Showing posts with label Blogs. Show all posts
Showing posts with label Blogs. Show all posts

Thursday, May 15, 2014

Windows Server Security Recommendations

The following recommendations are meant as a guide to secure servers (a server being either a physical or virtual instance of an autonomous software system intended to connect with and provide services to other computers). Each and every recommendation will not be applicable to every server; therefore the system administrator should exercise their own judgment in conjunction with their department's own requirements and business needs. Deviations from the recommended guidelines should be documented according to each department's own procedures. The end goal is a secure server that meets the functional and business needs of each department.
Note that if a department is required to comply with PCI (Payment Card Industry) regulations, the specific recommendation has been labeled with "PCI/DSS" so that it may be employed. These are requirements for PCI certification, and therefore not recommendations, if you are subject to the PCI requirements. Also, the sections "Installation" and "Configuration" refer to those recommendations aimed at system administrators. The "Hosting" section is specific to data centers or those hosting a server and "Ongoing" is meant to apply to those individuals/departments maintaining servers.
Specific sections for the most common operating systems at Northwestern have been included (Windows, RedHat Linux, OS X and Solaris). Other operating systems (ie Debian, OpenBSD, etc) are addressed by the more general recommendations that would apply to the respective operating system regardless and further augmented by the hardening guidelines from CIS (Center for Internet Security).

Audience:

Department and group information technology support and information technology security staff.

Policy Statement:

Windows Server Security Recommendations

  • Installation
  • Configuration
  • Networking
  • Hosting
  • Ongoing

Installation

NumberRecommendation/Description
1Disable system restore (if applicable to the version of Windows)
2Systems (servers) with a NetID password feed may not be used for multiple purposes. Exceptions require approval of NUIT-ISS/C.
3(PCI/DSS) Implement only one primary function per server (for example, web servers, database servers, and DNS should be implemented on separate servers)*

Configuration

NumberRecommendation/Description
1Remove, disable or change password of default accounts
2Guest accounts disabled
3All local and domain accounts with privileges above normal user level should have a minimum 15 character passphrase and must be changed at least once every quarter. To facilitate remembering such a password, wallet-sized cards may be created and carried by system administrators for reference.
4Audit the use of all privileged accounts. This auditing should include the read and write access performed by these accounts.
5Machines may not be connected to the network until they have had the latest OS and application updates applied, anti-viral software installed and activated, firewall enabled, AND a strong passphrase enabled on all accounts.
6OS that is not older than one minor release, or service pack, from the current release, if business needs allow for it.
7Software and OS patches installed as soon as practical for your environment.
8(PCI/DSS) Ensure that all system components and software have the latest vendor-supplied security patches installed. Install relevant security patches within one month of release.
9(PCI/DSS) Deploy anti-virus software on all systems commonly affected by viruses, ensure that anti-virus programs are capable of detecting, removing, and protecting against other forms of malicious software, including spyware and adware.
10(PCI/DSS) Ensure that all anti-virus mechanisms are current, actively running, and capable of generating audit logs.
11Hosts should either automatically disable local accounts or attacking hosts for a period of not less than two minutes after 15 authentication failures in a rolling five minute window.
12Unused services should be disabled
13Remove LM Hash
14Clock must be automatically synchronized to a recognized time server (time.northwestern.edu).
15Departments must limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) and to the types of transactions and functions that authorized users are permitted to exercise.
16Departments must establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations.
17Departments must: (i) ensure that individuals occupying positions of responsibility within organizations (including third-party service providers) are trustworthy and meet established security criteria for those positions; (ii) ensure that organizational information and information systems are protected during and after personnel actions such as terminations and transfers; and (iii) employ formal sanctions for personnel failing to comply with organizational security policies and procedures.

