In the past, we did not have a DDI system, so information was distributed in different places. As our environment became more complicated with on-campus, remote offices, and cloud setups, we wanted to integrate all the information together. We recognized the need for a DDI system.
BlueCat Address Manager for AWS
BlueCat Networks | cBAM7000 BlueCat Address Manager for AWS 9.6.1Linux/Unix, Debian bullseye - 64-bit Amazon Machine Image (AMI)
External reviews
External reviews are not included in the AWS star rating for the product.
Easy to use, simple licensing, and has a single pane of glass view
What is our primary use case?
How has it helped my organization?
BlueCat Integrity provides a single pane of glass view for the IP address space, which is important for general planning, design, and implementation. As the environments become more complex, it is very hard to grab information from different places.
It has helped us avoid overlapping information, which is a major benefit as previously we picked up information from different places. We have largely been using IPAM and DNS, although the DNS migration into BlueCat is still in progress.
BlueCat Integrity has helped reduce human error by 20% to 30%.
BlueCat Integrity might have had some effect on reducing downtime or improving network stability. It is hard to measure the effect. Both these aspects are operations-related. If we avoid any overlap in the design and planning phases, generally, it can lower operational risk.
What is most valuable?
It is easy to use. It has an understandable GUI interface. Its deployment is relatively easy. I would rate it a nine out of ten for ease of use.
The license model of BlueCat Integrity is easier to manage compared to Infoblox.
What needs improvement?
The solution is too granular and sometimes complex to configure. We do not always need so many details. Simpler configurations with fewer details would be beneficial.
The API aspect could be improved with more use cases and better handling of object attributes. It is already better than in previous versions. Their product team is planning further improvements in the upcoming version 9.6.
Last month, we had a roadmap meeting with the BlueCat product team. There will be a lot of improvements in version 9.6 coming in the second half of 2025. We will then upgrade our system to that one. It will have quite a lot of new features.
For how long have I used the solution?
We started testing it three to four years ago, and the system has been operational for around two to three years.
What do I think about the stability of the solution?
BlueCat Integrity is quite stable. I would rate it a nine out of ten for stability.
What do I think about the scalability of the solution?
I would rate the scalability of the solution a seven out of ten.
We have about 50 people working with this solution in the organization.
How are customer service and support?
Their technical support is good. The previous solution that we were using was open source.
BlueCat's technical support is a bit better than Infoblox's. They are quite responsive. They usually get back within one to two hours, or even faster for urgent issues. I would rate them a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used phpIPAM for some programs, but for others, we only had Excel sheets, which were not ideal.
phpIPAM is an open-source product, but it only functions as a pure IPAM without integration with DNS or DHCP. It was more of a documentation tool. We also tested NetBox for a while but did not use it in production.
How was the initial setup?
We have a hybrid deployment model. The implementation was done over a period of six to eight months involving four to five people. It was neither too simple nor too complex.
In terms of maintenance, it requires upgrades every two to three months. The upgrades can be done in a few hours, but, normally, we schedule it across a week. We upgrade some of the things first and then upgrade the rest.
What about the implementation team?
The implementation involved four to five people.
What was our ROI?
It has helped save time, money, and resources by 20% to 30%. As we are migrating other tools into this one, there can be 30% to 40% cost savings.
What's my experience with pricing, setup cost, and licensing?
Our licensing model with BlueCat Integrity is cheaper than Infoblox.
Which other solutions did I evaluate?
We did a brief comparison of Infoblox and BlueCat.
What other advice do I have?
I would recommend BlueCat Integrity to others. It is quite easy to use. The product's performance is stable, and support is good.
The general documentation is also good. The API part can be improved a little bit. Overall, it is a good solution.
I would rate BlueCat Integrity a nine out of ten.
Decentralized management empowers comprehensive visibility across IP operations
What is our primary use case?
We have been a partner of BlueCat for two years now, and we are responsible for deploying the solution over the Middle East region. I have the most experience with BlueCat Integrity.
How has it helped my organization?
BlueCat Integrity is generally easy to use and administer, though the ease of use can vary depending on the user's experience level. Migration can be complex for beginners or those new to IT, but daily operation is straightforward.
BlueCat Integrity provides a single interface for managing IP address space, DNS, and DHCP within one console. Many organizations have separate consoles or teams for these functions, leading to unused IP space and a lack of awareness regarding its allocation. If team members leave, knowledge of this IP space is lost, resulting in wasted resources and inefficient management, especially when viewed from a cross-team perspective.
It provides immediate benefits by allowing us to easily migrate our existing files to its software. The software then automatically identifies any missing or misconfigured elements in our network environment, providing a comprehensive overview and improving overall efficiency.
The primary migration tool helps reduce human error by automating the transfer of existing network configurations into the BlueCat system. This tool simplifies the migration process and verifies configurations against industry best practices, highlighting potential issues. While BlueCat offers recommendations, it ultimately allows users to make informed decisions and retain specific configurations necessary for their unique environment, such as those required for certain products to function correctly.
BlueCat consolidates disparate network management tools. Organizations often rely on default Microsoft DNS and DHCP servers, which are separate tools within Active Directory, and manage IP addresses through the DHCP server. This results in three separate components with different consoles and configurations. BlueCat streamlines this by integrating all these functions into a single, unified platform.
It has helped organizations by providing automation features that can handle specific IT tasks, freeing up IT staff for other projects.
BlueCat reduces the total cost of ownership by automating tasks, which allows IT staff to focus on other projects instead of managing DNS and DHCP tools. Additionally, BlueCat consolidates functionalities into a single server, decreasing infrastructure costs associated with separate solutions and consoles. This automation and consolidation significantly reduce IT costs.
Once correctly configured and deployed, it offers significant relief through its automation capabilities. This automation enables features like automatic failover to redundant DNS or DHCP servers, eliminating concerns about server failures and ensuring service continuity. IP address management can also be automated based on device and location, further streamlining network administration. With proper configuration, BlueCat Integrity minimizes the need for ongoing manual intervention and reduces the administrative burden on network administrators.
What is most valuable?
