The product is used as a web application firewall for Layer 7, Layer 3, and Layer 4 DDoS protection. It is also used for caching, acceleration, and faster delivery.
Security Engineer at Amazon
A stable and easy-to-use solution that can be used for caching and faster delivery
Pros and Cons
- "The product has a good UI."
- "The performance of the cloud monitoring tool is low."
What is our primary use case?
What is most valuable?
The product has a good UI. It is an easy-to-use solution.
What needs improvement?
The solution should improve the monitoring tool a little bit. The performance of the cloud monitoring tool is low.
For how long have I used the solution?
I have been using the solution for five years.
Buyer's Guide
Akamai App and API Protector
November 2024
Learn what your peers think about Akamai App and API Protector. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
More than 100 people are using the solution in my organization.
How was the initial setup?
The solution is easy to implement because Akamai provides support.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive.
What other advice do I have?
People should definitely use the product. Most of the time, it will fulfill our requirements. The tool has many customers. The tool requires a lot of tuning. Overall, I rate the product an eight out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CTO at a tech services company with 10,001+ employees
Enables us to move faster with new products because we have this layer of protection set up in our infrastructure
Pros and Cons
- "It enables us to move faster with new products because we have this layer of protection set up in our infrastructure."
- "The WAF features definitely have a lot of room for improvement. A lot of the WAF is really basic. For some products or some of our solutions, we need to run a second layer of more advanced WAF. If it had better layer seven protection then we would not need a second WAF."
What is our primary use case?
We're using it as DDoS on a basic WAF. We use a hybrid cloud deployment model.
How has it helped my organization?
It enables us to move faster with new products because we have this layer of protection set up in our infrastructure.
It saves time and gives us a consistent way to export those services.
What is most valuable?
It's a SaaS solution and so it's scalable outside of our infrastructure. That's the most valuable thing for us.
What needs improvement?
The WAF features definitely have a lot of room for improvement. A lot of the WAF is really basic. For some products or some of our solutions, we need to run a second layer of more advanced WAF. If it had better layer seven protection then we would not need a second WAF.
We use Akamai because it's good at what it does. There are some other things that we would like it to be good at and it's not that good. Quality of protection is our primary concern.
We need more advanced layer seven protection, SQL injection, applied scripting, and more confidence in the precision of the system. I think all of those things would be very useful for us.
For how long have I used the solution?
We've been using this solution for about five years.
What do I think about the stability of the solution?
It's fairly stable. We're happy with the stability of the product.
What do I think about the scalability of the solution?
It's being used fairly extensively, any new internet-facing applications are going through Akamai Kona. Whether we extend the usage really depends on whether it's going to meet some of the quality objectives with web application firewalls.
How was the initial setup?
The initial setup was straightforward. It has an API. We haven't hit any kinks that we couldn't work with it.
What other advice do I have?
As far as DDoS protection is concerned, I'm firmly in the Akamai Kona box.
In terms of consistency, I think people should consider API-based adoption for Kona configuration. That gives us a broader state which looks and feels the same, and a small team can support it rather than needing a large team to support it.
For what it does, it's really good. For what we want it to do, there's room for improvement. I'd give it an eight and a half out of ten. In order for it to be a 10 I would say that it should be one of the market-leading WAF solutions and not just a volumetric solution.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Akamai App and API Protector
November 2024
Learn what your peers think about Akamai App and API Protector. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
Senior Security Engineer at a comms service provider with 10,001+ employees
A highly-scalable defense service with a valuable custom rules feature
Pros and Cons
- "The most valuable feature is the custom rules feature. This is because many of our customers require a lot of custom rules. Because it's a very customized project for our customers, I think they have the best of everything already."
- "They are already very flexible, but room for improvement is there. Reports generation could be better and should be improved."
What is our primary use case?
I provide a service. We manage the Akamai service for our customers. Our customers are predominantly government agencies and medium-sized companies, and banks.
What is most valuable?
