A10 Thunder TPS provides advanced DDoS mitigation with seamless traffic management, ensuring legitimate network activity while blocking threats efficiently. It operates with minimal oversight, featuring quick response capabilities and operational simplicity.


| Product | Mindshare (%) |
|---|---|
| A10 Thunder TPS | 1.6% |
| Cloudflare | 11.9% |
| Imperva Application Security Platform | 7.7% |
| Other | 78.8% |
| Company Size | Count |
|---|---|
| Small Business | 5 |
| Midsize Enterprise | 2 |
| Large Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 132 |
| Midsize Enterprise | 28 |
| Large Enterprise | 48 |
A10 Thunder TPS is engineered for rapid detection and defense against DDoS threats, employing programmable automated solutions through RESTful API integrations and aGalaxy management. This system efficiently handles extensive attacks with multi-vector protection, supporting functions such as load balancing. Its intuitive interface allows quick adaptation, helping organizations minimize operational expenses and quickly counter threats. Challenges arise in aligning TPS features with aGalaxy, necessitating improvements in reporting and user training methods. Integration issues due to import restrictions further complicate deployment endeavors.
What are the key features of A10 Thunder TPS?A10 Thunder TPS serves as a robust defense for cloud infrastructure and hosting companies against powerful DDoS threats. By rerouting harmful traffic and ensuring legitimate traffic reaches its destination, this protection system is employed on-premises alongside other tools for substantial availability. Its capabilities in load balancing and network troubleshooting further reinforce its role in maintaining security and reliability against high-capacity attacks across industries.
DDoS defense solution trusted for more than 200 service providers, online gaming, and enterprises including; Bungie, Comcast, KDDI Corporation, Leaseweb, Microsoft Azure, NTT Docomo, Softbank, Turkcell Superonline, Verizon and more.
| Author info | Rating | Review Summary |
|---|---|---|
| Information Technology Security Engineer at a tech services company with 11-50 employees | 5.0 | I currently use A10 Thunder TPS in a test setup with a Check Point firewall and Juniper MX router. The Management Console, A Galaxy, is interesting, but the user interface has issues needing improvement. A flexible demo license policy would help. |
| Sales Account Executive at L8 Group | 4.0 | A10 Thunder TPS is valuable for its DDoS protection in Brazil, helping mitigate attacks and protect resources. However, the absence of a blocking key is an issue. Although useful, it doesn't offer a strong ROI or flexibility compared to alternatives. |
| Technology manager at Folha de S. Paolo | 4.5 | I use A10 Thunder TPS for load balancing in our data center, handling both internal and external services. While it excels at managing HTTP protocols, it struggles with HTTPS due to SSL limitations. It's effective but somewhat expensive. |
| Director of Technology at a comms service provider with 51-200 employees | 4.0 | I use A10 Thunder TPS to protect my network from DDoS attacks. It offers automated mitigation and expert support, which enhances its reliability. Previously, I relied on an in-house script but switched to this appliance for its efficiency and support. |
| IP/DDOS Senior Engineer at Türk Telekom International | 4.5 | I use A10 Thunder TPS for monitoring tickets and reports on the configuration site. The solution is user-friendly, though its documentation could be improved. I have not used or considered other solutions, and there's no specific cloud provider deployment involved. |
| Director of IT Networks at a comms service provider with 201-500 employees | 5.0 | I use the A10 Thunder TPS for on-premise DDoS mitigation, finding it superior to costly cloud alternatives. It delivers instant, automatic protection, ensuring 100% availability and customer retention. Setup was simple, and support is excellent. It's an indispensable solution, preventing daily attacks effectively. |
| Co-Founder at Acorus Networks | 3.5 | I value its API-driven automation, fast attack mitigation, and efficient aGalaxy management, which boosts team productivity and customer ROI. However, ZAP for MSSPs, port density, upgrades, documentation, and reporting need significant improvement. |
| Managing Director Leaseweb Network at Leaseweb | 4.0 | We use A10 Thunder for DDoS protection, significantly reducing our customer complaints and support tickets. It effectively mitigates over 98% of attacks, including small, previously unnoticed ones. We find its high scrubbing quality, low maintenance, and scalability deliver excellent ROI. |
| Cybersecurity Consultant at a tech services company with 1,001-5,000 employees | 3.5 | I use A10 Thunder TPS as an anti-DDoS tool because it is easy to use and implement. However, it needs improvement in fail-open capabilities to ensure network traffic continuity. Compared to A10, Arbor is more widely known and used. |
| Security IT at a financial services firm with 201-500 employees | 4.5 | I use A10 Thunder TPS mainly for load balancing, particularly server load balancing. The firewall features are the most valuable, and while implementation has posed some challenges, overall, I have encountered no significant issues with the product. |
Neutral

The most valuable feature of the solution is protecting customers and supporting them against attacks in Brazil.
