No more typing reviews! Try our Samantha, our new voice AI agent.

Citrix SD-WAN [EOL] vs Steelhead comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
Web Application Firewall (WAF) (6th)
Citrix SD-WAN [EOL]
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
No ranking in other categories
Steelhead
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
26
Ranking in other categories
WAN Optimization (1st), WAN Edge (13th)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
Rohit Ghorpade - PeerSpot reviewer
Cloud Network Engineer at a insurance company with 5,001-10,000 employees
A scalable solution for MCN controller but lacks technical supports, upgrades
There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out. Previously, we faced some issues with the slowness part. Apart from that, feature like end gateway level antivirus. We are currently using a NetFlow proxy to establish a virtual position for the NetFlow. Our current environment has many use cases, but we are not using them on the Citrix SD-WAN. When I navigate the NCL part, it involves configuration. I want to highlight this disadvantage. Sometimes, when we push the configuration, it tries to push it to all branch locations. This process takes a lot of time, nearly 30 minutes, to push a single change from the NCL. Overall, I don't think Citrix meets our use cases what we have. This is based on my feedback after using it for the past year and working on this Citrix SD-WAN. However, from my experience, it is the worst solution I have seen. There's no domain-based routing, which is horrible. That's why we are moving to other products. We have checked our use case requirements with Fortinet, Palo Alto, and they meet them. I will consider the PoC or another OEM. There are many things in the area you need to be prompt, like the automation part. If any link or device goes down, alerting notification, etc. We need to perform and highlight so many things to your management. This should be improved.
Chaudhary Muhammad Moez Manzar - PeerSpot reviewer
Senior manager at a tech services company with 201-500 employees
Reduces operational costs through bandwidth optimization but struggles with high traffic licensing and complex deployments
The logs in Steelhead are fantastic. There is a deep level of logs such as top 10 docker and top 50 docker. I can check from the top 50 docker which type of application is optimizing well and which type of traffic is not optimized. Steelhead provides logs and percentage levels, which is good. I can see any type of log report, report security, different types of report availability, but it is not customizable. Overall, this is a good feature. Steelhead provides real-time optimization with graphs and tables on real-time optimization, informing us packet by packet including port, source IP, destination IP, and destination port number. This reporting and real-time monitoring is fantastic, although I faced a problem in Oracle. Steelhead mainly saves the money that needs to be paid to ISPs. My actual traffic is around 2 GB, but I purchased a link from the ISP for only around 700 to 800 MB. All the prices that need to be paid monthly to the ISP are saved, which is a significant saving for my company after using Riverbed.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution does a good job of preventing web application attacks, SQL injections, and cross-site scripting attacks."
"The solution protects our application, which runs on the HTTP protocol, from DDoS attacks."
"It is a SaaS solution unlike much of the competition."
"We extensively use the solution every day. The solution is very stable; we haven’t seen any glitches."
"The product has improved our security posture by blocking bad actors."
"It is configurable via API."
"The integration of Cloudflare with Cloud Suite is its most valuable feature."
"The Cloudflare Web Application Firewall's most valuable feature is its ease of configuration."
"We are using it widely for the local record for SaaS-based applications. Another valuable feature is a local breakout."
"We tried to use it, and it worked well."
"It allows us to use additional VPNs, offering more options compared to other VPN solutions."
"The hands-on customer support and load balancing that come with this solution are above all others on the market."
"The solution is brilliant, the way it calculates its paths and trails is great."
"The tool is quite cost-effective because it replaces the need for MPLS, which is a bit expensive...Citrix SD-WAN doesn't need much maintenance."
"It allows you to combine two asymmetrical connections."
"It's been three years we have deployed this product and I have not had any downtime or any issues with the product."
"SteelHead works from the application. I use it to optimize traffic from Amazon. It is mainly used for customers who need to increase the traffic to 33K. For other users, it has been more of an operation."
"You should buy SteelHead for WAN optimization because it delivers more."
"There are several features specific to branches, like keeping data hot and active on Steelhead devices. These features prevent unnecessary data travel across the international LAN."
"It's helped to reduce WAN traffic by approximately 60%."
"Steelhead has drastically improved user experience."
"TCP optimization... caches a particular TCP connection and the next time a user uses that connection he will reach the destination easily."
"Through this product, we can easily find the bottlenecks and where the traffic occurs or is generated in the network."
"Steelhead is stable, and it can even help you avoid service interruption in the event of a power outage. If your hardware fails, technical support will replace your device quickly."
 

