SlideShare a Scribd company logo
F5Solutions
Locations:
• Azure has regions around the world.
Availability Sets:
• Azure provides the redundancy option for VMs by isolating them
in different fault and update domains.
Virtual Networks (VNETs)
• Logically isolated network. You can create subnets, route tables.
Subnets: Fixed address blocked within a VNET (ex. 10.0.1.0/24 )
User Defined Routes (UDRs): Route table for next hop
Network Security Groups (NSGs): network firewall rules used to
secure resources
Azure Resource Manager Templates: Used to orchestrate
resources and deliver services in Azure
VNET Connectivity:
• On Prem to VNET
• Two methods.
1. VPN Gateway
2. ExpressRoute™ – secure dedicated connection
• VNET to VNET
F5 available as a drop down option to connect
to your remote BIG -IP
© 2016 F5 Networks, Inc 4
https://blog.kloud.com.au/2016/04/05/azure-classic-vs-azure-resource-manager/
https://azure.microsoft.com/en-us/documentation/articles/resource-manager-deployment-model/
•ARM Templates: Can be used ONLY in ARM mode.
Networking
•
Topology
•
•
•
•
Capacity Planning
•
•
Azure F5 Solutions
• 1 NIC for Management and External
• Change configuration utility port 443 => 8443
• Use a Transparent/forward virtual server per
service port.
• Separation of traffic via iRule, SNI or traffic
policy.
• Networking objects (vNIC 1.0, an internal
VLAN, and an internal self IP address) are
created automatically for you.
• Supports One-Armed and DSR mode.
• Supports one-armed, two armed and DSR mode use
cases.
• Still only one public IP address available
• Change BIG-IP configuration utility port 443 => 8443
• You can’t use BIG-IP GUI to create this configuration.
- An Azure template
- PowerShell
- The Azure command-line interface (CLI)
• Supported in version 12.0 HF1 and later
•
•
•
•
Azure F5 Solutions
Public Cloud - Shared Responsibility Security Model
CP Global
Infrastructure
Data Centers
Zones
Regions
Edge
Locations
Networking Services
Compute Database Storage
Deployment & Management
Client-Side Data
Encryption & Data
Integrity Authentication
Server-Side Encryption
(File System and/or
Data)
Network Traffic
Protection (Encryption,
Integrity, Identity)
Operating System, Network and Firewall
Configuration
Platform, Applications, Identity & Access
Management
Customer Data Customer’s responsibility
• Protecting the
confidentiality, integrity,
and availability of their
data in the cloud
• OS and
application-level security
Cloud Provider responsibility
• Providing a global secure
infrastructure and services
PhysicaltoHypervisorOSandApplication
CloudProviderCustomer
Preconfigured WAF with Azure Security Center
Product : F5 Web Application Firewall (WAF) Solution
• Simple deployment experience integrated
with Azure workflow and services
• Out-of-the-box choice of security settings
preconfigured by F5 experts
• Comprehensive application security and
compliance with advanced Layer 7 attack
protections
• Consistent policy management and user
experience across Cloud and Datacenter
apps
• Integration with Azure dashboard and alerts
/ visualization services
F5 WAF Solution Integrated With
Azure Security Center (ASC)
Use Case Example
F5 provides ARM template to configure Preconfigure WAF outside of Azure Security Center to support broader customer needs.
WAF
• Strengthens security posture by enabling
device checks, multifactor authentication, up-
leveling authentication and AD & AAD
Integration
• Consolidates & centralizes security when
offering hybrid services across cloud and on-
