SlideShare a Scribd company logo
NGINX
App Security
Solutions Update
DAPHNE WON
ISAAC NOUMBA
DANIEL EDGAR
| ©2021 F5
2
Agenda
• NGINX App Security Solutions Overview
• NGINX App Protect: New features for protection of modern apps
• NGINX Controller App Security
• Q&A
| ©2021 F5 NETWORKS
3
F5/NGINX is delivering on the promise of Adaptive Apps
BIG-IP
NGINX
BIG-IP +
NGINX +
SHAPE
BEACON
& AI
Simplifying traditional app delivery for
multi-cloud environments
Enabling modern app delivery
at scale
Securing every app anywhere
Unlocking the value of app insights
Web app
firewall
Secure
access
App/web
server
Anti-fraud
& anti-bot
Denial of
service
Ingress
controller
API
gateway
Load
balancer
APPLICATION SECURITY
APPLICATION DELIVERY
APPLICATION INSIGHTS
TELEMETRY
| ©2021 F5 NETWORKS
4
Tackle Your Application Security Challenges
Embed Security Policy
Your Pipeline
Integrate security controls directly
into your pipeline with security as
code.
Secure Modern Apps
Strong security controls for
microservices, containers, APIs,
and other modern topologies.
Gain Security Insights
Security tools that go beyond alerts
with intelligent security insights about
your apps and APIs.
| ©2021 F5 NETWORKS
5
Tackle your application security challenges
Security policies and protections
are optimized for DevOps
workflow.
Deploy and manage app security
controls across distributed
environments.
NGINX & F5 Investments
Embed Security Policy
Into Your Pipeline
Integrate security controls directly into
your pipeline with security as code.
Secure Modern Apps
Strong security controls for
microservices, containers, APIs, and
other modern topologies.
Gain Security Insights
Security tools that go beyond alerts
with intelligent security insights about
your apps and APIs.
Centralized visibility and insights
dig into the root cause of
application issues.
| ©2021 F5 NETWORKS
6
NGINX Controller App Security
(Available Now for Controller ADC)
(Coming soon for Controller API-Management))
NGINX App Security Offer Summary
NGINX App Protect
DOS
NGINX App Protect
WAF
ModSecurity for
NGINX Plus
ModSecurity
OSS
à
Compliance Requirements
–
Higher Performance
–
Easier Tuning
à
Individual App/
Infrastructure
Emphasis
Enterprise Emphasis w/
App Centric Controls
and DevOps Ease of Use
Free
| ©2021 F5
7
NGINX App Protect
Update
| ©2021 F5 NETWORKS
8
NGINX Plus routes, hardens, and secures your apps and APIs.
Decentralized, best-of-breed
tools that developers need for
agility.
Deployed as specific “flavors”
optimized for application,
API, and Kubernetes
environments.
Microservices Control Plane
Kubernetes
Ingress Controller
Service
Mesh
NGINX Ingress Controller
NGINX Service Mesh
CODE
CUSTOMER
Data Plane
Web Server /
Reverse Proxy
API
Gateway
Load
Balancer CDN
NGINX Plus
Bare Metal | Containers | VMs | Private Cloud | Public Cloud | Hybrid Cloud | Multi-Cloud
App
| ©2021 F5 NETWORKS
9
Microservices Control Plane
Kubernetes
Ingress Controller
Service
Mesh
NGINX Ingress Controller
NGINX Service Mesh
CODE CUSTOMER
Data Plane
Web Server /
Reverse Proxy
API
Gateway
Load
Balancer CDN
NGINX Plus
Data Plane Security
NGINX App Protect
DoS
WAF
Bare Metal | Containers | VMs | Private Cloud | Public Cloud | Hybrid Cloud | Multi-Cloud
App
Adding in NGINX App Protect
Strong app security
Built for modern app architectures
CI/CD Friendly
| ©2021 F5
10
Tools Recently Introduced for App Protect WAF
CONFIDENTIAL
Policy Converter
Converts BIG-IP XML format ASM/AWAF security policy to App Protect JSON declarative format
Policy Exporter
Exports a fully-populated JSON policy with applied settings from the base template
Signature Report Tool
Exports signature metadata of the signatures installed on a system
User-defined Signatures Converter
Converts ASM/AWAF user-defined signatures to App Protect JSON format
Repo of tools demo: https://github.com/aknot242/app-protect-tools
| ©2021 F5
11
Demo: Policy Conversion &
Signature Report
| ©2021 F5 NETWORKS
12
API Security Features
• JSON Schema Enforcement
• OpenAPI/Swagger Enforcement
• gRPC Protofile Enforcement
| ©2021 F5
13
Demo: Open API &
gRPC Protection
| ©2021 F5
14
NGINX Controller App Security
| ©2021 F5 NETWORKS
15
NGINX Controller
automates application
infrastructure-as-code.
