In the past three years, I implemented Advanced Firewall Manager to safeguard our clients' DNS solutions and protect applications from DDoS and BPOS attacks. This involved securing DNS queries and ensuring resilience against various cyber threats.
Director Comercial at a consultancy with 11-50 employees
Ensures service availability and safeguards against infrastructure and application-level threats
Pros and Cons
- "It excels in preventing downtime and maintaining application performance, which is crucial for our clients' security and operational continuity."
- "There is room for improvement in Advanced Firewall Manager's dashboard statistics, especially during attacks."
What is our primary use case?
What is most valuable?
The most valuable features of Advanced Firewall Manager are its effectiveness in protecting applications from DDoS attacks, ensuring service availability, and safeguarding against infrastructure and application-level threats. It excels in preventing downtime and maintaining application performance, which is crucial for our clients' security and operational continuity.
What needs improvement?
There is room for improvement in Advanced Firewall Manager's dashboard statistics, especially during attacks. Enhancements in graphical representation and more detailed reports would be beneficial for a more comprehensive understanding of the security landscape.
For how long have I used the solution?
I have been using Advanced Firewall Manager for seven years.
Buyer's Guide
F5 BIG-IP Advanced Firewall Manager (AFM)
February 2026
Learn what your peers think about F5 BIG-IP Advanced Firewall Manager (AFM). Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,757 professionals have used our research since 2012.
What do I think about the stability of the solution?
In terms of stability, Advanced Firewall Manager performs well. Logging is straightforward, allowing for easy analysis and integration with other solutions. It provides detailed logs during attacks, facilitates in-depth review, and supports integration with SNMP for added insights into security events.
What do I think about the scalability of the solution?
Advanced Firewall Manager scales well with a flexible SKN architecture, allowing easy capacity and high availability expansion. This scalability extends to hybrid setups, enabling consistent policies and configurations across on-premise and cloud environments through the BigIQ solution. It ensures seamless synchronization for efficient management.
How are customer service and support?
Contacting F5 support for issues, especially related to traffic, attacks, or platform bugs, is easy and communication is straightforward. However, there is room for improvement in the support team's accuracy, as sometimes their recommendations may not directly address the reported issues, leading to a need for clearer and more relevant guidance. I would rate the support as a seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
The installation could be moderately complex, involving the implementation of new traffic flows and applications into the network for protection. Deployment for Advanced Firewall Manager for one application takes approximately one week. However, the technical configuration itself, focused on proactive platform setup and protection, can typically be accomplished in about a day.
Deploying Advanced Firewall Manager usually involves around five people, covering security, network, application, support, and project teams.
What's my experience with pricing, setup cost, and licensing?
While Advanced Firewall Manager comes with a relatively higher price, it aligns with the platform's benefits, stability, and warranty.
What other advice do I have?
Overall, I would rate F5 BIG-IP Advanced Firewall Manager as an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Head of security of digital systems, electronic databases and networks at a financial services firm with 1,001-5,000 employees
A stable solution that can be used for load balancing and WAF (web application firewall)
Pros and Cons
- "We use the solution for load balancing and WAF (web application firewall)."
- "The solution’s initial setup is not easy."
What is most valuable?
We use the solution for load balancing and WAF (web application firewall).
What needs improvement?
The solution's initial setup is not easy.
For how long have I used the solution?
I have been using F5 BIG-IP Advanced Firewall Manager (AFM) for three years.
What do I think about the stability of the solution?
F5 BIG-IP Advanced Firewall Manager is a stable solution.
I rate F5 BIG-IP Advanced Firewall Manager a nine out of ten for stability.
What do I think about the scalability of the solution?
F5 BIG-IP Advanced Firewall Manager is a scalable solution. Two administrators from IT use the solution for load balancing, and two administrators from security use it for WAF.
Which solution did I use previously and why did I switch?
We previously used Arbor and Radware.
What about the implementation team?
We implemented the solution through a consultant.
