No more typing reviews! Try our Samantha, our new voice AI agent.

Citrix SD-WAN [EOL] vs Steelhead comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
Web Application Firewall (WAF) (6th)
Citrix SD-WAN [EOL]
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
No ranking in other categories
Steelhead
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
26
Ranking in other categories
WAN Optimization (1st), WAN Edge (13th)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
Rohit Ghorpade - PeerSpot reviewer
Cloud Network Engineer at a insurance company with 5,001-10,000 employees
A scalable solution for MCN controller but lacks technical supports, upgrades
There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out. Previously, we faced some issues with the slowness part. Apart from that, feature like end gateway level antivirus. We are currently using a NetFlow proxy to establish a virtual position for the NetFlow. Our current environment has many use cases, but we are not using them on the Citrix SD-WAN. When I navigate the NCL part, it involves configuration. I want to highlight this disadvantage. Sometimes, when we push the configuration, it tries to push it to all branch locations. This process takes a lot of time, nearly 30 minutes, to push a single change from the NCL. Overall, I don't think Citrix meets our use cases what we have. This is based on my feedback after using it for the past year and working on this Citrix SD-WAN. However, from my experience, it is the worst solution I have seen. There's no domain-based routing, which is horrible. That's why we are moving to other products. We have checked our use case requirements with Fortinet, Palo Alto, and they meet them. I will consider the PoC or another OEM. There are many things in the area you need to be prompt, like the automation part. If any link or device goes down, alerting notification, etc. We need to perform and highlight so many things to your management. This should be improved.
Chaudhary Muhammad Moez Manzar - PeerSpot reviewer
Senior manager at a tech services company with 201-500 employees
Reduces operational costs through bandwidth optimization but struggles with high traffic licensing and complex deployments
The logs in Steelhead are fantastic. There is a deep level of logs such as top 10 docker and top 50 docker. I can check from the top 50 docker which type of application is optimizing well and which type of traffic is not optimized. Steelhead provides logs and percentage levels, which is good. I can see any type of log report, report security, different types of report availability, but it is not customizable. Overall, this is a good feature. Steelhead provides real-time optimization with graphs and tables on real-time optimization, informing us packet by packet including port, source IP, destination IP, and destination port number. This reporting and real-time monitoring is fantastic, although I faced a problem in Oracle. Steelhead mainly saves the money that needs to be paid to ISPs. My actual traffic is around 2 GB, but I purchased a link from the ISP for only around 700 to 800 MB. All the prices that need to be paid monthly to the ISP are saved, which is a significant saving for my company after using Riverbed.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution protects our application, which runs on the HTTP protocol, from DDoS attacks."
"It's pretty convenient and pretty easy to set up and run. And then kind of for static content, it also offers caching."
"We like that there's load balancing, firewall capabilities, DDoS protection, et cetera, all covered by Cloudflare."
"Very glad the WAF rulesets works out of box, and requires very little tuning or maintenance."
"Caching is the most valuable feature of Cloudflare Web Application Firewall."
"Cloudflare is cheaper compared to Azure WAF, which I have considered before."
"Cloudflare has positively impacted my organization by making it easier for me to handle and set up DNS for multiple clients; I can easily go in and access their accounts, make changes they need, and it's a one-stop shop."
"I have not had any issues with this solution, and I would recommend it to others who are interested in using it."
"This is a good product and I recommend it."
"The zero-touch deployment is most valuable for us."
"Citrix SD-WAN helps us in re-routing certain traffic, for example, local internet breakouts for Office 365, and it also helps us to be more agile when we are opening new offices or when we are moving locations."
"The VPN and the load balancing are the most valuable features."
"CIFS optimisation is really good and benefits are realised if using ICA also."
"It's been three years we have deployed this product and I have not had any downtime or any issues with the product."
"It allows us to use additional VPNs, offering more options compared to other VPN solutions."
"They have a zero downtime failover mechanism, where, when there's a link failure or a link weakness, or bad link conditions, they provide the ability to fail back seamlessly."
"The data compression through the WAN is like being on a LAN and is even more effective when the technology uses an adaptive transfer scheme known as warm transfer."
"It's helped to reduce WAN traffic by approximately 60%."
"The data reduction that we realize (>85% for our most common protocols) is amazing."
"Steelhead has drastically improved user experience."
"This product is far way ahead from its competitors."
"TCP optimization... caches a particular TCP connection and the next time a user uses that connection he will reach the destination easily."
"The connectivity to speed is the valuable feature."
"The compression of Riverbed is very powerful. It can also handle large quantities of traffic."
 

