Product technical features:
1) Comprehensive load balancing
BIG-IP LTM (local traffic management) includes static and dynamic load balancing methods, including dynamic rate balance, minimum connection and observation mode, which are used to track the dynamic performance of the server as a whole. This ensures that the best resources are always selected to improve performance. It can support all server load balancing based on TCP/IP protocol. It can support load balancing algorithms such as minimum number of connections, polling, proportion, fastest response, hash, prediction, observation and dynamic proportion.
2) Application status monitoring
The monitors provided by BIG-IP LTM are used to check the availability of devices, applications and contents, including special monitors suitable for various applications (including various application servers, SQL, SIP, LDAP, XML/SOAP, RTSP, SASP, SMB, etc.). ), as well as custom monitors for checking content and simulating application calls.
3) High availability and transaction guarantee
BIG-IP LTM can provide sub-second system failover and comprehensive connection mapping, ensuring that it is a highly available solution regardless of system, server or application failures. BIG-IP LTM can actively detect and respond to any server or application error.
4) Support NAT address translation.
Provides NAT address translation function, which can realize dynamic or static address translation.
5) Support access control lists
Can you realize the basic functions of firewall, establish access control list and refuse to connect to IP network segment or port number?
6) Wide area traffic manager (plug-in module)
Provide high availability, maximum performance and global management for applications running in multiple data centers around the world.
7) Link controller (plug-in module)
Seamlessly monitor the availability and performance of multiple WAN connections, and intelligently manage the two-way traffic of the site, thus providing fault tolerance and optimized Internet access. For example, manage and control the network traffic of CT and CNC.
8) Application firewall (plug-in module)
This module can be added to F5 devices to provide more advanced security services for devices.
9) Support routing
This function is the basic function of F5 devices, but it only supports static routing. If you use the advanced OSPF routing protocol, you need to purchase a separate module to support it.
Extend applications-reduce server load
1) content conversion
BIG-IP LTM provides a comprehensive solution to offload many complex or repetitive functions to centralized high-performance network devices. SSL, compression and many other functions of BIG-IP LTM provide a complete content conversion gateway, which can redirect, insert or completely convert application content to achieve effective and efficient application integration.
2)OneConnect
F5 OneConnect? Gather millions of requests into hundreds of server-side connections to ensure that the back-end system can handle these connections efficiently, thus increasing the server capacity by 60%.
3) caching
Intelligent caching can increase the server capacity by 9 times by offloading the repeated traffic of Web and application servers, thus achieving significant cost savings. This function is also the only solution in the industry to provide multi-library cache, which can manage different cache libraries for each application or department and provide accurate and intelligent control for high-priority applications.
4)SSL acceleration and unloading
Every BIG-IP LTM device provides SSL encryption and hardware acceleration to eliminate the SSL burden of the application server. By speeding up setup and bulk encryption, enterprises can migrate all communications to SSL with more secure passwords, which will hardly cause application performance degradation or bottlenecks.
Application of optimization
1) intelligent application switching
BIG-IP LTM has the unique ability to read all IP applications, so it can transform and retain the unique information of application servers (Microsoft, IBM, Oracle, SUN, etc.). ) specific suppliers. XML data of Web service application; Or a customized value indicating a mobile/wireless application. With the ability of BIG-IP LTM to convert, record and continuously retain payloads or data streams, your enterprise can achieve higher reliability and scalability.
2) Intelligent compression
Improve application performance by 3 times while reducing bandwidth usage by 80%. Use industry-standard gzip and DEFLATE compression algorithms to reduce HTTP traffic, reduce bandwidth consumption through slower/lower bandwidth connection, and shorten user download time. This function provides rich support for compressing various types of files, including HTTP, XML, JavaScript, J2EE applications and so on.
3) Flexible 4-7 layer traffic shaping.
By allocating bandwidth for higher priority applications, controlling peak traffic and determining traffic priority according to Layer 4 or Layer 7 parameters, the best application performance can be guaranteed. That is, the QOS function enabled by IDC computer room on the core switch.
