BIG-IP R10920-DF is F5’s high-capacity FIPS-oriented appliance in the r10000 class, designed for organizations that need enterprise application delivery and security together with hardware-protected cryptographic key storage. It combines the compute and interface scale of the r10000 platform with an integrated hardware security module, making it relevant to government, financial services, healthcare, telecommunications, and other environments where cryptographic controls are part of the compliance design.
The platform provides 36 vCPUs for BIG-IP tenants, 256 GB of memory, dual RAID1 SSDs, sixteen 10G/25G interfaces, and four 40G/100G interfaces. Unlike R10600 and R10800, R10920-DF is not simply another PAYG performance step. Its value comes from the integrated FIPS capability.
Series Highlights
- FIPS-focused member of the F5 r10000 platform class
- 1RU physical application delivery appliance
- 36 vCPUs available for BIG-IP tenants
- 256 GB system memory
- Integrated NITROX III hardware security module
- Sixteen 10G/25G SFP+/SFP28 interfaces
- Four 40G/100G QSFP+/QSFP28 interfaces
- Dual 1 TB SSDs configured as RAID1
Review BIG-IP R10920-DF Price List and request a quote tailored to your licensing needs.

BIG-IP R10920-DF At a glance
What it is: High-capacity FIPS-enabled application delivery and security appliance
Product family: BIG-IP rSeries License
Platform layer: F5OS
Compute: 48 total vCPUs; 12 reserved for F5OS and 36 available to tenants
System memory: 256 GB
Storage: Dual 1 TB SSDs with RAID1 protection
HSM: Integrated NITROX III cryptographic module
FIPS partitions: Up to 32
Interfaces: Sixteen 10G/25G plus four 40G/100G ports
Typical role: Regulated ADC, TLS termination, application security, FIPS-protected key handling, DNS, access, and multi-tenant application services
Series Overview
The BIG-IP R10920-DF uses a 24-core processor presented as 48 logical vCPUs. Twelve are reserved for the F5OS platform, leaving 36 for tenant workloads. Those resources can be concentrated into one large BIG-IP instance or distributed across multiple tenants.
Its major distinction is the integrated HSM. F5 uses the NITROX III CNN35XX-NFBE HSM family, which is validated to FIPS 140-3 Level 3. An important technical distinction is that the Level 3 validation applies to the embedded HSM, not to the entire R10920-DF appliance. BIG-IP and F5OS cryptographic modules have their own separate validation levels and certificates.
Performance is also substantial. F5 publishes up to 190 Gbps L4/L7 throughput, 6.6 million L7 requests per second, and 95 Gbps bulk encryption for R10920-DF under its specified test conditions.
Licensing and Part Number Guidance
Ordering BIG-IP R10920-DF should start with the FIPS requirement, not simply traffic capacity. If hardware-protected private keys are not required, the standard R10900 may provide a simpler option with comparable tenant compute. R10920-DF becomes relevant when policy, regulation, contractual requirements, or security architecture calls for keys and cryptographic operations to be handled inside a validated hardware module.
The final configuration must also account for the BIG-IP services running on the platform such as LTM, Advanced WAF, DNS, AFM, APM, or another supported combination.
FIPS resources then need to be allocated separately. The r10000-DF HSM supports up to 32 partitions, as many as 102,235 key slots, and up to 63 acceleration devices that can be divided between partitions.
Common Use Cases
| Use case | Why R10920-DF can fit |
|---|---|
| Government applications | Hardware-backed cryptography for regulated systems |
| Financial services | Protected private keys for sensitive application infrastructure |
| Large TLS environments | High-capacity SSL/TLS processing with integrated HSM |
| Application security | BIG-IP security services plus protected key storage |
| Multi-tenant FIPS | Separate HSM partitions for different BIG-IP tenants |
| Data-center ADC | Dense 25G/100G networking and large compute capacity |
| FIPS iSeries refresh | Modern rSeries replacement architecture |
| HA deployment | Matching FIPS appliances for resilient BIG-IP services |
Models, Licenses, and Ordering Scope
| Area | What to confirm |
|---|---|
| Platform | BIG-IP R10920-DF |
| Compliance | Exact FIPS or HSM requirement |
| BIG-IP services | LTM, Advanced WAF, DNS, AFM, APM, or required bundle |
| Tenant design | Number, vCPU, memory, and workload per tenant |
| FIPS partitions | Number of tenants requiring HSM access |
| Key capacity | Keys required for each partition |
| HSM acceleration | Cryptographic processing allocation |
| Interfaces | 10G, 25G, 40G, or 100G |
| Availability | Standalone or HA pair |
| Storage | Dual 1 TB RAID1 |
| Power | AC or DC requirement |
| Support | Coverage level and term |
| Part numbers | Appliance, software, optics, support, power, and accessories |
What to Check Before Requesting a Quote
Start by confirming why an integrated HSM is required. This avoids paying for a specialized platform when standard R10900 cryptography would satisfy the project. Next, define peak traffic, TLS volume, certificate and private-key quantity, application-security services, tenant count, interface speeds, and HA requirements. For multi-tenant environments, identify which tenants actually require FIPS access. R10920-DF can use up to 32 HSM-backed partitions, while additional tenant workloads can operate without a FIPS partition where appropriate. The HSM allocation should also match real cryptographic demand. A few high-volume TLS tenants may need more acceleration resources than a larger number of low-traffic applications.
Activation and Delivery Notes
R10920-DF configuration starts in F5OS. The HSM must first be initialized; FIPS partitions can then be created and assigned key capacity and acceleration resources before being attached to BIG-IP tenants. F5 currently requires tenants using the rSeries FIPS capability to run BIG-IP 17.1.0.1 or later. Each FIPS tenant is associated with an HSM partition so its private keys can remain within the hardware-backed cryptographic boundary. For HA or migration projects, partition design, key backup, and equivalent resource allocation should be considered before production activation. F5 supports backup-enabled FIPS partitions to assist with supported key-migration workflows.
F5 pricing depends on your product edition, license type, deployment model, traffic needs, term, and support requirements.