No more typing reviews! Try our Samantha, our new voice AI agent.
RoiNahari - PeerSpot reviewer
CEO at CyberApp
Real User
Top 5Leaderboard
Apr 17, 2025
Bot protection capabilities enhance application security
Pros and Cons
  • "The whole mechanism of F5 Advanced WAF is effective."

    What is our primary use case?

    I am working with an integration and security company that collaborates with various vendors. I am currently dealing with F5 Advanced WAF.

    What is most valuable?

    The whole mechanism of F5 Advanced WAF is effective. It contains the logic of both negative and positive security combined, providing added value to the company I work with to protect their applications.

    What needs improvement?

    I do not have anything in mind right now that needs improvement. Generally, it works well. If we need any specific feature, we approach F5 directly.

    For how long have I used the solution?

    I have probably used it for ten years or so.

    Buyer's Guide
    F5 Advanced WAF
    June 2026
    Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
    900,747 professionals have used our research since 2012.

    How are customer service and support?

    I do not need them much because my team is professional. If there is a bug, the support is usually understanding and resolves issues.

    What's my experience with pricing, setup cost, and licensing?

    The price is affordable and satisfactory.

    What other advice do I have?

    One of the best features is the bot protection capabilities. I rate the product eight out of ten.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Abdul Azim - PeerSpot reviewer
    Network Security Engineer at a tech vendor with 11-50 employees
    Real User
    Top 5
    Dec 24, 2024
    Client-side and mobile app protection with 24/7 support for security
    Pros and Cons
    • "The bot defense capability, as well as protection from brute force attacks and OWASP Top Ten, are notable features."
    • "F5 Advanced WAF has significantly enhanced our organization's security posture by protecting critical banking applications against sophisticated threats."
    • "F5 needs to improve API protection with a single F5 solution, without requiring additional modules."

    What is our primary use case?

    F5 Advanced Web Application Firewall (AWAF) is primarily used in financial sectors like banking to secure web applications against advanced threats, ensuring compliance with industry regulations. Our Key use cases include:

    1. Protection Against OWASP Top 10: Safeguarding banking applications from SQL injection, XSS, and other common vulnerabilities.
    2. Bot Mitigation: Detecting and blocking malicious bots to prevent account takeovers, credential stuffing, and fraud.
    3. DDoS Protection: Defending against application-layer DDoS attacks to ensure service availability.
    4. PCI DSS Compliance: Enforcing security policies to meet compliance standards for protecting sensitive customer data.
    5. API Security: Securing APIs used in banking platforms from abuse and unauthorized access.
    6. Threat Intelligence: Leveraging threat intelligence to identify and mitigate zero-day attacks.
    7. Application Traffic Control: Managing and monitoring application traffic to ensure optimal performance and security.

    These use cases help financial institutions maintain secure and resilient applications, critical for trust and compliance.

    How has it helped my organization?

    F5 Advanced WAF has significantly enhanced our organization's security posture by protecting critical banking applications against sophisticated threats. It ensures compliance with regulatory standards, improves customer trust through robust bot mitigation, and enhances application performance by mitigating DDoS attacks and securing APIs. Additionally, it provides real-time threat intelligence and streamlined security management, reducing downtime and operational risks.

    What is most valuable?

  • Bot Protection: Mitigates automated attacks like credential stuffing.

  • API Security: Safeguards APIs against exploitation.

  • Advanced Threat Detection: Protects against OWASP Top 10 vulnerabilities and zero-day threats.

  • DDoS Mitigation: Ensures application availability during attacks.

  • Behavioral Analytics: Detects and mitigates anomalous traffic patterns.

  • Granular Policy Control: Enables precise security policy customization.

  • Threat Intelligence Integration: Offers real-time updates for proactive protection.

  • What needs improvement?

    1. Ease of Deployment: Simplify initial setup and policy configuration.
    2. UI Enhancements: Improve user interface for better navigation and usability.
    3. Integration: Enhance compatibility with third-party tools like SIEMs and DevOps pipelines.
    4. Performance Optimization: Reduce latency during high traffic volumes.

