Around fifty F5 Advanced WAF (ASM) capabilities, and how WAFY builds and tunes each one at Basic, Standard and Premier. WAFY manages and runs these policies for you.
Basic, Standard and Premier are feature tiers: they set how much of the F5 Advanced WAF (ASM) toolkit WAFY applies, independent of how many policies you run. Grades below describe how each capability is built and tuned at that tier, across HTML web applications and API endpoints alike. The OWASP column maps each capability to the OWASP Top 10 items it helps address (Web 2021 and API 2023). Pricing scales separately by policy count, published in full on the Subscription Services grid. Grading, cadence and OWASP mappings shown here are confirmed per estate.
| Capability | Basicfrom £3,000 / year | Standardfrom £3,500 / year | Premierfrom £4,000 / year |
|---|---|---|---|
| Policy scope and cadence | |||
| Learning suggestion reviews How often we work through the policy's learning suggestions. | Monthly | Monthly | Weekly |
| Event logs, correlation reviews and reports Regular review of request/violation logs, correlated and reported back. | Monthly | Monthly | Weekly |
| Attack signature updates (incl. staging review), all scopes Signatures updated, reviewed in staging, then promoted to blocking. | Monthly | Monthly | Monthly |
| Policy review Periodic health review of the policy's configuration and posture. | |||
| Entities and positive security | |||
| File type entities How tightly file types are enumerated and enforced. | Compact / Selective | Selective / Always | Always |
| URLs / endpoints Explicit URL entities managed in the policy. | Never / Compact | Selective / Always | Selective / Add all |
| URL allowed / disallowed Allow / disallow rules for URLs. | Wildcard / Compact | Selective / Always | Always |
| Parameter reviews How thoroughly parameters are enumerated and tuned. | Wildcard / Compact | Selective / Always | Always |
| Cookie security (allowed / enforced), ASM cookie protection ASM cookie signing and allowed/enforced cookie handling. | Never or Selective | Selective | Selective |
| Content profiles (XML / JSON) Structured request body validation for XML and JSON. | |||
| Core protections (every tier) | |||
| Evasion techniques (detecting and tuning) | |||
| HTTP protocol compliance (detecting and tuning) | |||
| Response code tuning based on application traffic | |||
| Illegal HTTP response blocking | |||
| Standard tier and above | |||
| Hostnames and redirect domains | |||
| Data Guard Masking of sensitive data (e.g. card / national ID numbers) in responses. | |||
| CSRF configuration | |||
| Complex API policies (methods / content profiles) Method and content-profile enforcement for richer API policies. | |||
| Parameters (URL / flow / global) | |||
| Parameter properties (including sensitive) | |||
| Premier tier | |||
| Web services security | |||
| Antivirus / ICAP File upload scanning via ICAP. | |||
| IP address and geolocation settings | |||
| Disallowed access from user / session / device | |||
| Login pages, bypass and expiry | |||
| Header protections | |||
| Brute force protection | |||
| IP address intelligence (licence dependent) Requires the IP Intelligence subscription on the device. | |||
| DDoS profiles and DDoS tuning | |||
| Policy templates and parent policies | |||
| Parent policies / inheritance settings | |||
| Rapid deployment policies for interim protection | |||
| Further capabilities (scoped on request; grading to confirm) | |||
| Bot defence and bot defence tuning (learning / ignoring) | · | · | · |
| Policy cleanup of unused objects | · | · | · |
| Threat campaigns | · | · | · |
| Customised response pages | · | · | · |
| PCI compliance PCI DSS, not OWASP. | · | · | · |
| OWASP compliance reporting and OWASP tightening Addresses the OWASP Top 10 as a whole. | · | · | · |
| Policy type setting and tuning | · | · | · |
| File types and dynamic file type protections | · | · | · |
| Microservices protection | · | · | · |
| Logging formatting and tuning (Splunk / Syslog) | · | · | · |
| LTM local traffic policies for ASM distribution / bypassing | · | · | · |
| Policy bypassing and failsafe systems | · | · | · |
| Shun reporting | · | · | · |
| Custom signatures and custom signature sets | · | · | · |
The Basic, Standard and Premier tiers and their prices are published in full on the Subscription Services page. Grading, cadence and OWASP mappings shown here are confirmed per estate. “Where” shows whether a capability typically applies to HTML web applications, API endpoints, or both. The OWASP column maps each capability to the OWASP Top 10 items it helps address (Web 2021 and API 2023); a capability often supports more than one, and some are general controls with no single mapping.