4)TCP Express
BIG-IP LTM highly optimized TCP/IP stack (called TCP Express? ) Combine the improved functions of TCP/IP technology and the latest RFC with many improved and extended functions developed by F5 to minimize the impact of congestion, packet loss and recovery. BIG-IP LTM is a full proxy device, so TCP Express can mask and transparently optimize the original or incompatible TCP stack running on the server or client. This can improve user performance by 2 times, improve bandwidth efficiency by 4 times, and reduce the connection load of your server.
Security application
1) basic firewall function-packet filtering
BIG-IP LTM integrates a control point, which is used to define and implement filtering rules based on the fourth layer (PCAP, similar to network firewall) to improve the network protection ability.
2) Resource hiding and content security
BIG-IP LTM virtualizes and hides all applications, server error codes and real URL references, because these may provide hackers with information about infrastructure, services and related vulnerabilities. Sensitive documents or content are not allowed to leave your website.
3) Customized application attack filtering
Comprehensive detection and event-based strategies provide significantly enhanced capabilities for searching, detecting and applying various rules to prevent known layer 7 attacks. BIG-IP LTM also uses secure application templates to prevent known attacks and attacks against application business logic. The extra security layer can prevent hackers, viruses and worms, while providing continuous services for legitimate traffic.
4) Isolation protocol attack
BIG-IP LTM provides protocol purification and complete TCP terminal points to manage client-side and server-side connections respectively, thus protecting all back-end systems and applications from malicious attacks.
5) Network attack protection
As a security agent, BIG-IP LTM can resist DoS attacks, SYN Flood and other network-based attacks. Like SYNCheck? Other functions can provide comprehensive SYN Flood protection for servers deployed behind BIG-IP devices. BIG-IP LTM uses dynamic harvesting (an adaptive method to obtain idle connections) to filter the most heavily loaded attacks and provide uninterrupted service for legitimate connections.
6) Selective encryption
BIG-IP LTM provides the most selective encryption method in the industry, which can encrypt data in whole, in part or conditionally, thus protecting and optimizing the communication between different users.
7)Cookie encryption
Cookie and other tokens transparently assigned to legitimate users are encrypted. Enterprises can obtain excellent security and higher user identity trust of all stateful applications (e-commerce, CRP, ERP and other key business applications).
8) Advanced SSL encryption standard
BIG-IP LTM adopts the most secure SSL encryption technology on the market, and supports higher standard AES algorithm without additional processing cost.
9) Grab the bag tool
Tcpdump tool is provided for packet capture analysis, which can be used for fault handling, traffic analysis and other directions. A 10 Company is the world's leading manufacturer in the field of application delivery network (ADN), and its market share is the third in the world. Headquartered in silicon valley, USA, it has been rated as one of the fastest growing enterprises in the world by INC.500 for many years. Its products won the Best Teched 20 13 Best Hardware Award and the Most Popular Award from Microsoft in 2013. This is the most cost-effective and best performance-per-watt application delivery product in the industry. See Chinese official website of A 10 company for details.
Application Case (International)
Twitter, Microsoft, LG, Samsung, Godaddy, NTT, Linkedin, AOL, Evernote, Terra, Bizrate, meebo, Box, Subaru, gamania, mevio, TED baker…… ...
Application case (domestic)
Taobao, Alibaba, Ctrip, China Yahoo, Shanda Network, Century Internet, Store 1, Xinhuanet, People.com, First Video, 5 million lottery tickets, auto company, State Taxation Administration of The People's Republic of China, China Insurance Regulatory Commission, Ping An Group, China Construction Bank, Agricultural Bank, Shanghai Jiaotong University, Zhejiang University, Sichuan University, Xinhua News Agency, Guodian Group, Sinochem Group, etc. , intelligently match the user's access request to the optimal link, select the server with the fastest response speed for users, improve the user experience, and provide scientific management decisions for enterprises.