    Suggested Features for Next Release:

    1. AI-Driven Threat Detection: Advanced machine learning for proactive defense.
    2. Comprehensive API Protection: Extended support for GraphQL and WebSocket APIs.
    3. Cloud-Native Integration: Better functionality in hybrid and multi-cloud environments.
    4. Automated Policy Suggestions: AI-based recommendations for policy tuning.

    For how long have I used the solution?

    It's been two years that I've been working with this solution.

    What do I think about the stability of the solution?

    I am not experiencing any significant instability.

    What do I think about the scalability of the solution?

    F5 AWAF offers excellent scalability, enabling organizations to protect applications seamlessly across on-premises, cloud, and hybrid environments. It can handle increasing traffic volumes with minimal latency, ensuring consistent security for both small-scale deployments and enterprise-grade architectures. With its ability to integrate into CI/CD pipelines and auto-scale in cloud environments, F5 AWAF supports dynamic application growth without compromising performance or protection.

    How are customer service and support?

    Customer service is very responsive. If the issue persists beyond my local support capabilities, I open a ticket with F5, and they respond quickly. I rate their technical support 9 out of 10.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Not now just I have checked the comparision and collect reviews from peerspoot and Quadrant 

    How was the initial setup?

    The initial setup experience is straightforward, and I did not face any complexities. I recommend deploying the F5 AWAF solution on a single appliance with LTM.

    What's my experience with pricing, setup cost, and licensing?

    F5 is relatively less expensive compared to other solutions as F5 is considered the best.

    Which other solutions did I evaluate?

    Not Now

    What other advice do I have?

    I rate F5 eight to nine out of ten. I recommend F5 to customers who require a robust solution and have the budget for it. However, for customers looking for modest pricing, I would not recommend the F5 solution.

    I'd rate the solution eight out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Buyer's Guide
    F5 Advanced WAF
    June 2026
    Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
    900,747 professionals have used our research since 2012.
    Ehab Kamal - PeerSpot reviewer
    Import Comliance Specialist at silicon21
    Reseller
    Top 5
    Nov 18, 2024
    Empower critical applications with comprehensive protection and enhanced security capabilities
    Pros and Cons
    • "F5 Advanced WAF is a comprehensive community platform with a strong commitment, making it valuable for businesses."
    • "I would like to see improved features in the F5 Advanced WAF solution, especially with a focus on enabling Kubernetes fully."

    What is our primary use case?

    I was in charge of the F5 on-premises solution, where I published several applications for certificate verification and protected various applications. Additionally, I was working with botnets.

    What is most valuable?

    F5 Advanced WAF is a comprehensive community platform with a strong commitment, making it valuable for businesses. The capabilities on GitHub are highly appreciated, allowing me to count on F5 for reliability.

    What needs improvement?

    I would like to see improved features in the F5 Advanced WAF solution, especially with a focus on enabling Kubernetes fully. The database needs better service discussions and updates on communication. Additional improvements could also be made in asset management for the data.

    For how long have I used the solution?

    I've been working with F5 for what seems like a lengthy period.

    What do I think about the stability of the solution?

    F5 is logistics-oriented, ensuring that the Webpack performs well in making every single case for the Stereo platform.

    What do I think about the scalability of the solution?

    F5 is scalable, especially for Stellar and virtualization processes. Customers can scale efficiently.

    How are customer service and support?

    F5's technical support team is commendable. They are professional and take high-priority prompts seriously.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    My experience includes comparing F5 with FortiWeb. F5 provides more security capabilities for applications than FortiWeb.

    How was the initial setup?

    The initial setup of the F5 Advanced WAF solution involves multiple stages and might require revisiting configurations based on customer needs. The setup can be complex compared to other options.

    What about the implementation team?

    I am part of the deployment and implementation team, and we follow a strategy that involves providing quality assurance to ensure data integrity and server protection. Collaboration and dialogue with customers are part of the implementation.

    What was our ROI?

    Customers have shown consistent ROI with F5 solutions, especially when daily requests come in for assistance.

    What's my experience with pricing, setup cost, and licensing?

    The user interface and sub-management prices can be a concern, however, they generally align with the industry's needs.