In the tool, we use a lot of its DDoS protection features to protect the resources in a link. It also helps mitigate attacks so that users don't face problems because of it.
One problem for me with A10 Thunder TPS is that the box comes from another country in Brazil. In the tool, there is no one key to block it. For example, in F5 Networks, we have a key. If you try to buy another box from Huawei or from F5 and try to enable them in A10 Thunder TPS, you need a key to do it. The problem here is when you buy another box from A10, they want to put Thunder TPS to run, and it works okay, after which we cannot block it for another solution to be used, which is a problem for me where improvements are needed.
I have been using A10 Thunder TPS for years.
Stability-wise, I rate the solution an eight out of ten.
It is a scalable solution. Scalability-wise, I rate the solution an eight out of ten.
The solution's technical support takes more than a week to reply to a query from our company's end. I rate the technical support a six out of ten.
Neutral
The difference between A10 Thunder TPS and other DDoS solutions is that, with the formerly mentioned product, our customers use the box already there in their environment, allowing me to sell more than just one solution for security. I have used Huawei's DDoS tool. Huawei only runs DDoS services, so there are not many more features available.
The product's initial setup phase is very simple. I rate the product's initial setup phase an eight out of ten. The setup phase is a little bit more complex than A10 Thunder ADC because with A10 Thunder TPS, you have to have to know what you are doing, or else you will end up buying some application with some other features for your customers.
The solution can be deployed with help from the experts associated with the security side since they have skills related to ADC and TPS.
With the tool, I have just one opportunity to try to add one more feature for the customer, so I feel my company does not experience a very good return from the tool.
The tool is expensive. If one is low price and ten is expensive, I rate the tool's price as a ten.
A10 Thunder TPS has very good features for ISPs. For me, right now, the tool is too expensive. I am also an ISP trying to get another solution from another player because A10 Thunder TPS is still very expensive.
I never configured the tool in a way that allows me to use the multi-vector attack protection feature. It also varies depending on the performance of the tool on the customer's end.
I have had no problems with the maintenance of the product because the hardware part is good. Even during the trial, I saw that it was a good tool.
I recommend the tool to others.
In my company, we don't use any AI with the product, but I know that some of our customers use a little bit of AI.
I rate the tool an eight out of ten.

We have our own data center, and we perform load balancing for a lot of internal and external services using A10 Thunder TPS. For some users, we use A10 Thunder TPS for HTTP protocol. We perform load balancing for HTTPS on A10 Thunder TPS and others with too much workload we have to do on the servers. We cannot do the load balancing using HTTPS.
There is a limitation for SSL communication, but we had a problem with our application that started to hang. So, we had to change the SSL certificate to this server.
The most valuable feature of A10 Thunder TPS is load balancing.
The solution is a little expensive.
I have been using A10 Thunder TPS for seven years.
I rate A10 Thunder TPS ten out of ten for stability.
We have 20,000 active connections simultaneously for A10 Thunder TPS.
We contacted the solution's technical support to maintain and exchange the power supply. A few versions ago, we had some CPU and memory problems. We just started the appliance, and it was already on 70% of CPU usage.
We first contacted our reseller in Brazil and then escalated the issue to A10 Thunder TPS support. The reseller in Brazil was a little slow, but the A10 Thunder TPS support was fast.
Positive
We did a price survey, and compared to other solutions, A10 Thunder TPS wasn't cheap.
A10 Thunder TPS is a good product, and I have recommended it to a manager from another company in the past.
Overall, I rate A10 Thunder TPS a nine out of ten.
Thunder TPS protects your network from DDoS attacks.
Our company experienced some DDoS attacks that temporarily took down parts of the network. The manual process we had in place took some time to execute, and Thunder TPS offered better mitigation methods so we could block malicious IP addresses at the edge of the network.
Thunder TPS has automated mitigation and fully managed support in case the device cannot handle the attack. They have engineers available to respond.
We were in the early stages of using Thunder TPS when I left the company, so I only used it for a few days.
I rate Thunder TPS seven out of 10 for scalability.
We used A10 support during the deployment. They were helpful.
We had a script built in-house. We decided to replace some of our own programming with a proper appliance.
Setting up Thunder TPS isn't complex, and A10 provided excellent support. My team received pre-provisioned devices and sent them to our offices in Chicago and Toronto. We deployed it with their base configuration and brought the appliances online using their technical support. The whole process took about a month.
Thunder TPS costs about the same as most other DDoS protection, but it isn't a cheap solution. We had a 100-gig production license on each appliance and two devices. You pay annually for a license and support.
