Tolly Report Archive: 50 Most Recent Reports

Click on report title to go to the report abstract page. Report download requires registration and/or purchase.





Broadcom Inc. Document number: 222122
Symantec Secure Access Service Edge (SASE) Portfolio Comparison to Gartner SASE Framework
Release date: 01 August 2022

The growing reliance of businesses large and small on cloud infrastructure has, naturally, focused attention on the security of that infrastructure. To reflect this new focus, industry analysts at Gartner coined the term SASE, Secure Access Service Edge, and defined the key elements covered by the Gartner SASE framework which is broken down into two areas: WAN edge services and cloud-hosted security services which Gartner calls the Security Services Edge (SSE).

Broadcom commissioned Tolly to examine its portfolio of Symantec web security solutions and document how they encompass the SASE elements as defined by Gartner.* Broadcom’s security components can work with any SD-WAN solution.

The Tolly analysis shows that the Symantec web security portfolio provides solutions within each of Gartner’s SASE categories and provides services beyond the Gartner main components.




Auvik Networks Inc. Document number: 222131
Auvik Network Monitoring & Management
Release date: 26 July 2022

Solving user connectivity problems requires visibility into those problems. It is essential that all locations, networks and devices be quickly visible and easily navigated to expedite the problem resolution process. Auvik has designed its cloud-based network monitoring and management solution to allow friction-free, rapid access to all network devices.

Auvik commissioned Tolly to evaluate its network visibility system versus the network visibility capabilities of three other prominent solutions. These solutions represented both commercial options licensed by node and by sensor and open source options. These will be referenced generically. Tolly evaluated installation and functional capabilities such as dynamically generating topology maps, providing network visibility by IP subnetwork and VLAN, and providing detailed information about network infrastructure devices and access to those devices.

Auvik was very easy to install and configure for discovery. Auvik generated a topology map dynamically, provided network inventory by subnet and details on network infrastructure. Auvik’s capabilities exceeded those of the other solutions.




Huawei Technologies, Co.Ltd Document number: 222136
Huawei CloudEngine S5731-L Series Remote Unit Switches Performance Evaluation and Feature Validation
Release date: 25 July 2022

Huawei CloudEngine S5731-L series remote unit switches (hereinafter referred to as CloudEngine S5731-L RUs) support an innovative simplified architecture and can be used as the extended ports of other CloudEngine S-series switches, extending the reach of switch ports, saving cabling costs, and reducing workload. Plus, CloudEngine S5731-L RUs are management-free, greatly simplifying the routine management on campus networks.

CloudEngine S5731-L RUs provide all-gigabit data access and support the innovative optical-electrical Power over Ethernet (PoE) technology. They can draw 300m PoE++ or 1.2km PoE from the central switch. With these characteristics, CloudEngine S5731-L RUs can be used in a wide range of scenarios, including offices, education institutions, hotels, and healthcare facilities, helping enterprises construct green and low-carbon buildings.

Huawei commissioned Tolly engineers to test CloudEngine S5731-L RUs. The test results show that they stand out in management, deployment, energy efficiency, and power supply.




Huawei Technologies, Co.Ltd Document number: 222135
Huawei CloudEngine S5731-H Series Switches Performance Evaluation and Feature Validation
Release date: 25 July 2022

Huawei CloudEngine S5731-H series hybrid optical-electrical switches (hereinafter referred to as CloudEngine S5731-H) are new additions to Huawei's CloudEngine S5731-H switch portfolio. These new switches come with high-performance programmable chips, and provide GE/10GE downlink ports, 10GE uplink ports, and one extended slot. They can be deployed at the aggregation or access layer in large or midsize campuses, at the core layer in branches and small campuses, and at the access layer in data centers.

Tolly engineers tested the performance and functions of CloudEngine S5731-H. CloudEngine S5731-H builds on Huawei's high-performance Versatile Routing Platform (VRP) and boasts various agile features. For example, integrated WLAN Access Controller (WAC) capabilities achieve wired and wireless convergence, while the free mobility feature ensures network-wide consistent policies and user experience. The series also supports Virtual Extensible LAN (VXLAN), achieving one network for multiple purposes to support multiple services. Plus, CloudEngine S5731-H can be used together with Huawei HiSec Insight for Encrypted Communication Analytics (ECA) and threat deception, achieving network- wide collaborative security protection.




Huawei Technologies, Co.Ltd Document number: 222136ZH
华为 CloudEngine S5731-L 系列交换机远端模块 性能测试和功能验证
Release date: 07 July 2022

华为 CloudEngine S5731-L 系列交换机远端模块支持创新的极简架构,可作为华为 CloudEngine S 系列交换机端口扩展模块,实现交换机端口的拉远,节省布线成本及工作量;远端模块无需管理,这可极大简化园区网络的日常管理。

CloudEngine S5731-L 系列远端模块可提供全千兆的数据接入能力,可选支持创新光电 PoE,由中⼼交换机为远端模块提供 300 米远距 PoE++ 供电,PoE 供电距离最⼤ 1200 ⽶,可广泛用于企业办公、教育、酒店、医疗等行业场景,助力企业打造绿色低碳楼宇。

华为委托 Tolly 对 CloudEngine S5731-L 系列交换机远端模块进行了测试,结果表明该系列远端模块在管理、部署、绿色、取电方面拥有突出优点。




Huawei Technologies, Co.Ltd Document number: 222135ZH
华为 CloudEngine S5731-H 系列交换机 性能测试和功能验证
Release date: 07 July 2022

华为 CloudEngine S5731-H 光电混合交换机是华为 CloudEngine S5731-H 家族新增发布的全新产品款型,采⽤华为⾃研 ARM 架构 CPU 和 Solar 交换芯⽚,具有 GE 及 10GE 接⼊端⼝及 10GE 上⾏端⼝,同时⽀持⼀个子卡扩展槽。它们适合部署在⼤型和中型园区的聚合或接⼊层、分⽀ 机构和⼩型园区的核⼼层、以及数据中⼼的接⼊层。

Tolly ⼯程师测试了华为 CloudEngine S5731-H 光电混合交换机的性能及功能。该交换机搭载华为⾼性能 VRP 软件平台,⽀持 WLAN ⽆线控制器功能(随板 AC),实现有线⽆线及网络深度融合;支持业务随行特性,可实现用户在全网范围内的一致策略和体验;支持 VXLAN 特性,可实现多业务的融合承载实现“一网多用”。CloudEngine S5731-H 系列交换机可配套和华为 HiSec Insight 联动实现全⽹安全协防,进⾏加密通信分析(ECA)和安全诱捕。




Huawei Technologies, Co.Ltd Document number: 222125
Huawei CloudEngine S8700 Series Switches Performance Evaluation and Feature Validation
Release date: 27 June 2022

Huawei CloudEngine S8700 series switches ("CloudEngine S8700") are next-generation modular aggregation/access switches ideal for future- proof cloud campus networks. They are available in two models — CloudEngine S8700-6 with 6 slots and CloudEngine S8700-10 with 10 slots — and come with ultra-high densities of GE, 10GE, 25GE, 40GE, and 100GE ports, helping build a future-proof campus network quickly with a simplified architecture.