For our services, the solution took nearly three months to deploy.
What's my experience with pricing, setup cost, and licensing?
We need to pay a yearly licensing fee for the solution.
What other advice do I have?
I would recommend F5 BIG-IP Advanced Firewall Manager to other users.
Overall, I rate F5 BIG-IP Advanced Firewall Manager a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
F5 BIG-IP Advanced Firewall Manager (AFM)
February 2026
Learn what your peers think about F5 BIG-IP Advanced Firewall Manager (AFM). Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,757 professionals have used our research since 2012.
Sr. Architect at a media company with 10,001+ employees
Easy to use, good performance, and capable of processing a large load of traffic
Pros and Cons
- "Its performance and ease of use are valuable."
- "There should be simplified and better integration with BIG-IQ."
What is our primary use case?
We use these as our data center firewalls. At the time of our analysis of the systems, they were the ones able to process the large load of traffic that we needed over any other systems out there. So, capacity-wise, these were able to address our needs.
We have version 12, version 13, version 14, and version 15.
How has it helped my organization?
We're a media company, and it provides security around very sensitive content. It provides security for content before being released.
What is most valuable?
Its performance and ease of use are valuable.
What needs improvement?
There should be simplified and better integration with BIG-IQ. There should also be a more modular approach. I believe they are working on it, and it is just a matter of deployment.
For how long have I used the solution?
I have been using this solution for eight years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable. There are 20,000 to 30,000 people who use it on a daily basis. Their roles vary from content editors to content viewers at different levels of the organization. Its usage might increase.
How are customer service and support?
I would rate them a four out of five.
Which solution did I use previously and why did I switch?
We have got different products. We have got different vendors for firewalls. We have Palo Alto, Juniper, Cisco, etc.
How was the initial setup?
It is pretty straightforward. The duration depends on our typical deployment scenarios. Usually, it takes about three months from the time our projects are fully approved and all the way down to deployment. So, from initial installation to releasing the production, our deployment scenarios take three months.
Its maintenance is easy and simple. For maintenance, we need a staff of one.
What about the implementation team?
It was implemented in-house. For deployment, we have different teams and levels, and they could be a team of five. We have another team for the day-to-day operations, and they could be anywhere from ten people.
What was our ROI?
For our requirements, we have seen an ROI.
Which other solutions did I evaluate?
We did look at different options. At the time we were looking at it, this was the only one that was able to perform at the level of performance required.
What other advice do I have?
I would advise doing your homework. Do your research, and make sure you understand what the product is for so that you do not deploy it where it will not fit your needs. This is not a next-gen firewall. It is not meant to compete against next-gen firewalls. It is meant primarily for DNS type of things. That doesn't mean it can't do next-gen tasks, but the way I see it and the way I understand it, it is more for data centers.
I would rate it an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network and Security Engineer at a engineering company with 1,001-5,000 employees
Robust security management that's effective and offers valuable security features
Pros and Cons
- "The features of F5 BIG-IP Advanced Firewall Manager that have proven most effective in securing the network are significant."
- "Apart from the price, I feel no other areas need improvement."
What is our primary use case?
The primary use case for F5 BIG-IP Advanced Firewall Manager is in government offices.
What is most valuable?
The features of F5 BIG-IP Advanced Firewall Manager that have proven most effective in securing the network are significant. The user mentioned that these features are valuable in security management, suggesting that they find the product attractive for their needs.
What needs improvement?
I have encountered challenges with the price of the solution. Apart from the price, I feel no other areas need improvement.
For how long have I used the solution?
I have used the solution for two years.
What do I think about the stability of the solution?
I would rate the stability of F5 at eight out of ten.
What do I think about the scalability of the solution?
I would rate the scalability of F5 as six out of ten. While there is room for improvement, it somewhat meets the scalability requirements.
How was the initial setup?
The initial setup was easy for me.
What's my experience with pricing, setup cost, and licensing?
The price of the solution presents a challenge.
What other advice do I have?
