No more typing reviews! Try our Samantha, our new voice AI agent.
PeerSpot user
Technical Consultant at Westcon
Real User
May 21, 2020
A10 Thunder TPS (Threat Protection System) is the world’s highest-performance DDoS protection solution, leading the industry in precision, intelligent automation, scalability, and performance.
Pros and Cons
  • "The GUI is very use-friendly, you can configure it through CLI or GUI so they give you an option to choose, and it's a good solution in terms of the appliance itself because it's very light compared to other brands that offer DDoS solutions."
  • "They have a cloud scrubbing feature that redirects the traffic if the on-prem appliance can't accommodate a large amount of traffic but it's not available where we are."

What is our primary use case?

One of the largest persistent threats to service uptime is Distributed Denial of Service Attacks (DDoS). The networking industry and business analysts are seeing a trend in increasing DDoS attacks. These attacks are occurring more frequently and with greater intensity and increased sophistication. Legacy DDoS protection solutions suffer from the following fatal limitations that have made them ineffective at protecting against these attacks:

• Lack of flexibility

• Inability to scale

What is most valuable?

MULTI-VECTOR ATTACK PROTECTION

Detect and mitigate DDoS attacks of many types, including volumetric, protocol, or resource attacks; application-level attacks; or IoT-based attacks. Hardware acceleration offloads the CPUs and makes Thunder TPS particularly adept to deal with simultaneous multi-vector attacks

For how long have I used the solution?


What do I think about the stability of the solution?


Buyer's Guide
A10 Thunder TPS
September 2026
Learn what your peers think about A10 Thunder TPS. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.

What do I think about the scalability of the solution?


How are customer service and support?


How was the initial setup?


What's my experience with pricing, setup cost, and licensing?

The A10 aGalaxy management system provides centralized management of Thunder TPS systems and policies, orchestrates detection and mitigation of DDoS attacks, and delivers a single-pane-of-glass view of the generated reports across all managed Thunder TPS appliances.

No need to license each feature to activate it, it got a perpetual licensing and everything is there, you just have to configure and enable the feature when you need it.

What other advice do I have?

Select Thunder TPS hardware models to benefit from our Security and Policy Engine (SPE) hardware acceleration, leveraging FPGA-based FTA technology and other hardware-optimized packet-processing for highly scalable flow distribution and hardware DDoS protection capabilities.

Disclosure: My company has a business relationship with this vendor other than being a customer. distributor
PeerSpot user
Ethernet IP Engineer at a comms service provider with 11-50 employees
Real User
Sep 11, 2019
Our customers that are directly connected have almost instantaneous mitigation
Pros and Cons
  • "The solution has reduced the amount of manual intervention required during an attack. We have the inline solution and when it comes to the customers that we have on it, it has saved us some troubleshooting time."
  • "The solution has been rock solid for us; we haven't had any issues, we've had numerous attacks, and it's worked perfectly."
  • "If there's one aspect of A10 that needs improvement it would be the training. All of their training is done online, at least in what we've been exposed to. I would like to have a classroom environment for training... It would give [people] a chance to provision it."
  • "If there's one aspect of A10 that needs improvement it would be the training."

What is our primary use case?

Availability is very critical for us. We use it to mitigate DDoS attacks for rural North Dakota. We really don't use it to identify attacks, we use third-party software, a Kentik solution, to identify anomalies within the IP stack. Then, we turn around and send mitigation profiles to the A10 based on an API call, and the A10 initializes a BGP session to our core routers to offload that traffic and mitigate it.

We provide hosted solutions so our deployment of A10 is private cloud.

How has it helped my organization?

Our setup is something of a hybrid solution. We're using the third-party software, the Kentik solution, but we also have some clients that are directly connected to TPS. There is a 30-second delay in time to mitigation for clients that are not direct. By the time that third-party solution identifies something and sends it, via API, to the TPS, there's about a 30-second delay. When we have customers that are directly connected, they have just about instantaneous mitigations with TPS.

