Skip to content
Migrated from on-pr...
 
Notifications
Clear all

Migrated from on-prem F5 to cloud WAF - what we missed

1 Posts
1 Users
0 Reactions
17 Views
(@jamesk)
Estimable Member
Joined: 3 months ago
Posts: 80
Topic starter   [#14143]

Hey folks. Just wrapped up a six-month migration from our old F5 ASM on-prem boxes to a major cloud WAF vendor (won't name them, but it's one of the big three). Overall, the scalability and managed rules are great, but we missed some crucial operational nuances that bit us during the cutover. Sharing here so you can check your list twice.

The big thing we underestimated was **application learning vs. positive security modeling**. Our F5 had years of learned URLs, parameters, and cookies. The cloud WAF came with a generic rule set and we assumed "learning mode" would replicate that. It didn't. We had to manually rebuild our trusted entity lists for several core apps. For example, our legacy app passes JSON in a custom `X-Data` header. The cloud WAF blocked it until we explicitly added it to the "trusted headers" list in a custom rule.

Here’s a snippet of the Terraform we used to fix it, after the fact:

```hcl
resource "cloud_waf_custom_rule" "allow_legacy_app_headers" {
name = "Allow-Legacy-App-Headers"
priority = 10
action = "allow"
conditions {
field = "REQUEST_HEADERS"
operator = "contains"
value = "X-Data"
}
}
```

Other gotchas:
* **SSL/TLS decryption depth:** On-prem, we decrypted and inspected everything internally. Cloud WAF, by default, might not forward client cert details or inspect past the initial proxy layer. We had to reconfigure our origin to trust the WAF's IPs and set up custom headers for client IP and TLS version.
* **Logging granularity and cost:** The default logs were too sparse for our SecOps team. Enabling full request/response logging for debugging created a massive (and expensive) data stream. We had to implement sampling and filtering early.
* **API endpoint protection:** The F5 handled our north-south and east-west traffic. The cloud WAF only sees internet traffic. We had to roll out a separate service mesh policy for internal API security, which wasn't part of the original project scope.

Anyone else made this jump? How did you handle the positive security model transition and logging costs? I've got some more Helm chart tweaks for the sidecar collectors if anyone's interested.

-jk



   
Quote