A10 DS 15100 en 1
A10 DS 15100 en 1
A10 DS 15100 en 1
THUNDER ADC
APPLICATION DELIVERY CONTROLLER & LOAD BALANCER
PLATFORMS
Offering a complete application optimization solution,
A10 Thunder® ADC (Application Delivery Controller) processes THUNDER ADC
Physical & SPE Appliances
a complex set of functions simultaneously via the industry’s
V
highest-performing appliances. It integrates advanced L4-7
vTHUNDER ADC
techniques to ensure server availability, protect vulnerable Virtual Appliance
THUNDER ADC
AGILE APPLICATION Thunder ADC delivers the capacity,
scalability, multi-tenancy and
Container
TALK
reduce downtime, ensure business continuity A10’s Advanced Core Operating System
and builds highly available applications and (ACOS®) platform, Thunder ADC delivers
environments. application performance and security for
any environment. WITH A10
WEB
a10networks.com/adc
1
BENEFITS
APP
ENHANCE SECURE
APPLICATION AVAILABILITY COMMUNICATIONS
ENSURE PROTECT
BUSINESS CONTINUITY VULNERABLE APPLICATIONS
worldwide, administrators must catch most, but typically not all, coding
ACCELERATE
CONTENT DELIVERY
2
OPTIMIZE CONSOLIDATE
APPLICATIONS VIA MULTI-TENANCY ACCESS CONTROL
To optimize the delivery and security for Organizations must allow external
potentially hundreds of apps in a given clients access to web portals, internal
data center, IT administrators need a resources and mobile/BYOD apps. At the
multi-tenant methodology. same time, security must be maintained
with authentication and be transparent
Thunder ADC provides the ability to
to the user.
granularly program more than 1,000
individual partitions on a single appliance Thunder ADC centrally manages multiple
for tailor-made policies by application, facets of authentication, authorization
service or user, as well as achieve and accounting (AAA) with a system-
appliance consolidation. wide perspective, while eliminating
separate authentication points, for a
single sign-on (SSO) experience.
PROACTIVE
INFRASTRUCTURE MODIFICATIONS
THUNDER
220/200 Gbps 100 44M 10.5M
7440-11 ADC
BY THE NUMBERS
L4/L7 Application
Throughput
GbE
Ports
L4
HTTP RPS
L4 Connections
Per Second
1,023 75 Gbps
Application SSL Bulk
Delivery Throughput*
* With Maximum SSL Partitions (L3V)
3
REFERENCE ARCHITECTURES
INTERNET
HARMONY
CONTROLLER
AVAILABILITY SECURITY
GSLB WAF
High Availability DAF
Health Checks AAM (SSO)
Server Load Balancing DDoS Mitigation
ACCELERATION
THUNDER ADC SSL Offload
TCP Reuse
RAM Caching
Compression
INTERNET
THUNDER ADC THUNDER ADC DNS SERVERS
Traffic Steering DNS SLB
MOBILE USERS SLB DNS Application Firewall
Service Chaining
APPLICATION DELIVERY
PARTITIONS
INTERNAL USERS
4
FEATURES
ADVANCED GLOBAL
SERVER LOAD BALANCING SERVER LOAD BALANCING (GSLB)
BROAD HIGH-DENSITY
ACCELERATION METHODOLOGIES
APPLICATION DELIVERY PARTITIONS
Leverage numerous techniques to
Provide support for multi-tenant
overcome inherent distance-related
environments with application
latency, inefficient internet protocols
delivery partitions (ADP). They allow
and application design limitations.
the configuration of more than 1,000
Acceleration methods, including TCP
partitions on a single Thunder ADC
connection multiplexing, RAM caching,
appliance, which enables Layer 3
GZIP compression and SSL-offload,
virtualization. Each partition may be
expedite content transfer. The solution
configured for a unique set of policies
supports TCP optimization standards,
and offers resource isolation for most
such as selective acknowledgment,
application-oriented use cases.
client keep-alive and window scaling, to
further speed delivery.
