Skip to main content
Version: v8

Hardware Specs

Haltdos hardware specs page introduce customers about various range of models along with their hardware specifications.


Model - HD-CAN-4100

MITIGATION PERFORMANCE
L4 Throughputupto 5 Gbps
L7 Throughputupto 4 Gbps
SSL Throughputupto 4 Gbps
Compression Throughput4 Gbps
Decompression Throughput5 Gbps
SSL/TLS Connections per Second22K (RSA 2K) & 15K (ECC)
L4 Connection per Second3M
L7 Request per Second1M
DDoS Attack Flood Prevention Rate1 to 5 Mpps
Max Concurrent Connections24 M
Induced Latency< 1 milli-second
Operating Temperature Range (°C)0° to 40° C
Storage Temperature Range (°C)0° to 45° C
Operating Humidity (%RH)8% to 95%

Model - HD-CAN-4600

MITIGATION PERFORMANCE
L4 Throughputupto 24 Gbps
L7 Throughputupto 20 Gbps
SSL Throughputupto 20 Gbps
Compression Throughput20 Gbps
Decompression Throughput20 Gbps
SSL/TLS Connections per Second40K (RSA 2K) 25K (ECC)
L4 Connection per Second1.2M
L7 Request per Second3M
DDoS Attack Flood Prevention Rate5 to 20 Mpps
Max Concurrent Connections24M
Induced Latency< 1 milli-second
Operating Temperature Range (°C)0° to 40° C
Storage Temperature Range (°C)0° to 45° C
Operating Humidity (%RH)8% to 95%

Model - HD-CAN-5100

MITIGATION PERFORMANCE
L4 Throughputupto 48 Gbps
L7 Throughputupto 40 Gbps
SSL Throughputupto 40 Gbps
Compression Throughput24 Gbps
Decompression Throughput30 Gbps
SSL/TLS Connections per Second50K (RSA 2K) 25K (ECC)
L4 Connection per Second7M
L7 Request per Second7M
DDoS Attack Flood Prevention Rate10 to 30 Mpps
Max Concurrent Connections56M
Induced Latency< 1 milli-second
Operating Temperature Range (°C)0° to 40° C
Storage Temperature Range (°C)0° to 45° C
Operating Humidity (%RH)8% to 95%

Model - HD-CAN-5400

MITIGATION PERFORMANCE
L4 Throughputupto 72 Gbps
L7 Throughputupto 60 Gbps
SSL Throughputupto 50 Gbps
Compression Throughput37 Gbps
Decompression Throughput54 Gbps
SSL/TLS Connections per Second100K (RSA 2K) 50K (ECC)
L4 Connection per Second10M
L7 Request per Second10M
DDoS Attack Flood Prevention Rate25 to 50 Mpps
Max Concurrent Connections96M
Induced Latency< 1 milli-second
Operating Temperature Range (°C)0° to 40° C
Storage Temperature Range (°C)0° to 45° C
Operating Humidity (%RH)8% to 95%

Model - HD-CAN-6200

MITIGATION PERFORMANCE
L4 Throughputupto 120 Gbps
L7 Throughputupto 100 Gbps
SSL Throughputupto 100 Gbps
Compression Throughput66 Gbps
Decompression Throughput120 Gbps
SSL/TLS Connections per Second150K (RSA 2K) 75K (ECC)
L4 Connection per Second12M
L7 Request per Second15M
DDoS Attack Flood Prevention Rate50 to 80 Mpps
Max Concurrent Connections160 M
Induced Latency< 1 milli-second
Operating Temperature Range (°C)0° to 40° C
Storage Temperature Range (°C)8° to 45° C
Operating Humidity (%RH)8% to 95%

Model - HD-CAN-6700

MITIGATION PERFORMANCE
L4 Throughputupto 150 Gbps
L7 Throughputupto 120 Gbps
SSL Throughputupto 200 Gbps
Compression Throughput132 Gbps
Decompression Throughput240 Gbps
SSL/TLS Connections per Second200K (RSA 2K) 100K (ECC)
L4 Connection per Second15M
L7 Request per Second18M
DDoS Attack Flood Prevention Rate50 to 80 Mpps
Max Concurrent Connections192 M
Induced Latency< 1 milli-second
Operating Temperature Range (°C)0° to 40° C
Storage Temperature Range (°C)8° to 45° C
Operating Humidity (%RH)8% to 95%

HD-CAN Series

The following common features are available across all HD-CAN Series models.