    What other advice do I have?

    I recommend the F5 Advanced WAF solution for everyone with critical applications. Security needs to be embedded within the full visualization pipeline, allowing significant savings. I rate F5 Advanced WAF at a nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Usama Nasir - PeerSpot reviewer
    Network Security Engineer at IIPL
    Real User
    Top 5
    Oct 29, 2024
    Enhanced security with adaptive traffic management and policy learning
    Pros and Cons
    • "I appreciate the way F5 Advanced WAF builds policies by configuring a basic policy and queuing it in learning mode."
    • "The GUI interface can be confusing due to similar-looking tabs for policy building, traffic learning, and event logs."

    What is our primary use case?

    Our clients mostly have their own applications, such as banking apps, and use F5 Advanced WAF to avoid vulnerabilities and threats on both the application layer and transport layer. 

    We create web policies for their apps and configure ASM signatures to prevent vulnerabilities. After configuring the policies, I monitor logs continuously to block vulnerability attacks and assist clients in addressing any issues.

    How has it helped my organization?

    One of the things that surprised me the most about F5 devices is their compatibility with the existing infrastructure of most customers. They can be easily integrated between the main firewall and back end servers, making it a seamless addition to enhance security.

    What is most valuable?

    The traffic learning feature stands out as the most valuable. When an app is accessed, the log generated in F5 Advanced WAF provides suggestions on what actions to take. This feature is particularly beneficial in new vulnerability scenarios, offering guidance based on learned data. 

    Additionally, I appreciate the way F5 Advanced WAF builds policies by configuring a basic policy and queuing it in learning mode. The solution learns from logs, and based on that learning, I configure ASM signatures.

    What needs improvement?

    The GUI interface can be confusing due to similar-looking tabs for policy building, traffic learning, and event logs. A more explanatory GUI would be beneficial. However, F5 solutions are a bit expensive compared to others, although they provide the best service and options.

    For how long have I used the solution?

    I have been working with F5 Advanced WAF for around six months.

    What do I think about the stability of the solution?

    The solution is very stable. I would rate it a nine out of ten for stability.

    What do I think about the scalability of the solution?

    F5 Advanced WAF is very scalable, and I would rate its scalability as nine out of ten.

    How are customer service and support?

    F5 support is excellent and deserves a ten out of ten. Their technical support is responsive and helpful, making the overall experience very satisfactory.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have not worked with many other vendors as extensively as F5, but I have some knowledge of FortiWAF. FortiWAF has fewer options compared to F5, particularly in features like iRULES, which offers more flexibility for traffic management and coding.

    How was the initial setup?

    The initial setup is not very lengthy. Once the device is on-premises, configuring and managing it is quite efficient, though the entire project from start to end may take about a month to a month and a half.

    What about the implementation team?

    I work with a team of five to six network engineers across different cities, providing support and collaboration for client deployments.

    What was our ROI?

    The return on investment is quite high with F5 solutions. Customers prefer F5 for their superior service and features, despite the higher cost.

    What's my experience with pricing, setup cost, and licensing?

    F5 is on the expensive side but offers superior solutions and options. Customers are willing to pay for the quality and features provided.

    Which other solutions did I evaluate?

    I have some knowledge of FortiWAF, but F5 provides more options, especially with features like iRULES for managing traffic.

    What other advice do I have?

    I would recommend F5 Advanced WAF to other users. It provides excellent features, flexibility, and support.

    I'd rate the solution ten out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    reviewer2586870 - PeerSpot reviewer
    Senior Network Engineer at a comms service provider with 11-50 employees
    Real User
    Top 5
    Dec 3, 2024
    Harness comprehensive security to protect web applications from modern threats
    Pros and Cons
    • "The most valuable feature of F5 Advanced WAF is its extensive set of capabilities for application protection, including DDoS prevention, and its ability to work with Pentesters and external scanners to observe user activity and eliminate false positives."
    • "It's a powerful tool yet can be complex for new users."
    • "All features of Advanced WAF offer numerous functions, which means tuning configuration is not simple."

    What is our primary use case?

