Hardware Specs
Haltdos hardware specs page introduce customers about various range of models along with their hardware specifications.
Model - HD-CAN-4100
| MITIGATION PERFORMANCE | |
|---|---|
| L4 Throughput | upto 5 Gbps |
| L7 Throughput | upto 4 Gbps |
| SSL Throughput | upto 4 Gbps |
| Compression Throughput | 4 Gbps |
| Decompression Throughput | 5 Gbps |
| SSL/TLS Connections per Second | 22K (RSA 2K) & 15K (ECC) |
| L4 Connection per Second | 3M |
| L7 Request per Second | 1M |
| DDoS Attack Flood Prevention Rate | 1 to 5 Mpps |
| Max Concurrent Connections | 24 M |
| Induced Latency | < 1 milli-second |
| Operating Temperature Range (°C) | 0° to 40° C |
| Storage Temperature Range (°C) | 0° to 45° C |
| Operating Humidity (%RH) | 8% to 95% |
Model - HD-CAN-4600
| MITIGATION PERFORMANCE | |
|---|---|
| L4 Throughput | upto 24 Gbps |
| L7 Throughput | upto 20 Gbps |
| SSL Throughput | upto 20 Gbps |
| Compression Throughput | 20 Gbps |
| Decompression Throughput | 20 Gbps |
| SSL/TLS Connections per Second | 40K (RSA 2K) 25K (ECC) |
| L4 Connection per Second | 1.2M |
| L7 Request per Second | 3M |
| DDoS Attack Flood Prevention Rate | 5 to 20 Mpps |
| Max Concurrent Connections | 24M |
| Induced Latency | < 1 milli-second |
| Operating Temperature Range (°C) | 0° to 40° C |
| Storage Temperature Range (°C) | 0° to 45° C |
| Operating Humidity (%RH) | 8% to 95% |
Model - HD-CAN-5100
| MITIGATION PERFORMANCE | |
|---|---|
| L4 Throughput | upto 48 Gbps |
| L7 Throughput | upto 40 Gbps |
| SSL Throughput | upto 40 Gbps |
| Compression Throughput | 24 Gbps |
| Decompression Throughput | 30 Gbps |
| SSL/TLS Connections per Second | 50K (RSA 2K) 25K (ECC) |
| L4 Connection per Second | 7M |
| L7 Request per Second | 7M |
| DDoS Attack Flood Prevention Rate | 10 to 30 Mpps |
| Max Concurrent Connections | 56M |
| Induced Latency | < 1 milli-second |
| Operating Temperature Range (°C) | 0° to 40° C |
| Storage Temperature Range (°C) | 0° to 45° C |
| Operating Humidity (%RH) | 8% to 95% |
Model - HD-CAN-5400
| MITIGATION PERFORMANCE | |
|---|---|
| L4 Throughput | upto 72 Gbps |
| L7 Throughput | upto 60 Gbps |
| SSL Throughput | upto 50 Gbps |
| Compression Throughput | 37 Gbps |
| Decompression Throughput | 54 Gbps |
| SSL/TLS Connections per Second | 100K (RSA 2K) 50K (ECC) |
| L4 Connection per Second | 10M |
| L7 Request per Second | 10M |
| DDoS Attack Flood Prevention Rate | 25 to 50 Mpps |
| Max Concurrent Connections | 96M |
| Induced Latency | < 1 milli-second |
| Operating Temperature Range (°C) | 0° to 40° C |
| Storage Temperature Range (°C) | 0° to 45° C |
| Operating Humidity (%RH) | 8% to 95% |
Model - HD-CAN-6200
| MITIGATION PERFORMANCE | |
|---|---|
| L4 Throughput | upto 120 Gbps |
| L7 Throughput | upto 100 Gbps |
| SSL Throughput | upto 100 Gbps |
| Compression Throughput | 66 Gbps |
| Decompression Throughput | 120 Gbps |
| SSL/TLS Connections per Second | 150K (RSA 2K) 75K (ECC) |
| L4 Connection per Second | 12M |
| L7 Request per Second | 15M |
| DDoS Attack Flood Prevention Rate | 50 to 80 Mpps |
| Max Concurrent Connections | 160 M |
| Induced Latency | < 1 milli-second |
| Operating Temperature Range (°C) | 0° to 40° C |
| Storage Temperature Range (°C) | 8° to 45° C |
| Operating Humidity (%RH) | 8% to 95% |
Model - HD-CAN-6700
| MITIGATION PERFORMANCE | |
|---|---|
| L4 Throughput | upto 150 Gbps |
| L7 Throughput | upto 120 Gbps |
| SSL Throughput | upto 200 Gbps |
| Compression Throughput | 132 Gbps |
| Decompression Throughput | 240 Gbps |
| SSL/TLS Connections per Second | 200K (RSA 2K) 100K (ECC) |
| L4 Connection per Second | 15M |
| L7 Request per Second | 18M |
| DDoS Attack Flood Prevention Rate | 50 to 80 Mpps |
| Max Concurrent Connections | 192 M |
| Induced Latency | < 1 milli-second |
| Operating Temperature Range (°C) | 0° to 40° C |
| Storage Temperature Range (°C) | 8° to 45° C |
