tgreene
Executive Editor

F5 mixes SSL VPN with load balancing

Opinion
Nov 3, 20052 mins

* F5 integrates its SSL VPN gear with its load balancing, traffic mgmt. hardware

F5 is integrating its SSL VPN gear with its load-balancing, traffic management hardware to turn the SSL device into a central policy and access enforcement point.

With a new release of software for the equipment, users accessing network resources by any means – wireless, remote access, from the LAN – are authenticated, and the machine they are coming in on is scanned for whether it meets security policies.

If not, the software now can divert users to a remediation site where they can download software to bring their machines into compliance.

This is interesting to businesses that want to make sure every device on a network is properly configured to be secure, even machines that are attached to the LAN. They can use F5’s FirePass SSL box to check every user, avoiding the alternative of maintaining access control lists on switches all over the network.

This new software also enables F5’s Big IP load-balancing/traffic management device to front end multiple FirePass SSL VPN devices. This means that Big IP can terminate the SSL sessions authorized by the FirePass device, leaving the FirePass device to apply authentication, and to scan and maintain policies. It also means that by adding more and more FirePass devices to a configuration and adding more Big IPs as necessary, businesses can scale to very large remote access VPNs. While offloading SSL termination to Big IP saves processing cycles on the FirePass devices, F5 is making no claims about the configuration improving the capacity of the FirePasses.

This is F5’s version of controlling network access to maintain security and may be interesting to current F5 customers in particular as well as to very large organizations interested in creating the largest SSL VPN networks.