I rate A10 Thunder TPS eight out of 10. A10 is well-known in the networking world. The product is good, and it met the company's requirements.

I use the solution to check the tickets and reports of the configuration site.
The solution is easy to use.
The solution’s documentation could be better.
I have been using the solution for one year.
It is a stable solution.
It is a scalable solution. Around 50% of our staff use it.
The solution's initial setup process is straightforward.
I recommend the solution to others and rate it a nine out of ten.
We use it for DDoS mitigation. First of all, we decided that outsourcing it or putting it out into the cloud was just too expensive, so we decided to build our own scrubbing center rather than outsource it to somebody else. We use it to protect against DDoS attacks.
It's on-prem.
Availability is absolutely critical to our business. We get attacked two and three times a day at times. Without it we'd be hamstrung, bandwidth-wise.
Although the attacks happen every day, they're not a big deal anymore because the mitigation takes care of it. But in the past, before we had the solution in place — there are other components to it beyond just the A10; the A10 is just the mitigation piece of our DDoS protection scheme. But before this whole solution was in place, it used to take two or three engineers half an hour to figure out how to mitigate an attack. Now, it's pretty much zero. We get an attack, we get an e-mail saying, "Hey, there's an attack underway." The systems that are in place redirect it to the A10, the A10 scrubs the traffic and it's not such a big deal anymore.
In terms of how much it has increased availability, being that we get attacked two or three times a day, with some of them we probably we wouldn't really know they were happening. But some of them would take us to our knees. We've never really measured it. We're a service provider in the Northeast region, so we've got lots and lots of bandwidth. It has helped a lot, but I couldn't put a number on it because we're always up.
In terms of small attacks we were getting but missing prior to having Thunder TPS, we're over 200 Gig in the backbone now, but we never saw a lot of those little, what I call "squirt-in-the-eye" attacks before. We had a 50-Meg customer out there that was getting DDoS'ed at a 100 Meg. We would've never seen that before. We would have never mitigated it. The customer would have called and said, "Hey, my circuit's down," and we would have looked at it and spent time trying to figure out what's up with the circuit. Then somebody would have looked at their bandwidth charge and said, "Oh, you're maxed," and the customer wouldn't understand why they were maxed. Now, the DDoS solution we put in place sees those small attacks, mitigates them, and the customer never calls.
It has absolutely made a big difference for our customers. DDoSes are happening every moment of the day. We just never know who we're protecting from a given attack or why, but it just happens automatically and we don't really worry that much about it any longer.
All it does is mitigation. It mitigates and scrubs bad traffic. We send the bad traffic to it, it determines the good traffic and allows the good traffic to come through. That's the only feature we use on it, the DDoS mitigation.
Given its 1RU form factor, the performance has been excellent for us so far. What they said was that it is about 38.5 Gig of throughput. We've not really hit that yet, we haven't tested the extremes, but so far it's doing well and we haven't had any performance issues.
The response time to an attack is instant. We've used some outsourced solutions in the past, out in the cloud, that weren't so quick. But it's all within our control now. We control how fast it mitigates.
We have 100 percent uptime.
We haven't found that it's helped us to scale defenses because we have pigeonholed it to do one thing and that's DDoS. So it hasn't helped us scale but it's helped us retain customers who otherwise probably would have been angry and left us, thinking it was our fault that they got DDoS'ed. But defense scale-wise, no. Although we're still scaling up like crazy, it's not due to this DDoS product whatsoever.
We haven't experienced any issues with performance. But again, we haven't put that much traffic on it yet. I'm sure it's coming. I'm sure, some day, we'll get a DDoS attack that's more than 40 Gig and then we'll have an answer for how it scales.
Their tech support has been excellent. Every time we've had to call them they have been very responsive and always fixed our problem within minutes. It's been excellent so far.
I believe the last issue we had to contact them about was just a question of a false-positive. The A10 system wasn't supposed to decide what is a false-positive. So if we send it good traffic, it's supposed to just pass that good traffic through. But we opened this last ticket because the A10 did block some of the good traffic. Their support had to tweak it a little bit, but it wasn't anything that took a long time. It was pretty much just minutes. They understood what the issue was. They tweaked something and fixed it.
What we signed off on when we signed the contract with them was very specifically DDoS mitigation. We went over all the specs of what we intended the system to do. They met all the specs better than the other vendors as far as the throughput, the footprint, and cost went. So we went with them.
The main reason we switched was cost. The cloud solutions were very expensive and, as we sent more traffic, of course, the prices went up. And it was a huge variable. We couldn't budget saying, "We're going to spend X amount of dollars per month on DDoS," because it all depended upon how much traffic we sent to those mitigation servers. If we got attacked one month a couple of hundred times, our expense there could have been tens of thousands of dollars a month. We were not willing to play that game and have that much variability in our expense. By putting this system in, it's our system, so we use it as much as we need to, and we don't pay a monthly expense. We pay A10 for support and that's it.
