The most valuable feature is the grouping of multiple targets via the scan policy. It is valuable because of the large number of targets and governmental requirements to conduct periodic scans.
Sr. Consultant at a tech services company with 51-200 employees
Scan policies allow us to group multiple targets and standardize our database scanning. Technical support is probably the biggest drawback.
What is most valuable?
How has it helped my organization?
With acquisition of a license to use the product, we received the ability to standardize database scanning and data protection across the enterprise around one product.
What needs improvement?
Many features are buried under not-straight-forward options and, at times, hard to find screens. Very few import features have clearly defined format requirements. Agent installation for data usage/blocking activities on target boxes requires the involvement of OS admins and DBA’s, which complicates coordination of installation and delays implementation. The discovery feature does not accurately discover the instances and instead identifies auxiliary end points (SQL – 1434) and TCP listeners (Oracle – 1521).
For how long have I used the solution?
I’ve used and administered Imperva SecureSphere for 2 years.
Buyer's Guide
Imperva Web Application Firewall
May 2025

Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.
What do I think about the stability of the solution?
Periodically, the site stops functioning and the appliance requires a reboot to restore functionality.
What do I think about the scalability of the solution?
Scalability capabilities are well thought through by product development. Installation of additional MX servers and gateways on remote networks ensures coverage of scanning and data usage monitoring/data protection capabilities.
How are customer service and support?
Technical support is probably the biggest drawback. No contact with technical support ever results in an immediate response and the solution is usually preceded with series of emails, going on for up to a week, before a live person gets on the phone. But, even then, their task is to observe the manifestation of the problem and request a collection of additional information (logs, traces, etc.) without any attempt to solve the problem during the call/WebEx session. Their technical support staff has at most two or three engineers that have a good working knowledge of the product, but most of the time, a level one technician is running the case. When support staff finally gets on the phone, their first statement is a disclaimer that they are on the call ONLY to collect information and that the customer should not expect any resolution.
This pattern of providing technical support greatly differs from what IBM offers for their Guardium product (competitor solution).
Which solution did I use previously and why did I switch?
We attempted to use several previous solutions. One was Tenable SecurityCenter with its custom, XML-like scripting where each check had to be written by the Database Security Specialist (myself). We also attempted to use AppDetectivePRO, though its performance, lack of customization, scalability, and licensing costs prevented us from continuing with it.
How was the initial setup?
The setup is very straightforward considering that it’s either a physical or virtual (OVF template) appliance. The wizard-like initial setup and configuration are somewhat awkward, but can be completed after reviewing the instructional videos available to the customers.
What's my experience with pricing, setup cost, and licensing?
Licensing should be chosen based on the current infrastructure setup and growth plans. Purchasing appliances of different types may lead to unnecessary/unjustified expenditures and ultimately lead to complications in administration.
Which other solutions did I evaluate?
The product that was evaluated and was chosen as the recommendation was IBM Guardium. Unfortunately, its licensing cost was a lot higher. Therefore, the management decided not to proceed with the purchase.
What other advice do I have?
Be prepared to obtain every piece of documentation that comes with the product. Thoroughly research it to obtain a clear understanding of how to implement the product and ensure you have a dedicated Imperva first-response engineer that can answer your questions without going through a normal support channel. Be patient when encountering a bug or a feature failure, as well as discrepancies between the product interface and/or behavior with the accompanied documentation. Their support is not prepared to jump in and start working on a fix or update the documentation.
In many cases, the documentation remains outdated referring to old releases regardless how long you’ve been asking for an update. Their instructional videos are also out of date, but references to them are consistently sent by their support whenever you may have a question. And finally, thoroughly document your deployment and license-related information, because every email to technical support is responded with an automated reply requesting this information. Not replying to this automated email with correct info will lead to further delays.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Manager, IS Security & Infrastructure at Fintech Kenya Limited
User-friendly with good performance and helps to secure digital assets
Pros and Cons
- "It mitigates all of the availabilities of risks around web applications."
- "Their portal is very limited and needs improvement."
What is our primary use case?
We are a reseller and integration partner, and we have customers who are using this solution in on-premises deployments.
How has it helped my organization?
This solution has helped in securing our clients' assets, which is key. It mitigates all of the availabilities of risks around web applications.
What is most valuable?
The most valuable feature of this solution is web application security.
This is a user-friendly solution.
This solution has good performance ratings.
What needs improvement?
I would like to see more support available for this product online. Some customers find this to be a real limitation.
The virtual processing could be improved.