The most valuable feature of BlueCat Integrity is decentralized management, which enables real-time visibility and control over the entire IP address space, DNS, and DHCP from a single console. This feature is crucial for organizations.
What needs improvement?
The user interface could be improved, as the implementation of BlueCat can be complicated and requires personnel with expertise in DNS, DHCP, and IP management.
For how long have I used the solution?
We have been a partner of BlueCat for two years.
What do I think about the stability of the solution?
BlueCat is a well-known, stable solution in the community, with an architecture designed for reliability. The appliance itself provides a clustered environment, so even if one service fails, there's no need for manual configuration or worry. This built-in redundancy minimizes service disruptions, ensuring your network runs smoothly at all times.
What do I think about the scalability of the solution?
BlueCat Integrity's scalability depends on the type of appliance used, so we typically communicate with the customer to determine their IP address and DNS server needs. Virtual appliances offer inherent scalability by simply adding resources for smooth software operation, with performance contingent on the provided hardware specifications.
How are customer service and support?
BlueCat's customer support, particularly its solutions team, has been excellent. While I've collaborated extensively with its partner team, including solution architects, I haven't needed to contact its general technical support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have seen customers using Infoblox and Microsoft IPAM, and we have migrated these customers to BlueCat. BlueCat is better because it provides a unique blend of features and flexibility.
How was the initial setup?
Implementing BlueCat Integrity itself is straightforward, but migrating data from older configurations and consolidating solutions can be complex for those who aren't seasoned professionals.
The deployment of the solution itself takes about two or three hours. Migration depends on the size of the IP address management and can take nearly 24 hours.
The number of people required for deployment depends on their experience with the BlueCat solution. As an implementation service provider, we could deploy with two people at most. While the interface may seem complex to those unfamiliar with it, customers should also be able to deploy with two to three people: one with IP knowledge, one with DNS expertise, and one with DHCP experience. Ultimately, the most crucial requirement is someone who thoroughly understands the environment where the solution will be deployed.
What about the implementation team?
I handle professional services as a partner, providing integration and migration support to customers in the Middle East. It typically requires two people to implement the solution.
What was our ROI?
BlueCat helps reduce IT cost because it automates many tasks. This automation frees up staff for other projects and consolidates several solutions onto a single server, reducing infrastructure costs.
What other advice do I have?
I would rate BlueCat Integrity nine out of ten. The only negative is the complexity that can occur around migrations.
BlueCat is not typically used to directly prevent downtime. While its DNS functionality helps resolve domain names, this depends entirely on how it's configured within your organization or solution. BlueCat doesn't actively support downtime prevention. Although it aids in the handover process between multiple DNS or DHCP servers, it offers no active functionality to prevent downtime for a single DNS server.
Upgrading BlueCat Integrity requires some downtime, regardless of whether it's a physical or virtual appliance. The process involves setting up the new appliance and migrating the configuration from the old appliance. While virtual appliance migration typically takes under an hour, physical appliance upgrades require additional time for installation and initial setup. The configuration transfer is relatively quick, simply importing and exporting existing settings.
If someone believes they don't need a full DDI solution, I recommend they first verify their IP address management is accurate and all allocated addresses are being utilized effectively. They should also confirm their DNS is functioning correctly and that critical services are operating as expected. There's a high chance of misconfigurations or outdated settings that could lead to downtime or security vulnerabilities. This is where a dedicated DDI solution can provide comprehensive management and prevent potential issues.
New users should understand their organization's IP structure and DNS configurations before implementing BlueCat for a smooth experience. It is important to be familiar with DDI technologies.
Which deployment model are you using for this solution?
User-friendly interface, exceptional support, and enables a lot of time savings
What is our primary use case?
I use BlueCat Integrity for end-to-end DDI management, which includes DNS, DHCP, and IP management. It helps in creating domains, records, and networks. It serves IPs to specific hosts, simplifying life as a DDI engineer.
How has it helped my organization?
The overall benefit of using BlueCat Integrity is that it allows access to servers and troubleshooting of servers, which is not offered by some of the other market products. When you use BlueCat Integrity, you learn more than VDI. You get hands-on experience with Linux. You get to learn more things when you are using BlueCat Integrity. They also offer exceptional customer service.
BlueCat Integrity provides a single-pane-of-glass view of our IP address space. Within this single pane of glass, we can also have multiple views. I can create multiple subblocks and configure them, for example, country-wise.
It drastically reduces human error, reducing it by 80% to 85%.
BlueCat has helped our organization reduce downtime. We can monitor the online status of services with the help of SNMP. We can use all three SNMP variables, such as SNMPv1, SNMPv2, and SNMPv3. With the help of that, we can monitor server health.
It has helped save a huge amount of time in the domain and record creation process. It saves about 90% of our time.
BlueCat Integrity has relieved engineers from manual tasks, freeing up time for other projects. It relieves engineers in a huge way. It relieves the DDI engineers from touching the Linux bind servers or DB servers. Using BlueCat Integrity saves a huge amount of time. With that time, we can handle other projects.
I use REST APIs. I create scripts, and we have our gateway, so we create our own gateway workflows. We use BlueCat automation to create around four to five thousand objects. It saves about two minutes per object.
What is most valuable?
The most valuable aspect is its user-friendly interface. It is straightforward to use. Even individuals with minimal DNS knowledge can easily work with BlueCat GUI.
It offers multiple additional services, such as Edge, K3, etc. We can integrate it with multiple applications and achieve more things. For example, we can use REST API with the help of GUI and achieve REST API construction in a single place. We can give it to multiple users to use it.
What needs improvement?
Some areas need improvement, especially the issue with stale entries in the BlueCat tenancy. I have heard that it is already fixed in BlueCat Integrity 10. I have not used that yet.
Additionally, they can integrate DIG into BlueCat Integrity.
For how long have I used the solution?
I have been working with BlueCat Integrity for the past five to six years. I was also a BlueCat TAC engineer for about two years.
What do I think about the stability of the solution?
The stability of BlueCat is sometimes problematic. Every two months, something breaks, and if not resolved immediately, it leads to downtime for several hours. In some situations, we get no answer from BlueCat because we cannot replicate the issue, but it still affects the organization. Recently, because of that, BlueCat Integrity was not available for anyone for at least two and a half hours. I would rate it a five out of ten for stability.
