F5 WAF for NGINX

NGINX One

  • NGINX One Console
  • NGINX Plus
  • NGINX Instance Manager
  • NGINX Ingress Controller
  • NGINX Gateway Fabric
  • NGINX Open Source
  • NGINX Agent

F5 WAF for NGINX

  • F5 WAF for NGINX
  • F5 DoS for NGINX

NGINX as a Service

  • NGINXaaS for Azure
Skip Navigation
    • Overview
    • Technical specifications
    • Terminology
    • Virtual machine or bare metal
    • Kubernetes
    • Kubernetes operations improvements (Early access)
    • Docker
    • Disconnected or air-gapped environments
    • Update F5 WAF for NGINX signatures
    • Upgrade F5 WAF for NGINX
    • Uninstall F5 WAF for NGINX
    • Configure NGINX features with F5 WAF
    • Use apreload to apply configuration updates
    • Build and use the compiler tool
    • Build and use the converter tools
    • Configure SELinux
    • Secure traffic using mTLS
    • Add a read-only filesystem for Kubernetes
    • Configure policies
    • Policy parameter reference
    • Allowed methods
    • Attack signatures
    • Brute force attack preventions
    • Cookie enforcement
    • Data guard
    • Deny and Allow IP lists
    • Disallowed file type extensions
    • Evasion techniques
    • Geolocation
    • GraphQL protection
    • gRPC protection
    • HTTP compliance
    • IP address lists
    • IP intelligence
    • JWT protection
    • Server technology signatures
    • Time-based signature staging
    • Threat campaigns
    • User-defined HTTP headers
    • XFF trusted headers
    • XML and JSON content
    • Log types
    • Security logs
    • Operation logs
    • Debug logs
    • Access logs
  • Changelog
  • Support
NGINX Docs
  • F5

    Deliver and secure every app

  • DevCentral

    Connect & learn in our hosted community

  • MyF5

    Your key to everything F5, including support, registration keys, and subscriptions

  • NGINX

    Learn more about NGINX Open Source and read the community blog

  • Community Forum

    Engage with the broader NGINX community for discussions and troubleshooting

  1. Home
  2. F5 WAF for NGINX
  3. Policies

Policies

In this section

Configure policies

Policy parameter reference

Allowed methods

Attack signatures

Brute force attack preventions

Cookie enforcement

Data guard

Deny and Allow IP lists

Disallowed file type extensions

Evasion techniques

Geolocation

GraphQL protection

gRPC protection

HTTP compliance

IP address lists

IP intelligence

JWT protection

Server technology signatures

Time-based signature staging

Threat campaigns

User-defined HTTP headers

XFF trusted headers

XML and JSON content


View source
Edit this page
Create a new issue
F5 logo

©2025 F5, Inc. All rights reserved. NGINX is a registered trademark of F5, Inc.

Trademarks Policies Privacy California Privacy Do Not Sell My Personal Information