Tuesday, March 16, 2010

Rant: F5 LTM and GTM Doesn’t Do External AAA Authorization

February 27, 2008 by Greg Ferro · 3 Comments 

F5 BigIP LTM and GTM does not have any user author­isa­tion cap­ab­il­ity for admin­is­tra­tion by Radius or TACACS. Can you believe that?

They have been pro­du­cing F5 BigIP soft­ware for more than a dec­ade and I can­not believe that cus­tom­ers have not been ask­ing to provide external user author­isa­tion. To com­pare, I have just been con­fig­ur­ing APC Switched Rack Power Distribution bars, and they have Radius author­isa­tion. How can a product cost­ing tens of thou­sands not sup­port this fea­ture when a product worth a few hun­dred can ?

Service Oriented !

My data centres are now being driven to Service Oriented Networking, and without AAA serv­ers I can­not con­trol secur­ity policy to my F5 devices. If I had only one or two of these, this might be OK, but the busi­ness needs are that I MUST have mul­tiple units (and F5 BigIP does not sup­port hyper­vir­tu­al­iz­a­tion or even para­vir­tu­al­iz­a­tion, just a simple resource partition )

Authentication

The F5 does sup­port authen­tic­a­tion, how­ever this means that you must still cre­ate the user account on the F5 and con­fig­ure all the neces­sary group priv­ileges for the user. Not a bril­liant idea when you have around fifty oper­at­ors in a 247 NOC and the staff turnover is high.

Conclusion

F5 seems to be con­cen­trat­ing on nifty fea­tures for Microsoft sys admins (Powershell, iCon­trol) , but miss­ing out on fun­da­ment­als for net­work­ing. I hope someone is listen­ing: external device authen­tic­a­tion and author­isa­tion is a man­dat­ory require­ment in mod­ern net­work­ing, and the cur­rent method in BigIP is not good enough. I have talked about com­par­ing the F5 and ACE here, minus 5 points to F5. for this.

Please rate this post:

  Why Rate Posts?
1 Star - It\\\'s Crud2 Stars - It\\\'s Tosh3 Stars - Something\\\'s missing4 Stars - Needs works5 Stars - Good Enough6 Stars - Good7 Stars - Excellent8 Stars - Brilliant9 Stars - Astonishing10 Stars - Awesomely Godlike? (1 votes, average: 10.00 out of 10)
Loading ... Loading ...

Comments

3 Responses to “Rant: F5 LTM and GTM Doesn’t Do External AAA Authorization”
  1. Christian says:

    I’ve recently ran into the same prob­lem.. very annoying

    BUT —  I have got­ten basic Radius work­ing fine

    also — F5 is a few years ahead of ace, i use ace’s too for vir­tu­al­ized cus­tomer infrastructures

    The ACE is no com­pet­i­tion for the F5 IMO, but i would really like to see F5 imple­ment TACACS very soon

  2. Good Faith Disclosure: I am an F5 employee, one of the ones “…con­cen­trat­ing on nifty fea­tures…” ;-)

    I’ll give you that it’s incon­veni­ent not to have Radius do it for you (and prior to my employ­ment at F5 have ran­ted about this in data cen­ter devices and appli­ances in gen­eral — and stor­age in par­tic­u­lar), but there are two simple facts:

    (1) The data cen­ter is sadly filled with devices and appli­ances that still don’t sup­port Radius, F5 is hardly unique in that sense.

    (2) F5 does a very good job of listen­ing to cus­tom­ers — that is one of the reas­ons I came to the company.

    When cus­tom­ers are asked where devel­op­ment time should be spent, Radius always loses. It always loses because for most organ­iz­a­tions it is a minor impos­i­tion and they can get big­ger bang for their buck if we imple­ment things like Powershell and Control Point. We give the cus­tom­ers what they want — ask­ing them would be a waste of time if we didn’t listen.

    That doesn’t make it less incon­veni­ent — par­tic­u­larly on ini­tial setup — but for most cus­tom­ers that incon­veni­ence is a min­imal part of over­all con­fig­ur­a­tion cost and effort. For those it isn’t, they get basic Radius con­figured, as Christian mentions.

    Remember that this is not core func­tion­al­ity for these products — a dif­fer­en­ti­ator def­in­itely, but not gen­er­ally a buy/​no buy decision point.

    Don.

  3. Greg Ferro says:

    Thanks for your response. I have two points.

    I dis­agree with you on point 1, my data cen­ter is filled with products that do sup­port author­iz­a­tion usu­ally RADIUS or TACACS, but some­times LDAP. In fact, I can’t think of any other product that does not have external author­iz­a­tion. But then, I believe myself to be a pro­fes­sional and I make secur­ity con­scious choices.

    I can see why RADIUS would lose in the devel­op­ment cycle and your point appears valid in this con­text. Let me make this point, if F5 can’t get the basic func­tions in place, how are they going to deliver the main functions ?

    To put it dif­fer­ently, listen­ing to cus­tom­ers when they SAY what they want, and fail­ing to address fun­da­ment­als (or what they actu­ally need) can lead to poor choices. Everyone says they want junk food, even when they know its the wrong choice.

    Addiitonally, I have been ask­ing for Radius authen­tic­a­tion for years, and I am not alone. Check the for­ums for the ‘me too’ on my post. Which cus­tom­ers have you been listen­ing to ?

    Develop all the fancy fea­tures you like, but lets not for­get fun­da­ment­als here. F5 has abrog­ated a primary secur­ity respons­ib­il­ity and it should be addressed.

Speak Your Mind

Tell us what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!