Nile NaaS Architecture – A Peek Under the Hood
Nile’s mission is to be the “easy button” for network and security in on-premises deployments. The company was founded by networking industry veterans, including former Cisco executives John Chambers and Pankaj Patel, to address the complexity of enterprise LAN environments. Nile has pioneered a new architectural approach, backed by numerous patents, that has led to its recognition as a Visionary in the Gartner Magic Quadrant for Enterprise Wired and Wireless LAN Infrastructure. The Nile service is deployed globally across various verticals, powering large-scale environments such as a 12 million square-foot warehouse and concurrently supporting over 200,000 users.
Suresh Katukam elaborated on Nile’s architecture, which is built upon a “Zero Trust Fabric” composed of Nile’s custom-built, enterprise-grade hardware including access points, switches, and sensors. This hardware provides constant, real-time telemetry to the Nile cloud, where an AI engine called Nile Experience Intelligence (NXI) uses closed-loop automation to manage and secure the network. A key architectural principle is that the entire fabric is Layer 3 only, which fundamentally eliminates the complexities and vulnerabilities associated with traditional Layer 2 networking, such as VLANs and broadcast storms. The fabric itself is hardened by design, featuring secure boot, automated patching, and a complete lack of direct management ports like SSH or Telnet, ensuring the infrastructure itself cannot be easily compromised.
This architecture flips the traditional networking paradigm from “communicate first, secure later” to “security first, communicate later.” Instead of relying on a complex stack of overlay solutions like NAC, ACLs, and firewalls, Nile integrates security natively. It unifies policy for all wired and wireless users and devices (IT, OT, and IoT) under a single, identity-based engine that integrates with SSO providers. This enables true micro-segmentation and a “segment of one” by default, where every device is isolated with a blast radius limited to itself unless policy explicitly allows communication. This built-in approach delivers Zero Trust principles to the LAN, simplifying security and operations while offering innovative features like a fully isolated guest service that automatically tunnels traffic directly to the internet.
Presented by Suresh Katukam, Co-founder and CPO. Recorded live at Security Field Day 14 in Silicon Valley on September 25, 2025. Watch the entire presentation at https://techfieldday.com/appearance/nile-presents-at-security-field-day-14/ or visit https://techfieldday.com/event/xfd14/ or https://NileSecure.com for more information.
Transcript
So Shahi talked about this architecture, and if you look at Chin know, uh, I will go a little deeper into that. At the bottom of it, you see Nile services in Edge portfolio, and that includes our hardware access points, switches, distribution switches, sensors, and the gateways. And this is in-house built, you know, this is our own hardware, our own software that we built in.
And this is enterprise grade hardware, high performance secured service that we are trying to deliver. And this forms the fabric. And when you think of, you know, delivering as a service, you have to build it for scale.
You cannot really build network operation center with lots of people monitoring and managing it. You need to build it. You know, when you think of self-driving car, you need to mo it needs to run on its own.
So you need lots of sensors, lots of data that's coming in real time, it's processing it and taking care of it. So the reason we built our own hardware and the software is anything, everything that you ever needed to know about your hardware, about your software, your processes, and your data plan, control plan, management plan. And more importantly, when you think of a car, it needs to monitor the road conditions.
Similarly, we have sensors that monitor the conditions around the network. So you need to monitor voltage fluctuations, powerful electricians, cabling situations, you know, cable twice, and electromagnetic interference that anything and everything that can interrupt the network operations to have a seamless connectivity. So that data is coming in real time to the cloud.
And our AI and what we call is, you know, NXI, Nile Experience Intelligence. This is our core, you know, brain of the system if you want to think of it that way. That process this data in real time and automatically using closed loop automation, uh, uh, commands to the, uh, network and takes action.
And when you take an action, how do you know that the action is successful? So we built agents that agents, what they do is constantly check from the end user perspective and from the network perspective. Did every user and device connect to the network after you make the change?
Do they have equal or better experience? We have 50 different parameters that will look at your experience and make sure that any change at every change that we have done is successful. If not, you have the Gen I that will explain in a plain English to our production network engineering team.