prem datacenters
• Streamlines access by providing federation &
single sign on across all SAML/OAuth enabled
on-prem, O365, Azure, and SAAS apps
• Reduces configuration complexity
simplified deployment using Azure Solution
Template
• Enables migration with context aware, user &
device based traffic redirection
Office 365 Identity Federation & Single Sign On
Product : F5 BIG-IP Best (BIG-IP Access Policy Manager)
Azure
Private Cloud
Unauthorized
User
Authorized
Users
Use Case Example
BIG-IP
SSO
AD
SAML FEDERATIONSAML IDP SAML SP
App A App B
Employee Contractor/Partner
SSL-VPN
On premises
BIG-IP
• Back Ground
• Need secure access (SSL-VPN) to Azure for
employees, contractors and partners.
• Integration with existing identity
infrastructure
• Solution
• Secure access by enabling SAML for all
the apps in Azure.
• Federate ID with existing AD and SAML IDP
• Endpoint security check and SSL VPN
enables secure remote access to Azure
• Increase high availability by deploying F5
into multiple Azure regions
SSL VPN and secure access to Azure
Product : F5 BIG-IP Best (BIG-IP Access Policy Manager)
Use Case Example
Azure
SSL-VPN
SQL
Backend
Active
Directory
End Users
Internet
ACTIVE
BIG-IP
STANDBY
BIG-IP
Use Case 1: Cloud Deployment with Single Sign On and Firewall
Pre-authentication Traffic
Backend Data Communication
Load Balancing + App Delivery + SSLLTM
Access ManagementAPM
Web Application FirewallingASM
• Secure, policy driven single sign-on Access Management
• Web application security, firewalling and DDOS protection
• Stateful Layer 4-7 load balancing, SSL offloading and application delivery
Firewalling + DDoS protectionAFM
LTMAFM APM ASM
• Consistent settings and policies on prem and off
• Single-Sign-On for both on prem and cloud based apps
• Web-Application Firewall where-ever your app resides
Azure Virtual Net On-Premise Net
S2S VPN
IPsec
Pre-authentication Traffic
Backend Data Communication
ACTIVE
BIG-IP
STANDBY
BIG-IP
SQL
Backend
On Premise DC
Active
Directory
BIG-IP
Platform
Use Case 2: Hybrid Cloud with site to site VPN
Internet
End Users
LTMAFM APM ASM
Load Balancing + App Delivery + SSLLTM
Access ManagementAPM
Web Application FirewallingASM
Firewalling + DDoS protectionAFM
WEST US EAST US
Authentication Traffic
GSLB
Use Case 3: Hybrid Cloud with GSLB and SAML
• Delivers Business Continuity
• Users get the best possible QoE
because the service comes from the
closest available source
Internet
End Users
Load Balancing + App Delivery + SSLLTM
Identity Access ManagementAPM
Web Application FirewallingASM
Business Continuity + DNSGTM
Azure F5 Solutions
•
•
•
•
•
•
•
Azure F5 Solutions
•
•
•
•
•
•
Azure F5 Solutions
OFFERING
• Certified Images in marketplace and on
downloads.f5.com
• All BIG-IP Modules (GBB and standalone) in
Classic and ARM
• Performance: 25M, 200M, 1G BYOL and Utility
• Single and Multi NIC deployments
• Available in Azure Government Marketplace
• Available 30 day evaluation and lab licenses
• WAF offering in Azure Security Center
© 2016 F5 Networks, Inc 24
Parameters BYOL (1)(2) Utility
Presence Currently Available Releasing Dec. 2016 as 12.1.2
• Commercial Y (3) (4) Y (4)
• Government Y (5)
Max throughput SKU 1 Gbps 1 Gbps
Modules Stand alone and GBB GBB
downloads.f5.com
12.0.0HF4, 12.1.0 HF2, 12.1.1 HF1
NOTES
•
•
•
•
•
•
•
•
•
Available in
January 2017
•
• https://github.com/F5Networks/
• https://github.com/f5devcentral/
•
•
• https://github.com/F5Networks/f5-azure-arm-templates
•
Azure F5 Solutions