Networking

NumberRecommendation/Description
1Appliance based firewall required. If a host based firewall option is available, consider using it in addition to the appliance.
2(PCI/DSS) Build a firewall configuration that restricts connections between publicly accessible servers and any system component storing cardholder data, including any connections from wireless networks.
3(PCI/DSS) Prohibit direct public access between external networks and any system component that stores cardholder data (for example, databases, logs, trace files).
4No open, non-authenticated, file sharing may be enabled.
5(PCI/DSS) Encrypt all non-console administrative access. Use technologies such as SSH, VPN, or SSL/TLS (transport layer security) for web-based management and other non-console administrative access.  
6Remote access software must be disabled or restricted to specific IP addresses by default. It can be temporarily enabled on a case by case basis by authorized personnel. Only software that supports end to end encryption should be used for this purpose.

Hosting

NumberRecommendation/Description
1Port Reporter or similar system installed and active.
2Encrypted backups should be taken regularly, and all on/off site storage should be physically secure.
3(PCI/DSS) – Clocks must be synchronized to two (2) internally hosted time servers (time.northwestern.edu) *
4Housed at University data center or similar setup.

Ongoing

NumberRecommendation/Description
1Mandatory audit log monitoring program or procedure by personnel of the department owning the logs or an approved subcontractor/vendor.
2(PCI/DSS) Logs must be reviewed, or aggregated and then reviewed, daily.
3(PCI/DSS) Logs must be available online (electronically) for three months, available on tape (or other removable media) for one year.
4(PCI/DSS) Ensure that all system components and software have the latest vendor-supplied security patches installed. Install relevant security patches within one month of release.
5(PCI/DSS) Establish a process to identify newly discovered security vulnerabilities (for example, subscribe to alert services freely available on the Internet). Update standards to address new vulnerability issues.
6Encrypt sensitive data (Recommendations currently in development).
7Defined process for approval, acceptable use, and removal of system privileges.
8(PCI/DSS) Follow change control procedures for all system and software configuration changes.
9(PCI/DSS) Identify all users with a unique user name with at least one authentication method (passphrase, token device and/or biometrics).
10(PCI/DSS) Immediately revoke access for any terminated users.
11Remove inactive user accounts at least every 90 days.
12(PCI/DSS) Set first-time passwords to a unique value for each user and change immediately after the first use

Wednesday, January 8, 2014

IT career salaries infographic: Salary expectations, projects and mood

IT career salaries infographic: Salary expectations, projects and mood

Emily McLaughlin, Associate Site Editor, and Rachel Lebeaux, Managing Editor
Have you wondered how IT career salaries at your company stack up against the masses? Do you think the mood within your IT organization is unusually optimistic -- or pessimistic? In this year's Annual Salary and Careers Survey, Tech Target polled 1,771 IT professionals -- ranging from systems administrators to CIOs -- about their total compensation and overall job satisfaction in 2013. The survey covered everything -- from bonuses and pay cuts to staffing to IT priorities in the coming year. In this Search CIO salary info graphic, we reveal how your paycheck compares to those of others with a similar job title, divulge that salary expectations are on the rise and show that IT professionals are optimistic about the road ahead.


CIO IT salary infographic



Saturday, January 4, 2014

10 companies where employees are most happy

10 companies where employees are most happy

Bob Iger, Chairman and Chief Executive Officer, of the Walt Disney Company, stands next to Mickey Mouse in front of Sleeping Beauty Castle.

