
IWL's New Website
October 5, 2026
Yes, we have updated our website.
The overall structure is quite different from the old.
We are in the process of moving over relevant white papers, videos, and blog entries.

October 5, 2026
Yes, we have updated our website.
The overall structure is quite different from the old.
We are in the process of moving over relevant white papers, videos, and blog entries.
Custom packet manipulation involves creating or changing data packets in a network stream to mimic certain conditions in network environments. However, it’s not enough just to have them mimic ordinary operations. Developers and...
For the last decade, apps have played an increasingly integral role in our lives. But often, we don’t think about what’s happening underneath that robust performance or what’s guaranteeing the stability of applications. This is where programmable ne...
These days, the need for robust, reliable network testing environments has never been greater. Programmable Network Emulators, or PNEs, are designed to meet this need. Today's PNEs allow network administrators and...
Optimizing network performance is necessary with the surge in data consumption and increasing demands of end-users and apps. At the heart of this challenge is network bandwidth—the lifeline of data flow. Understanding and managing th...
Why doesn’t everyone just use Netem?
Netem, short for “Network Emulator”, is a Linux networking tool that allows for the simulation of network properties. It’s part of the Linux kernel’s tc, or Traffic Control, system. It can be used...
Developers, network engineers, and IT professionals must be able to accurately predict and emulate real-world conditions. This is where statistical probabilities in network emulation come into play.
At its core, net...
The QA (Quality Assurance) process is always evolving alongside the world of network technology. Traditional network testing methods, static and limiting as they are, are no longer enough. Today’s programmable network emula...
Ensuring network reliability, security, and performance is an immense task. The challenge grows even more significant as these networks become more complex and scalable. Enter programmable network emulators, a must-have tool for QA professionals. T...
IWL talked to many quality engineers, design engineers, and gaming enthusiasts and asked them about the different ways they think about and prioritize testing online, interactive, multiplayer games. This is a compendium of the results.
Software, and network related products and services, have long been sold, licensed, or operated with a unique degree of immunity for flaws and failures.
A sea change may be coming.
This change could be of Biblical proportions, so perhaps a Biblical sounding warning should be heralded:
Manufacturers, makers, and vendors take heed lest you be drowned.
In March of 2023 the Biden Administration released a "National Cybersecurity Strategy"
Take a look at Strategic Objective 3.3, "Shift Liability For Insecure Software Products and Services":
The Administration will work with Congress and the private sector to develop legislation establishing liability for software products and services. Any such legislation should prevent manufacturers and software publishers with market power from fully disclaiming liability by contract, and establish higher standards of care for software in specific high-risk scenarios. To begin to shape standards of care for secure software development, the Administration will drive the development of an adaptable safe harbor framework to shield from liability companies that securely develop and maintain their software products and services.
I have long advocated that network devices and the software they contain be fully subject to the kinds of liability that are imposed on other kinds of products.[1][2]
It seems that perhaps the US government has finally gotten the message.
It is obvious to everyone that a lot of software is flawed. Vendors have evaded responsibility for a long time through the use of "terms of use" or license disclaimers of warranties; coerced arbitration; liability dollar limits; and choice of law, venue, and jurisdiction stipulations.
The Administration built its proposal around concerns for security and privacy. And that may well be where vendor liability attaches first.
But the logic and arguments in the proposal are not limited to security and privacy. Just as product liability began with products that could cause direct and terrible damage to people, courts and legislatures may expand the scope as network software harm manifests itself in ways beyond security or privacy.
Recently we purchased two of the Apple Silicon (M2) based Mac Minis for one of our offsite networks. One was the mid-range version; the other was the top-of-the-line. We ordered both with the 10G network interface. That interface supports 10G, 2.5G, 1G, 100M, and 10M.
The Mac Minis are both running Ventura 13.3.
We also recently upgraded parts of our network to 2.5G, including a 2.5G-equipped pfSense router to one of Comcast's faster offerings (1G in, 25M out.) Our cables are all of sufficient rating to run at 2.5G.
