LIVE · HOW WOULD YOU LIKE TO CONSUME THIS PAGE?
Close
Privacy settings
We use cookies and similar technologies that are necessary to run the website. Additional cookies are only used with your consent. You can consent to our use of cookies by clicking on Agree. For more information on which data is collected and how it is shared with our partners please read our privacy and cookie policy: Cookie policy, Privacy policy
We use cookies to access, analyse and store information such as the characteristics of your device as well as certain personal data (IP addresses, navigation usage, geolocation data or unique identifiers). The processing of your data serves various purposes: Analytics cookies allow us to analyse our performance to offer you a better online experience and evaluate the efficiency of our campaigns. Personalisation cookies give you access to a customised experience of our website with usage-based offers and support. Finally, Advertising cookies are placed by third-party companies processing your data to create audiences lists to deliver targeted ads on social media and the internet. You may freely give, refuse or withdraw your consent at any time using the link provided at the bottom of each page.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Keep F5 for delivery. Replace the security layer.

Wallarm unifies API discovery, web and API protection, abuse prevention, and MCP controls in one platform that deploys alongside your F5 estate. Keep F5 for application delivery, DDoS, and load balancing. Its API and AI security spans BIG-IP Advanced WAF, NGINX App Protect, Distributed Cloud, and the AI Security Platform, and the one in front of your APIs decides your protection.

No rip and replace

Deploy inline, sidecar, or out of band

Keep BIG-IP for delivery and DDoS

See Wallarm In Action

Qualifier

Which F5 product is protecting your APIs today?

This is the question that decides everything else. F5's API and AI security capabilities differ by product. A capability documented for one product may not apply to the one you actually run.

BIG-IP Advanced WAF + API Security Local Edition

The estate incumbent in most enterprises. Local Edition can run entirely on your own infrastructure with no external connectivity, adds passive API discovery, monitoring, and risk analysis, and pairs with BIG-IP Advanced WAF for inline enforcement. [1][7]

F5 WAF for NGINX

Documents dedicated GraphQL and gRPC protection. Coverage depends on it being in the path for the APIs you care about. [8][9]

F5 Distributed Cloud

Combines schema-based API protection with runtime behavioral detections, and discovers GraphQL, gRPC, SOAP, and XML-RPC APIs. [10][11][12]

F5 AI Security Platform

Covers AI governance, discovery including MCP tool calls, security testing, runtime protection, and observability. [13][14]

Worth asking internally

Name the F5 product enforcing on your top three APIs right now. Then compare that product, not the portfolio.

Why Teams Move

Why F5 customers add or move API security

1

Several products for one job.

Covering API discovery, WAF, bot defense, and AI security with F5 means combining multiple products and services. Wallarm API Security brings them into one product. [1][2][3][4]

2

Leaked keys never cross an enforcement point.

API keys and secrets exposed in public places never pass through a WAF, so no in-path product sees them. In the public F5 sources we reviewed, we didn't find a capability for discovering exposed API credentials on public external sources. Wallarm AASM scans public resources for exposed credentials, API keys, client secrets, and authorization tokens. [15][1][10][2][16]

3

Nested request formats need parsing depth.

Wallarm documents dedicated parsers for ASP.NET ViewState and JWT, exposing both the JWT header and payload and applying Base64 and JSON parsing to them. Test what your current engine does with the same requests. [17]

See the cited evidence for each: How Wallarm and F5 compare, dimension by dimension →

Capability Snapshot

Where Wallarm changes the picture

Capability

Wallarm

F5

Integration

API Security combines discovery, WAAP, abuse prevention, and MCP controls in one product. [3][4]

Capabilities delivered across multiple products and services. [1][2]

API leak detection

AASM scans public resources for exposed credentials, keys, secrets, and tokens. [16]

Not found in the public F5 sources reviewed. [15][1][10][2]

MCP enforcement

ACLs by MCP method and primitive; tools/call arguments validated against schemas learned from tools/list; invalid calls blocked. [18]

MCP tool-call discovery and runtime enforcement via the F5 AI Security Platform. [13][14]

Two Paths

Layer alongside F5, or consolidate at renewal.

Layer alongside BIG-IP

For a heavy BIG-IP estate that isn't moving.

Wallarm deploys inline, as a sidecar, or out of band. [5][6]

No change to application delivery or DDoS protection.