There are some companies that know how to keep their employees happy, while there are others where staff is usually unhappy.
Let's take a look at companies where workers are most happy.
Source: careerbliss.com
Pfizer
Industry: Pharmaceutical
Headquarters: New York, United States
Revenue: $58.98 billion
Employees: 91,500
Happiness score: 4.139
Average salary: $83,000
Rank in happiness: 1
Pfizer, which is one of the largest pharmaceutical companies by revenue in the world, keeps its employees happiest.
Kaiser Permanente
Industry: Healthcare
Headquarters: Oakland, California, United States
Revenue: $47.9 billion
Employees: 190,900
Happiness score: 4.122
Average salary: $76,000
Rank in happiness: 2
Kaiser Permanente, which is the largest managed care organisation in the United States, operates in nine states and the District of Columbia.
 Texas Instruments
Industry: Semiconductors
Headquarters: Dallas, Texas, United States
Revenue: $12.82 billion
Employees: 35,759
Happiness score: 4.120
Average salary: $81,000
Rank in happiness: 3
Texas Instruments, which is the third-largest manufacturer of semiconductors in the world, is considered one of the most ethical companies in the globe.
EMC Corporation
Industry: Computer storage
Headquarters: Hopkinton, Massachusetts, United States
Revenue: $21.713 billion
Employees: 60,000
Happiness score: 4.118
Average salary: $89,000
Rank in happiness: 4
EMC Corporation, which offers data storage, information security and cloud computing, is one of the largest provider of data storage systems in the world.
Qualcomm
Industry: Telecommunications equipment and semiconductors
Headquarters: San Diego, California, United States
Revenue: $24.87 billion
Employees: 26,000
Happiness score: 4.114
Average salary: 87,000
Rank in happiness: 5
Qualcomm, a semiconductor company that designs, manufactures and markets digital wireless telecommunications products and services, operates in 157 locations around the world.
KBR
Industry: Engineering, construction and private military contractor
Headquarters: Houston, Texas, United States
Revenue: $9.1 billion
Employees: 27,000
Happiness score: 4.095
Average salary: $86,000
Rank in happiness: 6
KBR, which is an engineering, construction and private military contracting company, is the largest non-union construction company in the United States.
Bristol-Myers Squibb
Industry: Pharmaceuticals
Headquarters: New York City, United States
Revenue: $20 billion
Employees: 30,000
Happiness score: 4.063
Average salary: $81,000
Rank in happiness: 7
Bristol-Myers Squibb, which is a pharmaceutical company, has operations around the world, including India.
General Electric
Industry: Conglomerate
Headquarters: New York City, United States
Revenue: $147.35 billion
Employees: 305,000
Happiness score: 4.053
Average salary: $75,000
Rank in happiness: 8
General Electric, which is the fourth-largest company in the world, operates through four segments: Energy, Technology Infrastructure, Capital Finance and Consumer and Industrial.
Capital One
Industry: Financial services
Headquarters: Virginia, United States
Revenue: $21.39 billion
Employees: 40,000
Happiness score: 4.051
Average salary: $67,000
Rank in happiness: 9
Capital One, which specialises in credit cards, home loans, auto loans, banking and savings products, pioneered mass marketing of credit cards.
Avaya
Industry: Telecommunications
Headquarters: California, United States
Revenue: $5.17 billion
Employees: 17,000
Happiness score: 4.048
Average salary: $87,000
Rank in happiness: 10
Avaya, which supplies contact centres, networking hardware, unified communications and video products, is a major player in networking systems and the unified communication systems.

Wednesday, January 1, 2014

How to solve operational BI problems with SOA middleware

While traditional business intelligence (BI) focused on aggregation and improved historical data analysis, operational BI attempts to improve the decision-making process for frontline workers. This requires a different focus on taking data from real-time systems to help improve this process. A good service-oriented architecture infrastructure can help bring data together in a way that support s this as new insights arise.
puzzle piece fitting in
VEGE - FOTOLIA
"The operational BI system has to use the data about the customer and the context to give good advice to the front line worker," said James Taylor, principal consultant of decision management solutions, an analytics consultancy. "It can provide massive leverage, because any decision you make can be leveraged across employees."
In the operational context, training is lower and these workers don't have the same ability to make good judgments as an analyst. The value is even higher when you start targeting these workers. "You want a new hire on the phone with a customer to be able to respond appropriately," Taylor noted.

