A10 Thunder Series Application Delivery Controller (ADC)

Transcription

A10 Thunder SeriesApplication DeliveryController (ADC)Overview A10Networks, Inc.

Thunder ADC Solutions to Enhance Your BusinessAvailabilityAcceleration Scale Web and keyinfrastructure Provide fast andresponsive services Reduce downtime Competitiveadvantage Ensure businesscontinuity Drive down CAPEXand OPEX A10Networks, Inc.Security Protect againstadvanced andemerging attacks Protect brand andguard againstrevenue loss Meet requiredcompliancestandards2

Solutions

Enterprise Data Center Application availabilitySecurity:– To maintain uptime– SLB, GSLB, high-availability (HA),Health-checks, more Application accelerationDDoS MitigationWAFDAFAAMBackup Data CenterAcceleration:– For equipment consolidation andfaster user -checks– Caching, compression, networkoptimization, more A10 ADCSSL OffloadTCP ReuseRAM CachingCompression Application security services– For brand and asset protection whileenhancing your existing securityWeb App– FWLB, WAF, SSL services, more A10Networks, Inc.DNSOther App4

DMZ Security Solutions Scaling security devices andencrypted communications– SSL Intercept: Eliminate encryption blindspot and scale security appliancesA10 ADC– FWLB and SSL offload, more Firewall Load BalancingDDoS MitigationWAFDAFAAMTraffic SteeringaFleX ScriptingSSL OffloadFirewallsIDS/IPSDLPOther Defend against emergingDDoS attacks– Network and application protection Selectively apply dynamicsecurity chainsFirewall Load BalancingSSL InterceptA10 ADC– Traffic steering and advancedADC servicesData Center A10Networks, Inc.Internal Users5

Service Provider Solutions Optimized network efficiency andservices– Traffic steering and service chaining Enhanced service availability– Load balancing for Web, caches,Diameter, SIP, IPv4/IPv6 more Service Provider Networks A10Networks, Inc.6

Solving Customers’ Critical Business ChallengesADC services for millions of customersImproved reliability over legacy Cisco ACE load balancers whilekeeping costs down.Data center efficiency with large traffic volumesBest value to sustain very high traffic volume with the least capital andoperational expense, and all required features.Powering multiple internal and external servicesMulti-tenancy consolidates internal applications and external webservers ADC environment, reducing OPEX and CAPEX.Reducing costs by consolidating legacy appliancesA10 ADCs enable consolidation of racks of legacy load balancers foroperational efficiency and ease of management. A10Networks, Inc.7

Enhancing Key Applications Microsoft– Exchange and Lync certified, tested integrations includeSharePoint, IIS & more Oracle– Deployment guides for Application Server, E-business Suite,PeopleSoft Enterprise, Oracle Siebel CRM, WebLogic SAP– Reliability, security & performance certified for BusinessObjects Explorer (BOE), SAP Netweaver Portal & SAP CRM VMware– VMready certified, VMware View Other – Blackboard, Apache & more A10Networks, Inc.8

Application Availability

Application AvailabilityHighly available applications and data centersGlobal server loadbalancing (GSLB):High performanceserver load balancing:Intelligence forglobal operationsScaling capacity for peakloadsHigh availability:Health-checks:For uninterruptedoperationCompleteapplication faultdetection A10Networks, Inc.10

Performance and SLB: Scaling Capacity for Peak Loads Large capacity to handle high trafficvolumes in 1RUACOSperformanceNo restrictionsHardwareoffload– Up to 150 Gbps throughput– 5 M new sessions/sec– 256 M concurrent sessions Benefits:A10 ADC– Optimized for maximum performancewith ACOS– Hardware offload– All-inclusive performance onhardware appliancesData Center A10Networks, Inc.11

High Availability: For Uninterrupted Operation Eliminates the ADC as a point of failure Benefits:– Sub-second failover– Active-standby, active-active or N 1 options– Stateful failover to preserve sessionsA10 ADCData Center A10Networks, Inc.12

Health-checks: Complete Application Fault Detection Ensures servers are able to handleusers as intended Benefits:– Users always receive the optimalexperience– Ensures all components needed arefunctioningA10 ADC– Network, application (HTTP, DNS, more )or database health-checksUnreachable A10Networks, Inc.Componentdowne.g. databaseTrafficdirected toactive server13