Built on Huawei's proprietary software platform, CloudEngine S8700 offers customers a trusted system and secure data access. All key components of CloudEngine S8700, including the main control boards, power modules, and fan modules, implement a redundancy design for carrier-grade reliability.

With all these characteristics, CloudEngine S8700 is an ideal choice of aggregation/access nodes needed to build future-proof cloud campus networks, helping customers achieve their digital transformation goals.

Tolly engineers verified performance, specifications, and functions of CloudEngine S8700.




Huawei Technologies, Co.Ltd Document number: 222117
Network Access Control Interoperability Test of Huawei CloudCampus Solution with Forescout
Release date: 22 June 2022

iMaster NCE-Campus is Huawei’s next-generation autonomous driving network management and control system for campus networks. Legacy networks may already have a Network Access Control (NAC) system implemented and, thus, it is important to demonstrate interoperability with such existing systems.

Tolly engineers verified the interoperability of the Huawei CloudCampus solution with Forescout Platform 8.3 across a wide range of function types and interconnection methods with Huawei networking interconnections. Independent interconnections were tested via Huawei switches and standalone wireless access controller (WAC). Interconnection via iMaster NCE-Campus was tested for VXLAN, Cloud Access Point (AP) and Native Access Controller (AC) scenarios.

The test suite covered the following areas: endpoint discovery, endpoint identification, access authentication, endpoint security check, and control & authorization. All tests included both wired and wireless clients.




Huawei Technologies, Co.Ltd Document number: 222101
Network Access Control Interoperability Test of Huawei CloudCampus Solution with Aruba ClearPass
Release date: 22 June 2022

iMaster NCE-Campus is Huawei’s next-generation autonomous driving network management and control system for campus networks. Legacy networks may already have a Network Access Control (NAC) system implemented and, thus, it is important to demonstrate interoperability with such existing systems.

Tolly engineers verified the interoperability of the Huawei Cloud Campus solution with Aruba ClearPass 6.7 across a wide range of function types and interoperability methods with Huawei networking interconnections. Independent interoperability was tested via Huawei switches and standalone wireless access controller (WAC). Interoperability via Huawei iMaster NCE-Campus was tested for VXLAN, Cloud Access Point (AP) and Native Wireless Access Controller (Native AC) scenarios.

The test suite covered the following areas: access authentication, device management and access control, Extensible Authentication Protocol (EAP) authentication, authorization, Change of Authorization (CoA), profiling, Free Mobility, and endpoint security. All tests included both wired and wireless clients.




Huawei Technologies, Co.Ltd Document number: 222115
Network Access Control Interoperability Test of Huawei CloudCampus Solution with Cisco Identity Services Engine (ISE)
Release date: 22 June 2022

iMaster NCE-Campus is Huawei’s next-generation autonomous driving network management and control system for campus networks. Legacy networks may already have a network access control system implemented and, thus, it is important to demonstrate interoperability with such existing systems.

Tolly engineers verified the interoperability of the Huawei CloudCampus solution with Cisco Identity Services Engine (ISE) v3.0 network access control (NAC) solution across a wide range of function types and interoperability methods with Huawei networking interconnections. Independent interoperability was tested via Huawei switches and standalone wireless access controller (WAC). Interoperability via Huawei iMaster NCE- Campus was tested for VXLAN, Cloud Access Point (AP) and Native Wireless Access Controller (Native AC). Scenarios

The test suite covered the following areas: access authentication, device management and access control, Extensible Authentication Protocol (EAP) authentication, authorization, Change of Authorization (CoA), profiling, Free Mobility, and Endpoint security. All tests included both wired and wireless clients.




New H3C Technologies Co., Ltd Document number: 222130
H3C CR16000-F Series Router Performance Evaluation and Feature Validation
Release date: 22 June 2022

CR16000-F is an H3C proprietary high-end router. Running on Network Processor (NP) chips, it provides rich features and delivers powerful forwarding capabilities. With an advanced orthogonal Clos architecture and independent fabric modules, the router offers high reliability and scalability. It runs the cutting-edge Comware network operating system, uses multi-core CPU and modular design, and supports distributed computing, high availability architecture, and varieties of services. It provides open, standard programming Python and Tcl APIs to meet the customization needs of customers. It supports advanced technologies such as SR/SRv6, FlexE, Flex-Algo, interface slicing, iFIT, and NETCONF, and is suitable for multi-service scenarios such as Metro, BRAS, IPRAN, and enterprise gateway. In addition, it provides complete SDN capabilities. Working in collaboration with an SD-WAN (H3C AD-WAN) controller, it enables automated service deployment, flexible network scheduling, multi-dimensional service assurance, and intelligent network operation and maintenance.

H3C commissioned Tolly to evaluate CR16000-F router’s performance, capacity, and features.




Cambium Networks, Ltd. Document number: 222134
Tolly on Technology - Wi-Fi 6E Arriving Faster Than You Think: Conversation with Cambium Networks
Release date: 21 June 2022

Tolly Group Founder, Kevin Tolly hosts a Video Podcast discussing Wi-Fi 6E with Cambium Networks.

The Tolly on Technology Video Podcast series is a thought leadership podcast that interview experts on trends and best practices for IT leaders.

Kevin Tolly is joined by Cambium Networks' VP Bruce Miller to discuss the benefits of Wi-Fi 6E.

Tolly on Technology Landing Page.
(Note: There is no download for this Video Podcast item.)




Ruijie Networks Co., Ltd. Document number: 222133zh
锐捷 WLAN 产品 
多场景漫游性能评估
Release date: 21 June 2022

随着移动终端和数字化在各行各业的蓬勃发展,构建稳定、高性能、高可用性的无线网络至关重要。锐捷网络基于 15 年以上的企业级无线市场经验,开发了一系列 Wi-Fi 无线接入点,以及多套解决方案,以覆盖不同的应用场景。

由于 Wi-Fi 无线网络基于多台无线接入点(AP)的信号进行覆盖,终端移动过程中的漫游性能一直是用户最关注的性能指标之一。锐捷委托 Tolly 评估其多套解决方案的漫游性能,包括医疗无线零漫游方案、工业无线零漫游方案、双射频链路聚合方案、AR 无线零漫游方案、以及车地无线零漫游方案。




Infoblox, Inc Document number: 222110
Infoblox Authoritative IPAM for DNS and DHCP Automated Cloud and On-Premises Network Discovery with 3-Year TCO Evaluation
Release date: 17 June 2022

In recent years, the growth in both cloud and decentralized computing has translated to enormous flexibility for companies large and small. With that flexibility, however, has come a dramatic increase in complexity with respect to IP address management. Not only do traditional IPAM challenges remain but gathering information from disparate locations - and especially cloud services - can involve extensive and ongoing manual labor.