It's a small team that we have, and it'll give you needle in the haystack and explain in plain English so that they can take quick action and then they automate it and then we roll it out to every customer out there. On the right side, you see Nile customer portal. So unlike an MSP, you have complete control on this service.
I want to clarify that when you think of network as a service, it's not an MSP, it's not outsourcing it. Instead you have the complete control and visibility. Uh, how do you want your users devices to get onto the network?
What should they access the com. So you will have complete visibility control, and we have third party integrations. So you wanna integrate with the NO systems, our SOC systems, you can integrate with that.
So this led to developing a lot of, you know, catalog of services. So on the network side, you have the access service, access is wired and wireless access layer, distribution layer, core layer or entire campus. And more importantly, we have the edge where you can directly terminate internet on Nile service fabric or fabric itself.
So you have the complete stack and other one is creative, one in and very innovative is the guest service. So when you think of guest, when a guest connects to the network, you have to make sure the guest can only go to the co internet. So automatically cloud JTA fabric, when gas is connected, it takes the traffic tunnels to PO point of pop locations and send it to internet automatically without customer configuring gas v lands or tunnels or any of those things.
And you have URL filtering IP reputation, make sure that guests can do only activities that they can do. So guarantees guests can ever, ever get into corporate network and guests cannot see any other guest on the network. And then we have the other network services like DHCP.
It's a post secured, cloud-based DHCP service, and we have the radio service, again, cloud-based secured service. And more importantly, we have the trust service, which is the microsegmentation and find granular control. For example, ESH can print, but s has no reason to log into a printer.
So typically employees can print, but only IT team can log into the printer. So our trust service gives you that level of microsegmentation and granular controls so that you can do, allow what exactly what you need to do on your network. With that, let's talk about, you know, uh, over the last several years I talked to a lot of s and CISOs and Fortune 500 customers.
And all of these are saying that securing, as shahi said that land is your biggest surface area for attack. It's been extremely hard. One of the customers on Wall Street said we have three separate networks, one for the employees, one for the guest, one for the IO OT and one local customer here in Silicon Valley.
And it's a security customer, frankly security vendor. And they do not give access to wired networks for their employees because they realize I, they can secure wireless, but they cannot secure wired network. So because you have this, you know, separate set of solutions for wire and wireless, they think iot, as you guys know, 80% of the enterprise assets are outside of the IT control 80%.
So that includes, uh, devices controlled by the lines of businesses, that includes, uh, uh, IT and OT devices. And they put all the, uh, IOT devices, all these devices into a single vlan hoping that nobody can penetrate into that. So that's the challenge you're facing.
And why is that happening? If you look at how the networks were built in the beginning, networks were built to communicate with each other. Then we came up with VLAN to limit the broadcast.
Then we came up with the private lance where you can isolate every user from every other user. So when you think of private Lance, one of the local customer here, fortune 500 hundred customer, they said it took too many years to really have a per host isolation in the entire network, two many years. And imagine that.
And anytime they make a change, it's extremely brutal, it fails. So the 80% of the I the enterprise assets are not really being protected, even though you might have other solutions for user-based, uh, devices. And then other one is, so we started with V Lance, uh, pr private v lance, dynamic v lance.
And when NAC introduced, we came up with dynamic V relapse, then we came up with the a ACLS who can talk to whom, and then dynamic acls, then glorified acls, which turned into firewall and evolved. Then N Solutions. Look at the number of techniques and technologies and appliances that you have to manage in order to secure your network.
On top of that, you need to secure the network itself. So you came up with attack acts and you need to secure the systems, you need to secure the ports. And lately you probably have seen some solutions coming out in order to protect it.
And OT devices using, you know, overlay solutions, another appliance where you bring in all the traffic and using slash 32 so different mechanisms and apply the policies. So you can see that, you know, it's built over the last 30, 40 years. And we said, when you think of, you know, network as a service, it's our responsibility to secure your users devices.
And it's our responsibility to secure the infrastructure that we are delivering it to as a service. So we need to make sure that network, you know, today, 60% of the cybersecurity attacks leverage network as the weakest link because you have vulnerabilities and lateral movement of malware. And then next one is we talked about, you know, you have separate solutions for the wired separate solution for the wireless, separate solutions for the iot.
