TECHNOLOGIES: F5 BIG-IP

F5 BIG-IP Penetration Testing

BIG-IP’s Configuration utility and iControl REST are the device’s full administrative surface, and both can reach further across your network than intended. We test that exposure, admin roles, iRules and traffic policies. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
F5 BIG-IP Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
TMUI

TMUI, F5’s browser-based Configuration utility, and iControl REST are BIG-IP’s administrative interfaces, and F5’s own self IP documentation defines Port Lockdown as the setting that controls which protocols each address accepts. We check what is actually reachable on the management interface and on every self IP, not just what the design intended.

Why BIG-IP risk concentrates on who can reach the management plane

BIG-IP separates its administrative interfaces, TMUI and iControl REST, from the self IP addresses that carry application traffic, and F5’s own self IP documentation describes Port Lockdown as the setting that decides which protocols and services each self IP address accepts. We test what every self IP and the management interface actually accept, not what the deployment guide assumed was locked down.

Administrator, Manager, Operator, Guest and several other roles each grant a different set of permissions, and BIG-IP assigns a role separately for every administrative partition an account can reach, so the same account can be an Administrator on one partition and have no access on another. We test whether every account’s role and partition assignment matches what that person is meant to manage, and whether partition boundaries hold when an object or policy is shared across them.

Traffic policies and iRules both sit on the virtual server and both change what happens to a request before your application ever sees it, so we test the custom logic your team wrote, not F5’s own code. F5’s local traffic policy and iRule mechanisms can both act on the same virtual server, so we check what each one actually does to a request and how they interact. The same applies to Client SSL and Server SSL profile settings such as cipher preference and secure renegotiation, and to whichever TMOS version is actually running against F5’s currently supported releases and advisories.

SCOPE

What we pen test on an F5 BIG-IP device

BI-01

Management Interface Reachability (TMUI and iControl REST)

TMUI, the browser-based Configuration utility, and iControl REST both authenticate against the same BIG-IP user accounts and both expose the device’s full administrative surface. We test which networks can actually reach either interface, not just the network the management VLAN was designed for.

BI-02

Self IP Port Lockdown Configuration

Each self IP address carries its own Port Lockdown setting, Allow None, Allow All or Allow Custom, deciding which TCP and UDP protocols and services that address accepts, independently of every other self IP on the device. We test every self IP against what it should accept for its VLAN, not what a broader Allow All setting happens to let through.

BI-03

Administrator Accounts and User Roles

BIG-IP assigns a user role such as Administrator, Manager, Operator, Application Editor or Guest separately for each administrative partition an account can reach, and a role can differ between partitions on the same account. We test whether every account’s role actually matches the tasks that person needs, rather than a broader role granted for convenience.

BI-04

Administrative Partition Boundaries

Granting a user access to a partition and assigning that user’s role are two separate settings, so partition access alone does not determine what an account can do inside it. We test whether partition access and role assignment combine the way your team intended, including for objects or policies shared across more than one partition.

BI-05

Virtual Server and Pool Configuration

A virtual server pairs a listening IP address and port with the pool, profiles and address-translation behaviour that decide how traffic is handled, and a Forwarding (IP) virtual server disables address translation entirely. We test the running configuration behind every virtual server in scope against what it is supposed to expose.

BI-06

Local Traffic Policies

A local traffic policy attaches rules, conditions and actions to a virtual server to control traffic without writing an iRule, and more than one policy can be published against the same virtual server. We test what each published policy actually matches and does, and whether its rules still reflect the routing or security decisions they were written for.

BI-07

iRules and Custom Traffic Logic

An iRule is custom logic triggered by traffic events on a virtual server, giving it the same reach as any other code your team writes and deploys. We review and test every iRule attached to a virtual server in scope for the same classes of flaw we would test in application code.

BI-08

APM Access Policies

Where Access Policy Manager sits in front of an application, its access policy decides what a user must satisfy, and which resources they reach, before BIG-IP passes them through, including network access sessions established over a point-to-point SSL connection. We test the access policy the way a real user and an unauthenticated visitor would, not just the flow the policy diagram describes.

BI-09

SSL/TLS Profile Configuration

Client SSL and Server SSL profiles set cipher preference, certificate handling and secure renegotiation independently for traffic to the client and traffic to the pool, and a Server SSL profile can end up configured more loosely than the Client SSL profile facing your users. We test both profiles on every virtual server that terminates or re-encrypts TLS.

BI-10

Supported Version and Advisory Risk

F5 publishes administration guides and advisories against specific BIG-IP releases, and a device running a version outside that supported range stops receiving the fixes those advisories assume are in place. We confirm the TMOS version actually running against F5’s current guidance during scoping, rather than assuming the install date tells us what we need to know.

OUR PROCESS

F5 BIG-IP Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree the virtual servers, partitions and management access we need, including whether the Configuration utility, iControl REST or SSH is in scope for review, and admin accounts across the roles you use.

02

Configuration and Interface Mapping

We map every self IP’s Port Lockdown setting, the roles and partitions assigned to each admin account, and every virtual server’s profiles, traffic policies and iRules in scope.

03

Manual Testing

A CREST-certified tester manually tests management-interface reachability, role and partition boundaries, iRule and traffic-policy logic, and SSL/TLS profile configuration, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST F5 BIG-IP pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent F5 BIG-IP Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,460–£3,620
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£5,780–£8,810
4 to 6 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From F5 BIG-IP Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our BIG-IP device?

We need an account for each administrative role and partition you use, so we can test what every role can actually reach rather than just the Administrator account. Read access to the running configuration speeds up scoping but is not required for the test itself.

Will testing touch live traffic passing through the device?

Testing focuses on the management plane, configuration and the logic you have added, such as iRules and traffic policies, rather than generating load against production traffic. We agree upfront which virtual servers and testing windows keep any risk away from live application traffic.

How long does an F5 BIG-IP penetration test take?

A single device sits in our 2-day single-device scope, with a report typically landing around 5 working days after kickoff. A high-availability pair, multiple partitions or a larger set of virtual servers, iRules and traffic policies moves into a wider scope with more testing days.

Do you test a high-availability pair or just one device?

Our single-device scope covers one BIG-IP instance and its configuration. Where two devices form an active-standby or active-active pair, we scope both, since configuration can differ between them even when they share a device group.

What is out of scope for a single-device BIG-IP test?

The applications and servers sitting behind the virtual servers are out of scope for this test and covered by our web application penetration testing or API penetration testing instead. The wider network, routers and switches around the device are scoped separately too.

Do you need our iRule and traffic policy source?

No. We test iRules and traffic policies as they run, against the virtual servers in scope. Sharing the iRule code and policy rule definitions alongside testing, a grey-box option, lets us review logic paths that are hard to trigger from outside and usually speeds up the test.

Does F5 have a customer penetration-testing policy we need to follow?

BIG-IP is typically infrastructure you own and run yourself rather than a shared multi-tenant service, so the vendor-notification process built for SaaS platforms does not apply in the same way. We confirm F5’s current terms for your specific licensing and support agreement during scoping, along with any extra rules that apply if your BIG-IP is managed through F5 Distributed Cloud or another hosted F5 service.

Are your testers CREST certified?

Yes. Every test is delivered by CREST-certified testers, and EJN Labs holds CREST Approved Provider status.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your F5 BIG-IP device

BIG-IP’s Configuration utility and iControl REST are the device’s full administrative surface, and both can reach further across your network than intended. We test that exposure, admin roles, iRules and traffic policies. CREST-certified testers, fixed price from £2,460 for a 2-day single-device scope, quoted within 24 hours.