Focus on the problem

The first thing to remember is that operations analytics is not a wide open exploration of data; there is a focus on a business problem. Operations analytics provides a benefit to a specific issue that can lead to smarter procedures or more efficient use of resources.
In traditional BI, the focus is often on setting up a big data warehouse to answer any question. Operational BI, however, is about finding an answer to a specific business problem, usually for a nontechnical user. This means you don't give an analyst a tool to try out. You have to think about giving the nontechnical worker an answer, and make sure that answer is relevant and worth giving as a response on a regular basis.

Think in terms of events

With operational BI, the infrastructure is more event-oriented and needs to be able to pick up on real-time transactions. The infrastructure required is more like application integrationthan traditional data integration, according to Jake Freivald, vice president of corporate marketing for Information Builders. "We have seen a convergence between operational BI and traditional BI. We do see them coming together where historical BI is used to create a baseline for operational BI," he said. "A key part of this is the use of middleware that incorporates BI on top."
An enterprise architect has to begin with the end user in mind instead of the analyst.
Freivald sees more organizations willing to forego data warehouses than in the past. There is also more openness to the idea that you will not necessarily have a data warehouse. This means less focus on the tools and more on the SOA infrastructure required for supporting this style of integration.
Traditional BI is more concerned with loading the data warehouse, whereas operational BI is about creating process flows that add intelligence into operations for a particular business problem. Operational BI zeros in on one transaction and is concerned with data flow, rather than the information being instantiated in a data warehouse. After the transaction, this data can be dumped.

Real-time cleansing

Organizations need to make sure they are working with good data if they want to arrive at useful decisions. "Data quality used to be something that would happen on the way to the data warehouse," Freivald said. "But if you are not using a data warehouse, it needs to be cleaned in real time to be relevant to the operational systems."
A single transaction is not enough to make decisions on. There needs to be an enrichment process to make the data useful. With ETL (extract, transform, load), the enrichment process is easy. The system gathers results, marries them and sends them to the data warehouse.
With operational BI, the enrichment process happens in real time. For example, an application may have to reach into the systems to see if a particular transaction is fraudulent, such as comparing how many have occurred in a given week versus the customer's history. It has to evaluate how this compares with the predictive model to determine if a certain transaction is likely to be fraudulent, such as a customer relationship management or trade clearing, or you may need to go to a cloud-based resource.
The concept of a data quality firewall can help address this. "In the same way that a security firewall protects corporate systems from hackers, a data quality firewall protects operational BI systems from dirty data," Freivald said. The data quality firewall creates an infrastructure to clean, correlate and enrich transactions on the way into high-value systems. This makes is possible to do operational BI without worrying about the quality of the data to make decisions.

Focus on messaging instead of files

Another key element to building successful operational BI systems lies in thinking about messaging, rather than files. Enterprise architects need to think about middleware instead of ETL and data integration. "This requires different tools with a different mindset," Freivald said.
For example, Freivald talked to a bank recently that wanted to do fraud analysis of ATM transactions. The bank kept asking how to scrape the VSAM files used for storing the data. In this case, it made more sense to put a listener on the wire for the messages as they came in, rather than trying to access the files. "They were not thinking about messages since they were used to thinking about managing information using files," Freivald explained.

Making it work on the front line

An enterprise architect has to begin with the end user in mind instead of the analyst. The system needs to be simple and straightforward enough that a nontechnical worker can benefit from straightforward decisions delivered on a regular basis.
Freivald said this also involves integrating the information into the existing workflow. If a user has to leave the main application screen, it is unlikely they will look for an answer or that they will trust it. This means integrating the operational BI capabilities into their day-to-day Web application, CRM or the mobile device.

Expanded governance

It is important to think about the potential adverse impact of more information in the hands of a wider group of employees. It is one thing to give a trusted group of analysts' access to richer platforms for analyzing data, but that could create problems when the data is dispersed too widely.
"If I choose to present more data, I have to be careful about what is shown compared to if I only show it to 10 executives," Taylor said. People using that environment don't need to see the data, just the results of analyzing it. You don't need to include personally identifiable information in those models.

