F5 Distributed Cloud Private Interconnect
Overview
F5 Distributed Cloud Private Interconnect enables secure, high-performance private connectivity between customer environments and the F5 Distributed Cloud Regional Edge (RE) backbone. This utility extension allows organizations to consume security and networking services without exposing application origins to the public internet.
Core use cases
1. Secure Origin Connectivity Without Public Internet Exposure Customers can connect their application origin environments directly to the F5 Distributed Cloud (XC) Regional Edge (RE) backbone using private connectivity instead of exposing infrastructure to the public internet.
- Capabilities: Eliminates direct public internet exposure for origin servers and establishes isolated, dedicated, or semi-dedicated private connectivity between customer routers/servers and F5 infrastructure.
- Typical Environments: On-premises data centers, private cloud environments, hybrid cloud deployments, and multi-cloud application architectures.
- Benefits: Reduced attack surface, enhanced security and compliance, more predictable network performance, and lower risk of direct DDoS exposure.
2. DDoS Protection and Security Services for Application Origins Place application origins behind the F5 Distributed Cloud security stack while maintaining entirely private back-end connectivity.
- Traffic Flow: F5 becomes the internet-facing entry point where traffic is inspected and protected before reaching the origin, keeping customer origins completely hidden from direct internet access.
- Available Security Services: DDoS protection, Web Application Firewall (WAF), API security, Bot defense, and threat mitigation services.
- Key Advantage: F5 absorbs and mitigates internet-based attacks at the edge, preventing malicious traffic from directly reaching customer infrastructure.
Note: Routed DDoS and other security services can't share the same Private Interconnect circuit.
3. High-Speed Private Connectivity to the F5 Regional Edge Backbone Establish private, high-bandwidth connectivity into the F5 XC backbone to improve reliability and performance. This architecture provides faster, more stable connectivity, reduces dependency on public internet routing, and improves redundancy and resiliency.
4. Private Customer Edge (CE) to Global Network Connectivity Customers with on-premises Customer Edge (CE) devices can establish secure private connectivity directly into the F5 Global Network or Global Controller (GC) infrastructure.
- Target Scenarios: Ideal for enterprises with branch or edge infrastructure, regulated environments requiring private routing, or customers implementing hybrid WAN architectures.
- Benefits: Supports secure private control-plane communication without traversing the public internet.
5. Hybrid and Multi-Cloud Application Connectivity Supports architectures where application components are distributed across public clouds, private clouds, and on-premises infrastructure. By using private connectivity into the F5 backbone, customers can maintain secure east-west and north-south traffic flows while standardizing security enforcement across environments.
Technical connectivity models
The architectural model varies depending on whether your infrastructure is physically co-located within the same facility as the F5 Regional Edge provider.
| Model | Direct Physical Connection (Co-located) | Virtual Cross-Connect (Not Co-located) |
|---|---|---|
| Definition | Utilized when the customer is physically co-located in the same facility provider location as F5. | Utilized when the customer is not co-located in the immediate facility but is located within the broader geographic network region. |
| Port Availability | Dedicated capacity options available at 10 Gbps or 100 Gbps. | Provisioned as a virtual connection through cross-connect partners, with bandwidth ranging from 1 Gbps to 10 Gbps in 1 Gbps increments. |
| Configurations / Partners | Supports a full 100 Gbps port on the router or a 100 Gbps port split into four individual 10 Gbps connections. | Primary Partner: Equinix. Additional Providers: Megaport, Console Connect, and PacketFabric. |
Deployment topologies and reference architectures
This section describes the supported deployment models for F5 Distributed Cloud Private Interconnect. These reference architectures demonstrate how Private Interconnect securely connects users, applications, data centers, and cloud environments while leveraging F5 Regional Edge (RE) services.
Design Considerations
Consider the following best practices when designing a Private Interconnect deployment:
- Use dedicated private connectivity when regulatory, compliance, or security requirements prohibit public internet exposure.
- Deploy redundant interconnects to achieve high availability.
- Use Border Gateway Protocol (BGP)-based routing for dynamic path management and resiliency.
- Standardize security policy enforcement at the Regional Edge across hybrid and multi-cloud environments.
- Use cloud-native connectivity services, such as AWS Direct Connect or Azure ExpressRoute, when connecting cloud-hosted origins.
Deployment model 1: Internet to customer data center via Private Interconnect
Internet traffic is received by the F5 Regional Edge, where security services such as Web Application Firewall (WAF), Distributed Denial-of-Service (DDoS) protection, API security, and Bot Defense are applied. Clean traffic is forwarded through Private Interconnect to application origins hosted in a customer data center or colocation facility. This deployment model is the most common architecture for protecting application origins.

Deployment Model 1
Deployment model 2: Internet to public cloud via Private Interconnect
This deployment model extends the previous architecture to cloud-hosted application origins in AWS, Microsoft Azure, or Google Cloud. Customers establish private cloud connectivity by using services such as AWS Direct Connect or Azure ExpressRoute and connect through an approved interconnect partner to reach the F5 infrastructure.

