artofrf.com

Ali's Technology Blog

Menu
  • Home
  • Important Links
  • About Me
  • Tools and Scripts
Menu

NFD32 – Nile Promises true NaaS

Posted on August 2, 2023December 6, 2024 by mali

“AaS”, and “As a Service” is the common buzzword these days and we are all familiar with them. Lots of companies and vendors are offering some form of their product, tech “As a Service”. So when I say “Wireless as a Service” or “Network as a Service”, we aren’t new to these terms.

When I started to see Nile showing up in my LinkedIn feed, I was very curious about their offering. When I saw that they were one of the presenters at the NFD32 event, I was looking forward to seeing their presentation and asking questions.

Before I jump into what Nile presented I want to share an On-Premise IT Podcast from Gestalt IT, Network-as-a-Service is the End of Network Engineering Roles. There have been conversations around AI, Automation, and “aaS” models killing engineering roles, during this On-Premise IT Podcast led by Tom Hollingsworth, Pat Allen, Drew Conry-Murray and myself share some of our thoughts.

Nile was founded in 2018 by industry veterans Pankaj Patel, Suresh Katukam, John Chambers, and Sri Hosakote; the late company was launched in 2022.

Suresh Katukam kicked started the Nile presentation and touched on some points on past, present, and ongoing Enterprise Network operations and functions.

NFD32 – Nile – Enterprise Networks

Nile’s Vision:

Unlike many other vendors, to execute Nile’s vision, the company decided to also build hardware from scratch instead of merging or acquiring. In the technology industry, everyone talks about taking a proactive approach to resolving issues, Nile’s vision is to focus on eliminating issues from the beginning that may contribute to the issues later on, things as configuration errors, human errors, change management related errors, errors related to bad design, errors related to physical and logical connectivity, etc.
Nile opted to use an OpEx pricing model based on per user/SQ’ and consumption. Think of utilities like electricity, gas, water, etc.

NFD32 – Nile Secure

How Nile Does it:

While many companies offer some form of NaaS, Nile offers a paradigm shift in how NaaS gets done; Nile offers a guarantee with financially backed SLAs for the following three key elements..

  • Availability
  • Coverage
  • Capacity

Not only simply offering an RMA of hardware in case of a failure but overseeing the whole process from Define, Design, Implement, Validate, Operate, Monitor and lastly Refresh.

NFD32 – Nile Features

Nile uses a concept of “Nile Service Block (NSB)” which comprises of the following hardware.

  • Wireless Access Points
  • Wireless Physical and Virtual Sensors
    • Each access point has an additional radio that also acts like a sensor
  • Access Layer switches
  • Distribution Layer switches

All hardware is meant to be resilient, with no single point of failure. Switch failure in the Core, Distribution, and access layers will not bring down a huge section of the network. If an access point fails, per design there should be adequate secondary coverage for the clients. This does not stop here, continuous monitoring of SLAs, environment, and network using physical and virtual sensors, synthetic testing and other data available from the devices and clients ensures that the network is meeting all the agreed-upon SLAs.

NFD32 – Nile Service Block (NSB)
NFD32 – Nile Enterprise Gear

But what happens if there are physical changes in my environment which start to impact the WLAN user experience?

The answer to this question was interesting, and I feel like it is worth sharing; Suresh used an example of physical and user changes. As depicted in the pictures below. If most of the users end up converging in the middle of the area, based on the SLA and requirements, Nile may install an access point or two and/or relocate APs to update the design.

It is imperative to mention here that certain pieces of the overall network/infrastructure design are the responsibility of the Customer and Partner. RADIUS, DHCP, Internet, etc are some of the things that either a customer will need to configure or a partner will need to take responsibility for configuring those things.

NFD32 – Nile – Shared Responsiblity

Day 0 and 1:

Austin Hawthorne discussed day 0 and 1 operations, what stood out for me here was their Work Flow for getting a site up and running. There is a Work Order section that focuses on three different tasks associated with provisioning a site. Nile collaborates with their partners to provide these services and Installers get rated based on their performance.