The most valuable feature is the custom rules feature. This is because many of our customers require a lot of custom rules. Because it's a very customized project for our customers, I think they have the best of everything already.
What needs improvement?
They are already very flexible, but room for improvement is there. Reports generation could be better and should be improved.
For how long have I used the solution?
I have been using Akamai Kona Site Defender for two to three years.
What do I think about the stability of the solution?
Akamai Kona Site Defender is quite stable.
What do I think about the scalability of the solution?
Akamai Kona Site Defender is scalable. They offer the most scalability in the marketplace, and there's no problem with scalability.
How are customer service and support?
The guys at technical support are very technical, and then they're quite flexible. They are quite helpful to our customers.
How was the initial setup?
Because our customers are big companies, we would do all the initial setup. It's not complicated because we have standards, best practices, and policies. It's not complicated, and we make it simple for our customers.
What's my experience with pricing, setup cost, and licensing?
The price they are offering is quite reasonable for premium customers, but it's very expensive if you're a small and medium-sized enterprises.
Which other solutions did I evaluate?
I prefer Akamai Kona Site Defender to other competing products. We are working with several vendors, and vendors need to be open and accept criticism. Akamai is one of the good ones that accepts criticism, and they are open about it.
What other advice do I have?
I would advise potential customers to make sure that it's a medium or big company. It's not suitable for small companies.
On a scale from one to ten, I would rate Akamai Kona Site Defender above eight.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Chief Technologist at a financial services firm with 11-50 employees
Effective, feature-rich, and reliable, but they don't provide a free tier like Cloudflare
Pros and Cons
- "They have a fantastic tool for analyzing and viewing your traffic."
- "It's fine for a simple tool, but as I recall, if you encounter a lot of bots, scrapers, and other things, you'll need this tool bot and this other thing they offer called Bot Manager."
What is our primary use case?
We use Akamai Web Application Protector to block IP addresses and countries. If for example, you don't want users from Amazon AWS, you could configure it to block them.
It also has safeguards against common attacks like SQL injection. It does support some advanced custom rules, but you'll need someone from Akamai to code them. That isn't very user-friendly.
What is most valuable?
They have a fantastic tool for analyzing and viewing your traffic. You could look for traffic spikes. You could search for spikes by IP address. You could examine traffic by IP address to see if there are any spikes from a particular IP address.
It is an expensive service with many features. It's difficult, I suppose, to summarise it so quickly. However, it is relatively simple to locate and block IP addresses.
What needs improvement?
The custom rules were difficult to use. Overall, it works well. I don't have many complaints about it. Because it's a lower-end tool, it's not very good at dealing with bots and requires the use of a Bot Manager.
It's fine for a simple tool, but as I recall, if you encounter a lot of bots, scrapers, and other things, you'll need this tool bot and this other thing they offer called Bot Manager.
For how long have I used the solution?
We have been working with Akamai Web Application Protector for two years.
It's been managed for us. As far as I'm aware, everything is managed in their cloud.
What do I think about the stability of the solution?
Akamai Web Application Protector is exceptionally stable; after all, it is Akami.
It is effective. It works when it works. They have very nice traffic analysis where you can really slice and dice and get down to the nitty-gritty. And, they have rules that you can set up to block certain things. I haven't looked at this thing in a long time, and I see they've changed it.
What do I think about the scalability of the solution?
Akamai sees one-third of all web traffic. In terms of scalability, it can be scaled to any size you want.
I am confident that it can handle all of your traffic and then some.
How are customer service and support?
In general, technical support is good. It's gotten better, in my opinion, since the beginning.
Since about two years ago. Everything is fine. I have a dedicated person. I'm not sure how other customers handle things. The thing about Akamai is that they are Enterprise. It's high touch. They charge a lot of money. They provide high-touch support, you will be assigned a dedicated team, and hopefully, it's a strong team.
Unlike Cloudflare, when I looked at their offerings, Cloudflare provides a free tier. Akamai doesn't have a free tier; you can visit their website for free, but that's about it.