5
ULTRA LOW
LATENCY
FOR FINANCIAL APPLICATIONS
APPLICATION SECURITY
EXTENSIVE APPLICATION
CIPHER SUITE SUPPORT AUTHENTICATION & SSO
6
ZERO-DAY POWERFUL
APPLICATION PROTECTION DNS FIREWALL
DNS
An ICSA-certified web application Thunder ADC incorporates a
firewall (WAF) guards vulnerable sophisticated DNS application firewall
software from dozens of application (DAF) to stop buffer overflows,
layer attacks, including the Open Web malformed requests and head off DNS
Application Security Project (OWASP) amplification-based DDoS attacks.
top-10 threats. These attacks include It delivers validated DNSSEC pass-
cross-site request forgery, SQL injection through support to prevent threats such
and buffer overflows that target coding as DNS cache-poisoning and spoofing.
flaws. Integrated into Thunder ADC, the In addition, the ADC can load-balance
WAF blocks these and other application multiple DNS servers and cache DNS
behavior anomaly attacks, as well as responses to provide scalability to DNS
prevents unauthorized data leakage. servers.
SERVER THREAT
DDOS PROTECTION
INTELLIGENCE
DDoS protection is standard in all SERVICE
appliances. With FTA-based hardware
An optional subscription, the A10 Threat
models, using field-programmable
Intelligence Service provides data from
gate arrays (FPGA), protection may
more than three dozen security sources,
be enabled for high-volume attacks
including DShield and Shadowserver.
against application servers. FPGAs
The service enables Thunder ADC to
mitigate common volumetric attacks,
instantly recognize and block traffic to
while general-purpose CPUs mitigate
and from known malicious IP address
more sophisticated low-and-slow and
sources. The service protects networks
application attacks, such as Slowloris
from future threats, blocks threats
and HTTP floods. Additional methods
such as spam and phishing, and greatly
to limit unwarranted data floods include
increases Thunder ADC efficiency.
connection rate limiting and bandwidth
rate limiting per source IP.
CERTIFIED BY The integrated Thunder ADC web application firewall has achieved WAF
ICSA LABS certification from ICSA Labs. ICSA Labs testing and certification ensures
that Thunder ADC performs as intended to secure application services from
exploitation and attack.
7
APPLICATION VISIBILITY & MANAGEMENT
RICH FULLY
ANALYTICS AND VISIBILITY
>_ PROGRAMMABLE
When deployed in conjunction with the The Thunder ADC platform leverages
A10 Harmony Controller, Thunder ADC A10’s REST-based aXAPIs to configure
provides access to dozens of aggregate all features with 100 percent API
or per-request metrics in real-time. coverage. This interface is used to
These include end-to-end response integrate with third-party or custom
times, latency, popular URLs, and error management consoles, such as SDN
and health indicators. This data is platforms (e.g., Cisco ACI and VMware)
analyzed to provide per-app reporting and cloud orchestration systems (e.g.,
and alerts on availability, security and OpenStack and Microsoft SCVMM). A
performance. software plug-in is available for private
clouds leveraging vRealize Orchestrator
Detailed Layer 4 based analytics
from VMware.
information is separately provided by
individual clients, ADC (single appliance
or as a cluster) and per server.
SMART COMPREHENSIVE
TEMPLATES MANAGEMENT TOOLS
To optimally deliver server content, the Thunder ADC is supported by the A10
ADC front-ending the application should Harmony Controller; this controller is a
be ‘tuned’ with configurations that best centralized management platform that
fit the needs of that application; that coordinates and distributes application
takes time and iterative efforts to get centric service policies and configuration
the ideal settings. files to hundreds of Thunder appliances
and device cluster infrastructures
Thunder ADCs equipped with
across multi-cloud environments.
AppCentric Templates (ACT) bypass
Administrators can automatically
this step by providing select business-
discover, track and monitor each
critical applications — from Microsoft
appliance including key operational
(e.g., Exchange, Skype for Business
metrics such as CPU and disk usage as
and SharePoint), Oracle and many
well as device partitions and users. The
more — with predefined templates that
controller performs configuration backup
include the key policy settings on a per-
and restore operations and schedules
application basis for rapid deployment.
software upgrades.
8
APPLICATION SERVER VIEW
Thunder ADC with Harmony Controller provides
detailed analytics from the server perspective.