We use that inline setup as a premium service. If customers can tolerate a small spike in traffic flow until the mitigation happens then we'll just leave them on the Kentik solution. If they want it instantaneously then we'll put them inline and connect them directly to the TPS for that. Customers who opt for the premium service include financials, utilities - anything which needs that instant mitigation and understands the threat of DDoS. Some entities can tolerate it if they're down for a minute or two minutes and it's not crucial that they pay the extra dollars.

Overall, DDoS attacks affect small-town North Dakota in a fairly large fashion, meaning that they could affect infrastructure from schools to county courthouses to libraries, etc. Those places aren't directly associated with the target of the attack but the appliance itself and the solution in general allow for the protection of those services in those communities. It has been very successful.

The solution has reduced the amount of manual intervention required during an attack. We have the inline solution and when it comes to the customers that we have on it, it has saved us some troubleshooting time. If we can see that there is an active zone, we know that their traffic is being mitigated. If a customer calls and says, "Hey, I have internet problems", one of the first things we check is if there's a DDoS attack happening.

Anytime you filter, you set up thresholds, you can identify your traffic patterns a lot better.
It has helped in that aspect as well. We did miss attacks previously.

What is most valuable?

We're just using a portion of it, the mitigation aspect.

What needs improvement?

If there's one aspect of A10 that needs improvement it would be the training. All of their training is done online, at least in what we've been exposed to. I would like to have a classroom environment for training. I would like to say, "Okay, if we have three or four people who need to get trained up, we want to send them to a classroom." That way they're detached from their home office and have the lab facilities. They can have a classroom environment or experience instead of a virtual classroom. It would give them a chance to provision it. There's a better experience in a classroom than in a virtual classroom.

It's not a terrible issue, but the training was the biggest thing that we faced. We're two years into this and we haven't done all the training probably needed to fully support it, because our deployment is very limited. But when we did want to pursue training, I believe that the training was all virtual.

For how long have I used the solution?

We've been using this solution for about two years.

What do I think about the stability of the solution?

It's been rock solid. We haven't had any issues with power supplies or software anomalies. It's been a pretty good platform.

What do I think about the scalability of the solution?

For our deployment, we're probably not even using ten percent of its capacity as far as throughput port space. For us, the scalability is very high. For us, it's like investing future-forward.

The usage potential increases daily, exponentially, based on the internet curve. But we're just using a small percentage of the features and a small percentage of its capacity.

We have about 200 customers that have access to the solution with 100,000 users on their side. We carry something like 80 Gig of internet traffic into the state. Because we're using that third-party for the majority, TPS doesn't see all that 80 Gig of traffic. It only sees the traffic that has been identified by the third-party software. The TPS isn't necessarily handling packet, packet, packet, packet; it's handling only packets that are being sent to it by the third-party. In that scope of scalability, it's almost exponential because we're only identifying the traffic flows and patterns that need to be mitigated.

How are customer service and technical support?

We have opened a few tickets with TAC and they've been good, along with their sales engineering team. We may have a customer that will have an atypical type of deployment. In that case, we'll bring in the sales engineering team or TAC and they'll get us in contact with an expert in that field. Their tech support has been very good.

Which solution did I use previously and why did I switch?

We did not have a previous solution.

How was the initial setup?

The initial setup was pretty straightforward. You set up your routing tables, your interfaces. There was no magic there.

We have two and we had them both up and running within three or four days, meshed with our network. The process was to get it connected to our core internet routers and have it start talking to a third-party software and, after that, start the mitigation processes.

What about the implementation team?

We mostly did it ourselves. From the A10 side, we had our sales engineer and we had a few calls with their support staff. Based on that, we developed a roadmap and then we self-installed and deployed it.

What was our ROI?

Our situation is unique because we're owned by the 14 independent broadband providers in North Dakota. So we may not directly see an ROI because the bandwidth of the DDoS traffic basically gets to us. However, we save that extra bandwidth to our owner companies from downstream services. We're saving our members money with the solution.

Which other solutions did I evaluate?

We did a proof of concept and had a bake-off between Arbor and A10 and Kentik. Because of the reports that we wanted and how we wanted to handle things, the third-party and the A10 solution were technically the best, and scalable.

