f5 rules for aws waf
94 TopicsAWS F5_OWASP Managed Rule Blocking requests
AWS F5 OWASP managed rules are blocking requests all of a sudden (23-01-2025) We want to understand if there was any update made and also the changelog for this update and which rules were updated. Where do I find this information and AWS is not supporting these rules since these are managed by F5. Do we have a way to reach the vendor ?195Views1like5CommentsSilent update AWS Marketplace F5 OWASP
We use the F5 Rules for AWS WAF - Web exploits OWASP Rules for our WAF setup. Since 2025-07-13 T21:00:00 we see an enormous increase in blocked traffic on three rules blocking our legitimate traffic globally (on approx. 40 servers for different customers). Has a silent update been pushed (to the regex or something)? We've been reviewing our codebase and IaC logs - no changes from our side. The three rules that suddenly spike: rule_Cross_Site_Scripting_AllQueryArguments_Body rule_General_Protection__URI__UriPath rule_General_Protection_AllQueryArguments_BodySolved157Views1like2CommentsF5 Rules for AWS WAF CVE-2021-40438
Hello, We're checking in the AWS marketplace for the F5 Rules for AWS WAF - Common Vulnerabilities and Exposures (CVE) Rules and want to check if CVE-2021-40438 is covered by this rule set? https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40438478Views1like4CommentsF5 Rules for AWS WAF - Rule ID to Attack Type Reference
F5 offers security solutions for AWS customers who use the platform's hosting and load balancing services along with the AWS WAF offering. F5 Rules for AWS WAF - Web exploits OWASP RulesF5 Rules for AWS WAF - Bot Protection RulesF5 Rules for AWS WAF - Common Vulnerabilities and Exposures (CVE)F5 Rules for AWS WAF - API Security Rules With the recent addition of logging capabilities of requests that had a match with one of the rule sets, there is now an option to: See the full request that had a match with the rule ID. Understand the attack type that relates to the rule ID. Remove specific rule ID from the rule set in the case it generates false positives. The following CSV maps between rule IDs and attack types, and will help customers of the F5 Rules for AWS WAF products to better manage rule exclusions in their Access Lists. For more details on AWS-WAF logging configuration please visit:https://docs.aws.amazon.com/waf/latest/developerguide/logging.html2.6KViews1like9CommentsHow much does it cost to apply "F5 Rules for AWS WAF - Common Vulnerabilities & Exposures (CVE) Rules" to Cloudfront?
Hello How much does it cost to apply "F5 Rules for AWS WAF - Common Vulnerabilities & Exposures (CVE) Rules" to Cloudfront? The product page describes it as follows https://aws.amazon.com/marketplace/pp/prodview-y4tlpqpjpm4qi Monthly fee for each applicable region (pro-rated per hour) $20 / unit I understand that there is a fee for each region when applied to ALB, but what about Cloudfront? Will I be charged for all regions?424Views1like1CommentAWS WAF - Web Exploits Rules by F5 - Log4J Update
Hi F5 Does the ruleset "AWS WAF - Web Exploits Rules by F5" now offer any protection from requests seeking to exploit the Log4J vulnerability described in CVE-2021-44228 If not currently - can you advise when we may expect an update? Thank you527Views1like2Comments