# Enable F5 WAF for NGINX Type of document: How-to guide Product: F5 NGINXaaS > Enable F5 WAF for NGINX on an NGINXaaS deployment using the NGINXaaS Console. --- ## Overview This guide explains how to enable F5 WAF for NGINX on a F5 NGINX as a Service (NGINXaaS) deployment. [F5 WAF for NGINX](https://docs.nginx.com/nginx-app-protect-waf/v5) provides web application firewall (WAF) security protection for your web applications, including OWASP Top 10; response inspection; Meta characters check; HTTP protocol compliance; evasion techniques; disallowed file types; JSON & XML well-formedness; sensitive parameters & Data Guard. ## Enable F5 WAF for NGINX F5 WAF for NGINX is disabled by default and needs to be explicitly enabled on an NGINXaaS deployment. Follow these steps: ### Using the NGINXaaS Console - Open the [NGINXaaS Console](https://console.nginxaas.net/). - Log in with your preferred identity provider. - Select the Geography you want to work in. 1. Go to your NGINXaaS deployment. 2. Edit your deployment. 3. Enable **WAF** for your deployment. 4. Select **Save Changes** to begin the deployment process. ## What's next [Configure F5 WAF for NGINX](/nginxaas/overview/app-protect/configure-waf.md)