# F5 BIG-IP SSL Orchestrator Configuration with Advanced WAFaaS

**URL:** <https://community.f5.com/t/f5-big-ip-ssl-orchestrator-configuration-with-advanced-wafaas/72060>\
**Category:** F5 Technical Articles\
**Tags:** security, series-ssl-orchestrator-advanced-use-cases, series-big-ip-ssl-orchestrator\
**Created:** [April 26, 2023, 3:00pm UTC](https://community.f5.com/t/f5-big-ip-ssl-orchestrator-configuration-with-advanced-wafaas/72060 "2023-04-26T15:00:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![KevinGallaugher](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/kevingallaugher/32/13108_2.png) [@KevinGallaugher](https://community.f5.com/u/KevinGallaugher)\
**Post date:** [April 26, 2023, 3:00pm UTC](https://community.f5.com/t/f5-big-ip-ssl-orchestrator-configuration-with-advanced-wafaas/72060/1 "2023-04-26T15:00:00Z")

</div>

## Introduction

This use case allows you to insert F5 Advanced WAF functionality in SSL Orchestrator from the Service Catalog.&nbsp; This is a new feature in SSL Orchestrator version 11.0.

**Note:** &nbsp;This article applies to SSL Orchestrator version 11.0 and newer. If using an older version refer to the article [HERE](https://community.f5.com/topic/285752)

Below is a video demonstration of this article:

[![](https://d20hrnpixdzcsd.cloudfront.net/original/3X/1/8/184d45d570fa9bc0fb81ea070a127dec698007a1.jpeg "F5 BIG-IP SSL Orchestrator Configuration with Advanced WAFaaS") ](https://www.youtube.com/watch?v=6Ds3xx7m2L8)

Click [HERE](https://community.f5.com/topic/281631) for a Lightboard Lesson on F5 Advanced WAF.

Advanced WAFaaS is the ability to insert F5 BIG-IP Advanced WAF profiles into the SSL Orchestrator Service Chain for Inbound Topologies.&nbsp; This service allows you to configure and deploy Advanced Web Application Firewall profiles through the SSL Orchestrator. &nbsp;This configuration is specific to a WAF policy running on the SSL Orchestrator device.&nbsp; It is also possible to deploy WAF on a separate BIG-IP device, in which case you’d simply configure an inline transparent proxy service.&nbsp; The ability to insert F5’s Advanced WAF into the Service Chain presents a significant customer benefit.&nbsp; Some examples of the benefits are:

- Consolidation of best-in-class advanced WAF capabilities with SSL Orchestrator’s dynamic, policy-based decrypted malware inspection and traffic steering.
- The Advanced WAF Service can be used for multiple SSL Orchestrator Topologies.
- Management of SSL Orchestrator and Advanced WAF on the same platform.
- Simplifies logging and troubleshooting.

This guide assumes you already have SSL Orchestrator and F5 Advanced WAF licensed and provisioned on the BIG-IP and wish to add this functionality to an Inbound Topology.&nbsp; In order to run Advanced WAF and SSL Orchestrator on the same device you will need an Advanced Web Application Firewall (AWF) add-on license.

**Note** : SSL Orchestrator 11.0 requires BIG-IP version 17.1.0

## Configuration

From the SSL Orchestrator Guided Configuration click Services then Add

 ![Screen Shot 2023-04-04 at 12.45.48 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/a/a2cf0ad444b2ffb536b4545e6c2f3a76c963315c.png)

Select the F5 tab then double click on F5 Advanced WAF (On-Box)

 ![Screen Shot 2023-04-04 at 12.48.59 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/8/84c60ff5de960a27522da19357c14a8749023828.png)

Give it a name, F5\_AWAF in this example

Click the down arrow next to Application Security Policy and select your Advanced WAF policy, Advanced-WAF-Policy in this example

 ![Screen Shot 2023-04-04 at 12.51.59 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/c/ce8316a57191d3bb2d86af6eece24a1d64520e37.png)

The Advanced WAF Policy protects your web applications from application attacks like SQL injection, cross-site scripting and a variety of other malicious attacks.&nbsp; You can also specify a DoS Protection and Bot Defense Profile.

A DoS Protection profile will also protect your web applications from Denial of Service attacks.

A Bot Defense Profile will protect your web applications from malicious bot attacks

 ![Screen Shot 2023-04-04 at 12.56.26 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/b/b6ccf7374c3f776e453505c499cbc25606758d86.png)

Select a Log Profile if desired.&nbsp; The logging of connections is important for visibility and forensics.

