A tailor-made solution developed to run enterprise apps with optimized performance, comprehensive reliability and built-in availability.

Enterprise Application Platform Requirements

Critical enterprise applications are essential business continuity and prosperity. ERP is found in most enterprises, HIS in most hospitals, and MES in most manufacturing companies, all working in tandem with database services. Because these enterprise applications are crucial to business operations, they cannot afford slow response times, intermittent disruptions, and security threats. To avoid these issues that can cripple productivity, the underlying infrastructure platform must be equipped with components to ensure performance, availability, resiliency, and security.

Sangfor Enterprise Application Platform Powered By HCI and aStor

Sangfor Hyperconverged Infrastructure (HCI) continuously breaks new ground to meet the needs of critical enterprise applications. This robust infrastructure ensures performance, resiliency, and security at every layer of the platform.

In a typical enterprise setup, applications are distributed across different locations, including Core Data Centers, Remote Offices and Branch Offices (ROBO), Disaster Recovery (DR) sites, and off-premises Cloud Environments. Sangfor HCI offers centralized management to enable seamless integrate and maintenance of workloads, regardless of their location.

Data storage is a key aspect of enterprise application platforms, often requiring the storage of various data types such as block, file, and object data. Sangfor aStor, an advanced Enterprise Distributed Storage system, complements Sangfor HCI to support a wide range of data types, ensuring the optimal performance of enterprise applications.

Sangfor Enterprise Application Platform Advantages

Inside-Out Security

Sangfor HCI consolidates computing, storage, networking, and security to create a simplified enterprise application platform. This simplification reduces solution integration risk and minimizes the attack surface. The platform includes the built-in aSEC security operation center that uses virtual security appliances to protect public-facing applications and web services as well as critical internal databases. aSEC offers centralized security management, covering both internal and external traffic. This ensures excellent security visibility and governance across the entire HCI stack, effectively securing critical enterprise applications from the perimeter to the micro-segment level.

Efficient and Scalable Storage

Sangfor HCI’s built-in block storage can be complemented by Sangfor aStor—a unified, distributed storage system that supports block, file, and object storage. This combination of HCI and aStor allows for a flexible and efficient storage layer within the SDDC, opening up possibilities for a wider range of business scenarios. Both HCI and aStor run on commercial off-the-shelf (COTS) x86 servers, making them cost-effective, scalable, and easy to manage and maintain.

Local and Global Resiliency

Sangfor HCI provides local high availability (HA) through its data redundancy and integrated backup features. Additionally, Sangfor’s Disaster Recovery Management (DRM) solution offers off-site HA by replicating production workloads to the DR site. For scenarios that require the highest levels of availability, DRM allows HCI to stretch a cluster across two sites, establishing an Active-Active Data Center set up to ensure the best uptime for enterprise applications.

Sangfor Enterprise Application Platform Features & Capabilities

Security

aSEC 2.0 with Distributed IPS

  • Immediate Application Security: Apply security policies with a single click; no need for extra setup or configuration 
  • Adaptive Security Policies: Security policies automatically adjust to changes in VMs.
  • Unified Management: Manage both security and cloud resources from a single interface.
  • Flexible and scalable: VM-level control granularity. Scale out with business.

VM Protection with Sangfor Endpoint Secure

  • Built-in Endpoint Secure capabilities, including malware detection and removal, ransomware protection, asset management, vulnerability management
  • Automatic agent installation
  • Low resource consumption
  • File-level protection for Linux systems

 Threat Detection & Response with Sangfor Cyber Command

  • Cyber Command detects threats via network traffic analysis and coordinates with Sangfor Network Secure and Endpoint Secure to respond to various threats automatically or through manual intervention.
    • Ransomware: Takes snapshots of VMs to minimize data loss and enable recovery
    • Botnets: Works with the distributed firewall to quarantine compromised VMs
    • Cryptomining: Shuts down or suspends affected VM(s) to avoid illegal resource consumption

Disk Encryption Features

  • Provides secure encryption of VM disk images and snapshots.
    • Encryption algorithm: AES-256 and SM4
    • Range: One encryption module per VM
    • Key: One key per VM

Performance

HCI Host Affinity

  • The Host Affinity policy allows you to confine the entire stack of a web application—including the web, application, and database VMs—to a single server host.
  • This optimizes the communication between different tiers, as there is no need to route data to another server host.

HCI Virtual Load Balancer & Auto-Scaling

  • The virtual load balancer (known as Virtual Application Delivery [vAD] in Sangfor HCI) can be configured to distribute user traffic across multiple web or application VMs. This ensures that user traffic is evenly balanced, leading to optimal performance and user experience.
  • Auto-scaling groups comprising multiple VMs can be set up to automatically scale out or scale in based on resource utilization. Thresholds can be configured so that scaling is triggered when demand spikes, ensuring consistent performance.

Scale Out Capacity with Performance

  • Traditional SAN storage uses a frame-based design (controller with enclosures of disks) and scales up by adding more disks when performance bottlenecks occur at the controller.
  • Both HCI and aStor utilize a frame-less, shared storage design. By adding new nodes that connect to an ethernet storage switch, HCI and aStor can simultaneously scale out both storage capacity and data throughput, enhancing overall system performance.

Resiliency

HCI Cluster High Availability (HA)

  • Sangfor HCI offers a data protection strategy that replicates 2 or 3 copies of data across the cluster. This ensures that the cluster can tolerate the failure of one host with 2-copy redundancy or two hosts with 3-copy redundancy, all without data loss.
  • The HCI platform offers N+1 host redundancy, which allows for the recovery from a single host failure. In such cases, the affected VMs will automatically restart on another operational host to ensure service continuity.

aStor Data Protection

  • aStor software-defined storage uses Erasure Coding to secure data across its storage cluster. This mechanism prevents data loss in the event of a server node failure and offers better storage efficiency compared to the 2 or 3-copy redundancy in HCI.

Local High Availability

  • Beyond the built-in storage snapshots in HCI, the platform includes an integrated backup solution that saves data to external storage systems. Users can set backup schedules on an hourly or daily basis and recover data in minutes.
  • With Continuous Data Protection (CDP), HCI achieves near-zero Recovery Point Objective (RPO) by continuously backing up data every second.

Global High Availability

  • Sangfor Disaster Recovery Management (DRM) suite supports various Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO) configurations based on the criticality of different applications.
  • Sangfor DRM supports both on-premises DR (as CAPEX) and off-premises Cloud Disaster Recovery (as OPEX) with Sangfor Managed Cloud Services.
  • Sangfor DRM also supports VM replication of third-party virtualization platforms for added DR flexibility.