SCHIZOSCHIZOSCHIZO
  • WORK
  • ABOUT
  • BRAIN DUMP
  • TOOLS
  • CONTACT
2025-08-05

F5 BIG-IP Web Application Firewall

f5bigipWAFWeb SecurityOWASP

Positive security model

  1. >Positive: only allow positive (good) requests and block all others — e.g. allowed file types, allowed URL, allowed parameters, and allowed responses.
  2. >Negative: allow all traffic except known negative (bad) requests — e.g. attack signatures, malware hidden behind legitimate traffic, Data Guard.

Policy templates

  1. >Rapid
    • >Minimal configuration
    • >Relies on negative security
    • >Learning mode — Manual
    • >Enforcement mode — Transparent
  2. >Fundamental

Security policy

  1. >Transparent — do not block, let traffic pass and learn.
  2. >Blocking — blocks requests if the policy is attached.

Signature

  1. >Learn — appears in the traffic learning page.
  2. >Alarm — appears in the event log if the policy is in transparent. If the security policy is in blocking, the alarm will be generated even if the alarm flag is not ticked.
  3. >Block — block requests belonging to selected signature sets.

Signature sets

  1. >Staging — this signature set is learning and will not block anything.
  2. >Enforced — block traffic from this signature set.
WAF policy check1/3

Which security model allows only traffic you have explicitly defined?

Signature actions3 blanks

A signature can (traffic learning page), (event log), or requests in the selected set.

try it before revealing

Read next

  • 2026-01-13 · Deep DivesF5 BIG-IP Next and Distributed Cloud
  • 2026-06-25 · CheatsheetsSSL Offloading on F5 BIG-IP
  • 2026-06-25 · Byte-SizedLocking Down Ports on F5 BIG-IP
  • 2026-06-17 · ChecklistsConfiguring DNSSEC on F5 BIG-IP DNS

← All PostsSCHIZO Brain Dump
SCHIZO

Suhesh Kasti — AppSec & Offensive Security

Navigate

  • ▸ Projects
  • ▸ Brain Dump
  • ▸ Cyber Tools
  • ▸ About
  • ▸ Contact
  • Download CV

Connect

  • ◆ GitHub
  • ◆ LinkedIn
  • ◆ Twitter
  • ◆ YouTube
  • ◆ Telegram
© 2026 SCHIZO

Press / to search