Manages apps and APIs centrally to
simplify operations and security…
… accelerating time-to-market without
introducing complexity.
Simplify code to customer | Respond with intelligent insights | Empower with self-service
| ©2021 F5 NETWORKS
16
NGINX Controller
App Security
| ©2021 F5 NETWORKS
17
App Security Add-on for Controller ADC
F5/NGINX CONFIDENTIAL
Multi-cloud,
Multi-instance
Management
App-centric,
Self-Service WAF
Enablement
App Protection
App-centric
Feedback Loop
Visibility and Insights
WAF Policy
Tuning
• Management across
environments and clouds
• Data plane type: customer
managed-lifecycle
instances on virtual
machines
• App (component) level
WAF enablement via
same declarative
Controller ADC API and
Controller UI
• Lightweight WAF traffic
service (NGINX App
Protect)
• Out–of-the-box default
policy for protection for
low false positives
Using default policy:
• OWASP Top 10 protection
• Malformed cookie, JSON,
XML
• Response status code
checks, file type checks
• HTTP RFC compliance,
evasion techniques
• WAF outcome stats &
WAF violation events
using Controller Analytics
API
• Top WAF threats
• WAF events and Metrics
with WAF dimensions
forwarding to
Splunk, Datadog, syslog
servers
• Top signatures for
false positives
investigations
• Blocking or monitor-only
enforcement modes
• Signature disabling at
App Component (URIs)
| ©2021 F5 NETWORKS
18
F5/NGINX is delivering on the promise of Adaptive Apps
BIG-IP
NGINX
BIG-IP +
NGINX +
SHAPE
BEACON
& AI
Simplifying traditional app delivery for
multi-cloud environments
Enabling modern app delivery
at scale
Securing every app anywhere
Unlocking the value of app insights
Web app
firewall
Secure
access
App/web
server
Anti-fraud
& anti-bot
Denial of
service
Ingress
controller
API
gateway
Load
balancer
APPLICATION SECURITY
APPLICATION DELIVERY
APPLICATION INSIGHTS
TELEMETRY
F5 WAF
Technology
F5 WAF
Technology
F5 WAF
Technology
| ©2021 F5 NETWORKS
19
“Bring You Own” Custom NGINX App Protect Policy
Use Cases
NGINX App Protect
WAF
migrates to
Controller
App Security
2
1 adds
+
Controller
App Security
NGINX App Protect migrating to
Controller for simplified
management and out of the box
insights
F5 Advanced WAF or ASM
customers adding Controller for
protecting modern apps
F5 Advanced WAF
| ©2021 F5 NETWORKS
20
BYO NAP Policy: Pass Declarative JSON Policy To Controller
F5/NGINX CONFIDENTIAL
Custom
NGINX App Protect
Declarative JSON
API
GUI
NGINX Controller App Security Add-on
| ©2021 F5
21 CONFIDENTIAL
Controller BYO NGINX App Protect Policy
Demo
| ©2021 F5
22
NGINX Controller App Security
(Available Now for Controller ADC)
(Coming soon for Controller API-Management))
NGINX App Security Offer Summary
NGINX App Protect
DOS
NGINX App Protect
WAF
ModSecurity for
NGINX Plus
ModSecurity
OSS
à
Compliance Requirements
–
Higher Performance
–
Easier Tuning
à
Individual App/
Infrastructure
Emphasis
Enterprise Emphasis w/
App Centric Controls
and DevOps Ease of Use
Free
| ©2021 F5 NETWORKS
23
Want to Learn More?
