CEO Jerry Kennelly details beyond-WAN-optimization strategy that broadens Riverbed’s assault on top network rivals.
Riverbed, with its highly successful WAN optimization technology, has long competed with Cisco – but in a niche fashion, acknowledges CEO and co-founder Jerry Kennelly. Now, the company is taking its fight to the core of Cisco’s business with new SD-WAN routing technology that could make existing routers obsolete in the world of hybrid clouds and virtual networks.
In this installment of the IDG CEO Interview Series, Kennelly spoke with IDG Chief Content Officer John Gallant about this new battlefront, as well as Riverbed’s expanded role in application performance management. He also talked about Riverbed’s decision to go private in 2015 and why that move brings big benefits to customers.
When you bring up the name Riverbed, most people think of the WAN optimization company. How do you want them to think of Riverbed today?
Riverbed enables people to use applications across global networks, across vast physical distance, with the best performance, the best visibility, lowest cost, best response time. Our tag line is the “application performance company”, but it’s really what we do. When we got this business started I don’t think people understood WAN optimization that well. People thought it was all about bandwidth optimization.
Bandwidth is important. But we did something much more important, which was overcome the latency of packet travel in global networks such that you can get sub-second response time accessing sites anywhere in the world. When we started the company in 2002 the world was CIOs delivering applications to their knowledge workers from on-prem servers across captive MPLS networks. In that world, we were very powerful because we dramatically cut the two big costs of delivering applications; the cost in time – the latency – and the cost in dollars, the price you pay for bandwidth. That’s why we just exploded between 2004 and 2012. Then we realized we had a bigger mission and that was to enable a CIO or network manager to completely control the visibility, repair, response time and delivery of applications over networks. That’s really what we want to be known for.
Before we dig into some specific products and your strategic direction, let’s talk about something that happened in 2015, when Riverbed went private. Why did you do that and what’s been the result of that change?
Wall Street tends to favor revenue growth over profitability or cash flow. We did very well in revenue growth but we had a slowdown between 2012 and 2013 and that depressed our share price which made us an attractive target for activist investors. We got a very enthusiastic activist investor to the stock in late 2013.
That was Elliott Management?
Yeah. The Elliott folks, and they were campaigning. Their job was to buy stock at a discount and then sell it, usually within a year or two, at a much higher price. Your job as CEO is to decide. You have to capture all the noise and activist engagement and your ego and the company and decide the best outcome for the shareholders of the company. What course of action delivers the best share price?
I spent about six months trying to figure that out and in the end decided that to go private delivered a very good share price to all the shareholders, including the activists, employees and institutional holders, and it allowed us to operate with the benefits of being private. A lot of people don’t understand this but the equity model is usually a highly leveraged model where they put in some amount of equity and a large amount of debt to finance the go-private activity. To go private, you have to actually be both profitable and have a strong cash flow and those were two strong aspects of Riverbed. In a sense, it’s almost a mark of honor to be able to go private.
+ GOING PRIVATE: Riverbed goes private in $3.6 billion deal +
Once private, we needed to do some pivoting to re-fire up the growth. We were already very profitable but we could have been more profitable so I sold two lines of business. I sold our cloud storage business to NetApp and I sold our virtual ADC {application delivery controller} business to Brocade. Both of those were very good businesses, both best-of-breed products at the time but not really great fits with Riverbed, our sales force and our channels.
NetApp and Brocade were better homes for those businesses. That allowed us to focus on our core business and we’ve been able to re-fire the growth in the core business and improve profitability. When you have too many lines of business in one company you end up with a lot of extra cost, a lot of overlay technology specialists and overlay sales specialists. We were able to redo the cost structure of the company and this year, 2016, we’ll do $1.1 billion in sales at a 32% operating margin and generate over $350 million in cash and that’s the second year of being private.
On top of that I was able last year to do two important acquisitions. I bought a company {Ocedo} in January that had what we think is one of the most advanced versions of SD WAN – software-defined wide area networking. That will be very important for the future of Riverbed. In August, I bought a Boston/Tel Aviv company called Aternity that has a very interesting, probably best-of-breed product in what’s called end-user experience monitoring that’s been a great addition to the company. Those things would have been difficult to do under the eye of Wall Street where you’re on this 90-day treadmill. The private equity investors have more of a three- to four-year horizon for generating the value of their business rather than having to check every day to see what your stock is doing.
If you were to boil it down to a sentence or two, going private is good for customers why?
It’s good for customers because we’re able to focus on delivering value, making the company and the product more attractive and doing the best quality support. We’re less focused on grinding them the last week of each quarter to give us one more [purchase order].
Riverbed uses the term “application-defined networking”. What does that term mean and how is that shaping your corporate and product strategy?