Including server health, response times, number
of new and existing connections. Multiple filtering
options customize the reports.
CLIENT VIEW
The experience from the end-user perspective
may be measured and reported. Includes end-
to-end latency, app server latency and client
performance.
9
THUNDER ADC PHYSICAL APPLIANCE
THUNDER THUNDER THUNDER THUNDER THUNDER
PERFORMANCE 840 ADC 930 ADC 940 ADC 1030S ADC 1040 ADC
Application Throughput (L4/L7) 5 Gbps / 5 Gbps 5 Gbps / 5 Gbps 10 Gbps / 7.5 Gbps 10 Gbps / 10 Gbps 20 Gbps / 20 Gbps
SSL CPS *2
RSA (1K): 2K RSA (1K): 1.9K RSA (1K): 2K RSA (1K): 25K RSA: 15K*7
RSA (2K): 500 RSA (2K): 400 RSA (2K): 1k RSA (2K): 7K ECDSA: 15K*7
DDoS Protection (SYN Flood) SYN/sec 1.7 Million 2 Million 2 Million 4 Million 4 Million
NETWORK INTERFACE
1 GE Copper 5 6 5 6 5
1 GE Fiber (SFP) 0 2 0 2 0
HARDWARE SPECIFICATIONS
Intel Intel Intel
Intel Xeon Intel Xeon
Processor Communications Communications Communications
2-core 4-core
Processor Processor Processor
SSL Security Processor ('S' Models) N/A N/A N/A Yes Yes
1.75 (H) x 17 (W) x 1.75 (H) x 17.5 (W) x 1.75 (H) x 17.5 (W) x 1.75 (H) x 17.5 (W) x 1.75 (H) x 17.5 (W) x
Dimensions (inches)
12 (D) 17.45 (D) 17.25 (D) 17.45 (D) 17.25 (D)
Single 150W (AC only) Single 600W*6 Single 750W*6 Single 600W*6 Single 750W*6
Power Supply (DC option available)
100 - 240 VAC 50-60Hz 80 Plus Platinum efficiency, 100 - 240 VAC, 50 – 60 Hz
Power Consumption (Typical/Max)*3 57W / 75W 66W / 76W 60W / 80W 98W / 108W 80W / 110W
Cooling Fan Single Fixed Fan Hot Swap Smart Fans Removable Fans Hot Swap Smart Fans Removable Fans
FCC Class A, UL, CE, FCC Class A, UL, CE, FCC Class A, UL, CE, FCC Class A, UL, CE, FCC Class A, UL, CE,
TUV, CB, VCCI, CCC, TUV, CB, VCCI, CCC, GS, CB, VCCI, CCC, TUV, CB, VCCI, CCC, GS, CB, VCCI, CCC,
Regulatory Certifications
BSMI, RCM | RoHS MSIP, BSMI, RCM, FAC BSMI^, RCM^ | RoHS KCC, BSMI, RCM, FAC | BSMI^, RCM^ | RoHS
| RoHS RoHS, CC EAL2+
10
Thunder ADC Physical Appliance Specifications (Cont.)
SSL CPS *2
RSA (1K): 47K RSA: 30K RSA: 28K*7
RSA (2K): 14K ECDSA: 20K ECDSA: 28K*7
DDoS Protection (SYN Flood) SYN/sec 7.5 Million 8 Million 7.5 Million
1 GE Fiber (SFP) 2 2 18 2 2
25 GE Fibers (SFP28) 0 0 0 0 4
40 GE Fiber (QSFP+) 0 0 0 0 4
HARDWARE SPECIFICATIONS
Processor Intel Xeon Intel Xeon Intel Xeon Intel Xeon Intel Xeon
4-core 4-core 8-core 8-core 8-core
Dimensions (inches) 1.75 (H) x 17.5 (W) x 1.75 (H) x 17.5 (W) x
1.75 (H) x 17.5 (W) x 18(D)
17.45 (D) 17.45 (D)
11
Thunder ADC Physical Appliance Specifications (Cont.)
