Skip to main content
TrustRadius
F5 BIG-IP Access Policy Manager (APM)

F5 BIG-IP Access Policy Manager (APM)

Overview

What is F5 BIG-IP Access Policy Manager (APM)?

F5 Networks provides BIG-IP Access Policy Manager as an identity and access solution which can be deployed as a standalone solution or as an add-on to F5 Networks' flagship BIG-IP TLM or F5 Advanced WAF applications.

Read more
Recent Reviews
Read all reviews

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is F5 BIG-IP Access Policy Manager (APM)?

F5 Networks provides BIG-IP Access Policy Manager as an identity and access solution which can be deployed as a standalone solution or as an add-on to F5 Networks' flagship BIG-IP TLM or F5 Advanced WAF applications.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

17 people also want pricing

Alternatives Pricing

What is GoodAccess?

GoodAccess is a cloud VPN with zero-trust access controls specially designed for small and medium businesses. GoodAccess is a secure remote access solution that interconnects remote workers, applications, data centers, clouds, and offices via one resilient virtual network. No hardware or complex…

What is NetScaler Gateway?

NetScaler Gateway (formerly Citrix Gateway) is an access gateway with SSL VPN solution, providing single sign-on (SSO) and authentication for remote end users of network assets.

Return to navigation

Product Details

What is F5 BIG-IP Access Policy Manager (APM)?

F5® BIG-IP® Access Policy Manager® (APM) is an access management proxy solution managing global access to the user's network, the cloud, applications, and application programming interfaces (APIs). Through a single management interface, BIG-IP APM consolidates remote, mobile, network, virtual, and web access. BIG-IP APM can also serve as a bridge between modern and classic authentication and authorization protocols and methods. For applications which are unable to support modern authentication and authorization protocols, like SAML and OAuth with OIDC, but which do support classic authentication methods, BIG-IP APM converts user credentials to the appropriate authentication standard supported by the application.

Identity Aware Proxy is key to both a Zero Trust security architecture and to F5 BIG-IP APM. BIG-IP APM and F5 Access Guard deliver Identity Aware Proxy using a Zero Trust validation model on every application access request. Providing authenticated and authorized users secure access to specific applications, it leverages F5 best-in-class access proxy. BIG-IP APM centralizes user identity and authorization. Authorization is based on the principles of least privileged access.

F5 BIG-IP Access Policy Manager (APM) Features

  • Supported: Support for Identity Aware Proxy (IAP) enabling Zero Trust application access
  • Supported: Context-based authorization with dynamic L4/L7 ACLs
  • Supported: Seamless integration with third-party MFA solutions
  • Supported: DTLS 2.0 mode for delivering and securing applications
  • Supported: SAML 2.0 identity federation support
  • Supported: Support for OAuth 2.0 authorization protocol
  • Supported: SSO support for classic authentication (Kerberos, header- based, etc.), credential caching, OAuth 2.0, SAML 2.0, and FIDO2 (U2F)
  • Supported: Granular access policy enforcement
  • Supported: AAA server authentication and high-availability
  • Supported: Integration with leading IAM vendor products (Microsoft, Okta, Ping Identity)
  • Supported: BIG IP Edge Client and F5 Access integrate with VMware Horizon ONE (AirWatch), Microsoft Intune and IBM MaaS360
  • Supported: Risk-based access leveraging third-party UEBA and risk engines (HTTP Connector)
  • Supported: Scales up to 2 million concurrent access sessions

F5 BIG-IP Access Policy Manager (APM) Competitors

F5 BIG-IP Access Policy Manager (APM) Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

F5 Networks provides BIG-IP Access Policy Manager as an identity and access solution which can be deployed as a standalone solution or as an add-on to F5 Networks' flagship BIG-IP TLM or F5 Advanced WAF applications.

NetScaler ADC, Ivanti Connect Secure, and Zscaler Private Access are common alternatives for F5 BIG-IP Access Policy Manager (APM).