Covers the API path, including JWT, ViewState, and nested Base64 and JSON parsing. [17]

Expands into API discovery and external attack surface management. [19][20]

Consolidate at renewal

For when API security renewal is already in play.

Compare the F5 products you'd renew against Wallarm API Security. [1][2][3]

Bring session-aware and business-logic requirements into scope. [21][22]

Add API leak detection, which we didn't find documented in F5's public sources. [16]

Test both engines on the same traffic before the renewal decision.

Migration

Prove it on your own traffic first.

1

See what you actually have.

Wallarm builds an inventory of active APIs and MCP servers from your live traffic, so you can compare it with what your F5 policy and API documentation cover. Wallarm AASM adds exposed keys and secrets outside the traffic path entirely. [19][16]

2

Deploy alongside your F5 estate.

Inline, sidecar, or out of band, in monitoring mode. Compare what each engine detects on your own production traffic, starting with the seven request shapes to test on the engine in your path →. Nothing blocks until you decide it should. [5][6]

3

Move API enforcement to Wallarm.

Turn on request-level attack blocking, session blocking, and IP-based controls when the evidence says you're ready. Keep BIG-IP for delivery, load balancing, and DDoS. [23][24]

Common Objections

What F5 customers ask us

Still weighing the two? Read the full Wallarm vs. F5 comparison →

"We're a BIG-IP shop — F5 is already in our path."

That helps rather than hurts. Wallarm deploys alongside existing F5 traffic flows inline, as a sidecar, or out of band, with no rip and replace. BIG-IP stays where it is for delivery and DDoS. [5][6]

"F5 gives us one vendor for everything."

One vendor, several products: BIG-IP Advanced WAF, API Security Local Edition, F5 Distributed Cloud, F5 WAF for NGINX, and the F5 AI Security portfolio. Worth asking what closing the API security gap cost in integration and professional services last year. [1][2]

"F5 has a full AI security platform now."

Correct. The F5 AI Security Platform covers governance, discovery including MCP tool calls, testing, runtime protection, and observability. Compare the specific runtime controls you need. Wallarm API Security enforces MCP tool calls by method, primitive, and learned input schema. [13][14][18]

"We just renewed Distributed Cloud."

Then layer now and consolidate later. Deploy Wallarm alongside BIG-IP for the API path today, and bring the product-by-product comparison to your next renewal. See both paths →

Find out what your F5 deployment is forwarding to your origin.

Deploy Wallarm alongside your existing estate, compare detection on your own traffic, and move API enforcement when you're ready.

See Wallarm in ActionTalk to a Migration Expert

Citations

Sources

Every numbered reference on this page links to public documentation from Wallarm or F5. All sources accessed September 24, 2026.

[1]

F5 — API Security Local Edition

https://www.f5.com/products/api-security-local-edition

[2]

F5 — AI Security Solutions

https://www.f5.com/solutions/ai-security

[7]

F5 — API Security Local Edition Admin Guide

https://clouddocs.f5.com/products/f5-api-security-local-edition/latest/admin_guide/

[8]

F5 WAF for NGINX — GraphQL Protection

https://docs.nginx.com/waf/policies/graphql-protection/

[9]

F5 WAF for NGINX — gRPC Protection

https://docs.nginx.com/waf/policies/grpc-protection/

[10]

F5 Distributed Cloud — Setting Up API Protection

https://docs.cloud.f5.com/docs-v2/web-app-and-api-protection/quickstart/api-protection

[11]

F5 Distributed Cloud — Enable API Endpoint Discovery and Schema Learning

https://docs.cloud.f5.com/docs-v2/web-app-and-api-protection/how-to/app-security/apiep-discovery-control

[12]

F5 Distributed Cloud — Runtime API Security Detections

https://docs.cloud.f5.com/docs-v2/web-app-and-api-protection/concepts/owasp-api-security

[13]

F5 — F5 launches AI Security Platform (press release, June 22, 2026)

https://www.f5.com/company/news/press-releases/f5-ai-security-platform-control-enterprise-risk

[14]

F5 Blog — The F5 AI Security Platform: Eliminating the guesswork from AI security (June 22, 2026)

https://www.f5.com/company/blog/the-f5-ai-security-platform-eliminating-the-guesswork-from-ai-security

[15]

F5 — Security

https://www.f5.com/security