DATA SHEET FortiADC

Transcription

DATA SHEETFortiADC Available in:ApplianceVirtualMachineHostedCloudAdvanced Application Delivery ControllerHighlights§ Advanced ApplicationLoad Balancing§ Protection fromthe OWASP Top 10application attacks§ Multi-Deployment Modewith Hardware, VM, orCloud Solution (PAYG/ BYOL)Application Delivery Without Any LimitsFortiADC is an advanced Application Delivery Controller (ADC)that ensures application availability, application security, andapplication optimization. FortiADC offers advanced securityfeatures (WAF, DDoS, and AV) and application connectorsfor easy deployment and full visibility to your networks andapplications. FortiADC can be deployed as a physical or virtualmachine (VM), or as a Cloud solution.§ SSL Security and Visibility withHardware-based Solution§ Automation and FabricConnector to Third PartySolutions such as SAP, CiscoACI, AWS, and K8s§ User Authentication andAuthorization via MFA and SSO§ FortiGSLB Cloud IntegrationMaximizes Service AvailabilityApplication Availability24x7 application availability through automatic failover forbusiness continuity with application automation, global server loadbalancing, and link load balancing to optimize WAN connectivity.Application OptimizationMulti-core processor technology combined with hardware-basedSSL offloading and server optimization to increase end-user QoE.FortiADC 100F, 200F, 300F,400F, 1200F, 2200F, 4200F,5000F and VMApplication ProtectionAdvanced Web Application Firewall protection from theOWASP Top 10 and threat detection with Fortinet FortiGuardCloud Services.FortiCare Worldwide24/7 SupportFortiGuard .com1

DATA SHEET FortiADC HIGHLIGHTSApplication AvailabilityApplication OptimizationApplications are the lifeblood of a company’s online presence.Unresponsive applications can result in lost revenue andcustomers taking their future business elsewhere. Applicationperformance, scalability, and resilience are key but none ofthis matters unless the end-user has a good experience andcompletes their transaction.FortiADC provides multiple services that speed the deliveryof applications to users. The PageSpeed suite of websiteperformance enhancement tools can automatically optimizeHTTP, CSS, Javascript, and image delivery to applicationusers. FortiADC also provides Dynamic Caching and HTTPCompression and Decompression to improve end-userexperience and server productivity.FortiADC is a dedicated Application Delivery Controlsolution that provides a multi-tenancy solution (VDOM), highavailability, and scalability with hybrid solution deployment(on-premises and cloud offering) to your applications.SSL SecurityFortiADC delivers high capacity decryption and encryptionwith the latest cryptography standard using hardware-basedSSL ASIC. FortiADC provides SSL offloading, SSL inspectionand visibility to inspect traffic for threats, speeds up serverresponse, and reduces the load on the backend server.FortiADC also integrates with Gemalto’s SafeNet EnterpriseHardware Security Module (HSM).FortiADC Security FabricAs the threat landscape evolves, many new risks requirea multi-pronged approach for protecting applications.FortiADC’s antivirus and integration with FortiSandbox extendbasic security protections to scan file attachments for knownand unknown threats.Business ContinuityFortiADC’s included Global Server Load Balancing (GSLB)module on-prem or in the cloud (FortiGSLB Cloud) makesyour network reliable and available by scaling applicationsacross multiple data centers for disaster recovery or toimprove application response times. Customers can set uprules based on site availability, data center performance, andnetwork latency.Application ProtectionFortiADC offers multiple levels of protection to defend againstattacks that target your web applications. FortiADC WebApplication Firewall can detect a zero day attack and protectfrom OWASP Top 10 and many other threats with multi-vectorprotection. FortiADC also supports our FortiGuard Cloudwhich provides multi services such as IPS, Antivirus, and IPReputation service (subscription required) that protects youfrom sources associated with DoS/DDoS attacks, phishingschemes, spammers, malicious software, and botnets.Automation and ConnectorsFortiADC Fabric Connectors provide open API-basedintegration and orchestration with multiple software-definednetworks (SDN), cloud, management, and partner technologyplatforms. Fortinet Fabric Connectors deliver turnkey, open,and deep integration into third party services such as K8s,AWS, OCI, and SAP, in multi-vendor ecosystems, enablingscalability, security automation, and simplified management.22