PERFORMANCE 3230 ADC 3430 ADC 4430 ADC 4440 ADC 5330 ADC
Application Throughput (L4/L7) 30 Gbps / 30 Gbps 42 Gbps / 42 Gbps 38 Gbps / 38 Gbps 80 Gbps / 80 Gbps 78 Gbps / 78 Gbps
Layer 4 CPS 1.5 Million 2.5 Million 2.7 Million 2.9 Million 3.1 Million
Layer 4 Concurrent Sessions 64 Million 128 Million 128 Million 128 Million 128 Million
SSL CPS *2
RSA: 40K RSA: 45K RSA (1K): 86K RSA: 70K RSA: 70K
ECDSA: 26K ECDSA: 32K RSA (2K): 84K ECDSA: 42K ECDSA: 50K
DDoS Protection (SYN Flood) SYN/sec 55 Million 55 Million 55 Million 166 Million 112 Million
NETWORK INTERFACE
1 GE Fiber (SFP) 4 4 0 0 0
40 GE Fiber (QSFP+) 0 0 4 4 0
Management Ports Ethernet Mgmt port, RJ-45 console port, Lights Out Management
HARDWARE SPECIFICATIONS
Processor Intel Xeon Intel Xeon Intel Xeon Intel Xeon Intel Xeon
4-core 6-core 6-core 6-core 10-core
SSL Security Processor ('S' Models) Yes Yes Yes Yes Yes
Dimensions (inches) 1.75 (H) x 17.5 (W) x 1.75 (H) x 17.5 (W) x 1.75 (H) x 17 (W) x 1.75 (H) x 17.5 (W) x 1.75 (H) x 17.5 (W) x
17.15 (D) 17.15 (D) 24.6 (D) 30 (D) 17.15 (D)
Dual 600W RPS Dual 600W RPS Dual 600W RPS Dual 1100W RPS Dual 600W RPS
Power Supply (DC option available)
80 Plus Platinum efficiency, 100 - 240 VAC, 50 – 60 Hz
Heat in BTU/hour (Typical/Max)*3 648 / 819 717 / 887 908 / 1,088 1,229 / 1,519 717 / 887
Regulatory Certifications FCC Class A, UL, CE, FCC Class A, UL, CE, FCC Class A, UL, CE, FCC Class A, UL, CE, FCC Class A, UL, CE,
GS, CB, VCCI, CCC, GS, CB, VCCI, CCC, TUV, CB, VCCI, CCC, GS, CB, VCCI, CCC, KCC, GS, CB, VCCI, CCC,
KCC, BSMI, RCM, NEBS KCC, BSMI, RCM, NEBS KCC, BSMI, RCM, NEBS BSMI, RCM | RoHS, BSMI, RCM, NEBS |
| RoHS | RoHS | RoHS, CC EAL2+ FIPS 140-2^|*5 RoHS
12
Thunder ADC Physical Appliance Specifications (Cont.)
Layer 4 Concurrent Sessions 256 Million 256 Million 256 Million 256 Million
Layer 7 CPS (1:1)*1 950K 1.5 Million 1.5 Million 1.5 Million
SSL CPS *2
RSA: 100K RSA (1K): 180K RSA: 150K RSA: 150K
ECDSA: 60K RSA (2K): 174K ECDSA: 90K ECDSA: 90K
DDoS Protection (SYN Flood) SYN/sec 166 Million 100 Million 166 Million 166 Million
NETWORK INTERFACE
1 GE Fiber (SFP) 0 4 0 0
40 GE Fiber (QSFP+) 4 4 4 0
Management Ports Ethernet Mgmt port, RJ-45 console port, Lights Out Management
HARDWARE SPECIFICATIONS
Processor Intel Xeon 2 x Intel Xeon
Intel Xeon 18-core Intel Xeon 18-core
12-core 8-core
Dimensions (inches) 1.75 (H) x 17.5 (W) x 30 (D) 5.3 (H) x 16.9 (W) x 28 (D) 1.75 (H) x 17.5 (W) x 30 (D) 1.75 (H) x 17.5 (W) x 30 (D)
Dual 1100W RPS 2+2 1100W RPS Dual 1100W RPS Dual 1500W RPS
Power Supply (DC option available)
80 Plus Platinum efficiency, 100 - 240 VAC, 50 – 60 Hz
Power Consumption (Typical/Max)*3 360W / 445W 780W / 890W 375W / 470W 550W / 760W
Regulatory Certifications
FCC Class A, UL, CE, GS, CB, FCC Class A, UL, CE, TUV, CB, FCC Class A, UL, CE, GS, CB, FCC Class A, UL, CE, GS,
VCCI, CCC, BSMI, RCM | RoHS, VCCI, KCC^, EAC, FAC | RoHS, VCCI, CCC, BSMI, RCM | RoHS, CB, VCCI, CCC^, BSMI, RCM
FIPS 140-2^|*5 CC EAL2+ FIPS 140-2^|*5 | RoHS^
13
Thunder ADC Physical Appliance Specifications (Cont.)