Product technical features:
Unilateral acceleration function
The client can improve the access speed of users without installing any plug-ins and software, so that users can access the published content faster and more stably, and build a stable and intelligent commercial publishing platform.
Business intelligence analysis
Deeply convinced that AD application delivery products are different from traditional load balancing equipment, and pay more attention to a series of problems related to business and network optimization in the whole application delivery process of enterprises and institutions. The most remarkable feature is that, on the premise of ensuring the stability in the application delivery process, it can not only understand the running state of the organization's network and servers, but also help the organization analyze the running state of its own business system, thus providing decision-making basis for high-level network optimization and business optimization.
Link load and server load are two in one.
IT is believed that AD products include link optimization and server optimization, and load balancing on the fourth and seventh floors, which can monitor the status of each link and server in real time, and distribute requests to the corresponding links and servers according to preset rules, so as to finally realize the reasonable distribution of data streams, make full use of all links and servers, expand the overall processing capacity of the application system, improve the stability of the application system, improve the user's access experience and reduce the IT investment cost of the organization.
High return on investment
Deeply convinced that AD series application delivery products have broken the monopoly of foreign manufacturers, and have a two-in-one load balancing solution of link and server at the same input level, which directly enables many optimization functions such as SSL acceleration, caching and compression. , and obtain equipment performance beyond similar products in the industry. Barracuda Load Balancer realizes high availability and security of applications through traffic optimization and security scanning mechanism for multiple servers, and provides redundancy for applications through perfect server health check mechanism. Barracuda adopts the integrated design of software and hardware, avoiding the charging method based on the number of servers and ports, and providing users with cost-effective application security load balancing.
High availability and high scalability
According to industry analysis report, less than 20% of core applications have achieved high availability. The great challenges faced by application high availability include the extension of continuous working hours, the expansion of applications and the protection against attacks. Barracuda load balancer uses perfect server health check to monitor real servers in real time to ensure that users' requests always reach healthy servers and get normal responses. The high availability of barracuda load balancer itself can be realized by cluster deployment of barracuda load balancer.
For high-traffic application environment, barracuda load balancer balances traffic according to the real-time processing capacity of each server through dynamic weight distribution mechanism. For applications that need session keeping, barracuda load balancer provides source IP session keeping and 7-layer cookie session keeping functions.
Easy to manage and maintain
Barracuda load balancer is easy to deploy. Through the server automatic discovery function and friendly Web configuration interface, users can easily complete the configuration. At the same time, barracuda provides real-time security protection for applications through integrated IPS.
The Web management interface of barracuda load balancer provides perfect data statistics, real-time statistics of equipment performance, flow and other data, and provides an easy-to-operate service configuration page to provide convenient management for administrators. function
1, session maintenance settings to ensure business continuity and availability. 2. Distribute Internet traffic and solve the communication problem between North and South. 3. Link backup to improve link redundancy. 4. Bandwidth superposition reduces the cost of surfing the Internet. 5. Automatic link detection, error correction and health check 6. Intelligent Load Balancing/Manual Load Balancing 7. Routing is based on internal network address/external network address.
8, according to the procedure.
Advantages:
Support bandwidth superposition: bind multiple broadband into one, reduce network investment, and obtain the most efficient and stable network environment with the least investment. Support for line backup: When a link fails, it can quickly switch to other available links to ensure high availability and business continuity of the network. Solve the North-South Communication Problem: Effectively solve the ubiquitous "North-South Communication" problem caused by the differences between North-South Telecom and Netcom. Support multi-link load balancing: highly ensure the stability of enterprise network and business continuity, and avoid the adverse impact of system downtime, link interruption or congestion on enterprise operation. It has many advanced technologies, including HTTP compression, SSL acceleration, intelligent data compression, memory-based caching, TCP connection reuse, unilateral TCP acceleration and so on, which reduces the response time and significantly improves the end-user experience. Rich algorithms and strategies: Through a variety of balancing algorithms and rich load balancing strategies, users can use network resources more efficiently and reasonably, greatly improve the link utilization efficiency and ensure the efficient operation of services. Guarantee key business: support link and application status monitoring, support session maintenance, avoid service access interruption, and ensure the continuity of key business. Simple installation and deployment configuration: simple installation, convenient deployment, graphical configuration interface, simple and intuitive, reducing the complexity of user configuration and facilitating system management and maintenance. The AD product of Pinan Technology is an application delivery controller independently developed by Pinan Technology, with independent intellectual property rights, covering load balancing, application acceleration and application security functions. This product integrates unique key technologies such as multi-core and multi-thread scheduling and notification protocol stack, which can greatly improve the availability of servers, ensure the reliability and security of links, efficiently deliver applications to customers, improve user access experience and reduce IT investment costs.
