F5 VIPRION 4450 Blade
Securing, Optimizing, and Monetizing Service Provider Networks Beyond Scale
- Two Intel 12-core processors
- 256GB RAM
- 1.2 TB solid state drive
- Two 100GbE ports and Six 40GbE ports
- 180M concurrent connections with 140Gbps of L4 throughput
Overview:
The purpose-built, NEBS-compliant VIPRION 4450 blade delivers two 100GbE ports and six 40GbE ports, vastly increasing efficiency, throughput, and performance. It’s the first ADC to provide 100GbE ports in the QSFP28 form factor, delivering the smallest footprint and lowest power consumption of any 100GbE form factor. A VIPRION 4800 chassis fully loaded with VIPRION 4450 blades supports more than 1 Billion concurrent connections and over 1Tbps of DDoS protection. In the VIPRION 4480 or 4800 chassis, the 4450 delivers significant improvements for SSL and elliptical curve cryptography (ECC) performance, enhancing perfect forward secrecy (PFS). Advanced FPGAs, memory, and hardware search on the VIPRION 4450 handles and efficiently addresses software-defined networking (SDN) needs, delivering CPU offloading, optimization, and adaptability.
Service providers are overwhelmed by an ever-increasing number of mobile devices that require connectivity to the providers’ networks and applications. This number will be dwarfed, though, by the demand for connectivity from the Internet of Things (IoT). In addition, the extent, tenacity, and complexity of attacks against networks, applications, and subscribers continue to worry service providers, who are also besieged by the exponential growth of signaling traffic, the impending loss of IPv4 addresses, and the growing movement to IPv6.
- Two 100 GbE ports and six 40 GbE ports, which vastly increase efficiency, throughput, and performance.
- The first ADC with 100 GbE ports in the QSFP28 form factor, delivering a smaller footprint and lower power consumption.
- Significant performance improvements for 2K keys with SSL.
- Support for over a billion concurrent connections, ensuring network, data, and subscriber security.
- Manage security and connectivity with fewer devices.
- Scale dynamically to meet user growth.
- Reduce total cost of ownership (TCO) and speed return on investment (ROI).
- Remove complexity while increasing efficiency
The On-Demand Application Delivery Controller
Your organization’s growing infrastructure puts more pressure on the network—from rising numbers of users and data center consolidation to cloud migrations and more feature-rich applications. Scaling your Application Delivery Network (ADN) to meet these ever-evolving demands means increased operational cost and complexity, limiting your organization’s ability to react quickly to new needs and opportunities.
Each F5 VIPRION platform is a single, powerful Application Delivery Controller (ADC) with modular performance blades you can add or remove without disrupting users or applications. Instead of adding devices and segmenting applications, simply add more power to your existing infrastructure as needs and opportunities arise. VIPRION enables the scalability you need to establish a sustainable ADN growth strategy.
Key Benefits
Reduce costs
Decrease OpEx and CapEx with the F5 ScaleN architecture, which provides unique flexibility to scale on demand, virtualize, and deliver application scaling in a device cluster.
Maximize performance
Manage and protect demanding apps with industry-leading layer 4 and layer 7 performance and SSL processing power.
Consolidate devices
Reduce the number of servers and ADCs along with power, space, cooling, and management requirements.
Achieve ultimate reliability
Make the ADN always available with redundancy at both the chassis and blade levels.
Increase Intelligence, Not Operating Costs
As your infrastructure grows and requires more power for layer 4 and layer 7 processing, SSL, compression, and more, you can simply add a blade to the VIPRION chassis and it will start processing traffic automatically. Whether you’re using one blade, four blades, or eight blades, VIPRION remains one device with fixed management costs.
Intelligent Performance Where It Matters
Traditional performance measurements in terms of throughput don’t accurately represent the complex needs of delivering modern web applications. Connection capacity and L7 transactions per second are critical. For instance, ADCs must be able to process high levels of layer 4 and layer 7 connections and make application-layer decisions such as removing sensitive information or transforming application-specific payloads. BIG-IP appliances have the intelligence and performance to handle application layer decisions while securing your data and infrastructure.
Simplify Your Network
VIPRION can help you simplify your network by offloading servers and consolidating devices, saving management costs as well as power, space, and cooling in the data center.
With VIPRION’s massive performance and scalability, you can reduce the number of Application Delivery Controllers you need to deliver even the most demanding applications. By offloading computationally intense processes, VIPRION significantly reduces the number of application servers you need. VIPRION includes:
- SSL/elliptical curve cryptography (ECC) hardware acceleration—Offloads costly SSL encryption. Accelerates key exchange and bulk encryption to provide best-in-market SSL performance. Enhances perfect forward secrecy (PFS) capabilities through improved ECC performance.
- Hardware compression—Enables you to cost effectively offload traffic compression processing from your servers. Improves page load times and reduces bandwidth utilization.
- F5 OneConnect connection pooling—Aggregates millions of TCP requests into hundreds of server-side connections. Increases server capacity and ensures requests are handled efficiently by the back-end system.