Things seemed fine.
Until we fired up Zoom.
(This article has been updated to mention KMAX because it has similar functionality.)
A new Maxwell plugin that can do user-controlled re-sequencing of packets is available as part of the latest Maxwell TCP testing package.
The plugin is able to rearr...

This article was originally published on LinkedIn, 21 Feb 2022.
Real-world networks encounter all kinds of problems from issues like duplicate IP addresses, misconfigured routers, inadequate buffering, fast-path slow-path transitions, IP fragmentation, and more.
The TCP protocol, when initially designed, had problems when the path between the endpoints was undergoing congestion, which manifests itself in packet loss and delay. TCP was extended to implement algorithms to detect signs of congestion on the path and to take actions to avoid sending more traffic into that congestion.
The Log4j flaw, disclosed by Apache 9 December 2021, allows attackers to execute code remotely on a target computer, meaning that they can steal data, install malware or take control.
None of the IWL products use this code.
NO IWL products...
On December 4th, the President of the U.S. signed the IoT Cybersecurity Improvement Act of 2020, which directs the National Institute of Standards and Technology (NIST) to create standards and guidelines on the use and management of internet of things devices by federal agencies and to develop guida...
The claims about 5G continue to increase in audaciousness!
From Fierce Wireless:
"T-Mobile can keep telling consumers that its 5G service is faster than 4G and offers more coverage than rivals' 5G, but the National Advertising Division (NAD) of BBB National Programs recommends that it stop claim...

A SonicWall user recently came to us for help; the user felt the problem was within SIP and UDP. Here are some thoughts and ideas we provided to help him with his SIP diagnosis.
SIP is a somewhat troublesome protocol. The basic SIP transactions f...
We read Damien Garros' blog post -- Introduction to Network Emulation and Requirements for Virtual Network Devices with great interest as Mr. Garros takes an unusual view of networking. Our thoughts and comments follow.
Click on the link above to read the entire post, or view the pdf here
...IWL Chief Technical Officer Karl Auerbach delivered the Keynote speech at NANOG 77 in Austin, Texas on Tuesday, October 29, 2019.
It was 11:10pm on the night of October 9, 2019. Here along the Monterey Bay the weather was calm, cool, and a bit damp. The lights were on, the internet was working, the car was charging; everything was normal.
At 11:11pm things suddenly changed.
The lights went out.
Internet service dropped...
Karl Auerbach, Chief Technical Officer at IWL, will deliver one of the keynote addresses at the North American Network Operator’s Group (NANOG 77):
10:00 a.m. - 10:30 a.m.
Tuesday October 29, 2019
Lone Star...
ICS-CERT (Industrial Control System – Computer Emergency Response Team) is part of the U.S. Department of Homeland Security. Recently CERT issued two Advisories concerning TCP/IP implementation...
Prior to planning or funding 5G rollouts, technology implementers must rigorously question 5G claims and look for substantiated evidence
IWL issued a caution today that some of the claims made by investors in 5G technology are exaggerated or lead to overly-naïve conclusions.
5G i...
Nearly half of US mobile shoppers say they would abandon an app if it doesn’t load in three seconds or less, according to industry research reported in ComputerWeekly.com in 2014.
More than ever, users want a snappy, responsive product. If they don’t get it, they will walk away.
To help combat...
Practical considerations for software developers considering 5G network emulation
5G is the latest technology for cellular mobile communications. Deployment is expected to take place sometime between late 2019 and mid 2020. The benefits of 5G will be available to new, 5G-enabled devices. Howev...
Software developers and implementers want guidelines and advisories for testing TCP/IP. Available and implemented in the 1970s and codified in the 1980s, updates and changes to the TCP/IP protocol continue up through the present day.
W...
IWL's KMAX network emulator is changing the way passwords are handled.
The state of California has enacted a new law that affects the way that initial passwords are established on network attached devices TITLE 1.81.26. Security of Connected Devices
It is a sensible law that will improve the security of devices on the internet.
