Forum Discussion
F5 ASM blacklist/whitelist vs. NIPS
There's certainly no wrong or right answer - it depends on your circumstances.
If the F5 is already inline in the traffic path it is already in a position to see all traffic - all you have to do is add the ASM module and configure. It's also going to be performing SSL offload and potentially re-encrypting so it is in a unique position to be able to see traffic contents.
An all-purpose NIPS either has to be inserted into the traffic path (for IPS), or you need to use a precious SPAN session to send traffic to it (for IDS). In addition in order to see encrypted traffic it will need to have certs added, or be in the traffic path behind the SSL Offloader.
The WAF is specific to web applications whereas the NIPS will alert on all types of signatures, so it really depends on your requirements.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com