Virtual LoadMaster Datasheet

Transcription

Virtual LoadMaster – DatasheetVirtual LoadMaster DatasheetIndustry’s best virtual load balancer maximum value, flexibility and performancekemp.axCopyright 2002-2020 Kemp TechnologiesAll Rights Reserved.V 3.2 February 2020

Virtual LoadMaster – DatasheetCloud & Virtual Application DeliveryKemp’s Virtual LoadMaster is a fully featured load balancer and application delivery controller (ADC) that supports allthe major application workloads with easy-to-use templates. It offers key features such as SSL offload along withadvanced authentication and traffic delivery options.Figure 1- LoadMaster Hybrid TopologyDeliver AnywhereVirtual LoadMaster (VLM) instances can be deployed on all major hypervisors and on leading public cloud serviceswith a consistent set of features regardless of where deployed. Consistency across a wide range of platforms greatlysimplifies cloud migration and hybrid cloud deployments with seamless migration and reduced managementcomplexity.Flexible LicensingVirtual LoadMaster can be licensed using permanent or subscription licenses on each instance, or with meteredlicensing across multiple Virtual LoadMaster instances. Metered licensing provides the flexibility to deploy and retireload balancing resources on-demand, greatly simplifying DevOps environments and application scaling.Easily ManagedRegardless of where Virtual LoadMasters are deployed, a consistent administration interface is presented via Web UI,API and Kemp 360 Central. Kemp 360 Central provides cross-platform configuration and monitoring of load balancingresources to simplify the administration of multi-load balancer environments. The LoadMaster API (RESTful andPowerShell) enables automation of load balancer deployment, configuration and administration and integration ofload balancer operations with DevOps and hypervisor management frameworks.kemp.axCopyright 2002-2020 Kemp TechnologiesAll Rights Reserved.V 3.2 February 2020

Virtual LoadMaster – DatasheetSupport SubscriptionsLoadMaster support subscriptions offer flexibility, simplicity and value to meet your application deliveryrequirements and challenges. Support subscriptions are annual and can be upgraded and downgraded as applicationdelivery demands change for maximum flexibility. The tiers are mapped to common customer challenges andrequirements, simplifying the task of selecting the appropriate feature set and support levels.LoadMaster annual subscriptions (VLM-500, VLM-3000 and VLM-MAX) and cloud (AWS & Azure) pay-as-you-go includean Enterprise Plus support subscription as standard.LoadMaster Support Subscription TiersEach subscription tier adds to the features and services delivered by lower tiers as followsSTANDARD SUPPORTENTERPRISE SUPPORTENTERPRISE PLUS SUPPORT10x5 Customer Support24x7 Customer Support24x7 Customer SupportSoftware UpdatesSoftware UpdatesSoftware UpdatesSecurity PatchesSecurity PatchesSecurity PatchesL4-L7 Application DeliveryL4-L7 Application DeliveryL4-L7 Application DeliveryEdge Security PackEdge Security PackIntrusion PreventionIntrusion PreventionKemp 360 Vision- managed service for applicationmonitoring & preemptive alertingKemp 360 Vision- managed service for applicationmonitoring & preemptive alertingKemp 360 Central- centralized management& orchestration softwareKemp 360 Central- centralized management& orchestration softwareWAF with rule updatesGSLB with IP ReputationFloating Licensekemp.axCopyright 2002-2020 Kemp TechnologiesAll Rights Reserved.V 3.2 February 2020

Virtual LoadMaster – DatasheetFeaturesL4-L7 Application DeliveryGeneral Server Load Balancing (SLB) for TCP/UDP basedprotocolsTLS (SSL) OffloadLayer 7 Content SwitchingTransparent caching for HTTP/HTTPSCompression of static and dynamic HTTP/HTTPScontentHTTP/2 SupportUp to 1,000 Virtual and 1,000 Real ServersNAT-based forwardingSupport for Direct Server Return (DSR)configurationsConfigurable S-NAT supportVLAN Trunking (802.1Q)Link interface bonding (802.3ad)IPv6 support for addressing and featuresIPv6 - IPv4 bidirectional conversionHealth Checking Aggregated health checksICMP health checkingLayer 7 checking against any target server portActive/Hot Standby configurations for HighAvailabilityStateful FailoverScale-out ClusteringAggregated health checksSession Persistence Source IP (L4)TLS (SSL) SessionID (L4)HTTP/HTTPS Browser-session (L7)HTTP/HTTPS WebClient-session (L7)RDP Login ID (L7)Port Following for mixed HTTP/HTTPS sessionsSession reconnection for Microsoft RDSScheduling and Balancing Methods SDN AdaptiveRound RobinWeighted Round RobinLeast Connectionkemp.ax Weighted Least ConnectionAgent-based AdaptiveChained Failover (Fixed Weighting)Source-IP HashLayer 7 Content SwitchingGlobal Server Load Balancing (GSLB)AD Group based traffic steeringSSL/TLS Features Configurable TLS (1.0, 1.1, 1.2, 1.3) and SSL (2.0,3.0)Support for EV (Extended Validation) certificatesOCSP certificate validationServer Name Identification (SNI) supportSupport for up to 1,000 TLS (SSL) certificatesAutomated TLS (SSL) certificate chainingCertificate Signing Request (CSR) generationFIPS 140-2 Level 1 (Level 2 on FIPS models)STARTTLS mail protocols (POP3, SMTP, IMAP)Administration Change auditingWeb User Interface (WUI)SSH & physical consoleRESTful and PowerShell APIsVMware vRealize OrchestratorContext based help (WUI)Real time display of performance and availabilityApplication templatesRemote syslogd supportAutomated configuration backupSelective restore of configurationConnection drainingComprehensive logging and reportingSNMP supportDiagnostic shell with in-line tcpdumpSecurity Permit/Deny Access Control ListsIP address filteringIPsec Tunnel supportDDoS mitigation, including L7 rate-based attacksIPsec VPN to Azure, AWS and public cloudsAuthenticated NTPCopyright 2002-2020 Kemp TechnologiesAll Rights Reserved.V 3.2 February 2020

