Skip to main content
F5Customer feedback

A large AWS user is concerned about potential false positives and rule duplication when centrally managing their existing F5 marketplace rules for APIs via AWS Firewall Manager.

What happened

Post: "๐Ÿš€ [AWS Firewall Manager] Large-Scale Deployment Experiences & False Positive Management"

Source

Post

Highlighted: the lines this signal was extracted from

Hi r/aws, Weโ€™re planning to deploy AWS Firewall Manager (FMS) with WAFv2 across an AWS organization with 334 active accounts, including: 725 CloudFront distributions, 44 public ALBs and 12 public API Gateway stages, 431 attached Web ACLs (157 in production). Our goal is to centralize a common baseline (IP blacklist, geoblocking, AWS Managed Rules) while preserving user-managed application-specific rules (allowlists, rate limits, CAPTCHA, etc.). ๐Ÿ” Questions for the Community: Implementation Mode: Did you use RETROFIT_EXISTING (injecting the baseline into existing Web ACLs) or a full replacement of ACLs? โ†’ Weโ€™re leaning toward RETROFIT_EXISTING to preserve user-managed rules, but weโ€™re concerned about temporary rule duplication (e.g., F5/Fortinet rules existing both locally and centrally). Phased Migration: How did you structure your migration (by resource type, environment, etc.)? How did you handle exceptions (e.g., accounts with different IP profiles like X-Forwarded-For vs. origin)? Marketplace Rules (F5/Fortinet) Management: Did you centralize F5/Fortinet via FMS, or did you leave them under user control? โ†’ We want to centralize F5 for APIs and Fortinet for ALBs, but weโ€™re particularly concerned about false positives (e.g., a specific F5 rule causing issues for a particular account). How did you ensure these didnโ€™t disrupt legitimate traffic? ๐Ÿ’ก Key...

Keep reading with a free account

The rest of this post, and every signal for F5, is in your free account.

Also quoted as evidence

  • ๐Ÿ’ก Key Concerns: Avoiding false positives (e.g., ensuring a specific F5 rule doesnโ€™t block legitimate traffic for a particular account). Rule coexistence (e.g., temporary duplication of F5/Fortinet rules during migration).

    From the post

Comments on the post

  • โ€œWe have a slightly smaller organisation with just about 90 accounts and maybe around 200 or so WAF-protected resources. When we implemented Firewall Manager, we first made the decision to keep it simple: Just two WAF definitions: Private and Public. With the notion that if an application really needed something custom, they could always do their own WAF but were then also responsible for it. Pubโ€

    u/RecordingForward26903 points ยท Sep 24, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/aws

Companies

  • Amazon Web ServicesAlso named
  • FortinetAlso named

The full record

From the Signal API record

Numbers

Mentions
7

Details

Timing
Ongoing state
Category
Usability
Virality
Very low
Post kind
Text
Prominence
Core
Company's role
Vendor

Topics and mentions

Topics

  • cloud security
  • false positives
  • api security
  • centralized management
  • waf

Flair

  • architecture

Products named

  • F5 Marketplace Rules

Extraction

Sentiment
Neutral
Detected
Sep 21, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for F5 and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: โ€œWhat changed at F5 this week?โ€

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/05bda07c-6205-5b76-a37b-b1dca84b7991 returns this record as JSON. POST /v1/companies/enrich returns every signal for f5.com.

