No more typing reviews! Try our Samantha, our new voice AI agent.
Network Security Consultant at GBM
Consultant
Dec 24, 2022
Powerful and easy-to-use security features for compliance or integration
Pros and Cons
  • "It is easy to obtain dashboard compliance because security policy views are included."
  • "The solution should include RASP for another level of protection at the code itself."

What is our primary use case?

Our company uses the solution for customer use cases to replicate environments, perform integrations, and check for changes or issues. We have many internal users because we have a wide database of customers. 

Most customers have WAF or Advanced WAF but if you dig deep from a high-level perspective, then you find issues with configurations or missing security enhancements. 

The platform is capable of doing many API integrations and other things. Customers with public websites use our client-facing service to upload attachments. Often, customers are not integrating the solution with a malware sandboxing tool. This feature is natively in-the-box so protection can be enabled with a few steps. We determine if attachments are uploading malicious files because there isn't protection in the normal solution. We find out if customers are doing vulnerability or risk assessments. Integration tools such as Qualys help because we can import a file to resolve F5 issues. 

For one use case, a customer might have enabled the tech signature for a specific tech but an IP exclusion or public IP exclusion is a bit risky.

Another use case is for database security where we utilize the solution's very comprehensive security features. We can make a SQL database more visible to database security and order logs for the logins to the station tool. 

What is most valuable?

It is very powerful to be able to enable database security integration for an administrator or customers.

The integration between modules is good. You can license the APM policy manager, integrate, and make security posters for VPN clients. You can natively integrate the login pages to ensure client machines and websites are protected. 

The solution includes the typical load balancing offered by other vendors but has enhanced security compliance features that are powerful and easy to configure.

It is easy to obtain dashboard compliance because security policy views are included.  

What needs improvement?

The solution requires a bit of advanced knowledge. They are trying to make configurations less complicated by including guides, particularly for application protection in the cloud. Nothing is complicated but it takes a hands-on approach and a few hours to a few months to become familiar with how the solution works. 

The solution should include RASP which is runtime application security protection. Imperva includes RASP but the solution does not at this point. RASP would provide another level of application protection at the code itself.  

For how long have I used the solution?

I am a certified F5 engineer and have been using the solution for four years. 

I am a partner so I use both the on-premises and the public cloud solution. To get certification, you need to complete a lot of labs and training on your own. You must go into detail with everything and get your hands dirty. 

I use the public cloud solution for my own labs. There is a free F5 public cloud tenant that includes other features for setting up a lab or application. 

The solution's virtual edition can be deployed in other cloud services such as Azure, AWS, and OCI. The virtual edition takes the on-premises version to the cloud so it is not difficult to implement. The only difference is the cloud-native version includes the WARP feature that is used for web application API protection. 

Buyer's Guide
F5 Advanced WAF
June 2026
Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is definitely stable so I rate stability a nine out of ten. 

What do I think about the scalability of the solution?

The solution is quite scalable so I rate scalability a nine out of ten. 

How are customer service and support?

To be honest, I have not needed support because I have the knowledge to fix anything unless it is a bug within the solution. 

How was the initial setup?

The initial setup is not complex so I rate it a ten out of ten. 

For on-premises, it might take two weeks to deploy security policies which depend on application traffic. You choose a policy set type from fundamental, comprehensive, or rapid according to your needs. Then, you apply the policy. 

For example, you can deploy a quick policy for a nonfinancial side to protect from common threats. In this case, you choose the rapid security policy, choose the application language, and add the SQL or PHP server technology to implement the attack signature. This is helpful because you don't need to apply all of the OS signatures if you only have Windows. Just pull the Windows signature and it will be plugged. 

Then you proceed to the staging model for awhile to pick up the negative security model. You can proceed with a mix of negative and unboxing security models. After that, you start deploying, defining URL parameters, and setting other policies. You put it to staging and make edits. If you don't find too many suggestions or false positives, then you deploy it in blocking mode to the vendor. 

After two or three weeks, if the owner is fine with the policies and number of false positives, then you put it to blocking. 

What about the implementation team?

We implement the solution for customers. Implementation can be done by one person who is knowledgeable about the product and procedures. 