The flexibility of solutions was important to us. We have the ability to either go inline, to connect directly to the TPS, or to bring it through the third-party. That in itself was a major selling point because we're not stuck with one solution. If we decide that we want to change third-party vendors, we're not married to it. We can shop around and if there's something better that comes out, we can still interface the TPS system with that new software. It meant we weren't just saddled to one vendor for a DDoS solution.

What other advice do I have?

Do your research to understand your solution options. Then, have a PoC bake-off and task the system. Identify ad-hoc anomalies in your test-bed and look at the time to mitigation. Look at different types of situations to see, if an anomaly comes along, how long it would take you to deploy an ad-hoc solution or redirect the traffic. Research and proof of concept is our biggest thing. We never do anything without doing them thoroughly.

The biggest thing I have learned is how many attacks there are and how many different ways the attacks happen, throughout an attack. You can have a DNS attack, you can have an ICMP attack. You can have all these different flavors of attacks. That was probably the biggest eye-opener for me. When you hear the word "DDoS," everything gets put into a container. It's not until you look into the container that you see all the different types of attacks that are summed up by that word.

The solution has been rock solid for us. We haven't had any issues. We've had numerous attacks and it's worked perfectly.

I don't know that it has an increased network availability notably but it has added to it. Instead of having four-nines of availability, we've got five-nines. It's a solution and a package, so it's not our only tool in our toolbox.

We only use the TPS side of it and we're not 100 percent trained up on it, even though we've had two years of deployment on it. We don't know the whole, full-meal deal on what it can do. There's a possibility we'll go to the load balancing and some of those features. Even though we have hosted solutions, we don't have enough because we're a small company. There are other features but we'll explore those as we need.

We have just two people who have access for configuration of the solution and its operations, in our engineering operations.

I would have to rate A10 TPs as a nine out of ten. We've been very happy with the product. Of course, we don't want to give tens because then get people get cocky about it. 

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
A10 Thunder TPS
September 2026
Learn what your peers think about A10 Thunder TPS. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,287 professionals have used our research since 2012.
SocManag35a5 - PeerSpot reviewer
SOC Manager at a media company with 1,001-5,000 employees
Real User
Sep 10, 2019
Enabled us to ramp off our upstream cloud-scrubbing provider and handle all attacks on our own
Pros and Cons
  • "Based on previous equipment that we had, it's amazing that this device can do what it can do in a 1U form factor. The devices that we have right now have never gone over capacity and we've actually mitigated some pretty large attacks."
  • "Due to the availability and power of these devices, we've been able to ramp off our upstream cloud-scrubbing provider and handle all attacks on our own."
  • "We currently do not use the solution's machine-learning-powered Zero-day Automated Protection because of an issue with it... We also use the aGalaxy platform, which is a management platform for the TPS devices. The issue is that some TPS features were added at the TPS level but weren't carried over to aGalaxy, and we manage all of our devices through aGalaxy. So we can't actually use some of the new features that are available on the TPS because that functionality doesn't exist in aGalaxy. That is one of my biggest complaints."
  • "We currently do not use the solution's machine-learning-powered Zero-day Automated Protection because of an issue with it."

What is our primary use case?

We use it for DDoS mitigation. Availability is extremely critical to our business. We provide online services for two, large video game titles, so there's a requirement to keep our game online and for our players to be able to play the game.

We use it on-prem.

How has it helped my organization?

Due to the availability and power of these devices, we've been able to ramp off our upstream cloud-scrubbing provider and handle all attacks on our own. Right now 100 percent of our attacks are handled on-prem with these devices. In 2019 - we're nine months into the year - we've had 1,500-plus attacks and less than five of those attacks have had impact on us.

Our current setup is two 6435 TPS devices at each location. Each of those boxes is rated for 155 Gigs of traffic. We currently are sending 100 Gigs of traffic to each box, that's the bandwidth of the line that we have coming in, and we successfully mitigated a 163-Gig attack. That one was successfully mitigated within the last month by those devices.

In terms of increased availability, I would say it's at about 99.999 percent, overall. We haven't had any major impact, anything more than five minutes, in about two or three years now, due to DDoS.

