Stock Abbreviation : Topsec      Stock Code : 002212
7*24 hour service: 400-777-0777

SSL Unloading Application Case in Internet Area of Nangrid Research Institute

The South Network Research Institute has the Elink system, which is accessed by HTTPS encryption. There are two A10 load balancing servers in the network. Due to insufficient unloading performance, they cannot meet the requirements of users services. The average number of new SSL connections created by Elink system exceeds 3W+, and the peak reaches 6W+

Background

The original load balancing device in the current network will not be replaced, and the new SSL unloading device will not change the original network topology structure as far as possible. At the same time, HTTPS traffic will be decrypted to ensure that subsequent security devices can check the security of the traffic.

In order to ensure that network security incidents can be traced, SSL unloading devices need to bring in the source address of the client.

Activity & Announcement
Requirement analysis
01

Enhance server business processing performance.

02

Possess the capability for security incident forensics.

03

It can provide security protection for encrypted traffic.

Solution

1. Deploy our load balancing system on the original load balancing bypass. Through A10 device balancing, the traffic is diverted to our load balancing system to achieve horizontal performance expansion and disaster recovery purposes.

2. The load balancing system of our company, together with the hardware unloading card, enables SSL unloading function. The maximum SSL carrying capacity of a single device reaches 2W+, and the HTTPS encrypted traffic is unloaded to HTTP plaintext traffic to ensure that subsequent security devices can detect and defend the traffic.

3. Enable the X-forward-for function of the device, insert the client source IP into the HTTP request header, and ensure that subsequent security devices can trace the source.

Value to Customers
Full-scenario Load Balancing

TopApp Load Balancer integrates server load balancing, link load balancing, and global load balancing to ensure optimal data transmission in complex networks. It employs various load balancing algorithms tailored to specific scenarios, precisely distributing traffic across different links or servers for efficient resource utilization.

Access Speed Optimization

TopApp incorporates multiple network optimization technologies such as compression caching, one-sided acceleration, TCP connection reuse, database read-write separation, and SSL offloading, significantly improving user access speed.