FortiADC™
Available in:
Advanced Application Delivery Controller
Application Delivery Without Any Limits
FortiADC is an advanced Application Delivery Controller (ADC) that ensures application availability, application security, and application optimization. FortiADC offers advanced security features (WAF, DDoS, and AV) and application connectors for easy deployment and full visibility to your networks and applications. FortiADC can be deployed as a physical or virtual machine (VM), or as a Cloud solution.
HIGHLIGHTS
Application Availability
Applications are the lifeblood of a company’s online presence. Unresponsive applications can result in lost revenue and customers taking their future business elsewhere. Application performance, scalability, and resilience are key but none of this matters unless the end-user has a good experience and completes their transaction.
FortiADC is a dedicated Application Delivery Control solution that provides a multi-tenancy solution (VDOM), high availability, and scalability with hybrid solution deployment (on-premises and cloud offering) to your applications.
SSL Security
FortiADC delivers high capacity decryption and encryption with the latest cryptography standard using hardware-based SSL ASIC. FortiADC provides SSL offloading, SSL inspection and visibility to inspect traffic for threats, speeds up server response, and reduces the load on the backend server. FortiADC also integrates with Gemalto’s SafeNet Enterprise Hardware Security Module (HSM).
Business Continuity
FortiADC’s included Global Server Load Balancing (GSLB) module on-prem or in the cloud (FortiGSLB Cloud) makes your network reliable and available by scaling applications across multiple data centers for disaster recovery or to improve application response times. Customers can set up rules based on site availability, data center performance, and network latency.
Application Protection
FortiADC offers multiple levels of protection to defend against attacks that target your web applications. FortiADC Web Application Firewall can detect a zero day attack and protect from OWASP Top 10 and many other threats with multi-vector protection. FortiADC also supports our FortiGuard Cloud which provides multi services such as IPS, Antivirus, and IP Reputation service (subscription required) that protects you from sources associated with DoS/DDoS attacks, phishing schemes, spammers, malicious software, and botnets.
Application Optimization
FortiADC provides multiple services that speed the delivery of applications to users. The PageSpeed suite of website performance enhancement tools can automatically optimize HTTP, CSS, Javascript, and image delivery to application users. FortiADC also provides Dynamic Caching and HTTP Compression and Decompression to improve end-user experience and server productivity.
FortiADC Security Fabric
As the threat landscape evolves, many new risks require a multi-pronged approach for protecting applications. FortiADC’s antivirus and integration with FortiSandbox extend basic security protections to scan file attachments for known and unknown threats.
Automation and Connectors
FortiADC Fabric Connectors provide open API-based integration and orchestration with multiple software-defined networks (SDN), cloud, management, and partner technology platforms. Fortinet Fabric Connectors deliver turnkey, open, and deep integration into third party services such as K8s, AWS, OCI, and SAP, in multi-vendor ecosystems, enabling scalability, security automation, and simplified management.
Unleash the Power of Scripts
FortiADC Scripts provides the flexibility to create custom event-driven rules using predefined commands, variables, and operators. Using easy-to-create scripts, you get the flexibility you need to extend your FortiADC with specialized business rules that give you almost unlimited possibilities for server load balancing, health checks, application validation, content routing, and content rewriting to meet the needs of your organization.
Application Authentication
FortiADC provides centralized user authentication and authorization services to web applications. FortiADC acts as a gatekeeper to offload HTTP authentication and authorization to customer applications using single sign-on (SSO) services, SAML, LDAP, RADIUS, and MFA (using FortiToken Cloud and Google authenticator).
WAN Optimization
FortiADC provides a built-in link optimization with the Link Load Balancing module. Customers can create two or more WAN links (for inbound and outbound Link LB) to reduce the risk of outages or to add additional bandwidth to relieve traffic congestion.
Analytics and Visibility
FortiADC offers a comprehensive monitoring system for your network and application. With FortiView, customers can get real-time and historical data into a single view on your FortiADC. We also provide a network logical topology of real-servers, user/application data-analytics, security threats, attack maps, and some other system events and alerts. FortiADC is integrated with third party solutions such as Splunk, FortiAnalyzer, and FortiSIEM for more visibility, correlation, automated response, and remediation.
FortiADC Centralized Management
FortiADC Manager is a web-based management tool that allows you to centrally manage multiple FortiADC devices remotely. Network administrators can better control their devices by logically grouping devices, efficiently managing jobs and licenses, quickly checking various logs, and monitoring threat statistics in real time.