The automation in TPS makes my team more productive. There is less manual work for my team in dealing with attacks, and with other functions as well, because that automation is built-in: An incident is created, the attack is mitigated, and a report is created. There's really zero touch at this point in time for attacks. It has very much reduced the amount of manual intervention required during an attack.

That is especially true with the newest upgrades that just came out where it does automated pcaps. Everything that we need at this point in time is automated. The device automatically goes into mitigation. It gets the pcaps for us and, a large percentage of the time, it just blocks the traffic that we're looking for. Having those pcaps also helps out because in the future, when we're looking at attacks where we may not have either signature or a proper remediation, we can actually build that in based on the data that we're receiving from those pcaps.

Using TPS we have detected a lot more small attacks and attacks that we had been missing previously, but that's not only because of TPS. We do gather flow information from the TPS devices as well as from our border routers that we recently upgraded. We're using FlowTraq. With that combination, we are seeing a large increase in the number of DDoS attacks that we're detecting compared to what we were using previously, which was a third-party cloud provider. On average, we're detecting anywhere from 25 to 50 more attacks per week than we did previously.

What is most valuable?

The most valuable feature is the DDoS mitigation availability, the ability to be able to block different types of attacks, and large attacks. That's the main function of the device that we use today. They're able to block attacks that we see against us, to prevent attacks as we see them, to prevent further outage to the environment.

Also, based on previous equipment that we had, it's amazing that this device can do what it can do in a 1U form factor. The devices that we have right now have never gone over capacity and we've actually mitigated some pretty large attacks with these devices.

The solution's response time to an attack is pretty good. Normally, it's a matter of milliseconds and most of the time, within one minute, we have a response and we have mitigation in place. That limits the impact to our environment when we do have an attack.

We use the solution's programmable automated defense using RESTful API quite a lot. We don't use it for configuring the device, but we do use it for things such as grabbing stats and data as well as doing automated blacklisting of IPs and using class lists within devices. It works fairly well. For the most part, we only use the RESTful API for certain tasks. A10's aGalaxy uses API to configure the devices as well and we rely on that for all basic configuration such as IP addresses and port configuration.

What needs improvement?

We currently do not use the solution's machine-learning-powered Zero-day Automated Protection because of an issue with it. We have a ticket open with the team to try to resolve that problem. That is one of the problems that we have today, something that is not working.

We also use the aGalaxy platform, which is a management platform for the TPS devices. The issue is that some TPS features were added at the TPS level but weren't carried over to aGalaxy, and we manage all of our devices through aGalaxy. So we can't actually use some of the new features that are available on the TPS because that functionality doesn't exist in aGalaxy. That is one of my biggest complaints.

We're somewhat the guinea pig for using both aGalaxy and TPS. There are some features that we would love to use, but unfortunately, because we're on aGalaxy, we don't have the ability to use them due to limitations of the devices. The A10 team just needs to work on making sure they have a release cadence so that the TPS and aGalaxy are in line with each other.

A lot of the issues that we had previously with the devices were because a given functionality didn't exist and it took a while for the team to actually create that for us. But since they were implemented and the kinks were worked out, everything has been working pretty well.

For how long have I used the solution?

We have been using A10 TPS for about a year-and-a-half.

What do I think about the stability of the solution?

Overall, today, the stability is great. We have very few issues with the devices in terms of their performance or their availability. 

We did have some issues previously which were resolved. We had some crashing issues on the devices but, with the last upgrade that we received about a month or two ago, those issues were resolved. We haven't had any major issues with our devices since we moved to the new code version.

What do I think about the scalability of the solution?

It enables us to scale defenses. We can go up to eight boxes at each location, with the current configuration that we have.

As time goes on, we are looking into possibly going with the newer devices which just came out and which have increased capacity. We're also potentially looking to move out to more pop locations in the future: Having an internet connection and an A10 TPS at a remote location, and then we would back-haul traffic to us. We are looking to potentially expand our footprint in the future.

Overall, scalability is just a limitation of our own network. But having ECMP and BGP available to us, we can scale out as horizontal as we need to, relying on whatever size of pipe we have coming in. It's really our own limitation at this point in time. Each of our data centers do 100-Gig pipes, which the devices have plenty of support for. But if we did need to roll out to either four devices or six devices, we would have the availability to do that.

