F5 is announcing the latest release of its management, orchestration, visibility, and analytics platform, BIG-IQ.
With BIG-IQ 7.0 you can more easily manage, analyze, and troubleshoot every device, every application, and every policy from one centralized location—no matter the operating environment. Several new BIG-IQ features are:
More information is available on the F5 Newsroom or by visiting the BIG-IQ and Automation Toolchain product pages.
F5’s Container Ingress Services can now be used in conjunction with Google Cloud’s GKE On-Prem solution – a core component of Anthos – to deliver advanced traffic management and security services within this new hybrid container environment.
GKE On-Prem instances will come pre-packaged with Container Ingress Services to streamline the provisioning process for F5 customers.
For more information, check out this Newsroom article.
F5 has delivered another set of managed rules that can be layered atop the native AWS WAF to provide additional API protection.
This ruleset protects API’s within AWS’ API Gateway and other common API frameworks against threats, including XML external entity (XEE) attacks and server-side request forgery (SSRF).
For more information, check out this newsroom article or visit the AWS Marketplace listing here.
F5 has extended its multi-cloud ecosystem with newfound support for Alibaba Cloud.
F5 Virtual Editions including BIG-IP VE, Advanced WAF VE and Per-App VE can now be deployed in direct from the Alibaba Cloud International Marketplace to provide advanced traffic management, performance, and security services for applications.
For more information check out this Newsroom article, or visit the Alibaba Cloud International Marketplace direct.
This release expands F5’s Cloud Solution Template portfolio by delivering new templates for AWS, Azure and Google Cloud, while also providing various updates to existing templates. These updates are summarized below:
AWS CloudFormation Templates
Azure Resource Manager Templates
Google Deployment Manager Templates
Check out this overview or visit the F5 GitHub repository to learn more about F5 Cloud Solution Templates.
F5 is announcing the general availability of two preconfigured, packaged NFV solutions that simplify the deployment of virtualized solutions for service providers. The solutions include F5’s VNF Manager, delivering fully-automated, end-to-end VNF lifecycle management that allows for the dynamic spin up, spin down or addition of new resources. An auto-scale function helps customers dramatically reduce overprovisioning of services because bandwidth increases automatically and is available on demand.
The NFV solutions are purchased as throughput options of 5, 10 and 50 Gbps increments, which simplifies customer network planning, sizing and purchasing. Solutions are available as perpetual or subscription licenses. In addition, a new use-before-buy model means that customers can increased bandwidth usage as needs grow, and not be charged until the end of that quarter.
The two packaged NFV solutions are:
For more detailed information, read more on the NFV packaged solutions web page.
F5 Cloud solution templates allow for fast, automated, and dependable BIG-IP Virtual Edition (VE) and BIG-IQ Virtual Edition deployments across various public and private cloud environments.
This release includes expands F5’s Cloud Solution Template portfolio by delivering new templates for AWS, Azure and Google Cloud, while also providing various updates to existing templates. These updates are summarized below:
F5’s cryptographic module has recently been verified as FIPS 140-2 L1 compliant by NIST for BIG-IP Virtual Edition (VE) version 13.1.1 in the following cloud environments:
This validation enables customers in regulated verticals (i.e. Federal agencies and contractors) running v13.1.1 to conform with mandated security controls in the protection of confidential, unclassified information.
For more information on this certification, please review our solution overview or technical documentation provided by F5’s testing lab, ATSEC. Alternatively visit our certification page for a holistic view of F5 FIPS 140-2 compliance.
As part of the new BIG-IP v14.0 release, BIG-IP DNS now provides client subnet support, via EDNS ("Extension Mechanisms for DNS”).
Many authoritative name servers today return responses based on the perceived topological location of the user, this is an issue because most queries today do not have the source address of the client but that of the Intermediate Recursive Resolver leading to inefficient Global Server Load Balancing (GSLB) decisions and higher latency.
The EDNS0 client subnet option helps to convey client information that is relevant to the DNS message i.e. correct information about the source IP address of the client, resulting is in directing the client request to the nearest datacenter leading to better performance and minimum delay.
F5’s BIG-IP DNS now supports edns-client-subnet (ECS) for both responding to client requests (GSLB) or forwarding client requests (screening).
Here is a quick start on using this feature.
The wait is over. The BIG-IQ centralized management 6.0.1 release is now available, and unlocks new features for DNS that help you identify threats and better manage your traffic.
Please review the DNS page and the BIG-IQ page to learn more.
F5 Cloud solution templates allow for fast, automated, and dependable BIG-IP Virtual Edition (VE) deployments across various public and private cloud environments.
All AWS, Azure, Google and VMware templates support BIG-IP v13.1.1. In addition:
For details, see this overview or visit the F5 GitHub repository.