Cons

"We have noticed some latency when the call goes through the firewall. That could be improved."
"They need to improve their support because getting a response for basic requests took around 48 hours, which is too long."
"The rate limiting functionality could be enhanced, as we find it somewhat limited."
"The accuracy of the Cloudflare Web Application Firewall could be improved by reducing the number of false-negative alerts."
"The blocked logs are difficult to read at times."
"Cloudflare should update the version of the ModSecurity core rule set that they run on."
"They have some limitations with third-party integrations."
"The dashboard could be more user-friendly."
"Citrix SD-WAN does not have the SD-WAN with one optimization in a single license. Other competitors have this option and it should be added to this solution."
"The only improvement for Citrix SD-WAN would be to lower its cost."
"The level of support from Citrix is not that great."
"I would like to see more customization to adjust for the WAN lock-out due to our unexpected power outages."
"It is a bit expensive. A cheaper product would be good, but everybody likes things to be cheaper."
"Customer Service: Not great - the first line support for this product is pretty much nil."
"The firewall reporting could be easier to use and filter."
"Given that Citrix SD-WAN solved all our problems by providing us with everything we needed to unify communications with our branches and data centers, I cannot suggest anything further in terms of improvements."
"I didn't like the way platforms were scaled – if you started with a top end model of one of the tiers, if you needed to upgrade you had to rip and replace the box with a whole new one."
"The product should offer more integration capabilities."
"Personally, my expertise with this device I feel is too low to determine what areas could be improved."
"If we load a primary firewall, the secondary firewall usually handles all the active connections, but in Riverbed, this isn't the case. We lose all the active connections at the moment of failure."
"If we lose the primary Steelhead that handles the optimization, the secondary Steelhead cannot handle the same High Availability."
"Currently what we have in the system can not support the software-defined networks, so I won't say it's scalable."
"The Central Management Console (CMC) newly named SteelCentral Controller (SCC) has rudimentary netflow capabilities, but it doesn’t have particularly in-depth data."
"The scalability is not the best. If you find that you have outgrown the capacity of your appliance you are forced to repurchase the license and the appliance with very little discount even if your appliance is still under contract."
 

Pricing and Cost Advice

"It starts at $20 and can easily go up to $200 monthly"
"We pay $210 per month for CloudFlare WAF."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"The solution is expensive."
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"The annual licensing fee is $10,000 USD."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"The price is relatively expensive."
"I believe that Citrix SD-WAN is a good investment, but I do not have the information to be more specific."
"It is a bit expensive. A cheaper product would be good, but everybody likes things to be cheaper. We bought the devices up front, and then we pay for the annual support."
"I'm not quite sure of the price ranges. Roughly, the hidden devices can scale up to $20K for one appliance. However, the branch CPs are USD $1,000 to $2,500."
"It would be helpful to have a demo license available for customers who want to prove the concept and conduct a proof of concept (POC) before committing to the solution. This is particularly important for customers in Egypt who often require a demonstration of the solution's features and compatibility with their needs before making any investment or incurring costs. Providing a demo license would allow customers to assess whether the solution would meet their needs or not."
"It's a little bit on the high side compared to the other products."
"The license was a one-time purchase. It's expensive."
"The price of the subscription should be cheaper."
"Across our 12 data centers, we spend around $150k annually."
"The solution is expensive and the service contacts are costly too. The cost of the device makes the value proposition borderline acceptable for us. The service contract fees we pay is approximately $30,000 annually."
report
Use our free recommendation engine to learn which WAN Optimization solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Financial Services Firm
9%
Comms Service Provider
9%
Manufacturing Company
7%
Construction Company
16%
Financial Services Firm
11%
Manufacturing Company
8%
Computer Software Company
7%
Manufacturing Company
16%
Construction Company
15%
Financial Services Firm
11%
Outsourcing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise10
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise7
Large Enterprise14
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What needs improvement with Citrix SD-WAN?
The solution's licensing model could be improved. Citrix SD-WAN is a good product from a technical point of view. How...
What advice do you have for others considering Citrix SD-WAN?
If a customer already has Citrix NetScaler and is not looking to change anything in their existing environment, we pr...
What is the best network monitoring software for large enterprises?
We just did an assessment for our 47 datacenters around North America. The top two enterprise-level network monitorin...
What is your primary use case for Riverbed Steelhead?
I am currently working with Riverbed for replication between PR to DR for synchronization purposes, and for WAN optim...
What advice do you have for others considering Riverbed Steelhead?
Application performance may improve with Steelhead, but it varies application to application. Some applications, such...
 

Also Known As

Cloudflare WAF
Citrix CloudBridge, WOC, NetScaler SD-WAN
RIverbed Steelhead
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
AIDS Healthcare Foundation, Cornerstone Home Lending Inc., Dallara, ecVision, Essar, Eurofred, Groupe Promutuel, HMSHost Corporation, Royal Caribbean Cruise Lines Ltd, Royal Caribbean International
ElAraby, SFK Leblanc, Bobst Group, Northwest Pipe Company, Halkbank, Tradebridge, EFG Hermes
Find out what your peers are saying about Riverbed, Cato Networks, Hewlett Packard Enterprise and others in WAN Optimization. Updated: June 2026.
900,747 professionals have used our research since 2012.