How are customer service and technical support?

We used A10's support team, not for the initial setup but when we ran into issues. We would definitely use their support team for bringing issues to their attention and getting information to them saying, "Hey, this is what we're trying to do, this is what we need for the device to do," and they would actually build it out for us. That included their dev team as well. They were very open with their dev team for what we needed.

Overall, they're really great. For the most part, they understand what our needs are and they understand what problems we run into. Their support team is really good when we speak with them, as far as resolving our issues goes. 

It does take some time, at times, to get issues resolved, but that is the nature of having them build out products or fixes for us. They have worked on a number of issues with us where something is not scheduled to be released but they either give us a hot-fix or they fix it in code and give us that version ahead of time, before it's actually released to the public. That is a great asset for us.

Which solution did I use previously and why did I switch?

We were previously using the Arbor APS platform. Some of the reasons we switched were that the TMS platform we were looking at didn't have the functionality to do ECMP and BGP the way we wanted to be able to do them. The second major factor was pricing. Pricing was much higher with Arbor for the same type of solution.

How was the initial setup?

I'd break the initial setup into two parts. I did not do the network part of the setup, although I know our network team had some issues with the initial setup because of the limitations of the devices at that point in time.

For the network part of the setup, one of the limitations the device used to have, and no longer have, was with BGP. The way we run our environment is that the TPS device is actually a BGP device within our network and it peers with other devices. That's not a common setup that A10 is usually used for. It's normally used in an environment where there are routers to the north and south of the device, so that there's usually another device that you reroute traffic to when there's an attack. But because we wanted to be in an always-on, asymmetric situation, we didn't have that ability. So they had to build it for us.

They also had to build what's called ECMP, which is equal-cost multi-path. It's basically load balancing on the network side. They had to build that in for us as well because that was a requirement for how we were going to build the environment. So there were some growing pains when we first brought it online just to make sure that everything was working. They built it into the product for us and it is now working perfectly fine. It is a standard feature now in the newer versions. They've added the ability to have BGP route-on and route-off as an option. Some teams do use that functionality where they have the two routers and they route on only when there's an attack. In our case, we are always on so we have the ability to turn that functionality off because we don't need it.

From the perspective of defenses through aGalaxy, that's gotten better over time. They've made a lot of enhancements to the product that we've requested to make our lives easier. We are currently running approximately 163 zones in our aGalaxy. Managing that number of zones and IPs can be kind of a daunting task, but they've added a bunch of features in the new versions of aGalaxy to be able to easily do that and onboard new IP addresses in an easier manner.

It took us about six-plus months to deploy. We had our existing solution in place and the new solution was hanging off of that for testing purposes. It was a good six to eight months before we were fully migrated over and we had our devices inline.

Previously we were using a different vendor for our mitigation, which was basically two 10-Gig connections that were shared across a switch stack, with all the devices being inline. That was very susceptible to failure because the traffic was always inline. Part of the new implementation requirements from the network team was that we have the ability to set up BGP, which is how it's set up today. So if for some reason there is an issue with a device, like a TPS, we can always pull the BGP route to that device and route traffic around it. Previously we didn't have that ability, so if there ever was an issue on our hardware stack, it would affect all services.

What was our ROI?

We have definitely seen return on our investment by going with A10. We have been able to scale back our cloud services due to the deployment of the A10s. Our future goal is to actually discontinue use of cloud services for DDoS mitigation.

What's my experience with pricing, setup cost, and licensing?

We are doing multiyear licensing. We signed up for three years to get a discount. We're doing that for most of our vendors at this point in time.

As far as I'm aware, there aren't any additional costs to the standard licensing fees. For aGalaxy there is a limitation on how many zones and how many devices we can deploy, but that's the only limitation there is. Currently, we're at 500 zones and about 50 devices. Everything else is not on a gigabyte or a license model where you can only have so much traffic through these devices. There are no such limitations. It's a software license for being able to upgrade to newer versions.

