Bandwidth Aggregation Technology

With advanced bandwidth aggregation technology, you can combine multiple Internet links into a single high performance connection. Fixed and wireless lines operate together in real time, intelligently distributing traffic to maximize speed, stability, and uptime. This delivers higher throughput, improved resilience, and consistent performance for business critical applications, even when individual links fluctuate or fail.

Unified WAN Bonding & Optimization

Bandwidth aggregation and advanced WAN optimization are delivered using a comBOX network appliance connected to a regional comBOX network server through an active Virtual Leased Line subscription.

Placed between the customer’s LAN and the WAN connection modems/routers, the comBOX appliance functions as the secure internet gateway. It intelligently distributes packets across all available WAN links — including Starlink, Cellular (LTE/5G), Fiber, DSL, or Satellite — maximizing bandwidth efficiency and connection reliability.

The comBOX network server is a fully managed cloud endpoint hosted within our global private backbone. For every deployment, a dedicated virtual WAN bonding server is provisioned in the nearest data center to the customer. This server acts as the remote aggregation point, combining multiple WANs into one unified, high-performance connection.

Bandwidth Aggregation with comBOX Network Appliance

WAN Reliability & Failover

Smart (Transparent) same IP Failover

It enables the ability to survive WAN connections’ outages without a change in public IP addresses allowing for session continuity.

Low-cost public IP connections often suffer from many interruptions (downtime). As a result these connections are unusable for certain periods of time. In order to improve the availability of corporate WAN networks, the comBOX VLL technology uses the Smart Failover algorithm.  The algorithm reroutes sent and received data over the remaining WAN connections when part of these fail, isolating the faulty connections and ensuring that the end user does not notice any session interruption.

To achieve the maximum uptime, it is recommended to combine connections of different types and ISPs. The combination of wired and wireless WAN connections results in a hybrid WAN of unprecedented availability.

Flow-parallel Flow-parallel

Hardware failover cluster support

The hardware failover cluster functionality eliminates single points of failure and service downtime.

When the Internet connectivity is business critical, the customer has the option of utilizing dual, redundant comBOX network appliances. By configuring the appliances in a high availability cluster the backup hardware takes over in case the primary equipment fails. The redundant hardware can also be configured in a passive failover scenario which requires the user to switch the appliances manually. The latter scenario is preferred for deployments in extreme conditions for extended duration of the hardware’s life-cycle.
Shuffle Shuffle

Legacy session Load Balancing

The legacy session load balancing functionality offers the ability to distribute different sessions to the available WAN connections.

This feature is mainly utilized as a failover mechanism to maintain Internet access when the server infrastructure faces downtime. It is automatically enabled in case the comBOX network appliance gets disconnected from the comBOX network server maintaining the Internet access until the server connection is resumed. The session load balancing feature uses a round robin algorithm to distribute sessions to the available WAN connections. Additionally it supports sticky connections for compatibility with Internet services that track source IP addresses.
Share Share

Forward Error Correction

Real-time application traffic can be duplicated to guarantee no loss and optimal performance.

This feature normalizes the performance of real-time applications by transmitting data in redundant mode via multiple WAN paths.

The system selects the best two WAN connections in order to transmit two identical copies of the real-time data packets at the same time. Whichever packet gets through first, is the one to be delivered. This feature guarantees the smooth operation of real time protocols even when the available individual WAN connections face high packet loss and jitter.

Performance & Traffic Optimization

Packet loss & Latency management

The comBOX VLL technology incorporates a Performance Enhancing Proxy designed to improve TCP performance over  high latency and congested links.

By splitting the TCP sessions it enables an optimized TCP stack introducing cutting edge congestion control and loss recovery mechanisms. These mechanisms rely on link utilization metrics that are calculated in real time to ensure fast and uninterrupted data flows. This feature is a must have when individual WAN links face high packet loss or latency such as satellite connections.

The Transparent Performance Enhancing Proxy involves the breaking up of long end-to-end control loops to several smaller control loops by intercepting and relaying TCP connections within the network. By adopting this procedure, it allows for the TCP flows to have a shorter reaction time to packet losses which may occur within the WAN, thus guaranteeing a higher throughput.

End-to-end, bi-directional Quality of Service

The comBOX SD-WAN services offer reliable end-to-end QoS over multiple WAN connections in a simplified manner.

Many real-time or business critical applications need to be routed with high priority, in order to achieve constant speeds without interruptions. This is extremely important when there is simultaneous traffic of other types which exceeds the maximum WAN throughput. Priority setting as well as definition of the available bandwidth for each type of Internet traffic is undertaken by the Bandwidth Management (QoS) system, which manages the flow of data and allows for better performing real-time services (VoIP, Video-Conferences, Audio & Video Streaming, E-Learning platforms etc) and the control of the reserved bandwidth per application/device.