Features and advantages:
1, everything is one, and I think everything is one. The application delivery controller is an integrated multi-functional communication management platform, which integrates mainstream application traffic management and performance enhancement functions into a powerful platform, including layer 2 to layer 7 service load balancing (SLB), caching, link load balancing (LLB), SSL acceleration, HTTP compression, clustering, application security firewall (Webwall) and global service load balancing (GSLB). The platform accelerates the transmission of application programs and simplifies the process.
2. High performance and high performance. By adopting a variety of performance enhancement technologies, especially the revolutionary domestic unique technology, namely high-speed protocol stack technology, all the functions provided by the application delivery controller are integrated together, which greatly optimizes the processing process of each function and realizes the dynamic management of data, thus ensuring the high-speed and reliable operation of network applications and services.
3.TCP uninstall network uninstall. When the application delivery controller realizes service load balancing, it can greatly reduce the total load in the background under the condition of high load through unique performance optimization technologies such as connection reuse, thus providing better cost performance. When combined with the caching function, the application delivery controller can even reduce the load in the background by a hundred times, thus providing amazing performance.
4. Flexibility is flexibility. While achieving high processing power and functions, the application delivery controller is simpler and more user-friendly than other products in configuration, management and maintenance. At the same time, combined with the unique strong localization technical support and research and development strength, it can provide comprehensive technical services in time and accurately, and provide users with long-term value creation. Tianrongxin network guard TopApp-LB load balancing system is a link and server load balancing product with intelligent bandwidth control function. TopApp-LB load balancing system makes it easy to deploy large-scale applications by optimizing the network exit link and server resources, and at the same time achieves the most stable operation effect, the highest resource utilization rate, the best application performance and user experience. A large number of enterprises and institutions have successfully deployed their own applications through TopApp-LB load balancing system, which meets the needs of information development and greatly improves work efficiency.
Two in one load balancing
Integrate high-performance link load balancing and server load balancing to ensure that application data can obtain the best transmission path in complex networks. Improve the health check mechanism of link and application services, and timely diagnose links and servers that cannot work normally or are overloaded. According to the health status of applications and links, intelligently adjust the traffic distribution between multi-links and multi-servers, and automatically complete the handover, thus improving the availability of networks and applications.
Accurate flow control improves bandwidth value.
Innovative end-to-end accurate bandwidth control and balancing technology avoids the waste of downlink bandwidth in WAN brought by traditional queuing mechanism, and truly realizes priority management, bandwidth limitation, bandwidth guarantee and fair use of bandwidth, and enhances bandwidth value.
High availability guarantee
It realizes the highly available deployment of multi-machine cluster and active and standby modes, maximizes the application running time, and avoids the impact of equipment or network failure on business.
Enhanced security protection
Stateful firewall realizes high-performance access control, bidirectional NAT supports many-to-one address conversion, one-to-many address conversion and one-to-one address conversion, and IP/MAC addresses are automatically scanned and bound, effectively resisting dozens of network attacks.
Easy to use and deploy
Single-arm and dual-arm access modes can be selected to minimize the adjustment of user network structure. Adaptive management of load balancing algorithm, built-in China ISP address book, automatic notification of server faults and automatic repair of application faults reduce the complexity of user configuration management.