Request Body Matching Support in F5 XC Service Policies

F5 XC Service Policies currently support matching on attributes such as host, path, headers, HTTP methods, query parameters, source IP, and TLS fingerprint. However, they do not support inspection or evaluation of HTTP request body content, making it impossible to implement body-based security logic that exists in platforms such as AWS WAF.

As organizations increasingly migrate workloads from hyperscaler-native WAF solutions to F5 XC, request body inspection has become a common migration requirement. Adding support for body-based predicates within Service Policies would help achieve feature parity for migration scenarios, reduce the need for application redesign or external validation mechanisms, strengthen API security, and simplify the migration of existing security policies to F5 XC.

  • Vipul Soni
  • Jul 6 2026
  • Attach files