A10 DS Defend Mitigator
A10 DS Defend Mitigator
Platforms
Benefits
Maintain Deploy
Service Availability Wartime Support
Downtime results in immediate productivity and revenue No organization has unlimited trained personnel or
loss for any business. A10 Defend Mitigator ensures service resources during real-time DDoS attacks. A10 Defend
availability by automatically spotting anomalies across the Mitigator supports five levels of programmatic mitigation
traffic spectrum and mitigating multi-vector DDoS attacks. escalation and de-escalation per protected zone. Remove
the need for frontline personnel to make time-consuming
manual changes to escalating mitigation strategies and
Defeat improve response times during attacks. Administrators
have the option to manually intervene and coordinate with
Growing Attacks A10's DSIRT at any stage of an attack.
A10 Defend Mitigator protects the largest, most-demanding
network environments. Defend Mitigator offloads common
attack vectors to specialized hardware, allowing its powerful
$
Reduce
multicore CPUs to distinguish legitimate users from attacking
botnets and complex application-layer attacks that require Security OPEX
resource-intensive deep packet inspection (DPI). A10 Defend Mitigator is extremely efficient. It delivers high
performance in a small form factor to reduce OPEX with
significantly lower power usage, rack space, and cooling
Reference Architectures
Proactive Deployment
(Asymmetric or Symmetric)
Clean Traffic
Deploying A10 Defend Mitigator inline or
in-path of the services network provides
Firewall
Services continuous, comprehensive detection and
Edge Router A10 Defend
Mitigator
fast mitigation. This mode is most useful
API
for real-time services such as gaming and
REST API,
Cloud-based sFlow, UI VoIP where the user experience is critical,
DDoS Scrubbing Syslogs and for protection against application-layer
(Hybrid)
A10 Defend GUI, REST API
attacks. Mitigator supports L2 or L3 in-path
Orchestrator deployments. It also eases deployment of
hybrid DDoS protection with a cloud scrubbing
service in case volumetric attacks exceed an
organization’s internet bandwidth.
A10 Defend
Reactive Deployment
Orchestrator
Larger networks benefit from on-demand
API Communication
mitigation, triggered manually or by flow
analytical systems. A10 Defend Detector
is available as a standalone appliance
API, sFlow, (hardware or virtual). The flow-based DDoS
A10 Defend Detector A10 Defend Syslogs detector is tightly integrated with A10 Defend
Mitigator
Suspected Orchestrator and Mitigator for a intelligent
Traffic
Clean
UI and automated DDoS defense solution.
BGP / Traffic A10 Defend Mitigator is capable of sending
BGP FlowSpec
GUI, REST API
Flow BGP FlowSpec for better collaborating with
Information upstream routers.
Reference Architectures
A10 Defend
Orchestrator
Reactive Deployment with
Third-party Flow Detector
API Communication
Features
Full Spectrum DDoS Protection for Service Availability
A10 Defend Mitigator provides a complete solution for The Zero-day Automated Protection (ZAP) utilizes
DDoS defenses in proactive always-on or on-demand heuristics and machine learning to automatically discover
reactive modes to meet customers' business objectives. mitigation filters without advanced configuration or
Defend Mitigator can be deployed with inline mode in L2 manual intervention. ZAP speeds the response time against
or L3 with full IPv4 and IPv6 support, where the proactive increasingly sophisticated multi-vector attacks while
mode is ideal for critical and real-time services such as minimizing downtime and errors and lower operating costs.
gaming, voice and DNS. In reactive mode, A10 Defend
Mitigator works in concert with A10 Defend Detector
and Orchestrator, and becomes active only when needed. Non-stop DNS
DNS
When an attack is detected by a Detector, Orchestrator Authoritative DNS Cache
instructs Mitigator to initiate a BGP route redirection
for the suspicious traffic. Then Mitigator applies the A10 Defend Mitigator can be configured as a high-
appropriate countermeasures using a progressive performance authoritative DNS cache, enabling A10 Defend
auto-mitigation level escalation technique before Mitigator's non-stop DNS operational mode to cache up to
delivering the clean traffic to the intended destination. 240 million DNS records using zone transfer and respond
to queries at rates of up to 35 million queries per second.