PLATFORM & TECHNOLOGY
Platform & TechnologyHaltdos Platform with Signature from Threat Intelligence & Machine Learning
LicenseUnlimited applications. Bandwidth capped by license. Upgrade possible without hardware replacement up to max supported hardware bandwidth
Additional LicensesOptional license for GSLB, LLB, DDoS and SSL VPN
CertificationsFCC, ROHS, CE compliant, EAL 2+, IPv6 Ready Gold certifications
Support24x7 via Online, Email, Telephone and Dedicated Account Manager
Warranty1 year warranty. Additional charges for extended warranty
TAC SupportTAC support in India
INTEGRATION FEATURES
Custom Threat IntelIntegration with 3rd party Threat Intelligence (TI) feeds
Storage and ExportLocal retention of logs, reports and events. Support for export to 3rd party storage
NIMS IntegrationSupport for SNMP, NTP / SNTP, DNS, Web Proxy integration
3rd Party IntegrationNotification & Logging via SNMP, SMTP, SMS Gateway, and 3rd party integration via API hooks, CI/CD, Kubernetes
SIEM IntegrationSupport for integration with SIEM and Syslog services
AAA IntegrationSupport for integration via RADIUS and TACACS+
Identity ManagementInbuilt with support for integration with AD / SAML / LDAP
Security Tools IntegrationSupport for integration with SAST/DAST/IAST tools. Integration with 3rd party Threat Intelligence (TI) feeds
Export IOCsSupport for exporting attacking IOCs via STIX / TAXII
OPERATION MODE
Network OperationsOffline, Inline Reverse Proxy, Inline Forward Proxy, Inline Bridge, Inline Router Mode, Inline L2 Transparent
Inline ModesProxy or Direct Server Return, Immediate or Delayed Binding
Deployment Modes1-Arm or n-Arm, Support for Virtual Matrix Architecture & Direct Access Mode
BindingImmediate or Delayed binding
IP StackDual IPv4 & IPv6 stack
Supported HTTP ProtocolsHTTP 0.9, 1.0, 1.1, 2.0, 3.0 (QUIC) with translation
Web Socket SupportYes
Virtual Matrix ArchitectureYes
Direct Access ModeYes
Mitigation ModesBypass, Record (Report Only), Learning, Mitigation (Block & Report)
Tunnelling ProtocolsVLAN, MPLS, GRE, L2TP, GTP, IPinIP
Dynamic RoutingBGP, OSPF, RIPv1/v2
NetworkingVLAN, VXLAN, Link Aggregation & Trunking (LACP), Multiple Routing Tables, ARP Table etc.
Block ActionsDrop Request, Terminate Connection / Session, Rate Limiting, Blacklist (Temporary or Permanent), Send Challenge, Tarpit
VirtualizationMulti-tenancy with isolated VMs with dedicated CPU, RAM and Disk. Support for multiple OS templates for customized deployments
Supported Flow IngestionNetflow v5, Netflow v9, sFlow, IPFIX
HIGH AVAILABILITY
Multiple AppliancesN + 1 Active - Active or Active – Passive (VRRP) with floating MAC
Management ModesStandalone / Centralized Management (VM or appliance)
Secure CommunicationSecure communication between centralized management and HA appliances for full state synchronization
MANAGEMENT FEATURES
Graphical User Interface (GUI)Secure web interface over HTTPs with support for all modern browsers
API IntegrationYes (XML or JSON)
Command Line Interface (CLI)Command Line Interface over SSH or console port
System ManagementIPMI 2.0 Compliant
Audit Trail, Logging & RecoveryCentralized logging of system, services, MIS, incidents. Built-in MIS with policy recovery
Dashboards & ReportingReal-Time & historical dashboards with custom duration. Support for custom dashboards. Status dashboard for 1-click health check. Periodic daily, weekly or monthly reports in PDF or Excel
RBAC AdministrationConfigurable user profiles with role based access control
Policy ManagementOn the fly configuration updates on mitigation appliances
Backup, Restore & SnapshotsAutomatic or manual backup and restore. CLI tool for pushing current snapshot to Haltdos Cloud for diagnostics
Certificate ManagementSSL/TLS certificate management with support for Let’s Encrypt certificate generation
Events / AlertsDetailed event and alert reporting on attack, health, etc.
Network ForensicsNetwork forensic with packet capture and traceroute. Built-in utilities for investigating attacks, payloads and managing false positives
UpdatesPeriodic threat intel updates (Signatures, Geo IP, Bad IP, TOR IP, Anon Proxy, etc.) from Haltdos. Update and upgrade management on version releases and patch updates from Haltdos. Support for multiple OS Templates
Snapshots & Cloud SyncAutomatic and/or manual policy snapshot for diagnosis, policy creation & enforcement using AI/ML via Haltdos cloud
Backup & RestoreAutomatic or Manual Backup and restore. CLI tool for pushing current snapshot to Haltdos cloud for diagnostic.