Be ready for change

An enterprise architect has to look at the business process first and find things in the process that could be improved by adding intelligence. These need to be processes worth the investment of setting up the operational BI. You need to have analysts look at the problem because they understand the big picture, and you need business people looking at the answers the analysts are seeing.
Setting up an operational BI system tends to be iterative. Don't expect your first version to be awesome. You might find the operational BI system does not do what you want but could be improved with some additional data or predictive analytics running in the background. "This is an iterative process, and the business benefits won't come from a single waterfall-style development cycle," Freivald said.
You also need flexible people and middleware. There won't be a single-use ETL product to get from one database to another. It will call upon other applications and other BI models. "The main best practice is to focus on improving the business process and iterate on that with the right combination of business people," Freivald said.

Year in review: Cisco ACI, faster switches pace networking

Gargantuan switches, full-volume shipping of eagerly anticipated silicon and a glimpse into Cisco's SDN-flavored Application Centric Infrastructure (ACI) initiative were three of the dozens of major developments that shaped the networking industry in the past 12 months. These developments, in concert with faster Wi-Fi and accelerated WAN technologies, reflected an industry on the cusp of even greater transformation, as vendors laid the groundwork for new definitions of networking that will be revealed in the months and years to come. Below, a glimpse at some of the events and developments SearchNetworking covered in the past 12 months.

Click the links to check out the top stories from a particular month:

December

January

Cisco announced the expansion of its virtual desktop computing and collaboration architecture with Virtual Experience
Media Engine -- VXME. A major benefit of VXME is that it processes data locally, thus helping users avoid hairpinning communications -- sending messages through a data center before reaching their destination. This eliminates the middleman and allows for more direct communication flow.
Just how open can OpenFlow research be now that vendors are using educational institutions as proxy product development and testing centers? January's Techs in Paradise conference in Honolulu examined the challenge research and education institutions face as they develop the open source OpenFlow protocol. On one hand, engineers need an open and collaborative environment; on the other, once an institution partners with a vendor, it is usually asked to sign a nondisclosure agreement, which limits how much research it can share.

February

Cisco rolled out a new application-specific integrated circuit. The chip, called the Unified Access Data Plane (UADP), is most beneficial to Cisco's product development teams who will no longer have to build new hardware to add new features to products, analysts said. Combined with Cisco's new modular IOS-XE IOS software -- which allows switching, routing, security and wireless control to run as partitioned services on top of a broader operating system -- UADP opens up new possibilities for Cisco to develop future products quickly and efficiently.
Hewlett-Packard Co. launched a device to integrate wireless LAN controller functionality into its switching products. The device, the 10500/7500 20G Unified Wired-WLAN Module, is a wireless controller blade for HP's modular 10500 and 7500 switches. HP also introduced a new User Access Manager and Smart Connect module for its Intelligent Management Center, which simplifies the deployment and management of policy-based bring your own device access.

March

Juniper Networks Inc. announced plans to launch a new line of high-capacity switches based on its MX series of carrier-class routers. It said it would continue to sell the EX8200, but would no longer invest in its hardware platform. The rollout of the EX9200 reflected a general understanding among many networking vendors that they had been neglecting campus switching while focusing on the data center.
Cisco adjusted the requirements of its entry-level Cisco Certified Network Associate (CCNA) exam to make it easier for IT professionals to develop their careers. Requirements for the CCNA Voice, CCNA Security and CCNA Wireless accreditation were streamlined so that test-takers only have to pass two exams instead of three. The idea was to make it easier for employers to find specialists, as well as help professionals define their career paths.

April

Hewlett-Packard launched the HP FlexFabric 12900 series. The series, a line of data center switches, routers and virtual switches, greatly expands HP's data center core switch family. The premium 12916 chassis, with a maximum of 36 Tbps, and a nonblocking fabric with a top of 768 by 10 Gigabit Ethernetor 256 by 40 GbE ports, has industry-leading capacity. It also launched the FlexFabric 11908 data center switch for the aggregation tier of large networks, and the HSR 6800 router series, which HP described as a carrier-class router for data center WAN edge connections.
After a year in development, Brocade Communications Systems Inc. began shipping HyperEdge, a management platform that gives administrators a single point of oversight over all HyperEdge-compatible switches in a network. With a single management IP address for all switches, administrators use a single pane of glass for configuring and managing a network.

