Riverbed® Stingray™ Application Firewall


Application Firewall
Model Specifications: Riverbed Stingray Application Firewall
Stingray Application Firewall (SAF) consists of three independently scalable components:

Decider modules apply security policy to traffic bidirectionally. Decider modules are deployed on a cluster of 1 or more multi-core servers;

Enforcer plugins are deployed on origin web servers or proxies, forward selected traffic to the Decider cluster and enforce the decision returned;

The Administration Server manages and deploys security policies to the Decider cluster and reports on security status.
Platform Requirements
Decider, Enforcer and Administration Server
components are available as packages for
the following OS distributions, for x86 and
x86_64 architectures:
Centos 5 & 6, Debian 6, Fedora 17, Gentoo 12, RHEL 5 & 6, SLES 10 &11, ScientificLinux 6, Solaris 10 (x86 and SPARC only), Ubuntu,
8.04, 10.04, 12.04, Windows Server 2003, Windows Server 2008, Windows Server 2008 R2 (x86_64 only)
The Enforcer module integrates with the

following web / app servers:
Linux: Apache 2.0, 2.2; Apache Tomcat 5.5, 6.0
Windows: IIS 6, 7; ISA 2006; IAG Server 2007
Resource Requirements
A minimum of 1GB of free disk space is

required for each module for program data
and logging. In addition, the following
module specific requirements apply:
Decider: 1GB memory per core

Enforcer: CPU utilization of web server should not exceed 60% before deployment of Enforcer plugin

Administration Server: 2GB memory
Minimum resource requirements
1 GB disk space for program data and logging; 2 GB memory
1. Capacity of SAF Decider module depends on number of licensed cores and complexity of security policies.

2. SAF Administration Servers can manage 500 servers running SAF Decider modules. SAF Administration Servers may be deployed in a fault-tolerant cluster of up to 8 units for high availability.