What do I think about the scalability of the solution?
BlueCat is scalable, but it needs to be more robust. As an enterprise product, BlueCat needs to listen to customer feedback and make improvements where necessary.
We have more than 1,000 users in our organization. They are at multiple locations around the globe.
How are customer service and support?
The technical support by BlueCat is excellent. I would rate their support a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have worked with multiple vendors like VitalQIP and Infoblox in different organizations.
BlueCat is more straightforward than others. If you know DNS, you can work with BlueCat GUI very easily. Other vendors are difficult to work with for someone new, whereas with BlueCat Integrity, within 30 to 40 minutes, you can do basic things. It is more user-friendly. BlueCat's GUI interface and customer support set them apart from others. It does not require a lot of DDI knowledge.
Infoblox is a more robust product. BlueCat needs to reach that level. I worked with Infoblox for nearly a year, and I did not have to contact their TAC, whereas I have to contact BlueCat TAC every one or two months with a high priority.
How was the initial setup?
I was not involved in its deployment. If you know DDI, you can easily work with BlueCat Integrity.
The maintenance part is hard, but that is not because of BlueCat; that is because of technology. DNS has many vulnerabilities. We have to patch or upgrade the server every three to six months. We cannot avoid that.
What other advice do I have?
I would recommend a DDI solution like BlueCat Integrity if you have more than 100 users at multiple locations.
BlueCat provides plugins for various applications, such as ServiceNow and Cisco Umbrella. They have plugins for many applications, but we do not use these plugins. BlueCat Integrity is a very easy tool. If you know what you are doing, you can do it in a minute.
I would rate BlueCat Integrity an eight out of ten.
Which deployment model are you using for this solution?
We witnessed the benefits almost immediately
What is our primary use case?
We use BlueCat appliances and the Integrity platform for our DHCP environment. That's on the internal side. All of our DHCP for hospitals throughout the country are managed by BlueCat. The external DNS, also. We're authoritative for all of our own DNS zones. So we use BlueCat on the outside for public, DNS.
How has it helped my organization?
Better uptime than Windows due to patching. Single Pane of glass for managing enterprise wide DHCP.
What is most valuable?
The most valuable aspect of the solution would be separation from the Windows operating system. Prior to our BlueCat usage, we were doing Windows DHCP and Windows DNS on the outside. Not being dependent on the Windows operating system, which routinely needs patching, reboots, et cetera, is great. Our BlueCat environment is now free of any of those vulnerabilities of Microsoft.
Integrity is largely easy to use. It depends on whether you're coming from a Windows, Linux, or Unix background. If you have a background with Unix-based DHCP or name services, it's a little easier to adopt. Coming from a Windows background, where you traditionally use Windows for either of these functions, it's not hard. However, it's easier if you already have Linux or Unix experience.
We witnessed the benefits of Integrity almost immediately. Since we had to reboot our Windows servers every month for patching, and with the new updates coming out for the Windows environment on a monthly basis - it was challenging. After switching to BlueCat, we don't have to reboot just for the patch. We can deploy. And since we run a high availability platform we can take one node down and still keep services alive without production impacts.
Integrity provides very close to a single pane of glass view of our IP address space. It would be more so if we were more prudent. It has the potential. A single pane of glass is a buzzword. It's very common. Everybody's looking for that. It would be nice if we were diligent and disciplined enough to record everything in our BlueCat environment. However, we don’t.
Integrity helps reduce human error, more or less.
Integrity helped us to reduce downtime. Given that, in a Windows environment, if we are following our best practice of patching on a monthly basis, that's about an hour or a month. We used to have a few hours a month per device or a couple of hours a month per device. Now we just don't have any downtime. We've reduced our downtime by 100%.
Integrity helped consolidate tools in that we now have a much better configuration standard. It is BlueCat. It's all BlueCat. No more Windows, Linux, DHCP servers, aside from Bluecat BDDS. So, the configuration standard is being met and achieved every time, whereas there was always an opportunity to not maintain a standard when we were doing individual configurations.
BlueCat helped us free up IT staff for other projects to some extent. Not a substantial amount - and not really a measurable amount. We do have two primary engineers who operate this environment, and their workloads have certainly gotten better to where they can spend time doing other things.
Integrity helped us to improve the network stability due to a lack of downtime. If we're not having downtime when we're rebooting a Windows DHCP server, that means the clients continue to operate as they're expected without downtime failures.
BlueCat saved us money in terms of a life-and-death scenarios and the stress factors that surround a healthcare environment. We generally don't have downtime in our DHCP environments anymore. The clinics and the hospitals can continue to operate and not be in that position to be down. DHCP is a core NECESSARY service that you don't miss till it's not working. And sometimes, that does mean that there are lives on the line. So from a medical hospital health care stance, absolutely saves us. I don't know if you can put a price on life, however, for our use case, it's pretty significant for us.
What needs improvement?
We're still reviewing our architecture and design. We are having some challenges when it's integrated into our VMware environment. We've fixed a lot of those issues. That said, we're still going through an architectural review to make sure that our high-availability design is going to be okay. High availability is an area of weakness. In terms of questions such as what does it take to produce high availability, and what is the configuration standard that must be met to maintain the high availability, we've had some challenges there.
There are multiple ways you can achieve high availability. We're using one that they call xHA, a crossover high-availability heart beat network. xHA was not designed for a virtual environment, yet we are using it in a virtual environment. So we're trying to figure out ways to make that better.
Challenges with xHA in a Virtual Environment, when you have multiple BDDS on the same physical host, you can run into oddities and service stoppage.
UPDATE: After extensive exploration and meeting with both Bluecat Architectural groups and within our own architectural groups, we've identified that our usage of xHA for Virtual environments is not a recommended method. We'll be correcting that over the next 6-12 months and moving to an Active/Active solution via Bluecat. If you're using Physical Appliances, consider xHA. But in Virtual environments, use Active/Active.
For how long have I used the solution?
I've been using the solution for about four years.
What do I think about the stability of the solution?
Aside from some challenges, mostly due to virtualization, it is a very stable environment.