Infoblox IPAM and DHCP solves the traditional challenges of manual Windows-based and other freeware IPAM. Importantly, the solution has been updated and extended to provide IP address discovery for cloud-services and for distributed on-premises (hereafter on-prem) network sites.

Infoblox commissioned Tolly to evaluate the benefits of its cloud-based, automated IP address discovery and its on-prem network discovery. Cloud services included Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). Additionally, Tolly revisited and reconfirmed the TCO benefits of Infoblox IPAM and DHCP automation compared to Microsoft’s manual network update processes.

The Infoblox solution demonstrated dramatic time and effort savings with respect to cloud-based IP address management, automated discovery of on-prem network devices and illustrated significant time and cost savings with respect to traditional, manual processes associated with Microsoft Windows Server 2019.




Infoblox, Inc Document number: 222110-1P
Infoblox Authoritative IPAM for DNS and DHCP - One-Pager
Release date: 17 June 2022

Infoblox IPAM and DHCP solves the traditional challenges of manual Windows-based and other freeware IPAM. Importantly, the solution has been updated and extended to provide IP address discovery for cloud-services and for distributed on-premises (hereafter on-prem) network sites.

View the One-Pager on the key takeaways from Infoblox's Authoritative IPAM for DNS and DHCP Automated Cloud and On-Premises Network Discovery with 3-Year TCO Evaluation.

The full Tolly report can be downloaded from here.




Huawei Technologies, Co.Ltd Document number: 222125ZH
华为 CloudEngine S8700 系列交换机 性能测试和功能验证
Release date: 13 June 2022

华为 CloudEngine S8700 系列交换机包括 CloudEngine S8700-6 交换机和 CloudEngine S8700-10交换机。

CloudEngine S8700 系列交换机(简称 S8700)是华为面向云园区网络推出的全新一代框式汇聚/接入交换机,采用华为自研 ARM 架构的 CPU 及 Solar 系列交换芯片,提供 6 槽位及 10 槽位两种产品形态,拥有超高密 GE/10GE/25GE/40GE/100GE 全速率接入端口,满足客户快速构建一张两层极简架构的中大型园区网络需求。该系列交换机搭载华为自研软件平台,为客户提供可信的平台系统及安全的数据接入;主控、电源、风扇等关键部件采用冗余设计,提供电信级可靠保障,是构建云园区网络汇聚/接入交换机的理想选择,助力全球客户数字化转型。

Tolly 工程师测试了华为 CloudEngine S8700 系列交换机的性能并验证了其功能。




Huawei Technologies, Co.Ltd Document number: 221127
Huawei WLAN Access Controllers Application Identification, Fast Roaming, and Easy Operation & Management
Release date: 27 May 2022

With the development of smart devices, more and more applications are running over the wireless network. To improve the security and network resource management, administrators require visible application traffic statistics and application-based control. Huawei WLAN Access Controllers (ACs) provide the Application Identification function to support visible management and control of Layer 4 to 7 network attributes.

In the multi-AP environment, some clients may remain associated to the initially-connected AP even after the clients have moved and the signal has dropped to a very low level. Huawei Access Controllers support the Smart Roaming function to help clients roam to the best available AP for better single-user and overall network performance.

Huawei WLAN Access Controllers provide a built-in Web network management interface to support service deployment, network status monitoring, and problem intelligent diagnosis.




Huawei Technologies, Co.Ltd Document number: 221127ZH
华为无线控制器 应用识别,快速漫游和便捷运维管理功能验证
Release date: 27 May 2022

随着智能终端的发展,越来越多的应用在无线网络中使用。为了增强无线网络的安全性和资源管理,管理员们需要可视化的应用统计及基于应用的管理。华为无线控制器内置应用识别功能,支持对 4-7 层应用进行可视化管理和控制。

在多 AP 的高密环境,部分终端在移动后,尽管关联的 AP 信号质量已经变差,依然不发生漫游。华为无线控制器支持智能漫游功能,协助终端接入信号质量最优的 AP,提升单用户体验提升整个无线网络的性能。

无线控制器内置 Web 网管界面,提供业务部署、网络状态监控以及智能诊断功能。




Xena Networks Document number: 222127
Valkyrie Automotive Ethernet Performance Testing of 100Mbps/1Gbps Automotive Ethernet Switches
Release date: 26 May 2022

Ethernet has become the de facto standard for in-vehicle communication, especially for Connected Autonomous Vehicles (CAVs) and Electric Vehicles (EVs). This is because the immense amount of data generated by sensors, cameras, radars, LIDAR and external data flows like V2x, telematics and infotainment simply cannot be transported via traditional automotive communication systems like CAN (1Mbit/s) to CanXL (10Mbit/s).

Given the long life span of vehicles, it is essential that Automotive Ethernet (AE) switches perform within specifications and the first step in the process is to establish baseline performance in ideal conditions.

Xena Networks commissioned Tolly evaluate the AE performance benchmarking capabilities of the Xena Valkyrie system in conjunction with the Odin hardware module specifically designed for AE switch connections. Testing was conducted on an industry leading AE switch vendor.

Tolly tests confirmed the quick and easy setup for Xena Valkyrie to validate AE switches using industry standard “RFC” benchmarking suites. Test results generated included throughput, latency, and jitter.




Archeo Futurus Document number: 221141
AF F1-eco Server FPGA Cloud Server Performance vs. Power Consumption
Release date: 16 May 2022

Field-programmable gate arrays (FPGAs) are integrated circuits designed to be configured (programmed) by a designer after manufacturing. FPGAs can provide high performance usually associated with ASICs but with unprecedented flexibility.

Kyudoka Capital Corporation is a financial technology infrastructure company leveraging AF F1-eco technology to provide next generation, ultra high- performance systems that search, analyze, sort, and predict.

Archeo Futurus & Kyudoka commissioned Tolly to benchmark the cloud services server performance and power consumption of its AF F1-eco solution. The testing focused on measuring “worst case” small packet performance for three key web protocols: HTTPS (encrypted web), HTTP (standard web), and DNS (URL name resolution).