DATA SHEET FortiADC HIGHLIGHTSUnleash the Power of ScriptsAnalytics and VisibilityFortiADC Scripts provides the flexibility to create customevent-driven rules using predefined commands, variables,and operators. Using easy-to-create scripts, you get theflexibility you need to extend your FortiADC with specializedbusiness rules that give you almost unlimited possibilities forserver load balancing, health checks, application validation,content routing, and content rewriting to meet the needs ofyour organization.FortiADC offers a comprehensive monitoring system foryour network and application. With FortiView, customerscan get real-time and historical data into a single view onyour FortiADC. We also provide a network logical topologyof real-servers, user/application data-analytics, securitythreats, attack maps, and some other system events andalerts. FortiADC is integrated with third party solutions suchas Splunk, FortiAnalyzer, and FortiSIEM for more visibility,correlation, automated response, and remediation.Application AuthenticationFortiADC provides centralized user authentication andauthorization services to web applications. FortiADC acts as agatekeeper to offload HTTP authentication and authorizationto customer applications using single sign-on (SSO) services,SAML, LDAP, RADIUS, and MFA (using FortiToken Cloud andGoogle authenticator).WAN OptimizationFortiADC Centralized ManagementFortiADC Manager is a web-based management tool thatallows you to centrally manage multiple FortiADC devicesremotely. Network administrators can better control theirdevices by logically grouping devices, efficiently managingjobs and licenses, quickly checking various logs, andmonitoring threat statistics in real time.FortiADC provides a built-in link optimization with the LinkLoad Balancing module. Customers can create two or moreWAN links (for inbound and outbound Link LB) to reducethe risk of outages or to add additional bandwidth to relievetraffic congestion.FortiADC Dashboard3

DATA SHEET FortiADC USE CASESHigh Scale Performance with FortiADCand FortiGate (FWLB and SSL-VPN /IPSEC LB)§ Improved VPN performance anduser QoE§ User redirection based ongeolocation and round-trip time(RTT)§ Advanced health checks forapplications and NGFW in improvedsite visibility and availability§ Application Load Balancing and WAFProtectionMSSP / SP Advanced Offering§ Fully virtualized environment§ Service tailored per customer(SLB, L7, GSLB, WAF, andApplication Optimization)§ Can be managed via Single pane ofglass (CM, API, and Cisco ACI)§ Fully managed services§ High redundancyHybrid Cloud Solution§ Cloud Connector for visibility andavailability§ Fabric Connector to multipleapplications for automation andservice scaling§ Multi-Service solution (SLB, WAF,Authentication, and GSLB)44

