Your apps already sit behind BIG-IP. Remote access shouldn’t open the whole network — F5 BIG-IP Zero Trust Access, the former BIG-IP APM, puts an identity-aware proxy, Per-App VPN and IPsec VPN on BIG-IP you run yourself, federating SAML, OAuth and OIDC with your identity provider.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers F5 BIG-IP Zero Trust Access — the BIG-IP access module, formerly APM. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A proxy in front of each app checks who you are and what device you use on every request, instead of opening a network.
What consolidation actually replaces, dimension by dimension.
| Dimension | A VPN onto the whole network | F5 BIG-IP Zero Trust Access |
|---|---|---|
| What a remote user can reach | The whole subnet behind the VPN | One app at a time, judged per request |
| Sign-in standards | Each app wired to its own directory | SAML, OAuth, OIDC, Kerberos and RADIUS on one gateway |
| Device health | Assumed once the password works | Workspace ONE, Intune or MaaS360 verdicts in policy |
| Where sessions end | A VPN concentrator beside the ADC | The BIG-IP that already delivers the app |
| Who patches the gateway | Your team, on its own schedule | Still your team — F5’s security notices apply |
| What it is NOT | — | A cloud ZTNA service, SCIM-provisioned, or list-priced |
The cheapest test is one group on one existing BIG-IP: federate your IdP, front its web apps, and see which tunnels you still need.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
A software module on BIG-IP: an appliance, a VIPRION chassis or a Virtual Edition on your hypervisor or from a public-cloud marketplace image, all of it run by your own team.
Each request to a web application is judged on who is asking and in what context, per F5’s page, before the proxy passes it on — rather than trusting the session once at sign-in.
Per-App VPN and IPsec VPN sit beside the proxy; F5’s documentation adds the BIG-IP Edge Client for Windows and Mac, which hands out internal addresses for full network access.
SAML, OAuth and OIDC federation, Azure AD Conditional Access and MDM posture checks, with RADIUS, LDAP, TACACS+, Kerberos, SecurID and client certificates in F5’s AAA list.
A module on BIG-IP you run — an identity-aware proxy for web apps, per-app and IPsec tunnels for the rest.
F5 BIG-IP Zero Trust Access checks identity and device on every request, on BIG-IP you already own.
Web apps sit behind a per-request, context-aware proxy, so access is reconsidered request by request and not just at sign-in.
Per-App VPN scopes a tunnel to individual applications, rather than opening the whole internal network to the device.
F5’s docs describe the Edge Client on Windows and Mac taking an internal address from a lease pool, for apps a proxy cannot carry.
BIG-IP federates with modern identity providers over SAML, OAuth and OIDC, so cloud and in-house apps share one sign-in.
F5’s AAA list covers AD, LDAP, RADIUS, TACACS+, SecurID and Kerberos, plus OCSP, CRLDP and client-certificate checks.
Workspace ONE, Microsoft Intune and IBM MaaS360 integrations bring managed-device status into each access decision.
F5 rates one BIG-IP device for up to 1M access sessions and a single VIPRION chassis for up to 2M, so few boxes can serve a big workforce.
The same module runs on F5 appliances, a VIPRION chassis or a Virtual Edition, including images bought through cloud marketplaces.
F5’s page lists Citrix among the environments it fronts, so virtual-desktop users pass the same identity and device checks.
F5’s AppWorld 2026 case for its platform over SASE, and an F5 discussion of short-lived authentication for AI agents.
F5’s own argument, from AppWorld 2026, for its delivery-and-security platform over SASE; context for why this access tier is self-hosted.
An F5 conversation on short-lived authentication for AI agents; identity background rather than a product demo.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Where BIG-IP already load-balances an application, Zero Trust Access is a module on the same device: an identity-aware proxy judges each web request in context before it reaches the server. There is no separate cloud to route through, so the access decision is made inside the data centre you choose.
F5’s page lists SAML, OAuth, OIDC and Azure AD Conditional Access; its AAA documentation adds AD, LDAP, RADIUS, TACACS+, SecurID, Kerberos and client certificates. An estate whose older apps expect Kerberos while new ones expect OIDC can put both behind one front door.
F5 rates one BIG-IP device for up to 1M access sessions and a VIPRION chassis for 2M, so a large workforce can sit on a small number of boxes. Device verdicts come from Workspace ONE, Intune or MaaS360. Motorists Insurance Group is the customer F5 names, running it with Okta.
No price, no F5-hosted PoP, no documented SCIM or server-initiated support, and you patch it. CVE-2025-53521 and CVE-2026-94127 were exploited in 2026; in October 2025 F5 disclosed a nation-state theft of part of the BIG-IP source code (CISA ED 26-01). Versions 15.1 and 16.1 are out of support.
List every app remote staff use and tag it web, VDI or thick client, noting any VoIP or other traffic the server starts.
Confirm the software train — 17.1, 17.5 or 21.x, not 15.1 or 16.1 — and whether existing boxes have room for access sessions.
Federate the IdP over SAML or OIDC, keep Kerberos or RADIUS for older apps, and connect Intune, Workspace ONE or MaaS360.
Put one department’s web apps behind the identity-aware proxy and give its thick-client users a Per-App VPN instead.
Subscribe to F5’s quarterly security notices, check any OAuth server profiles, and agree a window for emergency fixes.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our core banking portal wanted Kerberos and the new HR suite wanted OIDC. The same BIG-IP pair now fronts both, with one login page.”