More Related Content

PDF
Succeeding with Secure Access Service Edge (SASE)
Cloudflare
 
PPTX
Azure WAF
Cheah Eng Soon
 
PDF
Fortinet security fabric
ANSItunCERT
 
PDF
F5 TLS & SSL Practices
Brian A. McHenry
 
PDF
SDWAN.pdf
sushil kumar
 
PDF
Microsoft Zero Trust
David J Rosenthal
 
PDF
Understanding SASE
Haris Chughtai
 
PDF
Introduction to Azure IaaS
Robert Crane
 
Succeeding with Secure Access Service Edge (SASE)
Cloudflare
 
Azure WAF
Cheah Eng Soon
 
Fortinet security fabric
ANSItunCERT
 
F5 TLS & SSL Practices
Brian A. McHenry
 
SDWAN.pdf
sushil kumar
 
Microsoft Zero Trust
David J Rosenthal
 
Understanding SASE
Haris Chughtai
 
Introduction to Azure IaaS
Robert Crane
 

What's hot (20)

PPTX
Fortinet
ABEP123
 
PPTX
From Cisco ACS to ISE
Mahzad Zahedi
 
PPTX
Transform your enterprise branch with secure sd-wan
DATA SECURITY SOLUTIONS
 
PDF
Secure Access – Anywhere by Prisma, PaloAlto
Prime Infoserv
 
PDF
IoT & Azure (EventHub)
Mirco Vanini
 
PPTX
F5 - BigIP ASM introduction
Jimmy Saigon
 
PPTX
Monitor Cloud Resources using Alerts & Insights
Synergetics Learning and Cloud Consulting
 
PPTX
Multi cloud security architecture
Maganathin Veeraragaloo
 
PDF
Meraki Overview
Cloud Distribution
 
PPTX
Azure virtual network
Lalit Rawat
 
PDF
Cloud Native Application
VMUG IT
 
PPTX
Microsoft Azure Technical Overview
gjuljo
 
PPTX
Service-mesh options with Linkerd, Consul, Istio and AWS AppMesh
Christian Posta
 
PPTX
Cisco Identity Services Engine (ISE)
Anwesh Dixit
 
PPTX
Azure Network Security Groups (NSG)
Shawn Ismail
 
PDF
Thingsboard IoT Platform - A Quick Tour
TechYugadi IT Solutions & Consulting
 
PDF
Réussir son projet de sécurisation des Identités en 5 commandements (parce qu...
Identity Days
 
PDF
F5 Web Application Security
MarketingArrowECS_CZ
 
PPTX
48. Azure Active Directory - Part 1
Shawn Ismail
 
PDF
Cloud computing Azure
vivek p s
 
Fortinet
ABEP123
 
From Cisco ACS to ISE
Mahzad Zahedi
 
Transform your enterprise branch with secure sd-wan
DATA SECURITY SOLUTIONS
 
Secure Access – Anywhere by Prisma, PaloAlto
Prime Infoserv
 
IoT & Azure (EventHub)
Mirco Vanini
 
F5 - BigIP ASM introduction
Jimmy Saigon
 
Monitor Cloud Resources using Alerts & Insights
Synergetics Learning and Cloud Consulting
 
Multi cloud security architecture
Maganathin Veeraragaloo
 
Meraki Overview
Cloud Distribution
 
Azure virtual network
Lalit Rawat
 
Cloud Native Application
VMUG IT
 
Microsoft Azure Technical Overview
gjuljo
 
Service-mesh options with Linkerd, Consul, Istio and AWS AppMesh
Christian Posta
 
Cisco Identity Services Engine (ISE)
Anwesh Dixit
 
Azure Network Security Groups (NSG)
Shawn Ismail
 
Thingsboard IoT Platform - A Quick Tour
TechYugadi IT Solutions & Consulting
 
Réussir son projet de sécurisation des Identités en 5 commandements (parce qu...
Identity Days
 
F5 Web Application Security
MarketingArrowECS_CZ
 
48. Azure Active Directory - Part 1
Shawn Ismail
 
Cloud computing Azure
vivek p s
 
Ad

Similar to Azure F5 Solutions (20)

PDF
Hybridní cloud s F5 v prostředí kontejnerů
MarketingArrowECS_CZ
 
PPTX
VMworld 2015: No App is An Island
VMworld
 
PPTX
Self service it with v realizeautomation and nsx
solarisyougood
 
PPTX
CCI2018 - Azure Network - Security Best Practices
walk2talk srl
 
PPTX
Securing your cloud perimeter with azure network security brk3185
jtaylor707
 
PDF
在小學有效運用雲端電腦以促進電子學習(第一節筆記)
Tsz Wing Chu
 
PDF
Гибридное облако - эффективность в квадрате
ActiveCloud
 
PDF
Presentation v mware virtualization & cloud vision 2010
solarisyourep
 
PDF
Business Agility and Security with VMware
Angel Villar Garea
 
PPTX
CCI2019 - Architecting and Implementing Azure Networking
walk2talk srl
 
PDF
Global Azure Bootcamp 2018 - Azure Network Security
Scott Hoag
 
PPTX
DEVNET-1009 Cisco Intercloud Fabric for Business (ICFB), Helping Enterprises...
Cisco DevNet
 