Maximize Large-Scale Application and Firewall Performance
With its industry-leading layer 4/7 throughput, connection processing, and SSL/ECC performance, VIPRION efficiently manages the most demanding applications, offloads servers, and consolidates your Application Delivery Network. In addition, as an ICSA Labs Certified firewall solution, F5 BIG-IP Advanced Firewall Manager (AFM) on VIPRION provides native, high-performance network firewall services to protect public-facing websites and data center applications from distributed, multi-layer cyber attacks.
VIPRION high-performance and distributed denial-of-service (DDoS) protection capabilities are enabled through field-programmable gate array (FPGA) technology tightly integrated with the F5 TMOS technology and software.
F5 embedded Packet Velocity Acceleration (ePVA) FPGA delivers:
- High-performance interconnection between Ethernet ports and processors.
- L4 offload, enabling leading throughput rates and reduced loads on software.
- Hardware-accelerated SYN flood protection.
- Hardware detection and mitigation of more than 100 types of denial-of-service (DoS) and DDoS attacks.
- Support for F5 IP Intelligence Services, with blacklist, whitelist, and graylist capabilities.
- Native network overlay (VXLAN/NVGRE) support.
- Hardware-enabled DNS caching, which hyperscales responses for fast service and app delivery (B2250).
- User selectable hardware profiles that enable different performance levels for targeted workloads. Initial profile options include optimized L4 throughput on select platforms for CGNAT or L4-centric traffic management solutions.
Achieve Ultimate Reliability
In a VIPRION system with multiple blades, you can remove a blade without disruption. The other blades will instantly take over the processing load. You can also deploy VIPRION in an active/standby configuration to add another level of redundancy. The chassis is built with redundant power supplies and field swappable components. This multi-layered redundancy significantly reduces the possibility of downtime.
Unparalleled performance with legendary scale
The F5 VIPRION 4450 blade offers two 100 GbE ports and six 40 GbE ports, vastly increasing efficiency, throughput, and performance. The purpose-built VIPRION 4450, which is Network Equipment-Building System (NEBS) compliant, scales up to 1.2 billion concurrent connections in a fully loaded VIPRION 4800 eight-blade chassis. That’s enough capacity to address IoT today and in the future.
The VIPRION 4450 blade is the first Application Delivery Controller (ADC) to provide 100 GbE ports in the QSFP28 form factor, providing the smallest footprint and lowest power consumption of any 100 GbE form factors. The 4450 blade delivers significant performance improvements for 2K keys with SSL, plus additional elliptical curve cryptography (ECC) performance improvements, enhancing perfect forward secrecy (PFS) capabilities. It also quadruples the bulk throughput transaction per second (TPS) rate of the VIPRION 4300 series blade and chassis combinations.
Simplified 4G to 5G migration
As service providers explore how to best manage the migration from 4G to 5G networks, network scalability and extensibility are crucial. The VIPRION 4450 blade and 4800 chassis combine for a superior connection setup rate of 20 M connections per second (CPS), easing migration.
Furthermore, as organizations run out of IPv4 addresses, supplementing existing IPv4 addresses with IPv6 addresses, the VIPRION 4450 provides support for up to hundreds of millions of concurrent sessions, thus handling the crossover with ease.
Scalable, extensible security
One of the most effective network attacks continues to be distributed denial-of-service (DDoS). The VIPRION 4450, in concert with F5 BIG-IP Advanced Firewall Manager (AFM)—a highperformance, stateful, full-proxy firewall—quickly ramps to distinguish between malicious and legitimate connections. This combined solution then absorbs or discards malicious connections before they can devastate network resources. Escalating subscriber and data usage helps drive the need for firewalls in a service provider’s SGi LAN. The VIPRION 4450 blade’s support for over a billion concurrent connections ensures that service provider networks, data, and subscribers remain secure.
The VIPRION 4450 blade effectively mitigates even the most virulent application attacks, provides an early warning of application attack vectors, and very efficiently defends against multi-pronged, simultaneous vectors. When combined with BIG-IP® Application Security Manager™ (ASM)—F5’s agile, scalable web application firewall (WAF)—the F5 solution can mitigate and defend against nearly any L7 attack.
Adaptive, software-defined hardware
The VIPRION 4450 blade’s advanced field-programmable gate arrays (FPGA) enable significantly improved CPU utilization, as well as capabilities for whitelisting, blacklisting, and graylisting. The personality of the FPGAs can be changed programmatically, furthering the 4450’s extensibility and future-proofing the investment. The software-defined hardware capabilities delivered by FPGAs, memory, and hardware search equip the VIPRION 4450 blade to efficiently handle software-defined networking (SDN). This provides CPU offloading, optimization, and adaptability.
The VIPRION 4450 blade, in conjunction with the VIPRION 4480 or 4800 chassis, further enhances performance, enabling dynamic resource allocation and maximizing service consolidation. Performance and capacity scale in linear fashion with each additional blade, so service providers adding a blade can begin processing traffic automatically, without a major upgrade.