Table of Contents
- Introduction
- Demo Video
- New Features in Zero Trust Access
- IPsec VPN Support
- HTTP Connector Support Added to Per-Session Policies in APM
- Dynamic Client Registration (DCR) support
- Custom Logging Preferences for Windows Edge Client
- Native Support for SAML Authentication for Windows
- Auto-Upgrade Machine Tunnel Service
- Endpoint Inspection Support on Ubuntu with ARM64
- Conclusion
- Related Content
Introduction
F5 BIG-IP Zero Trust Access, a key component of the F5 Application Delivery and Security Platform (ADSP), helps teams secure apps that are spread across hybrid, multi-cloud and AI environments. In this article, I’ll highlight some of the key Access features available in F5 BIG-IP v21.1.
F5 BIG-IP v21.1 was released in May of 2026. This release included an updated Zero Trust Access version (v10) with new features.
Demo Video
New Features in Zero Trust Access
IPsec VPN Support
Added support for Access IPsec VPN Tunnels, to meet global security standards and enable the transition from SSL/TLS-VPNs to IPsec VPNs. Clients can now connect to BIG-IP using the Windows Edge Client or F5 Access for macOS, establish an IPsec tunnel, and securely access the backend network.
To enable IPsec support, navigate to Access > Connectivity / VPN > Connectivity > Profiles
Click on a VPN Profile, “VPN-Profile1” in this example
Scroll down and click Edit Profile
![]()
Change the VPN Profile Type to IPsec and click OK
When you set the VPN Profile Type to IPsec, the system automatically generates an Access IPsec Policy.
HTTP Connector Support Added to Per-Session Policies in APM
Support for the HTTP Connector in per-session policies is now available in F5 BIG-IP Access Policy Manager (APM). This feature enables administrators to send HTTP requests to external services during session establishment and use the response for authentication, authorization, and access control decisions.
To use the HTTP Connector, navigate to Access > Profiles / Policies > Access Profiles
Edit the Per-Session Policy of any Profile you wish to add an HTTP Connector to, “Test“ in this example
Click the plus to add an item
Go to the General Purpose tab, select HTTP Connector and click Add Item
Select the HTTP Connector Profile then click Save
Dynamic Client Registration (DCR) support
This release adds support for OAuth 2.0 Dynamic Client Registration (RFC 7591). Administrators can enable DCR on OAuth profiles to allow authorized clients to dynamically register using an Initial Access Token (IAT). The feature includes support for the Client Credentials grant type, configurable client authentication settings, client secret expiration, and enhanced logging.
To enable DCR, navigate to Federation > OAuth Authorization Server > OAuth Profile
Click on the name of the profile you want to edit, oauth in this example
Check the box to enable Dynamic Client Registration
Click Update at the bottom
![]()
Custom Logging Preferences for Windows Edge Client
The Windows Edge Client now offers custom logging preferences, giving you enhanced control over log verbosity to improve both security and flexibility.
You can select the required log level from the APM Client Log Level drop-down in General Settings while creating a Connectivity Profile.
To change the Logging Preferences, navigate to Access > Connectivity / VPN > Connectivity > Profiles
Click on a VPN Profile, “VPN-Profile1” in this example
Scroll down and click Edit Profile
![]()
Change the APM Clients Log Level and click OK
![]()
Native Support for SAML Authentication for Windows
APM clients now support native SAML authentication, significantly improving user experience, maintainability, and overall supportability. Edge Client on macOS and Windows can leverage the system’s default browser to authenticate users with identity providers (IdPs), enabling modern authentication mechanisms such as FIDO2 and Microsoft Entra ID device authentication.
To enable this feature, navigate to Access > Connectivity / VPN > Connectivity > Profiles
Click on a VPN Profile, “VPN-Profile1” in this example
Scroll down and click Edit Profile
![]()
Select the Desktop Client Settings, check the box to Enable System Browser and click OK
Auto-Upgrade Machine Tunnel Service
Windows Edge Clients can now automatically upgrade the F5 Machine Tunnel Service when a newer version is available on BIG-IP, and the auto-upgrade feature is enabled. Additionally, if the Machine Tunnel service is running before the upgrade, it continues to run after the upgrade completes without affecting existing VPN configuration settings.
Endpoint Inspection Support on Ubuntu with ARM64
Endpoint Inspection is now supported on Ubuntu with ARM64, allowing seamless management and inspection of endpoints on Linux ARM64 platforms.
Conclusion
F5 BIG-IP Zero Trust Access, a key component of the F5 Application Delivery and Security Platform (ADSP), helps teams secure apps that are spread across hybrid, multi-cloud and AI environments. The latest version of F5 BIG-IP is packed with new Zero Trust Access features.
Related Content
Secure Corporate Apps with a Zero Trust Security Model
F5 BIG-IP APM Identity Aware Proxy (IAP): The Gateway to a Zero Trust Architecture













