location.
We have the identical architecture across all our customers. Imagine the benefit of it, you know, drew, like a laws that we eliminate snowflake. There are no more differences.
So whether it's university high tech, whether it's uh, whether it's a distribution center, we have identical architecture across all of them. This is why we can do the closed loop automation. This is why we can guarantee the service.
And second one is it, it is deterministic. It works exactly one way. It customizes it, but works exactly one way.
There is no configuration knobs, neither customer, not partner, not n goes and configure or pay for anything. We'll go into more details, but identical architecture and deterministic across all our customers. And more importantly, I talked about every network starts with a digital trend.
So we know exactly how it starts and how it needs to continue to work.