There was also a difference in response time between A10 and the cloud solutions because now we completely control the solution. Whereas, when we were outsourcing it, we didn't control any of it. So we would send traffic and hope that their mitigation system wasn't overtaxed. Their detection system, sometimes, could also be a little overtaxed and delayed, because there was the internet. We were sending traffic, sending our stats, across the net to their detection system. Their detection system would analyze that traffic, send a response back, and then mitigate if it had to. We had to send that traffic back out onto the public internet. So there was a lot of delay and a lot of variability in the response times. Now it's completely on our network and we control everything about it. So we get much faster response time in mitigation and detection.
The initial setup was very simple. Again, we only use one feature, so the complexities of the setup were pretty much nil. They asked us how much traffic we intend to send to this thing. We spec'ed out the box. They said, "Well, this is the box you want." We did some 15 or 20 minutes configuration of the box and that was it. It was up and live. Everything was done in an afternoon.
A10 did the initial config while it was all at our site. They did it remotely. It went flawlessly. It took about an hour or two hours and it was done. We've not had to change the configuration or anything about the box itself since we installed it.
There were three people involved in the deployment. Two others and me. I didn't do any of the configuration. I was just overseeing the whole project.
ROI is a tough one on this solution because it doesn't make us money, but it potentially saves us from losing some customers. I don't know how many customers would have left us if they got DDoS'ed or if our network didn't perform. So ROI on something that doesn't create revenue is a big, black hole. We don't know what would've been.
We don't charge for this, so there's no revenue associated with it. I'm sure it's saving us some revenue but, day one, it also saved expense. It actually cost us less to put this box in. For the expense that we were paying out to the cloud providers before, it was probably just a couple of months before it broke even with that expense that disappeared.
It was so variable, based on traffic. Some months we would spend $30,000 with that cloud provider and other months we'd spend $5,000. It was all based on the number of attacks that we would get. If we had a bad month of attacks, or even one bad day where somebody attacked us for 20 or 24 hours straight, we could be looking at spending $30,000 or $40,000 with that cloud provider. Today, it's nothing. There's no expense.
Pricing is very reasonable.
In the past, we've used other cloud-based solutions.
Don't even think twice about doing it. It's a given in this day and age; you just need to do it. You need to have some form of DDoS mitigation in place. And if you don't, God be with you. It's not a matter of if you will be attacked. A lot of ISPs think, "Oh, I'm too small," and even some enterprise customers think that way: "I'm too small. Nobody's going to attack me." These botnets don't care. They don't even know who you are. They just start sweeping IPs and, if they find some vulnerability or somebody decides that they'd like to attack even a customer of ours, it's going to happen. It's happening whether you know it or not, already.
The big thing was to get a lot more visibility into the types of DDoS attacks that we were getting, because now we had full access to the gears. One of the biggest lessons we learned — because we all assumed that non-volumetric attacks were not a problem for the provider — is that they were a problem. We just weren't seeing the problem. Some of our customers may have seen the problem, like a small DDoS attack against their DNS servers. DNS response time might've been delayed by just a fraction of a millisecond per query because of that DDoS attack, but in the grand scheme of things, with thousands of customers hitting that, it ended up being multiple milliseconds. That was something that we learned right off that was a "wow." When we looked at the response times of some of our servers that we never mitigated these attacks on before, it was big, overall.
The only automation features we use are the DDoS. We have other systems in place for the detection piece of it. That's the only feature we use. When it gets traffic, it mitigates it and that's pretty much it. We want to keep it extremely simple.
We haven't thought about where it has room for improvement because it is working so well right now. Again, we only use it for one very specific feature and that's the DDoS mitigation. It's doing what it's supposed to be doing right now. I don't have any enhancements I'd like to see on the product yet because we've not really used it for many of the features it's capable of.
In terms of maintenance, our company has a group that just updates software. That's all they do. They look at different systems in the network, Linux boxes, Windows boxes, appliances like this. They may spend half-an-hour a month if there are any updates to it. All they do is go to the web site and see if there are any updates. If there is an update, they look at what should be applied and they check with the different groups to see if they absolutely should apply it and then they download it.
We don't have plans to use any other features, but we do have plans to implement another system that our customer-support folks are looking at, to be able to do DDoS mitigation per customer. Right now my group, the engineering group, uses this system to protect the network as a whole, but we don't look at specific customers and say, "Well, that customer's getting a very small DDoS attack on their SQL server." We won't mitigate that because it doesn't affect the inner network. We would mitigate something that was a couple of hundred meg that we saw was malicious to the entire network, and that customer might benefit from it. Now, we're looking at selling this to customers. So if a customer calls and says, "Can you mitigate this attack against my SQL server?" the new system would be sensitive enough for even a tiny, little attack. Whereas, the system that we have now wouldn't. We'll probably do that in the next six months.
