TrustRadius: an HG Insights company

F5 BIG-IP SSL Orchestrator

Score9.3 out of 10

3 Reviews and Ratings

What is F5 BIG-IP SSL Orchestrator?

F5 Networks provides the SSL Orchestrator, a high-performance decryption, analysis, and re-encryption tool for SSL/TLS traffic across the network to locate threats or data exfiltration efforts concealed in encrypted traffic.

Categories & Use Cases

F5 at work

Use Cases and Deployment Scope

F5 VPN was really good it helped me log in to my laptop securely to access all the company data. the best part of it was it was very secure and it had 2 step authentication which really made the process secure and also very smooth I have used it at amdocs and I am very much satisfied with it

Pros

  • its very secure
  • it had 2 step authentication
  • it was cost effective to the company

Cons

  • it can have all the things on a single page
  • the UI needs change
  • it can be made much more easy to use

Usability

Alternatives Considered

F5 BIG-IP Advanced Firewall Manager (AFM)

High visibility of SSL / TLS traffic ideal to strengthen security and mitigate attacks

Pros

  • Provides a flexible, fast and simple implementation.
  • Provides strong encryption and decryption of traffic, ensuring high SSL visibility.
  • Ensures exposure of threats from inbound and outbound traffic and helps mitigate attacks.
  • Allows you to direct traffic through policies which provides better management of it.

Cons

  • It is a software with a somewhat complex documentation so when you are in doubt it is difficult to solve it through its documentation.
  • A good knowledge is required in the management of the software, because although its implementation is flexible, carrying it out in the appropriate way guarantees good operation.
  • Its price can be somewhat high if it is a small company, however considering its high versatility the investment is worth it.
  • Learning curve somewhat steep, but you can count on the support of your support team.

Most Important Features

  • The one that provides high visibility of SSL / TLS traffic, thus efficiently exposing and mitigating attacks.
  • Its devices with high traffic visibility help optimize the SLL infrastructure.
  • The one that is associated with other recognized security software guarantees an increase in security and a reduction in operating costs.

Return on Investment

  • By providing a high vision of inbound and outbound traffic, we manage to avoid the entry of threats and the exposure or loss of data from our business infrastructure.
  • Its policy based management is very helpful, since it is much simpler to manage SSL traffic and to be aware of any attack coming from it and to apply security controls to all business traffic.

Alternatives Considered

OpenSSL

Other Software Used

Forcepoint NGFW, FireEye Endpoint Security, Forcepoint Web Security

F5 BIG-IP SSL Orchestrator opens visibility for other Security Services in the Service Chain

Use Cases and Deployment Scope

Prior to F5 BIG-IP SSL Orchestrator we had an F5 sandwich which consumed additional vip/snat addresses and added latency in the way we diverted traffic to other appliances in our security service chain. We were able to leverage SSLO internally as well as in Azure to integrate security solutions seemlessly including our NGFW and AWAF policies.

Pros

  • Opens visibility for other Security Services in the Service Chain
  • Simplifies Deployment and Complexity
  • Easily control, assign and steer AWAF Policies
  • Easy to Deploy templates for common architectures

Cons

  • Clearing REST Storage kills SSLO Configuration and needs to be restored or rebuilt.

Return on Investment

  • Reduced complexity
  • Increased Security