TrustRadius: an HG Insights company

F5 BIG-IP Access Policy Manager (APM)

Score9.1 out of 10

44 Reviews and Ratings

What is F5 BIG-IP Access Policy Manager (APM)?

F5 Networks provides BIG-IP Access Policy Manager as an identity and access solution which can be deployed as a standalone solution or as an add-on to F5 Networks' flagship BIG-IP TLM or F5 Advanced WAF applications.

Read more details.

Top Performing Features

  • AES 256-bit Encryption

    Utilizes Advanced Encryption Standard with a 256-bit key to secure data and communication, ensuring high levels of confidentiality and protection against cyber threats.

    Category average: 9.3

  • Kill Switch

    Automatically disconnects the device from the internet if the VPN connection drops unexpectedly, preventing data leaks and exposure of sensitive information.

    Category average: 9

  • Split Tunneling

    Permits users to route some of their device's traffic through the VPN while allowing other traffic to access the internet directly, optimizing performance and efficiency.

    Category average: 9

Areas for Improvement

  • Multiple Server Locations

    Provides a wide selection of server locations worldwide, allowing users to bypass geo-restrictions, access region-specific content, and improve connection speeds.

    Category average: 8.9

  • IP Address Masking

    Conceals the user's actual IP address and replaces it with a virtual IP address, enhancing anonymity and preventing tracking of online activities.

    Category average: 8.8

  • No-Logs Policy

    Ensures that the VPN provider does not store or track users' online activities, guaranteeing privacy and anonymity while using the service.

    Category average: 8.2

Who Buys & Uses F5 BIG-IP Access Policy Manager (APM)

Pros

  • Robust user access and authentication management
  • Effective authentication and federation capabilities
  • Comprehensive access policy management with granular control

Cons

  • Policy Access module interface is perceived as outdated and cumbersome
  • Complexity of initial implementation
  • Challenges with ongoing management and configuration

F5 BIG-IP Access Policy Manager (APM)

Use Cases and Deployment Scope

Primarily for policy management and ingress from the Internet for Citrix clients and MS Exchange

Pros

  • Policy management
  • federation

Cons

  • Policy Access module feels outdated
  • Needs checks and balances between authentication methods and their usage within policy, it can be easily confusing and lots of clicking back and forth

Return on Investment

  • It's an added layer of protection that helps us secure ingress into the internal network.

Usability

Other Software Used

Imperva Web Application Firewall (WAF)

Amazing product

Use Cases and Deployment Scope

In our organization, we use F5 BIG-IP Access Policy Manager (APM) for various authentication, in house IDP, Federation IDP Chaining.

Pros

  • authentication
  • Logs
  • SAMl

Cons

  • integrated Gen AI to build irules/apm

Return on Investment

  • ROI
  • Security

Usability

Alternatives Considered

NetScaler

Other Software Used

F5 BIG-IP Local Traffic Manager (LTM), Okta, SecureAuth IdP

Our Experience with F5 BIG-IP Access Policy Manager

Use Cases and Deployment Scope

We use BIG-IP Access Policy Manager for a couple different use cases within our organization. We use it both for providing all employees within the company secure VPN access to company resources while working remote. We also use it to provide a more heavily secured webtop for very specific high-security applications within certain segments of our network that need to be more controlled.

Pros

  • Simple pushing of updates out to user workstations
  • Easy to add new tiles to our webtop for new resources
  • Ease of use of the Edge Client is a big point of satisfaction with users

Cons

  • CCU Licenses are limited by device and are not shared between APM devices
  • User sessions are not stored globally, so persistence can be an issue with users all over the world
  • Configuration can get complicated when split up between multiple sites

Return on Investment

  • Simplified our approach to company-wide VPN solutions greatly by allowing us to use a single product instead of multiple products like we had before
  • Can handle 15000-20000 users at once with no issues
  • Was able to configure to support users travelling with 4G connections on their laptops and accommodate constant changing IP addresses

Usability

Alternatives Considered

Cisco AnyConnect and Zscaler Private Access

F5 BIG-IP Access Policy Manager (APM) as cloud provider replacement

Use Cases and Deployment Scope

I'm a reseller and have experience with our customers using it. APM has been a breeze to replace things like Azure's native API Gateway, I just wish the APM module was available in F5 Distributed Cloud.

Pros

  • Displace native cloud provider's versions of APM
  • Clean & authenticate the traffic coming through
  • Make life easier for customer's SecOps & NetOps teams

Cons

  • Bring the module to XC
  • nothing else I can think of in my experience with it

Return on Investment

  • Overall, it's made displacing F5's competition relatively easy
  • I've been forced to sell BIG-IP VEs in an environment where XC would run better, but the customer needed APM so XC wasn't an option.

Usability

Alternatives Considered

F5 BIG-IP and F5 Distributed Cloud API Security

Other Software Used

F5 BIG-IP Advanced Firewall Manager (AFM), F5 Big-IP Advanced WAF, F5 BIG-IP DNS, F5 BIG-IP Local Traffic Manager (LTM), F5 Distributed Cloud Account Protection, F5 Distributed Cloud API Security, F5 Distributed Cloud Bot Defense, F5 Distributed Cloud DDoS Mitigation Service, F5 Distributed Cloud DNS Load Balancer, F5 Distributed Cloud WAF (Web Application Firewall)

F5 BIG-IP Access Policy Manager (APM) is great

Use Cases and Deployment Scope

SSO with saml idp for our 15000 students and 2000 faculty and staff across multiple virtual servers. We also use the oidc provider for jet. Solve the problem of seamless single sign on across multiple applications third party and in-house developed. Also helps having a centralized place for session management and load balancing.

We recently integrated multiple external service providers. With APM and iRules we were able to extend the system to provide a different SAML response when the service required unique data.

Pros

  • Saml idp
  • Insanely customizable
  • Oauth web tokens
  • Support multiple and separate domain cookies
  • Highly available

Cons

  • User interface
  • Needs responsive design
  • MFA implementation is clunky
  • Drag and Drop customization to UI components
  • Have to write code to provide a custom login UI

Return on Investment

  • Single sign on is great for students and faculty and staff
  • Users don't have to log in multiple times
  • Users don't need to remember multiple login IDs and passwords
  • Multi Domain SSO support bridges many internal and external facing products with single sign on

Usability

Alternatives Considered

Fortinet FortiGate

Other Software Used

GitLab, Microsoft 365, CobbleStone Contract Insight®