IT managers generally do not dig deep inside the solution because there is quite a bit of detail. They have a high-level overview but certified experts dig deep into configurations. 

What's my experience with pricing, setup cost, and licensing?

I am not sure about pricing but licenses are available on Google. 

What other advice do I have?

The solution is not about improving functionality but about improving the security of an infrastructure itself. You are improving the security profile so that data is not exposed to an attacker. 

I definitely recommend that everyone use the solution and rate it a nine out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Systems Engineer at Sify Technologies
Real User
Top 10
Nov 22, 2024
Securing web applications with API and bot protection while enhancing IP intelligence
Pros and Cons
  • "The product is used to secure web applications and has the ability to use API templates and bot protection features, such as blocking requests or presenting CAPTCHA pages to end users."
  • "Users would like to have an additional IP intelligence license to handle this within WAF itself without needing to engage with the SOC team."

What is our primary use case?

The primary use case is to secure the organization's applications from web-based attacks, securing both web applications and APIs.

What is most valuable?

The product is used to secure web applications and has the ability to use API templates and bot protection features, such as blocking requests or presenting CAPTCHA pages to end users. We also implement Swagger files for API security and use custom profiles for device ID threshold management.

What needs improvement?

The main improvement needed is related to IP intelligence. Once we start receiving traffic from repetitive IP addresses, we have to report it to the SOC team to block it at the layer four level. Users would like to have an additional IP intelligence license to handle this within WAF itself without needing to engage with the SOC team.

For how long have I used the solution?

The solution has been used for three years.

How are customer service and support?

Customer service and support depend on the level of support subscribed to, such as silver or platinum support, which determines the response time.

How would you rate customer service and support?

Positive

How was the initial setup?

Deploying the solution involves an application learning and blocking phase. The process includes collecting application data, creating policies, and applying them to lower testing environments like QA or dev before moving to UAT and production. The learning phase is used to handle false positives and fine-tune the policies before going live.

What about the implementation team?

The in-house team manages and supports the WAF, handling incidents reported by end users when legitimate traffic is blocked. They update the policies to prevent the recurrence of similar blocks.

What's my experience with pricing, setup cost, and licensing?

The pricing and support service levels affect response times from customer service, depending on whether the support level is silver, platinum, etc.

Which other solutions did I evaluate?

We are exploring cloud-based solutions like Azure WAF and AWS WAF.

What other advice do I have?

I rate F5 Advanced WAF an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
Buyer's Guide
F5 Advanced WAF
June 2026
Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
Muhammad Salahuddin - PeerSpot reviewer
Unit Head - Network and Security Solutions at FPM Solutions
Real User
Oct 11, 2022
Their support engineers are experts who always provide the right solution,
Pros and Cons
  • "F5 technical support is excellent. They are experts who always provide the right solution, and they understand the problem. Their response and resolution times are good."
  • "F5 products are highly stable, top-notch solutions, and we have also the expertise to deploy and design the F5 and Palo Alto product lines."
  • "Nevertheless, F5 products are generally considered to be hard to deploy."

What is our primary use case?

In Pakistan, the banking and financial sector requires F5 WAF solutions. I worked with other companies that had more clients, but my current company is a start-up. We have Palo Alto business, but we're trying to get F5 business.

What is most valuable?

F5 products are highly stable, top-notch solutions, and we have also the expertise to deploy and design the F5 and Palo Alto product lines. I have more than 10 years of experience with F5 and Palo Alto. I have deployed around F5 products for around seven or eight customers of F5.

What needs improvement?

F5 should consider adding network detection and response.

For how long have I used the solution?

We have been using F5 solutions for two years, including load balancers and Advanced WAF.

What do I think about the stability of the solution?

Advanced WAF is highly stable.

What do I think about the scalability of the solution?

F5 products are scalable, and they have an excellent R&D department. Their product is constantly maturing.

How are customer service and support?

F5 technical support is excellent. They are experts who always provide the right solution, and they understand the problem. Their response and resolution times are good.

How was the initial setup?

Advanced WAF is a difficult product for new users, but it's not too challenging if you have experience. Nevertheless, F5 products are generally considered to be hard to deploy. 

What's my experience with pricing, setup cost, and licensing?

