Your apps now live in two clouds and a data centre. Their front door shouldn’t need a box in each — F5 Distributed Cloud WAAP puts a SaaS WAF, DDoS defence, bot screening and API checks in front of your apps, sold yearly or by the hour on AWS, with PoPs in Mumbai and Chennai.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers F5 Distributed Cloud WAAP — the SaaS web app and API protection. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
A WAAP filters requests to web apps and APIs, combining a WAF, DDoS defence, bot screening and API checks in one service.
What consolidation actually replaces, dimension by dimension.
| Dimension | A WAF box per data centre | F5 Distributed Cloud WAAP |
|---|---|---|
| Where attacks are stopped | A WAF box in front of each data centre | F5’s SaaS network, Mumbai and Chennai PoPs included |
| Volumetric floods | They fill your internet link first | L3–4 DDoS defence is part of Essentials |
| API contracts | Specs sit in a repo that nothing enforces | OpenAPI schema validation on Enterprise |
| Paying for a pilot | A hardware quote and a lead time | AWS Marketplace pay-as-you-go by the hour |
| Sensitive data in transit | Noticed only after it leaks | Detected and masked on Enterprise |
| What it is NOT | — | Advanced bot protection, Bot Defense or a list price |
The cheapest test is pay-as-you-go on AWS Marketplace: front one app, review a fortnight of blocked requests, then price the annual package.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Requests are checked on F5’s Distributed Cloud network before they reach your origin; India gained PoPs in Mumbai (GPX One, Equinix) and Chennai (Sify) in December 2022.
Protection is attached per load balancer: F5’s AWS listing bills a load balancer with threat campaigns at $0.370 an hour and API Discovery at $1.079 per load balancer an hour.
Essentials brings the signature WAF, L3–4 DDoS defence, basic bot screening and API rules; Enterprise layers behavioural analysis, malware detection and data masking over them.
Bot Defense, API Security, DDoS Mitigation, Client-Side Defense and Web App Scanning are separate Distributed Cloud services, so deeper bot or API work is a second line item.
A SaaS policy on F5’s PoPs — attached per load balancer, sized by package, with Mumbai and Chennai in the network.
F5 Distributed Cloud WAAP inspects web and API traffic on F5’s own network before it reaches your apps.
Known web exploits are matched against attack signatures, the protection both annual packages start from before any behavioural layer.
Network-layer floods aimed at a protected app are dealt with on F5’s network as part of the base package rather than as a separate order.
Simple automated traffic is screened in Essentials; the advanced bot protection tier is an add-on, and Bot Defense is a service of its own.
Enterprise studies how each client behaves across many requests and flags suspicious users that a signature match alone would let pass.
Enterprise adds malware detection to the policy, a layer Essentials buyers do not get, so price the higher package if uploads matter to you.
Enterprise spots sensitive data moving through an app and can mask it; ask F5 which data types it recognises before you rely on it.
Rules scoped to API endpoints come with Essentials, so APIs get controls of their own before you pay for the deeper Enterprise package.
API calls are checked against your OpenAPI schema, so out-of-contract requests stand out; this is an Enterprise feature, not in Essentials.
Detections for the OWASP API Security Top 10 risks arrive with Enterprise, next to the schema checks, for estates that are mostly APIs.
F5’s own introduction to the WAAP service, how technology partners fit around it at the edge, and the Distributed Cloud platform it runs on.
F5’s own introduction to the WAAP service; it is a 2022 recording, so check package names against today’s pricing page.
How F5 places its technology partners around Distributed Cloud WAAP at the edge, as presented in mid-2022.
The wider Distributed Cloud platform the WAAP runs on, worth watching before you size load balancers and nodes.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Essentials covers what most public web apps need first: a signature WAF, L3–4 DDoS defence, basic bot screening and API protection rules. Enterprise adds behavioural analysis, malware detection, OpenAPI schema validation, sensitive-data masking and OWASP API Top 10 detections, so you can start small and move up later.
f5.com prints no WAAP price, but F5’s AWS Marketplace listing has carried pay-as-you-go rates since 1 January 2025: $3.704 an hour for the base package, $0.328 per thousand API protection requests and $1.079 per load balancer an hour for API Discovery. These are AWS software fees; re-check them before budgeting.
Since December 2022 F5 has run Distributed Cloud PoPs in Mumbai and Chennai, and said at the launch that it can contain and process that traffic in-country. For an estate that already runs BIG-IP or NGINX, the same vendor now offers a SaaS front door for apps that have moved to public cloud.
Advanced bot protection is an add-on even on Enterprise, and Bot Defense, API Security and DDoS Mitigation are separate services. F5 publishes no network capacity figure, no price on its own site and no Gartner Magic Quadrant placement for WAAP. Which services run inside the Indian PoPs is not published.
Inventory internet-facing apps and APIs, note which have OpenAPI specs, and flag those handling personal data under the DPDP Act.
Map needs to Essentials or Enterprise; schema validation, data masking and malware checks are the usual reasons to move up.
Front one app with a load balancer through the AWS Marketplace pay-as-you-go listing and watch the hourly node and request costs.
Review blocked and flagged requests with app owners, fix false positives, then set the hourly run-rate against an annual quote.
Sign the annual package or a private offer, onboard the remaining apps, and decide whether advanced bot protection earns its cost.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“We put our customer portal behind Essentials in a week, and the L3–4 floods that used to choke our uplink now stop before it.”