I'd give A10 a ten out of ten. I have no reason to subtract any points from it at all.
We work like an MSSP. We provide massive capacity and other network capacity to customers. We have customers connect anywhere on back burn. It can be in Europe. It can be in the US or in Asia. We plug the attack anywhere on the back burn, trying plug the attack closest to the source of the attack. So, we don't work like all the other guys who do scrubbing centers. We try to build a scrubbing network. That is why we need to buy more TPS in order to be distributive.
When we start to work with the customer, we don't know what they have. The goal for them is to be able to block any type of massive volume metric attack. The reason is why we have about a two terabytes capacity and are building to afford three to four terabytes of capacity. Therefore, anytime the customer needs to block something, we can configure for them any type of custom role.
We are using them for a mitigation offer that we have globally. We have a bunch of A10s and will deploy more in a few weeks.
We use both the hardware and software.
We started with them and built our network based on this solution. We started with them directly from scratch.
The automation makes our team more efficient and productive. We are distributed and don't use the A10 Portal. It's easy for us to deploy. E.g., they have an aGalaxy product. Instead of connecting to all the boxes, so we will have the A10 box. We don't want to send a code to all the A10 boxes. We will just send the information to one box: the A10 aGalaxy. This one box will proxy it and send the information all the other boxes. This is exactly what we are doing today. It has improved the way that we are working.
We use all the features, but our customers have started asking for key features around SIP. We are also using some proxy features.
The solution’s response time to an attack is fast. When it is configured in line, it is automatically done. When we have to stop the attack, it takes 10 to 15 seconds.
We selected the solution because of its programmable automated defense using RESTful API. We didn't want to connect to the box. We wanted to be able to do some automation. We wanted to have our own portal because we wanted to connect our customers to our own UI using the A10 API. It has been good and exactly what we need.
The TPS has reduced the amount of manual intervention required during an attack. When we have an attack, and we need to block some stuff everywhere, we just click on a button and push the rules. Then, it's deployed in Asia, Europe, and US. We don't have to do anything more.
The aGalaxy is a control plane for the product. It controls the entire TPS so you don't have to connect to the box. You just have to connect to this control plane.
The solution’s machine-learning-powered Zero-day Automated Protection (ZAP) works for enterprise customers, but for MSSPs, we have too much traffic and analytics. Therefore, it is unusable and A10 is working on a new feature that we requested. It should be ready in two weeks.
We have to be able to do some automatic rules proposals based on what is detected. We use this product internally and this feature hasn't been ready for the last eighteen months. So, this was done on the side. We would prefer them to develop this feature and pay for it rather than having us do it.
We need more 100 gig ports. Right now, there are a lot of 10 gig ports and we don't need them all. We really need are more ports between 10 gig and 100 gig, which isn't possible.
The upgrade process for the boxes is not efficient. We have to go through the A10 aGalaxy where we have issues, like timeouts. They told me it was fixed in the latest version, but I tried to do it on the Portal and it is not working all the time.
A10 needs to be more distributed across all their customers. This would allow them to have the ability to act quickly during an attack across their entire customer base. At the moment, there isn't a way to provide information (anonymously). This is something A10 will hopefully release Q1 next year.
The documentation with the A10 really needs some improvement. They need to work on this, as it's hard to find all the information that you want.
The Customer Portal is sometimes really buggy.
We don't have issues with the stability. However, we did have an issue when we had the new box. We needed to have some optic support, which was not working. This was fixed in two weeks when they created a specific code for us. Compared to the industry, this is very fast.
The TPS gives us increased availability because we are using it to protect our customers.
It is not complicated to maintain. It takes one person to maintain it.
We have deployed it globally in Europe and the US. We will be deploying in Singapore and Japan in a few weeks. We are increasing our deployment for customers.
Today, we are serving 30 customers.
While we have the biggest unit, we haven't had the chance to use the box's full capacity. As we are distributed, every time we have an attack, we are not able to reach the capacity of the box. One TPS can block 200 gigs, as well 100 and 150 gigs. So, we never been in the position that we are using the full capacity of the box, at least not today. We are not getting enough 100 gig from this box, which we have already spoken to the design team about.
With the smaller boxes, they are okay, but we are not able to evaluate the box's fullest capacity because we bought two of them.
