Cisco ACE30 Application Control Engine Module Data Sheet
Cisco ACE30 Application Control Engine Module Data Sheet
The Cisco ACE30 allows enterprises to accomplish these important IT objectives for application delivery:
Increase application availability and performance Secure the data center and applications Facilitate data center consolidation through the use of fewer servers, load balancers, and data center firewalls
The Cisco ACE30 achieves these goals through a broad set of intelligent Layer 4 load-balancing and Layer 7 content-switching technologies that work with IPv4 and IPv6 traffic and are integrated with the latest virtualization and security capabilities. It supports translation between IPv4 and IPv6 traffic, enabling migration to IPv6 and allowing deployments in mixed networks. The Cisco ACE30 provides flexibility in managing application traffic, scaling up to 16 Gbps in a single-slot module form factor, upgradeable through software licenses, thus providing IT with long-term investment protection and scalability. Additionally, through virtualization and role-based access control (RBAC) capabilities, the Cisco ACE30 enables IT to provision and deliver a broad range of applications from a single Cisco ACE module, bringing increased scalability for application provisioning to the data center. This capability helps streamline and reduce the cost of operations involved in implementing, scaling, accelerating, and protecting applications. The Cisco ACE30 greatly improves server efficiency through highly flexible application traffic management and the offloading of CPU-intensive tasks such as SSL encryption and decryption processing, HTTP compression, and TCP session management.
2011 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 1
The Cisco ACE platform is designed to serve as a last line of defense for servers and applications in data centers. An integrated firewall enables IT professionals to comprehensively secure high-value applications in the data center and facilitates data center consolidation (Figure 2).
Figure 2. Cisco ACE Network Integration
By combining high application performance with a comprehensive set of state-of-the-art application delivery features, the Cisco ACE30 promotes greater IT efficiency and reduces the total cost of ownership (TCO).
2011 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 2 of 6
Benefit Predictors or load-balancing algorithms enable the Cisco ACE30 to select the best server to satisfy a client request. Stickiness allows the same client to maintain multiple simultaneous or subsequent TCP or IP connections with the same real server for the duration of a session. Stateful failover capabilities help ensure resilient network protection for enterprise network environments. The Cisco ACE30 integrates with Cisco GSS to provide a multiple data center scaling and failover system.
Server health monitoring The Cisco ACE30 checks the health of application servers and server farms through configuration of health probes. Performance Compression SSL acceleration The Cisco ACE30 delivers up to 6-Gbps hardware-accelerated data compression and provides fast application performance for application users. The Cisco ACE30 integrates SSL acceleration technology, which offloads the encryption and decryption of SSL traffic from external devices (servers, appliances, etc.), thereby allowing Cisco ACE to look more deeply into encrypted data and apply security and application switching policies and help ensure compliance with internal and external regulations. The Cisco ACE30 directs website traffic in the most efficient manner by analyzing and directing incoming traffic at the request level. These capabilities enable highly specific application-layer policy and offload TCP processing from the web servers, saving CPU cycles.
TCP offload
Security Data center security Application security The Cisco ACE30 protects the data center and critical applications from protocol and denial-of-service (DoS) attacks and encrypts mission-critical content. The Cisco ACE30 provides deep protocol inspection capabilities, which enables IT professionals to comprehensively secure high-value applications in the data center. It secures mission-critical applications and protects against identity theft, data theft, application disruption, and fraud and defends web-based applications and transactions against targeted attacks by professional hackers.
Virtualized Services Virtual contexts Virtual contexts provide a means for creating resource segmentation and isolation, allowing the Cisco ACE30 to act as if it were several individual virtual appliances within a single physical appliance. Virtual contexts enable organizations to provide defined levels of service to up to 250 business departments, applications, or customers and partners from a single Cisco ACE appliance. RBAC allows organizations to specify administrative roles and restrict administrators to specific functions within the appliance or virtual contexts, allowing each administrator group to freely perform its tasks without affecting the other groups.
