Listing Thumbnail

    F5 Advanced WAF with LTM, IPI, and Threat Campaigns (PAYG, 25Mbps)

     Info
    Sold by: F5, Inc. 
    Deployed on AWS
    Free Trial
    F5 Advanced WAF (AWF) is an industry leading Web Application Firewall (WAF) that delivers the most innovative capabilities for application protection. Key features include anti-bot, DDoS Mitigation, Behavioral App Protection, Application Vulnerability Protection, and more.

    Overview

    Play video

    This offering includes a free, full featured 30-day trial as well as access to F5 premium support.

    The F5 Advanced WAF is an industry-leading web application firewall providing comprehensive protection for your websites, mobile apps, and APIs. Leveraging behavioral analytics, automated learning capabilities, and risk-based policies, the F5 Advanced WAF secures applications against threats including application-layer DoS attacks, malicious bot traffic, all OWASP top 10 threats and API protocol vulnerabilities.

    In addition to attack mitigation, powerful reporting capabilities allow for easy, real-time analysis of attacks allowing you to quickly make informed security decisions.

    This offering includes load balancing, IP Intelligence threat feed, and Threat Campaigns.

    Combining BIG-IP VE with F5 Container Ingress Services (free & open-source) delivers advanced application services to container environments including Kubernetes.

    Additionally, F5 has made it faster and easier to deploy and configure BIG-IP VE via the following mechanisms that can be integrated with all common automation and CI/CD tools:

    Consult the following topics for implementation details:

    For sales inquiries, contact our sales organization at here.  and for all other general inquiries, email F5 at tellaskf5@f5.com .

    Highlights

    • Proactive Bot Protection - Using fingerprinting and challenge/response techniques in combination with behavioral analysis, Advanced WAF blocks automated attacks like account takeover, web/content scraping, and vulnerability recon.
    • Advanced Application Protection - Combining machine learning and threat intelligence, Advanced WAF protects against OWASP Top 10 threats, application-layer DoS attacks, malware-infected browsers, and more.
    • Includes an IP Intelligence threat feed to block traffic from and to malicious IPs. Also, includes regular updates to Threat Campaigns signatures.

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    CentOs 7.3

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    F5 Advanced WAF with LTM, IPI, and Threat Campaigns (PAYG, 25Mbps)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (76)

     Info
    Dimension
    Cost/hour
    m5.xlarge
    Recommended
    $1.45
    m4.10xlarge
    $1.45
    m6i.4xlarge
    $1.45
    m3.xlarge
    $1.45
    t2.large
    $1.45
    m5n.xlarge
    $1.45
    m4.xlarge
    $1.45
    c5n.9xlarge
    $1.45
    m5.12xlarge
    $1.45
    r5.2xlarge
    $1.45

    Vendor refund policy

    For the hourly licensed AMI, F5 does not offer refunds, you may cancel at any time.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Additional details

    Usage instructions

    Before deploy: Create a key pair and VPC (if none exists).

    After deploy: Wait approximately 6 minutes before logging in. SSH (login w/ your ssh key as username 'admin') to the instance and run these tmsh commands to set the admin password (GUI User, not SSH): modify auth user admin password save sys config.

    Log into the Config utility web page: If only one NIC was present during deploy, use https://[eth0-IP]:8443. If more than one NIC was present during deploy, use https://[eth0-IP]:443. Ensure your security groups allow access to the required port.

    For details, see: http://clouddocs.f5.com/cloud/public/v1/aws_index.html  https://support.f5.com/csp/knowledge-center/cloud/Public%20Cloud/Amazon%20Web%20Services 

    Support

    Vendor support

    You can open a support case in the F5 WebSupport Portal , review additional F5 technical support documentation here  or contact F5 support directly (24x7x365):

    • North America: 1-888-882-7535
    • Outside North America: +800 11 ASK 4 F5 (800 1127 5435)

    F5 support centers are strategically located for partners and customers in APAC, Japan, EMEA and North America. Regionally located support centers enable F5 to provide support in a number of languages through native-speaking engineers who are available when you are.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Application Development, Network Infrastructure