  • Site Survey
  • Cabling
  • Installation
NFD32 – Nile Work Order

Guest WLAN:

Guest Wi-Fi access is a key component of networks these days, it can open up your network to security risks if not done properly. Generally Guest WLAN either will get routed directly through a separate firewall interface, or some kind of central forwarding device in the DMZ and then the firewall. Nile is making the process simple handling all the security, configuration, and policies to keep the Guest WLAN traffic separate from the rest of the network.

I want to discuss the Liability section that mentions “DMCA“. Nile takes over the legal liability when it comes to DMCA by sending the Guest traffic through their POP and using their IP addresses instead of customer Internet IP addresses.

NFD32 – Nile Guest WLAN

Guest connectivity – iPhone XR. Third image on the right shows the IP addressing scheme Nile was assigning to the Guest devices.

Suresh digs into Guest architecture in the following video starting at 24:40

Troubleshooting:

Suresh and Austin discussed some troubleshooting steps within the Nile Dashboard and how data can be used to figure out the root cause of the issue. Going to my.nilesecure.com and looking at my connection metrics was impressive. I can see this as an excellent Level 1 troubleshooting tool or even an end-user tool to determine the quality of their connectivity.

There is also an option to report an incident from the my.nilesecure.com user interface. It also allows you to grab a screenshot, attach it to the incident and send it to the help desk.

NOTE: I did not get to see which button or area on the screen brought up this incident reporting screen. I also need to understand the back-end process, for example, once you hit submit where does it go? Does it only integrate with ServiceNow or can it simply send an email to the help desk if there is one specified in there?

NFD32 – Nile Report Incident
NFD32 – Nile Troubleshooting user experience

Identity Based Access with Nile:

You can’t talk network, or wireless, and not discuss security. Nile decided to take a Zero Trust approach to security which means every single device that connects needs to be authenticated via Single Sign On or they will not gain access to the network. What happens to IoT/headless devices?

These devices will get quarantined and sit in the dashboard for Admin Approval. Nile can also support customer’s NAC/RADIUS if they prefer to use that instead of the built in portal authentication.

NFD32 – Nile Identity Based Access

Nile Service Block supports MACSec (Automatically negotiates) from the access point to the switches, all traffic is always hardware encrypted, which adds a layer of security. NOTE: Not only the access points but the switches also support MACSec, all links and traffic is encrypted.

Todd Ellison (Principal Solution Architect) further explained additional security features

  • Use of TPM Chipset in every hardware.
  • Secure Boot – Ensures that the software is signed by Nile and there is no tampering
  • Physical Security – No management or console port
  • Each device validates other device
  • Device and cloud authenticate each other
NFD32 – Nile Secure Infrastructure

One important thing worth mentioning here is that the device and cloud validation do lock the device to the location it is supposed to be installed. If you take a Switch or an AP from Site X and try to install it at Site Y, it will not work. Should you need to move a switch from Site X to Site Y, Nile support will need to engage and move that switch.

Understanding how Nile Service Block routes traffic and secures it is worth discussing here; by default, each device is isolated, and there is no east-west traffic. There are two ways Nile is handling this traffic:

  • All traffic gets routed to the firewall (Northbound) – This is the default and original method
  • Nile added a new option and ability to leverage built in micro-segmentation.

I see being able to do micro-segmentation without complex NAC policies as a pretty good feature and would love to see it in action.

NFD32 – Nile traffic security

Simple Things Matter:

At times simple things make a huge difference and make us happy, I know they do make me happy. Because at times a solution to a bigger or a complicated problem is a simple one. I have been involved in many network migrations, installs, and refreshes. Trying to do this remotely means you have to create tedious documentation, graphics, etc for the installers which they either lose, never use, never take out of the box or their dog ends up eating it. Regardless of what happens, I liked the very simple approach that Nile took on their switches.

Each switch comes with graphics on the top and this can be extremely helpful for the installers and remote engineers when they are trying to install, provision, or simply troubleshoot.