NGINX App Protect
1. Request a free trial of NGINX App Protect
https://www.nginx.com/free-trial-request/
2. Learn more
https://www.nginx.com/products/nginx-app-protect/
NGINX Controller (including Controller App Security)
1. Request a free trial of NGINX Controller
https://www.nginx.com/free-trial-request-nginx-controller/
2. Learn more
https://www.nginx.com/products/nginx-controller/
| ©2021 F5 NETWORKS
24
Q&A
| ©2021 F5
25
Thank you

More Related Content

PDF
Monitoring NGINX Deployments with Sumo Logic
PDF
API Gateway Use Cases​ for Kubernetes​
PPTX
Production-Grade Kubernetes With NGINX Ingress Controller
PDF
Deep Dive: Automating the Application and Security Pipeline with NGINX and An...
PDF
Découvrez NGINX AppProtect
PDF
Control Kubernetes Ingress and Egress Together with NGINX
PDF
Nim tames sprawl
PDF
Application Security with NGINX | APAC
Monitoring NGINX Deployments with Sumo Logic
API Gateway Use Cases​ for Kubernetes​
Production-Grade Kubernetes With NGINX Ingress Controller
Deep Dive: Automating the Application and Security Pipeline with NGINX and An...
Découvrez NGINX AppProtect
Control Kubernetes Ingress and Egress Together with NGINX
Nim tames sprawl
Application Security with NGINX | APAC

What's hot (20)

PPTX
Controller and Coffee: Deliver APIs in Real Time with API Management
PPTX
Extend DevOps to Your SQL Server Databases
PPTX
Control Kubernetes Ingress and Egress Together with NGINX
PPTX
NGINX: Back to Basics – APCJ
PDF
Deploy and Secure Your API Gateway with NGINX: From Zero to Hero – APCJ
PPTX
Accélérez vos déploiements applicatifs avec NGINX Controller
PDF
Fundamentals of microservices
PPTX
NGINX Lunch and Learn Event: Kubernetes and the NGINX Plus Ingress controller
PDF
Application Security with NGINX
PDF
Strengthen Security and Traffic Visibility on Amazon EKS with NGINX
PPTX
Flexible, Powerful, and Easy-to-Use Ingress Load Balancing with NGINX and Ope...
PPTX
Revolutionising IT Agility
PDF
Secured APIM-as-a-Service
PPTX
Deployment Patterns for API gateways
PDF
Securing Your Apps & APIs in the Cloud
PPTX
NGINX Unit at Scale: Use Cases and the Future of Unit
PDF
Relevez les défis Kubernetes avec NGINX
PDF
Deploy and Secure Your API Gateway with NGINX: From Zero to Hero
PPTX
NGINX Controller: Configuration, Management, and Troubleshooting at Scale
PDF
Why CIOs Need Real-Time APIs to Drive Competitive Digital Businesses
Controller and Coffee: Deliver APIs in Real Time with API Management
Extend DevOps to Your SQL Server Databases
Control Kubernetes Ingress and Egress Together with NGINX
NGINX: Back to Basics – APCJ
Deploy and Secure Your API Gateway with NGINX: From Zero to Hero – APCJ
Accélérez vos déploiements applicatifs avec NGINX Controller
Fundamentals of microservices
NGINX Lunch and Learn Event: Kubernetes and the NGINX Plus Ingress controller
Application Security with NGINX
Strengthen Security and Traffic Visibility on Amazon EKS with NGINX
Flexible, Powerful, and Easy-to-Use Ingress Load Balancing with NGINX and Ope...
