Aggregation Switch for a Bank's New Vietnam Headquarters: Multi-Vendor Interoperability and VS…
Industry Financial Services — Banking (Vietnam) Solution TiFRONT Cloud Security Switch with VSU Redundancy A New Office Meant a New Network When the Vietnamese subsidiary of a major Korean financial group relocated from its existing offices into a new headquarters building, it wasn’t simply moving desks. The move called for a network designed from the ground up — a full build-out of both the access switches serving each floor and the aggregation switches tying them together. In Banking, the Network Is Never Just Plumbing For a financial institution, a network outage isn’t an inconvenience; it’s an interruption to services customers are counting on. That reality set the bar for the project. The new network had to deliver high availability and rock-solid stability, and it had to be straightforward enough to maintain with the resources available on site. There was one more constraint, and it shaped the entire design: the organization’s network was standardized on a single incumbent vendor’s equipment. Whatever went into the aggregation layer had to interoperate cleanly with what was already there — no compromises, no surprises after cutover. PIOLINK at the Aggregation Layer, Existing Switches at the Edge The subsidiary deployed the PIOLINK TiFRONT Cloud Security Switch (TiFRONT-CS3826XQ) as its aggregation switch, paired with the access switches serving each floor. Between the two layers, every uplink and downlink runs over 1G fiber and is bundled using LACP. If a single link goes down, traffic simply keeps flowing across the remaining members of the group — services stay up, and nobody on the floor notices. Redundancy was designed into the aggregation layer itself as well. Using PIOLINK’s Virtual Switch Unit (VSU) technology, two physical switches operate as a single logical switch. Administrators configure and monitor one device rather than two, while the pair delivers hardware-level high availability underneath. Fewer things to manage, and one less single point of failure. Office floor switches connect back to the server room over single-mode fiber,where the TiFRONT-CS3826XQ aggregates traffic ahead of the firewall and the server-side switching layer. A Reference Earned in the Hardest Room to Win The deployment did what it was designed to do — and then some. In a financial environment standardized on another vendor’s equipment, the PIOLINK aggregation switch proved both its performance and its stability in production. Interoperability with the existing access layer was verified in a live banking network, not a lab. Link-level redundancy through LACP and switch-level redundancy through VSU gave the subsidiary the availability profile its business demands, without adding operational complexity. The subsidiary secured enterprise-class performance and VSU-based redundancy at a cost point that compared favorably with the alternatives it evaluated. Just as importantly, the project established a reference that travels. Korean financial institutions expanding into Vietnam face many of the same requirements this subsidiary did, and this deployment gives them something better than a specification sheet: a working network, in their own sector, in their own market. At a Glance 1.PIOLINK deployed at the aggregation layer 2.Verified interoperability with the existing access layer 3.1G fiber uplinks and downlinks, bundled with LACP 4.High availability through VSU-based redundancy 5.Stability proven in a live financial services environment 6.A banking reference established in the Vietnamese market For any organization designing a new network inside an established single-vendor environment — financial institutions especially — this deployment makes a practical point: interoperability isn’t a compromise you accept; it’s a capability you verify. And when it holds up, the aggregation layer becomes a place where availability, manageability, and cost efficiency stop competing with one another.