NFD32 – Nile top view of the switch

Wi-Fi 6E:

Yes that AP on the right is a Wi-Fi 6E access point (NOTE: AP on the left is an outdoor AP)

  • 2.4 GHz, 5 GHz, 6 GHz
  • 4×4:4 in all three bands
  • 1 Triband radio for WIPS/WIDS, virtual sensor
  • 5 Gbps Uplink
NFD32 – Nile Outdoor Wi-Fi 6 AP and indoor Wi-Fi 6E AP

My Final Thoughts and Wish List:

In my opinion, Nile offers a fresh and different take on NaaS and provides wired and wireless services. As I mentioned in the video above, I can see this as a good fit in multiple industries depending on a few factors:

  • Do they prefer a CapEx or OpEx model?
  •  Do they have enough resources and skills in their IT Department to handle the needs of the users and a growing network?
  •  Do they have a budget to hire experienced Network and Wireless engineers, especially if most of their enterprise devices rely on WLAN for their connectivity?
  •  Think refresh cycles, for an IT Director and/or a CIO this may take away the burden of refreshing hardware every 3, 5, or 10 years.
  • IT teams will also need to discuss internally and figure out how and where the solution fits.
    •  Depending on the business and technical requirements Nile can either be a full solution or focus on resolving specific needs, for example; An Enterprise may want their engineers to focus on core and above and use Nile for the distribution and/or access layer.
    •  An Organization may have certain locations that they acquired or are remote branches and do not have the time and resources to upgrade and integrate that network.
    •  At times an organization may not have the internal skills or time to handle WLAN design, deployment, and configuration, monitoring, troubleshooting. I can see an organization letting Nile handle all aspects of WLAN.
    •  Full or Hybrid approaches are a possibility.

Unfortunately, we ran out of time and were not able to look at the live demo that was also planned for the event. There is a big WLAN piece that also needs to be presented in some detail and discussed. Would love to see Nile present at one of the Mobility Field Day with a focus on Wi-Fi. Some of my wish list items:

  • Work Orders – Would love to see a work order flow for each Project/Task where users can add notes, pictures, timelines, and toll booths so customers can see in real-time the progress.
  • WPA3 support for MPSK.
    •  Nile SD-WAN/Firewall. Ideally, I’d love this SD-WAN/Firewall solution to be able to not just integrate with Nile hardware but also with other vendor hardware also.
    •  Possibly an integrated wireless AP option for smaller branch locations.
    •  LTE capabilities on the WAN side.
  •  Integration with Hamina.
    • To clarify, Nile APs are already available in Hamina for a predictive RF modeling.
    • Import/Export of a project is currently not available.
  •  Would like to better understand how the guest traffic is getting segmented from the rest of the network.
  •  NAC, NAC, NAC, would love to see a Nile NAC.
  •  Hospitality access point perhaps.
  •  Currently, Nile is using the OpEx model with per user/sq’ pricing model. I’d love to see a per-device model also.

Thank you for reading, if you have watched the Nile NFD32 presentation and/or have deployed the Nile solution. Would love to hear your thoughts and what would you like to see.

Category: Conferences and Meetings, Nile Secure, Nile Wi-Fi

11 thoughts on “NFD32 – Nile Promises true NaaS”

  1. Tom Flaherty says:
    August 2, 2023 at 9:27 pm

    Great read Ali!

    Reply
    1. mali says:
      August 3, 2023 at 2:58 pm

      Tom, thank you for reading and feedback.

      Reply
  2. Ozer Dondurmacioglu says:
    August 3, 2023 at 1:36 pm

    Ali, thanks for letting us share why/how/what we do and for the detailed analysis! So much to learn from your notes here. Looking forward to staying in touch and comparing notes.

    Reply
    1. mali says:
      August 3, 2023 at 2:58 pm

      Ozer, welcome to Nile. Missed you in California and yes absolutely.

      Reply
  3. Shaman Anderson says:
    August 3, 2023 at 2:43 pm

    Fantastic overview, Ali!!!

    Reply
    1. mali says:
      August 3, 2023 at 2:59 pm

      Shaman, thank you for reading.

      Reply
    2. AJ says:
      November 1, 2023 at 3:42 am

      Hey did you get a chance to understand how really the NSB blocks works within and what uniqueness Nile offers to other OEMs ?