Non-stop DNS can also work in conjunction with regular
Multi-vector A10 Defend Mitigator DDoS defenses to create a highly
Scalability Precise
Leading Mitigation Capacity Attack Mitigation at Scale
A10 Defend Mitigator provides solutions to protect A10 Defend Mitigator tracks more than 27 traffic and
organizations from attacks of all sizes, from 5 to 380 Gbps behavioral indicators and can apply escalating protocol
in power-efficient and small form factor hardware. It's also challenges to surgically differentiate attackers from
available as a virtual appliance with a feature parity and valid users for appropriate mitigation of up to 256 million
provides 100 Gbps throughput. concurrent tracked sessions.
The Defend Mitigator can easily scale its mitigation capacity Complex application attacks (e.g., HTTP, DNS, etc.) are
by clustering up to 8 appliances (e.g., 3 Tbps in hardware, mitigated with advanced parallel processing across a large
800 Gbps in a virtual appliance) with a list synchronization number of CPU cores to maintain high-performance system
technology. scaling, even for multi-vector attacks.
Eight lists, each containing up to 16 million entries, may DDoS attackers continue to innovate their multi-vector attack
be defined to utilize data from DDoS threat intelligence arsenals with new strategies. The A10 Defend Mitigator Zero-
sources, such as A10 Defend Threat Control. Such class day Attack Pattern Recognition (ZAPR) engine automatically
lists, along with own custom black/white lists, can be identifies DDoS attack characteristics and dynamically
configured as IP block lists or used for source IP-based applies mitigation filters without advanced configuration or
mitigation policy as needed. manual intervention.
Efficient Easy
Intelligent Automation Network Integration
No organization has unlimited resources or the time for With multiple performance options and flexible deployment
manual interventions. A10 provides the industry’s most models, A10 Defend Mitigator may be integrated into any
advanced intelligent automation capabilities powered by network architecture of any size, including MPLS and BGP.
machine learning throughout the entire protection lifecycle. And with aXAPI, A10’s 100-percent programmable RESTful
API, A10 Defend Mitigator easily integrates into third-party
Operators define the networks to protect and A10
detection solutions and into agile SecOps workflows.
defenses do the rest based on the operator’s pre-defined
policies, including individual learned detection thresholds Leveraging open standards like BGP blackhole and
per monitored entity, automatic traffic redirection Flowspec functionality, A10 Defend Mitigator integrates
orchestration, start of mitigation and escalation, and easily with any DDoS detection and DDoS mitigation
then extract and apply attack pattern filters. When the capable BGP routers solution. Open APIs and networking
attack subsides, the network and defenses are returned to standards enable tight integration with other devices,
peacetime posture and detailed reports are generated for including A10 threat detection partners, SDN controllers,
future analysis. and other security products.
Effective
Management
Average Latency 10 µs 20 µs 50 µs 50 µs
Hardware
Network Interface Bypass Model
1+4
1 GE Copper 5 6 0 0
(Bypass)
1 GE Fiber (SFP) 0 0 2 0 0
2 (Optical
1/10 GE Fiber (Fixed) 0 0 0 0
bypass)*5
Hardware Specifications
Processor Intel
Intel Xeon 8-core Intel Xeon 18-core*6 Intel Xeon 18-core
Communications Processor
