Try our new research platform with insights from 80,000+ expert users

F5 Advanced WAF vs R&S Web Application Firewall (DenyAll) comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
72
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
F5 Advanced WAF
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
67
Ranking in other categories
Web Application Firewall (WAF) (2nd)
R&S Web Application Firewal...
Average Rating
9.0
Reviews Sentiment
8.5
Number of Reviews
1
Ranking in other categories
Web Application Firewall (WAF) (39th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Richard Polyak - PeerSpot reviewer
Easy event identification, highly stable, and customizable
Generally, F5 Advanced WAF initial setup is straightforward. However, our environment was more complex and it took us a little more time to customize the solution to where we needed it to be. Additionally, the customization didn't rectify everything. We had to do customization to a certain event to prevent attacks that it wasn't catching, but that might not necessarily be the solutions' fault. It could be more of our setup than the solution's fault and not being able to run the latest version or the newer version could be more of a limitation on our ability to put it in the right place. The whole implementation to have the solution run at the level we wanted it to take approximately five months. Our company's environment is one that we can't put a canned solution in front of. Our environment, cannot have a canned solution that might fit everybody else because of how customized this environment is. It does need a lot of tuning to meet our environment's requirements. I rate the initial setup of F5 Advanced WAF a three out of five.
SS
Geo-localization and IP reputation help to keep our clients secure and more available
The area that should be improved is licensing. When using an active/passive cluster, we have to pay 70% of the master appliance and license for the passive server that does not work. Since we know that only one server works at a time, we should pay only one license for the appliances and for the support as well. In my opinion, this has to be improved. If possible, the client software should be a web application instead of downloading software for the management. This can avoid login problems when they update or patch.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution provides good load balancing and protection against DDoS attacks."
"I get a lot of value from Cloudflare's API because it enables you to build a separate environment inside the solution. You can create a domain for performing test requests before you move to the production environment and connect various domains."
"Generally, I am satisfied with this product."
"The solution automatically detects and responds to certain types of traffic based on geolocation."
"The technical support is good."
"Cloudflare is a security SaaS provider that provides security and protects us from any application layer attack."
"It is easier to configure and develop documentation to see how we have configured firewalls."
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"It also has antivirus and DDoS mitigation capabilities. We have enabled these features."
"The web application firewall itself is most valuable. It provides positive security and negative security. In negative security, it blocks a task such as cross-site scripting, code injection, etc. In positive security, it lets you specify and enforce things, such as the parameters allowed in username and password fields and the number of characters allowed in a field."
"It is also quite intuitive and user-friendly. They have several webinars that are actually like labs. You can use these webinars to learn about how to use all features of the product."
"The solution's most valuable features include application DDoS protection, bot blocking, and HTTP header verifications."
"The valuable features vary from customers to customers. Some customers are okay with the basic features of the WAF, and some customers use advanced WAF with a few other features."
"The most valuable feature of F5 Advanced WAF is its grand unity of the implementation, where you have the freedom to configure based on how it affects your use case or your organization. With the default setting of implicit deny, you can gradually start defining and deploying the tool to align with your environment, whether it is outdated, recent, or futuristic. This allows you to customize the solution to protect you from threat actors. You have the ability to define what the advanced threat act should do - whether it should alert, deny, or both - and it will deliver based on your configuration. Unlike other online solutions, F5 Advanced WAF provides flexibility to deliver to your unique environment the way you want."
"The solution is easily accessible on mobile and laptop devices."
"This solution inspects your traffic and based on that, automatically create distinct qualities for you, so you can add this to the policy already created. That's what I like most."
"The three most valuable features that I noticed are the geo-localization of the user, the IP reputation, and the compartmental analysis."
 

Cons

"An integrated SSO feature would be useful for Cloudflare DNS."
"The documentation could improve for Cloudflare DNS."
"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"It would be helpful if the solution could continue evolving to compete with the other solutions on the market."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"Cloudflare's console should be made more user-friendly."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"The product support needs to be accessible from more places, a wider area of coverage."
"I would like to see additional controls."
"The reporting portion of F5 Advance WAF is not great. They need to work out something better, as it is very basic. You only see the top IPs, I think there is more they can offer."
"Scalability could be improved."
"I think the deployment templates can be better."
"F5 Advanced WAF could improve on its funding for WAF features. There is a need to be more advanced WAF features."
"The interface is old-looking, it's not modern, which is why it's not always comfortable to use."
"One thing that can be improved, is to increase the quantity over predefine policy."
"The delay times on firmware patches and software updates could be better and improved."
"The area that should be improved is licensing."
 

Pricing and Cost Advice

"So far I use free tier and happy with it. You can subscribe to business package if needed."
"The product's pricing is cheap."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"The tool is a premium product, so it is very expensive."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"The cost primarily depends on the size of the organization."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"I would rate the pricing as seven out of ten"
"After buying the program, you just pay for the support every year."
"F5 Advanced WAF pricing structure should be adjusted to meet the need of small to medium-sized companies."
"F5 Advanced WAF's pricing is high."
"F5 bundles up services and the bundle is what you pay for rather than individual components."
"Its price is fair. We have done a couple of deals where they were able to give some kind of discount to the customers. The price was initially high for the customers, but after a couple of negotiations, it came within their budget. They were happy with that."
"I think the price is very high."
"I rate F5 Advanced WAF's pricing a three out of ten."
Information not available
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
838,713 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
24%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
8%
Financial Services Firm
15%
Computer Software Company
14%
Government
8%
Manufacturing Company
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about F5 Advanced WAF?
It's a fairly easy-to-use and user-friendly tool. My administrators and team also like its ability to customize the r...
What is your experience regarding pricing and costs for F5 Advanced WAF?
The setup cost is normal, yet not the best in terms of the commercial aspect. Other competitors like Fortinet are che...
What needs improvement with F5 Advanced WAF?
One improvement for AOF could be focusing on enhancing its AI engine to make it more mature.
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
 

Comparisons

 

Also Known As

Cloudflare DNS
No data available
Rohde & Schwarz Web Application Firewall, R&S WAF, DenyAll Web Application Security
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
MAXIMUS, Vivo, American Systems, Bangladesh Post Office, City Bank
Information Not Available
Find out what your peers are saying about Amazon Web Services (AWS), F5, Microsoft and others in Web Application Firewall (WAF). Updated: February 2025.
838,713 professionals have used our research since 2012.