FEATURES
Application Availability
- Virtual service definition with inherited persistence, load balancing method, and pool members
- Layer 4/7 application routing policy
- Layer 4/7 server persistence
- Custom scripting for SLB and content rewriting
- Scripting for event-driven rules using predefined commands, variables, and operators for SLB, content rewrite, persistencey, and security
- Advanced L7 application health check with support script for a customized health check
- Clone Traffic Pools
Layer 4-7 Application Load Balancing
- TCP, UDP, IP, DNS, HTTP, HTTPS, HTTP 2.0 GW, FTP, SIP, RDP, RADIUS, MySQL, MSSQL, RTMP, RTSP, and more applications
- L7 Content Switching and Rewriting – HTTP Host, HTTP Request URL, and HTTP Referrer – Source IP Address
- Persistent IP, has IP/port, hash header, persistent cookie, hash cookie, destination IP hash, URI hash, full URI hash, host hash, and host domain hash
- URL Redirect, HTTP request/response rewrite (includes HTTP body)
- Layer 7 DNS load balancing, security, and caching
Link Load Balancing
- Inbound and outbound LLB
- Support for policy route and SNAT
- Multiple health check target support
- Configurable intervals, retries, and timeouts
- Tunnel Routing
Security Fabric Connector
- FortiGSLB Cloud (One-Click-GSLB)
- FortiAuthentication
- FortiSIEM
- FortiAnalyzer
- FortiADC-CM
- FortiSandbox
- FortiGate BanIP Integration
External Fabric Connectors
- Kubernetes Service
- SAP Application
- AWS / OCI Connector
- Splunk Integration
Global Server Load Balancing (GSLB)
- Global data center DNS-based failover of web applications
- Delivers local and global load balancing between multi-site SSL VPN deployments
- DNSSEC
- DNS Access Control Lists
- GSLB setup wizard
Deployment Modes
- One arm-mode (Proxy with X-forwarded for support)
- Router mode
- Transparent mode (switch)
- High Availability (AA/AP Failover)
Web Application Firewall
Application Protection
- OWASP Top-10 Wizard
- Web Attack Signature
- API Protection
- Sensitive Data Protection
- Bot Detection
- Web Vulnerability Scanner
- Third-party scanner integration (virtual patching)
- HTTP RFC compliance
Security Services
- SQLi/XSS Injection Detection
- OpenAPI Validation
- API Gateway
- Web Scraping
- CSRF Protection
- Brute Force Protection
- Web Defacement Protection
- CAPTCHA Support
- Data Leak Prevention
- File Restriction
- Cookie Security
- XML/JSON/SOAP Validation
- HTTP Header Security
Application Acceleration
SSL Offloading and Acceleration
- Offloads HTTPS and TCPS processing while securing sensitive data
- Full certificate management features
- HTTP/S mirroring for traffic analyses and reporting
- Support TLS 1.3
HTTP and TCP Optimization
- 100x acceleration by off-loading TCP processing
- Connection pooling and multiplexing for HTTP and HTTPS
- HTTP Page Speed-UP for Web Server Optimization
- TCP buffering § HTTP compression and decompression
- HTTP caching (static and dynamic objects)
- Bandwidth allocation with Quality of Service (QoS)
Authentication Offloading
- Local
- LDAP
- RADIUS
- Kerberos
- SAML 2.0 (SP and Idp)
- AUTH2.0
- NTLM
- Two-Factor Authentication — FortiToken/ FortiToken Cloud, and Google Authentication
Networking
- Static NAT, Hide NAT, and Dynamic NAT for flexibility and scalability)
- VLAN and port trunking support
- Support integration with Cisco ACI, Nutanix, OpenStack, and Ansible
- NVGRE and VXLAN Support § BGP and OSPF with Route Health Inspection (RHI)
- IPv6 Support (SLB, interfaces, routing, and firewall)
- Support SR-IOV – VMware and KVM
Application Security
- FortiGuard Antivirus and FortiSandbox integration
- GEO IP security and logs (subscription required)
- Stateful Firewall
- Web Filtering (subscription required)
- IP Reputation (subscription required)
- IPv4 and six firewall rules
- Granular policy-based connection limiting
- Syn cookie protection
- Connection limits
- Intrusion Prevention System (subscription required)
- Application and Network DDoS Protection
- DNS Application Security
Management
- Central management for multiple FortiADC devices
- REST API
- SNMP with private MIBs with threshold-based traps
- Real-time Data Analytics
- Syslog support
- Role-based administration
- Real-time monitoring graphs
- Built-in reporting
- FortiView integration
- OWASP Top-10 Real-time monitoring
- Data analytics
- Virtual Domains (VDOMs)
- Support Inter-VDOM Connectivity