    F5 Advanced WAF is used for the protection of applications from current web threats, including DDoS attacks. It provides a comprehensive security solution that incorporates different protection levels.

    What is most valuable?

    The most valuable feature of F5 Advanced WAF is its extensive set of capabilities for application protection, including DDoS prevention, and its ability to work with Pentesters and external scanners to observe user activity and eliminate false positives. This comprehensive approach to application security enables an organization to protect its web applications from diverse web threats effectively.

    What needs improvement?

    All features of Advanced WAF offer numerous functions, which means tuning configuration is not simple. It's a powerful tool yet can be complex for new users. Future updates should ensure not to break the current state, as users are concerned the new version may not meet current standards.

    For how long have I used the solution?

    I have been using F5 Advanced WAF for more than ten years.

    What do I think about the stability of the solution?

    F5 Advanced WAF is considered a stable product, and I would rate it as ten out of ten in terms of stability.

    What do I think about the scalability of the solution?

    The solution's scalability is solid, with the option to increase capabilities through licensing and adding modules in the virtual edition. However, it requires additional expenses, so I would rate it as a seven or eight out of ten.

    How are customer service and support?

    F5 provides one of the best technical supports, though there have been a few cases where customers were dissatisfied due to response speed. However, in general, their support is highly efficient and knowledgeable.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    In the past, Imperva was the leading solution, however, now F5 is preferred as it offers a superior solution according to customer feedback.

    How was the initial setup?

    Deploying the solution, including initial configuration, licensing, addressing, and enabling WAF, could take one to three hours. However, for a comprehensive setup, considering external factors and optimizations, the process could take up to a month.

    What about the implementation team?

    I handle installations and other related aspects by myself, without any additional help.

    What was our ROI?

    There are numerous benefits for end customers, as a secure application helps prevent potential breaches and ensures the safety of customers' data, especially in sensitive sectors like banking.

    What's my experience with pricing, setup cost, and licensing?

    F5 Advanced WAF is not cheap. That said, it offers numerous features and is known as one of the best solutions in its segment. It provides significant value by offering comprehensive protection for high-stakes environments.

    Which other solutions did I evaluate?

    I work with other vendors, such as Broadcom, Qualys, BeyondTrust, and Trend Micro, depending on the customer's needs and the vision of my company.

    What other advice do I have?

    I would fully recommend F5 Advanced WAF for its feature-rich offerings and high detection rate of threats. I rate it a ten out of ten as it is one of the best solutions available.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    YUSUF  TAIWO - PeerSpot reviewer
    Founder roverupgrades.com.ng at 22 TEAM RESOURCES LIMITED
    Real User
    Dec 1, 2023
    Ensures a robust and unified security approach for our clients
    Pros and Cons
    • "F5's user-friendly interface and seamless integration stand out as the most valuable features for us."
    • "One area for improvement in the product is its SSO integration, which posed challenges and required significant effort to resolve."

    What is our primary use case?

    My clients often seek a comprehensive security solution for their hybrid environments, with both cloud and on-premise web applications. To address this, I recommend combining F5 Advanced WAF for web application security with Fortinet solutions, including FortiGate, FortiSign, and FortiAnalyzer, for broader network security aspects like vulnerability ranking, patch management, and remediation. I focus on FortiGate and FortiAnalyzer, collaborating with a colleague who manages firewall setup, ensuring a robust and unified security approach for our clients.

    What is most valuable?

    F5's user-friendly interface and seamless integration stand out as the most valuable features for us. The intuitive interface streamlines tasks, providing a straightforward experience. F5's adaptability in diverse environments sets it apart, especially when compared to alternatives like FortiGate. Despite being pricier, the ease of integration and user-friendly design make F5 Advanced WAF our preferred choice for securing web applications. F5's commitment to customer engagement, exemplified by hosting a certification event in Nigeria, further shows its support and involvement in our region.

    What needs improvement?

    One area for improvement in the product is its SSO integration, which posed challenges and required significant effort to resolve. The complexity of SSO deployment, coupled with high associated costs, could be addressed to enhance usability. Streamlining the SSO process and revisiting cost considerations would contribute to an improved user experience.