GSLB: Intelligence for Global Operations Provides multi-data center resiliency Benefits:– Enables disaster recovery on failure oractive-active data centersGeo Site– Optimizes users to the best performingdata center (e.g. response time,geo-location, more )A10 ADC– Ensures user’s Web experience is the fastestData Center A10Networks, Inc.14

Application Acceleration

Application AccelerationApplication acceleration for a faster user experience and optimized utilizationTechnology for Application AccelerationTCP Optimization:Compression:Improve applicationperformanceOptimize anybandwidth levelRAM Caching:SSL Acceleration:Faster page loads equalmore revenueSecure applications A10Networks, Inc.16

TCP Optimization: Improve Application Performance Reduces TCP connectionmanagement overhead– TCP reuse (multiplexing) to offload serverconnection setup and tear downMany TCPConnections Benefits:– Increases overall server capacityA10 ADC– Reduction in connectionsReduced TCPConnections– Improved response times lessrequired servers Details:– Server TCP stack offload– Persistent connection to serversData Center A10Networks, Inc.17

SSL Acceleration: Secure Applications Offloads compute intensive SSL traffic– Hardware security processor assist Benefits:SecuredHTTPS– Eliminates high SSL CPU overheadfrom servers– Servers support many more transactionsper secondA10 ADCUnsecuredHTTP– Simpler certificate management Details:– 4096-, 2048-, and 1024-bit keys– 2x key size 3x to 7x drop in legacySLBs capacityData Center A10Networks, Inc.18

RAM Caching: Faster Page Loads Equal More Revenue RAM Cached objects served from theThunder ADCRepeatedRequestsServed FromCache– Eliminates repetitive fetches for frequentlyrequested objects Benefits:– Faster response to the end userA10 ADC– Reduce connections and server requests– Reduce servers due to offloaded traffic Details:– Static or dynamic support– Extensive object type supportData Center A10Networks, Inc.19

Compression: Optimize Any Bandwidth Level Reduces transmission size for HTTP– Smaller payload to transfer to the end user Benefits:CompressedTraffic– Optimize traffic for international, mobile,legacy devices, etc.– Faster delivery to end-userA10 ADC– Offloads Web server CPU cyclesUncompressedTraffic Details:– Gzip & deflate encoding support– Hardware or software optionsData Center A10Networks, Inc.20

Application Security

Application SecurityEnhance existing security infrastructure, and protect against the latest threatsWeb applicationfirewall (WAF):DDoS protection:Multi-vector edgeprotectionEliminate common WebattacksApplication accessmanagement (AAM):Add authenticationseamlesslySSL intercept:Eliminate theoutbound SSLblind spot A10Networks, Inc.DNS applicationfirewall (DAF):Protect criticalinfrastructure22

WAF: Eliminate Common Web Attacks Benefit:– Protect web applications– Ensure against code vulnerabilities and assistPCI-DSS/HIPAA compliancy– Prevent damage to intellectual property,data and applications Advantage:– Fully integrated/designed for ACOS– No license; single device solution– Scalable and high performance A10Networks, Inc.23

AAM: Add Authentication Seamlessly Benefit:AuthenticationAccessAccess RequestChallengeGrantedRequestSuccess– User authentication required for resource access– Enhanced protection and server efficiency– Authentication offload Advantage:AAM– Supports popular authentication services/stores– No adjustment to web servers or infrastructure– Seamless integration A10Networks, Inc.24

SSL Intercept: Eliminate the Outbound SSL Blind Spot Benefit:Server4– Eliminate encryption blind spot to inspectencrypted traffic, including malware andadvance persistent threats (APTs)encrypted3 Advantage:– Optimized decryption with dedicated securityprocessors for CPU intensive 2048-bit keys– Offloads firewalls that can’t scaleSSL decryptionA10 ADCInspection/ProtectionDLPUTMIDSOther2– Freedom to work with any trafficinspection/mitigation devicedecrypted5A10 ADC16encryptedClient A10Networks, Inc.25

