Talk to us
by F5TechBag Intel Page

F5 BIG-IP Zero Trust Access

Your apps already sit behind BIG-IP. Remote access shouldn’t open the whole network — F5 BIG-IP Zero Trust Access, the former BIG-IP APM, puts an identity-aware proxy, Per-App VPN and IPsec VPN on BIG-IP you run yourself, federating SAML, OAuth and OIDC with your identity provider.

Identity-aware proxy on BIG-IPSessions end on your own hardwareQuote-only, as BIG-IP software

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
f5.com prints no Zero Trust Access price; it is quoted with the BIG-IP platform it runs on
Quote
Scale
F5’s ceiling for one BIG-IP device; a single VIPRION chassis is rated for up to 2M
1M sessions
Analysts
No current analyst placement for this product appears in F5’s own listings, so none is claimed
Not ranked
India
Access sessions terminate wherever you install BIG-IP; F5 runs no access PoP for this module
Your site

Quick answer

F5 BIG-IP Zero Trust Access, formerly BIG-IP Access Policy Manager (APM), is a BIG-IP module that puts an identity-aware proxy, Per-App VPN and IPsec VPN in front of your applications and federates SAML, OAuth and OIDC. It runs on BIG-IP hardware or a Virtual Edition you host — up to 1M sessions per device — so sessions end in your own Indian data centre. F5 publishes no price, and patching is yours. Read more ↓ Show less ↑
Part 01 · Orient

The F5 platform family

This page covers F5 BIG-IP Zero Trust Access — the BIG-IP access module, formerly APM. The rest:

Quick facts

30-second orientation
Product
Identity-aware proxy, Per-App VPN and IPsec VPN on BIG-IP; formerly BIG-IP Access Policy Manager (APM)
Maker
F5; Chairman, President and CEO François Locoh-Donou; revenue of $865M in the quarter to June 2026
Price
Not published; quoted as BIG-IP software, perpetual, subscription, marketplace or Flex Consumption
Runs on
BIG-IP hardware, a VIPRION chassis or a Virtual Edition, cloud marketplace images included; no F5-hosted PoP
Scale
Up to 1M access sessions on one BIG-IP device and 2M on a single VIPRION chassis, by F5’s figures
Identity
SAML, OAuth, OIDC and Azure AD Conditional Access; RADIUS, AD, LDAP, TACACS+, Kerberos, SecurID
Posture
MDM signals from VMware Workspace ONE, Microsoft Intune and IBM MaaS360, named on F5’s product page
Security
Exploited critical flaws in 2026: CVE-2025-53521, and CVE-2026-94127 in OAuth Authorization Server setups
India
Self-hosted, so sessions end on your own Indian hardware; F5’s Hyderabad R&D centre opened in May 2019
In India via
TechBag — apps sorted by protocol, BIG-IP sizing, quote in INR with GST
Part 02 · Learn

Understand zero trust access before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is an identity-aware proxy?

A proxy in front of each app checks who you are and what device you use on every request, instead of opening a network.

A VPN onto the whole network vs per-request access on BIG-IP — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionA VPN onto the whole networkF5 BIG-IP Zero Trust Access
What a remote user can reachThe whole subnet behind the VPNOne app at a time, judged per request
Sign-in standardsEach app wired to its own directorySAML, OAuth, OIDC, Kerberos and RADIUS on one gateway
Device healthAssumed once the password worksWorkspace ONE, Intune or MaaS360 verdicts in policy
Where sessions endA VPN concentrator beside the ADCThe BIG-IP that already delivers the app
Who patches the gatewayYour team, on its own scheduleStill your team — F5’s security notices apply
What it is NOT—A cloud ZTNA service, SCIM-provisioned, or list-priced

The cheapest test is one group on one existing BIG-IP: federate your IdP, front its web apps, and see which tunnels you still need.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the access tier lives

Platform

BIG-IP hardware or Virtual Edition

A software module on BIG-IP: an appliance, a VIPRION chassis or a Virtual Edition on your hypervisor or from a public-cloud marketplace image, all of it run by your own team.

02
How web apps are reached

Proxy

Identity-Aware Proxy

Each request to a web application is judged on who is asking and in what context, per F5’s page, before the proxy passes it on — rather than trusting the session once at sign-in.

03
How everything else is reached

Tunnels

Per-App VPN, IPsec and Edge Client

Per-App VPN and IPsec VPN sit beside the proxy; F5’s documentation adds the BIG-IP Edge Client for Windows and Mac, which hands out internal addresses for full network access.