What do I think about the scalability of the solution?
We're running over 300 devices, and our scale is rather large. We're shrinking our platform in terms of how many of these devices we have out there. Scalability, I would presume, is just fine. We scaled out right away in a fairly large enterprise, and it did very nicely.
How are customer service and support?
I contact support maybe once a month.
They are amazing. Just recently, I was able to upgrade our support contract as we found that the basic offering of support included with licensing was not adequate for our needs. Since we have gone to their premier level of support, we're having monthly cadence meetings. They're continually doing health assessments and checks, and we're getting ready to do a whole new architectural review. Support has been very nice, not that we've gotten to their premier tier. Prior to that, it was hit or miss.
Our support here through BlueCat, due to the nature of our support contract, is very personalized. We have a dedicated team who understands our environment and our needs, and it's not a reinvention. We don't have to train guys each time we contact them. In contrast, with Microsoft, you get the luck of the draw. You might get a very knowledgeable engineer in the beginning. None of them are ever familiar with your environment, so they won't know the ins and outs. So with the custom team or dedicated team that is just responsible for our environment, these guys are very good. Microsoft doesn't really offer that.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to running BlueCat, we ran Windows, Microsoft DHCP, and Microsoft DNS.
With BueCat, you get much more of a single pane of glass. You get a true high availability, and you get to divorce the primary services of DNS and DHCP from Windows so that you don't have to worry about patch management of Windows devices. You're not dependent on Microsoft anymore. And the high uptime seems to be much better for us.
How was the initial setup?
The deployment, for a large enterprise can be challenging. We definitely took our time over the course of two years to cycle through and deploy BlueCat. It was just more schedule coordination.
For 150+ hospitals, it took us almost two years to deploy. We had two engineers working on the deployment process, both of whom are no longer with the organization.
What about the implementation team?
The bad part is that, at the time, the purchasing decision was made to implement BlueCat on our own without the assistance of BlueCat Professional Services. I can't really speak to their professional implementation services. We did it on our own.
What was our ROI?
By way of uptime, we have reduced our total cost of ownership.
The peace of mind that BlueCat Integrity provides is much better. Especially on the uptime and being challenged with how to balance downtime for patching requirements versus just continual operations. From that perspective, BlueCat is is not quite set and forget, however, it is very close to set and forget.
What's my experience with pricing, setup cost, and licensing?
Everybody wishes everything was cheaper, of course. However, for our enterprise our contract is under half a million dollars a year, so that's pretty good for the size of the organization. Their pricing is reasonable.
Which other solutions did I evaluate?
We did not really look at other options previous to this solution.
What other advice do I have?
To those individuals at an organization who don't think that they need a full-stack integrated DDI management solution, I'd say the biggest selling point is availability and uptime. If you have to patch a Windows operating system, which is probably the largest competing product to BlueCat in the typical enterprise, if you have to worry about Windows patching, all those problems disappear.
I'd rate the solution nine out of ten.
I'd advise new users to get professional services engaged as quickly as they can. Don't try to manage it individually very complex organizations, and don't try to just learn it overnight. Spend a little bit of money and engage with professional services to get them to help you through your migration path.
Which deployment model are you using for this solution?
Helps reduce downtime, saves us time, and is user-friendly
What is our primary use case?
Our company provides network infrastructure management services for ten clients. We handle DNS, DHCP, and IPAM for these clients, all utilizing the BlueCat Integrity platform.
How has it helped my organization?
The most effective features for IP management are log reviews and configuration management.
BlueCat Integrity is easy to use but it can be time-consuming. It has improved our troubleshooting. We can go to the server and see the logs.
BlueCat Integrity has helped reduce downtime andhas saved 50 percent of our time.
It has streamlined our IT team's workflow, freeing up valuable time for other projects. The intuitive user interface simplifies the process of provisioning IP addresses to customers.
We recommend the BlueCat automation to our customers because it saves almost 50 percent of our time. Through the self-service portal, our customers can complete their requests themselves.
BlueCat Integrity helped improve network stability.
The professional DNS and support service helps integrate BlueCat Integrity.
What is most valuable?
The most valuable features of BlueCat Integrity are the user-friendly UI and the permission management.
What needs improvement?
A common complaint about BlueCat is that adding new features or making even small changes requires a full deployment process, which can be time-consuming. This is especially problematic for deployments using SSP (hidden primary), the business-critical DNS server, which can take up to seven minutes to deploy depending on network size.
Unfortunately, BlueCat Integrity doesn't support bulk Content Security Policy configuration. We'll need to set these policies manually for each element or develop a script to automate the process.
For how long have I used the solution?
I have been using BlueCat Integrity for two and a half years.
What do I think about the stability of the solution?
I would rate the stability of BlueCat Integrity eight out of ten. At times we get high utilization on some servers.
What do I think about the scalability of the solution?
I would rate the scalability of BlueCat Integrity ten out of ten.
How are customer service and support?
The technical support is responsive and they have resolved any issues we have had.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously implemented Infoblox and it remains in use, but we've also added BlueCat Integrity to our network management toolset. We prefer the integration and automation in BlueCat.
How was the initial setup?
While BlueCat Integrity is easy to deploy, the overall deployment time varies based on network complexity. New customers can be up and running in two weeks, but migrating existing configurations from Infoblox to BlueCat Integrity can take up to three months. This is because the migration involves a staged approach, transitioning DNS settings first, then DHCP, and finally finalizing DNS changes.
What's my experience with pricing, setup cost, and licensing?
BlueCat Integrity is more cost-effective than Infoblox.
What other advice do I have?
I would rate BlueCat Integrity eight out of ten.
The majority of our clients who use BlueCat Integrity are enterprise customers.
Once BlueCat Integrity is deployed there is no maintenance required.
We did not face any challenges when integrating BlueCat Integrity into our client's systems.
Even for organizations hesitant about needing a full-suite DDI management solution, BlueCat Integrity's time-saving features and cost-effectiveness make it a compelling choice. I recommend BlueCat Integrity to others.
Which deployment model are you using for this solution?
Improves our operational efficiency, reduces downtime, and provides peace of mind
What is our primary use case?