What's my experience with pricing, setup cost, and licensing?
Cost depends on the volume of traffic. I'm not even going to give you a number because everything is priced individually for you, the customer, based on traffic.
It's a four out of five. It works, it's a little pricey in my opinion, but overall, I'd give it a four. The device works.
What other advice do I have?
I would rate Akamai Web Application Protector a seven out of ten. It does a lot, and for what it does, it works; for what it doesn't do, a Bot Manager is required.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Information at a leisure / travel company with 51-200 employees
Great technical support, scales extremely well, and is very stable
Pros and Cons
- "The solution can scale extremely well."
- "The pricing could be reduced a bit."
What is our primary use case?
We primarily use the solution as an application firewall.
What is most valuable?
If you compare it to other products in the market, it's quite holistic in terms of the features that it provides.
Technical support has been very helpful and responsive.
The solution can scale extremely well.
The product has proven to be quite stable.
What needs improvement?
The product really isn't very user-friendly. They could improve it so that it's easier for their customers to navigate and use. From a management perspective, it's difficult. Managing these rules with the product isn't easy. It is not taking into account that this might be used by somebody who doesn't necessarily excel in IT. It should be more accessible to everyday users. For example, report generation should be much simpler to handle. It shouldn't be a complex task.
The pricing could be reduced a bit.
They should provide an image optimizer and have it included within the package due to the fact that ultimately all websites that have high content are looking for this.
For how long have I used the solution?
I've been using the product for two years at this point. It hasn't been too long.
What do I think about the stability of the solution?
The stability is excellent. We haven't had any issues with bugs or glitches. It doesn't crash or freeze. Its performance is reliable.
What do I think about the scalability of the solution?
The solution can scale extremely well. That's not a problem at all. If a company would like to expand the solution, it can do so with relative ease.
How are customer service and technical support?
Technical support has been great so far. They are knowledgeable and responsive. We're satisfied with the level of assistance we receive from them. I have no complaints.
Which solution did I use previously and why did I switch?
I'm currently also using AWS products.
How was the initial setup?
The initial setup took us a bit of time to execute. It's got a moderate amount of complexity. It's not hard, however, it's not exactly straightforward either.
What's my experience with pricing, setup cost, and licensing?
The pricing isn't the highest, however, it's not the lowest either. They could adjust it so that it was a bit more affordable. It would be appreciated by the customers.
It's expensive, however, if you compare it to AWS, you'll get different services that you'll have to collaboratively pick in order to get the same solution that Akamai provides to you in one package.
What other advice do I have?
We are just customers and end-users. We don't have a business relationship with the company.
I would recommend the solution. It depends on what the organization wants, however. If you're going for cost optimization or whether you are looking for a through and through security feature, it might vary in its acceptability. It depends on what exactly you want and your company's priority. However, overall, it's a good product.
In general, I would rate the solution at an eight out of ten. We've mostly been quite satisfied with it.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Co-Founder and CEO at PT Eugenea Kreasi Utama
Powerful and feature-rich, but the technical support is slow to respond
Pros and Cons
- "The features are powerful and better than F5."
- "Support and the pricing need to improve."
What is our primary use case?
We use Akamai Kona for our cloud services.
What is most valuable?
The features are powerful and better than F5. I would rate the features a nine out of ten.
What needs improvement?
Support and the pricing need to improve. I would rate this area a six out of ten.
For how long have I used the solution?
How are customer service and support?
Technical support is very slow to respond.
Which solution did I use previously and why did I switch?
Previously, we were not using any other solution.
What's my experience with pricing, setup cost, and licensing?
Akamai is very expensive. It is more expensive than F5.
What other advice do I have?
I would rate Akami Kona Site Defender a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Cloud Security & DevSecOps at a financial services firm with 11-50 employees
A fully managed DDoS solution with good technical support
Pros and Cons
- "The most valuable feature is the DDoS protection, which is the main reason we got it."
- "The interface is a little bit clunky and can be improved."
What is our primary use case?
