Manual Chapter : Network HSM Overview

Applies To:

  • BIG-IP APM

    21.0.0, 17.5.1, 17.5.0, 17.5.1, 17.5.0, 17.1.3, 17.1.2, 17.1.1, 17.1.0, 17.1.3, 17.1.2, 17.1.1, 17.1.0

  • BIG-IP LTM

    21.0.0, 17.5.1, 17.5.0, 17.1.3, 17.1.2, 17.1.1, 17.1.0

  • BIG-IP DNS

    21.0.0, 17.5.1, 17.5.0, 17.1.3, 17.1.2, 17.1.1, 17.1.0

  • BIG-IP ASM

    21.0.0, 17.5.1, 17.5.0, 17.1.3, 17.1.2, 17.1.1, 17.1.0

Network HSM Overview

For information on setting up and managing keys for network hardware security modules (HSMs) that are supported with BIG-IP systems, see the guide for your specific network HSM:

  • BIG-IP System and SafeNet Luna SA HSM: Implementation

  • BIG-IP System and nCipher HSM: Implementation

    Note: The Thales HSM name has changed to nCipher HSM

  • BIG-IP System and Network HSM: Implementation

    Note: This guide includes these network HSM vendors:

    • Amazon CloudHSM
    • Equinix SmartKey HSM
    • SafeNet Data Protection on Demand (DPoD) HSM
    • Atos (Bull Trustway Proteccio) HSM

If the Network FIPS add-on license is combined with a Platform FIPS or VE FIPS add-on license, you need to decide which location to use to store your keys based on the certificate and SSL Policy. You would need to set up and administer the network HSM using the instructions for your specific network HSM. For keys not stored in the Network HSM, see the key information for the Platform FIPS or VE FIPS.

The Network FIPS add-on license should not be used on an Embedded FIPS system.