 ![Screen Shot 2023-04-04 at 1.00.45 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/4/2/4288813516eece9e54163790cbb2c910a19b00b5.png)

Click Save & Next at the bottom

![Screen Shot 2023-04-04 at 1.02.02 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/b/b6546442777607f9f5fe9faf7bc0c63931647092.png)

Click Save & Next at the bottom

![Screen Shot 2023-04-04 at 1.03.16 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/c/b/cb314f58edc75785a9c36fb3492a64f5e8d9ecbe.png)

Click Deploy

 ![Screen Shot 2023-04-04 at 1.04.35 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/2/2e72407a59400a00918a7e988222fc2814355853.png)

Click OK to the Success message

 ![Screen Shot 2020-06-11 at 2.22.51 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/6/676f9aa11988dc397e17e1b53a91681f294e3963.png)

Add the Advanced WAF Service to the Service Chain by clicking the Service Chains tab then click on the name of the Service Chain, Service\_Chain in this example

 ![Screen Shot 2023-04-04 at 1.09.23 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/2/2333e7178e4a1cf3bdb69c830d2a58c8801fa153.png)

Move the F5\_WAF Service from Available to Selected

 ![Screen Shot 2023-04-04 at 1.10.41 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/7/a/7ae0e30bbf01f874f8f10450c785492470f433f9.png)

Click Deploy when done

 ![Screen Shot 2023-04-04 at 1.12.51 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/c/c421f7b84b5cd1ac5d571800a9c1136361cba92d.png)

If presented with the following warning, click OK

 ![Screen Shot 2023-04-04 at 1.14.04 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/9/93956d55c9fe26e8af7f2f13d4f907aea8461640.png)

Click OK to the Success message

 ![Screen Shot 2023-04-04 at 1.15.18 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/d/d262e19377ae999d41f5de81076cc473150e45e2.png)

When done it should look like the following

 ![Screen Shot 2023-04-04 at 1.07.27 PM.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/d/4/d4bbff63b9d0032c1c97c75dec0c928fddc6db6f.png)

The configuration is now complete.&nbsp; Using the F5 Advanced WAFaaS this way is functionally the same as using it by itself.&nbsp; There are no known limitations to this configuration.

## Additional Information

For more information on configuration of SSL Orchestrator refer to the Deployment Guides [HERE](https://clouddocs.f5.com/sslo-deployment-guide/)

## Exporting/Importing WAFaaS policy

To export an existing Advanced WAF policy navigate to Security \> Application Security \> click the name of the policy you wish to export

 ![Screen Shot 2023-04-05 at 11.07.02 AM.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/4/44a210dd7111a3f699001fec513e2004626763f7.png)

Click Export then choose one of the supported formats like XML

 ![Screen Shot 2023-04-05 at 11.09.42 AM.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/1/5/159ee347d36ac75dd001b5b56d03e1fa8d33f858.png)

To import the Advanced WAF policy click Create \> Import from the Policies List screen

 ![Screen Shot 2023-04-05 at 11.13.41 AM.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/d/e/de79b4500088ab737b1dd7852da8570b45348302.png)

## Example of Advanced WAF Policy creation

A demo video of Advanced WAF Policy creation is available [HERE](https://www.youtube.com/watch?v=WxwCGj5TXl8&t=374s)

## Example of Advanced WAF Protection in action

SQL Injection is a common web application attack that should be blocked by the Advanced WAF policy.&nbsp; Here is what a typical SQL Injection attack might look like as an HTTPS request:

```tcl
https://10.1.20.200/rest/products/search?q=qwert%27%29%29%20UNION%20SELECT%20id%2C%20email%2C%20password%2C%20%274%27%2C%20%275%27%2C%20%276%27%2C%20%277%27%2C%20%278%27%2C%20%279%27%20FROM%20Users--

```

This request should be blocked and the response will look like this:

 ![SQL-Injection-blocked.png](https://d20hrnpixdzcsd.cloudfront.net/original/3X/e/3/e380590a239ff8d9de0555cae3b3743010b26e58.png)

Here is an example of what the Log File should contain:

 ![WAF-logs-blocked.png](https://d20hrnpixdzcsd.cloudfront.net/original/2X/6/61aa7ca386bbe0bed63dbd7ab3e3c33bb44086e4.png)

**Note:** Both Advanced WAF and SSL Orchestrator are CPU-driven functions. This will need to be factored into capacity planning when deploying the two together.