The goal is not to use it at maximum capacity because we want to have good quality for our customers. We want to add more boxes in order to have a lot of distribution for DDoS attacks across all the TPS boxes. Today, we have four boxes in position. We are going to order four more boxes (minimum) in order to distribute the traffic as much as we can. The goal is to be able to not use more than 60 percent capacity of the box.
We are doing stuff today to have the traffic not go through the box every time. It triggers going through the box for IOPS maybe two or three percent of the time.
Tech support is good. We have access directly to engineering where we can speak to someone to debug. All our tickets go to engineering.
We had some internal stuff previously. For solutions that we purchased, this was the first.
We have had the solution since the beginning. We have used it as our own mitigation and detection.
The box was deployed really easily. When we had to do the distributed mitigation, it took some time because we had to work with the aGalaxy and aGalaxy was pretty new for A10. We had to work directly with the engineering. Initial setup was done within a week because it was easy.
If you're just starting to work in a sample environment, what we did the first time, the process can be done really quickly. But, when you want to do something, like engineering or custom configurations, this can take sometimes months.
We did the setup ourselves since we have access to engineering. It only took one person to implement. It was pretty easy.
All the B2B configuration have to be done manually. As a network operator, this is easy for us. However, if you take an enterprise person who needs to do this, they may have some issues. They may spend a lot of time trying to understand how to configure it, as there is a lack of templates available. This is something which needs to be improved for the enterprise market.
We had a customer who was down for six hours and the loss of revenue for him was three times the price he was paying for us per year. The customer just said, "I don't care about paying you because on only one attack I saved money. It's three times better than losing money."
When customers start to get attacked, they need to be protected and we protect them. It's like insurance. When you buy your car, you don't use it. You say, "I pay for nothing." But the day someone crashes your car, and you are paying for insurance, you are happy that you are insured. This solution is exactly the same for customers.
We are waiting for our subscription model on our next four boxes.
We also looked at Radware and Fortinet.
Radware had good reporting. A10 does not have good reporting.
A10 had a good B2B code and the TPS box has good capacity. The key thing for us was the direct access to engineering. However, A10 is more complex then the other solutions. You have to spend time with it to become efficient at using it. You cannot just buy it and get started on it.
We use Juniper a lot. Their support would take months to fix the same issue that A10's engineering tech support team can fix in a couple of weeks.
The solution is not for newbies. You need to know some security stuff. The box is very flexible and capable with a lot of possibilities.
We are using A10, not just as a mitigation box. We provide the TPS box and all its mitigation backbone to our customer as a tool. At some point, we are obliged to do some training and do some testing in our lab for them.
DDoS attacks are evolving every day. Attackers are getting smarter. You have to continue to learn and experiment.
As a cloud infrastructure and hosting company, we provide public and private cloud services. We use the A10 technology to protect our customers against DDoS attacks against their hosting instances. The latter could be dedicated servers or virtual servers or data storage platforms.
We have technology in place to detect attacks at the border routers of our networks in all 20 data centers worldwide where we operate. If we detect an attack, we reroute the traffic of the IP addresses that are being attacked to the A10 Thunder systems. They drop the malicious attack traffic and they pass through the legitimate traffic to the servers or the virtual servers that our customers use.
We deploy different types, different sizes of equipment. We use these solutions on-premises.
When we started deploying this and we measured the impact on the number of customer complaints, we saw a significant reduction in the overall number of customer tickets. If customers have an issue with one of our servers, they open a ticket; that could be any outage or a DDoS attack. We saw an overall reduction of 11 percent in support tickets.
But we also saw that we were typically able to mitigate over 98 percent of all the attacks that we detect. That has a two-fold benefit. First of all, customers are happier because their service stays alive even in a situation where they are being attacked. And for us, it has a positive impact on our support team because it has 11 percent fewer tickets it needs to handle. That's especially true since "attack tickets" are not nice tickets to have to handle. It also helped us a little bit in the engagement and the motivation of our support team.
A10 has also definitely reduced the amount of manual intervention required during an attack. Before we had these systems in place, if an IP address or server was attacked above a certain level, we would manually no-route or "black-hole" the traffic, and basically remove that IP address from the internet. That was all manual work, while customers were complaining, and their customers were complaining. People were opening tickets. With this solution in place, all that manual work no longer has to happen. After detection of an attack, the scrubbing is initiated automatically. In the case of a huge attack, we will still null-route the traffic which is going to the IP address under attack, but that process is fully automated. So deploying these systems has reduced a lot of the manual work.
Using this solution we have also, to some extent, detected more small attacks, attacks that we had been missing previously. Before we deployed A10, we did not have any technology in place to detect an attack. Only if a customer opened a ticket did we know there was an attack. But when we started deploying the detection technology and the A10 scrubbing technology, we suddenly saw that we actually have a lot of smaller attacks as well, which were invisible to us previously. That means, most likely, that there were a lot of unhappy customers - or unhappy end-users of our customers' systems - that we were never aware of. That was suddenly fixed by deploying these systems. In all of 2018, we identified about 400 attacks each day, anywhere in our 20 data centers around the world. Many of these attacks were invisible to us before 2016 when we did not have this solution in place.