PPTX
Deploying couchbaseserverazure cihanbiyikoglu_microsoft
Cihan Biyikoglu
 
PPTX
Nutanix_Cloud_Platformportfolio_offerings.pptx
kiton11726
 
PDF
엔터프라이즈를 위한 하이브리드 클라우드 및 보안 관리
Amazon Web Services Korea
 
PDF
Simplifier le deploiement d'applications dans le nuage hybride
Cisco Canada
 
PPT
Cloud computing
gd1410
 
PDF
Microsoft Azure Security Overview
Alert Logic
 
PPTX
Microsoft Azure News - Oct 2016
Daniel Toomey
 
PDF
Presentation vmware building “your cloud”
solarisyourep
 
Hybridní cloud s F5 v prostředí kontejnerů
MarketingArrowECS_CZ
 
VMworld 2015: No App is An Island
VMworld
 
Self service it with v realizeautomation and nsx
solarisyougood
 
CCI2018 - Azure Network - Security Best Practices
walk2talk srl
 
Securing your cloud perimeter with azure network security brk3185
jtaylor707
 
在小學有效運用雲端電腦以促進電子學習(第一節筆記)
Tsz Wing Chu
 
Гибридное облако - эффективность в квадрате
ActiveCloud
 
Presentation v mware virtualization & cloud vision 2010
solarisyourep
 
Business Agility and Security with VMware
Angel Villar Garea
 
CCI2019 - Architecting and Implementing Azure Networking
walk2talk srl
 
Global Azure Bootcamp 2018 - Azure Network Security
Scott Hoag
 
DEVNET-1009 Cisco Intercloud Fabric for Business (ICFB), Helping Enterprises...
Cisco DevNet
 
Deploying couchbaseserverazure cihanbiyikoglu_microsoft
Cihan Biyikoglu
 
Nutanix_Cloud_Platformportfolio_offerings.pptx
kiton11726
 
엔터프라이즈를 위한 하이브리드 클라우드 및 보안 관리
Amazon Web Services Korea
 
Simplifier le deploiement d'applications dans le nuage hybride
Cisco Canada
 
Cloud computing
gd1410
 
Microsoft Azure Security Overview
Alert Logic
 
Microsoft Azure News - Oct 2016
Daniel Toomey
 
Presentation vmware building “your cloud”
solarisyourep
 
Ad

More from MarketingArrowECS_CZ (20)

PDF
INFINIDAT InfiniGuard - 20220330.pdf
MarketingArrowECS_CZ
 
PDF
Využijte svou Oracle databázi na maximum!
MarketingArrowECS_CZ
 
PDF
Jak konsolidovat Vaše databáze s využitím Cloud služeb?
MarketingArrowECS_CZ
 
PDF
Chráníte správně svoje data?
MarketingArrowECS_CZ
 
PDF
Oracle databáze – Konsolidovaná Data Management Platforma
MarketingArrowECS_CZ
 
PDF
Nové vlastnosti Oracle Database Appliance
MarketingArrowECS_CZ
 
PDF
Infinidat InfiniGuard
MarketingArrowECS_CZ
 
PDF
Infinidat InfiniBox
MarketingArrowECS_CZ
 
PDF
Novinky ve světě Oracle DB a koncept konvergované databáze
MarketingArrowECS_CZ
 
PDF
Základy licencování Oracle software
MarketingArrowECS_CZ
 
PDF
Garance 100% dostupnosti dat! Kdo z vás to má?
MarketingArrowECS_CZ
 
PDF
Využijte svou Oracle databázi naplno
MarketingArrowECS_CZ
 
PDF
Oracle Data Protection - 2. část
MarketingArrowECS_CZ
 
PDF
Oracle Data Protection - 1. část
MarketingArrowECS_CZ
 
PDF
Benefity Oracle Cloudu (4/4): Storage
MarketingArrowECS_CZ
 
PDF
Benefity Oracle Cloudu (3/4): Compute
MarketingArrowECS_CZ
 
PDF
InfiniBox z pohledu zákazníka
MarketingArrowECS_CZ
 
PDF
Exadata z pohledu zákazníka a novinky generace X8M - 2. část
MarketingArrowECS_CZ
 
PDF
Exadata z pohledu zákazníka a novinky generace X8M - 1. část
MarketingArrowECS_CZ
 