Release 12 release notes for AWS, Azure, Google, and VMware.
Release 13 release notes for AWS, Azure and Google.
F5 improves its integration with the Google Cloud Platform via two new enhancements:
For details, check out the BIG-IP VE listings on the Google Cloud Marketplace.
F5 has supported Bring-Your-Own-License (BYOL) deployments for its government customers on Azure Government for some time now, and today, F5 expands on this integration by announcing Pay-as-You-Go (PAYG) licensing support on the Azure Government Marketplace. Both BIG-IP Virtual Edition as well as the Advanced WAF are now available from the Marketplace, and in the following throughput sizes: 25 Mbps, 200 Mbps an 1 Gbps.
For more information, check out this F5 blog, this Microsoft announcement, or visit the listings directly using the links below:
F5 is pleased to announce the general availability of i5820-DF and i7820-DF, the two new FIPS 140-2 compliant iSeries models, and of the i11800-DS, i11600-DS and i11400-DS, the iSeries variants with Turbo SSL.
FIPS Compliant iSeries Offering Overview
The two new FIPS compliant models are more cost-effective than the previous FIPS appliances with greater SSL TPS and incorporate a FIPS 140-2 Level 3 certified HSM.
Turbo SSL iSeries Offering Overview
The Turbo SSL iSeries platforms offer vCMP, HW Compression and TurboFlex capabilities utilizing quad Crypto Acceleration Chips, with industry-leading Eliptic Curve Cryptography (ECC) performance and better bulk encryption than previous generation BIG-IP platforms.
To find out more, visit the Hardware Page and review the Hardware Datasheet for detailed specifications.
The Cloud Solution templates from F5 allow for fast, automated, and dependable BIG-IP Virtual Edition (VE) deployments across various public and private cloud environments.
This release includes new templates as well as an experimental template for a new environment - Azure Stack. F5 is committed to providing template parity for multi-cloud environments.
This release also includes a refresh of all GitHub repositories to ensure consistent folder and template structure and naming. The new structure helps you find templates more easily.
VMware vCenter Templates
NEW! – Azure Stack ARM Templates
Check out this overview or visit the F5 GitHub repository to learn more.
Verified by both NIST and F5s testing lab, ATSEC, the FIPS 140-2 L1 add-on SKU is now supported for use on both AWS and Azure cloud platforms with BIG-IP VEs running v12.1.2 HF1. This enables customers in regulated industries to conform with mandated security controls such as NIST, HIPAA, PCI and DFARS.
For more information, check out this documentation.
BIG-IQ Centralized Management 6.0 is now shipping. Intended for new BIG-IQ deployments, this solution offers central management and orchestration of F5 devices and the services they provide. Featuring Application Centric Management, BIG-IQ can back-up and restore your devices, update policies, manage certificates and licenses and much more.
This release includes advanced analytics, application specific dashboards, application templates and auto-scaling so that application teams can deploy and manage security and network services for their applications – without being F5 or security experts.
For more information visit the BIG-IQ page on F5.com or download a free trial.
BIG-IP Cloud Edition is now generally available. Combining application delivery, security, and analytics, BIG-IP Cloud Edition offers a dedicated, right-sized, per-app approach to delivering F5 app services in public and private cloud environments.
BIG-IP Cloud Edition is offered as LTM or Advanced WAF per-app virtual editions (VEs) in 25M and 200M instances, together with BIG-IQ centralized management with easy-to-use per-app analytics, simplified self-service catalogs with app templates, and autoscale based on pre-defined thresholds.
Deployments by NetOps and app teams are made easy using a GUI or single declarative API. In addition, BIG-IP Cloud Edition is currently consumable using perpetual and subscription licenses as well as through an ELA.
For more information, read the BIG-IP Cloud Edition overview, and learn more about the advantages of a per-app architecture.
BIG-IP VE 184.108.40.206BIG-IQ 6.0
F5’s Cloud Solution templates allow for fast, automated, and dependable BIG-IP virtual edition (VE) deployments across various public and private cloud environments. This release includes new and updated templates, as well as increased licensing flexibility for AWS and Azure. These updates are summarized below:
BIG-IP Virtual Edition (VE) is now supported in Microsoft Azure Stack. Connect your Azure Stack subscription to your Azure subscription and download BIG-IP VE from the Azure Marketplace. With a bring your own license (BYOL) instance, you can now deploy the full suite of F5 advanced application and security services in both Azure and Azure Stack.
For more information, read more about F5 in Azure Stack, and check out the getting started documentation.