BlueCat Integrityk is our central DDI System used for DNS, DHCP, and IPAM.
Our BlueCat address managers are deployed on-premises in a clustered configuration. All the servers are physical machines located on-premises, except for one virtual server running in the Azure cloud. This external DNS server is specifically maintained to support our remote clients.
How has it helped my organization?
The key advantage of BlueCat Integrity is its adherence to open standards, allowing for integration with external tools. While I find Integrity's built-in bulk update functionality lacking, I can leverage open-source ISC tools and the standard NS update protocol for a smoother update experience. This gives me far better results.
I recognize that companies try to sell extra features and products. One of BlueCat's main competitors, Infoblox, heavily advertises and pushes its additional security features. However, my priority is a product that excels at DDI, which I believe BlueCat does well. While I welcome improvements, it currently performs its core function effectively, and I don't want additional features to compromise its security. I simply want it to do its job well, which it demonstrably does.
BlueCat Integrity effectively manages our IP address space with a centralized view, similar to how many companies encounter, we have a few exceptional cases where we've lost control of entire blocks or ranges. While this creates discrepancies, it's not a fault of BlueCat's but rather a result of these specific edge cases within our organization. Overall, BlueCat Integrity performs well. Having a single pane of glass view is important in an IPAM system.
BlueCat Integrity significantly improves our operational efficiency by automating IP address management. Manually tracking all our IPs would be a cumbersome and error-prone task, which Integrity effectively eliminates.
Last June, upon joining the organization, I began using BlueCat Integrity and found it to be a valuable tool. It has facilitated the smooth migration of various departments, similar to integrating external companies, and effectively addresses our general needs.
While DHCP redundancy has demonstrably reduced downtime, the existing DNS redundancy seems sufficient. There was a proposal for a redundant primary DNS server, but it appears to deviate from standard protocols and therefore won't be implemented.
BlueCat Integrity has streamlined the process of integrating external solutions, making it easier to incorporate products from other companies into our systems.
I am happy with the peace of mind BlueCat Integrity provides. I am not up at night worrying about anything related to BlueCat.
What is most valuable?
The most significant advantage of BlueCat is its foundation on open-source software, specifically BIND and ISC DHCP. Notably, BlueCat avoids any modifications to these underlying products, instead building its IPAM and DDI systems on top of them.
What needs improvement?
BlueCat is releasing a completely new interface next January. While it doesn't currently have all the minor features I want, hopefully, they'll be added over time.
While knowledge is a factor, both technical support and training need a significant overhaul. The root cause lies in the BlueCat support's attitude, which seems focused on closing tickets quickly rather than ensuring solutions. This means genuine attempts to improve functionality, even if not strictly broken, are met with workarounds and closed tickets. This focus on expediency hinders true problem-solving and a positive user experience.
Unfortunately, due to development timelines, new features won't be considered until the release of the next version of BlueCat Integrity, expected in January of next year. Any interface improvements or requests specific to the older system are a waste of time. This will ensure our requests are well-positioned for implementation in the upcoming release.
For how long have I used the solution?
I have been using BlueCat Integrity for eleven months.
What do I think about the stability of the solution?
BlueCat Integrity has been stable. I would rate the stability ten out of ten.
What do I think about the scalability of the solution?
BlueCat Integrity supports our network scalability and response to changing demands. I would rate the scalability seven out of ten.
How are customer service and support?
While the advanced support team has some excellent individuals who offer valuable design changes and assistance, the quality of day-to-day technical support is unfortunately lacking.
Compared to other solutions, BlueCat's technical support is poor.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
While the majority of our organization uses the industry-leading IPAM solution, BlueCat Integrity, there are a few pockets still utilizing Infoblox. Additionally, Active Directory continues to influence IP address management in some areas, requiring integration with the DDI system.
If we're considering replacing BlueCat Integrity, there are two main drawbacks to consider. First, unlike Infoblox, BlueCat directly interacts with existing DNS, DHCP implementations BIND and ISC DHCP, allowing for more granular control. Second, Infoblox creates a management layer that separates us from core functionalities like DHCP leases and zone files. This lack of direct access makes troubleshooting and advanced configuration difficult with Infoblox, which is a major advantage of BlueCat Integrity.
How was the initial setup?
While the initial setup of the entire system was easy, deploying the BlueCat software that manages the underlying services, ISE, DHCP, and Bind proved more complex. This complexity stems from legitimate reasons, but it can be challenging. For instance, setting up failover redundancy within BlueCat was more intricate than on our previous DHCP server, requiring additional learning on my part. These additional steps, though not impacting the core system's functionality, do add some complexity to the deployment process.
What other advice do I have?
I would rate BlueCat Integrity eight out of ten. BlueCat Integrity excels at its core functionality of managing DNS, DHCP, and IP addresses. Unlike some competitors who prioritize security features in their marketing even though they're DDI solutions, BlueCat should stay focused on what they do best: providing a robust DDI platform. While expanding into other areas is understandable because they want to increase profits, it's crucial not to lose sight of their core strength and risk compromising the user experience.
We operate four geographically separate data centers across two locations in Switzerland. These house two BAM servers, 34 production BDDS DNS DHCP servers of which one is virtual, and a small, entirely virtualized lab environment.
Two administrators manage the DDI system with full access, handling everything from BlueCat to DNS and DHCP. We focus on complex tasks and leave routine record updates to end users or a dedicated layer two team at the network operation center that handles tickets and other tasks. There's also a first-level support team, but their exact involvement in DDI maintenance is unclear.
While BlueCat excels as a DDI solution for managing DNS security, its attempts to expand into other areas like full device discovery are unnecessary for our needs. 30 specialized tools can handle those tasks more effectively. We prefer to keep BlueCat focused on its core strength: DNS security within our network.
I recommend BlueCat Integrity for DDI needs. Unlike QIP and Infoblox, Integrity adheres to open standards without modifying them, and leverages the most popular open-source implementations available, ensuring compatibility and avoiding potential issues arising from custom code.
We are fortunate to have two incredible individuals from BlueCat who provide exceptional support and guidance. Their expertise and willingness to help are truly invaluable.
Which deployment model are you using for this solution?