| Operating Humidity (%RH) | 8% to 95% |
HD-CAN Series
The following common features are available across all HD-CAN Series models.
| PLATFORM & TECHNOLOGY | |
|---|---|
| Platform & Technology | Haltdos Platform with Signature from Threat Intelligence & Machine Learning |
| License | Unlimited applications. Bandwidth capped by license. Upgrade possible without hardware replacement up to max supported hardware bandwidth |
| Additional Licenses | Optional license for GSLB, LLB, DDoS and SSL VPN |
| Certifications | FCC, ROHS, CE compliant, EAL 2+, IPv6 Ready Gold certifications |
| Support | 24x7 via Online, Email, Telephone and Dedicated Account Manager |
| Warranty | 1 year warranty. Additional charges for extended warranty |
| TAC Support | TAC support in India |
| INTEGRATION FEATURES | |
|---|---|
| Custom Threat Intel | Integration with 3rd party Threat Intelligence (TI) feeds |
| Storage and Export | Local retention of logs, reports and events. Support for export to 3rd party storage |
| NIMS Integration | Support for SNMP, NTP / SNTP, DNS, Web Proxy integration |
| 3rd Party Integration | Notification & Logging via SNMP, SMTP, SMS Gateway, and 3rd party integration via API hooks, CI/CD, Kubernetes |
| SIEM Integration | Support for integration with SIEM and Syslog services |
| AAA Integration | Support for integration via RADIUS and TACACS+ |
| Identity Management | Inbuilt with support for integration with AD / SAML / LDAP |
| Security Tools Integration | Support for integration with SAST/DAST/IAST tools. Integration with 3rd party Threat Intelligence (TI) feeds |
| Export IOCs | Support for exporting attacking IOCs via STIX / TAXII |
| OPERATION MODE | |
|---|---|
| Network Operations | Offline, Inline Reverse Proxy, Inline Forward Proxy, Inline Bridge, Inline Router Mode, Inline L2 Transparent |
| Inline Modes | Proxy or Direct Server Return, Immediate or Delayed Binding |
| Deployment Modes | 1-Arm or n-Arm, Support for Virtual Matrix Architecture & Direct Access Mode |
| Binding | Immediate or Delayed binding |
| IP Stack | Dual IPv4 & IPv6 stack |
| Supported HTTP Protocols | HTTP 0.9, 1.0, 1.1, 2.0, 3.0 (QUIC) with translation |
| Web Socket Support | Yes |
| Virtual Matrix Architecture | Yes |
| Direct Access Mode | Yes |
| Mitigation Modes | Bypass, Record (Report Only), Learning, Mitigation (Block & Report) |
| Tunnelling Protocols | VLAN, MPLS, GRE, L2TP, GTP, IPinIP |
| Dynamic Routing | BGP, OSPF, RIPv1/v2 |
| Networking | VLAN, VXLAN, Link Aggregation & Trunking (LACP), Multiple Routing Tables, ARP Table etc. |
| Block Actions | Drop Request, Terminate Connection / Session, Rate Limiting, Blacklist (Temporary or Permanent), Send Challenge, Tarpit |
| Virtualization | Multi-tenancy with isolated VMs with dedicated CPU, RAM and Disk. Support for multiple OS templates for customized deployments |
| Supported Flow Ingestion | Netflow v5, Netflow v9, sFlow, IPFIX |
| HIGH AVAILABILITY | |
|---|---|
| Multiple Appliances | N + 1 Active - Active or Active – Passive (VRRP) with floating MAC |
| Management Modes | Standalone / Centralized Management (VM or appliance) |
| Secure Communication | Secure communication between centralized management and HA appliances for full state synchronization |
| MANAGEMENT FEATURES | |
|---|---|
| Graphical User Interface (GUI) | Secure web interface over HTTPs with support for all modern browsers |
| API Integration | Yes (XML or JSON) |
| Command Line Interface (CLI) | Command Line Interface over SSH or console port |
| System Management | IPMI 2.0 Compliant |
| Audit Trail, Logging & Recovery | Centralized logging of system, services, MIS, incidents. Built-in MIS with policy recovery |
| Dashboards & Reporting | Real-Time & historical dashboards with custom duration. Support for custom dashboards. Status dashboard for 1-click health check. Periodic daily, weekly or monthly reports in PDF or Excel |