Based on my experience, I recommend F5 BIG-IP Advanced Firewall Manager to other people.
I would rate this solution overall as eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Presales Engineer at a tech services company with 11-50 employees
Reliable and straightforward to set up but has confusing logic
Pros and Cons
- "The protection is very useful."
- "For configuring the firewall, every single vendor on the planet has pretty much the same logic when it comes to firewalls, and F5 has a completely different approach and completely different behavior."
What is our primary use case?
We primarily use the solution as a data center firewall.
How has it helped my organization?
It offers a border between the DMZ, the demilitarized zone, and the rest of the data center. We already have an F5 solution over there with some other models included. This additional model is something extra that can make a difference in security protection.
What is most valuable?
The protection is very useful.
The solution is stable.
Once you understand the logic, it's straightforward to set up.
What needs improvement?
We seem to have confusing logic from the solution itself. This needs to be addressed.
For configuring the firewall, every single vendor on the planet has pretty much the same logic when it comes to firewalls, and F5 has a completely different approach and completely different behavior. When you first encounter the AFM, it can be really complicated to understand and find a way how to achieve the desired configuration. It's not logical. It's completely different than any other solution. In the end, it gives you similar results - just in a much more complicated way.
Technical support could be better.
For how long have I used the solution?
I've been using the solution for the last three years.
What do I think about the stability of the solution?
The solution is really stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability and cost-effectiveness of the solution is really good. Hardware appliances can forward some crazy amounts of traffic. However, this is not like all other firewalls. Scalability is pretty much somewhere in the middle. You always have some additional models on the same hardware or even in virtual machines. In general, it's not good, and it's not bad. You need to take everything into account.
How are customer service and support?
Technical support is not that great.
The solution itself works perfectly. That said, if there is an issue and when you open the ticket, nobody picks up the ticket for ages. It can be a problem.
How would you rate customer service and support?
Negative
How was the initial setup?
The initial setup is illogical, which makes it difficult.
Basically, as a user, you are expecting something, it's not easy to achieve that since logic is way, way different than any other firewall. That's the only reason why it can be hard to configure. Once you understand how the solution is processing the traffic, it becomes extremely easy.
The deployment only takes four days.
I didn't have any cases where the AFM was the only module or where we started deployment of the solution from scratch. We always used it as an additional service on an existing platform. Therefore, you have F5 already deployed with, let's say, Access Policy Manager or maybe an advanced firewall verification firewall; that's an extra service where we are enabling one more functionality regarding that AFM.
The first step is configuring the virtual service that moves the traffic and configuring the policies, rate limits, protection, and similar things. After that, we validate the configuration and eventually fine-tune everything before putting it into production.
The deployment pretty can be done by one man, no more than that. It's not that complex of a solution. It's a basic layer for the firewall and nothing more than that. In the cases where you have 3,000 policies, that could be time-consuming; however, in the end, one person can do it without any issues.
It requires, not maintenance in general terms, where you have something to patch or something to do with that. However, if change requests are considered, every now and then, you will have to allow some different things and maybe reconfigure some existing policies to include something that was not included or needed before. That's common practice.
In most cases, after that initial deployment and knowledge transfer, the customer itself is able to manage the solution.
What was our ROI?
When you are using it with another solution from F5, it's an excellent addition, and you get a lot of discounts, so it's affordable. In that case, the ROI is really nice. However, if you are using it as a standalone solution, I don't even know if that's comparable to other vendors or not. The ROI might be slightly below average. In that case, I'd rate the ROI at four out of ten.
What's my experience with pricing, setup cost, and licensing?
The pricing is somewhere in the middle. It was not expensive and not cheap.
The license itself is perpetual. Or you can get subscriptions. However, it is more than likely to be perpetual since you don't need any live feeds.
You can get separate subscriptions for threat intelligence, IP intelligence, and geolocation, yet you don't need any kind of subscription for the firewall itself.
Support is also an additional expense.
What other advice do I have?