Revolutionising IT Agility
Secured APIM-as-a-Service
Deployment Patterns for API gateways
Securing Your Apps & APIs in the Cloud
NGINX Unit at Scale: Use Cases and the Future of Unit
Relevez les défis Kubernetes avec NGINX
Deploy and Secure Your API Gateway with NGINX: From Zero to Hero
NGINX Controller: Configuration, Management, and Troubleshooting at Scale
Why CIOs Need Real-Time APIs to Drive Competitive Digital Businesses
Ad

Similar to What's New with NGINX Application Security Solutions (20)

PPTX
Securing Kubernetes Clusters with NGINX Plus Ingress Controller & NAP
PDF
Secure Your Kubernetes Apps from Attacks with NGINX
PDF
Get the Most Out of Kubernetes with NGINX
PDF
Nginx app protect-for-meetup-v1.0-202006_lk
PPTX
F5 and HashiCorp Multi-Cloud
PPTX
F5 Distributed Cloud.pptx
PDF
Easily View, Manage, and Scale Your App Security with F5 NGINX
PPTX
F5 XC Distributed cloud Security and Application Delievery
PPTX
What are Software Defined Application Services
PDF
Call of Duty: Warzone for Windows With Crack Free Download 2025
PDF
SamFw Tool v4.9 Samsung Frp Tool Free Download
PDF
IObit Uninstaller Pro Crack {2025} Download Free
PDF
Grand Theft Auto 6 PC Game Cracked Full Setup Download
PPTX
Gain multi-cloud versatility with software load balancing designed for cloud-...
PDF
From Code to Customer with F5 and NGNX London Nov 19
PDF
Connect Ops and Security with Flexible Web App and API Protection
PPTX
Successfully Implement Your API Strategy with NGINX
PPTX
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
PDF
NGINX Controller: faster deployments, fewer headaches
PDF
F5 Synthesis Toronto February 2014 Roadshow
Securing Kubernetes Clusters with NGINX Plus Ingress Controller & NAP
Secure Your Kubernetes Apps from Attacks with NGINX
Get the Most Out of Kubernetes with NGINX
Nginx app protect-for-meetup-v1.0-202006_lk
F5 and HashiCorp Multi-Cloud
F5 Distributed Cloud.pptx
Easily View, Manage, and Scale Your App Security with F5 NGINX
F5 XC Distributed cloud Security and Application Delievery
What are Software Defined Application Services
Call of Duty: Warzone for Windows With Crack Free Download 2025
SamFw Tool v4.9 Samsung Frp Tool Free Download
IObit Uninstaller Pro Crack {2025} Download Free
Grand Theft Auto 6 PC Game Cracked Full Setup Download
Gain multi-cloud versatility with software load balancing designed for cloud-...
From Code to Customer with F5 and NGNX London Nov 19
Connect Ops and Security with Flexible Web App and API Protection
Successfully Implement Your API Strategy with NGINX
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
NGINX Controller: faster deployments, fewer headaches
F5 Synthesis Toronto February 2014 Roadshow
Ad

More from NGINX, Inc. (20)

PDF
【NGINXセミナー】 Ingressを使ってマイクロサービスの運用を楽にする方法
PDF
【NGINXセミナー】 NGINXのWAFとは?その使い方と設定方法 解説セミナー
PDF
【NGINXセミナー】API ゲートウェイとしてのNGINX Plus活用方法
PPTX
Get Hands-On with NGINX and QUIC+HTTP/3
PPTX
Managing Kubernetes Cost and Performance with NGINX & Kubecost
PDF
Manage Microservices Chaos and Complexity with Observability
PDF
Accelerate Microservices Deployments with Automation
PDF
Unit 2: Microservices Secrets Management 101
PDF
Unit 1: Apply the Twelve-Factor App to Microservices Architectures
PDF
NGINX基本セミナー(セキュリティ編)~NGINXでセキュアなプラットフォームを実現する方法!
PDF
NGINXセミナー(基本編)~いまさら聞けないNGINXコンフィグなど基本がわかる!