| RBAC Administration | Configurable user profiles with role based access control |
| Policy Management | On the fly configuration updates on mitigation appliances |
| Backup, Restore & Snapshots | Automatic or manual backup and restore. CLI tool for pushing current snapshot to Haltdos Cloud for diagnostics |
| Certificate Management | SSL/TLS certificate management with support for Let’s Encrypt certificate generation |
| Events / Alerts | Detailed event and alert reporting on attack, health, etc. |
| Network Forensics | Network forensic with packet capture and traceroute. Built-in utilities for investigating attacks, payloads and managing false positives |
| Updates | Periodic threat intel updates (Signatures, Geo IP, Bad IP, TOR IP, Anon Proxy, etc.) from Haltdos. Update and upgrade management on version releases and patch updates from Haltdos. Support for multiple OS Templates |
| Snapshots & Cloud Sync | Automatic and/or manual policy snapshot for diagnosis, policy creation & enforcement using AI/ML via Haltdos cloud |
| Backup & Restore | Automatic or Manual Backup and restore. CLI tool for pushing current snapshot to Haltdos cloud for diagnostic. |
| Haltdos Threat Stream | Periodic threat intel update (signatures, Geo IP, Bad IP, TOR IP, Anon Proxy, etc.) from Haltdos. |
| ADC FEATURES | |
|---|---|
| Enforce RFC Compliance | Protection against invalid HTTP, MQTT requests |
| NAT & Routing | Support for client, server or full NAT, static routing for IPv4 & IPv6 |
| Advanced Load Balancing | Content based load balancing with upstream rules |
| Load Balancing | Layer 4 (TCP, UDP, Mail, etc.) and Layer 7 (HTTP, DNS, etc.) supported |
| SSL/TLS Management | Support for SSL v2/v3, TLS 1.0/1.1/1.2/1.3 offloading (and re-encryption) with custom cipher suites. Client certificate based authentication also supported, proxy SSL/TLS connections. Conditional SSL offloading by SRC, DST, SNI etc. |
| Virtual Contexts | Support for multiple virtual contexts along with resource allocation |
| Load Balancing Algorithms | Round robin (RR), weighted round robin, minimum misses, persistent hash, tuneable hash, least connections, least response time, least bandwidth, SNMP metrics such as CPU, RAM, etc. |
| Network Optimization | Support for TCP buffering, multiplexing & optimization, connection pools, TCP keep alive & timeouts |
| HTTP Optimization | Support for content compression (gzip or brotili) and caching. Content minification and acceleration for mobile clients |
| Failover Management | Automatic failover & recovery. Support for marking servers up / down / backup |
| Health Check | Periodic server or server group health check and alerting via TCP, SSL, ICMP, SNMP, HTTP, DNS or custom script |
| Client Visibility | Embedding Real IP information in X-* headers, client cert information, etc. |
| Redirection Rules | REGEX based redirection rules to rewrite URLs |
| Variable Rules | Support for embedding and using variables for A/B testing or custom load balancing |
| Script Rules | Embedding user defined custom code for advanced routing |
| Error Handling | Error rules for custom error handling |
| Content Transformation | Transformation rules for data manipulation and Header rules for add / edit or delete headers in request or response JSON to XML, HTTP to MQTT & vice versa |
| End-User Fingerprinting & Monitoring | Advanced user and device fingerprinting for user profiling and Real User Metrics (RUM) for performance monitoring |
| DDoS Protection | Protection against volumetric and low & slow DDoS attacks. Support for rate limiting based on connections and requests |
| Compliance | PCI DSS 2.0 section 6.6 enforcement |
| API Security | Built-in API gateway for authentication, rate limiting, transformation, documentation and discovery |
| Authentication | Support for Single SignOn with multiple Auth type like Basic Auth, Form Auth, NTLM, LDAP, SAML, etc. |
