Professional Documents
Culture Documents
Cloud Solution Templates Catalogue 10-6-17
Cloud Solution Templates Catalogue 10-6-17
Templates
Why do I need F5’s Cloud Solution Templates?
Common Solutions
Tested & Validated Simple & Automated Across Clouds
• Manual configuration of app • Templates Integrate with 3rd party • F5 is striving towards template
services is time consuming and automation tools such as Chef, parity across cloud vendors
prone to error Puppet & Ansible
• Enabling fast & simple replication
• Templates designed and tested • Improves efficiency while reducing of app services across multiple
by F5 experts following cloud cost, variability and deployment cloud platforms.
best practices. risks
• VE Deployments in minutes 2
General Information: Please Read!
1. These templates simplify and speed up the deployment of BIG-IP VE’s in public cloud environments by
packaging together all of the necessary resources and BIG-IP configuration parameters needed to
launch fully functioning BIG-IP VE’s in a virtual cloud network.
2. This deck contains only ‘F5 supported’ templates, which are those that have been created, tested and
verified by F5 Networks engineers, allowing customers to request assistance with them should they
need it. There are also ‘Experimental’ templates on GitHub which have not been fully validated and are
not subject to customer support.
3. All templates support BIG-IP v12.1.x through v13.0
4. All templates have built-in security checks, allowing customers to ensure the integrity of the template
5. All deployment times (both manual and templated times) stated in this deck are ESTIMATES, and
assume the user has an intermediate level of experience with both the BIG-IP and the cloud platform in
question. All times include boot time for the VE’s (~20mins). Pre-req’s are not included since they are
required for both manual and templated deployments, but are adjudged to take around 15-20mins. It is
important to note that with the more complex configurations such as the auto scaling solutions,
somebody without BIG-IP or cloud experience would take much longer than the estimated times
(magnitude of days to weeks) to replicate the set-up.
Template Updates/Notes – Release 6
• Service Discovery: All CFT’s and ARM templates including auto scaling solutions now support pool
member discovery through tags. Customers are able to tag any interface or VM in AWS or Azure and
have the BIG-IP automatically add those services as BIG-IP pool members. With frictionless bring-up of
BIG-IP we now have added hands-off service management.
• CFT’s & ARM’s now work with BIG-IQ 5.2 & 5.3 as license manager: Templates in AWS & Azure can
now receive licenses from the latest versions of BIG-IQ. This adds to our slate of supported hourly and
BYOL licensing options.
• All ARM Templates can now be deployed into existing Azure Virtual Networks – Previously a
selection of templates (auto scale and HA) could only be deployed as a new stack, however now they
can be deployed directly into an existing VNET, allowing implementation into production environments.
• Auto Scale Master Election for CFT/ARM - To increase the efficiency of our auto scale templates, all
our BIG-IP auto scale templates now have the ability to seamlessly select a new master BIG-IP VE
instance in the event that the original master instance is unavailable. This provides a smoother cluster
deployment and ensures your service is uninterrupted.
Template Updates/Notes – Release 6
• Template Statistics Reporting Functionality: All AWS and Azure templates now include an option to
send anonymous statistics to F5 Networks to help improve future templates. None of the information we
collect is personally identifiable. This information is critical to the future improvements of templates, but
should you choose not to send statistics, this information will not be sent. See the individual README
files for the types of statistics.
• Matrix for Tagged Releases: Matrices created for both AWS and Azure to showcase corresponding
BIG-IP versions, license types and t’puts avalaible for each tagged release. Available here:
• Azure: https://
github.com/F5Networks/f5-azure-arm-templates/blob/master/azure-bigip-version-matrix.md
• AWS: https://
github.com/F5Networks/f5-aws-cloudformation/blob/master/aws-bigip-version-matrix.md
• Azure HA-AVSET Template Update: This template now supports being configured in an active-
active configuration, instead of just active-standby. The templates now support up to 20 Azure public IP
addresses, and users are still able able to add more than 20 IP addresses manually if needed.
Template Updates/Notes – Release 6
• AWS Auto-Create Security Groups – All standalone and clustered templates now automatically create
security groups, eliminating this step from the pre-requisites and greatly simplifying the deployment.
• AWS 5Gbps Throughput Option – All AWS templates now support using VE’s with 5Gbps of
throughput.
• OpenStack Templates are now Supported! – See OpenStack slides for details.
• Azure Auto Scale Template Email Notifications – Auto scale templates can have multiple emails
attached to them to receive notifications on scaling events.
Cloud Solution Templates by Platform
7
Cloud Solution Templates by Use Case
Application Security
• Auto Scale Cloud WAF [AWS, Azure]
Deployment Topologies
• 1NIC VE Deployment [AWS, Azure, Google, OpenStack]
• 2NIC VE Deployment [AWS, Azure, OpenStack]
• 3NIC VE Deployment [AWS, Azure,]
• n-NIC VE Deployment [Azure]
• HA (Active/Active) [AWS, Azure]
• HA (Active/Standby) [Azure, OpenStack]
1-NIC BIG-IP VE Deployment on AWS
For deploying a single, standalone BIG-IP device with one network interface
• Scale up & Scale down traffic thresholds are customizable, initially set
as 80% & 20% of max throughput respectively
2. At this point, solutions are available for AWS and Azure for multiple different use case
scenarios.
3. All deployment times (both manual and templated times) stated in this deck are
ESTIMATES, and assume the user has an intermediate level of experience with both the
BIG-IP and the cloud platform in question. All times include boot time for the VE’s
(~20mins). Pre-req’s are not included since they are required for both manual and
templated deployments, but are adjudged to take around 15-20mins
• No prior knowledge of the BIG-IP system required to implement, and allows a customer to
deploy their VE’s confidently, in the knowledge that the pre-configured solutions have
been designed following best practices by F5 experts.
31
Integrated Marketplace Solutions by Use Case
Application Security
• WAF Solution (Inside Azure Security Center) [Azure]
• WAF Solution [Azure]
• Auto Scale WAF Solution [AWS, Azure]
Application Access
• Federated Access to Office365 Applications [Azure]
© 2017 F5 Networks 32
Auto Scale WAF Solution for AWS
Optimize application security and operational expenditure