Why I like F5 Distributed Cloud WAF
Use Cases and Deployment Scope
We currently use F5 Distributed Cloud WAF to protect our external marketing websites. The business problems solved by the F5 Distributed Cloud WAF is it solves us having a way to protect our site against malicious traffic, such as SQL injections, bot attacks, Denial of service etc, while giving us a powerful tool to monitor our web page hits and provide our team an effective measure to ensure we're hitting the mark on providing good security vs. limiting access.
Pros
- Provides comprehensive security across our hybrid environment
- Provides great API protection
- Defense against DDOS
Cons
- Lack of warnings, currently the console does not provide a warning when deleting key-value entry.
- The web GUI could use some tweaking, currently no undo option when removing exclusion rules.
- Configuration complexity, currently menus and options are hidden, making it hard to configure vs on prem.
Likelihood to Recommend
I think F5 Distributed Cloud WAF is well suited for multi-cloud/hybrid environments where protecting applications is spared across environments. Also DDOS protection on the edge.