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    2 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    13 reviews
    Insufficient data
    1 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Web Application Firewall
    Comprehensive protection for websites, mobile apps, and APIs using behavioral analytics and automated learning capabilities
    Threat Detection
    Advanced protection against OWASP Top 10 threats, application-layer DoS attacks, and malicious bot traffic using machine learning and threat intelligence
    Bot Protection
    Proactive defense using fingerprinting, challenge/response techniques, and behavioral analysis to block automated attacks like account takeover and web scraping
    IP Intelligence
    Integrated threat feed to block traffic from and to malicious IP addresses with regular signature updates
    Container Integration
    Advanced application services deployment for container environments including Kubernetes using BIG-IP VE and Container Ingress Services
    Web Application Threat Protection
    Comprehensive ruleset covering OWASP Top 10 web application threats including SQL Injection, Cross Site Scripting, and Known Exploits
    Security Signature Updates
    Regular threat information updates from FortiGuard Labs to maintain current protection signatures
    Malicious Traffic Detection
    Protection against malicious bots and common vulnerabilities and exposures (CVE)
    Configurable Security Response
    Flexible configuration options to log, alert, and block detected web application threats
    Attack Vector Coverage
    Comprehensive security rules targeting multiple web application attack vectors including general and known exploits
    Web Application Threat Protection
    Comprehensive ruleset targeting OWASP Top 10 Web Application Threats with low false-positive rate
    Vulnerability Mitigation
    Managed rules addressing code injection techniques including SQLi, NoSQLi, OScommandi, XSS, and directory traversal
    Technology-Specific Security
    Protection against known exploits for web technologies like Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, and Joomla
    Threat Intelligence Integration
    Regularly updated rulesets incorporating latest cyber threat intelligence
    Compliance Support
    Security rules designed to help meet security standards such as PCI-DSS

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    2 AWS reviews
    |
    18 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    RoiNahari

    Bot protection capabilities enhance application security

    Reviewed on Apr 16, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I am working with an integration and security company that collaborates with various vendors. I am currently dealing with F5 Advanced WAF .

    What is most valuable?

    The whole mechanism of F5 Advanced WAF  is effective. It contains the logic of both negative and positive security combined, providing added value to the company I work with to protect their applications.

    What needs improvement?

    I do not have anything in mind right now that needs improvement. Generally, it works well. If we need any specific feature, we approach F5 directly.

    For how long have I used the solution?

    I have probably used it for ten years or so.

    How are customer service and support?

    I do not need them much because my team is professional. If there is a bug, the support is usually understanding and resolves issues.

    How would you rate customer service and support?

    Neutral

    What's my experience with pricing, setup cost, and licensing?

    The price is affordable and satisfactory.

    What other advice do I have?

    One of the best features is the bot protection capabilities. I rate the product eight out of ten.

    reviewer2641242

    Enables flexible licensing and clear ROI evaluation

    Reviewed on Feb 24, 2025
    Review provided by PeerSpot

    What is our primary use case?

    I use F5 Advanced WAF  to manage enterprise clients, focusing on licensing and support flexibility to accommodate various customer segments, including enterprises and mid-market customers.

    What is most valuable?

    F5 Advanced WAF  provides two different licensing models. The subscription-based model offers competitive pricing, making it easier for me to see ROI. However, the perpetual license, despite an initial higher cost, lacks transparency regarding support expiration. Due to the subscription, I can compare it with other tools, but as a perpetual buyer, I am unaware of support expiration until after the purchase, allowing indicative ROI calculations but not actual ones. 

    Furthermore, F5 Advanced WAF  offers features not available in other products, though I suggest consulting a technical expert for specific features.

    What needs improvement?

    F5 Advanced WAF  sells perpetual licenses as perpetual assets during sales without informing me that support ends after a few years. I find out later and am required to pay for support without receiving updated versions. Deployment training for F5 Advanced WAF is lacking and restricts growth by being inaccessible and costly for partners.

    For how long have I used the solution?

    I provide the feedback based on my recent experience and judgment.

    How are customer service and support?

    I have interacted with F5's support, and while I have no major complaints, they could improve. I rate them eight out of ten.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    Deployment is easy for me, but enablement training is not easily available, accessible, or sufficiently supported.

    What was our ROI?

    I find it difficult to compute ROI for perpetual licenses due to the lack of upfront information about support expiry. Subscription models offer clearer ROI due to a more competitive pricing scheme.

    What's my experience with pricing, setup cost, and licensing?

    Subscription models have competitive pricing, while perpetual licenses involve an upfront higher cost, leading to ambiguity regarding support cessation. 

    Additional costs for deployment and training further impact my cost considerations.