F5's hardware product line is called BIG-IP, and they have many software licenses for IP DNS, Advanced WAF, APM, anti-spam, etc. We have around 10 licenses.

What other advice do I have?

I rate F5 Advanced WAF 10 out of 10. I would highly recommend the entire F5 product line.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Saeid Khanipour Ghobani - PeerSpot reviewer
IT Manager at Technology Evaluation Center
Real User
Sep 25, 2022
A robust solution for large companies that includes vCMP-like visualization
Pros and Cons
  • "The solution uses AI to protect against botnet attacks."
  • "Across all of our customers, we have more than a million users at the same time with no issues."
  • "The solution should include protection against web page attacks like what is available in FortiWeb."
  • "The solution is very expensive so should only be used in the right environment."

What is our primary use case?

Our company installs the solution for customers who require more features than are available with FortiADC. 

One of our customers is a bank that has API for both web and mobile applications. We use the solution to load balance and provide protection for the API requests that come from customers to the application server. With more than 200,000 DNS requests per second, the solution's advanced features are the best fit to the customer's needs. 

What is most valuable?

The solution uses AI to protect against botnet attacks. 

The solution has a vCMP-like feature that allows you to visualize more than two  TMOS at the same time on your hardware. This feature is not available with other solutions. 

What needs improvement?

The solution should include protection against web page attacks like what is available in FortiWeb. 

The solution should integrate with Kubernetes. I believe there is a new ADC planned for the end of 2022 that will accomplish this goal. 

For how long have I used the solution?

I have been using the solution for six years. 

What do I think about the stability of the solution?

The solution is super stable with extra chassis space. 

We sometimes use solution to its maximum capacity and it is still stable with no crashes. 

What do I think about the scalability of the solution?

The solution is super scalable. 

FortiADC is a good solution for small or mid-sized companies but F5 can handle the largest companies. 

Across all of our customers, we have more than a million users at the same time with no issues.

How are customer service and support?

I have not needed technical support. 

How was the initial setup?

The initial setup is more complex than FortiADC and takes about twice the amount of time. 

What about the implementation team?

Our company provides setup and deployment for our customers. 

What's my experience with pricing, setup cost, and licensing?

The solution is very expensive so should only be used in the right environment. I believe each device costs around $20,000 and includes a three-year license. 

I rate the cost a ten out of ten. 

Which other solutions did I evaluate?

We do not consider other options for large companies but do install FortiADC for small to mid-sized companies. 

What other advice do I have?

It is important to know your network and assess your needs such as dust protection, VAT, and load balancing before deciding if FortiADC or F5 are the best solution.  

F5 is expensive so is only appropriate for large companies with high-level use. 

I rate the solution a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Quoc Nguyen - PeerSpot reviewer
F5 Product Manager at Westcon-Comstor
Real User
Jul 20, 2022
A solution that would benefit with more documentation regarding bot protection
Pros and Cons
  • "The most valuable features of F5 Advanced WAF are the security features and the protection."
  • "F5 Advanced needs to improve its bot protection. The solution needs to have machine learning to learn the behavior of the customer to recognize the human versus the bot. This is a difficult feature to explain to our customers. I would like documentation about the bot feature to make it easier for the customer to understand."
  • "The pricing of F5 Advanced WAF is more expensive than other solutions like Radware and CD18, it is quite high."

What is our primary use case?

We are distributors in Vietnam. We consult for our customers and I am a Product Manager. We use F5 Advanced WAF as a firewall for our website applications and the websites of our customers.

What is most valuable?

The most valuable features of F5 Advanced WAF are the security features and the protection.

In the future, I would like to see F5 include AI in the hardware of F5 Advanced WAF.

What needs improvement?

F5 Advanced needs to improve its bot protection. The solution needs to have machine learning to learn the behavior of the customer to recognize the human versus the bot. This is a difficult feature to explain to our customers. I would like documentation about the bot feature to make it easier for the customer to understand.

For how long have I used the solution?

I have been using F5 Advanced WAF for two years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

F5 Advanced WAF is scalable.

How are customer service and support?

We tend to handle our own technical support for our customers. My experience with F5 support is a three out of five overall. They need to improve the information and training of the receiver.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was neither easy nor difficult. I would rate setup as a four out of five.