One Click to Fail Over, One Click to Come Back: HCI Migration and DR for a Public Institution
Industry Public Sector — Government Administration Solution PIOLINK POPCON HCI — Hyperconverged Infrastructure with Built-In Disaster Recovery (DR) When Stability Isn’t a Goal — It’s a Mandate For a public institution, system and operational stability aren’t aspirations to work toward — they’re baseline requirements. The services running on this institution’s infrastructure support complex public administrative operations that citizens depend on, and the data behind them includes highly confidential information the organization is entrusted to protect. That made building a proper disaster recovery (DR) system urgent. The institution needed an architecture that could keep administrative services running without interruption — no system failures, no data loss — even when something went wrong at the primary site. Alongside DR, its aging hyperconverged infrastructure was due for modernization. Recognizing that stability, continuity, and scalability had to be solved together rather than piecemeal, the institution set out to deploy an integrated solution. DR Built Around Real-World Constraints The requirements were specific, and they reflected the realities of running production systems in the public sector. On the migration side, existing virtual machines had to move over seamlessly through V2V migration, and the DR build had to make use of servers the institution already owned rather than requiring an entirely new hardware investment. On the replication side, data synchronization with the DR center had to stay reliable whether data volumes grew or shrank, and the institution wanted encrypted, compressed synchronization between the primary and DR centers to keep bandwidth consumption in check. And crucially, the requirements extended past the moment of failure. DR had to be implemented according to the institution’s own user-defined policies; operations at the DR site had to run smoothly; failback — reverse replication back to the primary site once it recovered — had to be clean and dependable; and the whole thing had to be provable through regular disaster recovery drills. A DR system nobody has rehearsed isn’t a DR system. It’s a hope. Two Centers, One Platform The institution migrated its aging HCI environment to POPCON HCI, modernizing its hardware foundation and building a multi-layered architecture in the process. New high-performance infrastructure running POPCON HCI was deployed at the primary center, while the DR system was stood up at the DR center on the institution’s existing infrastructure — giving the two sites complementary roles and stretching the value of hardware the organization had already paid for. With real-time data synchronization keeping the two sites aligned, failover became a matter of a single click on POPCON HCI at the DR center the moment an issue hits the primary site. Because the DR center was built on existing infrastructure, the system runs in an Active–Standby configuration — though POPCON HCI can flexibly operate in Active–Active as well, if operational needs call for it later. Recovery That Goes Both Ways Failing over is only half of disaster recovery. Getting back is the half that’s usually painful — and it’s where POPCON HCI’s failback capability sets itself apart. Through an intuitive UI, administrators can recover designated virtual machines with a single click, cutting out complex procedures and maximizing recovery speed. While the institution operates from the DR center, every data change is automatically tracked. Once the primary site is restored, only the incremental changes are synchronized back — delivering fast data consistency and service restoration instead of a full, time-consuming re-copy. That return runs inside a planned maintenance window with minimal downtime, so the system is restored without disrupting the business behind it. Ready Before the Disaster, Not After The payoff came in layers. The Active–Standby configuration gave the primary and DR centers a seamless working relationship, keeping operations continuous through unexpected system failures and disasters alike. Regular simulation drills validated and sharpened the institution’s response capability, turning DR from a documented plan into a rehearsed, systematic readiness posture. Most significantly, the system ensures the secure recovery of highly confidential information — establishing a robust foundation for protecting national data even in the middle of a disaster. For public institutions weighing an infrastructure refresh against a DR mandate, this deployment makes a useful point: the two aren’t separate projects. Modernizing onto a hyperconverged platform with DR built in lets an organization reuse the hardware it already has, fail over in one click, fail back just as cleanly — and prove it all works before the day it has to.
Keeping Essential Public Services Always On: Multi–Data Center Failover with PAS-K GSLB
Industry Public Sector — Government Services Solution PIOLINK PAS-K Application Delivery Controller (ADC) with Global Server Load Balancing (GSLB) When Downtime Isn’t an Option For a public institution delivering essential services to citizens, high availability is more than a technical metric — it’s a matter of public trust. An unexpected system failure or even a few minutes of downtime can do more than interrupt a single transaction; it can damage the institution’s reputation and, over time, push users toward alternative services. For the organization at the center of this case, continuous service availability — and the business continuity that depends on it — was a non-negotiable requirement. Redundancy Alone Wasn’t Enough To guard against outages, the institution had already built a hot-standby, active–standby architecture across two data centers: a primary site in Busan and a disaster recovery (DR) site in Seoul. Under