Their portal is very limited and needs improvement.
For how long have I used the solution?
We have been using this solution for close to five years.
What do I think about the stability of the solution?
This is a very stable solution.
What do I think about the scalability of the solution?
The solution is very scalable, but of course, the scalability comes with a cost.
How are customer service and technical support?
I think that technical support needs to be improved by making it more localized, or regionalized. Our support is currently coming from the US, and it is not very good. They need to take care of their global customers.
Which solution did I use previously and why did I switch?
We previously used Fortinet, but this solution has better performance ratings.
How was the initial setup?
I don't want to say that the initial setup is straightforward, but it is manageable. It requires a bit of technical knowledge.
What other advice do I have?
This is a solution that I highly recommend.
The biggest lesson that I have learned from this solution is that Imperva is not a one-house solution. They create a specialized solution, and that comes with a lot of value.
I would rate this solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Imperva Web Application Firewall
May 2025

Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.
Cyber and Information Security Officer at a energy/utilities company with 10,001+ employees
We can define custom policies, apply real-time changes and granular configuration
Pros and Cons
- "Learning mode and custom policies are helpful features."
- "Very intuitive and granular configuration - It does not require much time, or advanced knowledge, for configuration and maintenance."
- "The reporting is missing some features, such as: only two export formats, and the time period does not include the last day, week, year."
How has it helped my organization?
Protects and secures all our web sites.
What is most valuable?
- Learning mode.
- Custom policies.
- Very intuitive and granular configuration - It does not require much time, or advanced knowledge, for configuration and maintenance.
What needs improvement?
The reporting is missing some features, such as: only two export formats, and the time period does not include the last day, week, year.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
No issues with stability.
What do I think about the scalability of the solution?
No issues with scalability.
How is customer service and technical support?
10 out of 10 for local support, seven out of 10 for Imperva Professional Services.
How was the initial setup?
Straightforward. Easy to install and config.
Which other solutions did I evaluate?
F5.
What other advice do I have?
I rate it a 10 out of 10 because of the ability to apply real-time changes or creations, export and import applications learned, and it's very easy to use. It also features system logs or incidents, granular configuration in relation to a SIEM. It is the best product on the market, in my opinion. Cyber security leader.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technology Operations Manager, Global IT at a tech services company with 11-50 employees
Deploys easily; good, responsive customer service
Pros and Cons
- "I have had a positive experience with Imperva Web Application Firewall's tech support so far. They are knowledgeable and respond on time."
- "The Imperva Web Application Firewall automations are good, but there is still room for improvement with them."
What is our primary use case?
Our primary use case for the solution is securing our applications and customer-facing website.
What is most valuable?
The Imperva Web Application Firewall feature I have found the most valuable is the ease of deployment. The solution's customer service is good as well.
What needs improvement?
The Imperva Web Application Firewall automations are good, but there is still room for improvement with them. Fast rule propagation could also be improved.
For how long have I used the solution?
My company has been using Imperva Web Application Firewall for four years. But, personally, I have been using it for three years. It was already operational in the organization when I joined.
What do I think about the stability of the solution?
We have not had any issues with stability.
What do I think about the scalability of the solution?
I think Imperva Web Application Firewall is scalable.
How are customer service and support?
I have had a positive experience with Imperva Web Application Firewall's tech support so far. They are knowledgeable and respond on time.
How would you rate customer service and support?
Positive
How was the initial setup?
I was not with the company when Imperva Web Application Firewall was initially deployed but I believe the process was straightforward.
Which other solutions did I evaluate?
F5 firewalls are clunky and that is why we do not use them. They are good and powerful, but it takes quite a bit to set them up. They are not as easy to set up as Imperva Web Application Firewall.
What other advice do I have?
I would say: take Imperva Web Application Firewall into consideration because of its simplicity.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Consultant at FPG Technologies and Solutions LTD
Useful database monitoring, simple dashboards, and scalable
Pros and Cons
- "The most valuable features of Imperva Web Application Firewall are the monitoring of databases and the dashboards are easy to understand."
- "Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better."
What is our primary use case?
We are using Imperva Web Application Firewall to monitor databases.
What is most valuable?
The most valuable features of Imperva Web Application Firewall are the monitoring of databases and the dashboards are easy to understand.
What needs improvement?
Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better.
For how long have I used the solution?
I have been using Imperva Web Application Firewall for approximately three months.
What do I think about the stability of the solution?
Imperva Web Application Firewall is stable.
What do I think about the scalability of the solution?