AF F1-eco server was able to process over 100,000 HTTPS responses per Watt, nearly one million HTTP responses per Watt, and over 5.5 million DNS responses per Watt.




SonicWall Document number: 222126
Webinar: Elevating Your Firewall Protection to the Cloud
Release date: 12 May 2022

Tolly benchmarked the throughput and connection performance of SonicWall’s NSv 470 virtual firewall in AWS. Tolly engineers used Keysight’s CyPerf cloud-native testing solution to provide the test infrastructure for standardized, repeatable performance tests.

Join Tolly Group CEO Kevin Tolly; Keysight Technologies Senior Product Mgr. Amritam Putatunda; and SonicWall Dir. of Product Marketing Ajay Uggirala as they explore:

• Which firewall services can secure the public cloud

• The best way to deploy and test a firewall in a public cloud infrastructure

• What sort of performance you can expect from your SonicWall NGFW in AWS cloud, as validated by experts at Keysight and Tolly Group

SonicWall Webinar View On-demand Landing Page.

The Tolly report can be downloaded from here.




New H3C Technologies Co., Ltd Document number: 222103
H3C AD-Campus Solution (Application-Driven Campus Solution) Functionality Validation
Release date: 12 May 2022

The H3C Application-Driven Campus (AD-Campus) Solution is an innovative campus network solution which aims to achieve great integration and convergence to easily reflect intent to network operation. With full lifecycle management, open architecture and deep intelligence, AD-Campus is committed to solve existing challenges and assist customers to accelerate digital innovation and transformation.

AD-Campus combines VXLAN and the concept of Software-Defined Networking (SDN) to create a new-generation flexible network. It converts campus network from "user adapts to network" to "network adapts to users", enabling users and devices to roam around campus seamlessly, while remaining consistent user experience and simplified network operation. It reduces complexity of network deployment and maintenance and meets the increased requirements of mobility and massive endpoint access on campus network.




New H3C Technologies Co., Ltd Document number: 221154
H3C AD-DC Solution (Application Driven Data Center Solution) Functionality Validation
Release date: 11 May 2022

As organizations of all sizes across all industries, such as governments and enterprises, continue to advance digital transformation and improve the agility and flexibility of their IT systems, and in doing so, improve organizational efficiency and competitive advantage. Hybrid IT environments and multi-clouds are being used as indispensable tools for this purpose. Data center networks support multi-cloud environments with agility, elastic scalability, security and operational efficiency, and with a consistent network architecture that meets the needs of local cloud data centers and extends to public and edge cloud environments.

The Application Driven Data Center (AD-DC) solution is H3C’s new generation data center network solution, based on the cloud and intelligence native architecture, integrating management, control and intelligent analysis functions. H3C commissioned Tolly to evaluate the AD-DC solution, and the results show that the H3C AD-DC solution provides complete data center network lifecycle automation, intelligent operation and maintenance, comprehensive security protection, flexible networking architecture, and multi-level high availability. This open platform provides programmability, which can meet the network requirements of organization's hybrid IT and multi-cloud environment, ensures the agility and flexibility of organization's IT environment, and greatly improve the business efficiency of customers.




New H3C Technologies Co., Ltd Document number: 222105
H3C S10500X Series Next Generation Multiservice Core Switch Performance Evaluation and Feature Validation
Release date: 25 April 2022

With the development of cloud computing and campus networks, the gradually increasing scale accelerates requirements of high-performance and feature-rich switches. Core switches need to support comprehensive Ethernet protocols, high bandwidth, high availability features, SDN features, and provide easy-to-use O&M functions. The switches need to guarantee good network service and handle massive network traffic easily.

H3C S10500X series switch is designed for the core layer of data centers and next-generation campus networks. The advanced CLOS architecture delivers outstanding bandwidth scalability. S10500X supports comprehensive data center, network service and high availability features, including Multi-tenant Device Context (MDC), Fiber Channel over Ethernet (FCoE), Telemetry, microsegmentation, MPLS VPN, In-Service Software Upgrade (ISSU), Graceful Restart (GR), etc. It is suitable as primary choice to be the core layer switch in different industries.

H3C commissioned Tolly to evaluate S10500X core switch’s performance, capacity and features.




New H3C Technologies Co., Ltd Document number: 222106
H3C S12500G-AF Series Data Center Intelligent Core Switch Performance Evaluation and Feature Validation
Release date: 25 April 2022

With the rapid development of new-generation technologies such as 5G, cloud computing, and AI, the accelerated integration of information technology and traditional industries, data centers, as the physical carrier for the operation of information systems in various industries, have become indispensable for economic and social operations.

H3C S12500G-AF is H3C's new generation of AI intelligent switches for the core layer of data centers, provides ultra-high switching performance and rich network features. H3C S12500G-AF uses CLOS+ architecture, which greatly improves the system bandwidth, and the switching capacity can be smoothly expanded. At the same time, S12500G-AF supports virtualization technology, visualization technology, RoCE, FCoE and other software features to create a green, smart, safe, efficient, and flexible data center.




SonicWall Document number: 222113
SonicWall NSv 470 Virtual Firewall Performance on Amazon Web Service Public Cloud Leveraging Keysight CyPerf Test Tool
Release date: 20 April 2022

The massive migration to cloud-based computing has raised the profile of cloud-based network infrastructure. Security is essential to cloud computing, and virtual next-generation firewalls (NGFW) are responsible for providing that security. Firewalls directly impact application performance -- and a firewall's performance, in turn, depends on the resource characteristics of the cloud instance where it runs. Thus, it is essential to establish key performance indicators (KPIs) for firewalls.

Tolly benchmarked the throughput and connection performance of SonicWall’s NSv 470 virtual firewall in AWS. Tolly engineers used Keysight’s CyPerf cloud-native testing solution to provide the test infrastructure for standardized, repeatable performance tests.

Tests were run with both encrypted and unencrypted traffic, as NGFWs provide multiple layers of traffic screening that are selectable by the network security team. These tests were run with different NGFW security profiles: basic firewall, intrusion prevention service (IPS), and threat prevention services. Threat prevention services consisted of IPS, anti-virus, anti-spyware, and application control features all enabled. Firewall throughput depends on traffic profile, encryption settings and security services that are enabled.




VMware, Inc. Document number: 221128IG
Infographic: User Experience with VMware SD-WAN Work-from-Anywhere with Dual WAN Links
Release date: 14 April 2022

VMware and Intel commissioned Tolly to benchmark the quality-of-service and remediation capabilities of VMware SD-WAN to improve the end-user experience for voice-over-IP (VoIP) and work-from-anywhere (WFA) applications using a dual WAN link deployment. Additionally, Tolly benchmarked the packet throughput of VMware SD-WAN.