“OpenAPI schema validation is why we paid for Enterprise. Calls that had drifted from the spec showed up on the first day of the pilot.”
“Our BIG-IP team still runs the data-centre WAF; Distributed Cloud now fronts the apps we moved to AWS, with one vendor to call.”
“Hourly billing on AWS let us trial one load balancer with no contract, but the node charges climbed faster than we had modelled.”
“Bot screening in Essentials was too light for our ticket-sale spikes, so we ended up pricing the advanced bot add-on separately.”
“Data masking helped our DPDP review, though we had to ask F5 in writing which services actually run in the Mumbai PoP.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the web app and API protection market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
KuppingerCole WAAP Leader (2025); annual or hourly on AWS.
The grid nobody publishes — where the service can run and keep traffic, India included, vs how much protection comes in the base package.
SaaS with Mumbai and Chennai PoPs; advanced bots extra.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against Akamai App & API Protector, Cloudflare Application Security, Imperva Cloud WAF, Barracuda WAF-as-a-Service and AWS WAF — on deployment, price, add-ons, API and bot depth, India and exit.
| Dimension | F5 Distributed Cloud WAAP | Akamai App & API Protector | Cloudflare Application Security | Imperva Cloud WAF (Thales) | Barracuda WAF-as-a-Service | AWS WAF |
|---|---|---|---|---|---|---|
| What it is | SaaS WAAP from F5 | Edge WAAP from Akamai | WAAP on its own network | Cloud WAF under Thales | SaaS WAF on Azure | AWS rule engine |
| Deployment | SaaS on F5’s PoPs | Edge, or Hybrid | Proxy only | Cloud or WAF Gateway | SaaS, plus containers | AWS resources only |
| Pricing model | Annual or hourly | Quote, unit unpublished | Per-site plans | Quoted by Thales | Two plans, configurator | Pure usage |
| Published entry price | $3.704/hour on AWS | None published | About $20/site/month | None published | Not on the plan page | $5/web ACL + $1/rule |
| Included vs add-on | Advanced bots extra | Modules sold apart | Depth on Enterprise | Bot and API separate | Premium adds the ML | Everything metered |
| Network and scale | No capacity published | 100% SLA edge | 330+ cities, ~500 Tbps | About 60 data centres | Azure, 118-PoP CDN | Follows AWS Regions |
| Detection and tuning | Behaviour on Enterprise | Self-tuning engine | Managed rules + ML | Attack Analytics | Smart Signatures | Rules are yours |
| API protection | Schema + API Top 10 | Discovery built in | API Shield | Separate API product | JSON and GraphQL | No API inventory |
| Bot defence | Basic; advanced add-on | Visibility only | ML Bot Management | Advanced Bot Protection | 10,000+ bot signatures | Bot Control, metered |
| DevOps and SIEM | Not verified here | Terraform, SIEM kits | API and Terraform | API, log export | API-first config | AWS-native tooling |
| India data path | Mumbai and Chennai | Hybrid for local | Indian cities plus DLS | Mumbai and New Delhi | No India PoP named | Mumbai and Hyderabad |
| Support | Terms not published | 24/7/365 | Tied to plan tier | Ask in writing | Separate support plans | Paid plan for SRT |
| Lock-in and exit | F5 policy model | Akamai formats | Needs its proxy | Inside Imperva | JSON config file | AWS only |
| Best fit | BIG-IP shops adding SaaS | Akamai edge customers | Start small, grow up | Cloud plus own DC | Mid-market and MSPs | All-in on AWS |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no web app and API protection guide yet, so F5 Distributed Cloud WAAP sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (public web apps and APIs; engineer-hour cost). Estimates model security-engineering time spent hand-tuning WAF rules, chasing flood and bot alerts and keeping API specs enforced, at an assumed 1.5 hours per app a year, with 70% of it removed by one SaaS policy layer. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not on f5.com: F5 sells Distributed Cloud WAAP as Essentials or Enterprise annual packages, as private cloud-marketplace offers, or pay-as-you-go on AWS Marketplace, where rates effective 1 January 2025 are $3.704 an hour for the base package, $0.328 per thousand API protection requests and $1.079 per load balancer an hour for API Discovery. Those are AWS software fees, not a list price. TechBag models your apps first, then quotes in INR with GST.
Best for public-facing web apps
Best for a broader rollout
Best for API-heavy, regulated estates
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many public web apps and APIs need cover, and which of them already sit behind BIG-IP or NGINX today?
Do you need behavioural analysis, malware detection or schema validation? Those come only with Enterprise.
Is basic bot screening enough, or will you also price the advanced bot add-on or the separate Bot Defense service?
Are your OpenAPI specs current? Schema validation only helps where the contract matches what the API really does.
Will F5 confirm in writing which services and logs stay in the Mumbai and Chennai PoPs, and where the console runs?
Annual subscription, private marketplace offer or AWS pay-as-you-go: which fits your budget cycle and cloud commit?
If you leave, how will policies be rebuilt elsewhere, and how long will F5 hold your security logs after the term?
Does the quote list package, load balancers, add-ons and support term? Ask for the figure in INR with GST.
Model your public apps and APIs first, or let a TechBag advisor scope an hourly pilot that puts one app behind a Distributed Cloud load balancer.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.