We are always looking to do multi-year deals, especially with devices that we plan on keeping. Being able to do multi-year is a pretty standard thing now. It just works for us and it gives us the ability to grow as we need.

Which other solutions did I evaluate?

We looked at products such as Radware and another product but I don't remember the name of it. Ultimately, based on some information and data from other gaming companies that we spoke with, it was suggested that we look at A10.

It's so long since we actually looked at Radware, but Radware was being used by our cloud provider for their DDoS mitigation. One of the things that we looked at was that their capacity per box was much lower. At the time, those boxes only were able to handle about 10-Gigs of traffic each, which was way below our needs, especially since we were moving to a multi-hundred-Gig solution.

What other advice do I have?

The type of configuration and the type of network you're planning on running really matters. A10 does a good job of letting you know what's available and what works for the company, depending on those needs. For our use, we needed to be full, 100 percent on. Some companies don't require that and they can afford some type of downtime for BGP cut-over and such. My advice would be to really work with the A10 engineering team on what your needs are and what you're looking for in a product, to make sure that is a viable option. We spoke a lot with other gaming companies that were using the solution and asked, "What is your setup? What kind of issues have you had?" We're using it in a different fashion than some of the other gaming companies are using it today, but it works for us and we think it does a great job.

The biggest lesson I have learned from using this solution is that it does take time to implement. There always are going to be some software issues that need to be worked through. Having a more versatile environment and versatile network makes it a lot easier, so that if you do have issues you can certainly work around them. That's especially true in a production environment. We really don't have a test environment that we are able to set up to test these in and this was basically done by hanging off our production environment with minimal downtime.

In our organization, there are two major teams that use the tools. There are three folks on the networking team and they handle all networking aspects, including BGP, routing, and configuration of the device from a networking perspective. And my team is the SOC team. I currently have nine folks. We work about 95 percent off of the aGalaxy system. We're responsible for responding to alerts, responding to attacks, gathering pcap data, gathering data about zone alerts, etc. Those 12 people are the ones responsible for the A10 devices.

That same group of people is responsible for deployment and maintenance of the solution. I'm mainly responsible, on the security side, for any types of updates that get pushed to the devices. That would be any type of software updates or any type of work being done. Whereas on the networking side, it usually just requires one person if we're doing any type of work. It doesn't require the whole team, for the most part. All three people in the network team have knowledge of the system, but it's usually two people required for that work if we do any types of updates.

I would rate it at nine out of ten. It does have its issues that are being worked through, but overall it's great.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user1178106 - PeerSpot reviewer
Co-Founder at Acorus Networks
Reseller
Sep 3, 2019
Protects our customers against attacks. The upgrade process is inefficient and needs improvement.
Pros and Cons
  • "We selected the solution because of its programmable automated defense using RESTful API. We didn't want to connect to the box. We wanted to be able to do some automation. We wanted to have our own portal because we wanted to connect our customers to our own UI using the A10 API. It has been good and exactly what we need."
  • "The upgrade process for the boxes is not efficient. We have to go through the A10 aGalaxy where we have issues, like timeouts. They told me it was fixed in the latest version, but I tried to do it on the Portal and it is not working all the time."

What is our primary use case?

We work like an MSSP. We provide massive capacity and other network capacity to customers. We have customers connect anywhere on back burn. It can be in Europe. It can be in the US or in Asia. We plug the attack anywhere on the back burn, trying plug the attack closest to the source of the attack. So, we don't work like all the other guys who do scrubbing centers. We try to build a scrubbing network. That is why we need to buy more TPS in order to be distributive.

When we start to work with the customer, we don't know what they have. The goal for them is to be able to block any type of massive volume metric attack. The reason is why we have about a two terabytes capacity and are building to afford three to four terabytes of capacity. Therefore, anytime the customer needs to block something, we can configure for them any type of custom role.

We are using them for a mitigation offer that we have globally. We have a bunch of A10s and will deploy more in a few weeks.

We use both the hardware and software.

How has it helped my organization?

We started with them and built our network based on this solution. We started with them directly from scratch.