We're resellers. We're using the latest version of the solution.
Chances are, as a standalone product, you can find a better firewall at the same price.
It's limited with functionalities, so there is nothing really nice about AFM except that if you already have an F5 stack of solutions on hardware or on virtual infrastructure, and you are adding this license, in that case, it makes sense. Any other case doesn't simply work. That doesn't make sense.
I'd rate the product five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Head: Cyber and Information Research Centre at a educational organization with 1,001-5,000 employees
Responsive support, beneficial load balancing, but web gateway could improve
Pros and Cons
- "The most valuable features of F5 BIG-IP Advanced Firewall Manager (AFM) are the web gateway, load balancing, services, and applications available."
- "The web gateway feature could improve in F5 BIG-IP Advanced Firewall Manager (AFM)."
What is our primary use case?
I am using F5 BIG-IP Advanced Firewall Manager (AFM) for load balancing and an IP gateway.
What is most valuable?
The most valuable features of F5 BIG-IP Advanced Firewall Manager (AFM) are the web gateway, load balancing, services, and applications available.
What needs improvement?
The web gateway feature could improve in F5 BIG-IP Advanced Firewall Manager (AFM).
In the next release, the automation and AI aspect are very important nowadays, particularly from the incident point of view. I know they've added automation and AI in the recent update, but it could improve. The solution comes with devices and is more device-based, but it could be beneficial to have a software-defined load balancer. If there were less hardware it would save on costs.
For how long have I used the solution?
I have been using F5 BIG-IP Advanced Firewall Manager (AFM) for approximately five years.
What do I think about the stability of the solution?
F5 BIG-IP Advanced Firewall Manager (AFM) is a stable solution. I have not had many issues.
What do I think about the scalability of the solution?
The solution is scalable, but there are costs involved.
We have approximately 10,000 users using the solution. The solution is being used daily.
How are customer service and support?
I rate the technical support of F5 BIG-IP Advanced Firewall Manager (AFM) a four out of five.
They're responsive and have always have pointed helped out when we had issues.
How was the initial setup?
The initial setup of the F5 BIG-IP Advanced Firewall Manager (AFM) is of a medium level of difficulty. There are technical elements that are required to set it up.
What about the implementation team?
We used the vendor to help us do the implementation.
What's my experience with pricing, setup cost, and licensing?
F5 BIG-IP Advanced Firewall Manager (AFM) is an expensive solution. They are one of the best in the market, but the price could be cheaper.
I rate the price of F5 BIG-IP Advanced Firewall Manager (AFM) a three out of five.
Which other solutions did I evaluate?
There are competing solutions in the market. In terms of what F5 BIG-IP Advanced Firewall Manager (AFM) offers, from the load balancing point of view, I think they are one of the best. When it comes to firewalls and other solutions, there are better ones, such as FortiGate, Cisco, or Huawei. As a firewall, they are not the best. However, for load balancing, they're the best.
What other advice do I have?
F5 BIG-IP Advanced Firewall Manager (AFM) is a popular big brand name behind it. However, it is expensive. Everything that is being used by large corporations is going to have a high cost.
I rate F5 BIG-IP Advanced Firewall Manager (AFM) a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Infrastructure Engineer at a educational organization with 1,001-5,000 employees
Good support and security but is a bit expensive
Pros and Cons
- "It is stable."
- "Some spam can go by the firewall."
What is our primary use case?
We primarily use the solution as a firewall.
We use it to block or allow traffic inside the infrastructure.
Usually, if we want to tie it up to another service, we usually use AFM. The reason we use AFM is due to the fact that we have Anti-DDoS equipment and the components in order to mitigate those attacks, we use a combination of AFM, ATM, and GTM.
How has it helped my organization?
It's deployed in order to allow or deny traffic for us. It controls the flow and acts as a layer of security. It also is able to handle routing.
What is most valuable?
The security is quite good. It allows us to block certain addresses.
It is stable.
Support is quite helpful.
We have witnessed an ROI.