The most common users of F5 BIG-IP Access Policy Manager (APM) are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(21)

Reviews

(1-5 of 5)
Companies can't remove reviews or game the system. Here's why
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use BIG-IP Access Policy Manager for a couple different use cases within our organization. We use it both for providing all employees within the company secure VPN access to company resources while working remote. We also use it to provide a more heavily secured webtop for very specific high-security applications within certain segments of our network that need to be more controlled.
  • Simple pushing of updates out to user workstations
  • Easy to add new tiles to our webtop for new resources
  • Ease of use of the Edge Client is a big point of satisfaction with users
  • CCU Licenses are limited by device and are not shared between APM devices
  • User sessions are not stored globally, so persistence can be an issue with users all over the world
  • Configuration can get complicated when split up between multiple sites
I think that the platform is well suited to many Remote Access VPN solutions, but I also think there is a lot of room for improvement on the backend. If you are hoping to deploy your APM solution across many different datacenters or colos, it may not be the best choice for the final solution.
  • Simplified our approach to company-wide VPN solutions greatly by allowing us to use a single product instead of multiple products like we had before
  • Can handle 15000-20000 users at once with no issues
  • Was able to configure to support users travelling with 4G connections on their laptops and accommodate constant changing IP addresses
F5 BIG-IP Access Policy Manager integrates extremely well with the rest of our F5 infrastructure which is a big plus and provides us with a familiar user interface, but it isn't as scalable in its current iteration as something like Zscaler Private Access.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
I am using F5 BIG-IP Access Policy Manager (APM) for authentication services for distributors and end customer and this will give authentication and access based on profiles, also for network access control in place for organizational level
  • access based on user levels
  • Network access controls
  • Difficult to route the traffic on clusters due to policy verification as the traffic will rote to node after completion of access policy
F5 BIG-IP Access Policy Manager (APM) is used for Authentication servers as well as Network control access
  • resource constrains and localized authentication services
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We have create source and destination base policy with load balancing and it is working fine than any other product. Even link failover and high latency features working fine. Also SSL VPN connection through load balancing feature support through DNS So without manual interruption SSL VPN Working fine incas of link failover.
  • Source and destination IP Base policy
  • Source and application base policy
  • Ssl VPN with load balancing and fail over policy working fine.
  • When u leave it for long enough it get disconnected
  • GUI Not loos friendly
  • Reporting not good
Simplify access to on-premises and cloud apps with a SSO.control acces to web based applications and web filtering. Provide single management console.adaptive identity federation SSO, and MFA employing SAML and secure user experience across all apps.protect against data loss,malware and rouge devices access with comprehensive continuous endpoint integration and security checks.
  • Simplify access of all applications
  • Zero trust application access
  • Secure web access
  • Centralized console
  • Ensure seamless failover in case destination not reachable
  • Support 2FA with different authentication method
  • SSO to multiple applications
  • Reporting part need to improve
It is open platform so support is not good and than F5 and features visibility as not good as F5.
F5 Set up and easy to use to admin console.
Also have more feature visibility for load balancing, web server accelerator, application server ddos protection and WAF.
F5 more efficient to handle concurrent request.
Mohammed Younus Siddiqui | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use F5 BIG-IP APM to secure our applications. We also use to implement two-factor authentication for our VPN and allow RDP/SSH access to our users. It is the one-stop portal for all our users who are outside the university. We also deploy app tunnels and any specific user IP port access.
  • Remote Access to the local computer.
  • Application Security.
  • Authentication.
  • Two Factor Authentication Implementation.
  • UI/UX can be quick and modern.
  • The application hosting is not one-click.
  • You cannot observer the changes done for external users internally.
If you already have an F5 implementation or use the LTM for load balancing. Then APM is the most obvious choice for you. It is just an add-on subscription/license to your existing appliance. In this day and age, where remote work is considered the norm then APM is a good solution to ensure your users have the required access wherever they are.
  • VPN Portal.
  • Application Tunnels.
  • Remote Desktop.
  • Protecting simple web applications behind the VPN Portal.
  • Authentication the users using AD and a 2FA for better security.
  • Easy Remote Desktop access to the user's local computer.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
It helps to maintain a secure connection to our different sites from the outer world. Availability for centralized management and easy deployment is the main factor for considering this product. The product can be scaled to any larger environment and it works seamlessly. We already using SSO for all our applications in our company and this tool support SSO through SAML out of the box.
  • Ease the process in different policy creation
  • API protection
  • Employs Advanced Web Application firewall
  • Auto reconnect feature can be improved once network is restored.
  • Readability of logs can be improved when troubleshooting.
  • Central Management console can be added with more insights and dashboards.
For larger environments with secure applications that need to be accessed in a more secure way then F5 BIG-IP APM secures, simplifies, and centralizes access to apps. Ease of configuration and user-friendly centralized management. Support SSO and much-needed integrations. Allows creating multiple partitions to accomplish multiple customers. Greater benefit for organization.
  • SSO/SAML
  • Centralized Management
  • Access Guided configuration
  • Increases productivity
  • Returns greater benefit towards the investment
  • SonicWall Secure Mobile Access (SMA)
Easy of deployment. Greater control using central management and deployment.
SonicWall Secure Mobile Access (SMA), ManageEngine Access Manager Plus
Return to navigation