WHITE PAPER A10 Thunder and AX Series Evolution of ADCs: The A10 Advantage over Legacy Load Balancers
Table of Contents A10 Thunder ADC: Application Delivery Evolved... 3 Business Challenges Solved by A10 Thunder ADC... 3 High Performance Powered by ACOS... 4 A10 s Next-Generation ADC Features... 6 Application Availability... 6 Application Acceleration... 6 Application Security... 6 Scalable Management... 6 Next Generation Cloud Services... 7 Advanced Hardware... 8 Comprehensive ADC Features with All-Inclusive Licensing... 9 Consolidate and Scale Through Performance and Innovation... 9 About A10 Networks...10 Disclaimer This document does not create any express or implied warranty about A10 Networks or about its products or services, including but not limited to fitness for a particular use and noninfringement. A10 Networks has made reasonable efforts to verify that the information contained herein is accurate, but A10 Networks assumes no responsibility for its use. All information is provided as-is. The product specifications and features described in this publication are based on the latest information available; however, specifications are subject to change without notice, and certain features may not be available upon initial product release. Contact A10 Networks for current information regarding its products or services. A10 Networks products and services are subject to A10 Networks standard terms and conditions. 2
A10 Thunder ADC: Application Delivery Evolved Today s web servers host complex applications that require intelligence at every layer. Server downtime or poor performance can directly impact business productivity or result in site abandonment and lost revenues. While traditional load balancers satisfied organizations scaling and failover requirements two decades ago, they have failed to keep up with modern availability, acceleration, and security demands. Lacking essential management and networking features, legacy load balancers simply do not meet current application delivery requirements. Application delivery controllers (ADCs) bridge the gap by providing important capabilities like caching, compression, and security. A10 Thunder ADC represents the next stage in the application delivery evolution by providing complete control over application traffic in any environment and by offering advanced availability, acceleration, and security features. This paper describes how Thunder ADC s high-performance architecture, advanced features, and carrier-grade hardware meets application delivery requirements not addressed by legacy load balancers. Product performance details and validation from A10 customers help substantiate the benefits listed in this paper. Users Availability Cloud Internet Acceleration Data Center Security Scale Figure 1: Typical ADC Placement Business Challenges Solved by A10 Thunder ADC A10 Thunder ADC provides the flexibility to solve critical business challenges. With unrivaled performance, Thunder ADC enables businesses to scale their application infrastructure while reducing operational expense and complexity. Compared to legacy load balancers, A10 delivers dramatic performance improvement as well as innovative features like global server load balancing for disaster recovery, scripting for custom traffic control and management, and advanced security, including DDoS protection, for security and compliance. 3
High Performance Powered by ACOS Thunder ADC has catapulted ahead of legacy load balancers by delivering a highly scalable networking platform with higher throughput, connections per second, and SSL processing speeds than existing platforms. Efficient & Accurate Architecture High-Speed Shared Architecture 64-bit Multi-Core Optimized 1 2 3 N Optimized Flow Distribution Flexible Traffic Accelerator Switching and Routing Figure 2: A10 s ACOS architecture A10 s Advanced Core Operating System (ACOS ) is the foundation for the technological success of the A10 Thunder ADC. Seasoned by over 8 years of customer-driven development, ACOS delivers a 64-bit application networking platform optimized for multicore system designs. The ACOS advantage is the reason Thunder ADC can get maximum leverage from processors and memory, resulting in a platform that is extremely energy efficient. 4
Because of the ACOS platform, Thunder ADC delivers exceptionally high performance in energy-efficient appliances with compact form factors as small as one rack unit (RU) supporting millions of new connections per second, reducing rack space and power consumption costs. ACOS also optimizes flow processing in software-based vthunder virtual appliances. vthunder supports leading hypervisors and cloud Infrastructure-as-a-Service (IaaS) platforms. High-speed Shared Usage Usage Usage Usage Figure 3: ACOS high-speed shared memory architecture delivers accurate data and faster processing compared to traditional memory architectures With the advanced ACOS platform built from the ground up for 64-bit architectures to meet rapidly growing networking demands organizations can increase application efficiency and enhance the end-user experience. ACOS delivers predictable performance and data center efficiencies to reduce cost and operational complexity. The chart above shows the performance improvement customers experienced after replacing their F5, Citrix, or Cisco products with A10 Thunder ADC. 5
