Logo

BIG-IP R5920-DF

BIG-IP R5920-DF is the FIPS-focused model in the F5 r5000 Series, designed for environments where application delivery and security must be combined with hardware-protected cryptographic key storage. It uses the same general r5000 performance class as R5900, but adds an integrated hardware security module (HSM) and redundant internal storage, making it particularly relevant to government, financial, healthcare, and other regulated environments with stricter cryptographic requirements.

The platform provides 26 vCPUs for BIG-IP tenant workloads, 128 GB of memory, 25G and 100G interfaces, and an integrated FIPS HSM. Unlike R5600 and R5800, however, R5920-DF is not a Pay-as-you-Grow model. It should be selected because FIPS-protected key handling is part of the design, not simply because more r5000 performance is required.

Series Highlights

Review BIG-IP R5920-DF Price List and request a quote tailored to your licensing needs.

View BIG-IP R5920-DF Part Numbers

BIG-IP R5920-DF

BIG-IP R5920-DF At a glance

What it is: FIPS-capable r5000 Series application delivery and security appliance

Product family: BIG-IP rSeries License

Platform layer: F5OS

Compute: 32 total vCPUs; 6 reserved for F5OS and 26 available to tenants

System memory: 128 GB

Storage: Dual 1 TB U.2 SSDs configured as RAID1

FIPS capacity: Up to 24 FIPS partitions

Interfaces: Eight 10G/25G ports plus two 40G/100G ports

Series Overview

The R5920-DF contains 16 physical CPU cores presented as 32 vCPUs through hyperthreading. Six are dedicated to the F5OS platform layer, leaving 26 vCPUs for BIG-IP tenants. In that respect, its tenant compute capacity is comparable to the fully enabled R5900.

The important difference is cryptography. R5920-DF includes an embedded HSM designed to protect private keys and perform cryptographic operations inside dedicated hardware. F5 currently lists the integrated NITROX III module used by R5920-DF under FIPS 140-3 Level 3 validation certificate 4700. F5 also explicitly notes that this Level 3 validation applies to the integrated HSM, not to the entire BIG-IP system.

Storage is another difference from standard r5000 appliances. Where R5600, R5800, and R5900 normally use a single SSD, R5920-DF includes two 1 TB U.2 SSDs in a RAID1 configuration, adding disk redundancy for this security-focused platform.

Licensing and Part Number Guidance

An R5920-DF order should begin with the compliance requirement. If the project does not require an integrated FIPS HSM, a standard R5900 may provide similar tenant compute with a simpler commercial model. Where protected cryptographic keys are required, the R5920-DF platform is then combined with the appropriate BIG-IP License services, such as traffic management, application security, DNS, access, or network-security capabilities.

FIPS resources introduce another sizing layer. The integrated HSM supports up to 24 FIPS partitions on the r5000-DF platform. F5 allows administrators to allocate key capacity and hardware acceleration devices among those partitions, which can then be associated with individual BIG-IP tenants. There is no R5920-DF PAYG tier. F5 specifically identifies R5920-DF and R10920-DF as FIPS platforms without Pay-as-you-Grow options.

Common Use Cases

Use case Why R5920-DF can fit
Regulated application delivery Combines BIG-IP ADC services with hardware-protected keys
TLS termination Keeps private-key operations inside an integrated HSM
Application security Supports BIG-IP security services with FIPS-oriented cryptography
Government environments Designed for deployments with formal FIPS requirements
Financial services Hardware key protection for sensitive application infrastructure
Multi-tenant FIPS Separate HSM partitions can be assigned to BIG-IP tenants
iSeries FIPS refresh Current replacement path for older i5820-DF / i7820-DF environments
HA deployment Two systems can provide BIG-IP tenant-level redundancy

F5 introduced R5920-DF and R10920-DF as the rSeries replacement options associated with the retirement of the older i5820-DF and i7820-DF platforms.

Models, Licenses, and Ordering Scope

Area What to confirm
Platform BIG-IP R5920-DF
Compliance Whether integrated FIPS HSM is actually required
BIG-IP services LTM, Advanced WAF, DNS, AFM, APM, or required combination
Tenant design Tenant quantity, vCPU, memory, and BIG-IP role
FIPS partitions Number of tenants requiring HSM access
Key capacity Cryptographic key requirements per partition
Interfaces 10G, 25G, 40G, or 100G
Storage Dual 1 TB RAID1 architecture
Availability Standalone or paired HA deployment
Power AC or supported DC configuration
Optics SFP+, SFP28, QSFP+, or QSFP28
Support F5 service level and term
Part numbers Appliance, BIG-IP entitlement, optics, power, support, and accessories

What to Check Before Requesting a Quote

The first question should be why FIPS hardware is required. If a policy, customer contract, government standard, or security architecture specifically requires private keys to remain inside a validated HSM, R5920-DF is materially different from R5900. Next, document the applications and cryptographic workload. Include expected traffic, TLS transactions, key quantity, tenant count, BIG-IP modules, security inspection, interface speeds, and HA requirements.

FIPS partition planning deserves particular attention. F5 documents up to 25,475 keys for the R5920-DF HSM and up to 32 acceleration devices, but these resources need to be distributed across the FIPS partitions created for tenants. If the environment needs more than the available r5000-DF compute, HSM resources, or tenant scale, compare R10920-DF rather than looking for a PAYG upgrade that does not exist.

Activation and Delivery Notes

R5920-DF is configured through the F5OS platform layer. In addition to normal rSeries networking and license activation, the HSM must be initialized before FIPS partitions are created and assigned to BIG-IP tenants.

F5 currently requires BIG-IP 17.1.0.1 or later for tenants using the rSeries FIPS platform. After the HSM is initialized, administrators can allocate keys and acceleration resources to individual partitions and associate those partitions with tenants.

For migrations from older iSeries FIPS appliances, F5 also provides an HSM-partition backup option intended to support secure key migration workflows.

Before shipment, confirm the precise FIPS requirement, BIG-IP entitlement, optics, power model, HA quantity, support term, and software compatibility.

F5 pricing depends on your product edition, license type, deployment model, traffic needs, term, and support requirements.

Request F5 Quote →

Frequently Asked Questions