VCF VPN Insight: Deployment
Version: 2026.1.0.0
This page covers installing the Management Pack and configuring an adapter instance.
User Permissions and Connection Requirements
| Category | Description |
|---|---|
| Cloud Proxy to BIG-IP | Reachable over HTTPS on port 443 from the collector group. |
| BIG-IP account | A read-only account with the F5 Auditor role plus iControl REST permissions, used for the base layer and the APM VPN layer. |
| APM module | The apm module must be provisioned on the BIG-IP for the VPN gateways, sessions, lease pools and access policies to be collected. The ltm and avr modules are optional and gate virtual servers and peak-session values. |
| F5 Device Group | Requires the Administrator role and is therefore not readable with the read-only account; the cluster is synthesized from the device member list instead. |
| Container registry | HTTPS/443 to https://registry.indevops.com (always) to pre-pull the adapter image. |
Installing the addon
- Pre-pull the adapter image on the cloud proxies belonging to the collector group, using the image name shown on the release page for the matching version.
- Install the PAK: in VMware Aria Operations go to
Data Sources > Integrations > Repository > Add, upload the PAK and tick bothInstall the PAK file even if it is already installedandIgnore the PAK file signature checking. - Configure the adapter account: add an adapter instance and supply the credentials and instance parameters below.
Adapter fields
Credentials. One credential type, VPN credentials, with two fields:
| Field Name | Definition |
|---|---|
| User name | BIG-IP account name. |
| Password | BIG-IP account password. |
Instance parameters. The address is the only required field; every other parameter is advanced and falls back to its default.
| Field Name | Default | Definition |
|---|---|---|
| Address (IP or FQDN) | required | IP address or FQDN of the target device management interface, reachable from the Cloud Proxy on the management port. |
| Management port | 443 | iControl REST port. |
| Accept self-signed certificates | 0 | 1 accepts any certificate presented by the BIG-IP. For lab targets; production should import the CA instead. |
| Maximum VPN session objects | 2000 | Hard cap on VPN Session objects per cycle. Sessions beyond it are not lost: they are counted into sessions_overflow on the VPN Gateway. This is not pagination. |
| Authentication | token | token uses the F5 login endpoint (recommended). basic sends the account on every call and needs TLS; some hardened instances disable the login endpoint. |
| Token refresh threshold (seconds) | 960 | Re-login once the token has lived this long. The F5 token TTL is about 1200 s, so the default leaves a full 300 s collection cycle of margin. |
| API timeout (seconds) | 60 | Per-request timeout for calls to the BIG-IP management interface. |
| Partitions | empty | Comma separated partition whitelist. Empty means every partition. |
| Scheme override | empty | Force https or http for the management connection. Empty infers it from the address; production is HTTPS. |
| Vendor | F5 | Vendor implementation to use. F5 is the only one implemented; the parameter exists so a second vendor can be added without a new adapter kind. |
