

Find out in this report how the two Web Application Firewall (WAF) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
Time savings in daily operations come from the automatic learning and signature update reducing the need for constant manual rule management, allowing the security and network teams to spend significantly less time handling false positive application-related escalations.
Subscription models offer clearer ROI due to a more competitive pricing scheme.
The amount of attacks it protects against is immense, more than F5 Advanced WAF itself costs.
Operational efficiency has improved; we no longer have staff consistently monitoring backend servers during deployment or scaling events, as HAProxy's health checks and hitless reloads allow us to push changes with minimal manual intervention.
This resulted in a drastic decrease in costs and, at the same time, the accuracy of the hits coming on HAProxy was almost around 100% or 99.99%.
I estimate seeing a return on investment with HAProxy, as it significantly reduced staff requirements and enhanced scaling capabilities, particularly when transitioning from NGINX, which faced issues.
Both response time and availability need to be improved.
While they resolve issues well, the time taken for responses to non-critical issues should be shorter.
If there is a bug, the support is usually understanding and resolves issues.
Since we are utilizing the open-source edition, community forums, mailing lists, and GitHub have been invaluable, with typically someone having encountered the same problems we faced.
My interactions with HAProxy's customer support were limited, but the feedback from my team indicated satisfactory service.
If you need to scale up, such as moving from a lower model to a higher one, the configuration from the lower model can be migrated easily without issues.
I can run it in HA mode or even divide the traffic volume to the number of instances that I have based on their resource sizing.
We manage an automatic load balancing feature where we add HAProxy servers dynamically behind the application load balancer to handle more traffic.
HAProxy's scalability is excellent; as our traffic expands, it handles load increases effortlessly.
For scalability, HAProxy meets my needs, supporting our initial horizontal scaling and then adapting to vertical scaling in a VMware environment.
F5 Advanced WAF has been very reliable and consistent for us; in our on-premise enterprise setup, it has been stable and predictable in day-to-day operations without any unexpected crashes or WAF-related downtime in production.
F5 Advanced WAF is stable, and there is no doubt it is one of the best WAFs in the market.
F5 Advanced WAF is pretty stable.
This reliability serves as a key reason for our choice, providing us with confidence even when faced with heavy traffic.
The hot reload feature of HAProxy also really helped us so that we never had to shut it down to reload it.
We have reduced a lot of servers, replacing them with one or two HAProxy servers which deliver better performance, accuracy, and an almost 100% success rate with requests.
Deployment training for F5 Advanced WAF is lacking and restricts growth by being inaccessible and costly for partners.
Overall, these are not blockers, merely enhancement opportunities, and once tuned, F5 Advanced WAF is very stable and reliable; improving usability, reporting, and onboarding would make it even more effective for larger environments.
Another improvement could be refining the bot detection to minimize false positives; it should be able to verify more granularly between legitimate and non-legitimate clients.
The configuration syntax is powerful yet can become overwhelming for newcomers; a more beginner-friendly interface or a native GUI without relying on third-party tools would ease the onboarding process.
An easier desktop interface to connect to a remote server and make changes on my PC would be beneficial.
The reloading functionality is effective as it allows soft reloads without interrupting traffic patterns.
Licensing is capacity-driven, so you need careful planning based on traffic volume and use cases, and adding features such as Bot Protection impacts costs; once licensing is clear and sized correctly, there are no surprises.
Subscription models have competitive pricing, while perpetual licenses involve an upfront higher cost.
The price is affordable and satisfactory.
Since we use the open-source edition, there are no licensing fees, with the main cost being the infrastructure running on EC2 instances in AWS, which helps maintain low expenses.
Setting up HAProxy didn't cost anything for me.
The pricing remains competitive compared to other vendors.
The Advanced Attack Signature database is very strong and regularly updated, effectively blocking SQL injections, cross-site scripting, command injections, and file inclusion attacks while allowing selective enabling or disabling of signatures to avoid blocking genuine traffic.
The perpetual license, despite an initial higher cost, lacks transparency regarding support expiration.
It contains the logic of both negative and positive security combined.
By moving all SSL termination to the load balancer, I now manage certificates in a single place, and I can also utilize Let's Encrypt with HAProxy's built-in ACME support, making renewal automatic.
HAProxy positively impacted our organization by exceeding scalability expectations, initially projected at 200k requests but ultimately handling over 15 million transactions per second without any issues.
As a production engineer at that time, I definitely wanted to ensure that the system could handle massive connections, especially since we operated an e-commerce platform where we could not lose any customer calls.
| Product | Mindshare (%) |
|---|---|
| F5 Advanced WAF | 3.6% |
| HAProxy | 1.9% |
| Other | 94.5% |

| Company Size | Count |
|---|---|
| Small Business | 27 |
| Midsize Enterprise | 16 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 15 |
| Large Enterprise | 16 |
F5 Advanced WAF delivers robust web security with features like signature-based threat protection and behavior analysis, ensuring app stability and security.
F5 Advanced WAF integrates advanced security with functionalities such as SQL injection defense and real-time threat intelligence. It enhances security for applications with load balancing, bot detection, and DDoS protection alongside comprehensive attack monitoring capabilities. Popular among diverse sectors, its usability and easy integration make it a practical choice by providing a stable security infrastructure across both on-premises and cloud environments.
What are the key features?Particularly relevant in banking and financial services, F5 Advanced WAF safeguards applications from threats like SQL injections and DDoS attacks, ensuring compliance and API security. Its capabilities are leveraged for both load balancing and application defense, offering a versatile deployment model suited for protecting critical infrastructure in competitive and demanding industries.
HAProxy delivers reliability, high performance, and efficient load balancing solutions. Its open-source model ensures cost-effectiveness and scalability, ideal for managing extensive infrastructure demands with minimal latency while offering seamless integration with modern platforms.
HAProxy is renowned for its robust performance in load balancing across TCP and HTTP protocols, featuring multiple algorithms such as round-robin. Users appreciate its customizable configuration and seamless SSL termination, which make it an excellent choice for managing complex infrastructures. The platform's open-source nature supports scalability, reducing costs while providing flexible proxy operations. HAProxy efficiently handles high concurrency, enabling smooth traffic management and ensuring stability within diverse systems.
What key features does HAProxy offer?HAProxy is extensively used in load balancing implementations across various sectors. Companies deploy it for managing high traffic, Layer 4 and Layer 7 applications, and SQL databases. It supports microservices architecture, performs SSL offloading, and manages email services like SMTP. As a reverse proxy, HAProxy delivers high availability for systems like Redis, RabbitMQ, and Apache while integrating with Docker and Kubernetes. Its features enhance web application firewall capabilities and traffic routing, making it suitable for industries demanding reliable and efficient network management.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.