Thunder® Convergent Firewall (CFW)
Consolidated solution for application delivery and network security
What is A10 Thunder CFW?
A consolidated network security platform for A10’s application and network infrastructure solutions.
There are two packaging options: CFW-ADC for enterprise solution and CFW-CGN for service provider solution. The all-in-one CFW package is still available for previous generation platform that doesn’t support modular licensing.
Enable Secure Interconnection Between Data Centers
CFW-ADC
- Unite application delivery and network security on a single platform to reduce hardware and operating costs.
- The high-performance DCFW includes security features such as stateful firewall, IPsec VPN with advanced server load balancing to protect data center assets from the inside out.
Secure and Scale DNS Infrastructure for Uninterrupted Service
CFW-ADC
- Build resilient and high-performance DNS using DNS load balancing, DNS cache and DNS application firewall (DAF).
- To enhance user-side security and privacy, DNS over HTTPS/TLS encrypts DNS queries.
Protect Users From Modern Encrypted Threats
CFW-ADC
- Eliminate the SSL blind spot in corporate defenses, restrict access to undesirable websites, and identify malicious traffic with a secure web gateway.
- This feature combines SSL Insight® technology, URL filtering, and a multi-layered security approach to protect users from modern, encrypted cyber threats.
Protect Your Mobile Infrastructure
CFW-CGN
- Protect subscribers and shield mobile core infrastructure from cyberattacks and signaling storms at the Gi/SGi, GTP/roaming and RAN to ensure uninterrupted operations
- Built on A10’s proven Thunder CGN technology, the firewall combines the security of a carrier-grade firewall with integrated DDoS protection features.
Key Benefits of A10 Thunder CFW
Key Features
Advanced Delivery Controller
High-performance advanced load balancer and application delivery controller that help meet availability and performance demands for both legacy and modern applications
SSL Visibility & Decryption
A comprehensive TLS/SSL decryption solution that enables security devices to efficiently analyze encrypted enterprise traffic and augment Zero Trust strategies
Carrier-Grade Networking
Highly scalable carrier-grade NAT (CGNAT) and IPv6 migration solution that helps extend IPv4 connectivity and enable a smooth transition to IPv6 deployment
Centralized Management with Analytics
A10 Control and Harmony Controller collect comprehensive telemetry from Thunder CFWs and help simplify operations by providing real-time, actionable insights
Network and Application Firewall (FW)
Flexible stateful FW providing L4 network segmentation and application-based control and visibility using DPI. Consolidated FW with ADC/CGN optimizes latency and system resource usage
IPsec VPN
High-capacity IPsec VPN enabling secure interconnection between data centers, site-to-site, clients-to-site, or between the mobile network RAN nodes and the core
Intelligent Traffic Steering
For value-added services or optimizing resoucre usage, traffic can be steered based on various attributes such as user ID, application ID, IMSI, radio access type (RAT), etc.
Available Subscriptions
- Web categorization for URL filtering and selective bypass
- Application visibility (DPI) for fairness user traffic control
- Threat intelligence list to block malicious IPs
Frequently Asked Questions
Don’t see your question listed? Contact a product expert to get answers.
Thunder CFW is a consolidated network security platform for application and infrastructure solutions. It is ideal for environments that require both security and application availability. For example, if you already deploy a firewall in front of application services that are protected by a load balancer or ADC, Thunder CFW allows you to consolidate both functions into a single platform. This simplifies network architecture, streamlines operations, reduces management complexity, and helps lower total cost of ownership (TCO).
Yes, FlexPool is available for Thunder CFW on both physical and virtual appliances. With FlexPool, you can dynamically allocate and redistribute capacity from a shared resource pool based on changing business requirements. It also provides deployment flexibility, allowing you to move Thunder CFW instances across supported cloud environments while using the same pooled capacity.
- Data center firewall by coupling stateful firewall and ADC/ load-balancer functions;
- Secure web gateway (SSLi) and cloud access proxy (forward proxy) deployments, leveraging advanced security such as URL filtering, web/app category-based access policy and more;
- Secure DNS load balancing and recursive cache. It also supports DNS over HTTP/TLS for user-side security and privacy.
Thunder CFW-CGN is ideal for secure Gi/SGi-LAN deployments, combining CGNAT, stateful firewall, and integrated DDoS protection to secure subscribers and infrastructure while simplifying network architecture and operations.
Absolutely. A10 Control simplifies the entire lifecycle of your SSLi deployment, including configuration, and troubleshooting. It also provides detailed, centralized analytics and actionable insights into the encrypted traffic flowing across your enterprise network.
Related Product
A10 Control
A10 Control is the next generation of centralized management and control platform for A10 solutions, consolidating existing A10 Harmony Controller and aGalaxy capabilities and more.