What's my experience with pricing, setup cost, and licensing?

The pricing of F5 Advanced WAF is more expensive than other solutions like Radware and CD18, it is quite high. I rate the product a one out of five for price, with one being expensive.

What other advice do I have?

Overall, I would rate F5 Advanced WAF an eight out of ten overall.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Head of Presales at a tech vendor with 10,001+ employees
MSP
Jul 2, 2022
Expandable with helpful support and great threat intelligence functionality
Pros and Cons
  • "The solution is stable."
  • "The threat intelligence function is great."
  • "The deployment side is quite complex."
  • "The solution is pretty difficult to set up. You really have to have a grasp of the product to configure it correctly."

What is our primary use case?

It's considered one of the modules for the LTM box. It's all modules for the LTM box.

It is actually to protect the customer web application which is published on the internet. It's actually to protect that, and nowadays, we also have this threat intelligence. You will link to the F5 centra, the depository of the threat intelligence database. We always have the latest update on the common threat that is happening currently. You will notify the customer if there's an issue.

What is most valuable?

The threat intelligence function is great. Nowadays, there is more awareness on the security side. They'd have a real-time update from F5. It provides peace of mind on the security side for the customer.

It is an add-on module to protect the web application.

The solution can scale with planning.

The solution is stable.

Support is helpful.

What needs improvement?

The deployment side is quite complex. We'd like them to simplify the implementation process. I'm not sure whether they can do that, however, they have to be very detailed on configurations, and sharing of the policy. Anybody that configures this box, the WAF, they have to have knowledge of the application and some of the security portions there as well.

For how long have I used the solution?

We've had the solution since last year. We have deployed it to a customer.

What do I think about the stability of the solution?

It is stable. Actually, it evolved from ASM, what they call the Application Security Manager, and now they name it Advanced WAF. It's been around for a while. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

We'll size up based on the customer requirement with some buffer, maybe 20% to 30% for the future extension. There is also some consideration on the capacity planning and the size of the box. You can scale. You just need to plan ahead. 

In terms of users, with Advanced WAF, normally their role is more related to the security side.

We just implemented the solution recently and we'll have to wait another three or four years before we change or upgrade the solution. 

How are customer service and support?

I've dealt with technical support. We're quite satisfied with them. They're good. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

F5 WAF is a web application, in the firewall domain, they have been in the market for a very long time. They know the requirements and the market trends very well. This is the reason why we normally chose F5.

How was the initial setup?

The solution is pretty difficult to set up. You really have to have a grasp o the product to configure it correctly.

The setup takes approximately two months. It's quite a long time. If the application is not ready, then the dependency will be on the application side. Therefore, the cycle is quite long. It depends on the application readiness.

We just need one to two people to handle deployment and maintenance. 

What's my experience with pricing, setup cost, and licensing?

The licensing is charged yearly. It's considered expensive, however, there are more expensive WAFs on the market - like Imperva. F5 is second after Imperva in terms of cost. L1 to L3 support is included in the cost.

I'd rate the price of the solution at a four out of five in terms of how expensive it is.

Which other solutions did I evaluate?

We tend to stay with F5, however, we will look at pricing and try to negotiate based on that. We'd like to get a discount and look at the market to see the costs. 

What other advice do I have?

I'd advise that new users need to know the requirement expectations, and then the criticality of the application that they're going to let the user use. Sometimes the application is public to the internet for a public user to log into and query the database. In that case, we're exposed to all kinds of external parties. So if you put something that is cheap in place, something that is not able to do the protection properly, then it will be a very big risk to the company. 

I'd rate the solution ten out of ten. Our clients have been very happy with it.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
PeerSpot user
Richard Polyak - PeerSpot reviewer
Sr. Architect at NBC Universal
Real User
Jun 27, 2022
Protects our environment and is easy to use and scalable for our needs
Pros and Cons
  • "Identification, ease of use, and ease of modifying it to most of our needs are valuable."
  • "There should be more ability to rate limit certain scenarios. The majority of the time, it is either on or off. For certain types of use cases, there should be the ability to rate limit, not just enable or disable."
  • "There should be more ability to rate limit certain scenarios."

What is our primary use case?

It protects our public entities. Its use case is very directed at a resolution of security.