View the Infographic on the key takeaways from the VMware SD-WAN Work-from-Anywhere with Dual WAN Links

The full Tolly report can be downloaded from here.




Cubro Document number: 222116
Cubro Custos Network Monitoring Functionality & Efficiency
Release date: 04 April 2022

When it comes to network monitoring, network size doesn’t matter. Local or global, small or large, it is essential for every company to have insights into network activity. Effective monitoring can provide critical insights into application usage, identify bottlenecks, and help reveal possible security threats. Cubro Custos is designed to be an intuitive and small-footprint network monitoring solution that provides critical insights into user and application activity.

Cubro Network Visibility commissioned Tolly to evaluate the usability, storage efficiency and approach to data structure used in Custos. Tests were run by evaluating a live network simultaneously using Cubro Custos and legacy NetFlow/ IP Flow Information Export (IPFIX) files.

Tests showed that the Custos 3D-style user interface provided insightful, immediately actionable network information, stored network data dramatically more efficiently than NetFlow/IPFIX, and implemented a human-oriented data structure that could be easily integrated into 3rd-party systems.




Xena Networks Document number: 222119
Tolly on Technology - Automotive Ethernet: The "Whys" & "Hows" of Testing - Conversation with Xena Networks
Release date: 11 March 2022

Tolly Group Founder, Kevin Tolly hosts a Video Podcast discussing Automotive Ethernet with Xena Networks.

The Tolly on Technology Video Podcast series is a thought leadership podcast that interview experts on trends and best practices for IT leaders.

Kevin is joined by Xena Networks' Thomas Schulze to discuss the "Whys" and "Hows" of testing Automotive Ethernet.

Tolly on Technology Landing Page.
(Note: There is no download for this Video Podcast item.)




VMware, Inc. Document number: 222118
Webinar: User Experience with VMware SD-WAN Work-from-Anywhere with Dual WAN Links
Release date: 11 March 2022

VMware and Intel commissioned the Tolly Group to benchmark quality of service and remediation capabilities of VMware SD-WAN™ to improve end user experience for VoIP and work-from-anywhere applications using a dual WAN link deployment.

Join Kevin Tolly, Founder at Tolly Group, Jen Horvath, Global Market Development at Intel, Swapnil Hendre, IT at VMware, for a webinar covering the quality-of-service and remediation capabilities of VMware SD-WAN to improve the end-user experience for voice-over-IP (VoIP) and work-from-anywhere (WFA) applications using a dual WAN link deployment. Additionally, Tolly benchmarked the packet throughput of VMware SD-WAN.

VMware Webinar View On-demand Landing Page.

The Tolly report can be downloaded from here.




Huawei Technologies, Co.Ltd Document number: 222111zh
华为 AirEngine 系列 Wi-Fi 6 无线接入点性能评估和功能验证
Release date: 10 March 2022

Wi-Fi 6 是最新商用化的 Wi-Fi 标准,被目前新发布的各类无线终端广泛采用。相较之前的标准,Wi-Fi 6 无线接入点(AP)能提供更大的带宽、更高的并发用户数、以及更低的时延。

Tolly 从市场上选取了几款华为最新 Wi-Fi 6 无线接入点 AirEngine 6761-21、AirEngine 5761R-11、AIrEngine 5761R-11E、AirEngine 5762-12、AirEngine 5762-12SW 以及 AirEngine 5762-15HW,验证了其部分最新功能。同时,Tolly 工程师测试了上述华为 Wi-Fi 6 AP 的单用户性能以及 AirEngine 6761-21T AP 的整机多用户性能。




Huawei Technologies, Co.Ltd Document number: 222111
Huawei AirEngine Series Wi-Fi 6 Access Points Performance Evaluation and Feature Validation
Release date: 10 March 2022

Wi-Fi 6 is the latest commercial Wi-Fi standard and is widely used by newly released wireless endpoints. Compared with earlier standards, Wi-Fi 6 access points (APs) provide higher bandwidth, a larger number of concurrent users, and lower latency.

Tolly tested some of the latest features of Huawei's latest Wi-Fi 6 APs: AirEngine 6761-21, AirEngine 5761R-11, AirEngine 5761R-11E, AirEngine 5762-12, AirEngine 5762-12SW, and AirEngine 5762-15HW. Tolly engineers also tested the single-user performance of Huawei Wi-Fi 6 APs and the multi-user performance of AirEngine 6761-21T.




Huawei Technologies, Co.Ltd Document number: 222112ZH
数据中心自动驾驶网络 华为 CloudFabric 与 Cisco IBN (Data Center) 对比测试报告
Release date: 04 March 2022

Tolly 本次就数据中心自动驾驶网络华为 CloudFabric 与 Cisco IBN for Data Center 在四个维度进行了评估(思科方案采用 Cisco ACI 架构): Day0 规划建设:规划建设环节,包括基于业务意图系统⾃动理解,并转化为⽹络需求,⽣成⽅案,同时完成部署验证等物理⽹络就绪的能⼒。 Day1 业务部署:业务部署环节,包括意图理解,事前仿真,配置⾃动化,事后检验等业务部署时⽹络配置效率及准确性能⼒。 Day2 监控排障:监控排障环节,包括意图监控,问题定界定位、⽅案⽣成、评估决策、⽅案实施、业务验证等智能运维能⼒。 DayN 变更优化:变更优化环节,对⽹络变更或优化的意图进⾏⽅案设计、评估决策,⽅案实施和验证等,以提⾼⽹络运⾏效率的能⼒。

根据数据中心网络自动驾驶指数评价体系,Tolly 从数据中心生命周期 Day0、Day1、Day2、DayN 4 个阶段,规划设计、部署开通、业务部署、监控排障、⽹络变更、优化调参 6 个大类、39 个⼩类,通过 150+ 指标测试,华为 CloudFabric 解决⽅案在部署效率和准确性、易用性、可维性、可靠性、网络性能优化等指标上以整体 3.51 分领先 Cisco IBN(Data Center)解决方案的 2.8 分,是 Tolly 评估过的业界唯⼀实现跨越 L3.5 级⾃动驾驶的数据中心网络解决方案。




Huawei Technologies, Co.Ltd Document number: 222112
Data Center Autonomous Driving Network – Huawei CloudFabric Solution Versus Cisco IBN Solution
Release date: 04 March 2022

The ultimate goal of full autonomous networks is a long-term process that needs to be implemented step by step. Based on the complexity of the communication network, the autonomous driving network levels are defined for data centers from the aspects of customer experience, manual involvement, and network environment complexity.

Tolly evaluated the Huawei CloudFabric solution and the Cisco IBN solution (ACI mode) for data center autonomous driving networks.

