Construction
Humphreys Replaces MPLS, SD-WAN Appliances, and Mobile VPN with Cato Cloud
MPLS Problems Complicate Networking
For years, MPLS services were the defacto standard for connecting company locations. And so, like many enterprises, Humphreys duly built its U.S. network on MPLS. The MPLS service gave Humphreys the predictable transport necessary for running business-class voice service, but it also brought plenty of headaches.
βThe problem with MPLS is that itβs expensive, slow, and takes forever to get anything done,β says Paul Burns, IT Director at Humphreys.
Connecting new locations took far too long, with circuit delivery requiring several months. βNinety days doesnβt fly anymore when a site is just two or three people in a garage and DSL can be delivered in a day or two,β Burns points out.
Whatβs more, MPLS wasnβt agile enough to accommodate Humphreysβ growth. βMany of our offices start with a few people, but then they outgrow the space. Every time we moved, our carrier wanted a three-year contract and 90 days to get the circuit up and running.β
Even simple network changes, like adding static routes to a router, necessitated submitting change tickets to the MPLS provider. To make matters worse, the carrier team responsible for those changes was based in Europe. βNot only did the carrier require 24 hours, but often the process involved waking me in the middle of the night,β Burns says.
MPLS inflexibility hurt more than the business; it hurt Burnsβ reputation. βI once sat in an executive meeting and learned that we were moving an office,β he recalls. βI explained to the other executives (again) that the move would take at least 90 days. They just looked at me like I was crazy.β
When Humphreys opened an office in Uruguay, Burns wanted to connect it to his MPLS service. His provider offered only a 1.5 Mbits/s MPLS connection for $1,500 a month, about the same price as his 50 Mbits/s MPLS connection in Dallas. βIt was a take-it-or-leave-it kind of deal β so we left it.β
SD-WAN Edge Appliances Not Much Better
Burns began investigating SD-WAN with Internet connectivity as a way of connecting his Uruguay office, maintaining MPLS for his voice service. He gradually deployed SD-WAN appliances in Uruguay and four other locations, swapping MPLS inflexibility for SD-WAN complexity.
βThe configuration pages of the SD-WAN appliance were insane. Iβve never seen anything so complicated. There were pages upon pages of settings with so many options,β says Burns. βEven the sales engineer got confused and accidentally enabled traffic shaping, limiting our 200 Mbits/s Internet line to 20 Mbits/s.β
The appliance-based architecture also proved difficult to get fully working. The SD-WAN appliances had to establish tunnels with one another, but that didnβt always happen. βSometimes Dallas could connect to two sites, but they couldnβt connect to each other. The vendorβs answer: update our firmware and reboot. But that didnβt work.β
Ultimately, Burns abandoned the SD-WAN appliance architecture. βIt was just the maintenance of it. We would get an e-mail every time there was some SD-WAN-related error. You expect e-mails at 4 am with a telco when itβs doing network maintenance and things go down. I donβt expectΒ thousandsΒ of early morning e-mails from an SD-WAN appliance.β
Cato: Converging SD-WAN, Security, and Mobility Simplify Networking
Burns decided to try Cato Cloud, Catoβs SD-WAN as a service. βWe drop-shipped devices out to New Orleans, and I flew out to install the stuff. Took less than a day, and performance was great.β
Eventually, he deployed Cato in every location but Garland and Orlando, which were still under MPLS contract. Cato was particularly helpful in connecting locations outside the U.S.
βCato gave us freedom. Now we can use a socket, a VPN tunnel, or the mobile client, depending on location and user requirements.β
βMy biggest concern with connecting Vietnam to our previous SD-WAN was shipping the appliance. There was the matter of clearing customs and installation. Weβd be dealing with a communist country, and I wasnβt familiar with its culture. Instead, users can now just download and run Catoβs mobile client.β
As for the Uruguay office, Burns could use a firewall-initiated IPsec tunnel. βWe set up Uruguay in 10 minutes because we just built a VPN tunnel through the existing firewall,β he says.
Burns expects to migrate all local firewalls to Cato. βOur public-facing βstuffβ has been relocated to the datacenter. The only inbound traffic comes from people βRDPingβ into their computers through Dallas. Now, when we see that, we just fix them up with the Cato VPN.β
Convergence Brings Business Value
Catoβs converging of networking, security, and mobility onto a managed backbone simplified Humphreysβ networkΒ andΒ helped the business.
Bandwidth costs will reduce as Burns phases out MPLS at the remaining locations. He can eliminate MPLS because of Cato Cloud quality and predictability. Cato Cloudβs latency and loss levels were more than sufficient for business-grade voice, he reports.
Humphreys was also free to tap the best talent without connectivity concerns. βOur Newport Beach branch wanted to hire a guy in Scottsdale, but we had no office there,β says Burns. βWith Cato, we just connected him with Catoβs mobile client. Without Cato, the guy basically wouldnβt work for us, or his functionality would be 25 percent of what it is now.β
Burns loved Catoβs security features as well. βWe hadnβt even subscribed to Catoβs security services, but we were alerted to potential malware on our usersβ machines,β he notes. βThatβs something that none of our other network providers can offer.β
Burnsβ bottom line on Cato? βWe set out to address our MPLS problem, and along the way we got an affordable MPLS alternative, security solution and mobile VPN solution.β