DAF: Protect Critical Infrastructure Benefit:– Uninterrupted DNS servicesRegular ClientsPerform asExpected– Protects vulnerable infrastructure– Ensures infrastructure cannot be aweapon against a 3rd party Advantage:“Zombies”Malicious andInfected ClientsInvalid Non-DNSGenerating Requests Traffic on Port 53Denied– Blocks non-DNS traffic (up to 70%)– Surge protectionOptional Maliciousand Invalid TrafficRedirection– Full DNS command set (aFleXand built-in)Surge ProtectionAllowed– Redirection for “honey pots”DNS InfrastructureResult Reduced and OptimizedCPU Usage A10Networks, Inc.26

DDoS Protection: Multi-vector Edge Protection Benefits:– Large-scale DDoS protection– Advanced protection features– Predictable operations RateaFleXSYNMore gControl– Full DDoS defense covers network andapplication attacks– Hardware DDoS protection for common attacks– SYN flood protection to 200 M per second A10Networks, Inc.27

Thunder Management

Comprehensive Management Options Comprehensive management options for operational simplicity and reducedmanagement cost– CLI and GUI: Ease of Use and Management– aFleX: Comprehensive DPI and traffic management– aXAPI scripting: Customizable management options for integration– aGalaxy: Centralized and automated operations for lower TCO– 3rd party integrations: SDN and Cloud orchestration integration– Other management options: Application delivery partitions and layer 3 virtualization (ADP/L3V) Virtual chassis system (aVCS) A10Networks, Inc.29

GUI and CLI: Ease of Use and Management GUI (Graphical User Interface)– Fewer screens and steps for tasks– Intuitive and easy to use CLI (Command Line Interface)– Industry standard CLI, familiar interface– Easy to use, comprehensive help A10Networks, Inc.30

aFleX: Comprehensive DPI and Traffic ManagementExample: Automatically displays a Web pagebased on the user’s language, using thelanguage set in the user’s browser. Deep packet inspection andscripting technology Benefits– Adjust traffic and L7 data as needed– Fix or optimize applications– Complete traffic controlEnglishChinese Japanese Spanish A10Networks, Inc.31

aXAPI: Customizable Management Options for Integration Integrate into 3rd-Party Applications– Reporting– Centralized configuration management– Provisioning Custom Management Solutions– Integrated into homegrown apps versususing the A10 CLI or GUI Interactive Infrastructure– Applications can issue triggers to changetraffic management behavior based onexternal events A10Third-party ApplicationAuthentication request,containing Thunderadmin username andpassword.Configuration ormonitoring request,containing the session IDNext configuration ormonitoring request,containing the session IDThird-party applicationsends session closerequest or allows sessionto time out.Networks, Inc.aXAPIIf authentication issuccessful, Thunder replieswith a session ID and status200 - okIf session ID is Valid, andsession has not timed outor been closed, Thunderperforms the requestedaction and replies withstatus 200 - OKThunder performsrequested action, if sessionID is valid and session hasnot timed out or beenclosed32

aGalaxy: Centralized/Automated Operations for Lower TCO A central network managementsystem for all A10 devices Benefits:– Automate repetitive tasks andeliminate human error– Centralized control of events andconfiguration– Faster operation for reduced OPEX A10Networks, Inc.33

3rd-Party Integrations: SDN/Cloud Orchestration Integration Achieve automation, operational agility, andreduced TCO SDN integration– Overlay & fabric integration– VXLAN and NVGRE– IBM SDN-VE, Cisco APIC, VMware NSX Cloud orchestration integration– Policy integration with Cloud orchestration platforms– aGalaxy, Microsoft SCVMM, VMware vCloudDirector, OpenStack A10Networks, Inc.34

Other Management Options: ADP/L3V and aVCS aVCS clustering ADP and L3V Multi-tenancy– Multi-tenancy for consolidation– Single point of management– Separate admin look and feel,overlapping IP addresses– Scale up to 8 units in a cluster– Scale to 1.2 Tbps in a cluster– Up to 128 partitions 1000 L3V partitions A10Networks, Inc.35

Product Portfolio, ACOSand ADC Form Factors

Thunder ADCRichfeatures Server loadbalancing andapplication delivery Acceleration Security (WAF, SI,DAF, DDoS, more )Flexibledeployment Broad array of formfactors– Virtual– Physical– Hybrid For on premise orcloud deploymentsSmartdesign Designed foroptimalperformance Delivering maximumuptime Green, data centerfriendly designEnabling Highly Available, Accelerated and Secure Applications A10Networks, Inc.37