04
Who is let in, and on what device

AAA

Authentication and federation layer

SAML, OAuth and OIDC federation, Azure AD Conditional Access and MDM posture checks, with RADIUS, LDAP, TACACS+, Kerberos, SecurID and client certificates in F5’s AAA list.

A module on BIG-IP you run — an identity-aware proxy for web apps, per-app and IPsec tunnels for the rest.

Part 03 · Evaluate

Nine capabilities. Connect, verify, operate.

F5 BIG-IP Zero Trust Access checks identity and device on every request, on BIG-IP you already own.

Connect
Identity-aware proxy

A decision on every request

Web apps sit behind a per-request, context-aware proxy, so access is reconsidered request by request and not just at sign-in.

Connect
Per-App VPN

A tunnel scoped to one app

Per-App VPN scopes a tunnel to individual applications, rather than opening the whole internal network to the device.

Connect
Network access

Full tunnel for thick clients

F5’s docs describe the Edge Client on Windows and Mac taking an internal address from a lease pool, for apps a proxy cannot carry.

Verify
Federation

SAML, OAuth and OIDC

BIG-IP federates with modern identity providers over SAML, OAuth and OIDC, so cloud and in-house apps share one sign-in.

Verify
Legacy AAA

Kerberos, RADIUS and LDAP too

F5’s AAA list covers AD, LDAP, RADIUS, TACACS+, SecurID and Kerberos, plus OCSP, CRLDP and client-certificate checks.

Verify
Device posture

MDM verdicts in the policy

Workspace ONE, Microsoft Intune and IBM MaaS360 integrations bring managed-device status into each access decision.

Operate
Session scale

A million sessions per box

F5 rates one BIG-IP device for up to 1M access sessions and a single VIPRION chassis for up to 2M, so few boxes can serve a big workforce.

Operate
Form factors

Hardware, VE or marketplace

The same module runs on F5 appliances, a VIPRION chassis or a Virtual Edition, including images bought through cloud marketplaces.

Operate
VDI access

Citrix behind the same gate

F5’s page lists Citrix among the environments it fronts, so virtual-desktop users pass the same identity and device checks.

See it, don’t just read it

Watch F5 BIG-IP Zero Trust Access in context

F5’s AppWorld 2026 case for its platform over SASE, and an F5 discussion of short-lived authentication for AI agents.

F5 (official)·AppWorld talk, April 2026

SASE vs. ADSP | AppWorld 2026

F5’s own argument, from AppWorld 2026, for its delivery-and-security platform over SASE; context for why this access tier is self-hosted.

F5 (official)·Episode, December 2025

Pop Goes the Stack | Now you see me, now you don't: Ephemeral Auth and AI agents | IAM

An F5 conversation on short-lived authentication for AI agents; identity background rather than a product demo.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why F5 BIG-IP Zero Trust Access

A VPN trusts the session; zero trust checks the request. BIG-IP Zero Trust Access does it on hardware you run.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Access on the platform that already delivers the app

Where BIG-IP already load-balances an application, Zero Trust Access is a module on the same device: an identity-aware proxy judges each web request in context before it reaches the server. There is no separate cloud to route through, so the access decision is made inside the data centre you choose.

02

Old and new sign-in methods on one gateway

F5’s page lists SAML, OAuth, OIDC and Azure AD Conditional Access; its AAA documentation adds AD, LDAP, RADIUS, TACACS+, SecurID, Kerberos and client certificates. An estate whose older apps expect Kerberos while new ones expect OIDC can put both behind one front door.

03

Capacity stated in sessions, posture from your MDM

F5 rates one BIG-IP device for up to 1M access sessions and a VIPRION chassis for 2M, so a large workforce can sit on a small number of boxes. Device verdicts come from Workspace ONE, Intune or MaaS360. Motorists Insurance Group is the customer F5 names, running it with Okta.

04

Where it stops

No price, no F5-hosted PoP, no documented SCIM or server-initiated support, and you patch it. CVE-2025-53521 and CVE-2026-94127 were exploited in 2026; in October 2025 F5 disclosed a nation-state theft of part of the BIG-IP source code (CISA ED 26-01). Versions 15.1 and 16.1 are out of support.

The idea
Zero trust access on your own BIG-IP
The residency
Sessions end in your Indian data centre
The price
Quote-only, as BIG-IP software
Proof, not promises

The numbers behind the platform

1M sessions
the access sessions F5 says a single BIG-IP device can hold at once
— Vendor
2M sessions
the ceiling F5 gives for one VIPRION chassis running the access module
— Vendor
3 MDM platforms
posture sources named on the page: Workspace ONE, Microsoft Intune and IBM MaaS360
— Vendor
9 AAA methods
beyond federation: AD, LDAP, RADIUS, TACACS+, SecurID, Kerberos, OCSP, CRLDP, certificates
— Vendor docs
2 exploited flaws
critical bugs in this module that attackers exploited in the wild during 2026
— CSA Singapore, CISA KEV
2019
when F5’s 90,000 sq ft engineering site in Hyderabad was inaugurated, CEO in attendance
— Vendor

What your F5 BIG-IP Zero Trust Access rollout looks like

Week 1Model

Sort the apps by protocol

List every app remote staff use and tag it web, VDI or thick client, noting any VoIP or other traffic the server starts.