normal conditions, the Busan site handles all user traffic; if it fails, that traffic is meant to move to the Seoul DR site so services stay online. But standing up a dual data center is only half the problem. The harder question was how to move traffic between sites — automatically, instantly, and without users noticing. The team needed intelligent traffic control at the top of the infrastructure: a way to distribute load, continuously monitor the health of each site, and fail over the moment something went wrong. They also wanted to avoid bolting on a stack of separate, single-purpose appliances that would only add cost and operational complexity. What they needed was Global Server Load Balancing (GSLB) working hand in hand with their existing load balancing — delivered as efficiently as possible. One Platform for Load Balancing and Failover The institution deployed PAS-K, a PIOLINK Application Delivery Controller (ADC) that consolidates L4–L7 load balancing and GSLB onto a single platform. The same device performs Server Load Balancing (SLB) in front of application servers, Firewall Load Balancing (FWLB) in front of firewalls, and GSLB across the two data centers. PAS-K’s GSLB engine continuously evaluates each site’s availability and network conditions, steering users to the optimal data center via DNS. During normal operations, it directs users to the Busan primary site. The moment a link failure or outage is detected in Busan, GSLB automatically fails traffic over to the Seoul DR site — with no manual intervention and no perceptible interruption for the end user. Crucially, the PAS-K unit at the DR site also runs in active mode, performing the same health monitoring and traffic handling as the primary. This design eliminates any single point of failure between the two sites. And because PAS-K delivers SLB, FWLB, and GSLB natively — with no per-feature licensing to purchase — the institution consolidated what would otherwise require several separate appliances into one cost-efficient, easier-to-manage platform. GSLB directs users to the Busan primary center and automatically fails over to the Seoul DR center, while a dedicated line keeps both sites in sync. Near-Zero Downtime, Lower Complexity The results were tangible. By pairing its dual data center architecture with PAS-K GSLB, the institution achieved near-zero-downtime failover between sites. Service continuity improved: the Busan site carries traffic under normal conditions, and failover to the Seoul DR site is now fully automatic. Traffic management became genuinely intelligent — GSLB continuously monitors the availability of each site and updates its DNS responses the instant a failure is detected, keeping users on the fastest healthy path. Consolidating firewall load balancing and GSLB onto a single platform improved operational efficiency and removed the need for additional devices or a complex network redesign. And with integrated load balancing and no additional licensing, the institution lowered both deployment and operating costs — reducing total cost of ownership while leaving room to scale as demand grows. “In the past, service outages were a major concern during system failures, but after adopting PAS-K GSLB, we’ve been able to maintain stable service operations. As a result, overall service reliability and quality have significantly improved.” For public institutions — and any organization where downtime simply isn’t an option — this deployment points to a clear principle: true resilience doesn’t come from redundancy alone, but from intelligent, automatic failover. And when server load balancing, firewall load balancing, and GSLB are consolidated into a single Application Delivery Controller like PAS-K, that resilience arrives without the added cost and complexity of a multi-appliance architecture.
Always-On BCP at Scale: How a DR Service Provider Modernized Its GSLB Platform with PAS-K
Industry Security & Financial Services — Managed DR/BCP Provider Solution PIOLINK PAS-K Application Delivery Controller (ADC) with Global Server Load Balancing (GSLB) A Business Built on Staying Online For a security and financial services provider whose core business is disaster recovery (DR) and business continuity (BCP), staying online isn’t just an internal goal — it’s the product. The company operates its own Internet Data Centers (IDCs) in Mokdong and Bundang, and delivers everything from DR design and implementation for its customers’ infrastructure to round-the-clock 24/7 monitoring. At the heart of its offering is a commercial, GSLB-based service: using Global Server Load Balancing (GSLB) across the Mokdong and Bundang centers, the provider can instantly redirect traffic to a DR center — or to its dedicated BCP center — the moment a customer’s data center fails or an application goes down. Customer domains are delegated to the provider and operated in a hosting model, which means the reliability of its GSLB platform directly underpins the business continuity of every customer it serves. Aging Infrastructure, Rising Expectations Over time, the GSLB appliances underpinning this service began to show their age. To keep its BCP service dependable — and to scale it — the provider set out to modernize the platform with three priorities in mind: replace the aging GSLB appliances with a stable, future-ready foundation; gain more flexible load-balancing policies to optimize traffic and improve operational efficiency; and achieve real-time synchronization between centers so that DNS service stays consistent no matter which site responds. There was an operational dimension, too. As a BCP provider managing a large number of customer domains, the company treated consistent configuration management, real-time reporting, and fast access to information for troubleshooting as non-negotiable. What it needed was a next-generation GSLB solution that would carry over the strengths of