BIG-IP VE 220.127.116.11
F5’s Cloud Solution templates allow for fast, automated, and dependable BIG-IP virtual edition (VE) deployments across various public and private cloud environments. This release includes both new and updated templates, as well as the introduction of experimental templates for a new environment - VMware. These updates are summarized below:
OpenStack Heat Orchestration Templates
NEW! - VMware vCenter Templates
The new BIG-IP Per-App virtual edition (VE) license offers a flexible option at the right price to deploy ADC services per-application. With this ADC for per-app mode, you can now accelerate the application rollout and configuration changes by integrating the ADC policies and configuration in continuous integration / continuous delivery (CI/CD) framework.
LTM and Advanced WAF are available options with this license.
BIG-IP Virtual Edition (VE) supports VMware guest customization at the time of deployment. This is accomplished through a tight integration between open-vm-tools and BIG-IP. This feature allows for a fully automated deployment of a VE. You can specify the management IP, the management gateway, and non-default passwords for the root and admin accounts. To see an example of how to use these properties, see VE on VMware - Part 1 - Custom Properties.
Deployments of the VE to a VMware environment can be completely automated, thanks to the ability to specify the management address and non-default credentials as the time of deployment. Specifically, neither DHCP nor console access are required for the initial management configuration and hardening. You can read about a sample Ansible deployment at VE on VMware - Part 2 - Ansible Deployment.
BIG-IP virtual edition (VE) is now available in the Amazon Web Services Intelligence Community (IC) Marketplace.
You can now pay as you go when you’re using BIG-IP virtual edition (VE) in Google Cloud, without needing a prior license from F5. Read more about BIG-IP VE in Google Cloud.
When you’re done using an instance of BIG-IP VE, you can revoke the license and reuse it on another instance, without having to contact F5 Support.
BIG-IQ Centralized Management and licensing
Use BIG-IQ Centralized Management to manage your BIG-IP licenses. GitHub templates are now available to deploy a BIG-IQ Centralized Management license management instance along with your BIG-IP services.
The BIG-IP iSeries i15000 is designed for large enterprises and service providers. It delivers high-end performance for security and services in a 2 RU form factor. With 300M L4 concurrent connections, the i15000 series consolidates services on a single device, including TCP/IP optimization, traffic steering, Firewall, DDoS, CGNAT, and DNS.
The i15000 offers the highest L4 throughput, supporting 320/160G of L4/L7 throughput and up to 10M L7 RPS. The series has quadruple TurboFlex FPGAs, 2x 14-Core Intel Xeon processors, 1.6TB of available use storage space, and 512GB DDR4 RAM. 4x 100G and 8x 40G fiber ports provide the highest density of high speed ports per rack unit available. See the BIG-IP Platform Datasheet to learn more.
F5’s Cloud Solution templates allow for fast, automated, and dependable BIG-IP virtual edition (VE) deployments across various public and private cloud environments. This release includes new and updated templates, summarized below:
Check out this overview or visit the F5 GitHubrepository to learn more.
F5 Container Connector facilitates real-time control plane integration of BIG-IP services with RedHat OpenShift container orchestration environment. In the latest Open Source Spotlight, you’ll learn how to intelligently shift traffic from one version of a container application to another (blue/green) or enable a comparison-based (A/B) test of an app, so you can make decisions based on data from real visitors. Visit F5 Container Integrations for more benefits of integrating and automating your container app traffic.
BIG-IQ Centralized Management provides a single point of control for F5 physical devices, virtual devices, and solutions. It simplifies management and compliance, so you can deliver applications securely and effectively. This new release includes:
Visit BIG-IQ Centralized Management or contact an F5 sales rep.
Use the iRules Profiler to:
To configure the iRules Profiler, use the tmsh object called rule_profiler. It collects performance metrics and records the execution sequence. You can configure the output from the iRules Profiler to export to an internal source, or to an external source like FlameGraph and CallGraph.
For details, see iRule Execution Tracing and Performance Profiling Part 1, Part 2, and Part 3.
The new BIG-IP iSeries i11600 and i11800 appliances address the needs of large enterprises and service providers seeking high-performance, CPU- and memory-intensive application delivery and security services. The new appliances offer twice the CPU and memory as the existing i10800, which is now comparable to high-end competitive platforms. The i11800 also supports double the number of vCMP instances to consolidate application services as the i10800 appliance.
The new appliances replace the BIG-IP 10350v. They are now available to order and ready to ship. For more information, check out the BIG-IP Platforms Datasheet.
If you have application servers in the cloud, you can use the new Service Discovery iApp to automatically add your app servers to a BIG-IP pool. This iApp is included whenever you use one of the F5 GitHub templates to deploy BIG-IP VE.
Watch a quick demo to see how it works.
BIG-IP VE 18.104.22.168