Haltdos Threat StreamPeriodic threat intel update (signatures, Geo IP, Bad IP, TOR IP, Anon Proxy, etc.) from Haltdos.
ADC FEATURES
Enforce RFC ComplianceProtection against invalid HTTP, MQTT requests
NAT & RoutingSupport for client, server or full NAT, static routing for IPv4 & IPv6
Advanced Load BalancingContent based load balancing with upstream rules
Load BalancingLayer 4 (TCP, UDP, Mail, etc.) and Layer 7 (HTTP, DNS, etc.) supported
SSL/TLS ManagementSupport for SSL v2/v3, TLS 1.0/1.1/1.2/1.3 offloading (and re-encryption) with custom cipher suites. Client certificate based authentication also supported, proxy SSL/TLS connections. Conditional SSL offloading by SRC, DST, SNI etc.
Virtual ContextsSupport for multiple virtual contexts along with resource allocation
Load Balancing AlgorithmsRound robin (RR), weighted round robin, minimum misses, persistent hash, tuneable hash, least connections, least response time, least bandwidth, SNMP metrics such as CPU, RAM, etc.
Network OptimizationSupport for TCP buffering, multiplexing & optimization, connection pools, TCP keep alive & timeouts
HTTP OptimizationSupport for content compression (gzip or brotili) and caching. Content minification and acceleration for mobile clients
Failover ManagementAutomatic failover & recovery. Support for marking servers up / down / backup
Health CheckPeriodic server or server group health check and alerting via TCP, SSL, ICMP, SNMP, HTTP, DNS or custom script
Client VisibilityEmbedding Real IP information in X-* headers, client cert information, etc.
Redirection RulesREGEX based redirection rules to rewrite URLs
Variable RulesSupport for embedding and using variables for A/B testing or custom load balancing
Script RulesEmbedding user defined custom code for advanced routing
Error HandlingError rules for custom error handling
Content TransformationTransformation rules for data manipulation and Header rules for add / edit or delete headers in request or response JSON to XML, HTTP to MQTT & vice versa
End-User Fingerprinting & MonitoringAdvanced user and device fingerprinting for user profiling and Real User Metrics (RUM) for performance monitoring
DDoS ProtectionProtection against volumetric and low & slow DDoS attacks. Support for rate limiting based on connections and requests
CompliancePCI DSS 2.0 section 6.6 enforcement
API SecurityBuilt-in API gateway for authentication, rate limiting, transformation, documentation and discovery
AuthenticationSupport for Single SignOn with multiple Auth type like Basic Auth, Form Auth, NTLM, LDAP, SAML, etc.
Forwarding RuleSupport traffic chaining, decrypt traffic forwarding to one or more devices.
WAF FEATURES
Comprehensive SecurityOWASP Top 10 Web Application Security Risks, OWASP Top 20 Automated Threats and SANS 25 Software Errors
Security ProfilesMultiple security profiles with support for different security status per application based on url, source, country, regex, etc.
Positive Security ModelSupport for Form Rules for positive security model
Negative Security ModelSupport for user defined Firewall Rules for REGEX based negative security model
Virtual PatchingSupport for virtual patching through built-in web security scanner or upload of 3rd party SAST / DAST / IAST scan results
Built-in SignaturesOver 4000+ built-in signatures on various technologies, platforms and frameworks with pre-defined templates
Bot ManagementAnti-bot protection with AI classification and scoring of bots based on advanced browser fingerprinting
0-day ProtectionAutomatic learning and profiling application structure. Threat scoring and baseline creation for AI driven 0-day attack protection
Anti-Automation ProtectionProtection against known and 0-day bots, account takeover attempts, brute force attempts, scraping, reconnaissance, cloaking, etc.
Mobile App ProtectionAnti-Bot mobile SDK for Android & iOS for protecting mobile apps and communication between apps and web APIs
AV ScanningBuilt-in AV scanner for malicious file upload. Support for ICAP integration for 3rd party scanners
Minimize False PositivesSupport for REGEX based whitelist rules and signature staging and deploy policies to minimize signature based false positives
HTTP ValidationsProtocol validations, request normalization (encoding & evasion techniques) before inspection, managing security headers and cookies etc.
Policy InspectionPolicy validation such as HTTP methods, file extension, request size, etc.