the existing system while adding a more intuitive configuration interface and markedly better day-to-day manageability. A GSLB Platform Built for Operators The provider replaced its aging appliances with PAS-K, a PIOLINK Application Delivery Controller (ADC) delivering GSLB on a platform built around exactly these operational realities. PAS-K’s intuitive, localized GUI cut configuration time and flattened the learning curve for operators, so routine changes no longer demanded specialist effort. Built-in GSLB DNS query and response logging gave the team real-time visibility into DNS traffic, dramatically shortening the time needed to isolate and resolve issues. Scheduled system health checks and automated traffic reports turned monitoring and customer reporting from a manual chore into a background process, helping the team catch potential failures before they surfaced. And real-time automatic configuration sync tied the two sites together: any change made at either the Mokdong or Bundang center is instantly recognized and applied to the PAS-K unit at the other, eliminating configuration drift between centers and keeping service consistent across the board. Reliable Failover, Simpler Operations The payoff showed up on both sides of the business — the service customers experience, and the operations behind it. On the service side, the provider can now redirect traffic in real time to its BCP center the instant a customer’s data center goes down, while PAS-K’s range of GSLB load-balancing methods distributes application traffic efficiently between customer data centers and the BCP center. On the operations side, real-time synchronization of configuration and availability status keeps DNS responses consistent and connection paths optimal, and DNS query and response logs give operators the visibility to analyze issues quickly when a customer calls. Combined with the intuitive GUI and automated reporting, the result is a markedly lighter operational load. Taken together, these gains give the provider a robust foundation for delivering stable, 24/7 BCP services year-round — safeguarding its customers’ business continuity against outages, disasters, and threats they can’t predict. For any managed service provider whose reputation rests on keeping other companies online, this deployment underscores a simple truth: dependable failover and effortless operations aren’t competing goals — the right GSLB platform, like PAS-K, delivers both at once.
Securing an Open Campus Network: How Chosun University Unified Switch Management, Visibility, and T…
Industry Higher Education — University Campus Network Solution PIOLINK TiFRONT Cloud Security Switch with TiController Integrated Management (NMS · NAC · QoS · ESM) A Campus Network Under Pressure Founded in 1946 and known as one of Korea’s first private universities, Chosun University runs a sprawling campus where thousands of students connect a constantly changing mix of personal devices to the network every day. That openness is part of campus life — but it also makes the network exceptionally hard to secure and manage. Open by Design, Exposed by Default The very openness that makes a campus network work also leaves it exposed. A single malware-infected device could join the network without its owner realizing it, giving an attacker a foothold to reach sensitive systems — university finances, personal records, and academic databases. Students plugging in unauthorized hubs or routers could create Layer 2 network loops, and the resulting broadcast storms were capable of flooding the network and knocking the entire campus offline. And with limited visibility into which devices were connected where, blind spots — and the security gaps that come with them — were hard to avoid. The IT team’s priorities were clear: block harmful traffic before it spreads, bring switch management under central control, and gain the endpoint and network visibility the university had been missing. One Console for the Whole Campus After evaluating several competing products, the university selected PIOLINK’s TiFRONT Cloud Security Switch — and what set it apart was how easy its management solution, TiController, made day-to-day operations. Through TiController, administrators can centrally manage the endpoints connected to switches spread across multiple buildings, with network monitoring (NMS), quality of service (QoS), enterprise security management (ESM), and Network Access Control (NAC) all brought together on one screen. That single pane of glass lets the team pinpoint the source of a problem and respond quickly, instead of chasing issues switch by switch. Built-in IP address management — available without purchasing add-on options — heads off IP conflicts before they can disrupt users. Stronger Security, Less Effort The switch refresh paid off on two fronts: stronger security, and far less operational effort. By unifying switch management, endpoint management, traffic management, and security into TiController, the university sharply reduced the workload on its administrators — making the platform a strong fit for a large network run by a lean IT team. Security and visibility improved just as dramatically. Administrators can now see exactly which devices are on the network, and block malware right at the access-layer switch closest to the infected endpoint — containing threats before they can move laterally across the campus, and speeding up detection and response. Automated IP management, meanwhile, made it easier for students, professors, and staff to move around campus and stay connected. For any organization running a large, open network with a small team — universities especially — Chosun University’s experience points to a clear lesson: real security starts with visibility, and when switch management, access control, and threat containment live in one console, protecting the network no longer has to mean more work.