| Forwarding Rule | Support traffic chaining, decrypt traffic forwarding to one or more devices. |
| WAF FEATURES | |
|---|---|
| Comprehensive Security | OWASP Top 10 Web Application Security Risks, OWASP Top 20 Automated Threats and SANS 25 Software Errors |
| Security Profiles | Multiple security profiles with support for different security status per application based on url, source, country, regex, etc. |
| Positive Security Model | Support for Form Rules for positive security model |
| Negative Security Model | Support for user defined Firewall Rules for REGEX based negative security model |
| Virtual Patching | Support for virtual patching through built-in web security scanner or upload of 3rd party SAST / DAST / IAST scan results |
| Built-in Signatures | Over 4000+ built-in signatures on various technologies, platforms and frameworks with pre-defined templates |
| Bot Management | Anti-bot protection with AI classification and scoring of bots based on advanced browser fingerprinting |
| 0-day Protection | Automatic learning and profiling application structure. Threat scoring and baseline creation for AI driven 0-day attack protection |
| Anti-Automation Protection | Protection against known and 0-day bots, account takeover attempts, brute force attempts, scraping, reconnaissance, cloaking, etc. |
| Mobile App Protection | Anti-Bot mobile SDK for Android & iOS for protecting mobile apps and communication between apps and web APIs |
| AV Scanning | Built-in AV scanner for malicious file upload. Support for ICAP integration for 3rd party scanners |
| Minimize False Positives | Support for REGEX based whitelist rules and signature staging and deploy policies to minimize signature based false positives |
| HTTP Validations | Protocol validations, request normalization (encoding & evasion techniques) before inspection, managing security headers and cookies etc. |
| Policy Inspection | Policy validation such as HTTP methods, file extension, request size, etc. |
| Blacklist / Whitelist | Support for temporary or permanent Blacklisting and Whitelisting based on IP, IP prefix, url, country, etc. |
| Challenge-Response | Support for JS, Crypto and CAPTCHA challenge on suspicious user activity or known bots or malicious IPs |
| Rate Limiting | Rate Limit rules for implementing request, bandwidth or connection limits per source, IP prefix or user defined policy |
| API & WebSocket Protection | Built-in XML firewall, validation of XML / JSON / Ajax requests and WebSocket requests |
| Security Breach Prevention | Built-in support for data leak prevention, response filtering for sensitive personal identifiable information |
| Tamper Proofing | Tamper rules for URL / parameter tamper protection, website defacement, hidden form field protection, cookie signing and encryption, etc. |
| Correlation Engine | Advanced correlation engine with support for custom correlation rules for detecting attack across user requests and sessions |
| Variables & Scripting | Support for user defined variables and scripts for building custom application specific security policy |
| Deception Technology | Implement decoys in web application to protect against advanced bots, profile attacks and trap attackers |
| L3-L7 DDOS PROTECTION | Protection against volumetric and low & slow DDoS attacks |
| Sensitive Data Masking | Support for Log Rules for masking sensitive information such as passwords in logs and events |
| Malicious Source Protection | Protection against TOR IP, Bad Reputation IP, dark IP, known Bots, proxies, spammers provided by Haltdos or user defined threat intel |
| Enforced Browsing | Protection against forceful browsing, access to private resources, unauthorized navigation with additional security enforcement with Two factor authentication (2FA) |
| DDoS Detection & Mitigation | Attack detection & mitigation in less than 18s and 10s respectively |
