F5® Application Delivery and Application Protection

The load balancer standing in front of your systems, and the bodyguard too. One device solves two problems: must not go down, and must not be breached.

F5 — Application Delivery & Security
BIG-IP® / NGINX® / Distributed Cloud
We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services.
Load balancing WAF protection SSL offload Disaster recovery

What is ADC / load balancing

ADC (Application Delivery Controller) is, in plain terms, a load balancer that sits in front of your servers. It does three things:

  • Distributes traffic: with three or five backend servers, connections are spread evenly, so peaks don't overload any one of them.
  • Automatically routes around failed hosts: continuous health checks stop sending work to a host once it goes down, usually without users noticing.
  • SSL offload: moves CPU-intensive encryption and decryption onto the ADC, freeing servers to focus on running applications.

Why F5 is often sold together with WAF

A WAF (Web Application Firewall) is a firewall that understands web traffic. A regular firewall only looks at IP addresses and ports. A WAF inspects the contents of HTTP requests to detect attacks such as SQL injection and XSS.

An ADC already sits on the path all traffic must take. Adding inspection is easiest done by turning on a WAF module on the same device: no new hardware to buy, no routing to redesign, one purchase solving two problems.

Main products

Modules are licensed separately and can be purchased individually. The product line has been renamed in recent years; old and new names are listed together below.

BIG-IP LTM

Load balancing, health checks, and SSL offload, with iRules for custom traffic handling. Hardware is rSeries / VELOS.

F5 WAF for BIG-IP

Formerly known as Advanced WAF, and ASM before that; the old names are still commonly used in the field. Covers OWASP Top 10, bot detection, L7 DoS, and API protection.

APM/AFM/DNS/SSLO

APM access control (SSL VPN / SSO / MFA), AFM network firewall, BIG-IP DNS (formerly GTM) for cross-site routing and disaster recovery, and SSL Orchestrator for decryption orchestration.

NGINX and F5 WAF for NGINX

One of the most widely used web server and reverse proxy software packages; the open-source version is free. The commercial NGINX Plus / One editions add centralized management and vendor support. F5 WAF for NGINX was formerly called NGINX App Protect WAF.

F5 Distributed Cloud WAAP

No hardware to buy; just route traffic through it. Includes cloud WAF, bot protection, DDoS mitigation, and API security.

BIG-IP Virtual Edition(VE)

A software edition that runs on a single virtual machine; it can run on your existing virtualization or hyperconverged platform, with no hardware purchase needed.

Current version status

Choosing a version is not about picking the newest one, but the one whose support period will outlast your maintenance contract.

BIG-IP 17.5.x

Supported until January 2029. A mature version that has been running in the field for years, and the first choice for upgrading an existing environment.

BIG-IP 21.1.x

Ships in May 2026, supported until May 2029. Suited to new purchases or a full replacement.

Note: v21.0 is a short-term support release; technical support ended on 6 August 2026, and it is not recommended for new projects. F5's current roadmap is to carry the existing TMOS platform forward and modernize it through 2029. Budget using the two LTS lines above.

Three deployment forms

Covering on-premises, hybrid, and cloud under one brand is F5's biggest differentiator. Which form to choose depends on where your systems sit.

BIG-IP hardware or VE

The device sits in your own data center, and traffic never leaves it. Suited to financial services, healthcare, and government bodies whose data cannot leave the country.

NGINX software form

Deployed alongside the application and can be built into CI/CD, with no changes to the network architecture. Suited to teams with DevOps in place.

F5 Distributed Cloud

Subscription-based, with no hardware to buy. Suited to systems already on public cloud, or to extending on-premises policy into the cloud.

Who this suits

The return on investment is clearest in the four situations below.

1
Data cannot leave the country
When traffic cannot be sent to a node outside the country, an on-premises solution is one of the few options that work.
2
Audits require traffic to be controllable
ISO 27001, regulator inspections, or a tender specification that states ADC and WAF outright.
3
High availability and security are both needed
The availability budget usually sits with the IT department and the security budget with the audit department; one device answers to both.
4
Already have BIG-IP, want to add protection
Traffic already passes through it, so adding a module needs no architecture change and has minimal impact.

Solutions for other scenarios

For the needs below, other solutions are a better fit; selection depends on where your systems sit and their scale.

Only application-layer protection is needed

When there is no load balancing requirement yet, a cloud or software-form WAF is worth evaluating first.

See the WAF solution
Switch and Wi-Fi replacement

F5 sits at the L4-L7 application layer. For switches and wireless access points, see our enterprise networking solutions.

See Enterprise Networking
Single backend, no on-site data center

Before traffic grows, a software form or cloud subscription keeps deployment cost proportionate to scale.

See how to choose a WAF

Scope of services

The device is only one part; configuration and ongoing tuning decide whether it succeeds.

Assessment and architecture planning
Site survey, requirements interviews, architecture design, selection recommendations, POC, and TCO estimates.
Build and configuration tuning
Rack mounting, cabling, and installation, plus VIP, server pool, health check, and cutover configuration.
System migration
Migration of existing device configurations, data transfer for equipment being replaced, and reconnection after virtual machine migration.
WAF policy tuning
Traffic is observed in detection mode first to tune out false positives, and blocking is switched on only after confirming there is no impact on the business.
Version upgrade planning
Reviewing current versions and licenses, and planning the upgrade path and maintenance window to 17.5.x or 21.1.x LTS.
Training and annual maintenance
Operational training and documentation handover; annual maintenance includes business-hours support, troubleshooting, and periodic health checks.

FAQ

How do you handle vendor security advisories and version updates?

Tracking vendor version updates and security advisories is included in annual maintenance. In practice, risk is kept in check with three basic settings: the management interface is not exposed to the internet, management access is restricted by source IP, and the version is kept at the vendor's recommended patch level. These three items are fixed checks in the annual health check. Regression testing is scheduled separately after any update.

What is your relationship with F5?

We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services; we do not use vendor logos and claim no authorized relationship.

How does this compare with other WAF options?

Selection comes down to where the protection sits: the internet edge, the data center entrance, or alongside your containers. Which brand is better is secondary. The decision approach is set out in how to choose a WAF; you can also start with Web & API Protection (WAF), and for the virtual machine form see hyperconverged platforms.

Trademark notice: F5, BIG-IP, and NGINX are trademarks or registered trademarks of F5, Inc. This page is not authorized, sponsored, or endorsed by F5, Inc.

Want to confirm whether on-premises, container, or cloud is the right form? Start with a current-state assessment.

Contact us See our services Back to Brands

Contact us about F5 deployment planning

Leave your contact details and a description of your needs, and an engineer will follow up to help assess architecture planning, deployment approach, and the scope of annual maintenance.

Send an enquiry
LINE Ask us on LINE