Load Balancing for e-Learning: How Teikyo University Kept 6,000 Students' Lectures Streaming W…
Industry Higher Education — University e-Learning Solution PIOLINK PAS-K Application Delivery Controller (ADC) with Server Load Balancing When the Classroom Moves Online, the Network Becomes the Campus Founded in 1966, Teikyo University is a comprehensive university in Tokyo with 10 academic departments — spanning medicine, the liberal arts, and science and engineering — across five campuses, anchored by its main campus in Itabashi. Long before remote learning became a global necessity, the university had been building the muscle for it: for years, every lecture was filmed and posted to its servers within 15 minutes, so students could review class material whenever they needed. There was one catch. That lecture video was only accessible from inside the university network, so the on-campus computer rooms were perpetually full of students trying to watch. The content was ready for a digital future; the delivery model was still tied to the building. A Sudden Shift to Learning at Scale When universities across Japan suspended in-person lectures and moved fully online, Teikyo made the same call for the semester beginning that April. Overnight, a system designed to stream video to students sitting in campus computer rooms had to serve an entire student body connecting from home, all at once. That kind of shift is where e-learning platforms live or die. The Itabashi campus alone has around 6,000 students, and among them are the medicine, pharmacy, and medical technology programs — students for whom grades matter intensely and for whom a frozen or dropped video stream mid-lecture isn’t a minor annoyance but a real academic risk. Handling a surge of simultaneous streaming sessions without degrading quality demanded serious traffic management underneath the platform. Nonstop Streaming, Powered by Load Balancing To keep its online lectures running without interruption, Teikyo University deployed the PIOLINK PAS-K — an Application Delivery Controller (ADC) that raises application availability, performance, and scalability through intelligent server load balancing. By distributing incoming streaming traffic evenly across servers, PAS-K prevented any single server from being overwhelmed as thousands of students logged in to watch lectures at the same time. The result was exactly what a university needs from its infrastructure during a high-stakes term: it stayed invisible. Students connected, watched, and reviewed — without the buffering, lockouts, or mid-class disconnections that would have followed a server overload. “Since introducing PAS-K, I haven’t received a single complaint from students or professors about being unable to access a class or getting cut off in the middle of one.” — Director, Information Center, Teikyo University A Foundation That Outlasts the Emergency What began as a response to an urgent situation turned into a lasting part of how the university teaches. Even as in-person life resumed and students returned to campus, online lectures remained a permanent fixture rather than a temporary workaround — a shift Teikyo expects to hold well into the future. With a dependable delivery foundation in place, the university is building on it rather than settling. Today PAS-K handles load balancing; going forward, Teikyo plans to extend it to web caching as well, alongside strengthening its Internet links and data center infrastructure — layering further performance gains on top of the availability it already relies on. For any institution whose service quality now depends on streaming to thousands of users at once — universities especially — Teikyo University’s experience illustrates a straightforward truth: great content still needs great delivery. Pairing years of e-learning know-how with the server availability that load balancing provides is what lets a university deliver lectures its students and faculty can simply count on.