DATA SHEET FortiADC FEATURESApplication AvailabilityExternal Fabric Connectors§ Virtual service definition with inherited persistence, load§ Kubernetes Servicebalancing method, and pool members§ Layer 4/7 application routing policy§ SAP Application§ AWS / OCI Connector§ Layer 4/7 server persistence§ Splunk Integration§ Custom scripting for SLB and content rewritingGlobal Server Load Balancing (GSLB)§ Scripting for event-driven rules using predefinedcommands, variables, and operators for SLB, contentrewrite, persistencey, and security§ Advanced L7 application health check with support scriptfor a customized health check§ Clone Traffic PoolsLayer 4-7 Application Load Balancing§ TCP, UDP, IP, DNS, HTTP, HTTPS, HTTP 2.0 GW, FTP, SIP,RDP, RADIUS, MySQL, MSSQL, RTMP, RTSP, and moreapplications§ L7 Content Switching and Rewriting– HTTP Host, HTTP Request URL, and HTTP Referrer– Source IP Address§ Persistent IP, has IP/port, hash header, persistent cookie, hashcookie, destination IP hash, URI hash, full URI hash, host hash,and host domain hash§ URL Redirect, HTTP request/response rewrite (includes HTTPbody)§ Global data center DNS-based failover of web applications§ Delivers local and global load balancing between multi-siteSSL VPN deployments§ DNSSEC§ DNS Access Control Lists§ GSLB setup wizardDeployment Modes§ One arm-mode (Proxy with X-forwarded for support)§ Router mode§ Transparent mode (switch)§ High Availability (AA/AP Failover)Web Application FirewallApplication Protection§ OWASP Top-10 Wizard§ Web Attack Signature§ Layer 7 DNS load balancing, security, and caching§ API ProtectionLink Load Balancing§ Bot Detection§ Inbound and outbound LLB§ Support for policy route and SNAT§ Multiple health check target support§ Sensitive Data Protection§ Web Vulnerability Scanner§ HTTP RFC compliance§ Configurable intervals, retries, and timeoutsSecurity Services§ Tunnel Routing§ SQLi/XSS Injection DetectionSecurity Fabric Connector§ OpenAPI Validation§ FortiGLSB Cloud (One-Click-GSLB)§ FortiAuthentication§ FortiSIEM§ FortiAnalyzer§ FortiADC-CM§ FortiSandbox§ API Gateway§ Web Scraping§ CSRF Protection§ Brute Force Protection§ Web Defacement Protection§ CAPTCHA Support§ Data Leak Prevention§ File Restriction§ Cookie Security§ XML/JSON/SOAP Validation§ HTTP Header Security5

DATA SHEET FortiADC FEATURESApplication AccelerationSSL Offloading and Acceleration§ Offloads HTTPS and TCPS processing while securingsensitive data§ Full certificate management features§ HTTP/S mirroring for traffic analyses and reporting§ Support TLS 1.3Application Security§ FortiGuard Antivirus and FortiSandbox integration§ GEO IP security and logs (subscription required)§ Stateful Firewall§ Web Filtering (subscription required)§ IP Reputation (subscription required)§ IPv4 and six firewall rules§ Granular policy-based connection limitingHTTP and TCP Optimization§ Syn cookie protection§ 100x acceleration by off-loading TCP processing§ Connection limits§ Connection pooling and multiplexing for HTTP and HTTPS§ Intrusion Prevention System (subscription required)§ HTTP Page Speed-UP for Web Server Optimization§ Application and Network DDoS Protection§ TCP buffering§ DNS Application Security§ HTTP compression and decompression§ HTTP caching (static and dynamic objects)§ Bandwidth allocation with Quality of Service (QoS)Management§ Central management for multiple FortiADC devicesAuthentication Offloading§ REST API§ Local§ SNMP with private MIBs with threshold-based traps§ LDAP§ Real-time Data Analytics§ RADIUS§ Syslog support§ Kerberos§ Role-based administration§ SAML 2.0 (SP and Idp)§ Real-time monitoring graphs§ NTLM§ Built-in reporting§ Two-Factor Authentication — FortiToken/ FortiTokenCloud, and Google Authentication§ FortiView integrationNetworking§ Virtual Domains (VDOMs)§ Data analytics§ Static NAT, Hide NAT, and Dynamic NAT for flexibility andscalability)§ VLAN and port trunking support§ Support integration with Cisco ACI, Nutanix, OpenStack,and Ansible§ NVGRE and VXLAN Support§ BGP and OSPF with Route Health Inspection (RHI)§ IPv6 Support (SLB, interfaces, routing, and firewall)66