    For how long have I used the solution?

    I have been working with F5 Advanced WAF for three years.

    What do I think about the stability of the solution?

    I would rate the stability as a nine out of ten.

    What do I think about the scalability of the solution?

    I would give the scalability of the solution an eight out of ten. It is quite scalable and performs well. I would recommend F5 Advanced WAF for medium-sized businesses and enterprises, primarily due to considerations around cost and sustainability. The solution is well-suited for companies of this size, ensuring that not only is it deployed effectively, but it can also be sustained over time to meet ongoing security needs.

    How are customer service and support?

    The technical support is good. I would rate it as a seven out of ten.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    For an end-to-end solution, Fortinet stands out over F5 Advanced WAF. Fortinet's comprehensive product suite, including FortiGate, FortiAnalyzer, and integrated features like CMDD, provides a more seamless and holistic approach to security. While F5 is strong in certain areas, the integrated capabilities of Fortinet make it my preferred choice for a comprehensive security solution.

    How was the initial setup?

    The initial setup for F5 Advanced WAF is user-friendly and relatively straightforward.

    What's my experience with pricing, setup cost, and licensing?

    The main drawback of F5 is the cost, which can be a challenge. 

    What other advice do I have?

    Overall, I would rate F5 Advanced WAF as a nine out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Freelancer at Freelance
    Reseller
    Jan 25, 2023
    Flexible configuration, reliable, and highly professional support
    Pros and Cons
    • "The most valuable feature of F5 Advanced WAF is its grand unity of the implementation, where you have the freedom to configure based on how it affects your use case or your organization. With the default setting of implicit deny, you can gradually start defining and deploying the tool to align with your environment, whether it is outdated, recent, or futuristic. This allows you to customize the solution to protect you from threat actors. You have the ability to define what the advanced threat act should do - whether it should alert, deny, or both - and it will deliver based on your configuration. Unlike other online solutions, F5 Advanced WAF provides flexibility to deliver to your unique environment the way you want."
    • "The most valuable feature of F5 Advanced WAF is its grand unity of the implementation, where you have the freedom to configure based on how it affects your use case or your organization."
    • "While F5 Advanced WAF does limit the number of partners in certain regions to ensure successful business transactions, they could also benefit from expanding their partnerships and making it easier for more people to learn about and become experts in F5 Advanced WAF. By doing so, they could increase the reach and exposure of their solution, similar to how Cisco has become widely recognized in the security industry."
    • "F5 Advanced WAF is not a cost-effective solution."

    What is our primary use case?

    Recent progress in F5 Advanced WAF's cloud technology has broadened the use cases for web application firewalls (WAFs) to include multi-cloud environments.

    What is most valuable?

    The most valuable feature of F5 Advanced WAF is its grand unity of the implementation, where you have the freedom to configure based on how it affects your use case or your organization. With the default setting of implicit deny, you can gradually start defining and deploying the tool to align with your environment, whether it is outdated, recent, or futuristic. This allows you to customize the solution to protect you from threat actors. You have the ability to define what the advanced threat act should do - whether it should alert, deny, or both - and it will deliver based on your configuration. Unlike other online solutions, F5 Advanced WAF provides flexibility to deliver to your unique environment the way you want.

    What needs improvement?

    While F5 Advanced WAF does limit the number of partners in certain regions to ensure successful business transactions, they could also benefit from expanding their partnerships and making it easier for more people to learn about and become experts in F5 Advanced WAF. By doing so, they could increase the reach and exposure of their solution, similar to how Cisco has become widely recognized in the security industry.

    For how long have I used the solution?

    I have been using F5 Advanced WAF for approximately seven years.

    What do I think about the stability of the solution?

    The solution is highly stable. I have deployed several F5 Advanced WAF sites since 2016, and they are running without any issues, such as crashes or corrupt systems. To ensure stability, all that is required is to keep the solution updated and manage the patches in a timely manner.

    Over the past 10 years, they have grown and increased its strength, adapting to the ever-changing market. They have incorporated Terraform and NGINX, showing their commitment to growth and stability. 

    I rate the stability of F5 Advanced WAF a ten out of ten.