As a consequence of these new requirements IWL is making a few changes to KMAX.
These changes are in effect for KMAX units constructed after mid November 2018. (Except for KMAX-V, the date for the change on that platform is yet to be established, but it is expected to occur before the end of 2018.)
Open source advocates have long proclaimed the intrinsic quality and security of open source code. They argue that because the code is open it is inspected by many eyes and tested by many hands.
I dispute that argument.
Code will become better through more inspection, and improved testing, no matter whether that code is "open", "free", or "proprietary".
IWL Engineering has completed its investigation of the CVE-2018-10933 security flaw (libssh bug) and found that this bug is not present in our products.
Based on testing conducted by IWL engineers, there is no indication that either Mini Maxwell or KMAX is subject to the libssh flaw.
For the Maxwell Pro products, based on RedHat Fedora, RedHat has stated that its systems are not vulnerable; our testing is consistent with that.

Question: My team is developing a new software app that runs on iOS and Android phones. I have Windows 10 running on my desktop. I plan to go ahead and test it out with the built-in Windows 10...
The Los Angeles Times reported today that "More than 23,000 Californians were registered to vote incorrectly by state DMV."
The reason:
The errors, which were discovered more than a month ago, happened when DMV employees did not clear their computer screens between customer appointments. That ...

The cost of computer security breaches is no longer hypothetical. According to the Cisco 2018 Annual Cybersecurity Report (page 46), more than half (53 percent) of all attacks resulted in financial damages of more than US$500,000 (for each org...

Network bandwidth is the maximum data throughput in a specific segment of a digital communication system. For example, a wireless access point rated at 300 Mbps network bandwidth, will support data transiting through the access point at a rate no greater than 300 Mbps...
In 2013, Google announced a new transport protocol, the QUIC protocol (Quick UDP Internet Connections). QUIC’s original goal was to reduce transport latency, particularly with users of web apps (that use HTTP over TCP). The goal was later expanded to provide a reliable, connection-oriented, low...
Network emulators, network modelers and network simulators -- how do they differ? How do I know what solution would be right for my application? How do I compare an emulator vs a simulator?
Modelers, simulators, and emulators represent a continuum, that begins with pure mathematical software models and moves towards the physical reality of emulation.
A network modeler is a representation of a network based on a set of mathematical equations. With a network modeler, you mathematically define traffic volumes, flows, network architectures, etc. You can then visualize th...
How do you measure gravitational waves? How does that compare to counting bits in networking?
In June 2017, IWL Staff attended a fascinating lecture by Dr. Jess McIver of CalTech titled "Einstein Gravitational Waves and Black Holes". Dr. McIver described the operation of the LIGO project for...
License IWL's stateful network impairment technology at a very reasonable price
IWL today announced a new patent licensing program for manufacturers and end users who use the technology of the Maxwell Patent.
IWL is the owner of US patent number 7,310,316 ("the Maxwell Patent", PDF, text)....
Several years ago, an Israeli company called Shunra Software, offered a network simulator product. The product’s purpose: to help IT staff verify the performance of apps and devices, prior to deployment in production networks. The original developers had IT backgrounds, so they understo...
The Washington Post recently published an article: "SpaceX wants to beam the Internet down to Earth. Here's How it will Start."
IWL believes the article doesn't give the whole story.
SpaceX is not proposing anything that is particularly new.
Low Earth Orbit (LEO) satellite networks have been around since the 1990's. There was Iridium and the former Soviet Union had a LEO satellite network for voice calls to remote locations (like Siberia).
The internet is a complex distributed process in which computers interact with one another over pathways that introduce delays and errors. There are many feedback loops. Some of those loops are simple to identify, such as the handshaking between the end points of a TCP connection. Other loops are harder to identify, such as the interaction of timers in ARP (address resolution), DNS (domain name system), and routing protocols (such as OSPF and BGP.)