“We moved 18,000 remote staff onto two boxes we already owned for load balancing. The session ceiling was never close to a problem.”
“Intune compliance now decides who reaches the claims app. A laptop that drops out of policy loses access at its next request.”
“Access policies get tangled fast once every app has its own branch. Name and document each rule while you build it, not after.”
“After the September advisory we patched in a weekend, then checked which virtual servers had an OAuth profile. Two did, and we fixed both.”
“No SCIM, so leavers are handled by our directory sync and a nightly script. Ask about provisioning before you plan the rollout.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the Zero trust access market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quoted as BIG-IP software; no public price.
The grid nobody publishes — how much of the access tier runs on infrastructure you control, vs how many apps, protocols and access modes it documents.
All on your BIG-IP; proxy, per-app VPN, IPsec, VDI.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Zscaler ZPA, Akamai EAA, Prisma Access, Cloudflare Access and InstaSafe ZTNA — on where it runs, who operates it, protocols, posture, identity, scale, price and India.
| Dimension | F5 BIG-IP Zero Trust Access | Zscaler Private Access (ZPA) | Akamai Enterprise Application Access | Palo Alto Prisma Access (ZTNA) | Cloudflare Access (Cloudflare One) | InstaSafe ZTNA |
|---|---|---|---|---|---|---|
| What it is | BIG-IP access module | Zscaler cloud ZTNA | Akamai ZTNA service | ZTNA in Prisma Access | Per-app access, suite | Indian ZTNA product |
| Where it runs | Your BIG-IP, your site | Cloud + App Connectors | Edge + your connectors | Prisma Access locations | Network + Tunnel | India-hosted service |
| Who runs the access tier | You, box by box | Zscaler runs the cloud | Akamai runs the edge | Palo Alto runs it | Cloudflare runs the edge | Managed by InstaSafe |
| Access modes | Proxy, per-app, IPsec | Agent + browser | Clientless + client | GlobalProtect + browser | WARP or browser | Agent + agentless |
| Apps and protocols | Web, VDI, full tunnel | Web, SSH, RDP, desktop | Web, RDP, SSH, TCP/UDP | Web, SSH, RDP, desktop | Web, SSH, RDP | Web, SSH, RDP, thick |
| Server-initiated flows | Not documented | Needs Network Connector | Not documented | Not established | Not established | Not documented |
| Device posture | Intune, WS1, MaaS360 | Agent, browser, rechecks | Checks + EDR risk | Agent and browser | WARP or browser | Agent and browser |
| Identity and SSO | Broad AAA, no SCIM | SAML, OIDC, SCIM | SAML, OIDC, SCIM | SCIM + conditional | SAML, OIDC, SCIM | SAML and OIDC |
| Scale evidence | 1M sessions per box | Widest deployed | Scale not published | Verified past 5,000 | Verified past 5,000 | Unverified past 5,000 |
| Pricing model | BIG-IP licence, quoted | Per user, by edition | Quote; unit unstated | Per user per year | Free tier, then per user | Per user, published |
| Published entry price | Not published | ~$6–11 reported | Not published | Not published | $0 to 50, then $7 | ~$8 per user/month |
| Standalone or bundled | Module on BIG-IP | Standalone, in editions | Own product, free trial | Not standalone | Standalone start | Standalone |
| India presence | Your Indian site | PoP cities unconfirmed | No EAA PoP named | Mumbai since 2021 | Six Indian cities | Indian-built and hosted |
| Best fit | BIG-IP estates | Retiring the VPN fully | Akamai customers | Palo Alto NGFW estates | Fast, priced start | Indian and GeM buyers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
F5 BIG-IP Zero Trust Access is one of 23 zero trust access products TechBag carries. The Zero Trust Access guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (remote-access users; IT cost per hour). Estimates model IT time spent on VPN tickets, access requests and per-app sign-in wiring at an assumed 1.5 hours per user a year, with 70% of it removed by one federated, identity-aware access tier. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: F5 prints no price for Zero Trust Access. It is quoted as BIG-IP software — perpetual, subscription, cloud-marketplace utility or the Flex Consumption Program — together with the hardware, VIPRION chassis or Virtual Edition it runs on. TechBag sizes your concurrent sessions and existing BIG-IP first, then quotes in INR with GST.
Best for estates with BIG-IP in place
Best for a broader rollout
Best for a fresh access tier
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Do you already run BIG-IP for delivery? If not, the platform itself becomes part of this purchase and its quote.
Are your boxes on 17.1, 17.5 or 21.x? BIG-IP 15.1 and 16.1 are past end of support and appear on recent CVE lists.
Which apps are web, which need VDI or a full tunnel, and does anything rely on server-initiated traffic like VoIP?
Which IdP federates over SAML or OIDC, which apps still need Kerberos or RADIUS, and how will you provision without SCIM?
Is Intune, Workspace ONE or MaaS360 the source of device truth, and what happens to unmanaged contractor laptops?
Does any virtual server pair an access policy with an OAuth Authorization Server profile? That is CVE-2026-94127’s target.
How many concurrent sessions at peak? F5 rates one device for 1M and a VIPRION chassis for 2M; size with headroom.
Perpetual, subscription, marketplace or Flex Consumption — and does the quote include the platform, support and INR with GST?
Model what your VPN and access tickets cost first, or let a TechBag advisor scope a pilot that moves one department's apps behind the identity-aware proxy.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.