    Which other solutions did I evaluate?

    I am interested in how F5 Advanced WAF features and pricing compare to alternatives like Fortinet and Check Point.

    What other advice do I have?

    I rate F5 Advanced WAF eight out of ten. 

    Despite a few issues, F5 Advanced WAF is performing well for me. Improving engagement and enablement for partners would enhance its value to GSI partners and service providers. 

    Overall, I see potential positive development for the product.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Amr Shawky

    Comprehensive security solution provides robust protection against threats

    Reviewed on Dec 24, 2024
    Review provided by PeerSpot

    What is our primary use case?

    The AOF solution is used for any customer with applications to protect them. It provides security features to protect the application from threats such as SQL injections and challenges of the browser using AI.

    What is most valuable?

    The AOF solution provides numerous security features. It protects applications from various threats, including SQL injection, and ensures that the application behavior is from a human, not a bot. It includes DDoS protection which has been enhanced after migrating from SDM. 

    The solution is very effective as it includes security features important for financial applications where protection is necessary to avoid potential financial loss or penalties. It helps protect the core and backend of applications.

    What needs improvement?

    One improvement for AOF could be focusing on enhancing its AI engine to make it more mature.

    For how long have I used the solution?

    I have used the solution for almost two years.

    What do I think about the stability of the solution?

    F5 is very good in terms of stability with no issues reported during maintenance.

    What do I think about the scalability of the solution?

    F5 scalability is excellent. I have not experienced any issues with scalability.

    How are customer service and support?

    F5 customer support is good but not as excellent as Infoblox support due to complexity issues. I would rate F5 customer support as seven out of ten.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I recommend Infoblox because it's a leader in DNS security with more than 15 customers using it. It is very flexible in configuration, support, and scalability compared to F5.

    How was the initial setup?

    The initial setup involves sending a request, understanding requirements such as policy and application number, and ensuring prerequisites are ready. It uses policy virtual servers and the network WAF , taking about five or six days to implement.

    What was our ROI?

    The ROI is very impressive as it is crucial for financial applications to be protected efficiently. Ensuring application security is a significant milestone, crucial to prevent financial losses or penalties.

    What's my experience with pricing, setup cost, and licensing?

    The setup cost is normal, yet not the best in terms of the commercial aspect. Other competitors like Fortinet are cheaper than F5.

    Which other solutions did I evaluate?

    Fortinet and its FortiWeb product are competitors to F5. Fortinet has many products yet lacks concentration on a single part, unlike F5.

    What other advice do I have?

    For enterprises in the financial sector, having F5 is essential. I would rate the solution a ten out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Abdul Azim

    Client-side and mobile app protection with 24/7 support for security

    Reviewed on Dec 23, 2024
    Review provided by PeerSpot

    What is our primary use case?

    F5 Advanced Web Application Firewall  (AWAF) is primarily used in financial sectors like banking to secure web applications against advanced threats, ensuring compliance with industry regulations. Our Key use cases include:

    1. Protection Against OWASP Top 10: Safeguarding banking applications from SQL injection, XSS, and other common vulnerabilities.
    2. Bot Mitigation: Detecting and blocking malicious bots to prevent account takeovers, credential stuffing, and fraud.
    3. DDoS Protection : Defending against application-layer DDoS attacks to ensure service availability.
    4. PCI DSS Compliance: Enforcing security policies to meet compliance standards for protecting sensitive customer data.
    5. API Security : Securing APIs used in banking platforms from abuse and unauthorized access.
    6. Threat Intelligence: Leveraging threat intelligence to identify and mitigate zero-day attacks.
    7. Application Traffic Control: Managing and monitoring application traffic to ensure optimal performance and security.

    These use cases help financial institutions maintain secure and resilient applications, critical for trust and compliance.

    How has it helped my organization?

    F5 Advanced WAF  has significantly enhanced our organization's security posture by protecting critical banking applications against sophisticated threats. It ensures compliance with regulatory standards, improves customer trust through robust bot mitigation, and enhances application performance by mitigating DDoS attacks and securing APIs. Additionally, it provides real-time threat intelligence and streamlined security management, reducing downtime and operational risks.

    What is most valuable?

  • Bot Protection: Mitigates automated attacks like credential stuffing.

  • API Security : Safeguards APIs against exploitation.

  • Advanced Threat Detection: Protects against OWASP Top 10 vulnerabilities and zero-day threats.