I said a bit earlier that there was an old world in 2002 that CIOs had for delivering applications; on-prem servers, MPLS network. Today, a CIO has to deliver applications from an on-prem server, from a SaaS provider who has his own data center somewhere, from an infrastructure-as-a-service data center at [Microsoft] Azure or wherever. He has to do it with his MPLS network and he wants to mix and match in a cheaper broadband internet network. All the permutations and combinations of trying to deliver applications with speed at a good cost with the right response time in this new world is very complex. It’s the hybrid cloud world. Old fashioned routers are still widely used and that’s one of the issues in the cloud world. Most things have been upgraded to 21st century technology to support cloud data processing except networking. Most networking is still mid-1990s technology, 25-year-old technology.
In this new, complex world you want to be able to decide packet-by-packet according to what the application is, how you route it, with what rules and what SLA. If a packet comes across a router and it’s an employee looking at a YouTube video, then you can give that a low priority and send it off over cheap bandwidth. If you look at the packet and inside the packet is an HR inquiry to the corporate data center, then you can give that packet high priority, high security and send it over your MPLS network.
You can only do that if you’re routing on Layer 7, which is the application layer, and only if you have a technology of deep packet inspection where you know what’s inside every packet. Classic routing and switching is done at Layers 2 and 3 in hardware. The future of networking in the hybrid cloud world is to route not at Layer 2 and 3 in hardware; it’s to route at Layer 7 in software using your application knowledge to route properly in terms of speed, cost, performance and security for each user according to the application type.
If you understand the routes of WAN optimization in the SteelHead product of 2002, it’s a Layer 7 optimization that requires application knowledge to do the latency optimizations. We have 15 years of domain knowledge, of understanding every packet and we have the best-of-breed deep packet inspection technology so we were able to do these latency optimizations at Layer 7 on all those applications. That knowledge is unmatched in the industry. Now we can use that knowledge to do routing at Layer 7 based on application knowledge rather than doing routing at Layers 2 and 3 based on hardware.
Diving into Riverbed’s products
I want to use that as a jumping off point to talk about the SteelConnect product. Can you explain how that works? I want to make sure readers really understand it because I think you’re onto an interesting approach here.
SteelConnect is our SD-WAN routing product. It’s a big loop for us. I wouldn’t have said this in past years but our original core business of WAN optimization was a good business, we were best in it, we were the market leader, but it was a bit to the side of mainstream networking. You might call it a niche, a big niche but a niche. With SteelConnect [we’re] entering mainstream networking, the routing and switching business for the first time. SteelConnect is our premier entry into that market. SteelConnect uses cloud-based management and orchestration software to control the deployment of branch routers and allow them their routes at Layer 7 using application knowledge. It’s the simplest, fastest way for any large corporation that has a big network of branch routing to deploy, change and manage their entire network worldwide.
The network giants use 20-year-old technology where you have to write CLI commands to define what a router does. It can take 700 to 1,000 lines of CLI command code per router to put a router in a network, tell it what to do, which other routers to talk to, how to do its routing. If, in one of those lines of code, you either leave out a zero or add an extra zero the thing doesn’t work. If you have 1,000 branch offices and 1,000 branch routers you have to write those 700 to 1,000 lines of code 1,000 times. It can take weeks, even months to deploy or update a change on a big global network of routers.
With this [SteelConnect} technology, it’s all managed and orchestrated centrally from cloud software that sits on either AWS or Azure. With three clicks of a mouse a network manager can deploy and configure a new router anywhere in the world and/or he can change the routing rules of all 1,000 of his routers in a matter of minutes, as well as also back up and correct it in a manner of minutes. Say that he’s got 1,000 branch routers out there and tomorrow the CEO of the company wants to send a video announcing the fantastic results of the quarter and his fantastic leadership abilities. You have to reconfigure every router to give special SLA priority to this video from the CEO. In the classic world that exists today with the Layer 2 and 3 hardware routers out there, you couldn’t do that. With a software-defined wide-area network with our SteelConnect product, that’s a five-minute exercise to reconfigure all 1,000 routers worldwide. It’s a dramatic change in the way people can deploy and manage a big global network of branch routing.
In terms of what you buy from Riverbed, is it software only for your existing Cisco or other routers? Are you buying hardware for the remote office? How do you deploy that?
All of the above. We offer hardware with the software mounted on it, what is known as the appliance model, but we also offer the software-only version if you want to run it on your own hardware. We don’t really care. It turns out most people choose the hardware version because of the environment. If you look at the topology of a network, a company might have three data centers and 1,000 branches so you might sell three virtual versions, or software-only versions, for the three data centers but then sell 1,000 appliances for the big branch deployment.