Blacklist / WhitelistSupport for temporary or permanent Blacklisting and Whitelisting based on IP, IP prefix, url, country, etc.
Challenge-ResponseSupport for JS, Crypto and CAPTCHA challenge on suspicious user activity or known bots or malicious IPs
Rate LimitingRate Limit rules for implementing request, bandwidth or connection limits per source, IP prefix or user defined policy
API & WebSocket ProtectionBuilt-in XML firewall, validation of XML / JSON / Ajax requests and WebSocket requests
Security Breach PreventionBuilt-in support for data leak prevention, response filtering for sensitive personal identifiable information
Tamper ProofingTamper rules for URL / parameter tamper protection, website defacement, hidden form field protection, cookie signing and encryption, etc.
Correlation EngineAdvanced correlation engine with support for custom correlation rules for detecting attack across user requests and sessions
Variables & ScriptingSupport for user defined variables and scripts for building custom application specific security policy
Deception TechnologyImplement decoys in web application to protect against advanced bots, profile attacks and trap attackers
L3-L7 DDOS PROTECTIONProtection against volumetric and low & slow DDoS attacks
Sensitive Data MaskingSupport for Log Rules for masking sensitive information such as passwords in logs and events
Malicious Source ProtectionProtection against TOR IP, Bad Reputation IP, dark IP, known Bots, proxies, spammers provided by Haltdos or user defined threat intel
Enforced BrowsingProtection against forceful browsing, access to private resources, unauthorized navigation with additional security enforcement with Two factor authentication (2FA)
DDoS Detection & MitigationAttack detection & mitigation in less than 18s and 10s respectively
Captcha ChallengeSupport for JS or Captcha challenge on suspicious user activity or known bots or Malicious IPs.
API SecurityBuilt-in API gateway for authentication, rate limiting, transformation, documentation and discovery
Misc. ProtectionSupport for protection against buffer overflow attacks, man-in-the-middle attacks, blocking malware payload, buffer overflow, SQL, SSI, LDAP injection, etc.
ANTI-DDoS FEATURES (ADDITIONAL LICENSING)
Comprehensive SecurityLayer 3 to Layer 7 protection covering Network, Protocol, Application, Reflection / Amplification and 0-day DDoS attacks
Block ActionsDrop Packet, Terminate Connection (RST), Blacklist (temporary or permanent), Send Challenge (TCP, HTTP, DNS), Rate Limiting
Hybrid DDoS IntegrationSupport for integration with Haltdos Cloud Scrubbing or ISP clean pipe services
Bi-DirectionalSupport for both inbound and outbound traffic protection
Deep Packet InspectionProtection against malformed packets (TCP, UDP, ICMP, Ping of death, DNS, HTTP, SIP, SNMP, IPv4, IPv6, Fragmented packets, etc.)
Enforce RFC ComplianceProtection against misbehaving clients sending invalid or out of state packets
Bot ProtectionAutomatic detection and blocking of bot traffic with support for manual bot policy
Behavior AnalysisNetwork behavior analysis for anomaly detection and packet scoring technology
Multiple Security ProfilesSupport for multiple security profiles for enforcing different policy for different sub-networks (Src, Dst IP Prefix, VLAN). Default Global security profile
Port MirroringMirror traffic / specific traffic to another NIC port
Rate Limit & QoS ManagementRate limit capability for bandwidth and QoS management with option for rate limit of specific traffic (based on proto, src, dst, etc.)
Blacklist / WhitelistSupport for temporary or permanent Blacklisting and Whitelisting based on IP, IP prefix, domain, country, etc.
Malicious Source ProtectionProtection against TOR IP, Bad Reputation IP, dark IP, known Bots, proxies, spammers provided by Haltdos or user defined threat intel
Custom SignaturesSupport for user defined custom rules with support for REGEX and byte matching
SYN Flood ProtectionTCP SYN flood protection with SYN Proxy and connection aging
Challenge & ResponseSupport for TCP, HTTP, DNS challenge and response for validation of traffic from suspicious sources
Connection Based ProtectionProtection against TCP connection DDoS attacks such as sockstress, connection / src, zombie flood, SSL renegotiations, etc.
DNS ProtectionBuilt-in DNS firewall capability for protecting DNS infrastructure against DNS DDoS attacks (Water Torture, NXDomain, etc.)
L7 DDoS ProtectionProtection against low & slow attacks such as Slowloris, R.U.D.Y., slow HTTP GET / POST, etc.
