Everyone talks about Prolexic's cloud scrubbing. But for a true hybrid on-prem deployment, you're still buying hardware. Akamai's appliance costs and licensing are opaque until you're deep in the deal.
NETSCOUT Arbor has been doing on-prem boxes forever. Their pricing is at least predictable.
My questions:
* What's the real TCO when you factor in the required cloud commit for Prolexic's hybrid model?
* How flexible is the traffic steering? I've heard the on-prem component becomes a dumb funnel if the cloud link drops.
* Who actually owns the threat intelligence data generated by your own traffic?
The sales sheets are identical. I want the contract and operational pitfalls.
read the fine print
I'm the principal architect for a fintech with about 350 people, handling a global hybrid stack where we run our own data centers plus AWS. We've had both Akamai Prolexic and NETSCOUT Arbor appliances in front of transactional workloads for about three years.
1. **Real TCO (Hardware, Cloud Commit, and Attrition)**
- **Arbor**: Predictable capex. A single SP 2k appliance was ~$150k upfront with a 3-year support bundle at 22%. Renewals are painful but clear. No forced cloud spend.
- **Prolexic**: You're not buying a box, you're buying a *commit*. The "Edge" appliances (rebadged hardware) are part of a term license. A 3-year hybrid deal for 20 Gbps mitigation started at ~$400k annually, and that's *mostly* for the cloud scrubbing you're forced to consume, even if your on-prem handles most attacks. Their finance team won't show you the hardware line item separately. It bleeds you.
2. **Traffic Steering and Link Dependency**
- **Arbor**: The box is autonomous. If WAN to cloud scrubbing center drops, it just does its best on-prem mitigation and logs. Traffic doesn't hairpin.
- **Prolexic**: Their "hybrid" steering is DNS-based with a health check. If the probe from their cloud to your on-prem appliance fails, they *can* reroute all your traffic to their cloud, turning your on-prem into a stale gateway. We saw this happen during a regional fiber cut and our traffic got an extra 80ms of latency for hours.
3. **Threat Intelligence Ownership**
- **Arbor**: Contractually, any fingerprints and attack signatures derived from your traffic are yours. You can export them.
- **Prolexic**: Their terms grant them a broad license to use anonymized data to improve their global threat feeds, which you then benefit from. It's a trade-off, not ownership. You can't take your data and run.
4. **Deployment and Operational Reality**
- **Arbor**: It's a router. You BGP peer, set thresholds, and tune. Took us two days from rack to filter. Support is classic enterprise: slow but deep, with an actual TAC.
- **Prolexic**: Requires their "orchestrator" and a tunnel to their cloud control plane just to configure the local box. Took a week of back-and-forth with their NOC to get the initial handshake done. If their cloud portal is down, you can't change local policies.
I'd pick Arbor for a deployment where 80% of attacks are handled on-prem and you just need cloud for the big floods. I'd only go Prolexic if you're all-in on Akamai's ecosystem (CDN, WAF) and want a single throat to choke, and your network can tolerate the steering quirks.
Tell me your average attack size and whether you already have an Akamai contract; that makes the call binary.
keep it simple