A10 s Next-Generation ADC Features A10 Thunder ADC provides an essential layer of intelligence to application networking, ensuring applications are available, accelerated, and secure. While traditional load balancers can distribute traffic loads across multiple servers, they cannot perform advanced application-layer traffic management. As a case in point, they cannot conduct application-layer health checks or programmatically inspect and transform application content. Thunder ADC, in contrast, provides the application delivery features, flexible management, and cloud services that today s organizations need. Application Availability With the ability to concurrently run advanced server load balancing (SLB) and global server load balancing (GSLB), Thunder ADC detects server outages for high availability and disaster recovery. In the event that a server or even an entire site is unavailable, Thunder ADC can direct traffic to active servers and data centers. Application availability features include: High performance server load balancing GSLB intelligence for global operations Application and network health checks to verify server responsiveness High availability for uninterrupted operation Application Acceleration Thunder ADC improves web user experience and reduces infrastructure utilization by accelerating and optimizing traffic. Using compression and SSL offload, Thunder ADC relieves servers from and memory-intensive tasks, helping organizations lower equipment and bandwidth costs. Application acceleration features provided by Thunder ADC include: RAM caching for faster page loads HTTP compression to reduce bandwidth and load time TCP optimization to improve application performance SSL acceleration to secure applications Application Security Efficient and secure network traffic flow is vital to an organization s fiscal health. For many organizations, Internet connectivity is an integral part of the core business. If the network is compromised, the results are often disastrous; leading to downtime, loss of revenue and loss of reputation. Key ADC technologies to enhance application security include: DDoS Protection for multi-vector edge protection Web Application Firewall (WAF) to prevent Web attacks DNS Application Firewall (DAF) to protect critical infrastructure SSL Intercept (SI) to eliminate the outbound SSL blind spot Application Access Management (AAM) to seamlessly add authentication Scalable Management To meet the needs of the largest enterprises and service providers, A10 offers multiple ways to provision and manage Thunder ADC appliances. Customers can use an intuitive web user interface, an industry-standard command line interface, or a REST-based API A10 s axapi to provision and manage Thunder ADC appliances. With A10 s comprehensive suite of management capabilities, customers receive: aflex TCL scripting policies for granular control over application traffic axapi REST-based API for scalable provisioning, configuration and reporting agalaxy centralized management system for unified monitoring and configuration of multiple appliances Application Delivery Partitions (ADPs) and role-based access control for multi-tenant deployments Virtual Chassis System (avcs) clustering for scaling and a single point of management 6
Customer benefits include the ability to deploy differentiated customer services, reduce costs through data center consolidation, increase efficiency with large traffic volumes, and accelerate web speed to drive customer satisfaction. With 50 percent of Thunder ADC customers using advanced features like aflex scripting, organizations clearly need advanced application traffic management features not provided by traditional load balancers. Next Generation Cloud Services With more and more organizations transitioning from physical data center to virtual data centers, application delivery solutions must support cloud-based architectures and keep up with growing bandwidth requirements. A10 s acloud Services Architecture enables advanced L4-L7 services, improved agility, and reduced infrastructure costs. Ideally suited for both enterprises and Infrastructure as a Service (IaaS) providers, acloud Services Architecture: Allows organizations to scale out their infrastructure on-demand with hypervisor or cloud based virtual appliances, for example VMware ESXi or Amazon Web Services respectively Offers Network Virtualization using Generic Routing Encapsulation (NVGRE) and Virtual Extensible LAN (VXLAN) capabilities in high-performance hardware appliances Supports pay-as-you-go rental and utility based pricing models for IaaS providers Eliminates manual configuration of services with Software Defined Networking (SDN) integration Automates provisioning and management with cloud orchestration technologies like Microsoft SCVMM, OpenStack, and VMware vcloud Director Organizations benefit from the agility and low total cost of ownership provided by the acloud Services Architecture. A10 offers automatic provisioning of application delivery and flexible billing options, enabling customers to choose a license model, or provider, that fits their business needs. 7
Advanced Hardware To ensure the highest levels of performance and reliability, A10 uses leading edge hardware components. The A10 Thunder Series uses no moving parts in the inaccessible part of the appliance. Traditional hard disk drives use spinning media, and are prone to failure. Instead, A10 uses solid state drives (SSDs), which provide much better performance, and as there are no moving parts, SSDs are infinitely more reliable than spinning media. Likewise, the processors are not equipped with attached cooling fans. The only moving parts in the A10 Thunder Series appliance are the fans belonging to the redundant power supplies and the smart fans. These items are hot swappable, so they can be replaced without requiring downtime. Thunder ADCs include Flexible Traffic Accelerator (FTA) functionality for flow acceleration, and switching and routing functions. In mid-to-higher end models these functions are performed in additional specific hardware-based processors (including FPGAs) for maximum acceleration of key functions. This also offloads the core s of each unit, further optimizing use and increasing overall capacity. Many legacy load balancers were designed before the general move to 2048-bit certificates in recent years, and before the availability of today s purpose designed SSL processors, causing concerns for their inability to keep up with SSL demand, while not being able to service the same amount of 2048-bit connections as they had previously done with 1024-bit connections. Select models are equipped with high-performance, multi-chip SSL security processors that are exceptionally well suited for environments with growing SSL needs. SSL traffic is becoming more ubiquitous and server hardware has trouble keeping up with the increased SSL key sizes that are now standard. The new SSL acceleration hardware for A10 Thunder Series provides near-parity performance for the upgrade to 2048- bit key lengths, and has the extreme power needed to handle 4096-bit keys at high-quality production levels. 