Machine Learning ProtectionAutomatic learning counter measures and dynamic signature creation upon attack detection
Signatures for Known VulnerabilitiesBuilt-in rules for known vulnerabilities (server, web, mail, FTP, SIP, SQL, DNS, etc.)
DDoS Protection & MitigationAttack detection & mitigation in less than 18s and 10s respectively.
Adaptive Packet Scoring EngineHigh-performance software-defined packet processing engine with an NPU-inspired packet processing architecture, utilizing adaptive packet scoring, behavioral analysis, machine learning, and threat intelligence for real-time Layer 3–Layer 7 traffic inspection and attack mitigation.
LLB FEATURES (ADDITIONAL LICENSING)
Load Balancing & Path SelectionRound robin (RR), weighted round robin, minimum packet loss, persistent hash, tuneable hash, least connections, least response time, least bandwidth, minimum jitter, etc.
NAT RulesSupport for static NAT, dynamic NAT, SNAT, DNAT, PAT, Full NAT
WAN ConfigurationSupports multiple WAN connectivity such as Static IP, DHCP, PPPoE, Bridge, transparent mode etc.
Health MonitoringLink monitoring with instant failover (<1s). Support for TCP, HTTP, DNS, ICMP or script based monitoring
Routing RulesCustom rules for Static and Policy based routing
Dual Stack LiteSupport for NAT 46 / 64 and DNS 46 / 64 with DNS Proxy
Traffic ShapingTraffic shaping and QoS on inbound and outbound links
GSLB FEATURES (ADDITIONAL LICENSING)
Global Load BalancingRouting traffic across multiple data centers based on health checks
WAN Load BalancingOutbound WAN link selection based on link health
Load Balancing AlgorithmsSupport for Least connection, Proximity, Round Robin, Weighted RR, Persistent Hash, Geo, etc.
Operation ModeOption for Authoritative or Recursive operational modes with support for various DNS record types such as A, AAAA, MX, TXT, PTR, etc.
Routing RulesCustom rules for Static and Policy based routing
Network ModeSupport DNS over HTTP, UDP, TCP & SSL as well as DNSSEC
DNS FirewallProtecting DNS infrastructure from bot attacks, data exfiltration attacks, RPZ policy
Blacklist / WhitelistSupport for permanent Blacklisting and Whitelisting based on IP, IP prefix, domain, country, etc.
Custom SignaturesSupport for user defined custom rules with support for pattern, suffix, domain, etc.
VPN FEATURES (ADDITIONAL LICENSING)
HTTP ProtocolsHTTP 0.9/1.0/1.1/2.0 with translation
Client SupportProvides access for Windows, Linux, Mobile Apps (Android and iOS), and Web (via browser-based solutions)
AuthenticationSupports Password, SAML, AD/LDAP, SSO, AAA, OAuth, Step-up Authentication and third-party integrations via Webhooks
NAT & RoutingEnables client, server, or full NAT and static routing for IPv4 and IPv6
User GroupingAllows creation of multiple users and user groups with granular access control
Clientless AccessOffers secure resource access via web browsers without additional client installation
Granular Access ControlConfigurable policies to control user access to specific resources and applications based upon time, country, user-group and IP addresses
Endpoint SecurityValidates the security posture of devices before granting access by performing Antivirus and Malware Scan of the devices, Windows Registry checks etc.
Concurrent User / ScalabilityScalable architecture supporting expansion to 4000+ concurrent users through vertical/horizontal scaling.
Multi-Factor Authentication (MFA)Additional verification factors, such as Email based OTP, TOTP, while accessing resources remotely
Split TunnelingConfigurable options for routing only specific traffic through the secure tunnel
Zero Trust PrinciplesStrict verification of users and devices before granting access
Dual Stack LiteSupport for NAT 46 / 64 and DNS 46 / 64 with DNS Proxy
SSL/TLS ManagementSupport for SSL v2/v3, TLS 1.0/1.1/1.2/1.3 offloading (and re-encryption) with custom cipher suites. Client certificate-based authentication also supported, proxy SSL/TLS Connections.
IP Address ManagementDynamic IP allocation from configurable network pools (IPv4/IPv6) with automated lease management
VPN Protocol & EncryptionModern VPN protocol utilizing Noise protocol framework with Curve25519 for key exchange, ChaCha20 for encryption, Poly1305 for authentication, and BLAKE2s for hashing
NetworkingSupport for VLAN, Link Aggregation & Trunking (LACP)
Policy RulesHTTP request interception with policy-based traffic filtering with comprehensive request logging at VPN authentication layer
Dynamic Routing ProtocolsBGP, OSPF, RIP v1, RIP v2