No more typing reviews! Try our Samantha, our new voice AI agent.

F5 Advanced WAF vs The Fastly Next-Gen WAF (powered by Signal Sciences) comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Ranking in Web Application Firewall (WAF)
6th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
No ranking in other categories
F5 Advanced WAF
Ranking in Web Application Firewall (WAF)
3rd
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
72
Ranking in other categories
No ranking in other categories
The Fastly Next-Gen WAF (po...
Ranking in Web Application Firewall (WAF)
33rd
Average Rating
7.6
Reviews Sentiment
4.8
Number of Reviews
4
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Web Application Firewall (WAF) category, the mindshare of Cloudflare Web Application Firewall is 3.8%, down from 5.8% compared to the previous year. The mindshare of F5 Advanced WAF is 3.9%, down from 8.2% compared to the previous year. The mindshare of The Fastly Next-Gen WAF (powered by Signal Sciences) is 1.1%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
F5 Advanced WAF3.9%
Cloudflare Web Application Firewall3.8%
The Fastly Next-Gen WAF (powered by Signal Sciences)1.1%
Other91.2%
Web Application Firewall (WAF)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
reviewer2797602 - PeerSpot reviewer
Senior Security Systems Engineer at a tech services company with 11-50 employees
Granular security policies have protected critical applications and ensure safe user and admin access
Improvements could be made regarding the log information from the backend CLI. There are enhancements needed; if a request gets blocked on the TCP layer, there should be traces or data to verify which source generated these requests, including the source and port information for initiation. These data are missing from F5 Advanced WAF. Besides that, another improvement could be refining the bot detection to minimize false positives; it should be able to verify more granularly between legitimate and non-legitimate clients. Overall, I find everything else good. A wish list feature I have is for the Technical Assistance Center (TAC) to respond more promptly. Their response time needs improvement; while they do not take excessive time, it can be enhanced, especially given it is a security product.
reviewer2161107 - PeerSpot reviewer
Staff Engineer at a retailer with 1,001-5,000 employees
Room for improvement with user interface while competitive pricing impresses
It is managed through Infrastructure as Code, so all configurations can be managed in the code itself, which is beneficial. Because it uses rules, it is easy to set up, and we have many different sites where the configurations are straightforward. Though the UI is not very interactive, which is a downside, we can manage many things. The UI is not very intuitive and could be better. However, we manage all the configurations through code, which is easy to maintain. It has extensive anomaly detection capabilities, so the traffic is classified into several categories where thresholds can be defined and customized based on false positives and false negatives. This is advantageous because you do not need to tweak it very often. Once you set it up, an audit once a quarter would suffice. Because The Fastly Next-Gen WAF (powered by Signal Sciences) is API-driven, we have integrations with the CI/CD pipeline through GitHub Actions, making it easy to integrate.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution does a good job of preventing web application attacks, SQL injections, and cross-site scripting attacks."
"I'm highly satisfied. It's remarkably user-friendly, enabling me to quickly identify issues, and deploy solutions, and it offers the necessary features."
"The product has improved our security posture by blocking bad actors."
"For us, the key feature of Cloudflare is DDoS protection and IP hiding, especially since we are a crypto company."
"Cloudflare has positively impacted my organization by making it easier for me to handle and set up DNS for multiple clients; I can easily go in and access their accounts, make changes they need, and it's a one-stop shop."
"Caching is the most valuable feature of Cloudflare Web Application Firewall."
"Cloudflare WAF provides protection through rules and functionalities like Cloudflare's SDRAP."
"Some of the most valuable features of Cloudflare Web Application Firewall include its DNS zone setup and the zero trust policy."
"The product is used to secure web applications and has the ability to use API templates and bot protection features, such as blocking requests or presenting CAPTCHA pages to end users."
"The web application firewall itself is most valuable. It provides positive security and negative security. In negative security, it blocks a task such as cross-site scripting, code injection, etc. In positive security, it lets you specify and enforce things, such as the parameters allowed in username and password fields and the number of characters allowed in a field."
"It protects and mitigates damage in the network."
"There is no need to worry about updating signatures because WAF will automatically update the signatures for you."
"The solution's most valuable features include application DDoS protection, bot blocking, and HTTP header verifications."
"My favorite feature of F5 is the ability to play around with the ciphers. I also like the ability to have an immediate display of the support IDs when a real blockage occurs. The protection offered is great."
"The most valuable feature of F5 Advanced WAF is its ability to mitigate attacks: DDoS and DNS, or layer seven application attacks, OWASP, and email."
"Web attack signatures are very important for detecting web attacks."
"Because The Fastly Next-Gen WAF (powered by Signal Sciences) is API-driven, we have integrations with the CI/CD pipeline through GitHub Actions, making it easy to integrate."
"Fastly (Signal Sciences) integrates and tags the intermittent traffic based on patterns. It generates signals and provides them in a dashboard where we can view them and decide whether to allow or deny traffic. It's a more advanced and easy-to-navigate dashboard."
"When configuring a web application firewall using Signal Sciences, we configure a rule whereby no one except a few people can access the application."
"The product's most valuable feature is its ability to set up the rules easily."
 