With its centralized console, we save time and money
What is our primary use case?
Our DDI environment is managed by BlueCat Integrity, a unified platform for our DNS, DHCP, and IP address management.
How has it helped my organization?
The user interface is intuitive and easy to learn. New users can navigate it confidently without confusion. Our international teams in France, India, and the US have all successfully managed the IPAM system with the UI, demonstrating its clear design. This reinforces the idea that a well-designed interface can make even complex technology accessible.
They offer a consolidated view, like a single pane of glass, of our entire IP address space. This comprehensive view is incredibly valuable. The vast amount of information is presented in a user-friendly way, similar to a database. BlueCat intelligently organizes this data, including the ERTs, for efficient exploration. A convenient dashboard provides a central location to access all this information.
It delivered immediate benefits. It offered a high degree of control, comprehensive information for log monitoring, and more. Compared to a Windows system, it streamlined log analysis with its exceptional logging capabilities. Overall, it's an excellent solution.
BlueCat Integrity helps reduce human error by automating tasks and improving data integrity. For example, its DNS features can check for typos and other configuration errors, ensuring accurate data is used. Additionally, Integrity's infrastructure creation and data organization tools promote consistency and reduce the potential for mistakes caused by manual processes.
It minimizes downtime by offering various high-availability features. One such feature is called XHA, which ensures service continuity even if individual machines or appliances experience issues. This allows services to remain online during maintenance updates, for example. Additionally, BlueCat Edge leverages Anycast technology to provide further redundancy for Integrity's DNS services.
Previously, BlueCat's reach was limited to North America. We've expanded our footprint globally. This involved decommissioning many legacy servers worldwide, particularly Windows-based ones like DNS and DHCP servers, as well as some digital services on firewalls and routers. This shift to BlueCat grants us greater control and allows for a more standardized configuration across our global network. It also facilitates easier deployment and enforcement of network-wide standards.
Our organization heavily utilizes BlueCat Integrity's API for automation and data integrity monitoring. It effectively provides all the information necessary for our current automation needs, making it a valuable tool.
BlueCat Integrity has significantly improved our IT staff's efficiency. A centralized console streamline updates, while global configuration deployment further reduces time spent on management tasks. Overall, BlueCat Integrity offers a wide range of time-saving functionalities that benefit our environment.
While we haven't encountered any server issues, a key strength lies in our well-architected DDI infrastructure. For instance, our DHCP redundancy server resides in a separate location, ensuring failover if the primary site experiences problems. Similarly, with geographically dispersed DNS servers in India and Australia, redundancy is built-in. BlueCat Integrity's robustness further enhances network stability. Since implementing it, we haven't experienced service outages or reboots. The product's maturity is evident, but our monitoring practices also play a crucial role.
The time saved by using BlueCat Integrity translates directly to cost savings.
BlueCat Integrity helps us reduce our TCO.
BlueCat Integrity has been a game-changer. It frees up my time to focus on other projects that improve our network environment, research new technologies, and more. This robust and mature product has given me peace of mind. Since joining this team and using BlueCat, I haven't lost a single night's sleep worrying about DNS, DHCP, or IP Address Management. It simply works reliably in the background, just as it should.
What is most valuable?
BlueCat Integrity has proven to be a robust solution. We haven't encountered any problems with it, and it is reliable.
BlueCat's ability to deliver secure updates quickly is crucial for us. When it comes to DNS security, timely updates and patches are essential. Fortunately, BlueCat excels in this area, providing the peace of mind we need.
I've been impressed by BlueCat's performance and user-friendly GUI. The API allows for easy data collection, particularly for automation purposes. While external monitoring tools are available, BlueCat's built-in monitoring provides an additional layer of convenience and trust.
What needs improvement?
BlueCat Integrity could benefit from several improvements. First, faster log processing would be beneficial. Ideally, the system would adopt a similar approach to BlueCat Edge for improved efficiency. Second, the IPAM dashboard could be enhanced to display more information and provide data analysis features. This could include visualizations, log analysis, and improved reporting with insights and metrics. Similar to BlueCat Edge, reports should be presented in a modern way that leverages more data for analysis. Ultimately, the goal is to visualize logs and gain insights directly within reports.
For how long have I used the solution?
I have been using BlueCat Integrity for ten years.
What do I think about the stability of the solution?
A mature solution, BlueCat Integrity has consistently demonstrated stability within our infrastructure, never exhibiting any issues.
What do I think about the scalability of the solution?
While we rely heavily on the network, there may be times when perfect network balance isn't achievable. The impact of this depends on our specific actions. Thankfully, BlueCat Integrity is a lightweight service, making it easy to scale our work. Additionally, our infrastructure has ample resources, allowing us to easily add more if needed, solidifying this solution's scalability.
How are customer service and support?
We truly value the professional support offered by BlueCat. While it is a paid service, their expertise is excellent, and we rely heavily on their assistance. They are the vendor with whom I have the best working relationship.
The technical support is quick to respond and knowledgeable.
How would you rate customer service and support?
Positive
How was the initial setup?
The deployment is straightforward. The most important part is to figure out all the clients and the networks that are going to rely on the infrastructure.
One person can handle the deployment as long as they are familiar with the solution.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
BlueCat Integrity's pricing is reasonable within the market.
What other advice do I have?
I would rate BlueCat Integrity ten out of ten. We heavily rely on BlueCat Integrity, and it's been very dependable. When we demonstrate our network management to other teams, they're impressed by the level of control we have. There's very little to complain about – it's a well-architected and implemented solution. The built-in redundancy and global distribution are particularly helpful, contributing significantly to its overall effectiveness.
Apart from system updates, no maintenance is required for BlueCat Integrity.
For those who say they don't need a full-stack integrated DDI management solution, I simply offer good luck. Dedicated DDI solutions provide far greater visibility compared to less mature options. This is crucial – without it, we'd be flying blind. Security is paramount for our company as well. A reliable vendor should quickly release patches for any Common Criteria Evaluation issues affecting our DNS, DHCP, and IT infrastructure. This allows us to swiftly update our security team and maintain a proactive stance. Remember, while DNS, DHCP, and IPAM aren't complex products, they are critically important. A single vulnerability can cripple the entire company. A proper response and vendor support during high-impact situations are essential. While the need for a solution like BlueCat Integrity scales with company size, even smaller organizations benefit from the peace of mind and efficiency it offers. Frankly, having experienced the advantages of DDI solutions, I wouldn't dream of working without one today.