We use this solution primarily to prevent DDoS attacks.
What is most valuable?
The most valuable feature is the DDoS protection, which is the main reason we got it.
What needs improvement?
The interface is a little bit clunky and can be improved. It takes a while to get from here to there.
For how long have I used the solution?
I have been using Akamai Kona Site Defender for two years.
What do I think about the stability of the solution?
This solution is stable and we haven't seen any problems at all. It's been a very simple service to use, so far.
What do I think about the scalability of the solution?
Being a cloud-based service, it scales up and down as per your needs.
We have between 10 and 20 users, who are engineers and integrators, and we are satisfied with it.
How are customer service and technical support?
I have been in touch with technical support and I don't have any complaints. It is a good service.
Which solution did I use previously and why did I switch?
We did not use another DDoS solution prior to this one.
How was the initial setup?
This solution is fully managed by the vendor so it is smooth sailing. They handle everything including the initial setup. There is no staff required for deployment or maintenance on my end.
Which other solutions did I evaluate?
We did not evaluate other options before choosing this solution.
What other advice do I have?
My advice for anybody who is evaluating this solution is to first evaluate your needs, and then check to see how much you need to put into this solution.
The biggest lesson that I have learned from using Site Defender is that you should do an analysis first, to see how it will fit into your ecosystem. You decide whether to buy it based on that, rather than because it is a good product. You have to make sure that it is compatible with your environment.
Overall, I am happy with Site Defender because what it's doing, it's doing well. I can't think of a single feature that might be missing.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solutions Architect, Cloud & SDDC at a computer software company with 5,001-10,000 employees
CDN and WAF features are an essential element with APIs a key element of the infrastructure
Pros and Cons
- "The CDN and the WAF features are the best."
- "Could integrate more features for each security."
What is our primary use case?
We have multiple use cases but the solution is primarily for content delivery network. The product has multiple features so we area also using it as a wall. It's really a combination between a CDN and a WAF. We also use Adidol switches. We are partners with Akamai and I'm a cloud solution architect.
How has it helped my organization?
The solution is very open because it's for public cloud and the interface is also very open. It's equal to having things like infrastructure as code to be defined, as well as having the ability to configure additional interfaces that we need for a service.
What is most valuable?
The CDN and the WAF features are the best in this solution.
What needs improvement?
I think there could be an improvement with the integration of more features for each security. Possibly inline IPS and more granularity for configuration.
I'd like to see incremental or integrated security features or maybe even for our transit anti-malware. It goes hand in hand with things like DLP.
For how long have I used the solution?
I've been using this solution for two years.
What do I think about the stability of the solution?
The solution has been very reliable.
What do I think about the scalability of the solution?
As a software it is very scalable. We don't have a problem with scaling the product or scaling the capabilities. This is more of an enterprise construct, so we provide it as a service which means there are not many users, everything is defined as code. For anything that requires a CDN, we'll use this construct and it will scale according to the enterprise.
How are customer service and technical support?
The technical support is above average and good.
How was the initial setup?
The initial setup was quite simple. It took between two to four weeks because it was quite a large deployment. Our strategy was to first implement a baseline and then to incrementally add any requirements for certain applications. We have a partnership with professional services from Aster Mind, as well as our own service integration services, to perform the setup. We had two staff members involved in deployment and they assist with maintenance.
What other advice do I have?
Programmability in the cloud is very important. So whatever we can program by APIs and define by API is very important in the infrastructure.
I would rate this solution an eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Akamai App and API Protector Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Web Application Firewall (WAF) Distributed Denial of Service (DDOS) Protection Cloud and Data Center SecurityPopular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
F5 Advanced WAF
Fortinet FortiWeb
Imperva Web Application Firewall
Cloudflare Web Application Firewall
Imperva DDoS
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
F5 Silverline Managed Services
Buyer's Guide
Download our free Akamai App and API Protector Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Can you share your experience on migration from Akamai Kona Site to Amazon CloudFront and AWS WAF?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?