Deployment and Management Function consolidation Through consolidation of application switching, SSL acceleration, data center security, and other functions on one device, the Cisco ACE30 helps achieve better application performance, with fewer devices, simpler network designs, and easier management. By default, the Cisco ACE30 supports virtualization with one administrator context and 250 user contexts, 30,000 SSL transactions per second (TPS), and up to 6 Gbps of compression. The default throughput can be increased to up to 16 Gbps without the need for new equipment, through software license upgrades. Cisco ANM supports the management of virtual contexts and hierarchical management domains across multiple Cisco ACE30 modules. This server-based management suite discovers, provisions, monitors, and reports across many virtual contexts on multiple Cisco ACE30 Modules, making deployment transparent.
Investment protection
Cisco ANM
Product Specifications
Table 2 presents the performance specifications for the Cisco ACE30.
Table 2.
Feature Throughput Compression throughput Virtual contexts SSL throughput SSL TPS Maximum number of Layer 4 connections per second
2011 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 3 of 6
Maximum Performance and Configuration 200,000 complete transactions sustained rate 4 million
Product Specifications
Description
2011 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 4 of 6
System Requirements
Table 4 lists system requirements for the Cisco Catalyst 6500 Series Switches used with the Cisco ACE30, and Table 5 lists requirements for the Cisco 7600 Series Routers.
Table 4.
Requirement Chassis Supervisor engine Chassis OS Chassis connectivity Chassis slots required
Cisco Catalyst 6500 Series System Requirements for the Cisco ACE30 Module
Details Cisco Catalyst 6503E, 6504E, 6506E, 6509E, 6509-V-E, 6513, or 6513E Switch Cisco Catalyst Sup720-3B, Sup720-3BXL, Sup720-10G-3C, Sup720-10G-3CXL, Sup2T-10G, or Sup2T-10G-XL Cisco Catalyst 6500 Series running Cisco IOS Software Release 12.2(33)SXI4 (or later depending on supervisor) Functions as a fabric-enabled line card Occupies 1 slot in the chassis
Table 5.
Requirement Chassis
Cisco 7600 Series System Requirements for the Cisco ACE30 Module
Details Cisco 7603, 7604, 7609, 7613, 7603-S, 7604-S, 7606-S, or 7609-S Router Cisco Catalyst Sup720-3B, Sup720-3BXL, RSP720-3C-GE, RSP720-3CXL-GE, RSP720-3C-10GE, or RSP720-3CXL10GE Cisco 7600 Series running Cisco IOS Software Release 15.0(1)S (or later) Functions as a fabric-enabled line card Occupies 1 slot in the chassis
Ordering Information
Table 6 lists part numbers for ordering the Cisco ACE30 Module.
Table 6. Ordering Information
Product Description Application Control Engine 30 Hardware ACE A4(1) SW for ACE30 Module ACE SW (5.1) for ACE30 Module ACE A5(1) SW for ACE30 Module with IPv6-IPv4 translation ACE SW A5(1) for ACE30 Module v6-v4 translation SPARE ACE30 Module with 4G, 1G Comp, 1K SSL TPS and 5VC ACE30 Module with 4G, 4G Comp, 30K SSL TPS and 250VC ACE30 Module with 8G, 6G Comp, 30K SSL TPS and 250VC ACE30 Module with 16G, 6G Comp, 30K SSL TPS and 250VC
Product Number ACE30-MOD-K9= SC6K-A41-ACE SC6K-A51-ACE ACE30-MOD-V6GAT R-ACE30-MOD-V6GAT ACE30-BASE-04-K9 ACE30-MOD-04-K9 ACE30-MOD-08-K9 ACE30-MOD-16-K9
Additional Information
For more information about the Cisco ACE product family, please visit the following sites or contact your local account representative:
Cisco ACE Modules: http://www.cisco.com/go/ace Cisco ACE 4710 Appliance: http://www.cisco.com/go/ace Cisco GSS Appliance: http://www.cisco.com/go/gss Cisco ANM management software: http://www.cisco.com/go/anm
Page 5 of 6
2011 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Printed in USA
C78-632383-00
10/11
2011 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 6 of 6