I want to make sure because this is one of those hyped-up phrases these days. When you think about software-defined WAN what do you mean by that and what do you think that brings to customers?
Software-defined WAN means that it’s central management and orchestration of the routing, rules and SLAs that sit on your routers, which in our case are inspecting each packet at Layer 7 and routing by application type. Basically, it’s still a piece of hardware but it’s routing at Layer 7 based on the application type and managed from a central orchestration platform. You’re able to deploy upgrades globally from a master console without having to go to each individual router one by one.
How threatening is this to the existing router vendors?
I don’t know if threatening is the right word. This a big market opportunity because the truth is, in this new world of digital initiatives and hybrid cloud deployments where people are mixing SaaS and on-prem and Azure and AWS, the old infrastructure isn’t adequate to deal with that. It’s too cumbersome, not agile, expensive and error prone.
People have upgrade cycles where existing branch routers go through end-of-life and have to be upgraded. That’s happening probably on a third of the branch routing hardware that’s out there right now. People don’t want to replace it with 30-year-old technology. They’re looking to bring in 21st Century technology now.
+ ALSO ON NETWORK WORLD How to choose a software defined WAN (SD-WAN) +
The topic of software-defined wide-area network is a hot topic right now. It’s what every network manager, what every CIO is talking and thinking about. It’s still nascent. Once you get a demo of the product {SteelConnect} and understand the benefits, you really don’t want to go back to the old world. The challenge for the big people who have dominated routing for the last 25 years is they don’t have the new technology yet so they’re either going to have to develop it or buy it or something.
I want to talk more specifically about how SteelConnect makes hybrid cloud easier?
You’re a CIO. You have your knowledge workers out in all your offices and they’ve got to use your captive applications that do whatever is strategic to your company but you also want to deliver Office 365, you want to deliver Salesforce, you want to deliver Workday, you may want to offload some processing to AWS instead of running it yourself. You want to do that reliably in an agile way, make quick changes and using least-cost routing. In other words, you want to put as little as possible on your MPLS network that you’re paying big bucks for to the service providers and put as much as possible out on the cheaper internet. Software-defined networking makes that world much easier. In fact, that world is very hard to address with classic routing. Software-defined routing makes that world possible really.
Talk about SteelFusion. What does this product set do and what can it replace?
SteelFusion is our edge product for people who want to have high performance of applications that run at a local branch but who don’t want the data and the storage to be in the branch for security reasons and for collaboration reasons. SteelFusion sits in a branch office, it will run all the local applications on VMs. All the data will be sitting in your central data center and using SteelHead WAN optimization technology. That data will be transmitted to the branch at virtual LAN speed so you can work out of the branch at LAN speed with data that’s sitting in the data center. That’s the best application performance at the least cost with the most security.
If the branch goes down, no data is lost because it is always resident in the corporate data center. One of the big applications for this actually has been government networks. They have been a big customer of this product. I don’t know if you remember the movie Argo, where the embassy in Iran is overrun and they’re trying to shred and burn all the papers. With SteelFusion, if the embassy is overrun you simply unplug the box. All the data is back in Washington, D.C. It was never actually in Tehran. If you’ve ever tried to restore a failed server in a branch, it’s something that can take maybe at a minimum a week, sometimes several weeks. With SteelFusion, you simply fire up a new box and all the data is retransmitted from the data center and you have a 15-minute recovery, restore from a failed branch office server. This is unheard of in the marketplace.
What happens if the branch loses connectivity?
If the branch loses connectivity the box continues to work. It still has its dataset. There is a data lock that’s established when the data goes out to the branch so the data in the data center can’t be changed and when the connectivity comes back up the two boxes resync.
SteelFusion is described as hyperconverged infrastructure on your website. Do you see that as competing with the kinds of hyperconverged infrastructure we’re hearing about from other companies like Nutanix or SimpliVity?
It’s very different and the difference is the target market and the footprint. In fact, we sell cooperatively with both Nutanix and SimpliVity. Their products are targeted at large data center deployments. It’s big iron. Our product is a smaller, low-cost version that works in a branch office. Our price point and our target market are vastly different than what they do and we actually can work cooperatively with those people.
I also want to talk about SteelCentral because that plays such a critical role in managing all this and the visibility people have into these environments. That’s been around longer, but can you talk about the more recent developments with SteelCentral and what it’s able to do for customers now?
Most of our sales leads these days come originally from SteelCentral because what SteelCentral enables someone to do is the end-to-end management from the application. The line of code in the application server out to the network, out to the other side of the network, to the knowledge worker, to his device. You can see all the way across, find, diagnose and cure every issue in the network that may be causing slow application performance.