Dimensions (inches) 1.75 (H) x 17.5 (W) x 17.25 (D) 1.75 (H) x 17.5 (W) x 18(D) 1.75 (H) x 17.5 (W) x 30 (D) 1.75 (H) x 17.5 (W) x 30 (D)
Unit Weight 14 lbs | 16 lbs (RPS) 18 lbs 34.3 lbs 34.3 lbs
Single 750W*4 Dual 750W RPS Dual 1500W RPS Dual 1500W RPS
Power Supply (DC option available)
80 Plus Platinum efficiency, 100-240 VAC, 50-60 Hz
Power Consumption (typical/max)*2 80W / 110W 151W / 205W 585W / 921W 585W / 921W
Cooling Fan (front-to-back airflow) Removable fans Hot swap smart fans
Regulatory Certifications FCC Class A, UL, CE, UKCA, FCC Class A, UL, CE, UKCA,
FCC Class A, UL, CE, UKCA, FCC Class A, UL, CE, UKCA,
CB, VCCI, KCC, BSMI, CB, VCCI, KCC, BSMI,
CB, VCCI, BSMI, RCM | RoHS CB, VCCI, BSMI, RCM | RoHS
RCM | RoHS RCM | RoHS
Mitigation Permanence
Throughput (software scrubbing)*1 220 Gbps 150 Gbps 300 Gbps 380 Gbps
Hardware Blocking 500 Gbps 500 Gbps 500 Gbps 1.2 Tbps
Average Latency 60 µs 60 µs 60 µs 60 µs
Network Interface
1/10 GE Fiber (SFP+) 48 0 0 0
40 GE Fiber (QSFP+) 0 4 4 0
Hardware Specifications
Processor 2 x Intel Xeon 18-core 2 x Intel Xeon 18-core 4 x Intel Xeon 18-core 2 x Intel Xeon 28-core
Hardware Acceleration 3 x FTA-4, SPE 4 x FTA-3, SPE 8 x FTA-3, SPE 2 x FTA-5, SPE
Dimensions (inches) 1.75 (H) x 17.5 (W) x 30 (D) 5.3 (H) x 16.9 (W) x 30 (D) 5.3 (H) x 16.9 (W) x 30 (D) 2.625 (H) x 17.5 (W) x 30 (D)
Dual 1500W RPS 2+2 1100W RPS 2+2 1100W RPS Dual 1500W RPS
Power Supply (DC option available)
80 Plus Platinum efficiency, 100-240 VAC, 50-60 Hz
Power Consumption (typical/max)*2 784W / 1,078W 1,000W / 1,200W 1,700W / 2,000W 1,121W / 1,300W
Heat in BTU/Hour (typical/max)*2 2,676 / 3,679 3,412 / 4,095 5,801 / 6,825 3,826 / 4,436
Regulatory Certifications FCC Class A, UL, CE, UKCA, FCC Class A, UL, CE, UKCA,
FCC Class A, UL, CE, UKCA, FCC Class A, UL, CE, UKCA,
CB, VCCI, CQC, KCC, BSMI, CB, VCCI, CQC, KCC, BSMI,
CB, VCCI, BSMI, RCM | RoHS CB, VCCI, BSMI, RCM | RoHS
RCM | RoHS RCM | RoHS
Hardware specifications and performance numbers are subject to change without notice, and may vary depending on configuration and environmental conditions. As for
network interface, it’s highly recommended to use A10 Networks qualified optics/transceivers to ensure network reliability and stability.
*1 Throughput performances are traffic-forwarding capacity and measured with legitimate traffic with DDoS protection enabled.
*2 With base model | *3 10Gbps speed only | *4 Optional RPS available | *5 Fixed SFP+ optical ports with dual rate (10GBASE-SR and 1000BASE-SX) | *6 Active CPU core
counts and memory size may vary depending on the modular license | ^ Certification in process | + Thunder 14045 comes with a splitter cable for console to provide access
to both modules
vRAM 16 GB 32 GB 64 GB
vDisk 60 GB 60 GB 100 GB
Bandwidth license
Licence Types FlexPool FlexPool
(per instance)
*1 Available in ACOS 6.0 and above. Tested with Defend Mitigator running on ESXi 7.0 with NVIDIA Mellanox ConnectX-6 NIC (SR-IOV enabled)
Learn More ©2023 A10 Networks, Inc. All rights reserved. A10 Networks, the A10 Networks logo, ACOS, Thunder, Harmony and SSL
Insight are trademarks or registered trademarks of A10 Networks, Inc. in the United States and other countries. All
About A10 Networks other trademarks are property of their respective owners. A10 Networks assumes no responsibility for any inaccuracies
in this document. A10 Networks reserves the right to change, modify, transfer, or otherwise revise this publication
Contact Us without notice. For the full list of trademarks, visit: A10networks.com/a10trademarks.
A10networks.com/contact Part Number: A10-DS-15136-EN-01 Mar 2024