BYOD Campus Security Without an Agent: How a University Secured Its Network at the Switch
Industry Higher Education — University Campus Network Solution PIOLINK TiFRONT Cloud Security Switch with Centralized Management A Campus Network Everyone Brings Their Own Devices To A university — spanning undergraduate colleges, graduate schools, and affiliated research institutes — runs one of the hardest networks to secure there is: an open Bring Your Own Device (BYOD) environment. Every day, students connect personal laptops and smart devices to the campus network, and there is no practical way to require them all to install a specific security agent on their own hardware. That openness is central to campus life — and it left the network both exposed and hard to keep running smoothly. Personal Devices, Shadow Networks, and No Way to See Them The problems came from every direction. Students plugged in unauthorized Internet-sharing devices to extend connectivity, spinning up shadow networks the IT team couldn’t see. P2P clients and web-hard programs installed to download music and movies generated heavy traffic that degraded service for everyone. And with personal devices joining freely, a single compromised laptop could introduce threats the network had no easy way to catch. Underneath it all was a visibility gap. In a BYOD environment where you can’t mandate software on student PCs, pinpointing the source of a network failure was genuinely difficult. The IT team’s priorities came into focus: block harmful traffic, bring IP and switch management under central control, and make the whole thing easy to operate — without asking a single student to install anything. Security Built Into the Switch, Not the Student’s Laptop Rather than redesign the network, the university simply swapped its existing switches for PIOLINK’s TiFRONT, keeping the internal campus network configuration intact. TiFRONT is an internal network security and management solution that pairs a cloud security switch with a cloud- and web-based management system, giving administrators centralized control over security-enabled switches — along with threat prevention, failover, and clear visibility into user devices and traffic. The key advantage: because protection lives in the switch, no security software is required on any student’s device. Replacing an existing switch with a TiFRONT switch resolves the security problem on its own. TiFRONT identifies and blocks disallowed terminals, devices with falsified IP/MAC addresses, and unauthorized NAT (Internet-sharing) devices before they reach the network. And in an 802.1X environment, it can enforce multi-factor authentication policies that require both user and device to authenticate before any network access is granted. Threats Blocked, Traffic Tamed, Network Visible With TiFRONT in place, harmful traffic — ransomware, botnets, ARP spoofing — is blocked at the switch level, right where devices connect, while built-in QoS keeps Internet service stable for everyone. Cabling complexity that once caused network loops was cleaned up, and the management system now gives administrators an at-a-glance view of the entire campus network. That visibility extends all the way to the endpoint. Administrators can see exactly which user devices are connected — including IP address, device type, and traffic usage — and analyze usage on a per-user basis: who sent what, when, where, and how much. Armed with that insight, the team could re-prioritize bandwidth-heavy traffic such as video streaming, preventing the campus-wide slowdowns that heavy usage used to cause. For any institution securing a large, open BYOD network — universities especially — this deployment makes a practical point: you don’t secure an open network by locking down every device on it. When threat prevention, access control, and full traffic visibility are built into the switch itself, the network protects itself — no agent on a single student laptop required.
Why Buy Two Boxes? Combining WAF and Load Balancing in a Single Appliance
Industry Financial Services — Insurance Solution PIOLINK WEBFRONT-K Web Application Firewall (WAF) with Integrated L7 Load Balancing & SSL Offloading When Web Services Become the Front Line For an insurance provider, the website and its online services are where much of the business now happens — and where much of the risk lives, too. As web traffic climbed and attacks against web services grew more frequent, Hyundai Insurance China recognized that strong, high-performance web security was no longer optional. It set out to find a Web Application Firewall (WAF) that could keep pace — one that was not only effective against attacks, but also simple to operate, with straightforward configuration and easy log analysis from a single dashboard. Two Problems, and the Cost of Solving Them Separately Web security was only half the challenge. As traffic surged at peak times, the company also needed load balancing to keep its web servers from being overwhelmed — along with the high availability and business continuity that health-check-driven failover provides. Conventionally, meeting both needs means deploying two separate systems — a web application firewall and a load balancer — each in a redundant configuration. But standing up and maintaining two solution stacks is expensive, and Hyundai Insurance China was reluctant to take on that cost and complexity. What it really wanted was a single solution that could deliver web security and load balancing together, without compromising on either. One Platform, Purpose-Built for Both After weighing which WAF