ACOS: Best-in-Class Performance ScalabilityEfficient &Accurate MemoryArchitecture64-Bit Multi-CoreOptimizedShared Memory izedFlow DistributionFlexible Traffic AcceleratorSwitching and Routing A10Networks, Inc.38

Thunder ADC Hardware Appliances79/78 Gbps (L4/L7)3.7M L4 CPS20M RPS (HTTP)SSL ProcessorHardware FTA79/78 Gbps (L4/L7)6M L4 CPS32.5M RPS (HTTP)SSL ProcessorHardware FTA150/145 Gbps (L4/L7)5.3M L4 CPS31M RPS (HTTP)SSL ProcessorHardware FTA150/145 Gbps (L4/L7)7.1M L4 CPS38M RPS (HTTP)SSL ProcessorHardware FTAThunder 6630 ADCThunder 6430(S) ADCPriceThunder 5630 ADCThunder 5430(S)-11 ADC5 Gbps (L4&L7)200k L4 CPS1 M RPS (HTTP)10 Gbps (L4&L7)450k L4 CPS2M RPS (HTTP)SSL Processor30 Gbps (L4&L7)750k L4 CPS3M RPS (HTTP)SSL Processor77/75 Gbps (L4/L7)2.8M L4 CPS17M RPS (HTTP)SSL ProcessorHardware FTA38 Gbps (L4&L7)2.7M L4 CPS11M RPS (HTTP)Thunder 5430S ADCThunder 4430(S) ADCThunder 3030S ADCThunder 1030S ADCThunder 930 ADCPerformance A10Networks, Inc.39

vThunder Software AppliancesvThunder (Perpetual Licensing) High-performance8 GbpsPrice 200 Mbps to 8 GbpsVMware, KVM, Hyper-V & XenhypervisorsDynamic provisioning, faster roll outScale up or down on-demandHigh-performance4 GbpsEntry Level/Lab1 GbpsEntry Level/Lab200 MbpsLab EditionPerformance A10Networks, Inc.40

Other vThunder Appliances and Flexible Billing OptionsvThunder for AWS Rent (RBM)Utility (UBM)License per MonthLicense per BytevThunder Pay-as-You-GoLicensing10 Mbps to 1 Gbps licensing1 click provisioning of 64-bit AmazonMachine Image (AMI)EC2 or VPC environmentsNo feature limitations; licensed bybandwidthBYOL perpetual license or hourly basedlicense A10Networks, Inc.Elastic & adaptive“Pay-as-you-Go” meteringAutomated licensingFor IaaS providers only41

Thunder Hybrid Virtual Appliance (HVA) Why HVA?– Hardware acceleration– Deploy instances on demand– Strong hypervisor-based isolation Advantage:– Hardware performance, virtual flexibilityPrice– Consolidation– OpenStack managementThunder 3530S HVAThunder 3030S HVA40 instances,100 Gbps8 instances,35 Gbps– SR-IOV support for network and SSLaccelerationPerformance– No performance or feature licenses A10Networks, Inc.42

Summary

Thunder Buzz“Provides substantial value very high performance platforms,but only 1RU in size ”Mark Fabbi, Gartner Source: NetworkWorld“ simplify our IT environment to“ provide value and efficientmeet and exceed service levelnetworking to our customers.”agreements for all of our users.”Jeff Doyle, Vice President ofGeorge Hamin, Director eBusiness &Engineering, TorreyPointInformation Systems for Subaru Canada, Inc. A10Networks, Inc.44

Summary – Thunder ADCs for Today’s Application Concerns Provides a better application experience, while optimizing your environment Provides essential application delivery features– Availability– Acceleration– Security Broad array of high performance Thunder form factors– Physical, hybrid, virtual and cloud A10Networks, Inc.45

vThunder Free Trial – Try Today Visit www.a10networks.com– 30 days, 5 Mbps limit– Full features– For VMware, Hyper-V, KVM and Xen A10Networks, Inc.46

THANK YOUwww.a10networks.com

A10 Networks, Inc. 25 Benefit: – Eliminate encryption blind spot to inspect encrypted traffic, including malware and advance persistent threats (APTs) Advantage: – Optimized decryption with dedicated security processors for CPU intensive 2048-bit keys – Offloads f