PDF
Keep Ahead of Evolving Cyberattacks with OPSWAT and F5 NGINX
PPTX
Install and Configure NGINX Unit, the Universal Application, Web, and Proxy S...
PPTX
Protecting Apps from Hacks in Kubernetes with NGINX
PPTX
NGINX Kubernetes API
PPTX
Installing and Configuring NGINX Open Source
PPTX
Shift Left for More Secure Apps with F5 NGINX
PPTX
How to Avoid the Top 5 NGINX Configuration Mistakes.pptx
PDF
Kubernetes環境で実現するWebアプリケーションセキュリティ
PDF
Software Delivery and the Rube Goldberg Machine: What Is the Problem We Are T...
【NGINXセミナー】 Ingressを使ってマイクロサービスの運用を楽にする方法
【NGINXセミナー】 NGINXのWAFとは?その使い方と設定方法 解説セミナー
【NGINXセミナー】API ゲートウェイとしてのNGINX Plus活用方法
Get Hands-On with NGINX and QUIC+HTTP/3
Managing Kubernetes Cost and Performance with NGINX & Kubecost
Manage Microservices Chaos and Complexity with Observability
Accelerate Microservices Deployments with Automation
Unit 2: Microservices Secrets Management 101
Unit 1: Apply the Twelve-Factor App to Microservices Architectures
NGINX基本セミナー(セキュリティ編)~NGINXでセキュアなプラットフォームを実現する方法!
NGINXセミナー(基本編)~いまさら聞けないNGINXコンフィグなど基本がわかる!
Keep Ahead of Evolving Cyberattacks with OPSWAT and F5 NGINX
Install and Configure NGINX Unit, the Universal Application, Web, and Proxy S...
Protecting Apps from Hacks in Kubernetes with NGINX
NGINX Kubernetes API
Installing and Configuring NGINX Open Source
Shift Left for More Secure Apps with F5 NGINX
How to Avoid the Top 5 NGINX Configuration Mistakes.pptx
Kubernetes環境で実現するWebアプリケーションセキュリティ
Software Delivery and the Rube Goldberg Machine: What Is the Problem We Are T...

Recently uploaded (20)

PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PPTX
assetexplorer- product-overview - presentation
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PPTX
Introduction to Artificial Intelligence
PPTX
CHAPTER 2 - PM Management and IT Context
PDF
medical staffing services at VALiNTRY
PDF
Cost to Outsource Software Development in 2025
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PPTX
L1 - Introduction to python Backend.pptx
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
Digital Systems & Binary Numbers (comprehensive )
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
Softaken Excel to vCard Converter Software.pdf
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PPTX
history of c programming in notes for students .pptx
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PDF
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
PDF
Upgrade and Innovation Strategies for SAP ERP Customers
PPTX
Odoo POS Development Services by CandidRoot Solutions
Navsoft: AI-Powered Business Solutions & Custom Software Development
assetexplorer- product-overview - presentation
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
Introduction to Artificial Intelligence
CHAPTER 2 - PM Management and IT Context
medical staffing services at VALiNTRY
Cost to Outsource Software Development in 2025
wealthsignaloriginal-com-DS-text-... (1).pdf
L1 - Introduction to python Backend.pptx
Which alternative to Crystal Reports is best for small or large businesses.pdf
Digital Systems & Binary Numbers (comprehensive )
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
Softaken Excel to vCard Converter Software.pdf
Design an Analysis of Algorithms II-SECS-1021-03
history of c programming in notes for students .pptx
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Why TechBuilder is the Future of Pickup and Delivery App Development (1).pdf
Upgrade and Innovation Strategies for SAP ERP Customers
Odoo POS Development Services by CandidRoot Solutions

What's New with NGINX Application Security Solutions

  • 1. NGINX App Security Solutions Update DAPHNE WON ISAAC NOUMBA DANIEL EDGAR
  • 2. | ©2021 F5 2 Agenda • NGINX App Security Solutions Overview • NGINX App Protect: New features for protection of modern apps • NGINX Controller App Security • Q&A
  • 3. | ©2021 F5 NETWORKS 3 F5/NGINX is delivering on the promise of Adaptive Apps BIG-IP NGINX BIG-IP + NGINX + SHAPE BEACON & AI Simplifying traditional app delivery for multi-cloud environments Enabling modern app delivery at scale Securing every app anywhere Unlocking the value of app insights Web app firewall Secure access App/web server Anti-fraud & anti-bot Denial of service Ingress controller API gateway Load balancer APPLICATION SECURITY APPLICATION DELIVERY APPLICATION INSIGHTS TELEMETRY
  • 4. | ©2021 F5 NETWORKS 4 Tackle Your Application Security Challenges Embed Security Policy Your Pipeline Integrate security controls directly into your pipeline with security as code. Secure Modern Apps Strong security controls for microservices, containers, APIs, and other modern topologies. Gain Security Insights Security tools that go beyond alerts with intelligent security insights about your apps and APIs.