Positive feedback loops are often merely annoying. But they can also cause more severe problems, such as connectivity failures.

Websites are a bit like fashion; what you wear says a lot about you as a person, and what your website looks like says a lot about your company. You don't want your clothes to make you look out of date, and you don't want your company to look out of date, either. So when it was time for IWL to up...
There's an old joke. It was said that English automobiles of the 1950's came equipped with a walnut inlayed toolbox containing many hammers. These ranged in size from a small jeweler's hammer up through a heavy, concrete shattering, sledge. It was said that when something in the automobile stopped working that one should begin by pounding on it with the smallest hammer. If that didn't solve the problem then one should move up to the next larger size. And so on, using ever larger hammers, until the sledge, which would reduce the automobile to a heap of shattered parts that could easily be hauled away – because the original problem was obviously insolvable.
Fuzz testing of software is somewhat like that old English automotive technique, but often without the benefit of an orderly sequence.

The Trump Administration proposes to "pause" and review an Obama-era program designed to improve wage transparency -- so women and minorities could learn how their compensation stacked up to white men. The Trump administration argues that the government's pay data collection process is "unnecess...
Last month I received a number of fun and friendly birthday wishes on Facebook. Though this was a sweet and kind gesture by each of the well-wishers, I felt guilty. That’s because … it was not my birthday! Facebook thinks my birthday is June 22, 1910, but the day, the month, and the year are all wrong.
So you may wonder: Why would I intentionally lie about my birthday on Facebook?
Women who work in automotive technology met at the British Bankers Club in Menlo Park last night for a lively discussion. The women represented many facets of the industry — research scientists at the major automotive companies, new infotainment and VR startups, regulatory and compliance lawyers, v...
Often when we read news stories, we find them lacking any technical substance. It would seem that the writer aborted the story before asking any interesting questions that would allow us, as technical professionals, to fully understand the story and draw our own conclusions.
Security researchers claim to have discovered an SNMP flaw that affects several models of Internet-connected devices. Presumably hackers could send random values in specific requests to the SNMP agent in various devices and the authentication mechanism would be bypassed.
Despite what one might read in certain techno-marketing publications, IPv4 is very much alive; it has not by any stretch yet been replaced by IPv6.
So it remains important that vendors of networking products do IPv4 and do it correctly.
But some vendors appear to be getting lazy.
In particular one of the largest vendors seems to be taking a shortcut that could leave users unable to communicate even though those users have otherwise perfectly usable packet service from their network providers.
Have you thought about how you will test the performance of IoT apps and drones? Our new video demonstrates performance testing of an IOT application controlling the ESP8266 Microcomputer mounted...
A New York City based start-up company, Confide, offers a text messaging system “with encrypted messages that self-destruct.” You can download the app at getconfide.com
Confide lets its users “discuss sensitive topics, brainstorm ideas or give unfiltered opinions without fear of the Internet’s permanent, digital record and with no copies left behind.” “Messages disappear forever after they are read once, making them as private and secure as the spoken word.”
What a description! Everyone’s dream come true, right? Certainly a perfect app for individuals wanting to communicate about classified information, military plans, or other top secret information.
The Building Automation and Control network (BACnet) protocol defines a network communication standard for building control systems to communicate. These building control systems include devices and applications for heating, ventilating, and air-conditioning (HVAC) control, lighting control, access...
Definition: SDN: Software Defined Networks
“SDN Complexity and Reality” by Russ White and Shawn Zandi, was published on page 31 of The Internet Protocol Journal, November 2016 (Volume 19, Number 3). You can download ipj19-3.pdf at http://ipj.dreamhosters.com/.
In the article, White and Zandi, examine the original three crucial elements to the SDN story:
First, SDNs were supposed to remove the intelligence from the distributed control planes and consolidate that intelligence in a centralized controller.
Second, SDNs were supposed to provide a more granular level of control – down to the flow level.