  • DDoS Mitigation: Ensures application availability during attacks.

  • Behavioral Analytics : Detects and mitigates anomalous traffic patterns.

  • Granular Policy Control: Enables precise security policy customization.

  • Threat Intelligence Integration: Offers real-time updates for proactive protection.

  • What needs improvement?

    1. Ease  of Deployment: Simplify initial setup and policy configuration.
    2. UI Enhancements: Improve user interface for better navigation and usability.
    3. Integration: Enhance compatibility with third-party tools like SIEMs and DevOps pipelines.
    4. Performance Optimization: Reduce latency during high traffic volumes.

    Suggested Features for Next Release:

    1. AI-Driven Threat Detection: Advanced machine learning for proactive defense.
    2. Comprehensive API Protection: Extended support for GraphQL and WebSocket APIs.
    3. Cloud-Native Integration: Better functionality in hybrid and multi-cloud environments.
    4. Automated Policy Suggestions: AI-based recommendations for policy tuning.

    For how long have I used the solution?

    It's been two years that I've been working with this solution.

    What do I think about the stability of the solution?

    I am not experiencing any significant instability.

    What do I think about the scalability of the solution?

    F5 AWAF offers excellent scalability, enabling organizations to protect applications seamlessly across on-premises, cloud, and hybrid environments. It can handle increasing traffic volumes with minimal latency, ensuring consistent security for both small-scale deployments and enterprise-grade architectures. With its ability to integrate into CI/CD pipelines and auto-scale in cloud environments, F5 AWAF supports dynamic application growth without compromising performance or protection.

    How are customer service and support?

    Customer service is very responsive. If the issue persists beyond my local support capabilities, I open a ticket with F5, and they respond quickly. I rate their technical support 9 out of 10.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Not now just I have checked the comparision and collect reviews from peerspoot and Quadrant 

    How was the initial setup?

    The initial setup experience is straightforward, and I did not face any complexities. I recommend deploying the F5 AWAF solution on a single appliance with LTM.

    What's my experience with pricing, setup cost, and licensing?

    F5 is relatively less expensive compared to other solutions as F5 is considered the best.

    Which other solutions did I evaluate?

    Not Now

    What other advice do I have?

    I rate F5 eight to nine out of ten. I recommend F5 to customers who require a robust solution and have the budget for it. However, for customers looking for modest pricing, I would not recommend the F5 solution.

    I'd rate the solution eight out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Ahmed Moamen

    Protects applications with versatile authentication features

    Reviewed on Dec 03, 2024
    Review provided by PeerSpot

    What is our primary use case?

    The primary use case for F5 Advanced WAF  is to protect applications that are exposed to the internet. It is used to protect applications from known attacks, such as cross-site scripting and DDoS attacks.

    What is most valuable?

    F5 offers a versatile solution that can be integrated with APM  in cases where integration with an external IDB is needed. It is useful for authentication backup if the on-prem directory service is unavailable. 

    Additionally, its WAF  functionality is valuable for protecting applications from attacks. It is a versatile and strong solution that's easy to understand and deploy.

    What needs improvement?

    The DDoS capabilities should be enhanced. More advanced features related to DDoS would be beneficial.

    For how long have I used the solution?

    I have been working with F5 Advanced WAF  since 2017, which is almost eight years.

    What do I think about the stability of the solution?

    The stability is high. It's a robust product with high availability, ensuring no disruptions for end-users if a node failure is detected. Our deployments are based on high availability clustering.

    What do I think about the scalability of the solution?

    F5 Advanced WAF  is highly scalable, both in its physical and virtual forms. Its scalability is based on the search, making it adaptable for various needs.

    How are customer service and support?

    The support from F5 is excellent, with resources readily available online. The quality of support depends on the service SLA purchased, with various levels of service provided.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup of F5 Advanced WAF is straightforward and easy to understand. Without prior training, I could build and publish applications using just the documentation.

    What about the implementation team?

    For standard and straightforward deployments, the implementation can be handled by a single person or a team based on the customer's size. Professional service can simplify the process significantly.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is not cheap; I rate it a six out of ten.

    While it reflects the advanced capabilities of the product, reconsideration of the pricing is suggested.

    What other advice do I have?

    For reverse proxy solutions, F5 Advanced WAF is the best choice. 

    Overall, I rate the solution an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    View all reviews