You have all these disjointed solutions. And as all of you know, when you walk into a, um, building, connecting ethernet port, you are on the VA, you're on the network, it's almost impossible to secure the ports on the ethernet ports. So there's an implicit trust, depending on where the VLAN is, you connect to it, you have automatically belong to that particular group.
And securing the IT OT device has been a challenge. And so what we said, we need to really address all of these challenges and said we need to unify the networking and security. We truly integrate the networking and security where, why do we need to unlock communication between the two devices In this day and age, all your applications go to the cloud or to the SaaS or to the internet or to your data center.
So the need for the local communication, communication has come down significantly. So we said security first, communicate later. So you need to flip the entire paradigm upside down and say that we need to have the security built in by day one.
So we integrated the network and security, which I'll go into more details on. And you need to really have one policy engine that goes across all types of users, like employees, partners, guests, contactors, all types of the devices, it, OT and IOT devices. You need a single policy engine.
You cannot have multiple policy engines and layers of appliances. And more importantly, one of the basic JTA principles is explicit trust. You cannot have any device that connects to it without having that trust, whether user device or an IOT device.
You have to have an explicit trust until then they cannot get onto the network and they cannot access anything else. And other one, as you, as we said in the traditional world, you have the the VLAN based. But here it has to be identity based.
It cannot be based on IP address based on a subnet. It has to be identity. So when you think of users, you have the identity in your active directory, you know the groups, what, what groups you belong to when you think of the IT and ot, other devices, you have device fingerprinting that tells you what type of the devices, all those on your network.
So you have to use this identity, you know, to provide the security. And, and you know, we talked to one of the banks on Wall Street, they're trying to refresh the network and the best is they're looking at, at the best they can do macro segmentation. You know, one, we land for employees, one for the guest, one for the IT OT devices.
It's really at the best. They're getting microsegmentation. They're not really able to accomplish microsegmentation.
So this is when we came up with the JTA fabric. It's extremely simple. When you look at the fabric components on the bottom, you have the sensors, these are the sensors that act like end users monitoring the network from security perspective as well as the performance perspective.
You have the access points, wifi six, wifi 60, wifi seven, high performance access points, access switches, distribution switches, core switches. This entire fabric is layer three only. There's no layer two, no more VLANs, no more configuration of the ports, no more configuration of the systems, no more configuration of protocols.
We eliminated all of that. This is a complete layer three only. And what you see at the end on the top is, you know, this fabric, gerta fabric can scale from extremely small where you can have just the access layer.
So you, it's not all or nothing with an N just wanna clarify that. It's not about all or nothing. It's really you can grow along as your needs grow.
You can start with the access layer or you can extend it to the distribution layer and you can extend it all the way to the entire campus. So it can grow as you need. And at the end of it you see fabric gateways.
These are the gateways that connect your existing network or terminate your ISP links. And all the traffic from every user and device gets to the policy enforcements. These are our fabric gateways.
Before you, any device can communicate to any other device, you have to go through the policy. Policy has to allow you to communicate only then you are allowed to go to the rest of the world. Until then you cannot connect to the network.
So if you look at it, that native access control, it's not a separate, not a net, you know, separate appliance. It's built in. So the access control is natively part of the fabric.
And then I talked about guest service. So our fabric intelligently, when you think of the guest, takes the traffic panels, the traffic to the internet pops and send it to the internet guarantees they can ever, ever get into corporate network. And more importantly, you know, when you are on the network and assuming that you got authentication to get onto the network, by default you deny you cannot go anywhere.
You have microsegmentation find granular controls that gives you the access, whether you're allowed to go to the internet, whether you're allowed to access anything local resources on the network. So quickly, if you want to compare, can I ask you a question? If you go back for just a minute.
So with zero trust, right, there's, there's the default and denial. Love that there's the policy enforcement when you go to access resource. I love that.
I get that. I like the fact it sounds like you're not just, I allow IP to ip, but you're, you look at ports and protocols, I love that there's also this idea of context and conditions. What else do I know about that device?