This test report compares and analyzes data center autonomous driving network solutions — Huawei CloudFabric and Cisco IBN from Day 0 — planning and construction, Day 1 — service provisioning, Day 2 — monitoring and troubleshooting, and Day N — change and optimization.




Huawei Technologies, Co.Ltd Document number: 222117ZH
华为 AirEngine 系列 Wi-Fi 6 无线接入点性能评估和功能验证
Release date: 23 February 2022

Wi-Fi 6 是最新商用化的 Wi-Fi 标准,被目前新发布的各类无线终端广泛采用。相较之前的标准,Wi-Fi 6 无线接入点(AP)能提供更大的带宽、更高的并发用户数、以及更低的时延。

Tolly 从市场上选取了几款华为最新 Wi-Fi 6 无线接入点 AirEngine 6761-21、AirEngine 5761R-11、AIrEngine 5761R-11E、AirEngine 5762-12、AirEngine 5762-12SW 以及 AirEngine 5762-15HW,验证了其部分最新功能。同时,Tolly 工程师测试了上述华为 Wi-Fi 6 AP 的单用户性能以及 AirEngine 6761-21T AP 的整机多用户性能。




Huawei Technologies, Co.Ltd Document number: 222114
Huawei CloudEngine S5731-S Series Switches Performance Evaluation and Feature Validation
Release date: 22 February 2022

Huawei CloudEngine S5731-S series switches are standard gigabit switches with GbE access ports and 10GbE uplink ports. They are ideal to be deployed in the aggregation or access layer of campus networks, and in the access layer of data center networks.

Tolly engineers evaluated Huawei CloudEngine S5731-S series switches’ performance and validated their features. Built upon Huawei’s high performance Versatile Routing Platform (VRP) software, CloudEngine S5731-S series switches can be configured locally or work in cloud- managed mode to be managed by Huawei Agile Controller. CloudEngine S5731-S series switches also support numerous security features and can interoperate with Huawei Cybersecurity Intelligence System (CIS) for Encrypted Communications Analytics (ECA) and network-wide threat deception.




Hughes Network Systems, LLC Document number: 222102
Benchmarking Hughes Hybrid Broadband vs. Terrestrial Broadband User Experience and Resiliency Evaluation
Release date: 17 February 2022

The importance of broadband Internet to families and households is well known, as it provides the connectivity required for remote learning, work-from-anywhere, video collaboration, telehealth, entertainment and other applications. A key metric that measures the effectiveness of broadband service in supporting these applications is Quality of Experience (QoE). The International Telecommunications Union (ITU) defines QoE as the “overall acceptability of an application or service, as perceived subjectively by the end user.” One example of a QoE metric is Mean Opinion Score (MOS) which measures user experience for Voice over IP (VoIP).

Hughes Network Systems, LLC (HUGHES), commissioned Tolly to benchmark the QoE of commonly used applications across their hybrid satellite and wireless broadband solution compared to a terrestrial broadband service. The Hughes hybrid solution is a multi- transport, high-performance, resilient service that supports high-bandwidth applications and latency-sensitive applications by combining satellite and wireless technology into a seamless end-user experience.

Applications tested included web browsing, videoconferencing, HD video streaming, gaming and VoIP. Results were judged both quantitatively (e.g., web browsing) and subjectively (e.g., video and gaming), using a 0-5 scale, where 0 is poor and 5 is excellent. Both the hybrid and the terrestrial services tested were configured for 100/20Mbps speeds.

Tests showed that the Hughes hybrid broadband solution provided a high quality user experience across all the different application types tested, delivering the highest score (excellent) across all applications.




Hughes Network Systems, LLC Document number: 222102Preview
Benchmarking Hughes Hybrid Broadband vs. Terrestrial Broadband User Experience and Resiliency Evaluation
Release date: 14 February 2022

The importance of broadband Internet to families and households is well known, as it provides the connectivity required for remote learning, work-from-anywhere, video collaboration, entertainment and other applications. A key metric that measures the effectiveness of broadband service in supporting these applications is Quality of Experience (QoE). ITU defines QoE as the “overall acceptability of an application or service, as perceived subjectively by the end user…” A good example of QoE metric is MOS (Mean Opinion Score) which measures user experience for VoIP.

Hughes Network Systems commissioned Tolly to benchmark the application QoE of commonly used applications across the Hughes broadband hybrid solution (HughesNet Fusion) and a terrestrial broadband solution. HughesNet Fusion is a hybrid, high-performance, highly resilient solution that supports both high-bandwidth applications and applications that require low latency by combining satellite and wireless technology into a seamless end-user solution.

Applications tested included web browsing, videoconferencing, HD video streaming, gaming and VoIP. Results were judged quantitatively (web browsing) and subjectively (video and gaming), using a 0-5 scale, where 0 is poor and 5 is excellent. Both systems were configured for 100/20Mbps bandwidths. .

Tests showed that the Hughes hybrid broadband solution provided the high quality user experience across all of the different application types tested, delivering the highest score (Excellent) across all applications.




New H3C Technologies Co., Ltd Document number: 222103Summary
H3C Application-Driven Campus (AD-Campus) Solution Feature Validation
Release date: 10 February 2022

Campus networks have great challenges in the face of increased mobility, emerging IoT and abundant applications. How to integrate applications with network infrastructure, ensure experience consistency, and simplify network management, it leads to a good subject for new generation campus solutions.

The H3C Application-Driven Campus (AD-Campus) solution converts campus network from “user adapts to network” to “network adapts to users”, enabling users and devices to roam around campus seamlessly and securely. Powered by H3C SeerAnalyzer and technologies such as gRPC, Telemetry Stream and ERSPAN etc, it reduces complexity of network deployment and maintenance and meets the increased requirements of mobility and IoT access in campus network in digital transformation.

The H3C AD-Campus solution adopts “cloud & intelligence native” architecture, which integrates management, control, and analysis capability with AI empowerment and unified management convergence of all scenarios covering campus network, WAN, and datacenter network.




Infoblox, Inc Document number: 222100
Infoblox BloxOne Threat Defense vs. Cisco Umbrella DNS-Layer Security Evaluation
Release date: 11 January 2022

Cyberthieves are constantly developing new methods to breach corporate networks, deploying various tactics that infiltrate typical cyberdefenses and create a “backdoor” in order to steal confidential data or deploy malicious tools such as ransomware.

For decades now firewalls and other security services have been in place to protect the direct interactions between corporate computers and external internet servers. As those security services protect against common attack techniques, hackers turned to other methods to evade detection, specifically for our discussion, the malicious use of Domain Name System (DNS) protocols.