{
  "signal_id": "05bda07c-6205-5b76-a37b-b1dca84b7991",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-09-21T12:33:35+00:00",
  "company": {
    "name": "F5",
    "domain": "f5.com"
  },
  "data": {
    "nsfw": false,
    "stage": "none",
    "awards": 0,
    "timing": "ongoing_state",
    "topics": [
      "cloud security",
      "waf",
      "false positives",
      "api security",
      "centralized management"
    ],
    "post_id": "1wmbi4r",
    "summary": "A large AWS user is concerned about potential false positives and rule duplication when centrally managing their existing F5 marketplace rules for APIs via AWS Firewall Manager.",
    "category": "usability",
    "comments": [
      {
        "url": "https://www.reddit.com/r/aws/comments/1wmbi4r/comment/pbsqpnb/",
        "depth": 0,
        "score": 3,
        "author": "RecordingForward2690",
        "excerpt": "We have a slightly smaller organisation with just about 90 accounts and maybe around 200 or so WAF-protected resources. When we implemented Firewall Manager, we first made the decision to keep it simple: Just two WAF definitions: Private and Public. With the notion that if an application really needed something custom, they could always do their own WAF but were then also responsible for it.\n\n Pub",
        "posted_at": "2026-09-24T16:40:29.000Z",
        "author_url": "https://www.reddit.com/user/RecordingForward2690/"
      }
    ],
    "evidence": [
      "[post] Did you centralize F5/Fortinet via FMS, or did you leave them under user control? โ†’ We want to centralize F5 for APIs and Fortinet for ALBs, but weโ€™re particularly concerned about false positives (e.g., a specific F5 rule causing issues for a particular account).",
      "[post] ๐Ÿ’ก Key Concerns: Avoiding false positives (e.g., ensuring a specific F5 rule doesnโ€™t block legitimate traffic for a particular account). Rule coexistence (e.g., temporary duplication of F5/Fortinet rules during migration)."
    ],
    "virality": "very_low",
    "post_date": "2026-09-21T12:33:35.000Z",
    "post_kind": "text",
    "post_text": "Hi r/aws,\n\nWeโ€™re planning to deploy AWS Firewall Manager (FMS) with WAFv2 across an AWS organization with 334 active accounts, including:\n\n725 CloudFront distributions,\n\n44 public ALBs and 12 public API Gateway stages,\n\n431 attached Web ACLs (157 in production).\n\nOur goal is to centralize a common baseline (IP blacklist, geoblocking, AWS Managed Rules) while preserving user-managed application-specific rules (allowlists, rate limits, CAPTCHA, etc.).\n\n๐Ÿ” Questions for the Community:\n\nImplementation Mode:\n\nDid you use RETROFIT_EXISTING (injecting the baseline into existing Web ACLs) or a full replacement of ACLs? โ†’ Weโ€™re leaning toward RETROFIT_EXISTING to preserve user-managed rules, but weโ€™re concerned about temporary rule duplication (e.g., F5/Fortinet rules existing both locally and centrally).\n\nPhased Migration:\n\nHow did you structure your migration (by resource type, environment, etc.)?\n\nHow did you handle exceptions (e.g., accounts with different IP profiles like X-Forwarded-For vs. origin)?\n\nMarketplace Rules (F5/Fortinet) Management:\n\nDid you centralize F5/Fortinet via FMS, or did you leave them under user control? โ†’ We want to centralize F5 for APIs and Fortinet for ALBs, but weโ€™re particularly concerned about false positives (e.g., a specific F5 rule causing issues for a particular account). How did you ensure these didnโ€™t disrupt legitimate traffic?\n\n๐Ÿ’ก Key...",
    "sentiment": "neutral",
    "subreddit": "aws",
    "post_flair": [
      "architecture"
    ],
    "post_title": "๐Ÿš€ [AWS Firewall Manager] Large-Scale Deployment Experiences & False Positive Management",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/aws/comments/1wmbi4r/aws_firewall_manager_largescale_deployment/",
    "entity_role": "vendor",
    "post_author": "GugWTF",
    "upvote_ratio": 1,
    "mention_count": 7,
    "mention_surge": true,
    "subreddit_url": "https://www.reddit.com/r/aws/",
    "total_upvotes": 4,
    "comments_total": 1,
    "total_comments": 1,
    "other_companies": [
      {
        "name": "Amazon Web Services",
        "role": "partner",
        "domain": "amazon.com"
      },
      {
        "name": "Fortinet",
        "role": "alternative",
        "domain": "fortinet.com"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/GugWTF/",
    "signal_category": "feedback",
    "comments_included": 1,
    "products_mentioned": [
      "F5 Marketplace Rules"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.