F5 steps up security

Opinion
Apr 22, 20032 mins

* F5 Networks adds security features to traffic management gear

With more critical business applications going on the Web, protecting those applications becomes as important as making sure they perform well. So it’s not surprising to see Web acceleration vendors continuously adding security features to their gear.

Take F5. F5 sells application traffic management products. It has combined security with traffic management for some time. Last week it stepped up the security capabilities across its Big-IP line of products, and all Big-IP devices will now be able to protect enterprise networks from common types of attacks, such as denial-of-service attacks and SYN floods.

The Big-IP device, which typically sits behind a firewall and in front of your application environment, terminates and inspects each TCP packet to detect rogue requests. That way, it can thwart denial-of-service attacks and SYN floods while still allowing legitimate connections to get through to back-end servers.

Another new security feature that will be available in the Big-IP products is the IETF’s Online Certificate Status Protocol, or OCSP. With OCSP, the Big-IP device can instantly check and validate whether a client should have access to an application or should be denied access. The device connects to an external OCSP responder and checks that the client’s certificate is up to date and valid. If it’s not, the Big-IP device can completely deny access or redirect the user to an acceptable site.

Cindy Borovick, an analyst at IDC, notes that the Big-IP device sits in an ideal place in a network to intercept traffic and analyze it.

The new security features will be available at the end of April at no charge to customers on the F5 software maintenance plan.