DNS is used constantly by almost every IP-based device that needs to connect to other IP-based systems (e.g., computers, IoT devices and OT devices), and its presence is essential to the internet and IP networks in general. DNS translates queries for names of resources (like web sites or IoT/OT management servers) and returns IP address information that allows the connection to be established. The whole concept of DNS was to translate IP addresses to common names we can easily remember.

Because DNS originated as a relatively simple translation tool, it was considered benign, with DNS traffic typically allowed to pass through security solutions without additional inspection. Unfortunately, cyberattackers have developed new techniques to exploit DNS and use it to steal sensitive data from corporate networks as well as to infiltrate malware into the network.

Infoblox commissioned Tolly to evaluate the effectiveness of the Infoblox BloxOne® Threat Defense solution in key DNS-layer threat scenarios and compare those results against the Cisco Umbrella solution. Building on the Tolly report published in 2020, this report re-checks those scenarios and adds new scenarios. The Infoblox Threat Defense solution demonstrated greater effectiveness than Cisco Umbrella, as will be detailed shortly, and provided broader threat intelligence and ecosystem integration than the Cisco Umbrella offering.




New H3C Technologies Co., Ltd Document number: 221150
H3C SR6602-I ICT Converged Gateway Performance Evaluation and Feature Validation
Release date: 27 December 2021

In the cloud-era, and especially with the global change to remote working, gateway devices have become extremely important for ISPs and enterprises. Gateway devices need to provide comprehensive support for WAN protocols, multiple VPN types, advanced forwarding modes such as MPLS and SRv6, high availability features, easy operations and maintenance functions, strong security, and SD-WAN technology to provide good user experience for remote workloads and various cloud services.

The H3C SR6602-I ICT converged gateway is powered by the Intel Xeon CPU and H3C’s Comware v9 software with integrated network, compute and storage capabilities. Its open architecture supports hosting OpenStack VMs and Kubernetes pods for value-added services. It supports high performance with numerous carrier-grade and enterprise-grade gateway features which make it an ideal and future-proof choice to be the gateway of carriers, governments, power industry, finance, education, and enterprise organizations.

H3C commissioned Tolly to evaluate SR6602-I ICT converged gateway’s performance, capacity, and features.




Proofpoint Document number: 221135-IG
Infographic: Cloudmark Platform For Mobile
Release date: 14 December 2021

For decades, email users have had to contend with junk mail as well as dangerous messages showing up in the inbox. The deluge of nuisance and malevolent messages that have targeted email users also now target mobile messaging users: spam, malware, phishing, and social engineering.

View the Infographic on the key takeaways from Cloudmark’s Carrier-Grade Mobile Messaging Security Capabilities

The full Tolly report can be downloaded from here.




Proofpoint Document number: 221135
Cloudmark Platform For Mobile Understanding Cloudmark’s Carrier-Grade Mobile Messaging Security Capabilities
Release date: 10 December 2021

For decades, email users have had to contend with junk mail as well as dangerous messages showing up in the inbox. The deluge of nuisance and malevolent messages that have targeted email users also now target mobile messaging users: spam, malware, phishing, and social engineering.

The problems are manifold for both the mobile network operator (MNO) and the user. Studies have shown that users are more likely to read and interact with mobile messages, including SMS, MMS, and RCS message types, than they are with email.

Legitimate traffic can present challenges as well. Application-to-Person (A2P) SMS traffic continues to grow. Unfortunately, some users attempt to bypass higher A2P message charges by sending this traffic on Person-to-Person (P2P) communications routes. This practice, known as using “grey routes,” deprives the MNO of legitimate revenue.

Since its founding nearly two decades ago, Cloudmark’s core focus has been messaging security. Over that time Cloudmark has built a security solution that leverages both artificial intelligence (AI) and machine learning (ML) to enhance and automate message security. Cloudmark supports various mobile messaging standards including SMS, MMS, and Rich Communications Services (RCS) messaging.




Ruijie Networks Co., Ltd. Document number: 221153
Reyee Wi-Fi 6 (802.11ax) Access Points and Ethernet Switches Comparative Performance Evaluation vs. Aruba/Ubiquiti and Feature Validation
Release date: 06 December 2021

Wi-Fi 6 is the latest generation Wi-Fi technology that brings improvements in individual device and overall system throughput. Built upon more than 16 years experience in the WLAN and Ethernet switch market. Reyee (a sub-brand of Ruijie Networks Co., Ltd.) developed a series of Wi-Fi 6 wireless access points, Ethernet switches, and routers for small and medium-sized enterprise (SME) networks with powerful performance and easy-to-use cloud management features. Ruijie Cloud offers life-time free cloud management for the Reyee network devices. Users can manage and monitor the network using a Web browser or the Ruijie Cloud app anytime from anywhere via the Internet.

Ruijie commissioned Tolly to evaluate the performance of the Reyee wireless access points and Ethernet switches as well as their features. Test results demonstrated that the Reyee Wi-Fi 6 access points provide supervisor performance and outperform the access points from other vendors tested. The Reyee Ethernet switches support 100% line-rate forwarding using all ports for all standard frame sizes with zero frame loss. Reyee's self- organizing network feature provides a pioneering solution in the provisioning of network devices. Without a controller, Reyee devices automatically form a network, and the entire network can be managed visually. The easy-to-use cloud managed Reyee products are ideal to provide high performance wired and wireless networks for SMEs.




New H3C Technologies Co., Ltd Document number: 221154Summary
H3C Application-Driven Data Center (AD-DC) Solution Feature Validation
Release date: 06 December 2021

The H3C Application-Driven Data Center (AD-DC) solution adopts “cloud & intelligence native” architecture, which integrates management, control, and analysis capability with AI empowerment and unified management convergence of all scenarios covering campus network, WAN, and data center network.

The H3C AD-DC solution provides rich network services (NaaS) and security services (SECaaS). It provides automated full-lifecycle data center network management and a unified network architecture to connect bare metal servers, virtual machines and containers. Powered by H3C SeerAnalyzer and technologies such as gRPC, Telemetry Stream, ERSPAN and in-band telemetry (INT), AD-DC could achieve millisecond-precision data capture, megascale VM data analysis, and real-time fault detection, reducing the OPEX of data center greatly. Besides, H3C AD-DC provides extensive integration with OpenStack, virtual machine managers, and customers’ existing management and orchestration frameworks and security devices to build an open and programmable platform.




