LIVE · HOW WOULD YOU LIKE TO CONSUME THIS PAGE?
Close
Privacy settings
We use cookies and similar technologies that are necessary to run the website. Additional cookies are only used with your consent. You can consent to our use of cookies by clicking on Agree. For more information on which data is collected and how it is shared with our partners please read our privacy and cookie policy: Cookie policy, Privacy policy
We use cookies to access, analyse and store information such as the characteristics of your device as well as certain personal data (IP addresses, navigation usage, geolocation data or unique identifiers). The processing of your data serves various purposes: Analytics cookies allow us to analyse our performance to offer you a better online experience and evaluate the efficiency of our campaigns. Personalisation cookies give you access to a customised experience of our website with usage-based offers and support. Finally, Advertising cookies are placed by third-party companies processing your data to create audiences lists to deliver targeted ads on social media and the internet. You may freely give, refuse or withdraw your consent at any time using the link provided at the bottom of each page.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Wallarm vs. F5.

Wallarm API Security brings API discovery, API and web protection, abuse prevention, and MCP controls into one product. F5 delivers the capabilities compared here across BIG-IP and API Security Local Edition, F5 Distributed Cloud, F5 WAF for NGINX, and its AI Security portfolio.

Integrated API security

for API discovery, WAAP, and MCP.

Wallarm

✓ Yes

F5

– Across multiple products

API leak detection

Exposed credentials on public sources

Wallarm

✓ Yes

F5

✕ NO

Every claim cites public documentation and names the F5 product it applies to.

Not sure which F5 product protects your APIs? Here's how to check.

See Wallarm In Action

At a glance

One Wallarm product. Four F5 offerings.

Nine capabilities, compared product by product and cited to public documentation. Claims about F5 come from F5's own public materials.

✓

SUPPORTED

–

Partial or indirect

✕

Not supported or not documented

Capability

Wallarm API Security

F5 BIG-IP

F5 Distributed Cloud

F5 WAF for NGINX

F5 AI Security

Inline enforcement

✓

Request-level attack handling, session blocking, and IP-based controls [6][7]

✓

WAF enforces inline; Local Edition pairs with it [3][8]

✓

Schema validation can report or block non-conforming traffic [15]

✓

GraphQL- and gRPC-specific enforcement [10][11]

API protocols

✓

REST, GraphQL, gRPC, SOAP, WebSocket [1][9]

–

Discovers GraphQL, gRPC, SOAP, XML-RPC [12]

✓

GraphQL and gRPC protection [10][11]

Behavioral API detection

✓

BOLA, enumeration, forced browsing, brute force [13][14]

✓

Schema plus runtime behavioral detections, incl. BOLA [15][16]

Credential stuffing

✓

Checks against 850M+ HIBP-derived records [17]

–

Product page lists credential theft among threats addressed [35]

✓

Real-time compromised-credential detection [18]

Bot and automated abuse

✓

ATO, scraping, IP and session rotation [19]

–

Product page lists automated attacks and bots among threats addressed [35]

✓

Botnet and simulation-software defenses [18]

API discovery

✓

Continuous API and MCP inventory from live traffic [9]

✓

Passive discovery via Local Edition [3]

✓

Discovery and schema learning [12]

–

Discovery of AI apps, agents, and MCP tool calls [24]

API leak detection

✓

Scans public resources for exposed credentials, keys, and tokens [5][20]

✕

Not found [3]

✕

Not found [15]

✕

Not found [4]

MCP controls

✓

MCP sessions, method/primitive ACLs, schema-validated tool calls [22][23]

✓

MCP traffic protection against OWASP MCP Top 10 [35]

✓

Distributed Cloud WAF MCP server protection [36]

✓

MCP tool-call discovery and runtime enforcement [24][25]

AI / LLM runtime protection

✓

AI payload inspection at configured request and response points [27]

✓

Governance, testing, runtime protection, observability [24][25]

Leak-detection review also included F5's portfolio security page. [21]

Architecture

How do Wallarm and F5 differ architecturally?

Wallarm API Security brings API discovery, API and web protection, abuse prevention, and MCP controls into one product. Wallarm AI Hypervisor is a separate AWS product for deeper AI-workload governance.

Wallarm

✓

Inline deployment handles attacks at the request level, with session and IP-based blocking controls. [6][7]

✓

Out-of-band modes observe and record malicious traffic but don't act as the inline blocking point. Inline deployment is required for blocking. [29]

✓

Deploys alongside BIG-IP inline, as a sidecar, or out of band, without changing application delivery or DDoS protection. [30]

F5

✓

BIG-IP provides application delivery, load balancing, DDoS protection, and WAF.

