[转帖]F5 BIG-IP 17.0.0

f5,big,ip · 浏览次数 : 0

小编点评

**BIG-IP LTM 17.0.0 New and Updated** **Expat Vulnerabilities CVE-2022-23852, CVE-2022-25235, CVE-2022-25236, and CVE-2022-25315** **Testing a health monitor using the Configuration utility** **Troubleshooting ConfigSync and device service clustering issues** **BIG-IP LTM-DNS Operations Guide** **Virtual-Edition, Release 04/26/2022** **Image file set for KVM Red Hat Enterprise Linux/CentOS2129** **Image file set for KVM Red Hat Enterprise Linux/CentOS67** **Image file set for Microsoft Hyper-V2131** **Image file set for Microsoft Hyper-V65** **Vhd.zip file for Microsoft Hyper-V** **Vhd.zip file for Microsoft Hyper-V65** **qcow2 file for Microsoft Hyper-V** **vhd.zip file for Microsoft Hyper-V** **All file sets for Microsoft Hyper-V**

正文

 

 
https://www.cnblogs.com/sysin/p/16438174.html

 

 


请访问原文链接:https://sysin.org/blog/f5-big-ip-17/,查看最新版。原创作品,转载请保留出处。

作者主页:www.sysin.org


img

BIG-IP is a collection of hardware platforms and software solutions providing services focused on security, reliability, and performance (sysin).

BIG-IP software products are licensed modules that run on top of F5’s Traffic Management Operation System® (TMOS).

BIG-IP 产品概述

BIG-IP

F5’s growing portfolio of products that provide the availability, performance, and security you need

BIG-IP Access Policy Manager
Secures, simplifies, and protects user access to apps and data

BIG-IP Advanced Firewall Manager
Protects your network against incoming threats, including complex DDOS attacks

BIG-IP Advanced WAF
Protects apps with behavioral analytics, bot defense, and app-layer encryption

BIG-IP Carrier-Grade NAT (CGNAT)
Fast, scalable, and secure IPv4/IPv6 IP address management as part of a suite of consolidated functions

BIG-IP DNS
Provides hyperscale and security during high query volumes and DNS DDoS attacks

BIG-IP Local Traffic Manager
Manages network traffic so applications are always fast, available, and secure

BIG-IP Policy Enforcement Manager
Improves network performance through effective policy management

BIG-IP Service Proxy for Kubernetes
Gives multi-protocol ingress/egress signaling control, security, and visibility for cloud-native 5G

BIG-IP SSL Orchestrator
Maximizes infrastructure efficiencies and security with encryption/decryption and traffic steering

Container Ingress Services
Provides automation, orchestration, and networking services for container deployments

BIG-IP Deployment

Deploy your applications on-premises, in the cloud, or both.

BIG-IP iSeries Appliances
Programmable ADC appliances with L4 and L7 throughput and connection rates

BIG-IP VIPRION Chassis and Blades
Extends your infrastructure by adding blades without disrupting apps or users (sysin)

BIG-IP Virtual Edition
Software-based traffic management, app security, and visibility

Cloud-Native Network Functions
Cloud-native solutions that help you transition to cloud and 5G

F5 rSeries
A fully automatable architecture, and the highest reliability, security and access control for your critical applications.

VELOS Chassis and Blades
Gives you the agility and scale of modern architectures

BIG-IP 软件支持策略

Major Release and Long-Term Stability Release versions supported with active software development

Major Release and Long-Term Stability Release versionsFirst customer shipEnd of Software DevelopmentEnd of Technical SupportLatest maintenance release
17.0.0 April 26, 2022 July 26, 2023 July 25, 2023 N/A
16.1.x July 7, 2021 July 7, 2025 July 7, 2025 16.1.2
15.1.x December 11, 2019 December 11, 2024 December 11, 2024 15.1.5
14.1.x December 11, 2018 December 11, 2023 December 11, 2023 14.1.4
13.1.x December 19, 2017 December 19, 2022 December 19, 2023 13.1.5

Note: EoTS and EoSD will occur on the same date, unless specified otherwise (sysin).