When it comes to the solution's performance given its form factors, for us, any equipment that takes up space and power is using scarce resources in a data center. The fact that these boxes do have a small form-factor, as only 1RU or 2RU devices, and that the power consumption is relatively low, is very beneficial for us.
We don't deliberately use the solution's machine-learning powered Zero-day Automated Protection (ZAP) but the systems require very little effort to keep them alive and manage them. The automation and the updates that A10 built in result in there being very little work for us to do to keep these systems up to date and efficient in the way they scrub attack traffic. So it's not functionality that we deliberately use, but it's a benefit of these systems, which helps us maintain a low cost of operations and an effective system.
The solution's automation also has the effect that the systems are very low-maintenance. That means that we can free up our people to do other work.
The primary benefit that we see from their systems is that their filtering technology has the ability to detect and drop the malicious traffic from the legitimate traffic with a high success rate. That, in combination with the very small effort needed to manage their systems, are the two most important benefits to us. On the one hand, it's the quality of scrubbing, and on the other hand, it's the low total cost of operations for us to keep these systems alive and working efficiently.
The quality of the scrubbing is, of course, what the system is supposed to do. It's the key functionality of the system. That's what we bought the equipment for. And the small effort to manage the systems and keep them alive, of course, immediately translates into a benefit that we have a low cost of managing those systems. That means we can allocate the time of our network engineers to other activities.
If you look at the total response time that we see in our solution, which means the time between the start of an attack and the time that the scrubbing really starts, we typically see two to three minutes. But the majority of that time is actually used by our detection technology, not so much the A10 network scrubbing technology. And then it takes a bit of time to reroute the traffic to the A10 equipment. Once it has been rerouted, the scrubbing starts very fast, so the start of the scrubbing is only a small part of the two to three minutes. In general, we're very happy with the response times and the scrubbing quality of the A10 equipment.
I've heard no complaints, so my perception is that the systems run very stable.
The solution enables us to scale defenses. We use different types or sizes of equipment. Typically, we start in some smaller locations with the smaller equipment type. When we see that location growing, we typically replace that device with a larger one and we move the smaller device to a new location where it's needed. We move the technology around quite a bit, which is our way of scaling up. The fact that there are different sizes of equipment, all with the same technology and the same processes for managing them, is very helpful for us. If you look at our smallest data center worldwide, it's a location which generates around ten gigabits per second of outbound traffic. That typically means about one or two gigabits of inbound traffic. Our larger data centers generate around 1.7 terabits per second of traffic. That's a lot more. And with one family of products, we can still protect both the smaller data centers as well as our larger locations.
So far, the systems do what we expect them to do and they scale as we expect them to scale.
Overall, our experience with technical support has been positive. We've had very few requirements for technical support. I know there's a 24/7 SOC team available to help us with large incidents or attacks which we can't resolve ourselves. But so far, we've never had a need to use that team. It's easy for us because the A10 team lives just a couple of blocks away from us. That makes it a bit easier to communicate.
The initial setup was pretty straightforward but we also had very good support from the local A10 team here in the Netherlands. Our headquarters are based in Amsterdam. The A10 Dutch office is just a couple of streets away from us, which also made it easier to work on this together. But having said that, the systems themselves are pretty easy to deploy.
Our initial deployment, back in 2016, happened in what were our six main data centers at the time. The easiest one for us was here in Amsterdam because it's almost next door to our office. The deployment itself, the physical installation and activation of the system, is not really the critical activity. Most of our time was spent integrating the systems with our own administration systems, so that we could deploy automatically. And there was the whole setting of profiles for IP addresses to understand how the detection should work and how the scrubbing should work. That was a bit of a software development effort which took about three months in total. But once that was done and we had all the integration tested, the actual deployment was basically determined by delivery time of the boxes, and that is true now for the deployment to new sites. Once a box is delivered, it's typically up and running in a couple of days.
Our implementation strategy was to make the solution part of our standard architecture for all data center networks. As of now, we have deployed the technology in 20 data centers around the world. Whenever we start a new site, we immediately put in this technology as well to make sure that we protect our customers on that site. And we try to automate the installation as much as possible so that deployment can be done remotely, from the configuration perspective. That way we don't need to send specialists onsite to a remote data center to get it up and running.
We did the first installation together with the A10 team here in Amsterdam. But all other installations, we've done ourselves, typically with remote hands that have very little knowledge about the specific systems in the data center itself.
