May 18, 2022

F5 rules for AWS WAF - Comparison between AWS Managed and F5 WAF rules

I was going through the AWS Marketplace for F5 Rules for AWS WAF to activate 2 rules:
Web exploits OWASP Rules and Common Vulnerabilities & Exposures (CVE) Rules

Both these rules are using 1000wcu each and they are the same as AWS Managed Amazon Core Rules and Known Bad Inputs respectively. But the AWS Managed Rules have 700 and 200 wcu as compared to F5.

Wanted to understand what extra security features does F5 provide with these rules as compared to AWS Managed Rules because there is a limitation on wcu per web acl and also only 1 application load balancer can be associated with a web acl.


