WAFY's F5 ASM experience includes a global interbank network that ran 79 separate Advanced WAF (ASM) policies on a single domain, one per application. Traffic was routed by a proxy behind the F5, so there was little local traffic routing on the BIG-IP itself, and many virtual servers pointed at a single pool member. The applications ran on very different stacks, with MySQL, SQL Server and Oracle back-ends and varied authentication and logging, and each had an application owner who regarded their application as absolutely business-critical. So the work was as much about confidence as configuration: every policy was enabled together, then moved into blocking one application at a time, through a single large weekend change window. Despite the understandable nervousness, every policy reached blocking without a single incident. Much of the effort went into XSS and SQL injection, today both OWASP A03 (Injection), and into talking to and training the development and application-owner teams so they trusted what enforcement would do. A significant DDoS protection project ran alongside the policy work.