What’s New in Zero Trust Access v10?

Table of Contents

Introduction

F5 BIG-IP Zero Trust Access, a key component of the F5 Application Delivery and Security Platform (ADSP), helps teams secure apps that are spread across hybrid, multi-cloud and AI environments. In this article, I’ll highlight some of the key Access features available in F5 BIG-IP v21.1.

F5 BIG-IP v21.1 was released in May of 2026.  This release included an updated Zero Trust Access version (v10) with new features.

Demo Video

New Features in Zero Trust Access 

IPsec VPN Support 

Added support for Access IPsec VPN Tunnels, to meet global security standards and enable the transition from SSL/TLS-VPNs to IPsec VPNs.  Clients can now connect to BIG-IP using the Windows Edge Client or F5 Access for macOS, establish an IPsec tunnel, and securely access the backend network.

To enable IPsec support, navigate to Access > Connectivity / VPN > Connectivity > Profiles

Click on a VPN Profile, “VPN-Profile1” in this example

Scroll down and click Edit Profile

image_346552.png

Change the VPN Profile Type to IPsec and click OK

When you set the VPN Profile Type to IPsec, the system automatically generates an Access IPsec Policy.

HTTP Connector Support Added to Per-Session Policies in APM  

Support for the HTTP Connector in per-session policies is now available in F5 BIG-IP Access Policy Manager (APM). This feature enables administrators to send HTTP requests to external services during session establishment and use the response for authentication, authorization, and access control decisions.

To use the HTTP Connector, navigate to Access > Profiles / Policies > Access Profiles

Edit the Per-Session Policy of any Profile you wish to add an HTTP Connector to, “Test“ in this example

Click the plus to add an item

Go to the General Purpose tab, select HTTP Connector and click Add Item

Select the HTTP Connector Profile then click Save

Dynamic Client Registration (DCR) support  

This release adds support for OAuth 2.0 Dynamic Client Registration (RFC 7591). Administrators can enable DCR on OAuth profiles to allow authorized clients to dynamically register using an Initial Access Token (IAT). The feature includes support for the Client Credentials grant type, configurable client authentication settings, client secret expiration, and enhanced logging.

To enable DCR, navigate to Federation > OAuth Authorization Server > OAuth Profile

Click on the name of the profile you want to edit, oauth in this example

Check the box to enable Dynamic Client Registration

Click Update at the bottom

image_346552.png

Custom Logging Preferences for Windows Edge Client 

The Windows Edge Client now offers custom logging preferences, giving you enhanced control over log verbosity to improve both security and flexibility.

You can select the required log level from the APM Client Log Level drop-down in General Settings while creating a Connectivity Profile.

To change the Logging Preferences, navigate to Access > Connectivity / VPN > Connectivity > Profiles

Click on a VPN Profile, “VPN-Profile1” in this example

Scroll down and click Edit Profile

image_346552.png

Change the APM Clients Log Level and click OK

image_346552.png

Native Support for SAML Authentication for Windows 

APM clients now support native SAML authentication, significantly improving user experience, maintainability, and overall supportability. Edge Client on macOS and Windows can leverage the system’s default browser to authenticate users with identity providers (IdPs), enabling modern authentication mechanisms such as FIDO2 and Microsoft Entra ID device authentication.

To enable this feature, navigate to Access > Connectivity / VPN > Connectivity > Profiles

Click on a VPN Profile, “VPN-Profile1” in this example

Scroll down and click Edit Profile

image_346552.png

Select the Desktop Client Settings, check the box to Enable System Browser and click OK

Auto-Upgrade Machine Tunnel Service 

Windows Edge Clients can now automatically upgrade the F5 Machine Tunnel Service when a newer version is available on BIG-IP, and the auto-upgrade feature is enabled. Additionally, if the Machine Tunnel service is running before the upgrade, it continues to run after the upgrade completes without affecting existing VPN configuration settings.

Endpoint Inspection Support on Ubuntu with ARM64 

Endpoint Inspection is now supported on Ubuntu with ARM64, allowing seamless management and inspection of endpoints on Linux ARM64 platforms.

Conclusion

F5 BIG-IP Zero Trust Access, a key component of the F5 Application Delivery and Security Platform (ADSP), helps teams secure apps that are spread across hybrid, multi-cloud and AI environments.  The latest version of F5 BIG-IP is packed with new Zero Trust Access features.

Related Content

F5 BIG-IP Zero Trust Access

Zero Trust Solution Overview

Secure Corporate Apps with a Zero Trust Security Model

F5 BIG-IP APM Identity Aware Proxy (IAP): The Gateway to a Zero Trust Architecture

Zero Trust Application Access for Federal Agencies

BIG-IP APM Configuration for Compliance Retrieval Service

3 Likes