For a smooth experience with BlueCat Integrity, prioritize initializing your IPAM component. Updating BlueCat with all your IP addresses upfront helps prevent future management challenges. Since IPAM can be complex, leverage automation as much as possible to automatically collect IP address information. Additionally, security is paramount when dealing with DNS, so always prioritize security best practices.
Which deployment model are you using for this solution?
It improves our security by providing a single source of IP address usage and contact information
What is our primary use case?
We use Integrity for DNS, DHCP, and IP address management. It provides a means to track our public and internal IP space and to find information about network utilization. Integrity is the sole DNS for the entire company. We have two on-prem data centers and servers on two cloud providers that all use the BlueCat DNS. The company has about 150 remote offices throughout the US, and they all use the centralized BlueCat DNS and DHCP services. There are 25,000 employees, but only about 50 are direct users, including a few engineers with admin rights.
How has it helped my organization?
We have experienced some challenges with the high availability of the physical boxes. As we've gone to the virtualization and cloud options, that has become much more resilient. Patching was sometimes problematic because we had to do it from the command line, and the GUI was limited. Sometimes, things would get stuck, so you had to go to the command line. Integrity offers some GUI enhancements, high availability, logging improvements, and tools you can use to pull data from it. It's much easier for lower-level engineers to do quick checks without command-line access. That has been a significant improvement.
A few years ago, we migrated to a virtual server infrastructure and changed the Active Directory in that model to point to BlueCat Integrity DNS rather than Microsoft ActiveNet. By doing that, we alleviated many of the security and performance issues we had with Microsoft appliances.
We also changed the server infrastructure from static IP addresses to dynamic DHCP reservations. Regardless of where the VMs come up, the DHCP reservation gives them the correct address and DNS. We do dynamic DNS with that. All those things reduced the labor required to fix and tune problems manually. It's a more automated, seamless solution. Integrity improved our resiliency and accuracy while reducing the potential for manual error.
Aside from the DHCP, there are other automated things we can do. We can integrate things like Splunk and other search or logging tools via API and extract data about IP addresses, DNS changes, etc., into other investigative tools or dashboards. The options are endless, and that has helped us with monitoring and integrating other tools. When we do projects that involve migrating servers or networks from one technology to another, having that API call to see the live status of the project is helpful.
Integrity improves our security by providing a single source of IP address usage and contact information. We also have carrier circuit and location information. The cybersecurity team can pull all those pieces together in one searchable query and find out about certain IP addresses and who to contact. You can add customizable columns and extra variables.
What is most valuable?
As a defense contractor, we must meet many compliance standards regarding logging, configuration, and administrative access. BlueCat is one of the few products that combines all the compliance components in a secure, reliable solution.
Integrity requires some technological expertise and a full-time employee to run the system. It is one of several technologies that my group manages, but maintenance requires minimal effort. Upgrading and deploying the solution is a bigger task, but it is easy to maintain once it is running.
BlueCat Integrity offers a single pane of glass view for our IP address space. From the GUI interface, you can see all the IP addresses and roll them up to the colored views of usage and availability. That capability is critical because we have multiple groups that are off on their own in a cloud environment. We can avoid IP address overlap by checking that as we add different projects. While I've worked at this company, we've had more than 50 acquisitions. As we acquire these companies, some IP addresses may overlap. We can integrate those, see the spaces, and adjust.
What needs improvement?
When you replace an appliance, there are many configuration steps, so adding zero-touch provisioning would be helpful. It can be quite tedious and time-consuming to replace a device if it fails or deploy a new one.
For how long have I used the solution?
We started using BlueCat Integrity in 2007.
What do I think about the stability of the solution?
I rate BlueCat 10 out of 10 for stability. It has been extremely stable. We have multiple layers of firewalls around it, so it breaks the traffic, but we've only seen it break one data center, and we continued to provide service to users. We're working behind the scenes to fix these firewall issues and stuff blocking other traffic. It's been so resilient that it's hidden other infrastructure issues, and it's been really great.
What do I think about the scalability of the solution?
I rate BlueCat Integrity 10 out of 10 for scalability. It has so much capacity to run queries. We've set up a distributed system where any calls go to the closest device to the answer, and we've never had any performance issues.
How are customer service and support?
I rate BlueCat support six out of 10. They used to have a free technical account manager for enterprise deployments. They changed that model a few years ago. Recently, they've adopted tiered support, and we pay an additional cost for enhanced service.
We have a dedicated mid-level engineer who is our environment's primary point of contact. We have a much more advanced deployment because we're defense contractors and there are many compliance issues where we need to tune the system. Also, we have it integrated with other things, so we need to do some advanced configuration. Having a dedicated engineer has been helpful. They also have additional staff in case that engineer is on leave or off shift, and we can call on their more experienced engineers to help us if needed.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously had Linux-based systems involving multiple pieces that we had to pull together and operate using a command line. The GUI was a separate database, so it was disjointed, and we had to perform repetitive procedures and manually enter data in multiple places.
Our switch to BlueCat was primarily motivated by compliance considerations. We needed to adopt a modern set of systems that other people could support. The level of technological expertise needed for the old systems was too high, and it was hard to hire engineers with those specialized skills. With BlueCat, you don't need to be a Linux guru. The learning curve was much lower, allowing less-experienced systems engineers to work on it. That freed up our high-skilled employees to work on more advanced things.
How was the initial setup?
The integration was somewhat complex. Integrity is integrated with multiple systems, so it has been incredibly flexible in that regard. It isn't too complex, but you need to do many steps to get it running how you want. It took a couple of weeks to get everything integrated and running.
We had to set up system logging and import all the IP addresses from our old systems before it went live. After deployment, BlueCat requires some maintenance. As defense contractors, we need to adjust when identifying vulnerabilities. We also have a support contract for yearly maintenance.
What was our ROI?