The automation makes our team more efficient and productive. We are distributed and don't use the A10 Portal. It's easy for us to deploy. E.g., they have an aGalaxy product. Instead of connecting to all the boxes, so we will have the A10 box. We don't want to send a code to all the A10 boxes. We will just send the information to one box: the A10 aGalaxy. This one box will proxy it and send the information all the other boxes. This is exactly what we are doing today. It has improved the way that we are working.

What is most valuable?

We use all the features, but our customers have started asking for key features around SIP. We are also using some proxy features.

The solution’s response time to an attack is fast. When it is configured in line, it is automatically done. When we have to stop the attack, it takes 10 to 15 seconds.

We selected the solution because of its programmable automated defense using RESTful API. We didn't want to connect to the box. We wanted to be able to do some automation. We wanted to have our own portal because we wanted to connect our customers to our own UI using the A10 API. It has been good and exactly what we need. 

The TPS has reduced the amount of manual intervention required during an attack. When we have an attack, and we need to block some stuff everywhere, we just click on a button and push the rules. Then, it's deployed in Asia, Europe, and US. We don't have to do anything more. 

The aGalaxy is a control plane for the product. It controls the entire TPS so you don't have to connect to the box. You just have to connect to this control plane.

What needs improvement?

The solution’s machine-learning-powered Zero-day Automated Protection (ZAP) works for enterprise customers, but for MSSPs, we have too much traffic and analytics. Therefore, it is unusable and A10 is working on a new feature that we requested. It should be ready in two weeks.

We have to be able to do some automatic rules proposals based on what is detected. We use this product internally and this feature hasn't been ready for the last eighteen months. So, this was done on the side. We would prefer them to develop this feature and pay for it rather than having us do it.

We need more 100 gig ports. Right now, there are a lot of 10 gig ports and we don't need them all. We really need are more ports between 10 gig and 100 gig, which isn't possible.

The upgrade process for the boxes is not efficient. We have to go through the A10 aGalaxy where we have issues, like timeouts. They told me it was fixed in the latest version, but I tried to do it on the Portal and it is not working all the time.

A10 needs to be more distributed across all their customers. This would allow them to have the ability to act quickly during an attack across their entire customer base. At the moment, there isn't a way to provide information (anonymously). This is something A10 will hopefully release Q1 next year.

The documentation with the A10 really needs some improvement. They need to work on this, as it's hard to find all the information that you want.

The Customer Portal is sometimes really buggy.

For how long have I used the solution?

I have been using it for eighteen months.

What do I think about the stability of the solution?

We don't have issues with the stability. However, we did have an issue when we had the new box. We needed to have some optic support, which was not working. This was fixed in two weeks when they created a specific code for us. Compared to the industry, this is very fast.

The TPS gives us increased availability because we are using it to protect our customers.

It is not complicated to maintain. It takes one person to maintain it.

What do I think about the scalability of the solution?

We have deployed it globally in Europe and the US. We will be deploying in Singapore and Japan in a few weeks. We are increasing our deployment for customers.

Today, we are serving 30 customers.

While we have the biggest unit, we haven't had the chance to use the box's full capacity. As we are distributed, every time we have an attack, we are not able to reach the capacity of the box. One TPS can block 200 gigs, as well 100 and 150 gigs. So, we never been in the position that we are using the full capacity of the box, at least not today. We are not getting enough 100 gig from this box, which we have already spoken to the design team about.

With the smaller boxes, they are okay, but we are not able to evaluate the box's fullest capacity because we bought two of them.

The goal is not to use it at maximum capacity because we want to have good quality for our customers. We want to add more boxes in order to have a lot of distribution for DDoS attacks across all the TPS boxes. Today, we have four boxes in position. We are going to order four more boxes (minimum) in order to distribute the traffic as much as we can. The goal is to be able to not use more than 60 percent capacity of the box.

We are doing stuff today to have the traffic not go through the box every time. It triggers going through the box for IOPS maybe two or three percent of the time.

How are customer service and technical support?

Tech support is good. We have access directly to engineering where we can speak to someone to debug. All our tickets go to engineering.

Which solution did I use previously and why did I switch?

We had some internal stuff previously. For solutions that we purchased, this was the first.

We have had the solution since the beginning. We have used it as our own mitigation and detection.

