F5 Distributed Cloud WAF

F5 Distributed Cloud WAF eases the burden and complexity of consistently securing apps across clouds, on-premises, and edge locations.

TrustRadius award

Combining F5’s Industry-Leading WAF with an Easy-to-Use SaaS Format

Secure app development with DevOps agility and SecOps control

Secure app development with DevOps agility and SecOps control

Simplify app security by seamlessly integrating protections into the development process with core security functionality, centralized orchestration, and oversight. Delivering the programmability that DevOps needs combined with the efficacy and oversight that SecOps mandates, enabling faster, more secure application delivery and release cycles.

Comprehensive protection with fewer false positives

Comprehensive protection with fewer false positives

Utilize both signature-based and AI/ML based detection techniques with automatic signature tuning to ensure maximum efficacy and reduced SecOps workloads.

Product Overview

Diagram of the F5 Distributed Cloud WAF

Secure apps in the cloud, on-premises, at the edge, or in the F5 Global Network

F5 Distributed Cloud WAF is a next-gen SaaS-based web application firewall that provides signature and behavioral-based threat detection to protect applications wherever they are deployed.

Manage and protect application workloads hosted across clouds, including AWS, Azure, and GCP.

Manage and protect applications at your data center and edge sites.

Manage and protect application workloads from any of the points of presence (PoPs) on the F5 Global Network.

Core Capabilities

F5 Distributed Cloud WAF combines signature and robust behavior-based protection for web applications. It acts as an intermediate proxy to inspect app requests and responses to block and mitigate a broad spectrum of risks stemming from the OWASP Top 10, threat campaigns, malicious users, layer 7 DDoS threats, bots and automated attacks, and more.

Captures Common Vulnerabilities and Exposures (CVEs) plus known vulnerabilities and techniques identified by F5 Labs, including Layer 7 DDoS, threat campaigns, bots, and automated threats.

Leverages AI/ML to monitor and score client interactions, deciphering intent based on the number of WAF rules hit, forbidden access attempts, login failures, error rates, and more, to help identify an app’s highest priority threats.

Enables micro segmentation and advanced security at the application layer, utilizing IP reputation and allow/deny lists to block clients with known bad TLS fingerprints, ASNs from suspicious countries, and more.

Easily determines if a signature-identified attack is really a threat, helping reduce the number of false positives.

Deploy through a simple UI or automate via APIs including best-practice default protections and the flexibility to create custom rules.

Rich observability via a single dashboard with a 360-degree view of app performance and security events across distributed applications.

Choose to deploy and manage on your own or as a managed service—deployed, maintained, and supported 24x7 by certified F5 experts in our SOC.

Platform Support

Broad platform and cloud provider support

Distributed Cloud Services can be delivered to apps running on any platform on any public/private cloud. Connect and secure apps running in VMs, containers, bare metal or serverless.

Simplifying DevOps and SecOps

F5’s native Terraform provider, vesctl CLI tool, and public APIs deliver the automation needs of app teams. Support for alerting tools (i.e., Opsgenie and Slack) and SIEM tools (i.e., Splunk and Datadog) simplify life of DevOps and SecOps.

Resources

trustradium-2023-best-value-and-featureset

F5 Distributed Cloud WAF Wins 2023 Awards

TrustRadius users have recognized F5 Distributed Cloud WAF in 2023 in three prestigious categories: Best Value for Price, Best Relationship, and Best Feature Set. We’re honored and excited that so many users of our solution think so highly of it, and of F5 overall.

See all 6 F5 TrustRadius Awards ›