No more typing reviews! Try our Samantha, our new voice AI agent.

Atomic ModSecurity Rules vs F5 Advanced WAF comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Atomic ModSecurity Rules
Ranking in Web Application Firewall (WAF)
29th
Average Rating
9.0
Reviews Sentiment
7.8
Number of Reviews
1
Ranking in other categories
No ranking in other categories
F5 Advanced WAF
Ranking in Web Application Firewall (WAF)
3rd
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
72
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Web Application Firewall (WAF) category, the mindshare of Atomic ModSecurity Rules is 0.8%, down from 1.0% compared to the previous year. The mindshare of F5 Advanced WAF is 3.6%, down from 8.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
F5 Advanced WAF3.6%
Atomic ModSecurity Rules0.8%
Other95.6%
Web Application Firewall (WAF)
 

Featured Reviews

Vahid Babaey - PeerSpot reviewer
PhD Student at University of North Carolina at Charlott
Open rules have enabled me to secure web apps against obfuscated SQL injection and XSS attacks
The best feature Atomic ModSecurity Rules offers is the open source aspect. I believe that because it's open source, all of the developers, programmers, and security experts are able to update this WAF and provide more rules, creating a more secure WAF for all of the clients and customers around the world. By accessing Atomic ModSecurity Rules, it has helped me significantly. Because of this open source feature, I am able to generate new rules and update the WAF and use this WAF in my research and also give it to other clients and customers to use the updated WAF. All of this is done just because of the open-source feature, because it can be updated.
reviewer2797602 - PeerSpot reviewer
Senior Security Systems Engineer at a tech services company with 11-50 employees
Granular security policies have protected critical applications and ensure safe user and admin access
Improvements could be made regarding the log information from the backend CLI. There are enhancements needed; if a request gets blocked on the TCP layer, there should be traces or data to verify which source generated these requests, including the source and port information for initiation. These data are missing from F5 Advanced WAF. Besides that, another improvement could be refining the bot detection to minimize false positives; it should be able to verify more granularly between legitimate and non-legitimate clients. Overall, I find everything else good. A wish list feature I have is for the Technical Assistance Center (TAC) to respond more promptly. Their response time needs improvement; while they do not take excessive time, it can be enhanced, especially given it is a security product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The best feature Atomic ModSecurity Rules offers is the open source aspect, because all of the developers, programmers, and security experts are able to update this WAF and provide more rules, creating a more secure WAF for all of the clients and customers around the world."
"I like them because I like the security solution. They get extra marks compared to other solutions or competitors. There are more features than any other product I can think of. They're always monitoring, and the security features offer more than other, lesser products."
"The most valuable features of the F5 Advanced WAF are the enhanced ASM and the performance, and additionally, the usability and effectiveness are very good."
"The most valuable features of F5 Advanced WAF are the security features and the protection."
"We chose this product because we believe it is the best product for us."
"The most valuable features of F5 Advanced WAF are SSL uploading, signature, and anomaly detection, and it is overall a high-quality solution."
"The web application firewall itself is most valuable. It provides positive security and negative security. In negative security, it blocks a task such as cross-site scripting, code injection, etc. In positive security, it lets you specify and enforce things, such as the parameters allowed in username and password fields and the number of characters allowed in a field."
"F5 Advanced WAF is a stable solution, we are satisfied. It is more stable than ForiWeb."
"WAF functionality is valuable for protecting applications from attacks."
 

Cons

"Additionally, I know that ModSecurity can block only SQL injection and XSS attacks, no more types of attacks."
"I would not expect traffic details to pass through the web application firewall across the length of the whole application. I think that there is a web application where it can let the application function without traffic going in into the WAF."
"One of our customers is a bit unhappy about the reporting options."
"For F5 Advanced WAF, it's only 70% different over time with upgrades. F5 can still build AWS support after many long years of absence."
"The scalability could be improved."
"F5 Advanced WAF sells perpetual licenses as perpetual assets during sales without informing me that support ends after a few years."
"There are opportunities for improvement in updating the user interface to a more modern look."
"Compatibility with multiple cloud environments needs improvement. Both stability and scalability need to be improved."
"I would like for there to be a cloud-based solution, this would also help to improve scalability."
 

Pricing and Cost Advice

Information not available
"It's more expensive than other solutions and depending on the modules, there can be additional fees."
"F5 bundles up services and the bundle is what you pay for rather than individual components."
"There are various plans available for Fortinet FortiWeb Cloud WAF as a Service, including a trial version."
"The price of the solution is reasonable when compared with other products, such as FortiWeb. I am very satisfied with the price."
"Licensing fees for this solution are paid on a yearly basis."
"The way we deployed it, I would rate it a four out of five in terms of pricing."
"There are different licenses available to use F5 Advanced WAF, such as BT, ASM, and LPM."
"The cost is slightly above average."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
913,924 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
27%
Hospitality Company
13%
Manufacturing Company
10%
Outsourcing Company
10%
Financial Services Firm
14%
Comms Service Provider
10%
Computer Software Company
8%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise16
Large Enterprise31
 

Questions from the Community

What needs improvement with Atomic ModSecurity Rules?
Atomic ModSecurity Rules can be improved by first studying and reading the structure of new obfuscated attacks, then trying to generate more specific and better rules to block these attacks, and th...
What is your primary use case for Atomic ModSecurity Rules?
My main use case for Atomic ModSecurity Rules is in my research, which tries to make websites secure against web attacks like SQL injection and XSS attacks. On one side, I try to generate some obfu...
What advice do you have for others considering Atomic ModSecurity Rules?
I would rate Atomic ModSecurity Rules nine out of ten. I chose nine out of ten because I have not studied other WAFs. I know that ModSecurity is the only open source WAF, but I believe that the oth...
What is your experience regarding pricing and costs for F5 Advanced WAF?
F5 Advanced WAF is somewhat costly compared to other vendors, but it is worth the investment due to the stability it provides to the environment and infrastructure.
What needs improvement with F5 Advanced WAF?
Improvements could be made regarding the log information from the backend CLI. There are enhancements needed; if a request gets blocked on the TCP layer, there should be traces or data to verify wh...
What is your primary use case for F5 Advanced WAF?
My main use case for F5 Advanced WAF is to protect external and internal applications from cyber attacks and to prevent malicious payloads and malicious data from reaching servers. Even if maliciou...
 

Overview

 

Sample Customers

Information Not Available
MAXIMUS, Vivo, American Systems, Bangladesh Post Office, City Bank
Find out what your peers are saying about Imperva, Radware, F5 and others in Web Application Firewall (WAF). Updated: September 2026.
913,924 professionals have used our research since 2012.