Try our new research platform with insights from 80,000+ expert users

FortiWeb Web Application Firewall (WAF) vs Imperva Web Application Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
74
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
FortiWeb Web Application Fi...
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
23
Ranking in other categories
Web Application Firewall (WAF) (16th)
Imperva Web Application Fir...
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
52
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
IgnitiusMolepo - PeerSpot reviewer
Protects internal applications and prevents target attacks
The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats. It blocks malicious traffic, including dormant and DDoS attacks, and offers integrated Web Application Firewall features to safeguard against compromises. You can set it up for customer-facing web applications because customers don't necessarily know all the IP addresses. It uses a source-based approach where any source accessing the application is defined by its IP. When accessing the application, it checks if they are using HTTP or HTTPS and blocks them if necessary. The tool's performance and security reporting capabilities contribute positively to IT security management. Consolidating management within the solution makes it easier for IT to handle the solutions. All functionalities managed on a single box reduce the number of boxes needed for management.
Abdullah Jin - PeerSpot reviewer
Offers bot protection and DDoS Protection and protects public-facing portals
Support is one thing I wish Imperva could improve. They follow the phone model and keep rotating you from one customer service person to another. The layer one support isn't very clear about the workings of the product. My feedback is primarily about Imperva Cloud, not on-premise. On-premise is a whole new story. Support is the issue for Imperva Cloud. It's also a bit pricey. It's a premium service and very expensive. The licensing model is not very straightforward. Every feature is priced separately, and to enjoy maximum protection, you'll have to spend a lot of money. The licensing model is a bit complex, and each feature is very pricey. For example, API security and web application protection are two separate license packages.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Even when there is a high load on our servers, Cloudflare is able to cache the data and serve it to users, ensuring they can still access the website."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"It is a fast and secure DNS."
"The most valuable feature is its usability."
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"The tool is user-friendly."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"Cloudflare has many features."
"We use it to secure VMs and applications. It protects against DDoS attacks. It's very user-friendly."
"FortiWeb Web Application Firewall helps us to block certain categories of browsing, such as weapons, and other inappropriate content on the client side. We have also blocked social media sites like TikTok and Facebook to enhance user productivity and maintain application security."
"Their support is truly exceptional when I compare it with similar large-sized companies."
"FortiWeb has a very extensive library of known attack signatures, which makes the product fit for any environment, regardless if the customer uses Windows-specific or non-Windows-specific applications."
"The product's initial setup phase was easy."
"The product is easy to configure."
"The machine learning feature reduces the false positives."
"The good thing about Fortinet is that their enablement is very good in terms of training me and enabling resources on their technology."
"There are a number of features that are valuable such as the account takeover and various antivirus features."
"Very intuitive and granular configuration - It does not require much time, or advanced knowledge, for configuration and maintenance."
"I have had a positive experience with Imperva Web Application Firewall's tech support so far. They are knowledgeable and respond on time."
"The most important feature I have found to be the ease in how to do the backup and restores."
"The solution has been quite stable. I have not seen any bugs at all."
"The most valuable features of the Imperva Web Application Firewall are performance and flexibility. We can extend or customize the box itself."
"Imperva monitors all traffic, even customer access, to the web application. Then, Imperva uses features like signatures to identify attacks like cross-site scripting or SQL injection."
"There are some features that are configured by default, so even without doing much, it can still provide a level of protection."
 

Cons

"There might be helpful if there was some web application firewall feature."
"There should be a specific price list for enterprise-level customers."
"For the free and Pro plans, Cloudflare could use a simple bot to provide information to users. This would improve support, especially for less advanced users who utilize the free components."
"The solution could work at being less expensive. It costs a lot to use it."
"The analytics, basically the dashboard, doesn't have much to it."
"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"Although I think it's quite good, it doesn't provide me with all the features I would expect to have if I were using Imperva."
"I believe they currently have this feature, but there will most likely be integration with APIs so we can control some features through API."
"WAF needs more signatures on FortiWeb and updates the database continuously to protect against new attacks."
"I don't see any issues with the tool apart from the pricing aspect of the product. The price of the product is an area where improvements are required."
"FortiWeb could have an inbound load balancing pack."
"The tool's price and performance are areas of concern where improvements are required."
"FortiWeb Web Application Firewall needs to improve its performance."
"If some of my customers want to migrate from F5 to Fortinet Firewall, or the Fortinet WAF solution, there are some migration issues since I cannot migrate all the elements quickly using Fortinet Firewall."
"The documentation is poor."
"It would be good if the solution integrated with other solutions, like SAP."
"It would be helpful to have a "recommended deployment", or even a list of basic features that should either be used or turned on by default."
"I would like to improve the tool's turnaround time in terms of support."
"Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better."
"The signature updates could be faster. Sometimes we have to upload signatures to the Imperva portal for checking and analysis before we can use them."
"The UI interface needs improvement."
"Some of the features should be included in the next release is a file integrating monitoring tool. This feature should be improved."
"I am looking for more data enrichment. We should have the ability to add our own custom data to the system, to the live traffic."
"If they can bring in generative AI features, that would be useful."
 

Pricing and Cost Advice

"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"A free version of the solution is available."
"The cost primarily depends on the size of the organization."
"The price of the solution is expensive."
"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"We are using the free version."
"That is one of the great features. I was able to access the majority of the features and services for free."
"This product offers two pricing options: a standard package and an advanced package."
"I rate the tool's pricing an eight out of ten."
"It is a cheap solution."
"The tool is really expensive."
"I would rate the pricing a four out of ten."
"The licensing cost of the product is pretty high compared to other OEMs in the market."
"I rate the product price a four on a scale of one to ten, where one is a high price, and ten is a low price."
"It is a cost-effective product. If you need an extra module in the product, there will be an extra cost in addition to the licensing fee."
"Imperva Web Application Firewall is expensive."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
"The tool is expensive."
"There are some licenses that you have to buy to use some features. Its price could be better. Price is always important because, at the end of the day, customers have a budget. If you can meet the budget, you can sell, and if you don't, you cannot sell."
"It's an excellent product, but it can be very costly."
"The solution's pricing is an issue."
"We sell three-year licenses for Imperva Web Application Firewall to our customers. The price is a little expensive."
"Everybody complains about the price of this solution."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
13%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
15%
Financial Services Firm
12%
Manufacturing Company
12%
Comms Service Provider
8%
Financial Services Firm
17%
Computer Software Company
13%
Insurance Company
7%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about FortiWeb Web Application Firewall (WAF)?
The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS.
What is your experience regarding pricing and costs for FortiWeb Web Application Firewall (WAF)?
FortiWeb uses a subscription-based license, but there is also an option for a perpetual license. It's not the cheapes...
What needs improvement with FortiWeb Web Application Firewall (WAF)?
There are some issues pertaining to the migration. If some of my customers want to migrate from F5 to Fortinet Firewa...
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you hav...
DDoS solutions: Any other solutions to consider aside from Radware DDoS Protection Service and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot ...
 

Also Known As

Cloudflare DNS
No data available
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Information Not Available
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about FortiWeb Web Application Firewall (WAF) vs. Imperva Web Application Firewall and other solutions. Updated: March 2025.
845,406 professionals have used our research since 2012.