May

Facebook announced plans to expand its Open Compute Project to include a top-of-rack data center switch. The aim of the project's latest update is to design switches that can run any network operating system and give data center operators the ability to decouple hardware and software in their networks.
Motorola Solutions Inc. introduced its 802.11ac access point series -- the AP 8232, AP 8222 and AP 8263 -- for both indoor and outdoor deployments. The three new access points, shipped with a fortified version of Motorola's LAN software, WiNG 5.5, can be managed from a single dashboard for IT via Motorola's NX 9500 controller.
Array Networks Inc. rolled out four application delivery controllers: the mid-level APV 2600 and 5600, as well as the higher-end 10600 and 10650 models. Each appliance supports 10 GbE interfaces, multicore processing and 2048-bit SSL acceleration.

June

Cisco used Cisco Live to introduce data center network features that automate and optimize massive spine-leaf architectures, as well as a core switch that dwarfs its competition in scale and performance. Cisco also unveiled a refresh of its campus switching and enterprise routing products, highlighted by the Catalyst 6800 series, a big brother to the Catalyst 6500 that is compatible with the older switch's existing supervisor modules and line cards.
Startup Cumulus Networks Inc. came out with a Linux-based network operating system that complements Facebook's Open Compute switch project. The OS is engineered to run on bare-metal switches and is tailored to provide some of the programmability of software-defined networks (SDN) without requiring the use of a controller. Cumulus also disclosed a list of vendors and partners with whom it will work to develop switches and other devices with the firm's OS already built in.

July

In an effort to more efficiently manage development and optimize performance of its top-of-rack and EX switches, Juniper Networks integrated its switching, routing and wireless LAN technologies under a single business unit, the Platform Systems Division. Juniper Executive Vice President Rami Rahim explained that Juniper was investing heavily in its broad switching portfolio and increasing simplicity to reduce the cost of running the network.
Cisco spent $2.7 billion to acquire network security specialist Sourcefire in an effort to strengthen its security business. Sourcefire's open source intrusion prevention technology,Snort, is one piece of the prize. The other: Sourcefire's Vulnerability Research Team. Analysts said engineers who specialize in writing signatures used in intrusion and malware protection are hard to come by.

August

Dell Inc. and Hewlett-Packard both announced new top-of-rack data center switches with high-density 40 Gigabit Ethernet ports at VMworld. The switches represent the ongoing advancement of top-of-rack switches with throughput and port density to handle servers with 10 GbE interfaces.
The notion of application-defined networking (ADN) gained traction as vendors tried new approaches. Some vendors, such as Brocade, Citrix Systems Inc. and F5 Networks Inc., extended the load-balancing capabilities of their products. Others, such as Cisco, will rely on the Cisco ACI initiative that enables applications to run in any environment, cloud or traditional data center, virtually or on bare metal. Lyatiss Inc. , a recent startup, is developing software-only ADN platforms.
Mobile malware attacks grew more than 600% in one year, according to research released by Juniper Networks. The vendor, in its third annual "Mobile Threats Report," said that out of 276,000 malicious apps counted in the study, 92% were aimed at Android users. The increase in Android malware was a result of Google taking a bigger share of the worldwide smartphone market.
Despite a good 2013 fiscal quarter, Cisco announced plans to cut 4,000 jobs, or 5% of its global workforce. Corporate execs said the move was taken to allow it to be more nimble as it placed resources into growing business units. But some observers said the layoffs reflected other changes sweeping through the networking industry.

