Forum Discussion

unload_132170's avatar
unload_132170
Icon for Nimbostratus rankNimbostratus
Aug 23, 2013

F5 AFM/ASM Firewall

What has been the groups experience with the F5 firewall vs other vendors like Checkpoint/Cisco/Juniper etc?

 

Have security teams really accepted this as a valid option for a secure high performance stateful firewall? Or is this being adopted quite slowly with the majority of the users still relying on a proven solution in front of the BIGIP? The performance numbers seem impressive with emulation testing but what has the real world seen? Our application team brought this up so we wanted to see how may have actually used this is the front line in a high performance secure network.

 

Thanks!

 

4 Replies

  • Our experience has been great. We're an ecommerce hosting provider with our own AS. We were looking to scale up to 20G and far beyond while having some ddos protection. AFM/ASM filled that role better than any of the dedicated ddos equipment, traditional firewalls, or next-gen firewall providers could.

     

    We currently have over 2,000 dedicated servers behind a ha pair of viprions on 11.3 and they're running great. We've pushed them up, and over, their stated new connections a second easily. Just make sure you set connections per second and max connections on your virtual servers. Otherwise they will try to process everything and overwhelm the cpu; resulting in lot's of connections being reaped. The reaper is what keeps them from falling over like traditional firewalls do when session state tables fill.

     

    Overall they're amazing devices and perform as stated. They are layer 7 proxies with high performance hardware. You can tune and inspect everything imaginable. It's overwhelming at times but the support people have been really helpful with it.

     

    They are ICSA Labs certified firewalls and are doing quite well in all the vendor tests being run (see the latest networkworld release on the f5 homepage).

     

    We're going to be doing a video recording of our case study for f5, in several weeks, about our experience. So if you have any specific questions, feel free to ask, and I'll answer them as best I can.

     

    • Wahezu_23937's avatar
      Wahezu_23937
      Icon for Nimbostratus rankNimbostratus
      Hi Cheezus, We are in the process of building a similar network but we don't know whether we should use the AFM as perimiter firewall and add second layer of firewall (CIsco or Juniper) down in the path for security. Normally, for security reasons, you put a perimeter Firewall and an Internal Firewall. How did you end up configuring that network? Thanks, Wahezu.
  • just remember can't be compared to a firewall as checkpoint / juniper / cisco for outgoing traffic. it is meant as an incomming firewall for your data center, that is the main goal.

     

  • Mike_Schrock_61's avatar
    Mike_Schrock_61
    Historic F5 Account

    I can understand the skepticism and concern by original post on F5's ability of doing stateful inspection at wire-speeds as they are often perceived as just an ADC or Load balancer appliance. However the F5 platform was designed and has delivered as network fabric a full proxy architecture since 2004. So, stateful, in fact even "full state" performance is not an issue for F5. TMOS is it's strong suit moving forward in security architectures as the security service simplification and consolidation is occurring rapidly at this real estate position. F5 is even wirespeed in our WAF product ASM, where most peers are not deployed inline as they fail to be as fast as stateful Firewalls and the F5 WAF.

     

    Equally impressive is what F5 is doing in Carriers with application classification with PEM.

     

    For more AFM proof and customers Here is how Interop used us as FW

     

    Video of same

     

    Here are other customers talking about it.