Medallia Tracks Customers’ Heroic Deeds with Help from F5

Organizations that want to be heroes in their stakeholders’ eyes rely on Medallia for customer and employee experience research and solutions. The company’s SaaS-based solutions are delivered with help from F5 NGINX Plus, which provides fast, secure access plus responsive support that has one Medallia IT engineer comparing F5 to speedy superhero Flash.

Business Challenge

According to an IT engineer at Medallia, Flash—the speedster superhero of the DC Comics universe—has nothing on F5. That’s high praise from a company that specializes in customer feedback.

For more than 20 years, Medallia has provided organizations across industries with integrated customer and employee experience solutions for needs ranging from contact center management and customer surveys to crowdsourced employee problem-solving and artificial intelligence (AI) analytics.

“Our goal is to make our customers’ customers happy,” says Vinnie Chhabra, IT Engineer for Medallia. Chhabra works for the company’s corporate IT team, which supports some 2,000 Medallia employees who create, sell, and support the Software as a Service (SaaS) solutions used by thousands of customers around the globe. With headquarters in California and roughly $500 million in annual revenues, the company delivers apps to internal and external users through a hybrid architecture of both on-premises and public cloud environments. However, the Tier 1 applications managed by Chhabra’s team run predominantly in on-premises data centers.

“All of our applications are supposed to be externally accessible,” he says. “Their IP addresses point only to the NGINX server, which protects access to our back-end servers.”

For a half-dozen years, open source NGINX was sufficient for the necessary HTTP server and reverse proxy services. Then about three years ago, the team began adding nodes to their back-end servers as a high availability strategy. While they could have managed all the resulting work manually, it would have required more time and labor than they wanted to invest.

Solutions

Fortunately, Medallia decided instead to obtain F5 NGINX Plus, which offers capabilities not included in their open source option. Chhabra’s team did consider other web server products, including Apache and HA Proxy, but ultimately chose NGINX PLUS.

“We found NGINX to be the most scalable and secure,” says Chhabra. “With NGINX Plus, everything was already there.” That includes built-in modules that the team otherwise would have had to compile in separately. “The other big reason was having the NGINX support.”

 

Because the team was already familiar with NGINX, implementation was easy. Chhabra says, “It was very easy, very straightforward. For the few questions we had, F5 engineering support has been awesome.”

Today, all of Medallia’s Tier 1 and some Tier 2 applications run behind NGINX Plus, which prevents unauthorized access to the back-end servers while load balancing traffic to improve app availability and performance.

Results

Fight cybercrime by preventing unauthorized access

The safety of Medallia’s intellectual property (IP) was a significant factor in the company’s decision.

“The servers we have behind NGINX have a lot of our intellectual property on them—our Tier 1 apps, all our code runs on those,” Chhabra says. “Anyone having access to those when they shouldn’t is very critical for us. So we were looking for something where we could keep our back-end servers hidden from the user community and from the Internet.”

Chhabra says, “NGINX Plus lets us easily keep our back-end servers secure with allow lists, passwords, different types of tokens, and SSL offloading as well. And it can be done at the front end of NGINX where we don’t have to worry about doing anything on the back end.”

In addition, any attack could be quickly thwarted. Chhabra says, “If we have any issue, we can just stop NGINX, and nobody externally can access anything at all.”

Save IT time delivering fast, secure websites

Chhabra praises the ease of deploying and securing apps with the solution. “The main thing about NGINX Plus is that it’s so easy to get started with,” he says. “If we want to implement something, so many times we can find an example out there and just build upon it to customize it to our own liking.”

He says ongoing management is easy, too. “Whether it’s allow lists or security passwords, certificates or SSL offloading, all that kind of stuff—NGINX Plus has just made things a lot easier for us.”

NGINX Plus also provides API gateway functionality. “We haven't really leveraged that as much as we should,” Chhabra says. “But we will be doing more, especially with applications between CI/CD and development, both of which are behind NGINX.”

Rely on support as fast as The Flash

The Medallia IT team particularly appreciates F5 technical support.

“I love having the MyF5.com account where I can download patches, download products, and get support,” Chhabra says. “Seriously, I submit a ticket and usually within 10 minutes I’m getting some kind of reply with suggestions.” He says most other vendors he works with take hours to respond.

He smiles. “If F5 were a superhero, I would call it Flash.”

It’s only coincidence that the F5 logo is red, but when it comes to F5 products and services, any resemblance to the Scarlet Speedster is intentional.

Medallia logo
Benefits
  • Fight cybercrime by preventing unauthorized access
  • Save IT time delivering fast, secure websites
  • Rely on support as fast as The Flash

Challenges
  • Deliver secure apps in a hybrid architecture
  • Protect IP while maintaining authorized access
  • Move past open source limits

Products