Deployment Model 2
Deployment model 3: Private enterprise network to application origin
Enterprise users, branch offices, or on-premises systems connect to the F5 backbone through Private Interconnect. Traffic is processed by Regional Edge services and delivered to application origins through either:
- A second Private Interconnect connection for an end-to-end private path.
- Internet-based origin connectivity.

Deployment Model 3

Deployment Model 3
Deployment model 4: Cloud-to-cloud connectivity
Private Interconnect provides a secure transit backbone between workloads deployed across multiple cloud providers. Traffic flows through the F5 Regional Edge, enabling centralized security policy enforcement, secure service-to-service communication, and application connectivity across cloud environments.

Deployment Model 4
Deployment model 5: Routed DDoS protection for data center origins
Internet traffic is redirected to the F5 DDoS mitigation infrastructure, where attacks are mitigated before clean traffic is delivered to customer data center environments through Private Interconnect. Optionally, Generic Routing Encapsulation (GRE) tunnels can be configured as backup connectivity.

Deployment Model 5
Availability by region
Private Interconnect availability varies by F5 Regional Edge (RE) location and connectivity partner. Refer to the following table for the currently supported regions.
Note: Availability is not guaranteed and subject to change.
F5 POP - Private Interconnect Availability- North America and South America Region
| POP Metro | Provider | Location | Equinix Fabric | Cologix Exchange | Megaport | Console Connect | Packet Fabric |
|---|---|---|---|---|---|---|---|
| Ashburn | Equinix | DC11 | Yes | No | No | No | Yes |
| New York | Equinix | NY2 | Yes | No | Yes | No | Yes |
| Atlanta | Equinix | AT1 | Yes | No | No | No | Yes |
| Miami | Equinix | MI1 | Yes | No | No | No | No |
| Chicago | Equinix | CH2 | Yes | No | Yes | No | Yes |
| Dallas | Cologix | DAL3 | Yes | Yes | Yes | Yes | Yes |
| San Jose | Equinix | SV10 | Yes | No | Yes | No | Yes |
| Seattle | Equinix | SE3 | Yes | No | Yes | No | Yes |
| Toronto | Equinix | TR2 | No | No | Yes | No | Yes |
| Montreal | Cologix | MTL7 | No | Yes | No | No | No |
| Mexico City | TBD | TBD | TBD | TBD | TBD | TBD | TBD |
| POP Metro | Provider | Location | Equinix Fabric | Cologix Exchange | Megaport | Console Connect | Packet Fabric |
|---|---|---|---|---|---|---|---|
| Sao Paulo | Equinix | SP4 | Yes | No | No | No | No |
F5 POP - Private Interconnect Availability- EMEA Region
| POP Metro | Provider | Location | Equinix Fabric | Cologix Exchange | Megaport | Console Connect | Packet Fabric |
|---|---|---|---|---|---|---|---|
| London | Equinix | LD6 | Yes | No | Yes | Yes | No |
| Paris | Equinix | PA2 | Yes | No | Yes | No | Yes |
| Paris | Equinix | PA4 | Yes | No | No | No | No |
| Paris | Telehouse | TH2 | No | No | No | No | No |
| Milan | Equinix | ML5 | TBD | TBD | TBD | TBD | TBD |
| Lisbon | Equinix | LS1 | Yes | No | No | No | No |
| Madrid | Equinix | MD2 | Yes | No | No | No | No |
| Amsterdam | Interxion | AMS9 | No | No | No | Yes | No |
| Stockholm | Interxion | STO6 | No | No | No | No | No |
| Frankfurt | Equinix | FR4 | Yes | No | No | Yes | No |
| Tel Aviv | Tamares | SDS3 | No | No | No | No | No |
| Dubai | Equinix | DX1 | Yes | No | No | Yes | No |
F5 POP - Private Interconnect Availability- APAC Region
| POP Metro | Provider | Location | Equinix Fabric | Cologix Exchange | Megaport | Console Connect | Packet Fabric |
|---|---|---|---|---|---|---|---|
| Mumbai | Equinix | MB2 | No | No | No | No | No |
| Chennai | Sify Tech | CHE | No | No | No | No | No |
| Singapore | Equinix | SG3 | Yes | No | Yes | Yes | No |
| Jakarta | Neutra | JK1 | No | No | No | No | No |
| Hong Kong | Equinix | HK2 | No | No | Yes | Yes | No |
| Seoul | TBD | TBD | No | No | No | No | No |
| Osaka | Equinix | OS1 | No | No | No | Yes | No |
| Tokyo | Equinix | TY8 | Yes | No | No | Yes | No |
| Melbourne | Equinix | ME1 | No | No | No | No | Yes |
| Sydney | Equinix | SY5 | No | No | Yes | No | Yes |
On this page:
- Overview
- Core use cases
- Technical connectivity models
- Deployment topologies and reference architectures
- Deployment model 1: Internet to customer data center via Private Interconnect
- Deployment model 2: Internet to public cloud via Private Interconnect
- Deployment model 3: Private enterprise network to application origin
- Deployment model 4: Cloud-to-cloud connectivity
- Deployment model 5: Routed DDoS protection for data center origins
- Availability by region