What needs improvement?
Some spam can go by the firewall. The processing is a bit slow, and spam can get by.
We'd like to be able to do a deep packet inspection. We haven't enabled that. Hopefully, the next-generation firewalls will be able to do that for us.
The solution is a bit pricey.
For how long have I used the solution?
I've used the solution for around four years. It's been a while.
What do I think about the stability of the solution?
The stability is okay. I'd rate it seven out of ten overall.
What do I think about the scalability of the solution?
The scalability would be based more on the hardware aspect. I'd rate its ability to scale at a six or seven out of ten, since it is rather fixed. It's still hardware and not fully virtualized, which makes scaling limited.
How are customer service and support?
Technical support is pretty good. I do find them to be mostly helpful and responsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have also used Check Point in the past. I've also used a few other firewalls as well.
How was the initial setup?
I wasn't directly involved in the initial setup. When I arrived at the company, I was more on the operations side of things.
What was our ROI?
We have witnessed an ROI while using the product.
What's my experience with pricing, setup cost, and licensing?
The solution is a bit expensive. I'd rate pricing four out of ten in terms of affordability.
What other advice do I have?
Companies should implement the solution if they have the budget. If you're going to deploy a security firewall device, this is a helpful solution.
I'd rate the solution seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Executive of the Telecommunications Area at a financial services firm with 501-1,000 employees
Top level support, scalable, and reliable
Pros and Cons
- "The most valuable feature of F5 BIG-IP AFM is all of my workers enjoy using it."
- "The initial setup of F5 BIG-IP AFM in a complex environment was simple. However, the full deployment took us approximately one year."
What is our primary use case?
F5 BIG-IP AFM is deployed on-premise and in the cloud.
We are using F5 BIG-IP AFM mostly for financial services.
How has it helped my organization?
F5 BIG-IP AFM has improved the way our organization functions.
What is most valuable?
The most valuable feature of F5 BIG-IP AFM is all of my workers enjoy using it.
For how long have I used the solution?
I have been using F5 BIG-IP Advanced Firewall Manager (AFM) for approximately 11 years.
What do I think about the stability of the solution?
F5 BIG-IP AFM is very good.
What do I think about the scalability of the solution?
The scalability of F5 BIG-IP AFM has been very good.
We have approximately 3,000 users using this solution in my company. If we have another system we will increase our usage.
How are customer service and support?
The support that we receive from the F5 BIG-IP AFM has been very valuable.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used Cisco solutions and I switched to F5 BIG-IP AFM because of the superior support.
How was the initial setup?
The initial setup of F5 BIG-IP AFM in a complex environment was simple. However, the full deployment took us approximately one year.
What about the implementation team?
We did the implementation of F5 BIG-IP AFM in-house.
We have seven people that are maintaining F5 BIG-IP AFM.
What's my experience with pricing, setup cost, and licensing?
F5 BIG-IP AFM is an affordable solution. There were not any additional fees other than the standard licensing.
What other advice do I have?
I rate F5 BIG-IP AFM a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free F5 BIG-IP Advanced Firewall Manager (AFM) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Distributed Denial-of-Service (DDoS) ProtectionPopular Comparisons
Imperva Application Security Platform
Akamai App and API Protector
A10 Thunder TPS
Buyer's Guide
Download our free F5 BIG-IP Advanced Firewall Manager (AFM) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- We are looking at managed DNS providers and want to know what others are using
- Prolexic vs. Arbor Networks: How do they compare?
- How does a WAF help to protect against DDoS attacks?
- Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
- DDoS solutions: Any other solutions to consider aside from Radware DDoS Protection Service and F5 Silverline DDoS Protection?
- Which is the best DDoS solution and why?
- When evaluating DDoS Protection, what aspect do you think is the most important to look for?
- What is the difference between denial of service and distributed denial of service?
- How does BGP routing help to mitigate DDoS attacks?
- How does a CDN protect against DDoS attacks?













