Forum Discussion
What is the difference between BIG-IP APM and BIG-IP LTM?
HI , best wishes for your test prep! For test purposes, the Local Traffic Manager is about application delivery, so more along the lines of L4-L7 proxy functionality, monitoring, HA, scale-out, protocol validation, etc. The ASM is a web application firewall (which is valid for the test version, but is End of Sale, the next-gen of the ASM is now the Advanced WAF product), and primarily dials in on L7 security functionality.
Thanks! As I understand it, BIG-IP is a full proxy in general, thus any other F5 product (e.g. LTM, but also APM or ASM) is a full proxy as well. Am I right, if I say that LTM provides overview of all the processes that happen on L4-L7? Actually I made a mistake and wanted to ask about BIG-IP APM vs LTM, not ASM.
- JRahmJun 28, 2021Admin
The proxy sits in between all client and server flows (except where explicitly bypassed like with HW acceleration) in the TMOS architecture on BIG-IP platforms. APM and ASM are plugins on-top of TMOS, and behave a little differently. For example, in iRules, an HTTP_RESPONSE event is processed before ASM (or APM) handles the response from the server, so anything you want to manipulate between ASM and the client in the response would have to happen after ASM hands it back off to TMM, and that can be done in the HTTP_RESPONSE_RELEASE event. See here for more details.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com