How has it helped my organization?

It protects our environment. It protects our entities.

What is most valuable?

Identification, ease of use, and ease of modifying it to most of our needs are valuable.

What needs improvement?

There should be more ability to rate limit certain scenarios. The majority of the time, it is either on or off. For certain types of use cases, there should be the ability to rate limit, not just enable or disable.

It is a very CPU-intensive application. I understand why, but I'm hoping that they could optimize the CPU utilization a little bit better.

For how long have I used the solution?

I have been using this solution for eight years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

It is very scalable for what we need. It is a public-facing service. So, everybody on the internet would be able to utilize this type of service.

We are exploring areas to increase its usage.

How are customer service and support?

I would rate them an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used other public entities for similar use cases.

How was the initial setup?

It is pretty straightforward. A typical setup for these types of projects takes three months.

What about the implementation team?

It is all done in-house. We do everything in-house. 

In its maintenance, I and other people are involved. The daily operations, which include modifying policies, are up to the individual application owners because they understand their applications a lot better than I or our standard operating team would. So, their usage might go higher than mine.

What was our ROI?

We have very much seen an ROI. It protects our revenue stream.

What's my experience with pricing, setup cost, and licensing?

The way we deployed it, I would rate it a four out of five in terms of pricing.

What other advice do I have?

I would advise doing your homework. It could be very simplified, or it could be very complex, but definitely, do your homework with the owners of the application because they understand the application more than certain people.

I would rate this solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Richard Polyak - PeerSpot reviewer
Sr. Architect at NBC Universal
Real User
Jun 19, 2022
Easy event identification, highly stable, and customizable
Pros and Cons
  • "The most valuable features of F5 Advanced WAF are the easy identification of events and customization. We can pinpoint our settings."
  • "F5 Advanced WAF has benefited our company by protecting us against revenue loss, preventing hacks that would have taken us offline or caused us a loss of revenue in different areas."
  • "F5 Advanced WAF could improve resource usage, it is CPU intensive. Additionally, adding automated remediation would be a benefit. For example, an easy button alerts us of the events that are occurring, and what we want to do at the time. An automated approach where somebody could be alerted very quickly. Instead of going and reconfiguring everything, an automated approach is what I'm looking at."
  • "F5 Advanced WAF could improve resource usage, it is CPU intensive."

What is our primary use case?

We are using F5 Advanced WAF to protect certain environments. It protects us against everything, such as botnets, web scraping attacks, and foreign entities attacks. It allows us to hone in on exactly the area that we need to focus on. It's a web-based firewall.

How has it helped my organization?

F5 Advanced WAF has benefited our company by protecting us against revenue loss. It's prevented hacks that would have taken us offline or caused us a loss of revenue in different areas.

What is most valuable?

The most valuable features of F5 Advanced WAF are the easy identification of events and customization. We can pinpoint our settings.

What needs improvement?

F5 Advanced WAF could improve resource usage, it is CPU intensive. Additionally, adding automated remediation would be a benefit. For example, an easy button alerts us of the events that are occurring, and what we want to do at the time. An automated approach where somebody could be alerted very quickly. Instead of going and reconfiguring everything, an automated approach is what I'm looking at.

For how long have I used the solution?

I have been using F5 Advanced WAF for approximately five years.

What do I think about the stability of the solution?

We can scale the F5 Advanced WAF very easily. We could configure it to be a canned solution or a customized solution. It goes from canned to full customization to what we need.

What do I think about the scalability of the solution?

After we sized F5 Advanced WAF just right and identified the correct way to configure it, it's very stable.

The solution is not being extensively used.

Which solution did I use previously and why did I switch?

We have used other solutions previously and in parallel.

How was the initial setup?

Generally, F5 Advanced WAF initial setup is straightforward. However, our environment was more complex and it took us a little more time to customize the solution to where we needed it to be. Additionally, the customization didn't rectify everything. We had to do customization to a certain event to prevent attacks that it wasn't catching, but that might not necessarily be the solutions' fault. It could be more of our setup than the solution's fault and not being able to run the latest version or the newer version could be more of a limitation on our ability to put it in the right place.

The whole implementation to have the solution run at the level we wanted it to take approximately five months.