Yes. And my policy. Yes.
What are some of those additional aspects that you're checking on a device or an identity before you're allowing them on the network? Sure. The many contextual factors, we take it, since we are access layer, we look at, you know, the type of the device you're using.
Yep. You know, not just your identity, but the type of device. They typically come on Mac device.
But today you are on a Windows device that kind of add to security. Typically you connect between eight to five, but now it's middle of the night. Typically you connect at a certain location, but you are at a different location.
So that's one type of the context. Second type of the context is we can con integrate with your MDMs in tunes of the world or IDs like crowd specs of the world to get the posture additional information about that particular device, right? So you can def you can, as part of the policy, you can define all of these additional attributes, conditions only when these conditions matter, you are allowed to access this particular application or particular device.
So you said something earlier about a blast radius of one I I've on my Windows device and during normal business hours I log in, um, I start working, but for whatever reason, like I'm no longer in policy with Intune, I've changed some of my device or CrowdStrike notices that I'm running some software that I haven't run. Uh, are you able to isolate the host in session? Yeah.
So we automatically, when that posture fails or a condition fails, we put you in a separate quarantine segment and the quarantine group or a segment can give you limited access. Let's say you want to upgrade your software, so you should be able to go to certain sites and up upgrade your software. So we'll show you some of those details as part of the use cases.
Alright, thank you. Before you move on, um, I agree. I mean the, the tool set is a challenge, but it's not the only challenge, right?
So the, one of the biggest challenge to get done to this microsegmentation level of control is understanding what the policy should be, not just the ability to implement the policy itself. Do you provide any tools about visibility or discovery or helping your customers figure out what that policy should be? So the answer is yes.
So as we go through the demos, we'll be able to show you some other information. And more importantly, you'll also, in the closed session, we'll share the roadmap. Okay, on how can, can we automatically do the policies for you?
What does it mean? How do we decide it? Because we have hundreds of customers.
So we can understand based on the device, based on the user, based on the type of the group the user belongs to. We can provide you automated policies as well. Okay, Thanks.
So quick comparison with the current world versus Nile world, right? So if you look at in the traditional world and what you have today is, you know, layer two, pretty much v lance and we had a customer in one of the automakers and they ran into a broadcast storm. Even today, you see broadcast loops happening, it, you know, like one of the customers in Austin, Texas, they connected two ethernet ports on the front and caused the broadcast storm and brought down the network for four hours.
It was almost impossible for them to go and debug. The problem with layer three, we eliminated all of that. We don't even have the stacking protocol.
You can stack all as many switches as you want using layer three. And you know, like when you think of the, uh, walking to e you know, building 19 9% of the times you can go walk into a building and connect to an ethernet port or on the network because every port is by default, it's open. It's extremely hard to secure wired ports.
In our case, every port is secured by default. You have to get authenticated authorized to get onto the network V lens at the best give you microsegmentation. And you heard of the VRF too, right?
So I was talking to a university campus, university customer, and they have about 160 RFS enterprises have, you know, five, six to 10 to 2030 rfs. It's almost impossible to really make that work. So people are trying to do segmentation and ex extremely hard with Nile, it's identity based microsegmentation.
So you can define the policy groups based on your identity, working with the active director, define the policy groups, and you can define the specific access policies that are allowed to do it. And we'll show you as part of the demos. And, um, by default, as soon as user con connects, if you think of a vlan, I can see every device on the vlan and I can propagate the malware.
With Nile, you are isolated from everyone else and only when it's authorized and based on the policy, you're allowed to access rest of that. Now it's not. So we talked about fabric protecting all your users, your employees, you know, guests and partners, and we talked about your IT and IOT and, uh, devices as well.
But more importantly, you need to protect the fabric itself from the attacks. So when a, whenever a user gets, you know, laptop gets compromised, first thing is they discover the network topology and they discover all the resources connected to the network, then they propagate the malware. In our case, we needed to make sure that that won't happen.
So by default, the fabric itself is secure. That, you know, every hardware device that we built comes with a TPM with a secure boot. So when a device gets manufactured, comes to the customer site, if the hardware or the software gets compromised, the box will not even come up.
