The load balancer standing in front of your systems, and the bodyguard too. One device solves two problems: must not go down, and must not be breached.
ADC (Application Delivery Controller) is, in plain terms, a load balancer that sits in front of your servers. It does three things:
A WAF (Web Application Firewall) is a firewall that understands web traffic. A regular firewall only looks at IP addresses and ports. A WAF inspects the contents of HTTP requests to detect attacks such as SQL injection and XSS.
An ADC already sits on the path all traffic must take. Adding inspection is easiest done by turning on a WAF module on the same device: no new hardware to buy, no routing to redesign, one purchase solving two problems.
Modules are licensed separately and can be purchased individually. The product line has been renamed in recent years; old and new names are listed together below.
Load balancing, health checks, and SSL offload, with iRules for custom traffic handling. Hardware is rSeries / VELOS.
Formerly known as Advanced WAF, and ASM before that; the old names are still commonly used in the field. Covers OWASP Top 10, bot detection, L7 DoS, and API protection.
APM access control (SSL VPN / SSO / MFA), AFM network firewall, BIG-IP DNS (formerly GTM) for cross-site routing and disaster recovery, and SSL Orchestrator for decryption orchestration.
One of the most widely used web server and reverse proxy software packages; the open-source version is free. The commercial NGINX Plus / One editions add centralized management and vendor support. F5 WAF for NGINX was formerly called NGINX App Protect WAF.
No hardware to buy; just route traffic through it. Includes cloud WAF, bot protection, DDoS mitigation, and API security.
A software edition that runs on a single virtual machine; it can run on your existing virtualization or hyperconverged platform, with no hardware purchase needed.
Choosing a version is not about picking the newest one, but the one whose support period will outlast your maintenance contract.
Supported until January 2029. A mature version that has been running in the field for years, and the first choice for upgrading an existing environment.
Ships in May 2026, supported until May 2029. Suited to new purchases or a full replacement.
Note: v21.0 is a short-term support release; technical support ended on 6 August 2026, and it is not recommended for new projects. F5's current roadmap is to carry the existing TMOS platform forward and modernize it through 2029. Budget using the two LTS lines above.
Covering on-premises, hybrid, and cloud under one brand is F5's biggest differentiator. Which form to choose depends on where your systems sit.
The device sits in your own data center, and traffic never leaves it. Suited to financial services, healthcare, and government bodies whose data cannot leave the country.
Deployed alongside the application and can be built into CI/CD, with no changes to the network architecture. Suited to teams with DevOps in place.
Subscription-based, with no hardware to buy. Suited to systems already on public cloud, or to extending on-premises policy into the cloud.
The return on investment is clearest in the four situations below.
For the needs below, other solutions are a better fit; selection depends on where your systems sit and their scale.
When there is no load balancing requirement yet, a cloud or software-form WAF is worth evaluating first.
See the WAF solutionF5 sits at the L4-L7 application layer. For switches and wireless access points, see our enterprise networking solutions.
See Enterprise NetworkingBefore traffic grows, a software form or cloud subscription keeps deployment cost proportionate to scale.
See how to choose a WAFThe device is only one part; configuration and ongoing tuning decide whether it succeeds.
Tracking vendor version updates and security advisories is included in annual maintenance. In practice, risk is kept in check with three basic settings: the management interface is not exposed to the internet, management access is restricted by source IP, and the version is kept at the vendor's recommended patch level. These three items are fixed checks in the annual health check. Regression testing is scheduled separately after any update.
We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services; we do not use vendor logos and claim no authorized relationship.
Selection comes down to where the protection sits: the internet edge, the data center entrance, or alongside your containers. Which brand is better is secondary. The decision approach is set out in how to choose a WAF; you can also start with Web & API Protection (WAF), and for the virtual machine form see hyperconverged platforms.
Trademark notice: F5, BIG-IP, and NGINX are trademarks or registered trademarks of F5, Inc. This page is not authorized, sponsored, or endorsed by F5, Inc.
Want to confirm whether on-premises, container, or cloud is the right form? Start with a current-state assessment.
Contact us See our services Back to BrandsLeave your contact details and a description of your needs, and an engineer will follow up to help assess architecture planning, deployment approach, and the scope of annual maintenance.