PDF
Úvod do Oracle Cloud infrastruktury
MarketingArrowECS_CZ
 
INFINIDAT InfiniGuard - 20220330.pdf
MarketingArrowECS_CZ
 
Využijte svou Oracle databázi na maximum!
MarketingArrowECS_CZ
 
Jak konsolidovat Vaše databáze s využitím Cloud služeb?
MarketingArrowECS_CZ
 
Chráníte správně svoje data?
MarketingArrowECS_CZ
 
Oracle databáze – Konsolidovaná Data Management Platforma
MarketingArrowECS_CZ
 
Nové vlastnosti Oracle Database Appliance
MarketingArrowECS_CZ
 
Infinidat InfiniGuard
MarketingArrowECS_CZ
 
Infinidat InfiniBox
MarketingArrowECS_CZ
 
Novinky ve světě Oracle DB a koncept konvergované databáze
MarketingArrowECS_CZ
 
Základy licencování Oracle software
MarketingArrowECS_CZ
 
Garance 100% dostupnosti dat! Kdo z vás to má?
MarketingArrowECS_CZ
 
Využijte svou Oracle databázi naplno
MarketingArrowECS_CZ
 
Oracle Data Protection - 2. část
MarketingArrowECS_CZ
 
Oracle Data Protection - 1. část
MarketingArrowECS_CZ
 
Benefity Oracle Cloudu (4/4): Storage
MarketingArrowECS_CZ
 
Benefity Oracle Cloudu (3/4): Compute
MarketingArrowECS_CZ
 
InfiniBox z pohledu zákazníka
MarketingArrowECS_CZ
 
Exadata z pohledu zákazníka a novinky generace X8M - 2. část
MarketingArrowECS_CZ
 
Exadata z pohledu zákazníka a novinky generace X8M - 1. část
MarketingArrowECS_CZ
 
Úvod do Oracle Cloud infrastruktury
MarketingArrowECS_CZ
 

Recently uploaded (20)

PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PDF
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
PPTX
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
PDF
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
PPTX
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
PDF
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PDF
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PDF
Software Development Methodologies in 2025
KodekX
 
PDF
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
PDF
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
PDF
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
PDF
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
PPTX
Simple and concise overview about Quantum computing..pptx
mughal641
 
PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
Agile Chennai 18-19 July 2025 Ideathon | AI Powered Microfinance Literacy Gui...
AgileNetwork
 
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
Software Development Methodologies in 2025
KodekX
 
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
Data_Analytics_vs_Data_Science_vs_BI_by_CA_Suvidha_Chaplot.pdf
CA Suvidha Chaplot
 
Economic Impact of Data Centres to the Malaysian Economy
flintglobalapac
 
SparkLabs Primer on Artificial Intelligence 2025
SparkLabs Group
 
Simple and concise overview about Quantum computing..pptx
mughal641
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 

