Stay current to protect your environment with F5 Hardened Releases.Learn more

BIG-IP Cloud-Native Network Functions (CNFs)

Part of BIG-IP Cloud-Native Edition, BIG-IP CNFs deliver proven BIG-IP traffic management and security services as Kubernetes-native network functions. Simplify operations, scale dynamically, and modernize service provider and enterprise infrastructure.

Bring BIG-IP services to Kubernetes

Deploy BIG-IP application delivery, networking, and security services as Kubernetes-native CNFs. Automate operations with Kubernetes APIs, scale resources with demand, and consolidate critical services on a proven BIG-IP data plane for service provider and enterprise environments.

Cloud native functions

Operate Kubernetes natively

Use declarative APIs and Kubernetes orchestration to automate deployment and lifecycle operations.

Scale resources efficiently

Scale cloud-native services with changing traffic demands while optimizing infrastructure utilization.

Consolidate critical services

Combine application delivery, firewall, DDoS, CGNAT, DNS, policy, and traffic management services.

Extend proven BIG-IP capabilities

Bring familiar BIG-IP capabilities into modern Kubernetes environments without relying on VMs.

Modernize network services with cloud-native agility

Cloud-native operations

Automate deployment and lifecycle management

Use Kubernetes APIs, custom resources, Helm, and CI/CD workflows to deploy, configure, scale, and upgrade BIG-IP CNFs. A common Kubernetes control plane reduces manual processes and helps teams modernize operations without carrying forward VM-centric lifecycle complexity.

cloud-gear-equal-sign

Elastic scale

Scale services with demand

Scale data-plane resources independently and use cloud-native traffic distribution to match capacity to changing demand. Optimize infrastructure utilization while maintaining the performance and resiliency required for high-volume service provider, edge, and enterprise workloads.

cloud-red-arro-blue-cloud-gear

Service consolidation

Unify critical BIG-IP services in Kubernetes

Consolidate application delivery, CGNAT, DNS, AFM firewall, DDoS, IPS, PEM subscriber policy, and traffic steering on a shared containerized architecture. Reduce service-chain hops, infrastructure overhead, and operational silos while extending familiar BIG-IP capabilities into Kubernetes.

servers-round-circle-square

Unified traffic management and security

Protect critical traffic with BIG-IP security

Apply stateful firewall rules, DDoS protection, intrusion prevention, IP intelligence, and secure connectivity to cloud-native traffic. Enforce protection close to applications and network services while maintaining the scale and control required for distributed Kubernetes environments.

lock-cloud-wall-equal-signs

Core Capabilities

Kubernetes-native ops

Deploy and manage services with Kubernetes APIs.

Application delivery

L4-L7 load balancing for apps and services.

Network security

Firewall, DDoS, IPS, and IP intelligence.

Carrier-grade NAT

Scale IPv4/IPv6 translation and address use.

DNS and GSLB

Accelerate DNS and steer traffic globally.

Policy enforcement

Apply subscriber-aware traffic policies.

Traffic steering

Distribute flows efficiently across CNF pods.

Secure connectivity

Protect traffic with cloud-native IPsec.

BIG-IP Cloud-Native Network Functions

Modular cloud-native services for Kubernetes

cnf diagram 2

Deploy CNFs where Kubernetes runs

Deploy CNFs where Kubernetes runs

Run BIG-IP CNFs on supported Kubernetes platforms on bare metal infrastructure. Use Helm and Kubernetes APIs for consistent deployment and lifecycle management.

Private cloud

Modernize enterprise applications and traffic management and security services in private data centers while aligning operations with existing Kubernetes workflows.

Service provider and edge

Deploy cloud-native traffic management, security, DNS, and subscriber services across 5G core, N6/SGi-LAN, MEC, broadband, and edge environments.

Public cloud

Extend CNF services to supported public-cloud Kubernetes environments for cloud-native applications and consistent multicloud operations.

DPU acceleration

Use DPU acceleration for supported services and configurations to offload traffic processing and preserve host resources.

Technology alliances

Extend cloud-native infrastructure with trusted partners

Optimize Kubernetes networking from core to edge

F5 works with leading infrastructure partners to simplify and accelerate cloud-native deployments. Run BIG-IP CNFs on Red Hat OpenShift and Microsoft Azure Operator Nexus, and use NVIDIA BlueField DPU acceleration for supported services and use cases that require greater performance, efficiency, and infrastructure scale.

Red hat logo
microsoft azure
nvidia logo

Resources

FAQs

BIG-IP Cloud-Native Network Functions (CNFs) are modular BIG-IP traffic management and security services designed to run natively in Kubernetes. As part of BIG-IP Cloud-Native Edition, CNFs use Kubernetes APIs and orchestration to automate deployment, scaling, configuration, and lifecycle operation

BIG-IP Cloud-Native Network Functions are a core part of BIG-IP Cloud-Native Edition. Cloud-Native Edition brings together BIG-IP CNFs, BIG-IP Next for Kubernetes, and BIG-IP eBPF Observability to provide traffic management, security, application delivery, infrastructure services, and visibility for Kubernetes environments. CNFs deliver the modular BIG-IP services within that broader Cloud-Native Edition architecture.

BIG-IP CNFs support cloud-native application delivery, AFM firewall and DDoS protection, intrusion prevention, carrier-grade NAT (CGNAT), DNS and global server load balancing, PEM subscriber-aware policy, traffic steering, and secure connectivity. Available capabilities vary by release and deployment configuration.

CNFs run as containerized services managed by Kubernetes rather than packaging network functions inside virtual machines. This enables Kubernetes-native automation, horizontal scaling, more granular resource allocation, and independent lifecycle management while reducing the infrastructure overhead associated with VM-based deployments.

BIG-IP CNFs support cloud-native traffic management and application delivery, firewall and DDoS protection, intrusion prevention, carrier-grade NAT (CGNAT), DNS caching, DNS firewall, global server load balancing (GSLB), subscriber-aware policy enforcement, traffic steering, and secure connectivity. Available capabilities vary by release and deployment configuration.

No. Service providers use BIG-IP CNFs for use cases such as 5G core, N6/SGi-LAN, CGNAT, DNS caching, DNS Firewall, GSLB, AFM firewall DDoS protection, and PEM subscriber policy. Enterprises can use the same cloud-native architecture for traffic management, application delivery, network security, DNS, secure connectivity, and other Kubernetes-based services where scalable BIG-IP capabilities are required.

BIG-IP CNFs can run on supported Kubernetes platforms across private cloud, service provider cloud, core, and edge environments. Supported deployments include Kubernetes platforms such as Red Hat OpenShift, Robin, AON, and other validated Kubernetes environments, with hardware acceleration available for supported configurations.