| Captcha Challenge | Support for JS or Captcha challenge on suspicious user activity or known bots or Malicious IPs. |
| API Security | Built-in API gateway for authentication, rate limiting, transformation, documentation and discovery |
| Misc. Protection | Support for protection against buffer overflow attacks, man-in-the-middle attacks, blocking malware payload, buffer overflow, SQL, SSI, LDAP injection, etc. |
| ANTI-DDoS FEATURES (ADDITIONAL LICENSING) | |
|---|---|
| Comprehensive Security | Layer 3 to Layer 7 protection covering Network, Protocol, Application, Reflection / Amplification and 0-day DDoS attacks |
| Block Actions | Drop Packet, Terminate Connection (RST), Blacklist (temporary or permanent), Send Challenge (TCP, HTTP, DNS), Rate Limiting |
| Hybrid DDoS Integration | Support for integration with Haltdos Cloud Scrubbing or ISP clean pipe services |
| Bi-Directional | Support for both inbound and outbound traffic protection |
| Deep Packet Inspection | Protection against malformed packets (TCP, UDP, ICMP, Ping of death, DNS, HTTP, SIP, SNMP, IPv4, IPv6, Fragmented packets, etc.) |
| Enforce RFC Compliance | Protection against misbehaving clients sending invalid or out of state packets |
| Bot Protection | Automatic detection and blocking of bot traffic with support for manual bot policy |
| Behavior Analysis | Network behavior analysis for anomaly detection and packet scoring technology |
| Multiple Security Profiles | Support for multiple security profiles for enforcing different policy for different sub-networks (Src, Dst IP Prefix, VLAN). Default Global security profile |
| Port Mirroring | Mirror traffic / specific traffic to another NIC port |
| Rate Limit & QoS Management | Rate limit capability for bandwidth and QoS management with option for rate limit of specific traffic (based on proto, src, dst, etc.) |
| Blacklist / Whitelist | Support for temporary or permanent Blacklisting and Whitelisting based on IP, IP prefix, domain, country, etc. |
| Malicious Source Protection | Protection against TOR IP, Bad Reputation IP, dark IP, known Bots, proxies, spammers provided by Haltdos or user defined threat intel |
| Custom Signatures | Support for user defined custom rules with support for REGEX and byte matching |
| SYN Flood Protection | TCP SYN flood protection with SYN Proxy and connection aging |
| Challenge & Response | Support for TCP, HTTP, DNS challenge and response for validation of traffic from suspicious sources |
| Connection Based Protection | Protection against TCP connection DDoS attacks such as sockstress, connection / src, zombie flood, SSL renegotiations, etc. |
| DNS Protection | Built-in DNS firewall capability for protecting DNS infrastructure against DNS DDoS attacks (Water Torture, NXDomain, etc.) |
| L7 DDoS Protection | Protection against low & slow attacks such as Slowloris, R.U.D.Y., slow HTTP GET / POST, etc. |
| Machine Learning Protection | Automatic learning counter measures and dynamic signature creation upon attack detection |
| Signatures for Known Vulnerabilities | Built-in rules for known vulnerabilities (server, web, mail, FTP, SIP, SQL, DNS, etc.) |
| DDoS Protection & Mitigation | Attack detection & mitigation in less than 18s and 10s respectively. |
| Adaptive Packet Scoring Engine | High-performance software-defined packet processing engine with an NPU-inspired packet processing architecture, utilizing adaptive packet scoring, behavioral analysis, machine learning, and threat intelligence for real-time Layer 3–Layer 7 traffic inspection and attack mitigation. |
| LLB FEATURES (ADDITIONAL LICENSING) | |
|---|---|
| Load Balancing & Path Selection | Round robin (RR), weighted round robin, minimum packet loss, persistent hash, tuneable hash, least connections, least response time, least bandwidth, minimum jitter, etc. |
