WAF custom rules are more flexible, of course, and from a business perspective, I can understand why they would recommend that option instead.
I currently filter on an nginx access log file among other filters (sshd, bot-search, bad-requests) and let fail2ban execute the ban/unban action itself.
From a quick search, it should be possible to handle bans/unbans externally, if that’s what you’re after.
Und das wäre dann auch sicherer als mit dem e-Scooter durch die Innenstadt zu pendeln, Herr Pistorius – ich meine, Herr Laschet.