DATA SHEET FortiADC SPECIFICATIONSFortiADC 100FFortiADC 200F1.5 Gbps / 1.3 Gbps3 Gbps / 2.2 GbpsSystem PerformanceL4/L7 ThroughputL4 CPS50,000100,000L4 HTTP RPS150,000300,000Maximum L4 Concurrent ConnectionL7 CPS (1:1) *SSL CPS/TPS (1:1) 2K keys **SSL Bulk Encryption ThroughputCompression ThroughputSSL Acceleration TechnologyVirtual Domains3M5M15,00025,0004001,000400 Mbps1 Gbps1Gbps1.5 GbpsSoftwareSoftware1010Hardware SpecificationsMemoryNetwork Interfaces10/100/1000 Management Interface8 GB8 GB6x GE RJ454x GE RJ45, 2x GE SFP——64 GB SSD64 GB SSDManagementHTTPS, SSH CLI,Direct Console DB9 CLI, SNMPHTTPS, SSH CLI,Direct Console DB9 CLI, SNMPPower SupplySingleSingle11StorageSimultaneous Sources (M)DimensionsHeight x Width x Length (inches)1.75 x 17.3 x 10.551.7 x 17 x 11.9Height x Width x Length (mm)44 x 440 x 26844 x 432 x 301.4Weight9.9 lbs (4.5 kg)10.98 lbs (4.98 kg)EnvironmentForm FactorInput VoltagePower Consumption (Average / Maximum)Maximum CurrentHeat DissipationOperating TemperatureStorage TemperatureHumidity1U Appliance1U Appliance100–240V AC, 50–60 Hz100–240V AC, 50–60 Hz40 W / 60 W70.98 W / 109.9 W100V / 1.5A, 240V / 0.6A100V / 2A, 240V / 0.84A132–163 BTU/h374.9 BTU/h32–104 F (0–40 C)32–104 F (0–40 C)-4–167 F (-20–75 C)-31–158 F (-35–70 C)10–85% relative humidity,non-operating, non-condensing20–90% non-condensingComplianceRegulatory ComplianceSafetyAll performance values are “up to” and vary depending on the system configuration.** Layer 7 CPS — measures number of new HTTP connections (1 HTTP request per TCP connection)** Tested with 1 HTTP request per SSL connection; SSL Ciphers AES256-SHA; 2K Keys7FCC Part 15 Class A, RCM, VCCI Class A, CE, UL/cCSA, C/US, CE, UL

DATA SHEET FortiADC SPECIFICATIONSFortiADC 300FFortiADC 400FFortiADC 1200FL4/L7 Throughput8 Gbps15 Gbps / 12 Gbps40 Gbps / 30 GbpsL4 CPS300,000400,0001,000,0001M1.5M3,000,000System PerformanceL4 HTTP RPSMaximum L4 Concurrent ConnectionL7 CPS (1:1) *SSL CPS/TPS (1:1) 2K keys **SSL Bulk Encryption ThroughputCompression ThroughputSSL Acceleration TechnologyVirtual 5,00035,0003 Gbps6 Gbps20 Gbps6 Gbps10 Gbps20 GbpsSoftwareASICASIC102045Hardware SpecificationsMemoryNetwork Interfaces10/100/1000 Management Interface16 GB32 GB32 GB4x GE RJ45, 4x GE SFP2x 10 GE SFP , 4x GE SFP, 4x GE RJ458x RJ45 GE port, 8x SFP GE port, 8xSFP 10G Ports——2128 GB SSD120 GB SSD240 GB SSDManagementHTTPS, SSH CLI,Direct Console DB9 CLI, SNMPHTTPS, SSH CLI,Direct Console DB9 CLI, SNMPHTTPS, SSH CLI,Direct Console DB9 CLI, SNMPPower SupplySingleSingle (optional Redundant PS)Dual1.73 x 21.5 x 17.3StorageDimensionsHeight x Width x Length (inches)1.73 x 17.24 x 16.381.73 x 17.24 x 16.38Height x Width x Length (mm)44 x 438 x 41644 x 438 x 41644 x 548 x 440Weight20 lbs (9.07 kg)20 lbs (9.07 kg)22.5 lbs (10.2 kg)EnvironmentForm FactorInput VoltagePower Consumption (Average / Maximum)Maximum CurrentHeat DissipationOperating TemperatureStorage TemperatureHumidity1U Appliance1U Appliance1U Appliance100–240V AC, 50–60 Hz, 5-3A100–240V AC, 50–60 Hz, 5-3A100–240V AC, 50–60 Hz90 W / 99 W114 W / 137 W251 W / 320 W100-240V AC / 6-3A, 50/60 Hz100–240V AC, 50–60 Hz, 5-3A120V / 7.1A, 240V / 3.5A337.8 BTU/h467.4 BTU/h856 BTU/h32–104 F (0–40 C)32–104 F (0–40 C)32–104 F (0–40 C)-13–167 F (-25–75 C)-13–167 F (-25–75 C)-4–167 F (-20–75 C)5–95% non-condensing5–95% non-condensing10–85% non-condensingComplianceRegulatory ComplianceSafetyFCC Part 15 Class A, RCM, VCCI Class A, CE, UL/cCSA, C/US, CE, ULAll performance values are “up to” and vary depending on the system configuration.** Layer 7 CPS — measures number of new HTTP connections (1 HTTP request per TCP connection)** Tested with 1 HTTP request per SSL connection; SSL Ciphers AES256-SHA; 2K Keys88