The solution is then managed by our team of specialists in our NOC here in Amsterdam. The team that manages it consists of three network engineers who also do other things, of course. They are a part of our network operations team. These three people have developed into specialists for these systems and are, on the one hand, responsible for maintaining them and managing them. But on the other hand, they sometimes get involved when there are specific, large attacks where manual intervention is required to mitigate the attack.
Our experience with the A10 team was very positive, both during the evaluation of the various vendors back in 2015 - A10 was very supportive - as well as during the initial deployments here in Amsterdam where we worked together. They were knowledgeable, responsive, enthusiastic.
We have definitely seen return on our investment. If you look at some of the things we can measure, like an 11 percent reduction in support tickets, that can easily be turned into cost savings. Other things, like improved customer satisfaction, are a bit harder to monetize. But for us, we were convinced that within a year, we'd definitely earn back the investment, both in the A10 equipment, as well as developing the end-to-end solution, including the integration with our administration systems.
The financials are always a challenge with this type of technology. That's not really a product-functionality thing but it's the area where we were pushing A10 the most. But compared to the alternatives that we evaluated in 2015, the price-performance of the A10 solution was definitely superior to the other solutions which we evaluated at the time.
The way we did the deal was a combination of the equipment, the license, and a five-year support contract, for all sites. At the time it was a pretty good deal.
We did a lot of analysis in the second half of 2015. We evaluated different technologies and we ended up using A10. We went with it based on the price-performance. We had four systems on the shortlist. We physically tested two of those providers and, at the end of the day, the two came out pretty even from a functionality and performance perspective. But the total cost of ownership of the A10 solution was superior to the other vendor, so we decided to go with A10.
One of the four providers did not want to support a proof of concept test, so we dropped that one right away. We dropped another one after looking at functional specifications which, at the time, were not as good as A10 and the other vendor. We were left with the two that we tested. At the end of the day, the total cost of ownership made the difference.
From our perspective, the technology works well, and it has a low cost to maintain and manage.
One of the biggest lessons for me, in using this solution, was that there are so many smaller attacks going on that we were not aware of and which must have had an impact on the satisfaction of our customers, as well as the satisfaction of their customers. Everybody always talks about the huge attacks, the one- or two-terabit attacks that get into the news. But the fact there is such a huge volume of smaller attacks going, script kiddies, etc., to make other people's lives miserable was, to me, a bit of an eye-opener. That was resolved by deploying the A10 solution.
Availability is very critical to the success of our business. If you look at the customers that we primarily and proactively target, they are customers in the online gaming market, in the advertising-technology/marketing-technology markets, in the Software-as-a-Service and in the managed service providers market. All these companies are borne on the internet and their internet presence is critical to their success, to their existence. So for us, it's of primary importance that we keep their services up and running at all times, even when they are being attacked by cyber-criminals.
As Leaseweb, we have around 18,000 customers using our hosting services. All these customers' services with us are protected by the A10 technology.
In terms of increasing our usage of the solution, whenever we deploy new data center locations, we put A10 in right away. We do have some new locations that will be opening up in the next six months, so we will definitely be using more of these systems and protecting more customers.
I would rate A10 at eight out of ten. What would take it to a ten is the scalability, the ease of scaling up without replacing a box.

We use A10 Thunder TPS as an anti-DDoS tool.
The solution is easy to use and implement in terms of operations.
The solution needs improvement in terms of fail-open. We need separate fail-open kits connected to A10 Thunder TPS and the network so that network traffic will pass through normally when the tool goes down.
I have been using A10 Thunder TPS for more than two years.
A10 Thunder TPS is a very stable solution.
The solution is more suitable for medium-sized companies.
The solution provides good technical support.
The initial setup of the solution is moderate, and it is neither easy nor very hard.
Arbor is more famous than A10 Thunder TPS, and more people use it.
It was easy to integrate the solution with our current IT workflow. I would recommend the solution to other users.
Overall, I rate the solution a seven out of ten.
The solution's firewall features are the most valuable feature of the solution. I think we can use all the features or capabilities that come with the product's license. Maybe today, we are just implementing an SOP or LOB.
We have had some issues with implementation. So, it is the only area that needs improvement. However, I have no issues with the product, so it is probably fine.
The solution's support is one of the coolest things about the product. I rate the solution's technical support an eight and a half out of ten.
Positive
We are currently having some issues with the implementation. I think it is because the partner is not ready for implementation, and it's not that they don't have the experience. So, even though we have some issues right now with implementation, the product is very good.
The solution's price is one of the coolest things about the product. We may need to pay fifty percent more if we purchase other solutions. For the payments made to A10 Thunder TPS, we have received three-year support.
I rate the overall product a nine out of ten.