Manual Chapter : BIG-IQ System Introduction

Applies To:

Show Versions Show Versions

BIG-IQ Centralized Management

  • 5.4.0
Manual Chapter

BIG-IQ Centralized Management documentation set

BIG-IQ Centralized Management documentation set is located on AskF5 at https://support.f5.com. Click the Product Manuals link under Resources, and select BIG-IQ Centralized Management from the product list, and select the appropriate version.

Title Use to:
F5® BIG-IQ® Centralized Management: Licensing and Initial Setup License and set up the BIG-IQ system in your network.
F5® BIG-IQ® Centralized Management: Authentication, Roles, and User Management
  • Configure authentication through a 3rd-party provider (LDAP, RADIUS or TACAS+) .
  • Use built-in and custom roles to manage user access.
F5® BIG-IQ® Monitoring and Reports
  • Set up health monitoring and alerts and statistics collections
  • Manage audit logs, run reports, and analyze statistics.
  • Troubleshooting Access reports.
F5® BIG-IQ® Centralized Management: Device
  • Discover BIG-IP devices and import F5 services.
  • Deploy software images, licenses, SSL certificates, backup files, and configurations.
F5® BIG-IQ® Local Traffic & Network Implementations Manage:
  • Local Traffic profiles
  • Virtual servers
  • Network objects
  • iRules
  • Applications and application templates
As well as configuring an IPsec tunnel and event viewing.
F5® BIG-IQ® Centralized Management: Security

Manage:

  • Object pinning
  • Firewall contexts
  • Address and port lists
  • Rules, rule lists, policies, and rule reports
  • Service, timer, and port misuse policies
  • NAT policies and translations
  • FQDN resolvers
  • Change verifications
  • External logging devices
  • Shared security for virtual servers, DoS profiles, device DoS configurations, network whitelists, logging profiles, and SSH profiles
  • Bot signatures and bot signature categories
  • IP intelligence settings
  • External redirection settings
  • Application Securities Policies
  • Signature files, custom attack signatures and sets
  • Web Application Security event logs
F5® BIG-IQ® Centralized Management: Access
  • Configure an Access group, HA pair, and cluster.
  • Manage access groups.
  • View and edit access configurations.
  • Configure authentication for Active Directory, SecuID, HTTP, Oracle Access Manager, OCSP responder, CRLDP, and Kerberos.
  • Manage audit logs
F5® Platform Guide: BIG-IQ® 7000 Series Set up and manage the BIG-IQ 7000 hardware platform.
   

About BIG-IQ Centralized Management

F5® BIG-IQ® Centralized Management is a tool that helps you manage BIG-IP devices, and all of their services (such as LTM, AFM, ASM and so forth), from one location. BIG IQ can manage up to 200 (physical, virtual, or vCMP) BIG-IP devices and handle licensing for up to 5,000 unmanaged devices.

Using BIG-IQ helps you more efficiently manage your BIG-IP devices through a single pane of glass view. That means you and your co-workers don't have to log in to individual BIG-IP systems to get your job done. You can discover, upgrade, deploy policy changes, manage license, and more from just one location.

From BIG-IQ, you can manage a variety of tasks from software updates to health monitoring and traffic to security. And because permissions for users are role-based, you can limit access to just a few trusted administrators to minimize downtime and potential security issues. You also have the ability to allow users to view or edit only those BIG-IP objects they need to do their job.

Here's an example of how BIG-IQ can fit into a data center.

BIG-IQ navigation overview

F5® BIG-IQ® Centralized Management includes navigation, search tools, and a customizable user interface to help you complete your tasks efficiently and find objects easily.

  • Customized interactions with System and Network Security views There are a few customizable viewing options for the System and Network Security views. You can specify the amount of time that passes before BIG-IQ logs you out when the system is idle and what screen displays when you log back in. If you're using the Network Security service, you can specify what types of firewalls are displayed in the menu, have rule lists in policies auto expand, treat terms you search for as a filter, and specify default values for columns.
  • Global search, related content, and preview pane

    BIG-IQ has a robust and interactive global search feature that allows you to easily find a specific content and related content. From any screen, you can click the magnifying glass icon in the upper-right corner of the screen and type a search string. Search results are grouped by content type. From the results, you can click an object to go directly to that object's properties screen in BIG-IQ.