September

Brocade added native multi-tenancy to its Virtual Cluster Switching Ethernet fabric, allowing network engineers to dramatically increase the number of network segments that can be created in a Layer 2 network.
With the launch of NSX, VMware Inc. clarified how it intended to pursue the network virtualization market. But NSX, a platform that combines the company's virtual networking technologies with overlay technologies from Nicira, opened a debate between system administrators and networking pros, kindling a potential conflict in the data center.
Hewlett-Packard entered the next-generation firewall market with a new line of TippingPoint firewalls. The new line extends the appliances' existing intrusion prevention systems with traditional packet filtering and application control. Businesses interested in intrusion prevention are the main beneficiaries.
Extreme Networks Inc. bought Enterasys Networks for $180 million. The partnership brought together Extreme's expertise in data center networking with Enterasys' experience in campus networking and wireless LANs.
Network security, Wi-Fi and data center network architecture upgrades were the primary goals for enterprises and organizations for 2014. According to TechTarget's 2013 networking purchasing intentions survey, a third of respondents said security was their main concern, while wireless and data center upgrades were cited as priorities by 27% and 25% of respondents, respectively. The survey included responses from more than 2,700 key networking and IT executives and professionals worldwide.

October

Juniper Networks announced MetaFabric -- a new architecture that ties together switching, routing and software into a comprehensive approach for data center and cloud networking. The new architecture addressed hybrid environments -- allowing interconnections between data centers themselves, as well as between data centers and the cloud, analysts said.
After some delay, Broadcom Corp. began shipping full production volumes of its StrataXGS Trident II network chip to switch manufacturers. Switch makers are using the silicon to anchor high-density data center switches with a range of features, including support for Virtual Extensible LAN, the tunneling platform that will enable vendors to integrate with network virtualization platforms such as VMware NSX.
Arista Networks Inc. shipped its first line of top-of-rack switches based on Trident II. The 7050X switch, with 2.56 Tbps of capacity, can process 1.44 billion packets per second and is geared to high-performance data centers with high-frequency trading environments and supercomputing environments.
Aruba Networks combined its cloud management platform -- Aruba Central -- with a series of instant access points to deliver a cloud-managed Wi-Fi offering for distributed enterprises and smaller branch office locations. Aruba also expanded its switching portfolio with the new Aruba S1500 Mobility Access Switch for cloud Wi-Fi environments.
Cisco beefed up its line of merchant silicon-based, top-of-rack data center switches with its new Nexus 3100 series. The switch is a low-latency, high-density Layer 2 and Layer 3 device, aimed at enterprises that require top-of-rack switches that can be deployed in a spine-leaf architecture using conventional Layer 3 protocols.

November

Cisco's launch of new data center switches as part of its SDN-flavored ACI had some customers concerned about the future of their existing investments in Cisco's data center switches. The new switches, the Nexus 9000 series, run on the ACI framework, but other switches, including the 7000 and 7700 core devices, will not.
Extreme Networks released its top-of-rack data center switch. The Summit X770 is engineered to ease the migration to 10 GbE and 40 GbE and is also targeted at companies with intensive big data analytics projects.
F5 Networks announced Synthesis, an application delivery structure that encourages data center operators to buy and operate application delivery controllers as fabric rather than as sets of appliances for specific applications.
Arista Networks released its 7000x Series of high-density switches enabling the concept of a single-tier "Spline" network. In Spline architecture, the switches are intended to automate provisioning, simplify cabling, reduce latency and cut network costs, trimming operating expenditures by as much as 40%.

December

Riverbed Technology Inc. integrated its Cascade performance management software into its Steelhead WAN optimization product line to combine deep application visibility and network control from anywhere on the network. The integration is engineered to give network administrators the ability to centrally manage applications across private WAN links and public Internet connections from any point on the WAN.
Silver Peak Systems Inc. added capabilities to its WAN optimization software that permits companies with hybrid WAN networks to use the best and most reliable routes to transmit their data. The new feature, Dynamic Path Control, automatically determines whether broadband Internet or Multiprotocol Label Switching is the best route, gauging metrics that include latency, packet loss and available bandwidth.