BIG-IP Next Cloud-Native Network Functions (CNFs)

F5 BIG-IP Next CNFs enable a cloud-native solution that is secure, automated, and scalable, critical for the transition to 5G networks.

Perfect for Moving Workloads to a Cloud-Native Architecture


Cloud and cloud-native security

An increasing threat surface, lack of fixed perimeters, increasing volumes of sensitive personal data, and accelerated app and code release cycles make security more challenging. BIG-IP Next Edge Firewall CNF is based on a proven and industry acknowledged security place leader, Advanced Firewall Manager (AFM) with its unique, application-centric design.

  • Firewall, DDoS and IPS - Firewall, DDoS, and Intrusion Prevention System (IPS) technology Based on F5 BIG-IP AFM.
  • CGNAT - Ease IPv6 migration and improve network scalability and security with IPv4 address management. Deploy as part of a security strategy.


Deploying a cloud-native infrastructure

CNF solutions are the perfect form factor for those looking to move workloads to a cloud-native architecture. For mobile service providers implementing 5G, or for fixed-line and cable service providers who are deploying data centers and adopting multi-access edge compute solutions. And large technology companies and enterprises looking to securely deploy revenue-generating apps in a Kubernetes based microservices architecture will benefit from BIG-IP Next CNFs.

Product Overview

Unlock the benefits of a cloud-native solution

A Helm chart with an F5 configuration is sent to the API server on the Kubernetes Control Plane Node. The F5 BIG-IP Controller will deploy the new configurations to the F5 components on the worker nodes and traffic can be sent through the network.

Firewall, DDoS, and Intrusion Prevention System (IPS) technology based on F5’s highly successful BIG-IP Advanced Firewall Manager (AFM).

Enable DNS caching and reduce DNS latency up to 80%.  DoH decrypts and resolves DNS queries over HTTPS without impacting RPS.

Ease IPv6 migration and improve network scalability and security with IPv4 address management.

Improve QoE and ARPU with tools like traffic classification and subscriber awareness.

Core Capabilities

Increase performance by offloading functionality to FPGAs or to Intel SmartNICs.

Offload SSL processing, deploy application delivery and security services anywhere, and protect your applications against the most prevalent attacks.

CNFs include native IPv6 and telco protocol support.

A native Kubernetes API is extended with CRDs to ensure F5 products can be configured properly.

Rapidly develop tailored solutions for multiple apps with iRules.

Platform Support and Integrations

BIG-IP Next Cloud-Native Network Functions (CNF) can be flexibly deployed on Kubernetes cloud-native infrastructure

The Edge Firewall CNF is certified by the Cloud Native Computing Foundation (CNCF).  The CNCF CNF Test Suite is an open-source test suite for telcos validating cloud native principles and best practices. 

Certify partner CNFs interoperability on SPK and Aspen Mesh

F5 and its partners certify onboarding, integration, deployment, and lifecycle management of BIG-IP Next SPK and Aspen Mesh in a cloud-native environment with F5 and vendor CNFs.

Read more about the CNF certification program ›




Watch F5 senior leaders and Heavy Reading Research Director Jim Hodges discuss the evolution to cloud-native network functions (CNFs) during this on-demand webinar.

Next Steps

Find out how F5 products and solutions can enable you to achieve your goals.

Contact F5