Forum Discussion
F5 ASM blacklist/whitelist vs. NIPS
We have endless questions with a customer about pros/cons of a WAF and a NIPS and where to do what. I'm interest if you could share some thoughts around this and also about where to do what kind of blacklisting. Or the different features of blacklists on a WAF or on a NIPS
1 Reply
- IheartF5_45022
Nacreous
There's certainly no wrong or right answer - it depends on your circumstances.
If the F5 is already inline in the traffic path it is already in a position to see all traffic - all you have to do is add the ASM module and configure. It's also going to be performing SSL offload and potentially re-encrypting so it is in a unique position to be able to see traffic contents.
An all-purpose NIPS either has to be inserted into the traffic path (for IPS), or you need to use a precious SPAN session to send traffic to it (for IDS). In addition in order to see encrypted traffic it will need to have certs added, or be in the traffic path behind the SSL Offloader.
The WAF is specific to web applications whereas the NIPS will alert on all types of signatures, so it really depends on your requirements.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com