SSL CPS *2
RSA (1K): 180K RSA (1K): 200K RSA (1K): 200K
RSA (2K): 180K RSA (2K): 200K RSA (2K): 200K
DDoS Protection (SYN Flood) SYN/sec 332 Million 332 Million 332 Million
NETWORK INTERFACE
1/10 GE Fiber (SFP+) 48 48 48
40 GE Fiber (QSFP+) 4 4 0
Management Ports Ethernet Mgmt port, RJ-45 console port, Lights Out Management
HARDWARE SPECIFICATIONS
Processor 2 x Intel Xeon 2 x Intel Xeon 2 x Intel Xeon
10-core 18-core 18-core
Dimensions (inches) 1.75 (H) x 17.5 (W) x 30 (D) 1.75 (H) x 17.5 (W) x 30 (D) 1.75 (H) x 17.5 (W) x 30 (D)
Regulatory Certifications
FCC Class A, UL, CE, GS, CB, VCCI, CCC, FCC Class A, UL, CE, GS, CB, VCCI, CCC, FCC Class A, UL, CE, GS, CB, VCCI, CCC^,
BSMI, RCM | RoHS KCC, BSMI, RCM | RoHS, FIPS 140-2*5 KCC^, BSMI, RCM | RoHS^, FIPS 140-2^|*5
The specifications, performance numbers are subject to change without notice, and may vary depending on configuration and environmental conditions.
As for network interface, it’s highly recommended to use A10 Networks qualified optics/transceivers to ensure network reliability and stability.
*1 Layer 7 connections per second - measures number of new HTTP connections (1 HTTP request per TCP connection, without TCP connection reuse ) within 1 second | *2 Tested
with maximum SSL option. Products showing both RSA and ECDSA are tested using 3rd generation SSL card(s). Cipher “TLS_RSA_WITH_AES_128_CBC_SHA256” with RSA 2K keys,
unless noted, are used for RSA cases, “TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256” with EC P-256 are used for PFS cases. | *3 With base model. Number varies by SSL model |
*4 With maximum SSL option | *5 For FIPS 140-2 Level 2 validated, FIPS models must be purchased | *6 Optional RPS available | *7 Tested with session ticket TLS extension enabled
on the 4th gen SSL model (QSSL) | *8 10Gbps speed only | ^ Certification in process
14
THUNDER ADC SPE PHYSICAL APPLIANCE
THUNDER THUNDER
NETWORK INTERFACE
1/10 GE Fiber (SFP+) 16 16
40 GE Fiber (QSFP+) 0 4
Management Ports Ethernet Mgmt port, RJ-45 console port, Lights Out Management
HARDWARE SPECIFICATIONS
Processor (Intel Xeon) 10-core 10-core
Dimensions (inches) 1.75 (H) x 17.5 (W) x 30 (D) 1.75 (H) x 17.5 (W) x 30 (D)
Regulatory Certifications FCC Class A, UL, CE, TUV, CB, VCCI, CCC, MSIP, BSMI, FCC Class A, UL, CE, TUV, CB, VCCI, CCC, BSMI, RCM,
RCM, EAC, NEBS | RoHS EAC, NEBS | RoHS
The specifications, performance numbers are subject to change without notice, and may vary depending on configuration and environmental conditions.
As for network interface, it’s highly recommended to use A10 Networks qualified optics/transceivers to ensure network reliability and stability.
