VCF VPN Insight: Deployment

Version: 2026.1.0.0

This page covers installing the Management Pack and configuring an adapter instance.

User Permissions and Connection Requirements

CategoryDescription
Cloud Proxy to BIG-IPReachable over HTTPS on port 443 from the collector group.
BIG-IP accountA read-only account with the F5 Auditor role plus iControl REST permissions, used for the base layer and the APM VPN layer.
APM moduleThe apm module must be provisioned on the BIG-IP for the VPN gateways, sessions, lease pools and access policies to be collected. The ltm and avr modules are optional and gate virtual servers and peak-session values.
F5 Device GroupRequires the Administrator role and is therefore not readable with the read-only account; the cluster is synthesized from the device member list instead.
Container registryHTTPS/443 to https://registry.indevops.com (always) to pre-pull the adapter image.

Installing the addon

  1. Pre-pull the adapter image on the cloud proxies belonging to the collector group, using the image name shown on the release page for the matching version.
  2. Install the PAK: in VMware Aria Operations go to Data Sources > Integrations > Repository > Add, upload the PAK and tick both Install the PAK file even if it is already installed and Ignore the PAK file signature checking.
  3. Configure the adapter account: add an adapter instance and supply the credentials and instance parameters below.

Adapter fields

Credentials. One credential type, VPN credentials, with two fields:

Field NameDefinition
User nameBIG-IP account name.
PasswordBIG-IP account password.

Instance parameters. The address is the only required field; every other parameter is advanced and falls back to its default.

Field NameDefaultDefinition
Address (IP or FQDN)requiredIP address or FQDN of the target device management interface, reachable from the Cloud Proxy on the management port.
Management port443iControl REST port.
Accept self-signed certificates01 accepts any certificate presented by the BIG-IP. For lab targets; production should import the CA instead.
Maximum VPN session objects2000Hard cap on VPN Session objects per cycle. Sessions beyond it are not lost: they are counted into sessions_overflow on the VPN Gateway. This is not pagination.
Authenticationtokentoken uses the F5 login endpoint (recommended). basic sends the account on every call and needs TLS; some hardened instances disable the login endpoint.
Token refresh threshold (seconds)960Re-login once the token has lived this long. The F5 token TTL is about 1200 s, so the default leaves a full 300 s collection cycle of margin.
API timeout (seconds)60Per-request timeout for calls to the BIG-IP management interface.
PartitionsemptyComma separated partition whitelist. Empty means every partition.
Scheme overrideemptyForce https or http for the management connection. Empty infers it from the address; production is HTTPS.
VendorF5Vendor implementation to use. F5 is the only one implemented; the parameter exists so a second vendor can be added without a new adapter kind.