✓

API Security Local Edition can run entirely on customer infrastructure with no external connectivity, and pairs with BIG-IP's WAF for inline enforcement. [3][8]

–

API and AI security capabilities vary by product. [3][4]

Detection

How do Wallarm and F5 inspect API requests?

Wallarm documents dedicated parsers for ViewState and JWT. Its JWT parser works on any part of the request, exposes both the header and payload, and normally applies Base64 and JSON parsing to them, so an attack inside a nested format is inspected, not just the outer wrapper.

Wallarm

✓

Dedicated parsers for JWT header and payload, ASP.NET ViewState, Base64, and JSON. [31]

✓

BOLA, enumeration, forced-browsing, and brute-force mitigation controls operate on API sessions. [13]

✓

Credential stuffing detection checks passwords against HIBP-derived compromised records. [17]

–

Abuse is blocked once confidence is high enough not to break legitimate traffic, so not every automated request is stopped on first sight. [19]

F5

✓

F5 Distributed Cloud applies schema validation, which can report or block non-conforming traffic, alongside runtime behavioral detections. [15][16]

✓

F5 WAF for NGINX documents GraphQL-specific violations and gRPC message parsing and enforcement. [10][11]

–

Parsing and inspection controls differ across F5 products. [3][4]

Test it on the engine in your path

These are the request shapes to try, in monitoring mode, against your own deployment. Results depend on your configuration.

A Base64 payload nested inside XML.

Two stacked encoding layers.

An encoded GraphQL pagination cursor.

Requires parsing GraphQL first, then decoding the cursor.

A .NET __VIEWSTATE field.

No readable markup to pattern-match against.

A payload in the JWT header.

The header itself, decoded and inspected, not just the bearer envelope.

An archive compressed inside a JSON parameter.

Requires decompressing the parameter to reach the payload.

An injection preceded by several hundred KB of filler.

Take an injection your WAF blocks unpadded, pad it, and send it again.

The same parameter name twice.

Does the engine recombine duplicates the way your application server will?

Response

How do Wallarm and F5 block attacks?

Wallarm request-level attack handling, session denylisting and blocking, and IP-based blocking controls, so it can stop a specific session rather than an entire IP address.

Wallarm

✓

Session denylisting and blocking act on a specific API session, not only on an IP address. [6]

✓

BOLA, enumeration, forced-browsing, and brute-force controls can run in monitor, IP-block, or session-block mode. [13]

✓

Out-of-band deployment is for visibility; inline deployment is required for blocking. [29]

F5

✓

BIG-IP's WAF enforces inline, and API Security Local Edition pairs with it for enforcement on discovered APIs. [3][8]

✓

F5 Distributed Cloud schema validation can report or block non-conforming traffic. [15]

Agents & MCP

How do Wallarm and F5 approach AI agents and MCP?

Wallarm API Security groups MCP traffic into dedicated sessions and enforces tool calls with ACLs by MCP method and primitive, request verification, and validation of tools/call arguments against schemas learned from tools/list.

Wallarm

✓

MCP servers are discovered into the API inventory from live traffic. [9]

✓

MCP sessions group tool calls, resource reads, and prompts, and show the server, method, primitive, attacks, arguments, and request sequence. [22]

✓

ACL policies by MCP method and primitive, request verification, and schema validation of tools/call arguments, with invalid calls blocked. [23]

–

Deeper AI-workload runtime governance lives in Wallarm AI Hypervisor, which is available on AWS, deploys on Amazon EKS, and follows a separate onboarding flow from API Security. [28]

F5

✓

F5 WAF for BIG-IP: MCP traffic protection against the OWASP MCP Top 10. [35]

✓

F5 Distributed Cloud WAF: described by F5 as drop-in protection for MCP servers. [36]

✓

F5 AI Security Platform: AI discovery spanning applications, agents, and MCP tool calls, plus MCP tool-call detection and runtime enforcement. [24][25]

✓

F5 extends zero-trust access to agents and MCP servers. [21]

Fit

Which platform fits which security architecture?

Choose based on which product you'll actually run in front of your APIs and how many products you want to operate. If you want API discovery, protection, abuse prevention, and MCP controls in one product, plus visibility into credentials exposed outside the traffic path, Wallarm fits that shape.

Wallarm fits when

✓

You want API discovery, API and web protection, abuse prevention, and MCP controls in one product. [1][2]

✓

You need to find exposed API credentials, keys, and tokens that never cross an enforcement point. [5]

✓

API traffic carries JWT, ViewState, or nested Base64 and JSON that needs dedicated parsing. [31]

✓

You need MCP tool calls validated against learned schemas and ACLs. [23]

✓

You're keeping BIG-IP for delivery and want to layer API security alongside it. [30]

F5 fits when

✓

Application delivery, load balancing, and DDoS are the primary requirement.

