Securing MCP Servers with F5 Distributed Cloud WAF

F5 DevCentral CommunityAbout 4 min readAug 16, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

  • Model Context Protocol (MCP): A protocol defining message exchanges over JSON RPC 2.0 to connect MCP clients to MCP servers, enabling tools to be advertised and consumed in Agentic AI.
  • Agentic AI: A generative AI pattern where tools enhance the capabilities of Large Language Models (LLMs).
  • MCP Server: Hosts and advertises tools that can be used by MCP clients.
  • MCP Client: An interface used by MCP hosts to consume tools from MCP servers.
  • MCP Remote Proxy: Enables connectivity to remote MCP servers, especially when clients like Claude only support local servers.
  • F5 Distributed Cloud WAFT (Web Application Firewall): A solution to protect MCP servers from vulnerabilities and attacks.
  • WAFT MCP Remote Proxy: A wrapper for MCP remote proxy that can process WAFT blocked response pages, providing a better user experience.
  • JSON RPC 2.0: The communication protocol used by MCP for message exchanges.

Introduction to Model Context Protocol and Agentic AI

The video introduces Model Context Protocol (MCP) as a key component in Agentic AI, a generative AI pattern where tools enhance the capabilities of Large Language Models (LLMs). Initially, these tools were tightly integrated with AI agents, but there's a growing need to separate them, especially when managed by different providers. MCP facilitates this separation by allowing tools to be advertised by MCP servers and consumed by MCP clients. MCP defines the message exchanges over JSON RPC 2.0. Although relatively new, MCP implementations already have identified vulnerabilities, which are expected to increase as Agentic AI becomes more prevalent.

Demo Setup: Claude, MCP Remote Proxy, and Vulnerable Tool

The demo uses Anthropic's Claude client connecting to a remote MCP server. Since Claude only supports local MCP servers, an MCP remote proxy is used to enable remote connectivity. The MCP server hosts three tools: "ping," "read file," and "get page." The "ping" tool is intentionally designed to be vulnerable for demonstration purposes.

Vulnerability Exploitation: Malicious Ping Request

The demo shows how a malicious user can exploit the vulnerability in the "ping" tool. A benign request to ping the localhost is successful, with Claude displaying a summary and the tool response details. However, when a malicious request is sent with a directory listing command appended to the ping command, the MCP server executes both commands. Claude summarizes the results, and the tool response details reveal the listing of all folders in the root directory, demonstrating the vulnerability.

Protection with F5 Distributed Cloud WAFT

The video highlights F5 Distributed Cloud WAFT as an effective solution to protect vulnerable MCP servers. It's presented as a high-efficacy, easy-to-configure solution that can protect against MCP attacks out of the box. The F5 distributed cloud platform also offers additional capabilities like API security.

When the malicious request is re-sent with F5 Distributed Cloud WAFT in place, Claude waits for a response but receives none. The WAFT blocks the malicious request and returns a default blocked response page. However, Claude cannot process this page because it doesn't conform to the MCP protocol, leading to a timeout.

Enhanced Integration with WAFT MCP Remote Proxy

To improve the user experience, the video introduces WAFT MCP Remote Proxy, a wrapper for the MCP remote proxy that can process WAFT blocked response pages. A link to the WAFT MCP remote package, including a user guide, is provided.

The only change required on the F5 Distributed Cloud WAFT side is to customize the blocked response page to use JSON formatting and set the HTTP response status code to a value (403 in this demo) that can be configured in the WAFT MCP remote proxy.

When the attack request is re-sent with this setup, Claude immediately processes the F5 Distributed Cloud WAFT blocked response page. Claude provides a natural language explanation of the incident and displays the details of the response, which is the configured WAFT blocking page content.

Conclusion

The demo effectively demonstrates how F5 Distributed Cloud WAFT can easily protect MCP servers from attacks, with most attacks being blocked out of the box with minimal configuration. The integration with WAFT MCP Remote Proxy further enhances the user experience by allowing Claude to process the WAFT blocked response pages and provide informative feedback. The main takeaway is that F5 Distributed Cloud WAFT offers a robust and easily deployable solution for securing MCP servers in Agentic AI environments.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.