| NAT Rules | Support for static NAT, dynamic NAT, SNAT, DNAT, PAT, Full NAT |
| WAN Configuration | Supports multiple WAN connectivity such as Static IP, DHCP, PPPoE, Bridge, transparent mode etc. |
| Health Monitoring | Link monitoring with instant failover (<1s). Support for TCP, HTTP, DNS, ICMP or script based monitoring |
| Routing Rules | Custom rules for Static and Policy based routing |
| Dual Stack Lite | Support for NAT 46 / 64 and DNS 46 / 64 with DNS Proxy |
| Traffic Shaping | Traffic shaping and QoS on inbound and outbound links |
| GSLB FEATURES (ADDITIONAL LICENSING) | |
|---|---|
| Global Load Balancing | Routing traffic across multiple data centers based on health checks |
| WAN Load Balancing | Outbound WAN link selection based on link health |
| Load Balancing Algorithms | Support for Least connection, Proximity, Round Robin, Weighted RR, Persistent Hash, Geo, etc. |
| Operation Mode | Option for Authoritative or Recursive operational modes with support for various DNS record types such as A, AAAA, MX, TXT, PTR, etc. |
| Routing Rules | Custom rules for Static and Policy based routing |
| Network Mode | Support DNS over HTTP, UDP, TCP & SSL as well as DNSSEC |
| DNS Firewall | Protecting DNS infrastructure from bot attacks, data exfiltration attacks, RPZ policy |
| Blacklist / Whitelist | Support for permanent Blacklisting and Whitelisting based on IP, IP prefix, domain, country, etc. |
| Custom Signatures | Support for user defined custom rules with support for pattern, suffix, domain, etc. |
| VPN FEATURES (ADDITIONAL LICENSING) | |
|---|---|
| HTTP Protocols | HTTP 0.9/1.0/1.1/2.0 with translation |
| Client Support | Provides access for Windows, Linux, Mobile Apps (Android and iOS), and Web (via browser-based solutions) |
| Authentication | Supports Password, SAML, AD/LDAP, SSO, AAA, OAuth, Step-up Authentication and third-party integrations via Webhooks |
| NAT & Routing | Enables client, server, or full NAT and static routing for IPv4 and IPv6 |
| User Grouping | Allows creation of multiple users and user groups with granular access control |
| Clientless Access | Offers secure resource access via web browsers without additional client installation |
| Granular Access Control | Configurable policies to control user access to specific resources and applications based upon time, country, user-group and IP addresses |
| Endpoint Security | Validates the security posture of devices before granting access by performing Antivirus and Malware Scan of the devices, Windows Registry checks etc. |
| Concurrent User / Scalability | Scalable architecture supporting expansion to 4000+ concurrent users through vertical/horizontal scaling. |
| Multi-Factor Authentication (MFA) | Additional verification factors, such as Email based OTP, TOTP, while accessing resources remotely |
| Split Tunneling | Configurable options for routing only specific traffic through the secure tunnel |
| Zero Trust Principles | Strict verification of users and devices before granting access |
| Dual Stack Lite | Support for NAT 46 / 64 and DNS 46 / 64 with DNS Proxy |
| SSL/TLS Management | Support for SSL v2/v3, TLS 1.0/1.1/1.2/1.3 offloading (and re-encryption) with custom cipher suites. Client certificate-based authentication also supported, proxy SSL/TLS Connections. |
| IP Address Management | Dynamic IP allocation from configurable network pools (IPv4/IPv6) with automated lease management |
| VPN Protocol & Encryption | Modern VPN protocol utilizing Noise protocol framework with Curve25519 for key exchange, ChaCha20 for encryption, Poly1305 for authentication, and BLAKE2s for hashing |
| Networking | Support for VLAN, Link Aggregation & Trunking (LACP) |
| Policy Rules | HTTP request interception with policy-based traffic filtering with comprehensive request logging at VPN authentication layer |
| Dynamic Routing Protocols | BGP, OSPF, RIP v1, RIP v2 |