Versions that have not yet reached EoTS

Software version or branchFirst customer shipEnd of Software DevelopmentEnd of Technical Support
12.1.x May 18, 2016 May 18, 2021 May 18, 2022
11.6.x May 10, 20161 May 10, 2021 May 10, 2022

1BIG-IP 11.6.x has entered the Long-Term Stability Release phase with the release of 11.6.1. All subsequent maintenance releases for BIG-IP 11.6.x are covered by this policy. EoSD and EoTS dates for earlier versions are defined by a previous version of this policy.

Minor and/or maintenance versions not listed in this table are past EoTS and no longer supported.

Branches of BIG-IP software that have reached EoL

BIG-IP 17.0.0 发布公告

F5 is excited to announce the release of the following products:

BIG-IP 17.0.0:

This is the latest major BIG-IP release, with new capabilities focused on security updates and enhancements. The release also includes a native integration between F5 Distributed Cloud Bot Defense and the BIG-IP product family. This is the first native integration of products from F5’s Shape Security acquisition with established F5 offerings. This capability and other features enhance and streamline security for enterprises and service providers while simplifying user and administrative experiences.

With BIG-IP 17.0.0, enterprise customers can do the following:

  • Significantly enhance their defense against sophisticated advanced persistent bots with the ability to deploy F5 Distributed Cloud Bot Defense (formerly Shape Integrated Bot Defense) through a new native integration with the BIG-IP system.
  • Assess and improve compliance with the 2021 OWASP Top 10 through a dashboard in F5 Advanced WAF that enables policy changes directly from the dashboard.
  • Migrate and leverage security policies deployed in Advanced WAF to NGINX App Protect through a full JSON declarative policy.
  • Protect against DNS spoofing and enable secure communications through DNS over TLS (DoT) with BIG-IP DNS.
  • Secure against DoS attacks, prevent errors that can lead to dangerous information leakage, and enhance the performance of GraphQL APIs with BIG-IP Advanced WAF.
  • View, prioritize, and address the latest Threat Campaigns by date.
  • Enhance secure OAuth authentication to mobile and publicly facing applications through Proof Key for Code Exchange (PKCE) support in BIG-IP APM.
  • Increase secure authentication to mobile-based services and between mobile devices and apps through JSON Web Encryption (JWE) support for public clients in BIG-IP APM.
  • Support and manage secure access for next-generation and IoT devices that employ ARM64 processors (for example, Microsoft Surface) with F5 Edge Client and BIG-IP APM.
  • Strengthen support for IoT endpoints by leveraging MQTT traffic load balancing for IoT clients in BIG-IP LTM.
  • Simplify and streamline setup and deployment of BIG-IP SSL Orchestrator through an integrated search capability for security policy objects.
  • Support NETSCOUT to analyze traffic decrypted by BIG-IP SSL Orchestrator as part of a service chain.

Service Providers can block malicious IPv6 addresses with F5 IP Intelligence (IPI) and its new third-party integration with a leading threat intelligence vendor (BrightCloud).

In addition to these capabilities and features, BIG-IP 17.0.0 also includes many additional quality improvements and security enhancements also found in the latest releases of BIG-IP 16.1.x.

Note that in accordance with [K5903: BIG-IP software support policy], support for BIG-IP 17.0.x continues for 15 months after the April 26, 2022 release date.

资源

下载地址

BIG-IP 17.0.0, Release date: 04/26/2022

FilenameDescriptionSize
BIGIP-17.0.0-0.0.22.iso Use for upgrades. Does not include EUD. 2510 MB
BIGIP-17.0.0-0.0.22.iso.md5 MD5 file for Use for upgrades. Does not include EUD. 57 Bytes
BIGIP-RECOVERY-17.0.0-0.0.22.iso Use for re-imaging. Includes EUD. 3009 MB
BIGIP-RECOVERY-17.0.0-0.0.22.iso.md5 MD5 file for Use for re-imaging. Includes EUD. 66 Bytes
BIGIP-17.0.0-0.0.22.html BIGIP-17.0.0 release notes 1 MB