If you’re a CIO today the slogan is: Slow is the new down. We have this term called meantime innocence. Any network manager is constantly getting calls in his organization that the network is slow and of course he’s being blamed for it. With the SteelCentral technology he can see what the cause is. Often the cause has nothing to do with the network. It could be a server in the data center that’s spooling or any number of things that are very hard to identify, diagnose and cure.
SteelCentral has one of the most powerful sets of tools end-to-end to do that. It can diagnose and cure even before a problem is noticed by the end user. There are a lot of vendors in this space. They’re typically split between what’s known as NPM, network performance management and then APM, application performance management. Riverbed, with SteelCentral probably has the most comprehensive end-to-end suite of tools that do both the APM and the NPM part of the visibility control of networks. Everyone can use SteelHead but it’s not absolutely mandatory in every network. Every network needs visibility and control tools. Every network needs SteelCentral.
I mentioned earlier our acquisition of Aternity, which has end-user experience monitoring software where you put a little agent on the laptop or mobile device and it can tell the CIO the exact response time of every user connected to his application. They can get in and fix that response time before the complaints start coming in. A very popular product.
Do you see SteelCentral as a competitor to offerings like the New Relic product line?
Yes, it is. Our history has been more in the NPM business. We entered the APM business two years ago when we bought a company called OPNET. They had just started their APM business and we finished it so we’ve actually really only been in the APM business with a full-fledged product for about a year now. We think the one we have is very powerful. We call it AIX Application Intelligence and we’re marrying to it the Aternity product that does this end-user experience monitoring. The combination of the two will put us in a very strong position vis-a-vis New Relic and the other people in that space. The difference is that our technology tends to be the heavy-weight, industrial-strength technology used by the very largest networks in the world and some of these other products are more lightweight products used more in the SMB market. If you’re a Fortune 100, a big government network, or someone with thousands of sites, servers and users you’ll want the Riverbed SteelCentral offering.
Riverbed competitors and partners
You’ve got a very different product set than when you first came out and that puts you in competition with a lot of different kinds of companies. Who do you view as your core competitors these days?
Fundamentally, we sell networking technology and they’re the giant in networking. We’ve competed with them very well over the years based on superior products, which at the end of the day is what counts in technology. The interesting competition will be in 2017 when we are fully in the market with our SteelConnect routing product which will really be the first time we go head-to-head with Cisco in one of their main networking product areas. It should be a very exciting year for both of us.
+ PREVIOUS Q&A: Riverbed CEO: Cisco can have Layer 2 and 3 networking, we’ll take 4 through 7 +
How is the traditional WAN optimization market evolving and how are your products changing?
It turns out that that’s an eternal market because fundamentally it overcomes the problem of global latency, which is the laws of physics. The truth is, there really is no such thing as the virtual world. It’s a digital world. The digital world depends on electrons travelling the networks. Electrons are part of the physical world so everything that people think is the virtual world is really the physical world. Everything in the physical world is subject to the laws of physics and the speed of light limit. An electron is in a package traveling a network as part of the physical world and every trip in the physical world has two costs; a cost in time, which is the latency of the trip, and a cost in dollars, which is the cost you pay for the transport of the physical item.
A packet going from San Francisco to London, the cost in time is 200 ms and the cost in dollars is whatever you have to pay AT&T for your bandwidth. Those two things never change and it doesn’t matter whether you have cloud, you have hybrid or you have on-prem, that condition always exists. The core WAN optimization technology dramatically cuts both those costs. It does today and it will 100 years from now. It’s a permanent benefit to anyone doing global networking and it’s more important today than ever when people are doing heavyweight applications across global networks and when people are using more SaaS and more cloud data centers.
The net impact of cloud and SaaS is that for the average knowledge worker in a corporation, each year he’s farther away from the server that is delivering his application than he was the year before. We solved the problem of transport across physical geographic distance and the value is still there. We have almost 90% renewal rates on the SteelHeads every year because no one can imagine going back to when WWW meant world-wide wait.
I want to dig in a little bit on your work with the cloud providers. I know you have partnerships with Microsoft and Amazon. Maybe you could talk a little bit about that strategy and what you’re doing to help customers by working with the cloud providers themselves.
The cloud providers are basically channeled through us. You can go to Amazon and spin up a software version of SteelHead to run in the Amazon data center. That will connect to the SteelHead in your office and you can optimize all the work that you’re doing in Amazon. The same thing with Azure. They are basically channels to our customers. Our customers, whether they’re using SaaS or Amazon or AWS, their optimization depends on their purchase. It’s not dependent on either the SaaS provider or the cloud provider and it doesn’t require their permission or even their knowledge. Some of them are cooperative and help propagate that technology for their customer to get a better experience of their application running in those environments.