Virtual LoadMaster –DatasheetFeaturesKemp 360 CentralWeb Application Firewall (WAF) Centralized management and orchestrationIncluded with Enterprise support subscription,and Enterprise Plus support subscriptionLoadMaster configuration managementAutomated LoadMaster backupsCentralized & scheduled firmware updatesLoadMaster logfile consolidationPerformance management3rd party load balancer supportReal-time application threat mitigationDaily rule updatesThreats mitigatedo Cookie tamperingo Cross site request forgeryo Cross site scriptingo Data loss preventiono SQL injectiono PCI-DSS Section 6.6 complianceKemp 360 VisionGlobal Server Load Balancing (GSLB) Scheduling and Balancing Managed service for application monitoring &preemptive alertingIncluded with Enterprise support subscription,and Enterprise Plus support subscription24/7 automated issue escalation serviceProactive issue managementIntegrated with Kemp Support ticketingEdge Security Pack Microsoft TMG replacementPre-authenticationMulti-domain authentication & SSOX.509 client certificate authenticationCustom login formsTwo-factor authenticationSAML, Active Directory, RADIUS & LDAPForms to Forms based authentication Round RobinWeighted Round RobinChained Failover (Fixed Weighting)RegionalReal Server LoadLocation BasedSecurity Black List (Access Control List)IP reputation filtering with automatic updatesDDoS mitigationHealth Checking & Failover ICMP health checking of server farm machinesLayer 4 TCP checkingHTTP/HTTPS health checkActive/Active High AvailabilityIntrusion Prevention Snort compatible IPSPermit/Deny IP by addressAutomated IP reputation updates for GSLBkemp.axCopyright 2002-2020 Kemp TechnologiesAll Rights Reserved.V 3.2 February 2020

Virtual LoadMaster - DatasheetLoadMaster Licensing OptionsPerpetual LicensingPerpetual licenses are available across all cloud and hypervisor platforms. Apply a support subscription to aperpetual license to define the support level and features enabled.VLM-500VLM-3000VLM-MAXVLM-GEOPublic Cloud (Azure & AWS) Hypervisor (Hyper-V, VMware, XEN, KVM,VirtualBox) Subscription LicensingSubscription licenses are available for one or three years on all cloud and hypervisor platforms. EnterprisePlus support subscription included as default.VLM-500VLM-3000VLM-MAXPublic Cloud (Azure & AWS) Hypervisor (Hyper-V, VMware, XEN, KVM, VirtualBox) PAYG LicensingPAYG (Pay-As-You-Go) licenses provide hourly usage licenses on Azure and AWS that includes platform usageand Kemp instance licensing. All PAYG Virtual LoadMasters include daily WAF and GEO (GSLB) rule updatesand Edge Security Pack as standard and do not require any additional subscription purchase.Public Cloud (Azure & AWS)VLM-FREEVLM-500VLM-3000VLM-MAX Metered LicensingMetered Licensing (MELA) offers a monthly subscription option based on aggregate peak usage by licensedVirtual LoadMaster instances. A single metered license enables the deployment of Virtual LoadMasterinstances on any supported cloud or hypervisor platform with no license limits on the instance capacity.Aggregate ThroughputMax. Virtual LoadMaster InstancesPlatform - Cloud & LA-100G1 Gbit10 Gbit25 Gbit50 Gbit100 GbitUnlimitedUnlimitedUnlimitedUnlimitedUnlimited Copyright 2002-2020 Kemp TechnologiesAll Rights Reserved.V 3.2 February 2020

Virtual LoadMaster - DatasheetLoadMaster Platform SupportVirtual LoadMaster on HypervisorVirtual LoadMaster is available on Hyper-V, VMware, XEN, KVM and VirtualBox.Subscription Tiers SupportedLicensing model supportedVLM-500VLM-3000VLM-MAXAllAllAllPerpetual, SubscriptionPerpetual, SubscriptionPerpetual, Subscription500 Mbps3 capped*1,000/1,0001,000/1,0001,000/1,000Licensed PerformanceLoad Balancer ThroughputSSL TPSConcurrent Layer 4 ConnectionsMax Servers/ Virtual ClustersVirtual LoadMaster on CloudVirtual LoadMaster is available on Azure and AWS and their Government variants.Subscription Tiers SupportedLicensing model supported§VLM-500VLM-3000VLM-MAXAllAllAllBYOL, PAYGBYOL, PAYGBYOL, PAYG500 Mbps3 capped*1,000/1,0001,000/1,0001,000/1,000Licensed PerformanceLoad Balancer ThroughputSSL TPSConcurrent Layer 4 ConnectionsMax Servers/ Virtual Clusters§ BYOL (Bring-Your-Own-License) instances are subject to cloud platform charges based on the VM size deployed. PAYG (Pay-As-You-Go)is an hourly billing scheme that includes the Kemp license and cloud platform charges.* Performance dependent on allocated system resources.kemp.axCopyright 2002-2020 Kemp TechnologiesAll Rights Reserved.V 3.2 February 2020

Microsoft TMG replacement Pre-authentication Multi-domain authentication & SSO X.509 client certificate authentication Custom login forms Two-factor authentication SAML, Active Directory, RADIUS & LDAP Forms to Forms based authentication Snort compatible IPS Permit/Deny IP by address