Table of Contents
Introduction
F5 BIG-IQ Centralized Management, a key component of the F5 Application Delivery and Security Platform (ADSP), helps teams maintain order and streamline administration of BIG-IP app delivery and security services. In this article, I’ll highlight some of the key features, enhancements, and use cases introduced in the BIG-IQ v8.4.2 release and cover the value of these updates.
Effective management of this complex application landscape requires a single point of control that combines visibility, simplified management and automation tools.
Demo Video
New Features in BIG-IQ 8.4.2
Support for Red Hat OpenShift
BIG-IQ v8.4.2 provides full support and validation for standalone deployments in Red Hat Open Shift (please note that HA deployments are not yet supported). Red Hat OpenShift virtualization is a popular, flexible, and lower-cost alternative to VMware virtual machines. This KVM-based virtualization platform ensures easy, simple migration of application workloads and deployments and works seamlessly with BIG-IP and BIG-IQ 8.4.2+.
The qcow2 image available for download from F5.com is now supported on Red Hat OpenShift:
![]()
Sample yaml file:
New Third-Party CA Management: CyberArk
BIG-IQ v8.4.2 has been updated to support CyberArk Certificate Manager for 3rd-Party CA Management. CyberArk, now the parent company for the Venafi TLS Protect certificate management product, offers a cloud/SaaS version of Venafi (rather than deployable software).
This new product form factor is fully supported in BIG-IQ, making it easy and more flexible to assign, manage, and renew device certificates as part of your BIG-IP management workflows.
AFM Policy Deployment Control
BIG-IQ v8.4.2 introduces per-device AFM Deployment Controls. Only devices with AFM discovered and enabled for Policy Deployment can have policies deployed. This allows you to disable Policy Deployment to specific devices or device groups/clusters without needing to remove AFM Services.
For devices imported with the AFM module selected, this enhancement introduces a toggle button labeled Disable Firewall Policy Deployment. If the AFM module is not discovered, the Properties Tab will not display this toggle, as firewall deployment is inherently disabled for such devices.
This enhancement helps the team more granularly deploy and manage network firewalls via the user interface or API. Additionally, per-device AFM management helps teams maintain consistency for device clusters by applying changes to all devices or single instances. This enhancement also adheres to any roles or user policies, helping ensure enforcement of RBAC—only admins can make changes to AFM policies while other roles are read-only. In short, this new feature enables teams to build consistent and resilient AFM policies and deployments—even during device re-import and re-discovery.
Support for F5 BIG-IP v21.1
BIG-IQ v8.4.2 has been updated for interoperability with BIG-IP up to v21.1, including full support for SSL Orchestrator v14. With this interoperability, teams can:
- Manage the latest versions of BIG-IP (17.5.X and 21.1) including both device/instance management as well as services running on these instances
- Configure and deploy BIG-IP devices and services in a repeatable and consistent manner at enterprise scale
- Provision, license, configure, and deploy the latest BIG-IP VEs, HW instances (including VELOS and rSeries), and the app services running on them
- Effectively troubleshoot issues with infrastructure, policies, configurations, app services, or apps themselves
Updated TMOS Layer
In the v8.4.2 release, BIG-IQ’s underlying TMOS version has been upgraded to v17.5.1.4, which will enhance the control plane performance, improve security efficacy, and enable better resilience of the BIG-IQ solution.
Upgrading to v8.4.2
You can upgrade from BIG-IQ v8.X to BIG-IQ v8.4.2.
BIG-IQ Centralized Management Compatibility Matrix
Refer to Knowledge Article K34133507
BIG-IQ Virtual Edition supported platforms
BIG-IQ Virtual Edition Supported Platforms provides a matrix describing the compatibility between the BIG-IQ VE versions and the supported hypervisors and platforms.
Conclusion
Effective management—orchestration, visibility, and compliance—relies on consistent app services and security policies across on-premises and cloud deployments. Easily control all your BIG-IP devices and services with a single, unified management platform, F5® BIG-IQ®.
F5® BIG-IQ® Centralized Management reduces complexity and administrative burden by providing a single platform to create, configure, provision, deploy, upgrade, and manage F5® BIG-IP® security and application delivery services.
Related Content
F5 BIG-IQ Centralized Management
Boosting BIG-IP AFM Efficiency with BIG-IQ: Technical Use Cases and Integration Guide







