Manual Chapter : New Features in this Version

Applies To:

Show Versions Show Versions

F5OS-A

  • 1.3.0
Manual Chapter

New Features in this Version

Tenants

For information about supported tenants, see the
F5 rSeries platforms
section of the F5 hardware/software compatibility matrix.
This release adds support for tenants running BIG-IP 15.1.8.

Software

System webUI enhancements

  • This release provides a visualization of the CPU Thread/Core statistics on the rSeries webUI dashboard.
  • You can now upload qkview information to iHealth via a web proxy, configurable from the webUI.
  • This release provides several additional webUI enhancements, including support for configuring CA bundles, disabling STP, configuring IPv6 prefix length, enabling chase referrals, using contiguous block MAC allocation, and removing LLDP interfaces.

CLI enhancements

  • You can now upload QKView information to iHealth using a web proxy, configurable from the CLI.
  • This release allows you to restrict access to the management interface from the CLI.
  • This release provides support for a ConfD web token, configurable from the CLI.
  • A CLI show command has been implemented to display total and available resources used for tenants.
  • This release provides several additional CLI enhancements, including support for configuring CA bundles, configuring IPv6 prefix length, and improved output formatting.

L2 inline support

This release adds support for L2 inline service for F5 r10000 and r5000 Series systems, allowing you to pass traffic through one or more service (inspection) devices at Layer 2 (MAC)/Bump-in-the-wire.

sPVA hardware support for AFM

This release adds hardware support for sPVA features for AFM, including enabling hardware DoS protection at a per-endpoint granularity, enabling individual IP addresses to be allow-listed or deny-listed, and enabling hardware-supported DoS protection profiles on a per-fully-qualified virtual server basis. For more information on configuring this feature for your BIG-IP tenant, see
BIG-IP Advanced Firewall Manager: Getting Started
.

SYN cookie protection for F5 r10000 and r5000 Series systems

This release adds global VLAN-based SYN cookie protection for the F5 r10000 and r5000 Series systems.

TCAM support for hardware-based subnet virtual DDoS protection

This release adds support for hardware-based subnet virtual DDoS protection, using a TCAM inside the F5 rSeries FPGAs. This feature enables DoS protection at the subnet level rather than for a fully-qualified IP address; wildcard Allow-Lists and Deny-List, which allows or denies IP subnets; and hardware SYN cookie support for wildcard virtual servers.

Service Provider features

These features are now supported on F5 rSeries platforms with BIG-IP tenant version 15.1.8.
  • ENT
  • TC (Traffic Classification)
  • BPTC (Basic Policy Enforcement Manager Traffic Classification)
  • SD (Service Discovery)
  • DPP (Dynamic Policy Provisioning)
  • DTS (DataSafe)
  • PEMQM (Policy Enforcement Manager Quota Management)
  • CGNAT (Carrier-Grade Network Address Translation)
  • DDOS (Distributed Denial of Service)
Policy Enforcement Manager (PEM) and BIG-IP Policy Enforcement Manager (BPEM) features are supported on some F5 rSeries r10000 and r5000 platforms.

Support for SSH allowed IPs

This release allows you to restrict which IP addresses can access the SSH port (port 22).

Network Time Protocol (NTP)

This release provides support for authenticated Network Time Protocol (NTP) configuration, ensuring that the system clock is synchronized with Coordinated Universal Time (UTC).

DAG support

This release, along with BIG-IP tenant version 15.1.8, adds support for SP-DAG and AH-DAG functionality.