  • Flexible access to objects and configuration options

    For some objects, you can view and edit settings that are located in other places in the user interface, without having to stop what you're doing and navigate to another part of BIG-IQ. For example, you could be editing a firewall policy and find an address list in the toolbox that you want to look at. Right there, you can click the address to access the details, and then view or edit it as you want.

    You can also configure some types of objects from different places in BIG-IQ, depending on what your user role is or what work flow you're in. For example, you can create an access group from the Configuration area of BIG-IQ, as well as from the Devices area. This makes it convenient for you to access during other tasks you're doing in different areas of BIG-IQ.

  • Filters

    For each screen that contains a list, you can use a context-sensitive filter to search on a term, and then narrow your search further to view only those items that are relevant to you at the moment. For example, say you wanted to see local traffic and network audit logs. You can use the search on local traffic, and further refine what is displayed by filtering again on network audit logs.

  • Customization and sorting columns

    You can customize the columns that display in each screen that has a list, hiding any information that isn't important to you, as well as rearrange the order the columns display, and sort objects in the list. This helps you to focus on only those attributes that are relevant to you.

Use global search to access associated objects from any screen

BIG-IQ® Centralized Management makes it easy for you to perform a search for specific details of your configuration across all your managed devices. From the content that is returned, you can access everything associated with that content, regardless of where it is on BIG-IQ. For example, if you search on a specific self-IP address, the results give you access to other content related to that self-IP address. We call this global search.

Global search is a powerful feature that gives you quick access to all objects that contain a certain string. This can give you insight about how objects are relate, even when they're running different services, devices, and so forth.

Important: BIG-IQ global search returns only the content specific to your user role privileges. For example, if your user role doesn't have privileges for content associated with security, content specific only to security does not display.
  1. On any screen, click the icon in the upper right corner.
    The global search popup screen opens.
  2. Into the search field, type all or part of a string you want to search for.
  3. If you want to specify search options, click the arrow next to the search field and select the options you want and click the Enter key.
    The screen refreshes to display content associated with your search term, organized by type.
  4. Click the object link to view the details for an object.
    Tip: You can navigate back to the results after you click on an object, by clicking the magnifying glass on upper right side of the screen again.
  5. If you want to clear the search results, click the X next to the BIG-IQ Search field of the popup window.

Customize how your object lists display

Only after you discover devices and their associated objects, can you view the devices and the related objects in object lists on various screens.
If you need to see only certain information about a list of objects and/or information displayed in a certain way, you can customize the way the screen lists content.
  1. Navigate to a screen that contains a list of objects.
    For example, Devices > SOFTWARE MANAGEMENT > Software Images .
  2. To limit the number of columns you want to view, click the gear icon on the far right of the screen and deselect the columns you don't want displayed.
  3. To customize the order in which the columns display, click the name of the column, drag it to, and drop it in another location.
  4. To sort a list in ascending or descending order, hover next to the column name and click the up or down arrow.

Filter an object list

For each screen that contains an object list, you can narrow the list to display only specific items, phrases, or numbers. This helps you easily navigate long lists and find what you need quickly.
  1. Navigate to a screen that contains a list of objects.
    For example, Devices > BIG-IP DEVICES .
  2. In the Filter field located towards the top of the screen, type a term, phrase, or number, and press the Enter key.
    Tip: By default, BIG-IQ uses this filter on anything that matches any field on the screen, so this can be a partial term, phrase or number. For example, if you wanted to see only objects that contained the number 191, you'd type 191.
    Tip: To limit the filter to a specific object type, click the down arrow next to the search field and select the type of object you're looking for. To require the term match exactly, click Exact.
    The screen refreshes to display only those items that include or exactly match the term you used for a filter. The filter you used displays at the top of the list.
  3. To further limit the results displayed, type another term in the Filter field, selecting options from the filter menu as you did before.
  4. To view the properties of an object, click the object's name.
    Tip: Click the back button to return to the filter results.
  5. To remove a filter, at the top of the list, click the X next to a filter.

Set preferences for BIG-IQ user interface

Only after you license and finish the initial setup for BIG-IQ® Centralized Management, can you specify a few preferences for the user interface.
Setting user preferences customizes your view into BIG-IQ.
Note: The navigation objects and screens you see depend on your user role.
  1. At the top of the screen, click System.
  2. On the left, click USER PREFERENCES towards the bottom of the screen.
  3. You can edit the user preferences for the overall BIG-IQ system by clicking the Edit button.
  4. Click Network Security and the Edit button to edit preferences for the Security service.
Click the icon at the top right of the screen for more information about these options.