We've realized an ROI from Integrity by saving time and eliminating issues. With a different system that adopts the old ways of doing things, the cost will probably be high, and you won't see much ROI. Integrity's automation and other features have enabled us to eliminate at least four or five full-time employees easily.
The cost of ownership has probably been maintained, but we've reduced the complexity and downtime. That's where the benefits are.
What's my experience with pricing, setup cost, and licensing?
BlueCat Integrity is a little expensive, but it's worth the price because it offers the flexibility and features we need in our space. We have more than 25,000 employees, and it makes sense for a network of our size. It's required for us to be compliant in the defense industry. Given the restrictions we face, we must be able to easily show that we've complied with all the regulations.
What other advice do I have?
I rate BlueCat Integrity nine out of 10. If you have a decent-sized network, you will have errors and gaps. Those spreadsheets and other systems are inadequate in today's changing world. Things move around so much, and having more automated and integrated solutions frees your engineers to do more worthwhile and advanced things.
I would recommend Integrity to companies managing large networks. We've tried other leading vendors and systems in this space. While some of them have small cost advantages, they lack flexibility and features. We've had plenty of mergers and acquisitions, so we've seen the systems other companies used, and Integrity has always exceeded those.
Which deployment model are you using for this solution?
Helped reduce human error by 70 percent and has helped reduce downtime by 80 percent
What is our primary use case?
We use BlueCat Integrity for IP networking.
How has it helped my organization?
BlueCat Integrity is easy to learn and use. It provides a single pane of glass view for our IP address space. The Single pane of glass is important because it allows us to manage our large environment in one place.
It has helped reduce human error by 70 percent and has helped reduce downtime by 80 percent.
We have been able to free up staff time to focus on other projects and tasks.
BlueCat Integrity's automation capabilities saved us around 80 percent of our time.
It has improved our network stability and has saved us around 40 percent of our costs.
What is most valuable?
BlueCat Integrity's scalability and user-friendliness are the most valuable features.
What needs improvement?
BlueCat Integrity can improve by increasing the amount of updates it releases.
For how long have I used the solution?
I have been using BlueCat Integrity for two years.
What do I think about the stability of the solution?
I would rate the stability of BlueCat Integrity ten out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of BlueCat Integrity ten out of ten.
How are customer service and support?
BlueCat's technical support is knowledgeable and quick to respond.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment is straightforward.
What's my experience with pricing, setup cost, and licensing?
BlueCat Integrity is affordable.
What other advice do I have?
I would rate BlueCat Integrity nine out of ten.
We have five users within our organization.
Our client is an enterprise organization.
I recommend BlueCat Integrity to others.
Which deployment model are you using for this solution?
Has a comprehensive dashboard, automation capabilities, and seamless integration with IT operation manager platforms
What is our primary use case?
It primarily serves as our DNS solution.
How has it helped my organization?
The insight into the overall health of our network, particularly in terms of DNS functionality, is positive. This visibility proves invaluable when troubleshooting and resolving issues. It provides a holistic view, including information on DNS and DHCP services, making it a thorough and effective tool for monitoring and managing DNS functionality.
DNS security is safeguarded comprehensively from end to end.
It offers a unified view of our IP address space through a single pane of glass. Whether using IPM or Integrity with DNS, you can easily correlate and match all assigned IPs with the DNS configuration. This integration ensures that each IP address in IPM corresponds to a DNS name, providing comprehensive visibility.
It has been seamlessly integrated with various IT operation manager platforms, including SolarWinds. While it might not be accurate to label the integration with Integrity as direct, it's apt to say that our BlueCat solution is monitored by SolarWinds. Additionally, for internet access, such as reaching domains like Google.com, we rely on Cisco Umbrella.
It helped us in minimizing human errors by facilitating automation through the use of scripts.
The design with BlueCat ensures minimal downtime as it is highly redundant. In the event of a server failure, multiple servers seamlessly handle the traffic, making the occurrence of downtime highly improbable.
It did not contribute to the consolidation of any previously used tools or applications.
It assisted in saving time for other projects.
What is most valuable?
One of the standout features of BlueCat is its foundation on Linux, making it one of the earliest DNS solutions. This inherent stability, derived from its Linux-based architecture, provides a well-established and reliable platform. Once you become familiar with the technology, managing it becomes straightforward.
What needs improvement?
It primarily supports DNS high availability failover when the servers share the same subnet. However, it does not offer robust support for high availability failover with different subnets, especially if the servers are located in different data centers and belong to distinct IP networks. In such cases, setting up high availability becomes challenging, often requiring manual failovers.
For how long have I used the solution?
We have been using it for approximately five months.
What do I think about the stability of the solution?
There were no stability issues.
What do I think about the scalability of the solution?
It provides good scalability capabilities.
How are customer service and support?
I am satisfied with its customer service and support. I would rate it eight out of ten.
Which solution did I use previously and why did I switch?
We were using NS-1 previously but decided to switch, primarily because IBM acquired the company, and subsequently, they discontinued the solution.
How was the initial setup?
The initial setup was somewhat challenging, but it wasn't overly difficult.
What about the implementation team?
The deployment process spanned approximately two months. The overall project required four resources, including roles such as design and project management, to complete it.
What's my experience with pricing, setup cost, and licensing?
I am not sure about the exact pricing, but I believe their cost is lower compared to Infoblox.
Which other solutions did I evaluate?
The previous solution reached its end, leading the vendor to discontinue the service. During the customer review, we evaluated options between BlueCat and Infoblox.
What other advice do I have?
For a medium-sized company, having a DNS solution is essential. Whether it's BlueCat, Infoblox, or another option, it's crucial for smooth operations. While it's technically possible to work with Linux Spine or other solutions like F5 DNS, they are often challenging to manage due to the absence of a graphical user interface. Having a dedicated DNS solution tailored for medium-sized companies, like BlueCat, is indispensable for scalability and efficiency. Before implementing BlueCat, it's advisable to ensure that employees undergo training. You may consider requesting an evaluation license from BlueCat to set up a lab for training resources dedicated to working on the BlueCat DNS solution. Additionally, exploring a POC could be beneficial. Overall, I would rate it nine out of ten.