When Rule sets aren't enough F5 Distributed Cloud WAF (Web Application Firewall) brings the brains
Use Cases and Deployment Scope
The big problem it mainly solves for us is zero day and unknown attack vectors. Right now every customer facing app and all our internal admin portals run behind F5 Distributed Cloud WAF. We've also wired it into our SIEM and SOAR tools to enrich alerts with traffic metadata and auto-initiate playbooks.
Pros
- Identifying exposure risks
- Mitigating bot and automation abuse
- The superb dynamic inspection capabilities
Cons
- Policy testing in pre production still requires some finesse. Maybe a sandbox environment with traffic replay built in would go a long way.
Likelihood to Recommend
Well in my organization, we use F5 Distributed Cloud WAF to secure all client facing APIs and web services across our multi-cloud environments. Our agency builds and deploys web apps for clients in different fields. These apps often have a short sprint cycles, frequent releases and just varying API architectures. Now that opens a lot of surface area for attacks and that's where F5 Distributed Cloud WAF comes in.
