| Specifications | Herculon DDOS i5800 | Herculon DDOS i2800 | Herculon DDOS i10800 |
|---|---|---|---|
| SSL TPS Throughput | ECC: 20K TPS (ECDSA P-256) RSA: 35K TPS (2K Keys) 20 Gbps bulk encryption |
ECC: 3.5K TPS (ECDSA P-256) RSA: 4.3K TPS (2K Keys) 8 Gbps bulk encryption |
ECC: 48K TPS (ECDSA P-256) RSA: 80K TPS (2K Keys) 40 Gbps bulk encryption |
| PPS (TCP/UDP) | 14M/115M | 2M/3M | 44M/140M |
| L4 Latency | <10 us | <10 us | <10 us |
| L4/L7 Max Throughput | 60 Gbps/35 Gbps | 10 Gbps/5 Gbps | 160 Gbps/80 Gbps |
| L4 Max Concurrent Connections | 40M | 14M | 100M |
| L4 Connections/sec | 900K | 250K | 1.5M |
| H/W SynCookies/sec | 50M SYN cookies/sec | 0.8M SYN cookies/sec | 130M SYN cookies/sec |
| Network DDoS Detection Speed | <1s | <1s | <1s |
The following table contains key features of the F5® Herculon DDoS Hybrid Defender®.
| Features: | |
|---|---|
| DDoS Mitigation: | All layer 3, 4, & 7 DoS/DDoS threats including flood/sweep with Src/Dst IP address awareness, UDP / DNS / HTTP / TCP / SIP / SYN / ACK / RST / FIN using sub-second detection, network behavior analysis, 120+ DDoS vectors, application anomaly detection, dynamic filtering, protocol analysis, source tracking, control policies, and more |
| DDoS Auto-Threshold Setting: |
Automatically generated and adjusted for all DDoS network and application threshold values for TPS, PPS, and requests per second |
| Malicious Bot Defense: | Proactive bot defense, captcha challenges, headless browser detection, bot categorizations identifying severity and good/bad bots, device fingerprinting |
| IP Intelligence: | Bad actor information can be communicated across other DHD devices; F5 IP Intelligence licensed services provide global DDoS threat intelligence feeds |
| DDoS Detection: | Out-of-band SPAN port, Netflow monitoring |
| SSL Inspection (Decryption): | Advanced, purpose-built TLS stack. Hardware accelerated: Key exchange and bulk inspection; RC4, DES, 3DES, AES-CBC, AESGCM, AES-GMAC, RSA, DSA, DH, ECDSA, ECDH, MD5, SHA, SHA2 ciphers. Keys protected by F5 Secure Vault. FIPS 140-2 Levels 1, 2, and 3 available |
| Reporting and Forensics: | Dashboard summary current attack and drill-down reporting, standard and customizable charts and graphs; blocked/passed traffic; app health, bot signatures; Top 10 threats/destination IPs/source_IPs; sys mon; max # of attacks; IPs participating in attack (dashboard) |
| Mitigation Techniques: | Rate limiting/blocking, connection limiting, source limiting, shunning/ denylisting/allowlisting, BGP route injection and RTBH (source and destination), dynamic signature filtering. Volumetric/cloud scrubbing redirection: manual or automated. |
| Management: | REST; CLI, Web UI; RBAC management |
| Deployment Modes: | Asymmetric Inline active/inactive; VLAN bridge mode; OOB Span/TAP monitoring with Netflow, packet data; appliance or virtual edition (software) |
| Event Notifications: | SNMP, Syslog, email |
| Cloud Signaling: | BGP / BGP Flowspec route injection for manual or automated redirection to licensed F5 Silverline or third-party volumetric scrubbing solutions. REST API route activation with licensed F5 Silverline DDoS Protection cloud-based scrubbing. |
| High Performance (HA): | Support HA active/passive |