The advanced multicore multithread hardware architecture allows the device to concurrently perform health monitoring, load balancing scheduling, security, and routing tasks without sacrificing performance. The data flow-based fast forwarding reduces route lookup time and improves packet forwarding efficiency. These features enable the device to bring high load balancing and security performance.
The device provides rich interface types and multiple expansion slots to meet varied requirements for interfaces. It provides GE copper and fiber ports and 10GE fiber ports.
Efficient Health Monitoring
The device supports multiple health monitoring algorithms. It supports dozens of active and passive health check methods, including ICMP, TCP, UDP, ARP, HTTP, HTTPS, DNS, SNMP, FTP, Radius, MySQL, and TDSQL. It allows you to monitor the health status of servers and applications at the network layer, application layer (TCP, UDP, HTTP, and HTTPS), and mainstream databases by using the network quality analyzer (NQA) technology. This consumes minimum system resources and ensures load balancing performance. The health monitoring algorithms are applicable to Layer 4 server load balancing and Layer 7 server load balancing.
Flexible Link Load Balancing Scheduling
The device supports load balancing among ingress and egress links. It can intelligently schedule the ingress and egress traffic by applications, link health conditions, link bandwidths and other factors. This improves user experience, realizes link backup, and improves bandwidth efficiency.
Rich Load Balancing Scheduling Algorithms
The device supports multiple load balancing scheduling algorithms for different application scenarios, including round robin, weighted round robin, least connection, weighted least connection, random, source address hash, destination address hash, and source address and port hash algorithms. These algorithms are applicable to Layer 4 server load balancing and Layer 7 server load balancing.
Layer 4 and Layer 7 Server Load Balancing
Layer 4 server load balancing is implemented based on Layer 4 features such as IP address and TCP or UDP port number.
Layer 7 server load balancing is implemented based on Layer 7 contents. It parses and analyzes packets based on the HTTP header, HTTP URL, HTTP cookie, or HTTP content and allows you to configure Layer 7 policies based on the analysis result to distribute HTTP packets and keep the sessions.
SSL Offloading and Acceleration
SSL offloading and acceleration take off encryption and decryption processing from the server and use no or weak SSL ciphers to communicate with the server. This feature greatly reduces SSL processing workloads on the server and saves server CPU resources.
The device supports TCP OneConnect. It allows numerous HTTP requests to be multiplexed over a small number of TCP connections. This reduces the server load greatly, decreases the delay caused by new TCP connection establishments, minimizes the number of concurrent connections of the server, and saves server resources.
Application Optimization
The device takes over all traffic from the clients and servers and can parse and optimize protocol fields of all layers. It features dedicated video optimization technology that can significantly enhance the delivery performance of video applications.
The device allows users to use the following profiles to optimize and improve application delivery:
IP Parameter Profile - You can use the IP ToS field to optimize various types of transmission protocols and improve the transmission performance of key applications.
TCL Parameter Profile - Options such as transmit and receive buffer sizes improve the link transmission quality and optimize TCP data transmission.
HTTP Parameter Profile - You can use the following options and parameters to satisfy the user requirements for optimizing and improving HTTP application delivery.
Diameter Parameter Profile - The device supports Diameter. Diameter requests can be distributed to specified server groups based on the load balancing algorithm, and custom Diameter-Session templates can be created. Sessions with the same attributes can be distributed to the same backend server. Check the health status of backend servers. It can meet the compatibility requirements of load balancing products and many application systems.
Intelligent DNS
The H3C SecPath L5000 application delivery security gateway provides intelligent DNS, offering external users smart resolution services. This technology addresses the issue of link selection when accessing internal servers from the external network. In networks lacking load balancing devices, external users can only select a single link or randomly choose a link to access internal servers. Unoptimized random link selection does not ensure a satisfactory user experience for external visitors. The H3C SecPath L5000, with its built-in intelligent DNS module, collaborates with the customer's resolution server to guide the domain name resolution of internal servers. When an external user accesses a customer's internal server via a domain name, the load balancing device selects the optimal link using a static list or dynamic algorithm and resolves the domain name to the IP address of the corresponding link.
Comprehensive Security Features
The device provides powerful and complete security features. It can defend against various types of attacks such as Intrusion Prevention System, Anti-Virus, Web Application Firewall and anti-DDoS.
High Availability
H3C software and hardware platforms make the device highly reliable. Highly welcomed at the market, it is widely used by service provider and enterprise customers.
RBM (Remote Backup Mechanism) – RBM achieves active-active or active-standby deployment modes.
N+M – N+M mechanism achieves cluster deployment with up to 32 devices.