    How are customer service and support?

    F5 Advanced WAF has an outstanding technical support team that is available worldwide. They have a Service Level Agreement (SLA) in place for critical issues, which guarantees a response within an hour. The team is highly professional and will stay with you until your issue is resolved.

    I rate the support of F5 Advanced WAF a ten out of ten.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    For a novice, deploying on F5 Advanced WAF is difficult. Everyone who works on the solution is expected to get trained and certified before they can be considered an administrator. Therefore, for someone who is certified, it is relatively easy to deploy.

    If your environment is prepared, it should take no more than four to five hours to do the implementation. The most common issue people have is that their environment is not ready or the deployment engineer does not understand it. However, this can be quickly resolved, and then the configuration can be made, allowing you to be up and running.

    Depending on the environment you are deploying in, you must first obtain the appropriate license. For example, if you are deploying in a virtual environment (VE) on-premise, you must first download the ISO file, deploy it, configure your interfaces, and then license the F5 Advanced WAF before configuring it.

    I rate the initial setup of F5 Advanced WAF a ten out of ten.

    What about the implementation team?

    We used five people for the deployment of the solution.

    What was our ROI?

    In terms of return on investment, F5 Advanced WAF offers a high ROI.

    The F5 Advanced WAF allows for easy onboarding of web applications without the need for additional investments. For example, if a company has one web application that needs to be protected, and then tomorrow they have 15 more, they can easily onboard them onto the same F5 Advanced WAF device without any extra cost. This saves both time and money. Additionally, F5 Advanced WAF provides protection for a company's assets and reputation, ensuring compliance with regulations such as PCI DSS, and improving overall business efficiency by reducing the need for troubleshooting and manpower. Overall, F5 Advanced WAF offers a high return on investment.

    I rate the ROI of F5 Advanced WAF a ten out of ten.

    What's my experience with pricing, setup cost, and licensing?

    F5 Advanced WAF is not a cost-effective solution. Although they are attempting to reduce prices with their VE and cloud options, they are more expensive than other solutions. The solution is more expensive on average.

    If you are interested in F5 Advanced WAF, it is billed on a yearly basis and based on the number of requests for the service. For example, if you purchase 200 megabytes, there is specific pricing for that capacity. Every year, we will renew the service and provide support for the solution.

    F5 Advanced WAF does not offer local support services unless the customer is discussing it with a vendor or partner. These services are typically provided by other partners.

    F5 Advanced WAF could improve in two main areas: pricing and partnerships. The current pricing of F5 Advanced WAF can be quite high, and while they do offer options like the VE or infrastructure service, they could make further efforts to make their solutions more affordable for everyone.

    I rate the price of F5 Advanced WAF an eight out of ten.

    What other advice do I have?

    We use one person for the maintenance of the solution.

    I would advise new users to familiarize themselves with the overall functionality of the solutions. Understanding F5 Advanced WAF is crucial to accessing the full range of its capabilities. Without this understanding, you may be limited to only using it for your initial intended purpose. I recommend taking the time to learn more about F5 Advanced WAF and its capabilities, as it can provide solutions for many other needs in addition to your initial use case. It's also suggested to get certified and familiarize yourself with the product portfolio.

    I rate F5 Advanced WAF a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    Özden-Aydın - PeerSpot reviewer
    Technology Consultant at 1ware
    Real User
    Top 5Leaderboard
    Oct 31, 2024
    Bot attack reduction and enhanced web security with reasonable pricing
    Pros and Cons
    • "It provides web application security and reduces bot attacks."
    • "The product could be more user-friendly for administrators."

    What is our primary use case?

    We use this solution for load balancing and web application firewall (WAF) services. We use the solution standalone and not integrated with other solutions.

    How has it helped my organization?

    It provides web application security and reduces bot attacks.

    What is most valuable?

    The web attack signatures are very important for detecting attacks, and the bot detection capability is an important feature that works well with F5 Advanced WAF.

    What needs improvement?

    The product could be more user-friendly for administrators. The user interface could be easier.

    For how long have I used the solution?

    I have been using it for almost three years.

