What is our primary use case?
Our clients mostly have their own applications, such as banking apps, and use F5 Advanced WAF to avoid vulnerabilities and threats on both the application layer and transport layer.
We create web policies for their apps and configure ASM signatures to prevent vulnerabilities. After configuring the policies, I monitor logs continuously to block vulnerability attacks and assist clients in addressing any issues.
How has it helped my organization?
One of the things that surprised me the most about F5 devices is their compatibility with the existing infrastructure of most customers. They can be easily integrated between the main firewall and back end servers, making it a seamless addition to enhance security.
What is most valuable?
The traffic learning feature stands out as the most valuable. When an app is accessed, the log generated in F5 Advanced WAF provides suggestions on what actions to take. This feature is particularly beneficial in new vulnerability scenarios, offering guidance based on learned data.
Additionally, I appreciate the way F5 Advanced WAF builds policies by configuring a basic policy and queuing it in learning mode. The solution learns from logs, and based on that learning, I configure ASM signatures.
What needs improvement?
The GUI interface can be confusing due to similar-looking tabs for policy building, traffic learning, and event logs. A more explanatory GUI would be beneficial. However, F5 solutions are a bit expensive compared to others, although they provide the best service and options.
Buyer's Guide
F5 Advanced WAF
May 2025
Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with F5 Advanced WAF for around six months.
What do I think about the stability of the solution?
The solution is very stable. I would rate it a nine out of ten for stability.
What do I think about the scalability of the solution?
F5 Advanced WAF is very scalable, and I would rate its scalability as nine out of ten.
How are customer service and support?
F5 support is excellent and deserves a ten out of ten. Their technical support is responsive and helpful, making the overall experience very satisfactory.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
I have not worked with many other vendors as extensively as F5, but I have some knowledge of FortiWAF. FortiWAF has fewer options compared to F5, particularly in features like iRULES, which offers more flexibility for traffic management and coding.
How was the initial setup?
The initial setup is not very lengthy. Once the device is on-premises, configuring and managing it is quite efficient, though the entire project from start to end may take about a month to a month and a half.
What about the implementation team?
I work with a team of five to six network engineers across different cities, providing support and collaboration for client deployments.
What was our ROI?
The return on investment is quite high with F5 solutions. Customers prefer F5 for their superior service and features, despite the higher cost.
What's my experience with pricing, setup cost, and licensing?
F5 is on the expensive side but offers superior solutions and options. Customers are willing to pay for the quality and features provided.
Which other solutions did I evaluate?
I have some knowledge of FortiWAF, but F5 provides more options, especially with features like iRULES for managing traffic.
What other advice do I have?
I would recommend F5 Advanced WAF to other users. It provides excellent features, flexibility, and support.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner