BIG-IP Cloud-Native Network Functions (CNFs)
Part of BIG-IP Cloud-Native Edition, BIG-IP CNFs deliver proven BIG-IP traffic management and security services as Kubernetes-native network functions. Simplify operations, scale dynamically, and modernize service provider and enterprise infrastructure.
Bring BIG-IP services to Kubernetes
Deploy BIG-IP application delivery, networking, and security services as Kubernetes-native CNFs. Automate operations with Kubernetes APIs, scale resources with demand, and consolidate critical services on a proven BIG-IP data plane for service provider and enterprise environments.
Operate Kubernetes natively
Use declarative APIs and Kubernetes orchestration to automate deployment and lifecycle operations.
Scale resources efficiently
Scale cloud-native services with changing traffic demands while optimizing infrastructure utilization.
Consolidate critical services
Combine application delivery, firewall, DDoS, CGNAT, DNS, policy, and traffic management services.
Extend proven BIG-IP capabilities
Bring familiar BIG-IP capabilities into modern Kubernetes environments without relying on VMs.
Modernize network services with cloud-native agility
Cloud-native operations
Automate deployment and lifecycle management
Use Kubernetes APIs, custom resources, Helm, and CI/CD workflows to deploy, configure, scale, and upgrade BIG-IP CNFs. A common Kubernetes control plane reduces manual processes and helps teams modernize operations without carrying forward VM-centric lifecycle complexity.
Elastic scale
Scale services with demand
Scale data-plane resources independently and use cloud-native traffic distribution to match capacity to changing demand. Optimize infrastructure utilization while maintaining the performance and resiliency required for high-volume service provider, edge, and enterprise workloads.
Service consolidation
Unify critical BIG-IP services in Kubernetes
Consolidate application delivery, CGNAT, DNS, AFM firewall, DDoS, IPS, PEM subscriber policy, and traffic steering on a shared containerized architecture. Reduce service-chain hops, infrastructure overhead, and operational silos while extending familiar BIG-IP capabilities into Kubernetes.
Unified traffic management and security
Protect critical traffic with BIG-IP security
Apply stateful firewall rules, DDoS protection, intrusion prevention, IP intelligence, and secure connectivity to cloud-native traffic. Enforce protection close to applications and network services while maintaining the scale and control required for distributed Kubernetes environments.
Core Capabilities
Kubernetes-native ops
Deploy and manage services with Kubernetes APIs.
Application delivery
L4-L7 load balancing for apps and services.
Network security
Firewall, DDoS, IPS, and IP intelligence.
Carrier-grade NAT
Scale IPv4/IPv6 translation and address use.
DNS and GSLB
Accelerate DNS and steer traffic globally.
Policy enforcement
Apply subscriber-aware traffic policies.
Traffic steering
Distribute flows efficiently across CNF pods.
Secure connectivity
Protect traffic with cloud-native IPsec.
BIG-IP Cloud-Native Network Functions
Modular cloud-native services for Kubernetes
Deploy CNFs where Kubernetes runs
Deploy CNFs where Kubernetes runs
Run BIG-IP CNFs on supported Kubernetes platforms on bare metal infrastructure. Use Helm and Kubernetes APIs for consistent deployment and lifecycle management.
Private cloud
Modernize enterprise applications and traffic management and security services in private data centers while aligning operations with existing Kubernetes workflows.
Service provider and edge
Deploy cloud-native traffic management, security, DNS, and subscriber services across 5G core, N6/SGi-LAN, MEC, broadband, and edge environments.
Public cloud
Extend CNF services to supported public-cloud Kubernetes environments for cloud-native applications and consistent multicloud operations.
DPU acceleration
Use DPU acceleration for supported services and configurations to offload traffic processing and preserve host resources.
Technology alliances
Extend cloud-native infrastructure with trusted partners
Optimize Kubernetes networking from core to edge
F5 works with leading infrastructure partners to simplify and accelerate cloud-native deployments. Run BIG-IP CNFs on Red Hat OpenShift and Microsoft Azure Operator Nexus, and use NVIDIA BlueField DPU acceleration for supported services and use cases that require greater performance, efficiency, and infrastructure scale.



Resources
Enterprise and Kubernetes
Service provider
Technical resources
CLOUD DOC
CLOUD DOC
CLOUD DOC
CLOUD DOC
CLOUD DOC
Release updates
FAQs
BIG-IP Cloud-Native Network Functions (CNFs) are modular BIG-IP traffic management and security services designed to run natively in Kubernetes. As part of BIG-IP Cloud-Native Edition, CNFs use Kubernetes APIs and orchestration to automate deployment, scaling, configuration, and lifecycle operation
BIG-IP Cloud-Native Network Functions are a core part of BIG-IP Cloud-Native Edition. Cloud-Native Edition brings together BIG-IP CNFs, BIG-IP Next for Kubernetes, and BIG-IP eBPF Observability to provide traffic management, security, application delivery, infrastructure services, and visibility for Kubernetes environments. CNFs deliver the modular BIG-IP services within that broader Cloud-Native Edition architecture.
BIG-IP CNFs support cloud-native application delivery, AFM firewall and DDoS protection, intrusion prevention, carrier-grade NAT (CGNAT), DNS and global server load balancing, PEM subscriber-aware policy, traffic steering, and secure connectivity. Available capabilities vary by release and deployment configuration.
CNFs run as containerized services managed by Kubernetes rather than packaging network functions inside virtual machines. This enables Kubernetes-native automation, horizontal scaling, more granular resource allocation, and independent lifecycle management while reducing the infrastructure overhead associated with VM-based deployments.
BIG-IP CNFs support cloud-native traffic management and application delivery, firewall and DDoS protection, intrusion prevention, carrier-grade NAT (CGNAT), DNS caching, DNS firewall, global server load balancing (GSLB), subscriber-aware policy enforcement, traffic steering, and secure connectivity. Available capabilities vary by release and deployment configuration.
No. Service providers use BIG-IP CNFs for use cases such as 5G core, N6/SGi-LAN, CGNAT, DNS caching, DNS Firewall, GSLB, AFM firewall DDoS protection, and PEM subscriber policy. Enterprises can use the same cloud-native architecture for traffic management, application delivery, network security, DNS, secure connectivity, and other Kubernetes-based services where scalable BIG-IP capabilities are required.
BIG-IP CNFs can run on supported Kubernetes platforms across private cloud, service provider cloud, core, and edge environments. Supported deployments include Kubernetes platforms such as Red Hat OpenShift, Robin, AON, and other validated Kubernetes environments, with hardware acceleration available for supported configurations.