Web Application Firewall
aws.amazon.com
aws.amazon.com
The bugs in these supposed "best in class" devices were ridiculous.
Here's a taste:
There was a bug where it would crash on a TCP FIN packet not associated with an existing connection. When a patch was released, installing it on the standby device reset its config and caused it to takeover as master, wiping the old master in the process.
I'm not putting anything business critical behind an F5.
Hopefully they don't screw up NGINX.
- there’s a (closed source for F5) black box that’s gonna mess with some of your requests
- it might block legitimate requests that “look” like SQL injection attempts (false positives)
- a WAF adds a bunch more latency to your request/response cycle
- malicious requests will still get through the WAF (false negatives), so it’s not like you can just forget about application security after you set one up
Just like obscurity. Security is not done only through obscurity, but obscurity van increase security.