Week 2Decide

Check the BIG-IP you have

Confirm the software train — 17.1, 17.5 or 21.x, not 15.1 or 16.1 — and whether existing boxes have room for access sessions.

Week 3Pilot

Wire identity and posture

Federate the IdP over SAML or OIDC, keep Kerberos or RADIUS for older apps, and connect Intune, Workspace ONE or MaaS360.

Month 2Prove

Move one group off the VPN

Put one department’s web apps behind the identity-aware proxy and give its thick-client users a Per-App VPN instead.

Month 3Commit

Set the patch rhythm

Subscribe to F5’s quarterly security notices, check any OAuth server profiles, and agree a window for emergency fixes.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.1
57+ reviews*
79% would recommend
Identity integration4.5
Scale and throughput4.4
Policy flexibility4.2
Ease of administration3.5
Value for money3.6
5★
42%
4★
37%
3★
14%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
BFSI
“Our core banking portal wanted Kerberos and the new HR suite wanted OIDC. The same BIG-IP pair now fronts both, with one login page.”
Identity Architect
BFSI
Logistics
“We moved 18,000 remote staff onto two boxes we already owned for load balancing. The session ceiling was never close to a problem.”
Network Security Manager
Logistics
Insurance
“Intune compliance now decides who reaches the claims app. A laptop that drops out of policy loses access at its next request.”
End-User Computing Lead
Insurance
Manufacturing
“Access policies get tangled fast once every app has its own branch. Name and document each rule while you build it, not after.”
BIG-IP Engineer
Manufacturing
Healthcare
“After the September advisory we patched in a weekend, then checked which virtual servers had an OAuth profile. Two did, and we fixed both.”
Infrastructure Security Lead
Healthcare
IT Services
“No SCIM, so leavers are handled by our directory sync and a nightly script. Ask about provisioning before you plan the rollout.”
IAM Engineer
IT Services
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the Zero trust access market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Zero Trust Access Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
F5 BIG-IP Zero Trust AccessThis page

Quoted as BIG-IP software; no public price.

Grid 02 · The architecture

Self-Run Control × Access Reach

The grid nobody publishes — how much of the access tier runs on infrastructure you control, vs how many apps, protocols and access modes it documents.

Broad cloud brokersBroad and self-runNarrow cloud accessSelf-run, narrow reach
F5 BIG-IP Zero Trust AccessThis page

All on your BIG-IP; proxy, per-app VPN, IPsec, VDI.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

F5 BIG-IP Zero Trust Access vs the zero trust access field

Against Zscaler ZPA, Akamai EAA, Prisma Access, Cloudflare Access and InstaSafe ZTNA — on where it runs, who operates it, protocols, posture, identity, scale, price and India.

DimensionF5 BIG-IP Zero Trust AccessZscaler Private Access (ZPA)Akamai Enterprise Application AccessPalo Alto Prisma Access (ZTNA)Cloudflare Access (Cloudflare One)InstaSafe ZTNA
What it isBIG-IP access moduleZscaler cloud ZTNAAkamai ZTNA serviceZTNA in Prisma AccessPer-app access, suiteIndian ZTNA product
Where it runsYour BIG-IP, your siteCloud + App ConnectorsEdge + your connectorsPrisma Access locationsNetwork + TunnelIndia-hosted service
Who runs the access tierYou, box by boxZscaler runs the cloudAkamai runs the edgePalo Alto runs itCloudflare runs the edgeManaged by InstaSafe
Access modesProxy, per-app, IPsecAgent + browserClientless + clientGlobalProtect + browserWARP or browserAgent + agentless
Apps and protocolsWeb, VDI, full tunnelWeb, SSH, RDP, desktopWeb, RDP, SSH, TCP/UDPWeb, SSH, RDP, desktopWeb, SSH, RDPWeb, SSH, RDP, thick
Server-initiated flowsNot documentedNeeds Network ConnectorNot documentedNot establishedNot establishedNot documented
Device postureIntune, WS1, MaaS360Agent, browser, rechecksChecks + EDR riskAgent and browserWARP or browserAgent and browser
Identity and SSOBroad AAA, no SCIMSAML, OIDC, SCIMSAML, OIDC, SCIMSCIM + conditionalSAML, OIDC, SCIMSAML and OIDC
Scale evidence1M sessions per boxWidest deployedScale not publishedVerified past 5,000Verified past 5,000Unverified past 5,000
Pricing modelBIG-IP licence, quotedPer user, by editionQuote; unit unstatedPer user per yearFree tier, then per userPer user, published
Published entry priceNot published~$6–11 reportedNot publishedNot published$0 to 50, then $7~$8 per user/month
Standalone or bundledModule on BIG-IPStandalone, in editionsOwn product, free trialNot standaloneStandalone startStandalone
India presenceYour Indian sitePoP cities unconfirmedNo EAA PoP namedMumbai since 2021Six Indian citiesIndian-built and hosted
Best fitBIG-IP estatesRetiring the VPN fullyAkamai customersPalo Alto NGFW estatesFast, priced startIndian and GeM buyers
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose F5 BIG-IP Zero Trust Access if…