How was the initial setup?

The box was deployed really easily. When we had to do the distributed mitigation, it took some time because we had to work with the aGalaxy and aGalaxy was pretty new for A10. We had to work directly with the engineering. Initial setup was done within a week because it was easy.

If you're just starting to work in a sample environment, what we did the first time, the process can be done really quickly. But, when you want to do something, like engineering or custom configurations, this can take sometimes months.

What about the implementation team?

We did the setup ourselves since we have access to engineering. It only took one person to implement. It was pretty easy.

All the B2B configuration have to be done manually. As a network operator, this is easy for us. However, if you take an enterprise person who needs to do this, they may have some issues. They may spend a lot of time trying to understand how to configure it, as there is a lack of templates available. This is something which needs to be improved for the enterprise market.

What was our ROI?

We had a customer who was down for six hours and the loss of revenue for him was three times the price he was paying for us per year. The customer just said, "I don't care about paying you because on only one attack I saved money. It's three times better than losing money."

When customers start to get attacked, they need to be protected and we protect them. It's like insurance. When you buy your car, you don't use it. You say, "I pay for nothing." But the day someone crashes your car, and you are paying for insurance, you are happy that you are insured. This solution is exactly the same for customers.

What's my experience with pricing, setup cost, and licensing?

We are waiting for our subscription model on our next four boxes.

Which other solutions did I evaluate?

We also looked at Radware and Fortinet.

Radware had good reporting. A10 does not have good reporting.

A10 had a good B2B code and the TPS box has good capacity. The key thing for us was the direct access to engineering. However, A10 is more complex then the other solutions. You have to spend time with it to become efficient at using it. You cannot just buy it and get started on it.

We use Juniper a lot. Their support would take months to fix the same issue that A10's engineering tech support team can fix in a couple of weeks.

What other advice do I have?

The solution is not for newbies. You need to know some security stuff. The box is very flexible and capable with a lot of possibilities. 

We are using A10, not just as a mitigation box. We provide the TPS box and all its mitigation backbone to our customer as a tool. At some point, we are obliged to do some training and do some testing in our lab for them.

DDoS attacks are evolving every day. Attackers are getting smarter. You have to continue to learn and experiment.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
Jaffar Ali - PeerSpot reviewer
Director Technical Services at TechnoBIZ
Reseller
Top 5
Apr 1, 2019
Enables us to keep a record of all the invoices and to track accrued sales but I would like to see an advanced reporting feature
Pros and Cons
  • "We can keep track of all the customer's requirements, we can forecast our trials, and we can forecast our overall financial things."
  • "I would like for them to develop an advanced reporting feature."

What is our primary use case?

Our primary use case is for our support ticketing and invoice generation. We're resellers and we provide it to our customers. 

Our other use cases are for keeping a record of all the invoices and we use it for our sales to track the accrued sales. 

How has it helped my organization?

We can keep track of all the customer's requirements. We can forecast our trails and we can forecast our overall financial things.

What needs improvement?

We are really trying to improve our sales module. When we need to see our exact payments and invoices we can track which payments and invoices are due so that we can make sure that all the invoices are done on time.

I would like for them to develop an advanced reporting feature. 

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

It is very stable. We're using a very basic model and it's the basic version. There are very few features so for those features, it is very stable. If we decide that we're going to implement more features into it, then there could be some concern about the stability of the product.

What do I think about the scalability of the solution?

Scalability is fine. 

We have sixteen users. On the support side when we generate tickets, we are quoted fifty plus customers that are on this solution.

How was the initial setup?

The initial setup was straightforward. Deployment only took a few hours. The  user training takes at least a day and then the whole site will go up in around a weeks time. It's all web-based so the back ends sometime require us to make changes but overall it's pretty simple and straightforward.

We only require one staff member for maintenance. 

What other advice do I have?

I would rate it a seven out of ten. 

Disclosure: My company has a business relationship with this vendor other than being a customer. Resellers.
PeerSpot user
Buyer's Guide
Download our free A10 Thunder TPS Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free A10 Thunder TPS Report and get advice and tips from experienced pros sharing their opinions.