    What do I think about the stability of the solution?

    The solution is very stable. I would rate its stability as nine out of ten.

    What do I think about the scalability of the solution?

    Very scalable. We use this solution for multiple customers and across data centers.

    How are customer service and support?

    The solution offers good support. That said, sometimes it takes too much time to reach the right person.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have also worked with Citrix NetScaler and F5 products, depending on customer needs.

    How was the initial setup?

    The initial configuration is not too difficult, but subsequent configurations can be complex because they depend on customer needs.

    What's my experience with pricing, setup cost, and licensing?

    I don't have direct knowledge of the pricing. From what I know, it is not too expensive compared to other solutions.

    Which other solutions did I evaluate?

    I am familiar with F5 and Citrix NetScaler solutions.

    What other advice do I have?

    I recommend this product to others because of its effectiveness in mitigating threats.

    I'd rate the solution eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    Phani Sundar Mandarapu - PeerSpot reviewer
    Enterprise Architect at Collins Aerospace
    Real User
    Apr 26, 2024
    Efficiently protect web servers exposed to the external network and robust stability
    Pros and Cons
    • "It's a fairly easy-to-use and user-friendly tool. My administrators and team also like its ability to customize the rules per the requirements."
    • "The user interface (UI) seems a bit outdated. Making it more user-friendly would be beneficial."

    What is our primary use case?

    Primarily, the Advanced WAF sits behind our network perimeter. It centralizes traffic flow to our network, filters requests, and identifies any potential threats.

    How has it helped my organization?

    It helps us detect threats or malicious requests coming into the network, protecting it from being hacked. It helps guard against issues like cross-site scripting (XSS) and other similar threats.

    So, F5 Advanced WAF helped mitigate bot traffic for our web applications.

    Moreover, my experience is that it's pretty straightforward to use. Our firewall team handles requests through a change management tool within scheduled change windows. However, F5 is our only firewall solution.

    What is most valuable?

    It's a valuable tool to protect web servers exposed to the external network. With numerous web applications running on Apache or IIS servers, the F5 Advanced WAF's threat detection capabilities protect the network before traffic reaches those servers.

    It's a fairly easy-to-use and user-friendly tool. My administrators and team also like its ability to customize the rules per the requirements. 

    What needs improvement?

    The self-service aspect could be improved. 

    The user interface (UI) also seems a bit outdated. Making it more user-friendly would be beneficial.

    For how long have I used the solution?

    We've been using it for approximately five to six years.

    What do I think about the stability of the solution?

    I would rate the stability a ten out of ten. It is a stable product. 

    What do I think about the scalability of the solution?

    It is pretty good. I would rate the scalability a seven out of ten.

    Ssometimes, the way our enterprise handles change requests might slow things down because of the internal rules and processes. But these changes, once approved, do take effect immediately on the firewall itself. 

    We have a change window twice a week for these requests. I don't think the limitation is with the firewall itself; it's more about our internal procedures.

    What other advice do I have?

    Overall, I would rate the solution an eight out of ten because I have seen that not too much customization is required during setup. The change requests we submit are usually clear and easily applied. 

    Overall, the policies work well, and the threat detection is good. It catches deviations and anomalies effectively.

    From a recommendation standpoint, it's a fairly easy tool to use. However, you definitely need some knowledge about scripting, OWASP fundamentals, threat detection, and general cybersecurity principles to get the most out of it.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    SOC Analyst at a financial services firm with 1,001-5,000 employees
    Real User
    Aug 20, 2022
    Stable and has a pool of resources for traffic distribution and management
    Pros and Cons
    • "The most valuable feature of F5 Advanced WAF is its ability to have a pool of resources that can distribute your traffic, and that is a plus for me. My company tried to look into a competitor, Imperva, but it was lacking that capability, so F5 Advanced WAF outperforms Imperva."
    • "As far as I am concerned, F5 Advanced WAF is one of the most stable solutions I've ever used, so it's good to implement."
    • "For me, an area for improvement in F5 Advanced WAF is the reporting as it isn't so clear. The vendor needs to work on the reporting capability of the solution. What I'd like to see in the next release of F5 Advanced WAF is threat intelligence to protect your web application, particularly having that capability out-of-the-box, and not needing to pay extra for it, similar to what's offered in FortiWeb, for example, any request that originates from a malicious IP will be blocked automatically by FortiWeb. F5 Advanced WAF should have the intelligence for blocking malicious IPs, or automatically blocking threats included in the license, instead of making it an add-on feature that users have to pay for apart from the standard licensing fees."
    • "For me, an area for improvement in F5 Advanced WAF is the reporting as it isn't so clear."