Cons

"The ModSecurity core rules need to be updated."
"I have experienced some difficulties with Cloudflare's support as a customer based in India."
"WAF doesn't directly affect bandwidth costs. It saves costs on protection. However, with the correct setup, it's difficult to determine if it saves costs overall due to the fixed enterprise plan fee."
"A key challenge arises when dealing with numerous integrations with HVAC systems. Depending on the specifics, there might be some configuration mismatches, which necessitate specific support."
"The notification part could be improved. It's very much connected to Web Application Firewall, rate-limiting, and DDoS protection."
"The accuracy of the Cloudflare Web Application Firewall could be improved by reducing the number of false-negative alerts."
"They need to improve their support because getting a response for basic requests took around 48 hours, which is too long."
"Their documentation could be better. They don't have documentation that explains everything well."
"Given that Citrix SD-WAN solved all our problems by providing us with everything we needed to unify communications with our branches and data centers, I cannot suggest anything further in terms of improvements."
"The price of the subscription should be cheaper."
"I would like to either see the price reduced or have it packaged with other products to give better value for the money."
"Citrix should continue to offer a perpetual licensing model because it is very important to us."
"I would like to see support for additional reporting."
"The firewall reporting could be easier to use and filter."
"The level of support from Citrix is not that great."
"There are a few things that can be improved, are domain-based routing and the slowness of virtual parts, and it may be due to the wrong configuration, which we have been unable to find out."
"There are issues with the tech support and scalability."
"The solution needs to have alert notifications."
"Steelhead's handling of encrypted traffic could be improved because it requires some complex configuration to optimize encrypted traffic, especially when working with Microsoft protocols for mail servers and VPN services"
"The product should offer more integration capabilities."
"Currently what we have in the system can not support the software-defined networks, so I won't say it's scalable."
"The application response time of the solution can be improved."
"The advertised “fail open” feature doesn’t work as expected."
"Personally, my expertise with this device I feel is too low to determine what areas could be improved."
 

Pricing and Cost Advice

"Cloudflare Web Application Firewall is more affordable than other solutions."
"The solution is expensive."
"The solution's pricing option needs to be more transparent for enterprise clients."
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"It starts at $20 and can easily go up to $200 monthly"
"We pay $210 per month for CloudFlare WAF."
"It is not too pricey."
"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"It would be helpful to have a demo license available for customers who want to prove the concept and conduct a proof of concept (POC) before committing to the solution. This is particularly important for customers in Egypt who often require a demonstration of the solution's features and compatibility with their needs before making any investment or incurring costs. Providing a demo license would allow customers to assess whether the solution would meet their needs or not."
"Citrix SD-WAN is quite an affordable product."
"As NetScaler is now, I find it quite pricey."
"It depends on the scale. In our case, it would have been better if we had known about the life cycling steps, but otherwise, it is worth the money."
"The price is relatively expensive."
"It is a bit expensive. A cheaper product would be good, but everybody likes things to be cheaper. We bought the devices up front, and then we pay for the annual support."
"I'm not quite sure of the price ranges. Roughly, the hidden devices can scale up to $20K for one appliance. However, the branch CPs are USD $1,000 to $2,500."
"The license was a one-time purchase. It's expensive."
"The solution is expensive and the service contacts are costly too. The cost of the device makes the value proposition borderline acceptable for us. The service contract fees we pay is approximately $30,000 annually."
"Across our 12 data centers, we spend around $150k annually."
report
Use our free recommendation engine to learn which WAN Optimization solutions are best for your needs.
908,834 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Comms Service Provider
9%
Financial Services Firm
9%
Outsourcing Company
7%
Construction Company
18%
Outsourcing Company
12%
Financial Services Firm
10%
Manufacturing Company
7%
Manufacturing Company
16%
Construction Company
16%
Outsourcing Company
10%
Financial Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise10
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise7
Large Enterprise14
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What needs improvement with Citrix SD-WAN?
The solution's licensing model could be improved. Citrix SD-WAN is a good product from a technical point of view. How...
What advice do you have for others considering Citrix SD-WAN?
If a customer already has Citrix NetScaler and is not looking to change anything in their existing environment, we pr...
What is the best network monitoring software for large enterprises?
We just did an assessment for our 47 datacenters around North America. The top two enterprise-level network monitorin...
What is your primary use case for Riverbed Steelhead?
I am currently working with Riverbed for replication between PR to DR for synchronization purposes, and for WAN optim...
What advice do you have for others considering Riverbed Steelhead?
Application performance may improve with Steelhead, but it varies application to application. Some applications, such...
 

Also Known As

Cloudflare WAF
Citrix CloudBridge, WOC, NetScaler SD-WAN
RIverbed Steelhead
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
AIDS Healthcare Foundation, Cornerstone Home Lending Inc., Dallara, ecVision, Essar, Eurofred, Groupe Promutuel, HMSHost Corporation, Royal Caribbean Cruise Lines Ltd, Royal Caribbean International
ElAraby, SFK Leblanc, Bobst Group, Northwest Pipe Company, Halkbank, Tradebridge, EFG Hermes
Find out what your peers are saying about Riverbed, Hewlett Packard Enterprise, Cato Networks and others in WAN Optimization. Updated: July 2026.
908,834 professionals have used our research since 2012.