DATA SHEET FortiADC SPECIFICATIONSFortiADC 2200FFortiADC 4200FFortiADC 5000F250 Gbps / 220 GbpsSystem PerformanceL4/L7 Throughput60 Gbps / 35 Gbps100 Gbps / 80 GbpsL4 CPS1,200,0001,800,0004ML4 HTTP RPS4,000,0005,000,00018,000,000Maximum L4 Concurrent Connection72,000,000144,000,000160,000,000L7 CPS (1:1) *280,000500,0001,100,000SSL CPS/TPS (1:1) 2K keys **40,00060,000100,000SSL Bulk Encryption Throughput25 Gbps50 Gbps120 GbpsCompression Throughput22 Gbps45 Gbps150 GbpsASICASICASIC609090SSL Acceleration TechnologyVirtual DomainsHardware SpecificationsMemoryNetwork Interfaces10/100/1000 Management Interface64 GB128 GB192 GB8x SFP ports, 12x 10GbE SFP ports4x 40GbE QSFP, 8x 10G SFP 4x 100 GE QSFP28, 8x 40 GE QSFP221240 GB SSD480 GB SSD960 GB SSDManagementHTTPS, SSH CLI,Direct Console DB9 CLI, SNMPHTTPS, SSH CLI,Direct Console DB9 CLI, SNMPHTTPS, SSH CLI,Direct Console DB9 CLI, SNMPPower SupplyDualDualDualHeight x Width x Length (inches)1.73 x 21.5 x 17.33.46 x 21.5 x 17.33.4 x 17.2 x 30.2Height x Width x Length (mm)44 x 548 x 44088 x 548 x 44080.6 x 436.9 x 777.222.5 lbs (10.2 kg)29.3 lbs (13.3 kg)68.3 lbs (31 kg)StorageDimensionsWeightEnvironmentForm FactorInput VoltagePower Consumption (Average / Maximum)Maximum CurrentHeat DissipationOperating TemperatureStorage TemperatureHumidity1U Appliance2U Appliance2U Appliance100–240V AC, 50–60 Hz100–240V AC, 50–60 Hz220–240V AC267 W / 340 W269 W / 360 W2200 W100V / 7A, 240V / 3.5A100V / 7A, 240V / 3.5A120V / 11.8A, 240V / 9.6A911 BTU/h917 BTU/h7506 BTU/hr32–104 F (0–40 C)32–104 F (0–40 C)50–95 F (10–35 C)-4–167 F (-20–75 C)-4–167 F (-20–75 C)-40–140 F (-40–60 C)10–85% non-condensing10–85% non-condensing8–90% non-condensingFCC/ ICES, CE, RCM, VCCI, BSMIFCC/ ICES, CE, RCM, VCCI, BSMICE, FCC, RCM, VCCI, BSMIUL/ cUL, CBUL/ cUL, CBUL, CB, IECComplianceRegulatory ComplianceSafetyAll performance values are “up to” and vary depending on the system configuration.** Layer 7 CPS — measures number of new HTTP connections (1 HTTP request per TCP connection)** Tested with 1 HTTP request per SSL connection; SSL Ciphers AES256-SHA; 2K Keys9