    What is our primary use case?

    Our client has an internally hosted website, and they wanted us to help them in reducing the attack surface in their web application, so we use F5 Advanced WAF for that purpose.

    What is most valuable?

    The most valuable feature of F5 Advanced WAF is its ability to have a pool of resources that can distribute your traffic, and that is a plus for me. My company tried to look into a competitor, Imperva, but it was lacking that capability, so F5 Advanced WAF outperforms Imperva.

    What needs improvement?

    For me, an area for improvement in F5 Advanced WAF is the reporting as it isn't so clear. The vendor needs to work on the reporting capability of the solution.

    What I'd like to see in the next release of F5 Advanced WAF is threat intelligence to protect your web application, particularly having that capability out-of-the-box, and not needing to pay extra for it, similar to what's offered in FortiWeb, for example, any request that originates from a malicious IP will be blocked automatically by FortiWeb. F5 Advanced WAF should have the intelligence for blocking malicious IPs, or automatically blocking threats included in the license, instead of making it an add-on feature that users have to pay for apart from the standard licensing fees.

    For how long have I used the solution?

    I've been using F5 Advanced WAF for about two years.

    What do I think about the stability of the solution?

    F5 Advanced WAF is a super stable solution. I've not been aware of any issues with the solution whenever my company uses it.

    What do I think about the scalability of the solution?

    How scalable F5 Advanced WAF is would depend on what resources your client or the virtual server has. It all boils down to the allocated resources. For me, F5 Advanced WAF is pretty much scalable in terms of the resources I've assigned.

    How are customer service and support?

    I contact the technical support team of F5 Advanced WAF from time to time, and I would rate support eight out of ten. What the support team needs to improve is the SLA, particularly the speed of response.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    In terms of setting up F5 Advanced WAF, what was challenging was the network part, but the rest wasn't that difficult. It took almost two weeks to complete the setup for F5 Advanced WAF.

    What about the implementation team?

    We implemented F5 Advanced WAF ourselves.

    What was our ROI?

    It's hard to tell if the customer got ROI from F5 Advanced WAF because it's based on the initial deployment and approach. It would've been just a matter of time before the customer enjoyed ROI from the solution. My company never experienced a serious incident with the use of F5 Advanced WAF for the customer, so my assumption is at some point, the customer is realizing the ROI.

    What's my experience with pricing, setup cost, and licensing?

    The pricing for F5 Advanced WAF is comparable to a Rolls-Royce. Its price is a bit high when you compare it with other vendors. F5 Advanced WAF is a bit expensive. The customer was on a three-year plan and it was around $560,000.

    Which other solutions did I evaluate?

    We evaluated Imperva, but F5 Advanced WAF was able to outperform Imperva.

    What other advice do I have?

    I'm an administrator of F5 Advanced WAF for my customer, so I'm more of a user. I'm not a partner or reseller of F5. I'm just a consultant and administrator.

    From what I recall, during the time of deployment, my company was using version 15 of F5 Advanced WAF, but I'm not so sure if there's been a new version or an upgrade after that version.

    My company has less than ten users/administrators of F5 Advanced WAF.

    My advice for people who want to implement the solution, though I might be biased because I've not used other solutions, but as far as I am concerned, F5 Advanced WAF is one of the most stable solutions I've ever used, so it's good to implement.

    My rating for F5 Advanced WAF is nine out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free F5 Advanced WAF Report and get advice and tips from experienced pros sharing their opinions.
    Updated: June 2026
    Buyer's Guide
    Download our free F5 Advanced WAF Report and get advice and tips from experienced pros sharing their opinions.