The Bandwidth Management system is able to support QoS classification via DSCP when the QoS classes are configured in a third party appliance (VPN server, Router, Firewall, UTM etc).

Rocket Rocket

Real-time data compression

The comBOX VLL technology enables real time data compression on the network layer to accelerate data transfers for uncompressed data.

Sent and received data is automatically compressed in real time to save bandwidth and further improve the WAN performance. The transmitted data can be reduced by 90% depending on the packets’ payload. This feature is extremely useful when it comes to broadband connections with traffic caps as it reduces the data transmitted, thus saving costs.

Progress-2 Progress-2

Jumbo Frames

The comBOX VLL technology uses Jumbo frames to achieve higher protocol efficiency.

With larger frame size, thus larger payload size, the comBOX VLL technology achieves less protocol overhead and the bandwidth saved is available for the packets’ payload. This feature also helps in the real time compression mechanism, as it enables greater degree of data compression saving even more bandwidth from the available WAN connections.

Popup Popup

Special Purpose Connection Legs

This technology feature allows specific WAN connections to be used by the bandwidth aggregation algorithm for specific types of traffic. As a result, the corporate network can take advantage of WAN connections with traffic caps for business critical applications.

This feature allows the configuration of sophisticated policies regarding the utilization of the available WAN connections. In fact, it allows each connection to be used by the bandwidth aggregation algorithm for specific QoS classes. This results in further increasing the available bandwidth or enabling additional WAN paths for redundancy.

Routing, Security & Management

Address Address icon

Policy Based Routing

 It allows the definition of rules in order to route specific types of traffic directly via specific WAN connections

The Policy Based Routing functionality provides an extremely powerful, simple, and flexible tool to implement advanced routing policies. In cases of legal or political constraints, the system can be configured to route specific traffic through local ISP connections.

Transparent routing

The comBOX network appliance offers the ability of transparent routing via the bridged mode functionality.

It enables the transparent operation of comBOX network appliance by forwarding the provided public IP addresses to the customer’s internal network. The public IP addresses can be configured on the WAN port of the customer’s edge Router or Firewall appliance. This feature allows the customer to maintain the available network infrastructure without altering the existing network configuration.

State of the art network security

Traffic Authentication at the Node Level

The CPE and the aggregation server authenticate each other using 4096-bit RSA keys and the TLS v1.2 protocol along with the TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 strong encryption cipher suite (256-bit AES encryption with SHA-384 message authentication and ephemeral ECDH key exchange signed with an RSA certificate). Keys are generated, managed and signed by a private PKI, avoiding the problems of trusting third party CAs, presenting a far smaller attack surface by eliminating the complex certificate chain validation risks commonly lInked with SSL security. All the above ensure no attacker can modify or forge bonded traffic between the CPE and aggregation server.

Furthermore, all network traffic between the CPE and the aggregation server can optionally be encrypted using the above algorithm/cipher suite to safeguard the user data transmitted between the comBOX VLL service endpoints.

Packet-Level Distribution Across Bonded Connections.

By its nature, the technology is highly secure. The packet-level distribution algorithm spreads traffic across multiple Internet connections. Even if an attacker manages to capture one of your individual Internet connections, only a small part of your entire traffic is visible. So, even though this is not a standardized security feature, it clearly provides a strong additional level of security.n server.

Seamless Integration with Existing Network Architecture

Your existing network security design will not be impacted. The technology supports all encrypted VPN traffic, and is also completely transparent to SSL traffic.

Remote Bonding Appliance (CPE) Security

Industry-standard SSL protects the appliance from unauthorized control. The CLI that could be accessed with SSH is equipped with protective functions by using access control lists. All services integrated in the router can be precisely configured in regards to how these services are accessible via which interfaces and IP networks.

Standard IP VPN encryption

The system has the ability to perform SSL IP VPN encryption for hub-and-spoke VPNs using 4096-bit RSA keys with SHA256 certificates, TLS v1.2, and Diffie-Hellman key exchange with elliptic curves.

Secure Operating System

Our service uses the popular open source Linux distribution CentOS. Many contributors around the world work to enhance the security of this operating system, from reviewing code to ensure security issues are eliminated before release, to implementing fixes within hours of a vulnerability becoming known. You benefit from their experience and abilities

Tools Tools

Centralized Service Management and Monitoring

The comBOX multi-WAN services can be managed remotely via the centralized management platform.

The centralized management platform allows our NOC and our service partners to monitor comBOX services and manage remotely the available CPEs through a simple to use interface. The centralized management platform offers the following functionality:

  1. Service Monitoring (Reporting and alerting of comBOX multi-WAN services deployment metrics)
  2. Remote CPE configuration management