best fit its security policies and operating environment, Hyundai Insurance China chose PIOLINK’s WEBFRONT-K. What makes WEBFRONT-K different is its foundation. Rather than running on general-purpose hardware, it’s engineered on a high-performance switching architecture derived from PIOLINK’s proprietary application delivery networking — the same technology behind PIOLINK’s Application Delivery Controllers (ADCs). Because WEBFRONT-K is a WAF built on that ADC platform, it delivers availability, performance, and security through built-in load balancing and SSL offloading — with no separate load balancer required. The company deployed two WEBFRONT-K units as a redundant pair, each with an embedded SSL acceleration module. Offloading SSL encryption and decryption to WEBFRONT-K meant the web servers handled encrypted traffic with no performance penalty. On the security side, WEBFRONT-K blocked malicious attacks, inspected and identified client requests and unauthorized access, and shut down suspicious connections. On the delivery side, its L7 load balancing improved web server reliability, while the redundant configuration kept services seamless and dependable. Safer, Faster, and Simpler to Run The results reached beyond security. WEBFRONT-K didn’t just protect and stabilize the web servers — it made the whole data center more effective, with faster application delivery and higher server availability. Just as important was the day-to-day experience. PIOLINK’s monitoring provided real-time visibility and effective log analysis, making the system easier to operate and security policies simpler to set. For Hyundai Insurance China’s network operators, that combination of straightforward configuration and easy policy management translated into a genuinely better operational experience. For any organization weighing web security against performance and cost — financial services firms especially — Hyundai Insurance China’s experience makes the case that WAF and load balancing don’t have to be two separate purchases. Delivered on the right platform, they can be one: stronger protection, better performance, and lower total cost of ownership, all at once.
SSL Offloading Without the Trade-Off: How Hitachi Systems Delivers Secure, High-Speed Cloud Services
Industry ICT Infrastructure & Managed Services Solution PIOLINK Application Delivery Controller (ADC) with SSL Acceleration A Cloud Provider Built on Trust Hitachi Systems (Hitachi Electronics Services) is an integrated ICT solutions provider supporting the full technology lifecycle of its customers — from planning, system design, and build, through operation and maintenance, to secure disposal and data erasure. As a trusted partner for enterprises seeking tailor-made ICT solutions, the company holds itself to the highest standards of reliability, security, and service continuity across every system it manages. As part of its cloud infrastructure strategy, Hitachi Systems deployed SSL encryption to protect data in transit across its cloud-based services — a security baseline increasingly required to meet modern compliance and data-protection standards. It was a decision that reflected the company’s commitment to security. But it also set the stage for a challenge that many cloud providers eventually face. When Strong Security Starts to Slow You Down Strong encryption comes at a computational cost. As SSL key strength increased, so did the processing load required for SSL/TLS encryption and decryption, placing growing strain on backend servers. Applications began to respond more slowly as CPU cycles were consumed by cryptographic processing at higher key strengths. At the same time, cloud traffic continued to scale. Distributing encrypted sessions efficiently across servers became increasingly difficult without dedicated infrastructure for load balancing. Hitachi Systems’ IT and security teams found themselves facing a choice no ICT provider wants to make: trading security for performance, or performance for security. Offloading the Burden, Without Compromising Security To resolve this, Hitachi Systems turned to a PIOLINK Application Delivery Controller (ADC) purpose-built for high-performance SSL offloading and intelligent load balancing. By offloading SSL encryption and decryption from backend servers to dedicated hardware, PIOLINK’s ADC freed application servers from the heavy computational burden of cryptographic processing — while the company continued to maintain SSL encryption across its cloud environment. Integrated load balancing distributed traffic evenly across server resources, and the infrastructure gained the headroom to support more computationally intensive cipher suites at scale, without sacrificing throughput. Faster, More Resilient, and Ready for What’s Next The impact was immediate. Cloud service availability improved as server load eased and traffic distribution was optimized. Response times improved, even under high-strength SSL encryption. And with a scalable foundation in place, Hitachi Systems’ infrastructure is ready for the stronger cipher suites and rising security requirements yet to come. “PIOLINK’s reliable SSL offloading enhances our cloud service availability and speed, even as our encryption requirements grow more demanding.” For ICT and cloud service providers balancing rising security requirements against performance expectations, Hitachi Systems’ experience demonstrates a clear principle: SSL offloading isn’t just a performance optimization — it’s the foundation for delivering strong encryption and reliable, high-speed cloud services at the same time.