BIG-IP 17.0.0_Virtual-Edition, Release 04/26/2022

FilenameDescriptionSize
BIGIP-17.0.0-0.0.22.ALL-vmware.ova Image fileset for VMware ESX/i Server 2397 MB
BIGIP-17.0.0-0.0.22.ALL-vmware.ova.md5 MD5 file for Image fileset for VMware ESX/i Server 68 Bytes
BIGIP-17.0.0-0.0.22.ALL.qcow2.zip Image file set for KVM Red Hat Enterprise Linux/CentOS 2129 MB
BIGIP-17.0.0-0.0.22.ALL.qcow2.zip.md5 MD5 file for Image file set for KVM Red Hat Enterprise Linux/CentOS 67 Bytes
BIGIP-17.0.0-0.0.22.ALL.vhd.zip Image fileset for Microsoft Hyper-V 2131 MB
BIGIP-17.0.0-0.0.22.ALL.vhd.zip.md5 MD5 file for Image fileset for Microsoft Hyper-V 65 Bytes

百度网盘链接:https://sysin.org/blog/f5-big-ip-17/

与[转帖]F5 BIG-IP 17.0.0相似的内容:

[转帖]F5 BIG-IP 17.0.0

https://www.cnblogs.com/sysin/p/16438174.html 目录 BIG-IP 产品概述 BIG-IP BIG-IP Deployment BIG-IP 软件支持策略 BIG-IP 17.0.0 发布公告 资源 下载地址 请访问原文链接:https://sysin.o

[转帖]CVE-2020-5902:F5 BIG-IP 远程代码执行漏洞复现

漏洞复现 Timeline Sec 2020-09-29 9,863 关注我们,一起学安全!本文作者:TeddyGrey@Timeline Sec本文字数:1197阅读时长:3~4min声明:请勿用作违法用途,否则后果自负0x01 简介 F5 BIGIP 链路控制器用于最大限度提升链路性能与可用性的

[转帖]关于F5负载均衡你认识多少?

https://www.cnblogs.com/xiexun/p/10718348.html 网络负载均衡(load balance),就是将负载(工作任务)进行平衡、分摊到多个操作单元上进行执行,例如web服务器、FTP服务器、企业关键应用服务器和其它关键任务服务器等,从而共同完成工作任务。实际上

[转帖]如何在 NGINX 中安全地分发 SSL 私钥

https://my.oschina.net/u/5246775/blog/7812621 原文作者:Owen Garrett of F5 原文链接:如何在 NGINX 中安全地分发 SSL 私钥 转载来源:NGINX 官方网站 NGINX 唯一中文官方社区 ,尽在 nginx.org.cn 本文介

[转帖]

Linux ubuntu20.04 网络配置(图文教程) 因为我是刚装好的最小系统,所以很多东西都没有,在开始配置之前需要做下准备 环境准备 系统:ubuntu20.04网卡:双网卡 网卡一:供连接互联网使用网卡二:供连接内网使用(看情况,如果一张网卡足够,没必要做第二张网卡) 工具: net-to

[转帖]

https://cloud.tencent.com/developer/article/2168105?areaSource=104001.13&traceId=zcVNsKTUApF9rNJSkcCbB 前言 Redis作为高性能的内存数据库,在大数据量的情况下也会遇到性能瓶颈,日常开发中只有时刻

[转帖]ISV 、OSV、 SIG 概念

ISV 、OSV、 SIG 概念 2022-10-14 12:29530原创大杂烩 本文链接:https://www.cndba.cn/dave/article/108699 1. ISV: Independent Software Vendors “独立软件开发商”,特指专门从事软件的开发、生产、

[转帖]Redis 7 参数 修改 说明

2022-06-16 14:491800原创Redis 本文链接:https://www.cndba.cn/dave/article/108066 在之前的博客我们介绍了Redis 7 的安装和配置,如下: Linux 7.8 平台 Redis 7 安装并配置开机自启动 操作手册https://ww

[转帖]HTTPS中间人攻击原理

https://www.zhihu.com/people/bei-ji-85/posts 背景 前一段时间,公司北京地区上线了一个HTTPS防火墙,用来监听HTTPS流量。防火墙上线之前,邮件通知给管理层,我从我老大那里听说这个事情的时候,说这个有风险,然后意外地发现,很多人原来都不知道HTTPS防

[转帖]关于字节序(大小端)的一点想法

https://www.zhihu.com/people/bei-ji-85/posts 今天在一个技术群里有人问起来了,当时有一些讨论(不完全都是我个人的观点),整理一下: 为什么网络字节序(多数情况下)是大端? 早年设备的缓存很小,先接收高字节能快速的判断报文信息:包长度(需要准备多大缓存)、地