Azure F5 Solutions

  • 2. Locations: • Azure has regions around the world. Availability Sets: • Azure provides the redundancy option for VMs by isolating them in different fault and update domains. Virtual Networks (VNETs) • Logically isolated network. You can create subnets, route tables. Subnets: Fixed address blocked within a VNET (ex. 10.0.1.0/24 ) User Defined Routes (UDRs): Route table for next hop Network Security Groups (NSGs): network firewall rules used to secure resources Azure Resource Manager Templates: Used to orchestrate resources and deliver services in Azure
  • 3. VNET Connectivity: • On Prem to VNET • Two methods. 1. VPN Gateway 2. ExpressRoute™ – secure dedicated connection • VNET to VNET F5 available as a drop down option to connect to your remote BIG -IP
  • 4. © 2016 F5 Networks, Inc 4 https://blog.kloud.com.au/2016/04/05/azure-classic-vs-azure-resource-manager/ https://azure.microsoft.com/en-us/documentation/articles/resource-manager-deployment-model/ •ARM Templates: Can be used ONLY in ARM mode.
  • 7. • 1 NIC for Management and External • Change configuration utility port 443 => 8443 • Use a Transparent/forward virtual server per service port. • Separation of traffic via iRule, SNI or traffic policy. • Networking objects (vNIC 1.0, an internal VLAN, and an internal self IP address) are created automatically for you. • Supports One-Armed and DSR mode.
  • 8. • Supports one-armed, two armed and DSR mode use cases. • Still only one public IP address available • Change BIG-IP configuration utility port 443 => 8443 • You can’t use BIG-IP GUI to create this configuration. - An Azure template - PowerShell - The Azure command-line interface (CLI) • Supported in version 12.0 HF1 and later
  • 11. Public Cloud - Shared Responsibility Security Model CP Global Infrastructure Data Centers Zones Regions Edge Locations Networking Services Compute Database Storage Deployment & Management Client-Side Data Encryption & Data Integrity Authentication Server-Side Encryption (File System and/or Data) Network Traffic Protection (Encryption, Integrity, Identity) Operating System, Network and Firewall Configuration Platform, Applications, Identity & Access Management Customer Data Customer’s responsibility • Protecting the confidentiality, integrity, and availability of their data in the cloud • OS and application-level security Cloud Provider responsibility • Providing a global secure infrastructure and services PhysicaltoHypervisorOSandApplication CloudProviderCustomer
  • 12. Preconfigured WAF with Azure Security Center Product : F5 Web Application Firewall (WAF) Solution • Simple deployment experience integrated with Azure workflow and services • Out-of-the-box choice of security settings preconfigured by F5 experts • Comprehensive application security and compliance with advanced Layer 7 attack protections • Consistent policy management and user experience across Cloud and Datacenter apps • Integration with Azure dashboard and alerts / visualization services F5 WAF Solution Integrated With Azure Security Center (ASC) Use Case Example F5 provides ARM template to configure Preconfigure WAF outside of Azure Security Center to support broader customer needs. WAF
  • 13. • Strengthens security posture by enabling device checks, multifactor authentication, up- leveling authentication and AD & AAD Integration • Consolidates & centralizes security when offering hybrid services across cloud and on- prem datacenters • Streamlines access by providing federation & single sign on across all SAML/OAuth enabled on-prem, O365, Azure, and SAAS apps • Reduces configuration complexity simplified deployment using Azure Solution Template • Enables migration with context aware, user & device based traffic redirection Office 365 Identity Federation & Single Sign On Product : F5 BIG-IP Best (BIG-IP Access Policy Manager) Azure Private Cloud Unauthorized User Authorized Users Use Case Example BIG-IP SSO
  • 14. AD SAML FEDERATIONSAML IDP SAML SP App A App B Employee Contractor/Partner SSL-VPN On premises BIG-IP • Back Ground • Need secure access (SSL-VPN) to Azure for employees, contractors and partners. • Integration with existing identity infrastructure • Solution • Secure access by enabling SAML for all the apps in Azure. • Federate ID with existing AD and SAML IDP • Endpoint security check and SSL VPN enables secure remote access to Azure • Increase high availability by deploying F5 into multiple Azure regions SSL VPN and secure access to Azure Product : F5 BIG-IP Best (BIG-IP Access Policy Manager) Use Case Example Azure SSL-VPN
  • 15. SQL Backend Active Directory End Users Internet ACTIVE BIG-IP STANDBY BIG-IP Use Case 1: Cloud Deployment with Single Sign On and Firewall Pre-authentication Traffic Backend Data Communication Load Balancing + App Delivery + SSLLTM Access ManagementAPM Web Application FirewallingASM • Secure, policy driven single sign-on Access Management • Web application security, firewalling and DDOS protection • Stateful Layer 4-7 load balancing, SSL offloading and application delivery Firewalling + DDoS protectionAFM LTMAFM APM ASM
  • 16. • Consistent settings and policies on prem and off • Single-Sign-On for both on prem and cloud based apps • Web-Application Firewall where-ever your app resides Azure Virtual Net On-Premise Net S2S VPN IPsec Pre-authentication Traffic Backend Data Communication ACTIVE BIG-IP STANDBY BIG-IP SQL Backend On Premise DC Active Directory BIG-IP Platform Use Case 2: Hybrid Cloud with site to site VPN Internet End Users LTMAFM APM ASM Load Balancing + App Delivery + SSLLTM Access ManagementAPM Web Application FirewallingASM Firewalling + DDoS protectionAFM
  • 17. WEST US EAST US Authentication Traffic GSLB Use Case 3: Hybrid Cloud with GSLB and SAML • Delivers Business Continuity • Users get the best possible QoE because the service comes from the closest available source Internet End Users Load Balancing + App Delivery + SSLLTM Identity Access ManagementAPM Web Application FirewallingASM Business Continuity + DNSGTM
  • 23. OFFERING • Certified Images in marketplace and on downloads.f5.com • All BIG-IP Modules (GBB and standalone) in Classic and ARM • Performance: 25M, 200M, 1G BYOL and Utility • Single and Multi NIC deployments • Available in Azure Government Marketplace • Available 30 day evaluation and lab licenses • WAF offering in Azure Security Center
  • 24. © 2016 F5 Networks, Inc 24 Parameters BYOL (1)(2) Utility Presence Currently Available Releasing Dec. 2016 as 12.1.2 • Commercial Y (3) (4) Y (4) • Government Y (5) Max throughput SKU 1 Gbps 1 Gbps Modules Stand alone and GBB GBB downloads.f5.com 12.0.0HF4, 12.1.0 HF2, 12.1.1 HF1 NOTES