Bandwidth aggregation and efficient WAN optimization can be achieved using a WANBOX network appliance connected to a regional WANBOX network server through an active WANBOX Virtual Leased Line service subscription.

The WANBOX network appliance is placed between the customer’s LAN and the WAN connection modems/routers, acting as an internet gateway. It distributes data traffic at the packet level to the available WAN connections.

The WANBOX network server is a fully-managed cloud server within our global private cloud infrastructure. For each new WANBOX deployment, we provision a new dedicated virtual server located in the nearest data center to the Customer premises. The network server or bandwidth aggregation server is essentially the other end of the circuit, where multiple WAN connections are transformed into a single one.

Why WANBOX VLL Technology?

The WANBOX VLL technology enables the deployment of cost-effective, flexible, easily managed, high-performing professional WANs. Through the intelligent traffic distribution to multiple WAN paths, WANBOX services perform absolute bandwidth aggregation, allowing the maximum utilization of the available telecom resources.

Splitting Traffic at the Packet Level

WANBOX

MULTI-WAN SERVICES

Book a Demo

The WANBOX VLL Technology makes real bandwidth aggregation possible by distributing individual packets to multiple Internet connections. By splitting all your Internet traffic at the packet-level, even large single socket transfers can be given a major speed boost! As a result, your business network can support high performing VPNs, uninterrupted video/audio streaming and ultra fast file transfers.

Technology Feature

Optimized bandwidth aggregation of diverse media



All WANBOX multi-WAN services use our proprietary traffic distribution algorithm to aggregate the bandwidth of multiple WAN connections and create a virtual “fat-pipe” whose speed is equal to the sum of the speeds of the individual WAN connections used.

The aggregated bandwidth offered by WANBOX VLL technology is available even for a single session (e.g. the transfer of a single file) since the data is sent simultaneously utilizing all the available WAN connections. The algorithm is self-tuning and adaptive to changes by monitoring the available WAN connections in real time, continuously measuring and watching each link for loss, latency, jitter and congestion. This allows intelligent traffic handling of applications’ data across the WAN and the cloud.

Furthermore, the algorithm mitigates WAN connections’ outages and errors by rerouting data packets to the functional connections. As a result, WANBOX services enable predictable and consistent Internet/VPN connectivity without impacting the applications’ performance.

Smart (Transparent) same IP Failover



It enables the ability to survive WAN connections’ outages without a change in public IP addresses allowing for session continuity.

Low-cost public IP connections often suffer from many interruptions (downtime). As a result, these connections are unusable for certain periods. To improve the availability of corporate WAN networks, the WANBOX VLL technology uses the Smart Failover algorithm.  The algorithm reroutes sent and received data over the remaining WAN connections when part of these fail, isolating the faulty connections and ensuring that the end user does not notice any session interruption.

To achieve the maximum uptime, combining connections of different types and ISPs is recommended. The combination of wired and wireless WAN connections results in a hybrid WAN of unprecedented availability.

End-to-end, bi-directional Quality of Service



The WANBOX SD-WAN services offer reliable end-to-end QoS over multiple WAN connections in a simplified manner.

Many real-time or business-critical applications need to be routed with high priority to achieve constant speeds without interruptions. This is extremely important when simultaneous traffic of other types exceeds the maximum WAN throughput. Priority setting as well as the definition of the available bandwidth for each type of Internet traffic is undertaken by the Bandwidth Management (QoS) system, which manages the flow of data and allows for better performing real-time services (VoIP, Video-Conferences, Audio & Video Streaming, E-Learning platforms etc) and the control of the reserved bandwidth per application/device.

The Bandwidth Management system is able to support QoS classification via DSCP when the QoS classes are configured in a third-party appliance (VPN server, Router, Firewall, UTM, etc).

Packet loss & Latency management



The WANBOX VLL technology incorporates a Performance-enhancing Proxy designed to improve TCP performance over high latency and congested links.

By splitting the TCP sessions it enables an optimized TCP stack introducing cutting edge congestion control and loss recovery mechanisms. These mechanisms rely on link utilization metrics that are calculated in real time to ensure fast and uninterrupted data flows. This feature is a must have when individual WAN links face high packet loss or latency such as satellite connections.

The Transparent Performance Enhancing Proxy involves the breaking up of long end-to-end control loops to several smaller control loops by intercepting and relaying TCP connections within the network. By adopting this procedure, it allows for the TCP flows to have a shorter reaction time to packet losses which may occur within the WAN, thus guaranteeing a higher throughput.

Real-time data compression



The WANBOX VLL technology enables real time data compression on the network layer to accelerate data transfers for uncompressed data.

Sent and received data is automatically compressed in real time to save bandwidth and further improve the WAN performance. The transmitted data can be reduced by 90% depending on the packets’ payload. This feature is extremely useful when it comes to broadband connections with traffic caps as it reduces the data transmitted, thus saving costs.

Jumbo Frames

 

The WANBOX VLL technology uses Jumbo frames to achieve higher protocol efficiency.

With a larger frame size and thus a larger payload size, the WANBOX VLL technology achieves less protocol overhead, and the bandwidth saved is available for the packets’ payload. This feature also helps in the real-time compression mechanism, as it enables a greater degree of data compression, saving even more bandwidth from the available WAN connections.

