F5, Inc. — 7 prefixes (MA-L)
Summary
- // what this is
- F5 is registered to MAC prefix
00:01:D7and 6 more in the IEEE OUI database. When a device's MAC address begins with00:01:D7, that block was registered by F5 — the OUI identifies the maker of the network hardware, which is not always the brand on the device. - // analyst note
- An F5 OUI on a globally-administered address reliably identifies BIG-IP hardware; the security-sensitive role of these devices (edge/DMZ, TLS termination, traffic management) makes accurate vendor identification useful for asset and exposure inventory.
About this vendor.
A MAC address beginning with one of F5 Inc.'s seven registered OUI prefixes belongs to F5, typically identifying the network interface of a BIG-IP application delivery controller or load balancer. F5 holds seven independent MA-L (24-bit) blocks — no MA-M or MA-S registrations were found — registered across two historical corporate addresses: Liberty Lake, WA and Seattle, WA (401 Elliott Ave. W. and 801 5th Avenue).
Seven separate OUI assignments is itself strong corroboration of an established manufacturer rather than a shell registration. F5, Inc. (NASDAQ: FFIV) is a publicly traded company founded in 1996 and headquartered in Seattle, renamed from F5 Networks, Inc. in November 2021 — no legacy "F5 Networks" string appears in the current IEEE registry org-name fields, so the registry already reflects the post-rename identity.
F5's own knowledge base documents that BIG-IP systems (its flagship application delivery controller / load-balancer line, shipping since 1997 across iSeries, rSeries, VELOS chassis, and virtual editions) draw interface, trunk, and VLAN MAC addresses from a pool sourced from these registered OUI blocks. Independent third-party MAC databases corroborate at least one block (00:0A:49) to F5 at the same Seattle address.
BIG-IP appliances are frequent, high-profile attack targets: they typically sit at network edges and DMZs handling TLS termination and traffic management, making them management-plane-sensitive equipment. CVE-2022-1388 (unauthenticated iControl REST auth-bypass RCE) and CVE-2023-46747 (unauthenticated auth-bypass via request smuggling in the Traffic Management UI) were both actively exploited in the wild and added to CISA's Known Exploited Vulnerabilities catalog.
IEEE's public OUI data (the IEEE MA-L registry) carries no assignment or registration date for any block, so none is attributed to IEEE here. A third-party lookup tool (maclookup.app) displays dates for OUI 00:0A:49, but cites no source or methodology for them — that figure is treated as an unverified database artifact, not a fact, and is excluded from this entry.
- IEEE assignment
- 7 MA-L prefixes → F5, Inc. [Confirmed] — the IEEE MA-L registry (cached IEEE MA-L extract)
- Registry / block size
- MA-L (24-bit OUI) only; no MA-M or MA-S entries found [Confirmed] — the IEEE MA-L registry, the IEEE MA-M registry, the IEEE MA-S registry (cross-checked, no F5 entries)
- HQ / country
- Seattle, WA, US (registry addresses also include Liberty Lake, WA) [Confirmed] — the IEEE MA-L registry
- Company status
- active, publicly traded (NASDAQ: FFIV) [Confirmed] — https://en.wikipedia.org/wiki/F5,_Inc.
- Device types
- BIG-IP application delivery controllers / load balancers [Confirmed] — https://www.f5.com/products
- Notable products
- BIG-IP iSeries, rSeries, VELOS chassis, virtual editions [Confirmed] — https://www.f5.com/products
- Verified sample prefixes (all MA-L, F5 Inc.)
- 00:01:D7, 00:0A:49, 00:23:E9, 00:94:A1, 14:A9:D0, 24:2D:4B, F4:15:63 [Confirmed] — the IEEE MA-L registry
- Legacy name check
- no "F5 Networks" (pre-2021-rename legacy name) string found in the IEEE MA-L registry, the IEEE MA-M registry, or the IEEE MA-S registry org-name fields [Confirmed] — the IEEE MA-M registry, the IEEE MA-S registry
- Registration date
- Unknown / not published — IEEE OUI data carries no assignment date for any block; a third-party date shown on maclookup.app for 00:0A:49 is an unverified database artifact, not attributed here [Confirmed absence; Unknown date] — https://maclookup.app/macaddress/000A49
- IANA reference
- not applicable to MAC/OUI vendor blocks; left blank [Confirmed]
- Security context
- BIG-IP CVE-2022-1388 and CVE-2023-46747, both actively exploited and added to CISA KEV [Confirmed] — https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-138a, https://nvd.nist.gov/vuln/detail/cve-2023-46747
- Related vendors
- none identified