*1 Layer 7 connections per second - measures number of new HTTP connections (1 HTTP request per TCP connection, without TCP connection reuse ) within 1 second
*2 Tested with maximum SSL option, using cipher “TLS_RSA_WITH_AES_128_CBC_SHA” with RSA 2K keys | *3 With base model. Number varies by SSL model
*4 With maximum SSL option
15
THUNDER ADC FOR LOW LATENCY
PHYSICAL APPLIANCE
THUNDER
PERFORMANCE 4435
Mean Latency L7 3.9 µs
Jitter L7 0.4 µs
NETWORK INTERFACE
1/10 GE Fiber (SFP+) 16
Management Ports Ethernet Mgmt port, RJ-45 console port, Lights Out Management
HARDWARE SPECIFICATIONS
Processor (Intel Xeon) 10-core
Storage SSD
Regulatory Certifications FCC Class A, UL, CE, TUV, CB, VCCI, CCC, MSIP, BSMI, RCM, EAC, NEBS | RoHS
The specifications, performance numbers are subject to change without notice, and may vary depending on configuration and environmental conditions.
As for network interface, it’s highly recommended to use A10 Networks qualified optics/transceivers to ensure network reliability and stability.
16
vTHUNDER ADC VIRTUAL APPLIANCE
vTHUNDER ADC
Supported Hypervisors VMware ESXi 5.0 or higher (VMXNET3, SR-IOV, PCI Passthrough)
KVM QEMU 1.0 or higher (VirtIO, OvS with DPDK, SR-IOV, PCI Passthrough)
Microsoft Hyper-V on Windows Server 2008 R2 or higher
Bandwidth Licenses Lab 200 Mbps 1 Gbps 4 Gbps 8 Gbps 10 Gbps 20 Gbps 40 Gbps 100 Gbps FlexPool
*1 *1|*2 *2
KVM • • • • • Yes
+
Microsoft Hyper-V • • • • •+ Yes
*1
SR-IOV
*2
PCI Passthrough
+
8 Gbps license not recommended for Microsoft Hyper-V
Licenses 30-days Trial License 30-days Trial License 30-days Trial License
Pre-installed Bnadwidth License: Pre-installed Bandwidth License: Pre-installed OCPU based License:
- 200 Mbps, 500 Mbps, 1 Gbps - 10 Mbps, 50 Mbps, 100 Mbps, - 1 OCPU to 24 OCPU
BYOL Bandwidth License: 200 Mbps, 500 Mbps BYOL Bandwidth License:
- Lab/Developer, 200 Mbps, 1 Gbps, BYOL Bandwidth License: - Lab/Developer, 200 Mbps, 1 Gbps,
4 Gbps, 10 Gbps - Lab/Developer, 200 Mbps, 500 Mbps, 4 Gbps, 10 Gbps
FlexPool License: 1 Gbps, 4 Gbps, 10 Gbps FlexPool License:
- Up to 10 Gbps FlexPool License - Up to 10 Gbps
- Up to 10 Gbps
Reference Platforms Cisco UCS, Dell PowerEdge, Ericsson Hyperscale Datacenter System (HDS), HP ProLiant and more.
Bandwidth Licenses* 10 Gbps (4 cores), 20 Gbps (8 cores), 40 Gbps (14 cores) and 60 Gbps (24 cores)
FlexPool
* Licenses are tied with maximum number of cores which can be allocated to ACOS
17
THUNDER ADC FOR CONTAINER
Image Format Docker
18
Detailed Feature List (Cont.)
19
Detailed Feature List (Cont.)
LEARN MORE ©2019 A10 Networks, Inc. All rights reserved. A10 Networks, the A10 Networks logo, ACOS, Thunder and SSL Insight
are trademarks or registered trademarks of A10 Networks, Inc. in the United States and other countries. All other
trademarks are property of their respective owners. A10 Networks assumes no responsibility for any inaccuracies
ABOUT A10 NETWORKS in this document. A10 Networks reserves the right to change, modify, transfer, or otherwise revise this publication
without notice. For the full list of trademarks, visit: www.a10networks.com/a10-trademarks.
C O NTACT US
a10networks.com/contact Part Number: A10-DS-15100-EN-42 DEC 2019
20