Cons

"Cloudflare Web Application Firewall should include port forwarding features."
"The learning curve was steep initially."
"The dashboard could be more user-friendly."
"We don't even use Cloudflare Bot Management because it's too expensive; you need to pay per request, and it's much cheaper to get one or two additional machines."
"The reporting could be improved if it were more granular."
"A key challenge arises when dealing with numerous integrations with HVAC systems. Depending on the specifics, there might be some configuration mismatches, which necessitate specific support."
"Their documentation could be better. They don't have documentation that explains everything well. They have documentation for everything you're looking for, but they lack a single piece of documentation to tie everything together. As a new user or beginner, it took us a little bit of time to figure out how to put all these things in place."
"We have noticed some latency when the call goes through the firewall. That could be improved."
"I would not expect traffic details to pass through the web application firewall across the length of the whole application. I think that there is a web application where it can let the application function without traffic going in into the WAF."
"The user interface (UI) seems a bit outdated. Making it more user-friendly would be beneficial."
"The DDoS capabilities should be enhanced."
"There are opportunities for improvement in updating the user interface to a more modern look."
"People who want to work with the device have to be pro in Linux"
"Everything is good about the F5 WAF, except the reporting. It's really difficult to set records from that device, the UI is kind of hard to work with, and the reporting must be improved."
"The solution's dashboard could be improved. When you're moving from policy to policy, the logs and the integration of the logs in other systems aren't straightforward."
"One of our customers is a bit unhappy about the reporting options."
"The areas that could be improved in Signal Sciences include the effectiveness of rules, as many didn't function optimally and required custom rule-writing to address bypasses for WAF."
"Fastly don't support caching for China users. That's the only feature lacking compared to Akamai."
"The UI is not very intuitive and could be better."
"Even if we create some custom rules, Signal Sciences cannot capture some of the malicious traffic."
 

Pricing and Cost Advice

"It starts at $20 and can easily go up to $200 monthly"
"The solution is expensive."
"The annual licensing fee is $10,000 USD."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"The solution's pricing option needs to be more transparent for enterprise clients."
"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"I would rate the pricing as seven out of ten"
"There is a perpetual license that comes with your hardware. There is also an additional fee for support."
"Licensing fees for this solution are paid on a yearly basis."
"Pricing for this solution is higher than average."
"The pricing of F5 Advanced WAF is more expensive than other solutions like Radware and CD18, it is quite high."
"I think the price is very high."
"After buying the program, you just pay for the support every year."
"The pricing is too high."
"The product has an affordable cost."
"Signal Sciences is pretty cheap compared to other solutions."
"The pricing is 50% less than Akamai."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
908,745 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Financial Services Firm
9%
Comms Service Provider
9%
Outsourcing Company
7%
Financial Services Firm
15%
Computer Software Company
9%
Comms Service Provider
9%
Government
8%
Retailer
10%
Manufacturing Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise16
Large Enterprise31
No data available
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What is your experience regarding pricing and costs for F5 Advanced WAF?
F5 Advanced WAF is somewhat costly compared to other vendors, but it is worth the investment due to the stability it ...
What needs improvement with F5 Advanced WAF?
Improvements could be made regarding the log information from the backend CLI. There are enhancements needed; if a re...
What is your primary use case for F5 Advanced WAF?
My main use case for F5 Advanced WAF is to protect external and internal applications from cyber attacks and to preve...
What is your experience regarding pricing and costs for Signal Sciences?
The pricing is very competitive compared to other providers. The pricing is definitely a factor in our decision-makin...
What needs improvement with Signal Sciences?
We do use it, but the UI can be improved as we mostly work through the CI/CD. It provides support, but sometimes it i...
What is your primary use case for Signal Sciences?
The CDN is for caching and The Fastly Next-Gen WAF (powered by Signal Sciences) is for protecting the servers from ma...
 

Also Known As

Cloudflare WAF
No data available
Signal Sciences Next-Gen WAF, Signal Sciences RASP
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
MAXIMUS, Vivo, American Systems, Bangladesh Post Office, City Bank
Chef, Adobe, Datadog, Etsy, GrubHub, Vimeo, SendGrid, Under Armour, Duo, AppNexus
Find out what your peers are saying about F5 Advanced WAF vs. The Fastly Next-Gen WAF (powered by Signal Sciences) and other solutions. Updated: June 2026.
908,745 professionals have used our research since 2012.