1024 SSL CPS 2048 SSL CPS 180,000 174,000 86,000 84,000 62,000 21,000 Thunder 4430S Quad Security Processor Thunder 5630S 4xQuad Security Processor Near Parity Thunder 4430S Quad Security Processor Thunder 6630S 4xQuad Security Processor 4096 SSL CPS Figure 4: With powerful security processors, A10 Thunder ADC delivers high performance at 1024, 2048, and 4096-bit SSL key sizes 8
Comprehensive ADC Features with All-Inclusive Licensing Over 3,000 customers, including enterprises, service providers and web giants, have chosen A10 Thunder ADC not just for its next-generation features and unrivaled performance, but also its simplified licensing. Thunder ADC includes all application availability, acceleration, and security features without additional licenses. Common licenses eliminated from legacy load balancers include: Global server load balancing licenses Virtualized partitions licenses Web application firewall license SSL offload licenses And more... Indeed, some legacy load balancers required separate appliances for certain functionality, consolidation of functionality and inclusive licensing streamlines the data center and license tracking headaches. As a result, A10 customers do not need to compromise on important networking or security capabilities to stay within budget. Besides providing all features at no additional charge, Thunder ADC hardware appliances also offer full performance and acceleration without licensing fees. Restricting bandwidth or disabling acceleration can introduce significant operational challenges to organizations. If application traffic spikes, either over time, or because of a successful marketing campaign, bandwidth license restrictions can limit application performance and prevent users from accessing applications. When bandwidth exceeds these artificially imposed restrictions, server and network administrators could spend hours or days investigating performance and server metrics, trying to determine the cause of the performance problems. During this time, the end-user experience is limited and an organization s reputation is impacted. Thunder ADC spares organizations from the complexity and operational risks introduced by license restrictions. Consolidate and Scale Through Performance and Innovation A10 Thunder ADC represents the latest evolution of application delivery controllers and a marked advancement over legacy load balancers. A10 has earned a wide base of satisfied customers in the decade since the company s inception, with consistent growth. The ability to quickly meet new application networking challenges as they emerge, while providing unparalleled support, helps A10 maintain its leadership in the industry. A10 has consistently delivered new meaningful features 3-36 months before other vendors; examples include SSL Intercept, DNS Application Firewall, comprehensive IPv6 migration, an operating system optimized for 64-bit computing, 100 GbE interfaces, and the most efficient and compact design on the market today. With the extreme performance that A10 Thunder models deliver, and the innovative, all-inclusive features of ACOS, the Thunder Series provide an excellent platform to consolidate multiple point products such as a WAF, DNS Application Firewall, and dedicated SLBs into one appliance. This is realized through the use of Application Delivery Partitions, which enable a customer to partition out select solutions for different end-users, or select parts of the network. A10 provides customers an award-winning ADC with the highest-performance per rack unit and the widest choice of features in a highly efficient platform. A10 Thunder ADC enables organizations to save energy, data center footprint, and cost. 9
About A10 Networks A10 Networks is a leader in application networking, providing a range of high-performance application networking solutions that help organizations ensure that their data center applications and networks remain highly available, accelerated and secure. Founded in 2004, A10 Networks is based in San Jose, California, and serves customers globally with offices worldwide. For more information, visit: www.a10networks.com Corporate Headquarters A10 Networks, Inc 3 West Plumeria Ave. San Jose, CA 95134 USA Tel: +1 408 325-8668 Fax: +1 408 325-8666 www.a10networks.com Part Number: A10-WP-21108-EN-01 June 2014 Worldwide Offices North America sales@a10networks.com Europe emea_sales@a10networks.com South America brazil@a10networks.com Japan jinfo@a10networks.com China china_sales@a10networks.com Taiwan taiwan@a10networks.com Korea korea@a10networks.com Hong Kong HongKong@a10networks.com South Asia SouthAsia@a10networks.com Australia/New Zealand anz_sales@a10networks.com To learn more about the A10 Thunder Application Service Gateways and how it can enhance your business, contact A10 Networks at: www.a10networks.com/contact or call to talk to an A10 sales representative. 2014 A10 Networks, Inc. All rights reserved. A10 Networks, the A10 Networks logo, A10 Thunder, Thunder, vthunder, acloud, ACOS, and agalaxy are trademarks or registered trademarks of A10 Networks, Inc. in the United States and in other countries. All other trademarks are property of their respective owners. A10 Networks assumes no responsibility for any inaccuracies in this document. A10 Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice. 10