The scalability of the Imperva Web Application Firewall is good.
How was the initial setup?
The initial setup of the Imperva Web Application Firewall is complex.
I rate the initial setup of Imperva Web Application Firewall a four out of five.
What other advice do I have?
I rate Imperva Web Application Firewall a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Systems Analyst at a financial services firm with 501-1,000 employees
An expensive solution that is scalable and stable
Pros and Cons
- "Imperva Web Application Firewall is stable."
- "The tool needs to improve CPU and storage memory."
What needs improvement?
The tool needs to improve CPU and storage memory.
For how long have I used the solution?
I have been using the solution for a year. However, my company has been using it for six years.
What do I think about the stability of the solution?
Imperva Web Application Firewall is stable.
What do I think about the scalability of the solution?
The product is scalable, and my company has 20,000 users. One administrator manages the tool.
What's my experience with pricing, setup cost, and licensing?
Imperva Web Application Firewall is expensive.
What other advice do I have?
I rate the solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CTO at Sorint.Lab
It's easy to use and deploy
Pros and Cons
- "Imperva is easy to use and deploy. The UI is excellent."
- "I'd like the option to pick your bot protection."
What is most valuable?
Imperva is easy to use and deploy. The UI is excellent.
What needs improvement?
I'd like the option to pick your bot protection.
For how long have I used the solution?
I have used Imperva for seven years.
What do I think about the stability of the solution?
Imperva is stability.
What do I think about the scalability of the solution?
Imperva is scalable.
How are customer service and support?
Imperva support is good.
How was the initial setup?
Setting up Imperva is easy, and it takes two days.
What's my experience with pricing, setup cost, and licensing?
The cost is reasonable. W have 50 clients and 10 websites per customer.
What other advice do I have?
I rate Imperva Web Application Firewall nine out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer:
GA Consultant Cyber Security at a tech services company with 51-200 employees
Suits large enterprises, supports different application sources, and provides tight control
Pros and Cons
- "Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva."
- "It should be more user-friendly. Like other web solutions, it would be helpful to be able to easily do policy configuration and identification inside the application. Understanding the in-depth configuration of a policy is somewhat difficult for an engineer, and they can improve that."
What is our primary use case?
We have an Akamai cloud-based solution for it. We have an in-house customer, and they have their own Akamai cloud for WAF. As a solution provider, we are working with their private Akamai WAF.
What is most valuable?
Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva.
It is quite proficient in terms of logs reports, and it provides tight control for policy configuration. So, there can't be any unwanted applications on the internal LAN site. It is quite restrictive, which is a plus point. The sizing of an application is quite easy to understand while we are configuring and deploying Imperva.
What needs improvement?
It should be more user-friendly. Like other web solutions, it would be helpful to be able to easily do policy configuration and identification inside the application. Understanding the in-depth configuration of a policy is somewhat difficult for an engineer, and they can improve that.
For how long have I used the solution?
I have about two to three years of experience with Imperva. I'm working as a GA consultant for cybersecurity and information security. I'm working on different security solutions such as WAF, IAM, DDoS, Azure firewall proxy, and antivirus. I work with different customers, and I also do the architecture review or assessment.
What do I think about the stability of the solution?
Its stability is quite good. It is not at all an issue.
It is also quite good performance-wise. We are confident about its performance.
What do I think about the scalability of the solution?
It is for large-scale enterprises where the traffic is huge, and there are many internet-facing applications, which is a plus point of Imperva.
We don't have the HA mode for the respective solution in Imperva, which has to be there when we have the DC and DR locations. We can activate only one solution at DC, but while we are conducting the drills between DC and DR, it is quite difficult to import all the configurations at the DR location in Imperva. It takes time.
How are customer service and support?
Their support is good. It is not an issue. Whenever we have any questions or concerns, we're getting an appropriate solution for our queries.
Some of the clients have had direct support from Imperva, and some of the clients had a third-party vendor. We also get support from a local Imperva employee. When I was working for a bank, there was good support from this person who was working with Imperva.
How was the initial setup?
The support for the setup is very good from the provider, but it can be difficult for an engineer to have an in-depth understanding of the configuration of a policy for an application.
What other advice do I have?
I would rate it an eight out of 10.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Imperva Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
F5 Advanced WAF
Fortinet FortiWeb
Cloudflare Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Buyer's Guide
Download our free Imperva Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Imperva WAF vs. Barracuda: Which One is Better?
- Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
A much more mature product in this regard is BeyondInsight. Highly customizable and flexible when it comes to scanning.