For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

4 Replies

  • See Gartner for WAF vendors. Managers love it like you are going to a supermarket and getting 50% discount 😉 

  • Hi saddiq_bilal​ 

     

    There are several advantages of using F5 AWAF (formerly ASM) to protect your F5-hosted applications and URLs. Some key benefits include:

    1. Advanced protection against OWASP Top 10 vulnerabilities
      b. Automatic threat intelligence updates to safeguard against emerging web threats
      c. Comprehensive security for public-facing web applications and API gateways against both common and advanced attacks
      d. Bot protection capabilities to detect and block malicious or automated bot activity
      e. Application-layer DDoS protection, along with various other enhanced security features


    F5 AWAF also allows highly granular security policy configuration, enabling you to tailor protections based on specific application behavior. While F5 provides extensive documentation to help you get started, I would also recommend the following best practices when planning your AWAF deployment:

    1. Avoid enabling full blocking mode initially. Start with the policy in Learning Mode so the system can observe traffic patterns, identify potential violations, and help you distinguish between true positives and false positives.
    2. Begin implementation in a lower environment to minimize any risk of unintended production impact.
    3. Build the policy in phases. Blocking everything from the start may lead to unnecessary false positives. A gradual, phased approach is far more effective.
    4. Collaborate closely with your application team. Having detailed knowledge of the application—such as expected URLs, methods, response codes, and technologies used—greatly helps in designing an accurate and effective WAF policy.
    5. Maintain separate policies for each environment. This approach provides flexibility and ensures that changes can be safely tested in lower tiers before being applied to production.



    Hope this helps! 

    Mayur