  • 5. | ©2021 F5 NETWORKS 5 Tackle your application security challenges Security policies and protections are optimized for DevOps workflow. Deploy and manage app security controls across distributed environments. NGINX & F5 Investments Embed Security Policy Into Your Pipeline Integrate security controls directly into your pipeline with security as code. Secure Modern Apps Strong security controls for microservices, containers, APIs, and other modern topologies. Gain Security Insights Security tools that go beyond alerts with intelligent security insights about your apps and APIs. Centralized visibility and insights dig into the root cause of application issues.
  • 6. | ©2021 F5 NETWORKS 6 NGINX Controller App Security (Available Now for Controller ADC) (Coming soon for Controller API-Management)) NGINX App Security Offer Summary NGINX App Protect DOS NGINX App Protect WAF ModSecurity for NGINX Plus ModSecurity OSS à Compliance Requirements – Higher Performance – Easier Tuning à Individual App/ Infrastructure Emphasis Enterprise Emphasis w/ App Centric Controls and DevOps Ease of Use Free
  • 7. | ©2021 F5 7 NGINX App Protect Update
  • 8. | ©2021 F5 NETWORKS 8 NGINX Plus routes, hardens, and secures your apps and APIs. Decentralized, best-of-breed tools that developers need for agility. Deployed as specific “flavors” optimized for application, API, and Kubernetes environments. Microservices Control Plane Kubernetes Ingress Controller Service Mesh NGINX Ingress Controller NGINX Service Mesh CODE CUSTOMER Data Plane Web Server / Reverse Proxy API Gateway Load Balancer CDN NGINX Plus Bare Metal | Containers | VMs | Private Cloud | Public Cloud | Hybrid Cloud | Multi-Cloud App
  • 9. | ©2021 F5 NETWORKS 9 Microservices Control Plane Kubernetes Ingress Controller Service Mesh NGINX Ingress Controller NGINX Service Mesh CODE CUSTOMER Data Plane Web Server / Reverse Proxy API Gateway Load Balancer CDN NGINX Plus Data Plane Security NGINX App Protect DoS WAF Bare Metal | Containers | VMs | Private Cloud | Public Cloud | Hybrid Cloud | Multi-Cloud App Adding in NGINX App Protect Strong app security Built for modern app architectures CI/CD Friendly
  • 10. | ©2021 F5 10 Tools Recently Introduced for App Protect WAF CONFIDENTIAL Policy Converter Converts BIG-IP XML format ASM/AWAF security policy to App Protect JSON declarative format Policy Exporter Exports a fully-populated JSON policy with applied settings from the base template Signature Report Tool Exports signature metadata of the signatures installed on a system User-defined Signatures Converter Converts ASM/AWAF user-defined signatures to App Protect JSON format Repo of tools demo: https://github.com/aknot242/app-protect-tools
  • 11. | ©2021 F5 11 Demo: Policy Conversion & Signature Report
  • 12. | ©2021 F5 NETWORKS 12 API Security Features • JSON Schema Enforcement • OpenAPI/Swagger Enforcement • gRPC Protofile Enforcement
  • 13. | ©2021 F5 13 Demo: Open API & gRPC Protection
  • 14. | ©2021 F5 14 NGINX Controller App Security
  • 15. | ©2021 F5 NETWORKS 15 NGINX Controller automates application infrastructure-as-code. Manages apps and APIs centrally to simplify operations and security… … accelerating time-to-market without introducing complexity. Simplify code to customer | Respond with intelligent insights | Empower with self-service