✓

API security must run entirely on your own infrastructure with no external connectivity, integrated with BIG-IP. [3][8]

✓

F5 Distributed Cloud is already in the path for your APIs. [15]

Decided Wallarm fits? You don't have to rip anything out. Layer alongside BIG-IP or consolidate at renewal.

FAQ

Frequently asked questions

Which F5 product handles API security?

Several do. BIG-IP's WAF enforces inline, and API Security Local Edition adds on-premises API discovery, monitoring, and risk analysis. F5 Distributed Cloud provides schema-based and behavioral API protection. [3][8][15][16] See how to check which product you run →

Do SecureIQLab's F5 results apply to BIG-IP?

F5 identifies the product evaluated in SecureIQLab's 2026 Cloud WAAP v5.0 validation as F5 Distributed Cloud WAAP. If BIG-IP or another F5 product enforces on your APIs, test that one. [34][33]

Does F5 support GraphQL and gRPC?

Yes, depending on the product. F5 WAF for NGINX documents dedicated GraphQL and gRPC protection, and F5 Distributed Cloud discovers GraphQL, gRPC, SOAP, and XML-RPC APIs. Coverage and controls vary by product. [10][11][12]

Does F5 detect leaked API keys?

In the public F5 product and documentation pages we reviewed, we didn't find a capability for discovering exposed API credentials on public external sources. Wallarm AASM scans public resources for exposed credentials, API keys, client secrets, and authorization tokens. [21][3][15][4][5]

How does Wallarm secure MCP servers?

Wallarm discovers MCP servers from live traffic, groups MCP traffic into dedicated sessions, and enforces tool calls with ACLs by MCP method and primitive and by validating arguments against schemas learned from tools/list. [9][22][23]

Sources

Citations

Every numbered reference on this page links to public documentation from Wallarm, F5, or SecureIQLab.

[3]

F5 — API Security Local Edition

https://www.f5.com/products/api-security-local-edition

[4]

F5 — AI Security Solutions

https://www.f5.com/solutions/ai-security

[8]

F5 — API Security Local Edition Admin Guide

https://clouddocs.f5.com/products/f5-api-security-local-edition/latest/admin_guide/

[10]

F5 WAF for NGINX — GraphQL Protection

https://docs.nginx.com/waf/policies/graphql-protection/

[11]

F5 WAF for NGINX — gRPC Protection

https://docs.nginx.com/waf/policies/grpc-protection/

[12]

F5 Distributed Cloud — Enable API Endpoint Discovery and Schema Learning

https://docs.cloud.f5.com/docs-v2/web-app-and-api-protection/how-to/app-security/apiep-discovery-control

[15]

F5 Distributed Cloud — Setting Up API Protection

https://docs.cloud.f5.com/docs-v2/web-app-and-api-protection/quickstart/api-protection

[16]

F5 Distributed Cloud — Runtime API Security Detections

https://docs.cloud.f5.com/docs-v2/web-app-and-api-protection/concepts/owasp-api-security

[18]

F5 — Prevent Credential Stuffing Attacks

https://www.f5.com/go/solution/credential-stuffing

[21]

F5 — Security

https://www.f5.com/security

[24]

F5 — F5 launches AI Security Platform (press release, June 22, 2026)

https://www.f5.com/company/news/press-releases/f5-ai-security-platform-control-enterprise-risk

[25]

F5 Blog — The F5 AI Security Platform: Eliminating the guesswork from AI security (June 22, 2026)

https://www.f5.com/company/blog/the-f5-ai-security-platform-eliminating-the-guesswork-from-ai-security

[26]

F5 Blog — Securing the New AI Attack Surface: How F5 WAF Solutions Protect MCP Servers (July 30, 2025)

https://www.f5.com/company/blog/how-f5-waf-solutions-protect-mcp-servers

[32]

SecureIQLab — 2026 WAAP CyberRisk Validation v5.0: Comparative Report

https://secureiqlab.com/waap-v5-report/

[33]

SecureIQLab — Publications (F5-specific report, registration required)

https://secureiqlab.com/publications/

[34]

F5 — F5 placed in the Leader tier of the SecureIQLab 2026 Cloud WAAP v5.0 CyberRisk Validation Comparative Report (press release, August 3, 2026)

https://www.f5.com/company/news/press-releases/secureiqlab-cloud-waap-comparative-report

[35]

F5 — F5 WAF for BIG-IP (product page)

https://www.f5.com/products/big-ip-services/advanced-waf

[36]

F5 DevCentral — Securing MCP Servers with F5 Distributed Cloud WAF (August 2025)

https://community.f5.com/kb/technicalarticles/securing-mcp-servers-with-f5-distributed-cloud-waf/343032

Compare Wallarm and F5 on your own traffic.

Deploy alongside your existing F5 estate and see what each engine detects.

Get a DemoPlan Your F5 Migration →