  • ✓You already run BIG-IP and want identity-aware access and VPN on that platform rather than in a new cloud service
  • ✓Your apps mix Kerberos, RADIUS and LDAP sign-ins with SAML, OAuth and OIDC, and one gateway should federate them all
  • ✓Policy says access sessions must end in your own Indian data centre, on hardware or Virtual Editions your team controls

Compare alternatives if…

  • ✓You want the access tier operated and patched for you — Zscaler, Akamai, Palo Alto and Cloudflare each run their own cloud
  • ✓VoIP or other server-initiated traffic must cross — of these six, only Zscaler documents it, through its Network Connector
  • ✓You need a figure before the first meeting — Cloudflare and InstaSafe both publish a per-user price

Do not expect…

  • ✓A published price, an F5-hosted point of presence, or documented SCIM provisioning
  • ✓A quiet patch calendar — two critical flaws in this module were exploited in 2026
  • ✓An analyst ranking for this product; none is on record

F5 BIG-IP Zero Trust Access is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does network-wide VPN access cost you?

Drag the sliders (remote-access users; IT cost per hour). Estimates model IT time spent on VPN tickets, access requests and per-app sign-in wiring at an assumed 1.5 hours per user a year, with 70% of it removed by one federated, identity-aware access tier. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual remote-access support cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: F5 prints no price for Zero Trust Access. It is quoted as BIG-IP software — perpetual, subscription, cloud-marketplace utility or the Flex Consumption Program — together with the hardware, VIPRION chassis or Virtual Edition it runs on. TechBag sizes your concurrent sessions and existing BIG-IP first, then quotes in INR with GST.

On BIG-IP you already run

Best for estates with BIG-IP in place

  • Added as a module on existing boxes
  • Perpetual or subscription, quoted
  • Up to 1M sessions per device, per F5

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

New BIG-IP platform

Best for a fresh access tier

  • Hardware, VIPRION or a Virtual Edition
  • Marketplace or Flex Consumption options
  • Platform and support in the quote

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Existing BIG-IP

Do you already run BIG-IP for delivery? If not, the platform itself becomes part of this purchase and its quote.

2
Software train

Are your boxes on 17.1, 17.5 or 21.x? BIG-IP 15.1 and 16.1 are past end of support and appear on recent CVE lists.

3
App protocols

Which apps are web, which need VDI or a full tunnel, and does anything rely on server-initiated traffic like VoIP?

4
Identity

Which IdP federates over SAML or OIDC, which apps still need Kerberos or RADIUS, and how will you provision without SCIM?

5
Device posture

Is Intune, Workspace ONE or MaaS360 the source of device truth, and what happens to unmanaged contractor laptops?

6
OAuth exposure

Does any virtual server pair an access policy with an OAuth Authorization Server profile? That is CVE-2026-94127’s target.

7
Capacity

How many concurrent sessions at peak? F5 rates one device for 1M and a VIPRION chassis for 2M; size with headroom.

8
Licence

Perpetual, subscription, marketplace or Flex Consumption — and does the quote include the platform, support and INR with GST?

FAQ

Questions buyers ask

It is the access module of F5 BIG-IP. An identity-aware proxy decides on each web request in context, Per-App VPN and IPsec VPN carry other traffic, and the box federates sign-in over SAML, OAuth and OIDC. It runs on BIG-IP hardware or a Virtual Edition that you install and operate.

Ready to evaluate F5 BIG-IP Zero Trust Access?

Model what your VPN and access tickets cost first, or let a TechBag advisor scope a pilot that moves one department's apps behind the identity-aware proxy.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.