Ruijie Networks Co., Ltd. Document number: 221149
Reyee Wi-Fi 6 (802.11ax) Home WLAN Access Points Comparative Performance Evaluation vs. NETGEAR and TP-Link
Release date: 18 November 2021

Wi-Fi 6 is the latest generation Wi-Fi technology that brings improvements in individual device and overall system throughput. Built upon more than 15 years experience in the WLAN market, Ruijie Networks Co., Ltd. developed a series of Wi-Fi 6 access point models to cover different application scenarios. Now, Wi-Fi 6 technology is coming to the home market where demand for Wi-Fi connectivity and bandwidth has surged. Today, It is not uncommon for homes to have dozens of devices connected to Wi-Fi at any given time. In addition to computers and smartphones, Smart TVs, thermostats, cameras, doorbells, lighting, sensors and more now have persistent Wi-Fi connections.

Ruijie commissioned Tolly to evaluate the performance of its Reyee (sub-brand) standalone and mesh Wi-Fi 6 home access points against similar models from NETGEAR and TP-Link. Tests included multiple user tests of up to 78 simultaneous users, single-client maximum performance tests, and signal coverage tests. Tests were run both at 2.4GHz and 5GHz frequencies.




SonicWall Document number: 221148
SonicWall NSsp 13700 Next-Generation Firewall (NGFW) Strategic Analysis vs. Fortinet FG-2600F
Release date: 16 November 2021

Remote working and cloud computing have had a major impact on the way that enterprises conduct business. Universally, the shift to distributed work has put a focus on both security and connectivity. Or, in the context of this report, next- generation firewalls and SD-WANs. Given the array of services available, and the cost differential across vendors, it is prudent to analyze offerings before proceeding with an NGFW acquisition. SonicWall has designed its NSsp 13700 to excel in protection of large enterprises while maintaining an industry-leading price- performance ratio.

SonicWall commissioned Tolly to review the published specifications of its NSsp 13700 and compare it to Fortinet’s FG-2600F. Analysis was primarily focused on evaluating key total cost of ownership (TCO) metrics of the comparable solutions.

The Tolly analysis shows that SonicWall has a dramatically lower 3-year TCO for High-Availability (HA) deployments compared to Fortinet while providing comparable or better security feature sets and performance characteristics. The TCO is enhanced by SonicWall’s High Availability licensing policy allowing a single firewall license to be used for both the primary and secondary (HA) appliance.




VMware, Inc. Document number: 221128
User Experience with VMware SD-WAN Work-from-Anywhere with Dual WAN Links
Release date: 12 November 2021

The flexibility and ease-of-use of SD-WAN has made it extraordinarily popular as the “next-gen” WAN for organizations large and small. SD-WAN’s network overlay topology can also provide significant benefits for end-user experience while maintaining solid throughput performance. VMware SD- WAN™ can automatically remediate packet loss and deliver a high-quality experience even under adverse network conditions. Dual WAN link deployments further enhance the user experience by providing even greater flexibility, robustness and higher aggregate throughput.

VMware and Intel commissioned Tolly to benchmark the quality-of-service and remediation capabilities of VMware SD-WAN to improve the end-user experience for voice-over-IP (VoIP) and work-from-anywhere (WFA) applications using a dual WAN link deployment. Additionally, Tolly benchmarked the packet throughput of VMware SD-WAN.

VMware SD-WAN delivered good voice quality (MOS of 4.31) across dual links even with packet loss levels of 15% and latency of 150ms with 20ms jitter. See Figures 1 & 2 respectively. VMware SD-WAN demonstrated automatic optimization for dual WAN links by automatically preferring the low latency link. File download of a 250MB video from Microsoft OneDrive illustrated that download continued after one link was failed. With both links active, a single download session was able to use bandwidth from both links for a faster download. Additionally, VMware SD-WAN Edge 640 delivered 3Gbps of device throughput across a pair of devices.




VMware, Inc. Document number: 221128ZH
VMware SD-WAN ⽤户体验 使⽤双 WAN 链接随时随地⼯作
Release date: 12 November 2021

SD-WAN 的灵活性和易⽤性使其作为“下⼀代”⼴域⽹,在各类企业和机构中异常受 欢迎。SD-WAN 的 overlay ⽹络在保持稳定的吞吐量性能的同时,还能为终端⽤户 的体验带来显著的好处。VMware SD-WAN™ 可以⾃动补救数据包丢失,即使在 不佳的 WAN ⽹络条件下也能为⽤户提供⾼质量的体验。双 WAN 链路的部署提供 更⼤的灵活性、稳健性和更⾼的总吞吐量,进⼀步增强了⽤户体验。

VMware 和 Intel 委托 Tolly 对 VMware SD-WAN 的服务质量和对较差⽹络状况的 补救能⼒进⾏了基准测试,以评估该⽅案在使⽤双 WAN 链路部署时,承载 IP 语⾳ (VoIP)和随时随地⼯作(WFA)应⽤的终端⽤户体验。此外,Tolly 还对 VMware SD-WAN 的数据包吞吐量进⾏了基准测试。

即使在 WAN 链路有 15% 丢包率,150ms 延迟,20ms 抖动的情况下,VMware SD-WAN 在双链路上也提供了良好的语⾳通话质量(MOS 为 4.31)。请分别参⻅ 图 1 和图 2。 VMware SD-WAN 展示了对双 WAN 链路的⾃动优化,⾃动优先选 择低延迟的链路。从微软 OneDrive 下载⼀个 250MB 的视频,即使在⼀个链接故 障后,下载仍在继续。在两条链路都激活的情况下,单个下载会话能够使⽤两条链 路的叠加带宽,以实现更快的下载。此外,两台 VMware SD-WAN Edge 640 设备 间可实现总共 3Gbps 的设备吞吐量。




Apposite Technologies Document number: 221140
Apposite Netropy Traffic Generation L2-L3 & L4-L7 Ease of Use and Features
Release date: 04 November 2021

Benchmarking is essential if companies are going to deliver on service level agreements (SLA). Validating the traffic handling characteristics of networks, applications and security solutions is the only way to deliver services with confidence. Traffic generators have been available for quite some time. In many cases, though, the complexity and expense of traffic generators has kept them out of all but the larger enterprise labs. Apposite seeks to redefine the traffic generator with its Netropy series. Netropy Traffic Generation delivers a wide range of L2-L3 and L4-L7 functions all using a browser-based GUI and at a price point attractive even to smaller companies.

Apposite Technologies commissioned Tolly to evaluate the ease-of-use features of its Netropy Traffic Generation solution, specifically the Netropy TrafficEngine -one of four applications available. Testing was conducted using the Netropy 10G2 platform that provided four ports capable of 10GbE. In addition to confirming wire throughput capabilities, Tolly exercised a range of throughput testing scenarios.

Tolly tests confirmed that the Netropy 10G2 can send and receive zero-loss, wire-speed 10GbE traffic on both sets of ports simultaneously. Tolly engineers were able to configure both lower-level and upper-level protocol tests without any product training using the browser based GUI.