Clustering Advanced Threat Defense Appliances

When you have a very heavy load of files to be analyzed for malicious content, you can cluster two or more Advanced Threat Defense Appliances. So, the analysis load is efficiently balanced between the Advanced Threat Defense Appliances (nodes) in the cluster.

Consider multiple inline Sensors submitting hundreds of files per second to one Advanced Threat Defense Appliance. In the blocking mode, a Sensor waits for up to 6 seconds for Advanced Threat Defense to analyze a file. After this time period, the Sensor forwards the file to the target endpoint. Faster response from Advanced Threat Defense could be accomplished by clustering Advanced Threat Defense Appliances for load-balancing.