Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

OPSEC Partners

BIG-IP

Product Version Certified: BigIP 4.5.10
Certified for use with: Check Point NG AI R55

 
Product Description:  BIG-IP optimizes web services and applications by intercepting, inspecting, transforming, and directing the traffic. It continuously monitors each server for service and application availability/performance, and routes incoming queries to the most available server. BIG-IP allows network managers to use a variety of sophisticated load-balancing algorithms to fine-tune performance and availability.
     
Key Features and Benefits
OPSEC Integration
  f5 Networks
 
Company Description: Over the next 4 years, the complexity of Internet service delivery will continue to grow. This is due to an increasing number of Internet users, increased broadband usage, a higher number of Web sites using sophisticated business applications, and the richness of Internet/Web content itself.Intelligent and automated control of time sensitive content and traffic between the origin sites and network edge is critical for ensuring the high level of service that customers demand. F5 Networks simplifies and optimizes this complex networked environment for business, enabling organizations to control, access and use the Internet to their full advantage.F5 Networks provides integrated products and services to manage, control and optimize Internet traffic and content. Our solutions deliver the best possible Internet performance, availability and content distribution to enable our customers and partners to maximize the use of the Internet in their business.Founded in 1996, F5 has grown to more than 500 employees and boasts an impressive list of more than 3500 of the top corporations.
   
Key Features and Benefits

Intercept
In order to add value to traffic flows, the ITM device first must intercept the traffic. This first requires the ITM device to be outfitted with an appropriate port count and connectivity to fit into the existing network topology. As traffic flows through the device, it must be intercepted in order for it to be inspected, transformed, and directed.Interception usually takes two forms: simple and delayed binding. Simple interception allows the simple inspection and traffic transformations usually associated with Layer 4 load balancing. Delayed binding allows advanced, deep inspection to determine the type of transformation and direction required.

Inspect: Requires Processing Power and SSL
Once the traffic is intercepted, the device must then inspect the traffic in order to determine exactly what it is, and how it should be treated. This is where processing power becomes very important. Simple inspection may include evaluating traffic based on Layer 4 criteria, such as IP and port information. Most businesses, however, are demanding that their ITM device be capable of inspecting their traffic at a level deeper than Layer 4 and beyond basic URL-based traffic inspection. Initially, the market demanded that ITM devices be able to inspect the full http header in order to make traffic management decisions on cookies or other information contained therein.

Most recently, however, demand has shifted again, requiring that the ITM device be able to inspect any portion of the data field or payload within IP packets to make traffic management decisions and effectively manage applications delivered over Internet technologies.In order to effectively inspect traffic, the ITM device must be able to apply all of its processing capabilities to the traffic flowing through the device; this is where the decision must be made. Furthermore, the ITM device must be able to apply a high degree of processing power in order to provide the level of inspection required on the actual payloads of packets - then make traffic management decisions based on the results, and the customized business rules that an organization has.

Secure Socket Layer
Additionally, SSL or encrypted traffic poses a special challenge during the inspection step, as the ITM device is blind to what the encrypted traffic really is. In order for the ITM device to inspect and make decisions on SSL traffic, the device must also be able to act as a termination point for the encrypted traffic and un-encrypt it ("bring it into the clear") in order to perform the inspection task. Since most businesses are securing an increasing amount of their traffic and applications using SSL, it is imperative that the ITM device include this functionality and be able to perform this task.

Transform: Requires Intelligence
Once the traffic has been inspected, the ITM device must then perform any necessary transformations on the traffic. Transformations can include simple things such as changing the destination IP addresses and port addresses in order to get the traffic to the desired asset being load balanced. Transformations can also be more advanced, such as re-encrypting traffic using SSL so traffic sent to the servers is protected, re-writing URL values for things like Akamaization (changing content without manually re-writing code), or inserting cookies into HTTP headers for persistence so applications avoid time-consuming alterations.

Direct: Requires Intelligence
Finally, the ITM device must direct traffic to one of the assets being load balanced. The decision of where to direct traffic is based on availability and responsiveness of the assets, and advanced business rules for the traffic.

BIG-IP is an adaptive solution that can evolve with the demands placed on today's web services and applications for the enterprise, hosted, and wireless carrier provider networks, saving both entities considerable time and money, and opening new revenue opportunities.

OPSEC Integration
F5's BIG-IP provides superior high availability load balancing, administration, management, security, and extensibility for Check Point VPN-1/FireWall-1 deployments utilizing their state synchronization capabilities. BIG-IP also provides the ability to log events to a Check Point management station utilizing Check Point's OPSEC ELA API. BIG-IP's unmatched intelligence provides assurance that all business-critical traffic is properly distributed across the available resources and guarantees the delivery to the intended destination. The extensive BIG-IP feature set allows for flexible deployment scenarios that easily accommodate infrastructure modifications as business requirements dictate, without costly disruptions.