Forum Discussion
F5 ASM WAF vs. Akamai Kona Cloud based WAF
We plan to sell our customer an F5 ASM WAF solution (added to the traffic manager). The customer asked us why they should invest into an inhouse deployment when they could get WAF from Akamais cloud offering.
I'm looking for a technical feature list that compares the solutions or explains why the inhouse deployment sitting close to the web apps is better, richer, more customizable than a cloud based offering.
Any help, ideas, input?
Thanks
Andre
3 Replies
- What_Lies_Bene1
Cirrostratus
I'm not even that familiar with ASM but my concerns about using Akamais solution (which I've only briefly looked at) would run along these lines;
1) This solution wouldn't protect against DDoS attacks directly targeted at you if the attackers discovered your 'origin' IP addresses
2) I'd imagine your ability to build, test and customise your security policy will be limited as would your abilities in relation to responses to attacks
3) Your costs are not fixed
4) Are you really happy to 'outsource' your security, who is responsible if it fails?
I'm sure someone better informed than me where security is concerned will also provide some input. - Iselator_38937
Nimbostratus
Hi Steve
Akamai says they have a solution to protect the origin IP and configure some rules on your firewalls/routers to route back/deny direct access from the internet to the origin IPs
Costs could be also fix as they have a model where they just charge for one DDoS apparently on a monthly basis and everything in addition is covered in the monthly fee
Akamai promises a 100 % availability of their environment with 130000 servers around the globe.
But all those things rather relate to the DDoS feature than to the WAF features I'm looking for. I would seek some good comparison of technical features between Akamai and F5 WAF. There is a comparison model WAFEC that could provide a basis for comparion but the latest version is from 2006 and there is no actual information in the model, just the framework.
Regards
André
- hoolio
Cirrostratus
Hi André,
I'd talk with your F5 or partner SE to get a comparative list of features.
One major issue I see customers balk at with outsourcing app security is that they generally need to provide their SSL keys to a third party. Most security focused companies aren't willing to risk having their keys in an unknown environment.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com