DATA SHEET FortiADC M04FORTIADC-VM08FORTIADC-VM16FORTIADC-VM32Hardware SpecificationsHypervisor SupportVMware ESX/ESXi, Citrix XenServer, Open Source Xen, Microsoft Hyper-V, KVM, AWS, Azure, Google Cloud, Oracle Cloud. Please see theFortiADC-VM Install Guide for the latest hypervisor versions supported.L4 Throughput*1 Gbps2 Gbps4 Gbps10 Gbps16 GbpsVirtual Domains10101010152012481632101010101010vCPU Support (Maximum)Memory Support (Maximum)24 GbpsUnlimitedNetwork Interface Support (Maximum)Storage Support (Minimum / Maximum)UnlimitedThroughputHardware DependentManagementHTTPS, SSH CLI, Direct Console DB9 CLI, SNMP* Actual performance values may vary depending on the network traffic and system configuration. Performance results were observed using an appliance with an Intel CPU E5-1650 v2 @ 3.50GHz running VMware ESXi 5.5.ORDER INFORMATIONProductSKUDescriptionFortiADC 100FFAD-100FFortiADC 100F, 6x GE ports, 1x 64 GB SSD storage.FortiADC 200FFAD 200FFortiADC 200F, 4x GE RJ45 ports, 2x GE SFP ports, 1x 64 GB SSD storage.FortiADC 300FFAD-300FFortiADC 300F, 4x GE RJ45 ports, 4x GE SFP ports, 2x GE management ports, 1x 128 GB SSD storage.FortiADC 400FFAD-400FFortiADC 400F, 4x GE RJ45 ports, 4x GE SFP ports, 2x 10 GE SFP ports, 2x management ports, 1x 480 GB SSD storage,Hardware SSL Accelerator, Optional Redundant PSU.FortiADC 1200FFAD-1200FFortiADC 1200F, 8x 10 GE SFP ports, 8x GE SFP ports, 8x GE RJ45 ports, 2x GE RJ45 management port, 1x 240 GB SSD, dualAC power supplies.FortiADC 2200FFAD-2200FFortiADC 2200F, 12x 10 GE SFP ports, 8x GE SFP ports, 2x GE RJ45 management port, 1x 240 GB SSD, dual AC power supplies.FortiADC 4200FFAD-4200FFortiADC 4200F, 4x 40 GbE QSFP , 8x 10 GbE SFP , 2x GbE RJ45 management port, 1x 480 GB SSD, dual AC power supplies.FortiADC 5000FFAD-5000FFortiADC 5000F, 4x 100 GE QSFP28, 8x 40 GE QSFP, 1x GE RJ45 management port, 1x 960 GB SSD, dual AC power supplies.FortiADC-VM01FAD-VM01FortiADC-VM software virtual appliance. Supports up to 1x vCPU core.FortiADC-VM02FAD-VM02FortiADC-VM software virtual appliance. Supports up to 2x vCPU cores.FortiADC-VM04FAD-VM04FortiADC-VM software virtual appliance. Supports up to 4x vCPU cores.FortiADC-VM08FAD-VM08FortiADC-VM software virtual appliance. Supports up to 8x vCPU cores.FortiADC-VM16FAD-VM16FortiADC-VM software virtual appliance. Supports up to 16x vCPU cores.FortiADC-VM32FAD-VM32FortiADC-VM software virtual applian

Load Balancing § Protection from the OWASP Top 10 application attacks § Multi-Deployment Mode with Hardware, VM, or Cloud Solution (PAYG/ BYOL) § SSL Security and Visibility with Hardware-based Solution § Automation and Fabric Connector to Third Party Solutions such as SAP, Cisco