Our company's environment is one that we can't put a canned solution in front of. Our environment, cannot have a canned solution that might fit everybody else because of how customized this environment is. It does need a lot of tuning to meet our environment's requirements.

I rate the initial setup of F5 Advanced WAF a three out of five.

What about the implementation team?

We did the implementation of this solution in-house. We have a very small group that is managing it. However, because it's for external users it's not a company use solution. Managing it, it's a very small subset of users that will manage the solution and the environment behind it. It is for external customers only.

What was our ROI?

We have received a return on investment by using F5 Advanced WAF which has saved us from losing revenue.

I rate the return of investment from F5 Advanced WAF a four out of five.

What other advice do I have?

My advice to others would be to define the parameters well in the beginning, and then they will be fine. They could define it as a regular canned solution and go from there, instead of working it as not a canned solution. Define the environment and what you need to protect, that way you can build a base protection profile that you could deploy elsewhere instead of building the policy to the environment first because then customizing cannot be deployed easily.

I rate F5 Advanced WAF an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
SamerHamadeh - PeerSpot reviewer
System Engineer at DShield
Reseller
Apr 30, 2024
A cost-effective solution for load balancing with data loss prevention
Pros and Cons
  • "It protects and mitigates damage in the network."
  • "They should work on the virtualization of NGINX."

What is our primary use case?

We use the solution for load balancing.

What needs improvement?

They should improve the capability, and then they should work on the virtualization of NGINX. Currently, most environments are virtualized. F5 Advanced WAF will not be able to protect it.

For how long have I used the solution?

I have been using F5 Advanced WAF as a reseller for 5 years.

How are customer service and support?

Technical support is good but not enough. It takes a lot of time to get support.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is not so easy nor not so complex. There is a learning phase, and there are policies to apply. It complies with regulations. Recently, we used it for Formula One, and it proved very effective.

What was our ROI?

ROI is covered in one year. You can see how it protects and mitigates damages in the network.

What's my experience with pricing, setup cost, and licensing?

The product is not so expensive. It depends on the assets.

What other advice do I have?

There are other solutions for data loss prevention, such as Symantec and IP solutions. There are options available for DNS blocking. While these solutions may specialize in certain aspects, They offer comprehensive coverage across various areas. Each vendor specializes in different aspects, but F5 Advanced WAF excels in its particular domain.

I recommend the solution. Most of the environment is going to virtualization.

Overall, I rate the solution an 8 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
Bonieber  Orofeo - PeerSpot reviewer
IT Manager at Chong Hua Hospital
Real User
Top 5
Feb 17, 2023
High availability, many features, and scales well
Pros and Cons
  • "The most valuable features of F5 Advanced WAF are the overall capabilities, there is not a comparable solution on the market."
  • "F5 Advanced WAF could improve the reporting. It's a bit difficult to populate, them. If you're not so familiar with the functions, such as where to find the logs and other settings."

What is our primary use case?

We are using F5 Advanced WAF for the applications that we are publishing mainly for intrusion prevention and proxy features.

What is most valuable?

The most valuable features of F5 Advanced WAF are the overall capabilities, there is not a comparable solution on the market.

What needs improvement?

F5 Advanced WAF could improve the reporting. It's a bit difficult to populate, them. If you're not so familiar with the functions, such as where to find the logs and other settings.

In a future release, it would be beneficial to have a DNS boost feature.

For how long have I used the solution?

I have been using F5 Advanced WAF for approximately five years.

What do I think about the stability of the solution?

I rate the stability of F5 Advanced WAF a ten out of ten.

What do I think about the scalability of the solution?

We have approximately 300 users using this solution in my organization.

I rate the scalability of F5 Advanced WAF a nine out of ten.

Which solution did I use previously and why did I switch?

I was previously using NGINX App Protect and we switched to F5 Advanced WAF because the GUI was better.

How was the initial setup?

The full implementation of the solution took approximately eight hours. There are sections of the configuration at can be difficult.

What about the implementation team?

We used a third party to do the implementation.

What other advice do I have?

I rate F5 Advanced WAF an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free F5 Advanced WAF Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2026
Buyer's Guide
Download our free F5 Advanced WAF Report and get advice and tips from experienced pros sharing their opinions.