  • 16. | ©2021 F5 NETWORKS 16 NGINX Controller App Security
  • 17. | ©2021 F5 NETWORKS 17 App Security Add-on for Controller ADC F5/NGINX CONFIDENTIAL Multi-cloud, Multi-instance Management App-centric, Self-Service WAF Enablement App Protection App-centric Feedback Loop Visibility and Insights WAF Policy Tuning • Management across environments and clouds • Data plane type: customer managed-lifecycle instances on virtual machines • App (component) level WAF enablement via same declarative Controller ADC API and Controller UI • Lightweight WAF traffic service (NGINX App Protect) • Out–of-the-box default policy for protection for low false positives Using default policy: • OWASP Top 10 protection • Malformed cookie, JSON, XML • Response status code checks, file type checks • HTTP RFC compliance, evasion techniques • WAF outcome stats & WAF violation events using Controller Analytics API • Top WAF threats • WAF events and Metrics with WAF dimensions forwarding to Splunk, Datadog, syslog servers • Top signatures for false positives investigations • Blocking or monitor-only enforcement modes • Signature disabling at App Component (URIs)
  • 18. | ©2021 F5 NETWORKS 18 F5/NGINX is delivering on the promise of Adaptive Apps BIG-IP NGINX BIG-IP + NGINX + SHAPE BEACON & AI Simplifying traditional app delivery for multi-cloud environments Enabling modern app delivery at scale Securing every app anywhere Unlocking the value of app insights Web app firewall Secure access App/web server Anti-fraud & anti-bot Denial of service Ingress controller API gateway Load balancer APPLICATION SECURITY APPLICATION DELIVERY APPLICATION INSIGHTS TELEMETRY F5 WAF Technology F5 WAF Technology F5 WAF Technology
  • 19. | ©2021 F5 NETWORKS 19 “Bring You Own” Custom NGINX App Protect Policy Use Cases NGINX App Protect WAF migrates to Controller App Security 2 1 adds + Controller App Security NGINX App Protect migrating to Controller for simplified management and out of the box insights F5 Advanced WAF or ASM customers adding Controller for protecting modern apps F5 Advanced WAF
  • 20. | ©2021 F5 NETWORKS 20 BYO NAP Policy: Pass Declarative JSON Policy To Controller F5/NGINX CONFIDENTIAL Custom NGINX App Protect Declarative JSON API GUI NGINX Controller App Security Add-on
  • 21. | ©2021 F5 21 CONFIDENTIAL Controller BYO NGINX App Protect Policy Demo
  • 22. | ©2021 F5 22 NGINX Controller App Security (Available Now for Controller ADC) (Coming soon for Controller API-Management)) NGINX App Security Offer Summary NGINX App Protect DOS NGINX App Protect WAF ModSecurity for NGINX Plus ModSecurity OSS à Compliance Requirements – Higher Performance – Easier Tuning à Individual App/ Infrastructure Emphasis Enterprise Emphasis w/ App Centric Controls and DevOps Ease of Use Free
  • 23. | ©2021 F5 NETWORKS 23 Want to Learn More? NGINX App Protect 1. Request a free trial of NGINX App Protect https://www.nginx.com/free-trial-request/ 2. Learn more https://www.nginx.com/products/nginx-app-protect/ NGINX Controller (including Controller App Security) 1. Request a free trial of NGINX Controller https://www.nginx.com/free-trial-request-nginx-controller/ 2. Learn more https://www.nginx.com/products/nginx-controller/
  • 24. | ©2021 F5 NETWORKS 24 Q&A