Forward Error Correction

 

Real-time application traffic can be duplicated to guarantee no loss and optimal performance.

This feature normalizes the performance of real-time applications by transmitting data in redundant mode via multiple WAN paths.

The system selects the best two WAN connections in order to transmit two identical copies of the real-time data packets at the same time. Whichever packet gets through first, is the one to be delivered. This feature guarantees the smooth operation of real-time protocols even when the available individual WAN connections face high packet loss and jitter.

Special Purpose Connection Legs



This technology feature allows specific WAN connections to be used by the bandwidth aggregation algorithm for specific types of traffic. As a result, the corporate network can take advantage of WAN connections with traffic caps for business critical applications.

This feature allows the configuration of sophisticated policies regarding the utilization of the available WAN connections. In fact, it allows each connection to be used by the bandwidth aggregation algorithm for specific QoS classes. This results in further increasing the available bandwidth or enabling additional WAN paths for redundancy.

Policy Based Routing



It allows the definition of rules in order to route specific types of traffic directly via specific WAN connections

The Policy Based Routing functionality provides an extremely powerful, simple, and flexible tool to implement advanced routing policies. In cases of legal or political constraints, the system can be configured to route specific traffic through local ISP connections.

Legacy session Load Balancing



The legacy session load balancing functionality offers the ability to distribute different sessions to the available WAN connections.

This feature is mainly utilized as a failover mechanism to maintain Internet access when the server infrastructure faces downtime. It is automatically enabled in case the WANBOX network appliance gets disconnected from the WANBOX network server, maintaining Internet access until the server connection is resumed. The session load balancing feature uses a round-robin algorithm to distribute sessions to the available WAN connections. Additionally, it supports sticky connections for compatibility with Internet services that track source IP addresses.

Transparent routing



The WANBOX network appliance offers the ability of transparent routing via the bridged mode functionality.

It enables the transparent operation of the WANBOX network appliance by forwarding the provided public IP addresses to the customer’s internal network. The public IP addresses can be configured on the WAN port of the customer’s edge Router or Firewall appliance. This feature allows the customer to maintain the available network infrastructure without altering the existing network configuration.

State of the art network security

 

Traffic Authentication at the Node Level

The CPE and the aggregation server authenticate each other using 4096-bit RSA keys and the TLS v1.2 protocol along with the TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 strong encryption cypher suite (256-bit AES encryption with SHA-384 message authentication and ephemeral ECDH key exchange signed with an RSA certificate). Keys are generated, managed and signed by a private PKI, avoiding the problems of trusting third-party CAs and presenting a far smaller attack surface by eliminating the complex certificate chain validation risks commonly linked with SSL security. All of the above ensures no attacker can modify or forge bonded traffic between the CPE and aggregation server.

Furthermore, all network traffic between the CPE and the aggregation server can optionally be encrypted using the above algorithm/cypher suite to safeguard the user data transmitted between the WANBOX VLL service endpoints.

 

Packet-Level Distribution Across Bonded Connections.

By its nature, the technology is highly secure. The packet-level distribution algorithm spreads traffic across multiple Internet connections. Even if an attacker manages to capture one of your individual Internet connections, only a small part of your entire traffic is visible. So, even though this is not a standardized security feature, it clearly provides a strong additional level of security.n server.

 

Seamless Integration with Existing Network Architecture

Your existing network security design will not be impacted. The technology supports all encrypted VPN traffic, and is also completely transparent to SSL traffic.

 

Remote Bonding Appliance (CPE) Security

Industry-standard SSL protects the appliance from unauthorized control. The CLI that could be accessed with SSH is equipped with protective functions by using access control lists. All services integrated in the router can be precisely configured in regards to how these services are accessible via which interfaces and IP networks.

 

Standard IP VPN encryption

The system has the ability to perform SSL IP VPN encryption for hub-and-spoke VPNs using 4096-bit RSA keys with SHA256 certificates, TLS v1.2, and Diffie-Hellman key exchange with elliptic curves.

 

Secure Operating System

Our service uses the popular open source Linux distribution CentOS. Many contributors around the world work to enhance the security of this operating system, from reviewing code to ensure security issues are eliminated before release, to implementing fixes within hours of a vulnerability becoming known. You benefit from their experience and abilities

Hardware failover cluster support

 

The hardware failover cluster functionality eliminates single points of failure and service downtime.

When Internet connectivity is business critical, the customer can utilise dual, redundant WANBOX network appliances. By configuring the devices in a high availability cluster, the backup hardware takes over in case the primary equipment fails. The redundant hardware can also be configured in a passive failover scenario, requiring the user to manually switch the appliances. The latter method is preferred for deployments in extreme conditions for an extended duration of the hardware’s life cycle.

Centralized Service Management and Monitoring

 

The WANBOX multi-WAN services can be managed remotely via the centralized management platform.

The centralized management platform allows our NOC and our service partners to monitor WANBOX services and remotely manage the available CPEs through a simple-to-use interface. The centralized management platform offers the following functionality:

  1. Service Monitoring (Reporting and alerting of WANBOX multi-WAN services deployment metrics)
  2. Remote CPE configuration management