Third, SDNs would enable the network to be programmable…
The world is an imperfect place. The internet is no exception. The internet has its good days and it has its bad days. Or to be more precise, the internet has its good seconds and its bad seconds.
Blemishes in internet performance arise from many sources.
Real network conditions are rarely static. Real life networks suffer transient conditions – congestion builds up and dissipates, tree branches wave in the wind across radio links, long distance routing paths change, VoIP call trunks are filled with more calls during working hours than during the evening. Even something as small as a person standing near a wi-fi access point can change the carrying capacity of a network.
KMAX and our Maxwell Pro can emulate these kinds of changes.
The ESP8266 is very popular among the maker set as a platform for experimentation in the realm of Internet of Things (IoT).
We have been playing around with the ESP8622 micro-controller running NodeMCU. We’ve been loading simple LUA programs onto the ESP8266 to get familiar with its capabilities.
Now that we’re reasonably familiar with its capabilities, it’s time we put ESP8266/NodeMCU to test.
Cloud computing has taken hold of the business world, nearly reaching its saturation point according to multiple industry reports. The business cloud and its cloud testing capabilities are growing at an extremely fast pace due to scalability, adaptability, cost-effectiveness, and efficiency across nearly every industry.
When evaluating your application for deployment, it is critical to know exactly how it will respond to a variety of network conditions. In some cases, this means going out into the field in search of live, real-world testing scenarios that can be used to test app functionality and user-friendliness.
Many CEOs and business owners think data center relocation involves the simple process of unplugging of a few servers, some careful packaging, and a secure shipment to the next location. IT professionals know that it’s actually a lot more complicated than that.
IDC reports that up to 50% of cloud customers have brought workloads back in house, due to network latency and performance issues, in the cloud. This is an expensive, cumbersome, and counterproductive measure that halts the progress of a company’s technology and growth.
In this article, Wayne Wil...
There’s no question about it—any business that wants to stay relevant these days needs to have a mobile app to keep communication flowing between their clients and their organization. According to a recent Gallup Poll, 52% of the population check their smartphones multiple times per hour and another 20% checks at least once per hour—making the average mobile device a marketing hotspot for businesses.
Enterprise apps are like sports cars: they promise sleek efficiency, but require the right environment to perform optimally. An app may perform well on an enterprise LAN, but will it perform the same when it is deployed in the cloud?
You’ve written an awesome app, and the whole company is banking on how well it does. You’ve done the tests; it has passed QA. It’s exactly what everyone says they need. So your company launches the product, and you wait for the awesome reviews to come rolling in.
Monday, June 13th is the birthday of James Clerk Maxwell, the inspiration for our network emulators!
James Clerk Maxwell was born 13 June 1831. Among his many contributions to physics, James proposed a thought experiment called “Maxwell’s demon” that suggests that the Second Law of Thermodynamics...
Joe rises early as he has a busy day ahead of him. The first thing he does is reach for the smart baby monitor on his nightstand. The visual feed tells him that his 3-month-old daughter is still sleeping soundly,and the temperature display for the nursery lets him know that the baby is neither too hot nor too cold.
NTIA has published a Notice for Public comment that is titled “The Benefits, Challenges, and Potential Roles for the Government in Fostering the Advancement of the Internet of Things”. This could become ICANN-2, bigger, longer, and uncut; and with a much greater impact on the future direction of the internet.
How well is the documentation for a product written? What is the measure of “documentation efficiency”?
Given a problem with trying to use a product feature, what is the probability that you can find the answer to the problem by looking in the documentation, without having to search through stackoverflow?
This letter is a response to Tom Green’s article in the June 5, 2015 edition of Robotics Business Review: “Why are Too Few Females in Robotics? Could it Be the Robots?”
| IPv6 Ready Logo Program | IWL Maxwell IPv6 Tests |
|---|---|
| Basic RFC Conformance | Advanced IPv6 Conformance |
| Basic Interoperability | Advanced Interoperability |
| Community Support | Commercial Support |
| No Software Development (1) | Ongoing Software Deve... |