And more importantly, you know, um, we always run the latest software. We are the network as a service provider, we roll out based on your maintenance windows, based on restricted windows, we automatically roll out the software to make sure you always have the latest software, latest security patch. As a guest know, that's extremely difficult to do in today's world.
It requires a lot of resources, a lot of time, a lot of validation. We eliminate all of that for you. And Sosh, just on that real quick, we have control over that because some environments obviously don't want or can't have automated buffer updates.
Yeah. Especially If they, if they're in set patch windows, like not what I do now, but when previous roles, like, you know, when you're doing, you know, patch deployments or you know, windows updates or whatever it be, and, and patching your servers in boxes, they have to do it like maybe 10 at a time and then 15, like they do it in like four set increments instead of just pushing out. How does that Sure.
Kinda, So let me answer multiple aspects of can. First of all, yes, you do have control on it, so give us a maintenance windows. You can also give a restricted window.
So maintenance window Friday midnight or Saturday midnight, two to no 4:00 AM for example. And it's based on your local time. Or you can say, do not touch anything from Thanksgiving to New York first, you know, uh, happy new, uh, to the New York so that we don't do any of the changes.
That's one. Second is the way we do the software upgrades is first, you know, we have M1 three, M five. So first we always deploy within our Nile networks and make sure everything is working.
Then we have alpha customers. We make sure everything is working there. When we say we make sure we have the agents that are making sure every deployment that we have done, the every user and device is connected back, they have equal or better experience.
Then we have the beta customers, then we have the vertical specific, uh, alpha customers only, then we roll it out to the mass first. So you do have control and it goes to lots of checks and balances. And even well before that, do that as, as we mentioned, we always start with any network at customer site with a digital twin in the cloud.
And we first look at the digital twin, we do all our operations on the digital twin to make sure that when we go and do the, uh, software upgrade, it is successful. So to your point, answer is yes, but we also go through lots of checks and balances, which using some of the AI agents that we have to ensure that the software is, uh, upgraded successful. Is this, uh, like server patching or is this also third party patching?
So this is about our access points, our switches, distribution switches, and the gateways. The entire RO trust fabric, the network side of the patching we are talking about. So just real quick on, just to expand on it, if we have a regulated environment, think of a pharmaceutical.
Mm-hmm. They have to, they have to qualify every version update. They can't just decide that it's gonna roll out.
Sure. How do you work in that environment? So We inform the customers in advance and three days in advance, and depending on the customer, uh, type and customers can choose, I I do want it.
I do not want it. And if needed, we can sit down with the customer and talk to them to give the confidence that this is something that they're okay with it. Perfect.
And more importantly, when you think of the fabric, you know, we came up with attack acts, we came up with the system, port port security, we eliminated all of that. There's no access into our network elements. There's no configuration port, no management port, no telenet and SSH.
If I can log into box, you know it, someone else can log into it. There's no, no matter what we do. So we eliminate because anything, everything you ever needed to know, we have the data in the cloud.
That's the key. And then, you know, the fabric, when we are deploying it, we start with the digital twin as designed. When you're deploying it, we make sure that the deployment aligns with the digital twin that we created.
So there is a, the, you cannot introduce a third party because there's a mutual oath and it also aligned with what we designed in the cloud. So every device has a mutual auth and more importantly, the communication between our systems and the cloud is secured using GRPC or TLS and the communication between our systems, depending on the model you choose, we have the Maxx. So from the access point all the way to exit the Nile service block, that traffic is encrypted end to end.
So even if you tap, uh, try to tap the wire, you'll get encrypted traffic. So now let's talk about a specific use case. You know, we were talking to one of the Fortune 500 customer and they told us their office users are less secure than remote users.
When you think of that, right, because as, uh, Shashi was talking about return to office, when people are coming in from personal environments coming here, now suddenly they're exposed to the rest of the organization. You know, devices are other users, and this is where they've been trying to use N solutions. But 60% of the cybersecurity attacks leverage network vulnerabilities and do the lateral moment of malware.