      Reply
  4. Suresh Katukam says:
    August 8, 2023 at 11:04 am

    Ali, very well done!! Thank you for articulating our story and our solution.

    Reply
    1. mali says:
      August 8, 2023 at 2:05 pm

      Thank you for reading, it was a pleasure meeting you and looking forward to seeing Nile present at one of the MFDs.

      Reply
  5. Henry Chou says:
    August 9, 2023 at 3:38 am

    Nile has already been integrated with Hamina. You may create predictive models in Hamina using Nile AP.

    Reply
    1. mali says:
      August 9, 2023 at 12:42 pm

      Thanks, Henry. I should have elaborated a bit more. When I say integration I was more interested in seeing ability to import and export projects. That option is not available yet and as far as I know, it is in progress.

      Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Recent Posts

  • CLI to UI – Nile Guest APIs
  • Nile Secure Guest – Configuration and Use Case
  • WLAN Pros Toolbox
  • Nile does NAC – Configuring Trust Engine
  • WLAN Validator

Tags

#MFD9 - Juniper Presents AP W318 arista Arista AGNI Arista CV-CUE Arista Hospitality AP Arista NAC Arista presents at MFD9 Arista wall plate AP Arista WIPS Arista WPA3 UPSK Aruba Central Automation CWAP 403 EAP Format MAC Addresses Hamina Network Planner Juniper Mist show cloud-native NAC Juniper SRX300 Marvis MFD8 MFD9 MistAI Mist MPSK Mist Premium Analytics Mist Wireless NaaS Networking Field Day NFD32 Nile APIs NileNav Nile Secure Nile Wi-Fi Tech Field Day Troubleshooting with Marvis Troubleshooting with Mist Troubleshooting with Mist AI Troubleshooting with Wireshark True NaaS Wireless Adjuster Wireless Adjuster Level II Wireless troubleshooting WLPC wlpc2023 Wyebot

Tech Blogs

  • CCNA Wireless
  • Cisco Full Bars
  • Packet Life
  • The ASCII Construct
  • Juniper Port Checker
  • Bad-Fi
  • Gjermund Raaen
  • Havilandweb
  • WiFiTodd
  • BadgerWiFi
  • WiFrizzy
  • Spectrum Chart

Recent Comments

  • Hiten Thakkar on PCAP I/O Graph Analyzer
  • mali on Deploying Nile Secure – My First NSB
  • Larry Farrish on Deploying Nile Secure – My First NSB
  • Courtney on Mist Access Point – CSV
  • ayoub chabrouk on Ubiquiti stealing the show at MFD11

Archives

  • August 2026
  • July 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • October 2025
  • August 2025
  • May 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • September 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • May 2021
  • April 2021
  • March 2021
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • April 2019
  • March 2019
  • November 2018
  • October 2018
  • September 2018
  • May 2018
  • January 2018
  • December 2017
  • August 2017
  • January 2017
  • September 2014
  • December 2013
  • October 2013
  • May 2013
  • August 2012
  • July 2012

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Categories

  • AeroHive
  • Arista
  • Arista
  • Aruba
  • Aruba
  • Aruba Central
  • BYoD
  • Certifications
  • Cisco
  • Cisco
  • Cisco EEM Scripting
  • Cisco Routing
  • Cisco Security
  • Cisco VoIP
  • Cisco VPN
  • Cisco Wireless
  • Conferences and Meetings
  • Design
  • Ekahau
  • General
  • Hamina
  • IoT, IIoT, OT
  • Juniper Security
  • Juniper Switching
  • Juniper/Mist
  • Linux
  • Microsoft
  • Mist
  • Mist Wireless
  • Nile
  • Nile Secure
  • Nile Wi-Fi
  • Programming/Automation
  • Python
  • Ruckus
  • Ruckus Wireless
  • Ruckus/Brocade
  • Ruckus/Brocade Scripting
  • Ruckus/Brocade Switching
  • Secure Guest Service
  • Security
  • Switching
  • Tools
  • Troubleshooting
  • Trust Engine
  • Uncategorized
  • Windows
  • Wireless
  • Wireless
  • WLAN Tools
© 2026 artofrf.com | Powered by Minimalist Blog WordPress Theme