And the customer was not able to do microsegmentation with JTA fabric. And almost all the CIOs and CSO talk to, they wanna see the right side of the picture where, you know, you have the security for all users, all devices and all the EastWest is protected. But anything that's going up and um, into applications in the, uh, in the data centers or in the cloud, they need to go through SSC.
So we provide you seamless integrations with all of the SSC provides, whether it's Zscaler, Palo Alto, Prisma access, or you know, Microsoft and other players and seamlessly, we, and, and you can select what kind of traffic and that can go to the, you know, the SSC progress before they go to the applications. With that, just to summarize everything that we talked about, we are able to unify the networking and security. So it's completely integrated and it's across all the wide end wireless users and devices.
And with integrations with SSE, we can deliver the complete end-to-end security. And more importantly, simplification. We eliminated all your VLANs, we eliminated private VLANs, we eliminated configurations, the port level security, the system level security.
You don't need to configure any of those things. We eliminated lots of appliances overlay solutions that you needed to do it. And we brought in microsegmentation, it's built in, it's for your IT devices and OT devices as well as for users and more importantly, single pan of glass.
You don't have multiple pan of glasses from multiple vendors, multiple situations and automated using ai we're able to deliver this seamless service. With that, this led a lot of innovations as you can imagine. You know, we are the only one in the industry with the, and we are the only one and we are the first one in the industry to deliver truly unified and wire and wireless.
Katie, you've been in the industry for long enough. You know, we've been trying to do wire unified, the wire and wireless for the last 20 years. Frankly, it hasn't happened yet, right?
This is the first time we are bringing unified wide and wireless and we are also bringing simplification on the authentication purpose. You know, doing the data X on the Y is almost impossible, very difficult. We brought in single signon.
Think of how you get onto an application, use single signon, why can't the network be considered as an application? So when you connect to ethernet plug automatically you get a single signon page with the dual factor authentication, you're on the network. That's the first, you know, innovation and secure guest service.
Almost all of our customers use this guest service where it guarantees that traffic is going only to the internet without, without them doing anything built in microsegmentation, as we talked about, and specifically the, uh, fabric where we, you know, by default we bring in all the gerta capabilities and default deny, which is extremely hard to, uh, uh, accomplish today. And segment of one to your point, right? Every device is the blast.
Radio security is compromised, it's limited to that particular device and it cannot go anywhere else unless there is a policy that allows them to go to that. With SSO, what protocols are you using? So let's say when you connect to the network Yeah, right?
With the wire and wireless, we connect with your Okta of the world or ping identities of the world using via salmon, right? If you're talking about protocol, we use a salmon and we connect with them and we authenticate. And if you use a second factor authentication passwordless mechanisms, you can use any of those because it's seamless for the N.
So if I am thinking again about zero trust at that identity layer, I can run that through my Okta policy. I can run it through my Microsoft conditional policy. Because you're basically doing IDPA handoff.
That's right. Exactly. I have a quick question about the use of, uh, AI agents at scale and using digital twins.
So where, uh, how do you prevent the, uh, decision fatigue and where do you have to have human oversight voice? If I'm a customer? Sure.
So that's a great point, Marion. You know, first of all, can you really trust the AI automatically? The answer is no.
You should never trust that automatically, because even if it is 1% wrong, you don't do not want to bring down the network for that 1% of the time. So it's a critical infrastructure. So what happens median is, you know, we have the, you know, as I talked about, ai, ML and gen ai, which explain in plain English to our production network engineers, they look at the recommendation, then they automate it, they test it, make sure it is working, and we deploy it in few places and then we automate it.
We do not automate at the first stance when the AI recommends it. So after that, it's completely automated. Now you can scale across the globe.
Okay. And then you offer professional services to help with that mapping the process before automation. So Ian, uh, there are two sites.
One is, if you think of anything inside the J task fabric, we automatically handle that. And to add your question, definitely we have pre services for multiple, uh, purposes. One is, you know, when you're trying to do, deploy the network and when you want to migrate from your existing network to Nile, we have the preference services that will help you to, you know, migrate to Nile very easily.