Try our new research platform with insights from 80,000+ expert users

Fortinet FortiDDoS vs Imperva DDoS comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 5, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Ranking in Distributed Denial-of-Service (DDoS) Protection
1st
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
74
Ranking in other categories
CDN (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Fortinet FortiDDoS
Ranking in Distributed Denial-of-Service (DDoS) Protection
13th
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
14
Ranking in other categories
No ranking in other categories
Imperva DDoS
Ranking in Distributed Denial-of-Service (DDoS) Protection
7th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (7th), Web Application Firewall (WAF) (18th)
 

Mindshare comparison

As of March 2025, in the Distributed Denial-of-Service (DDoS) Protection category, the mindshare of Cloudflare is 18.9%, down from 19.3% compared to the previous year. The mindshare of Fortinet FortiDDoS is 3.0%, up from 2.8% compared to the previous year. The mindshare of Imperva DDoS is 7.0%, down from 8.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Yazan Omar - PeerSpot reviewer
An easy-to-use tool with great GUI
The product's initial setup phase was really easy. There is a lot of time involved in the testing phase and other processes related to the area of deployment, so it may take up to two weeks to deploy the solution. The solution is deployed on an on-premises model. One person is enough to take care of the deployment phase of the product. The person involved in the deployment phase needs to better understand topologies when dealing with Fortinet.
Syed Ubaid Ali Jafri - PeerSpot reviewer
I like the content monitoring feature which I haven't seen in other WAF solutions.
They could improve by minimizing false positive results. Although this occurs less with Imperva, we would like to see some further improvements. We have been using this product for last 1 years, it's result is very impressive. But due to the excessive load on the Web site where thousands of requests‎ are generated from legitimate users, however the request in which any sequential or specialised characters are requested would be directly blocked by impreva . Currently imperva blocks the special character request generated from the user, as I conduct a test where I am parsing the encoded html values of the same special characters to the input field, imperva bypasses these encoded values for example : ' i.e. %27 or / i.e %2F, the WAF bypasses these encoded characters. I hope that this device should have a capability to detect the pattern which is associated with Xss or Xsrf, rather then by not blocking the request which contains any special characters.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"From what I've seen so far, there are no negatives to report as of yet"
"The technical support is good."
"Its most significant benefit to date is the speed with which it refreshes DNS records on the internet once you change it. If you are changing a website or registering a new record, it is very quick."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"New and innovative way to protect the client's data."
"The most valuable feature of Cloudflare is the GUI. You are able to control the solution very well through the interface. There is a lot of functionality that is embedded in the service."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"The most valuable feature of Cloudflare DNS is security."
"Among its key features: Detects and mitigates DDoS attacks at L3 to L7; negligible to zero false-positives; Generates and sends reports without the need for an expensive third-party solution."
"The equipment works very well, and I have not encountered any issues with it. It is a good solution for my company."
"This solution can protect Layer 3, Layer 4 and Layer 7 attacks of applications for us."
"The product allows the users to adjust the thresholds."
"It is a user-friendly product in terms of monitoring and updating policies."
"We have researched them all, and it's a good solution all around."
"The most valuable feature is the cloud DDoS scrubbing capability."
"The solution already has security profiles and it can protect from DDoS attacks and other kinds of attacks."
"They're quite easy to install and quite easy to set up. Clients really like that. Especially when you're dealing with the cloud, it's really easy."
"On the site security, I can see which countries have incidents, whether it was a robot attack, a real human user, or non-human user."
"The technical support is excellent."
"The bot management features are very effective, as they help filter unwanted traffic using keywords."
"DDoS protection and WAF are the most valuable features. It is easy to deploy a service. It is easy and quick to deploy to a new website."
"The dashboard is good and user-friendly."
"Simplifies putting everything in code."
"It fits our requirements, as well as our budget."
 

Cons

"We have noticed multiple instances where Cloudflare falsely indicates that our servers are down, even when there is no actual load on them. This makes it challenging for us to identify the exact issue."
"They lack a good way to manage DNS as a company, since everything is relegated to single account logins until you get to the higher levels. They have come out with a paid feature to remedy this, but I have not had a chance to fully review it yet to know if it fixes the access problem."
"Support response time could be improved."
"The solution could use more analytics on the backend to give us more insights into everything. More reports would be helpful."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"It should have easier documentation for the configuration. It's very technical and people who aren't technical should also be able to do the configuration."
"The pricing could be improved."
"We are a product integrator and reseller, and we would like to have a better partner relationship, similar to a channel sales relationship. Sometimes we are on our own or get diverted by Cloudflare because they have direct sales, which competes with us and makes it difficult to build a relationship with this company since we want to be an MSP or a managed service provider for the solution."
"The primary area for improvement is the on-premises capacity limit, currently fixed at 10 GB."
"The only thing they need to do is to automate it. Today, you must create tools that do not require the use of an expert or anyone with special skills."
"I find that there have been issues in the past year with the solution hanging. It freezes often."
"The solution can be a little more user-friendly and it can be more affordable."
"There aren't really any aspects of the solution we are unhappy with. It's been a positive experience overall."
"The main improvement would be to change the firewall model, however, currently, everything is fixed and working well."
"The product’s pricing needs improvement."
"All the thresholds that need to be configured should be included in the default so that user will not forget or misconfigure."
"I am not sure if this application has a policy where you can create your custom policy and run it as our firewall. We should have some ability to also create some custom policy, then run it as a firewall."
"I miss being able to integrate the dashboard with other BI tools we are using. We have to export and import data to be able to present it, and doing so is a lot of work."
"Incapsula services also provides load balancing services for their service IP address environment. So far, with monitoring their services, the IP address was only changed once."
"The cost could be lower; our end clients need to have a high budget to purchase this solution."
"It would be better if we were able to manage and apply changes to multiple websites/web applications, and search WAF logs for multiple websites, via the Incapsula dashboard."
"The product could use a broader scope in the area of policies."
"It would be beneficial to include vulnerability management in the solution, similar to what they have for their on-premise solution."
"We had an issue when securing the web applications for DDoS protection."
 

Pricing and Cost Advice

"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"I give the price a five out of ten."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"There are no additional costs beyond the standard licensing fees."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"The product's pricing is minimal compared to other products."
"We are using the free version."
"The price of the solution is expensive."
"The solution is reasonably priced."
"It's quite pricey."
"The product’s pricing needs improvement."
"It is expensive."
"We have an issue with Imperva Incapsula in the Iraqi market because of the high price."
"The data packages are higher than our needs so we end up paying for data that we don't use."
"It is not expensive compared to the other similar solutions in this category."
"Varies depending on the needs of the customer."
"Imperva charges us based on bandwidth, which is better than other vendors that charge us according to data transfer."
"For enterprise contracts you will be in touch with a dedicated account manager who will guide you regarding licensing."
"The solution's price is high for small companies."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
839,319 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Educational Organization
24%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
8%
Computer Software Company
14%
Financial Services Firm
11%
Manufacturing Company
10%
University
7%
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would...
What do you like most about Fortinet FortiDDoS?
The product's initial setup phase was really easy.
What do you like most about Imperva Incapsula?
We use Imperva DDoS to stop DDoS attacks and reduce the amount of unwanted queries against web services or web scraping.
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing is rated a ten on a scale where ten is very expensive. The solution is only cloud-based and does not prov...
What needs improvement with Imperva DDoS?
Pricing can be improved, as it is quite expensive. Additionally, support response times for emails can sometimes be d...
 

Also Known As

Cloudflare DNS
Fortinet DDoS, FortiDDos
Imperva Incapsula
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Black Gold Regional Schools, Amadeus Hospitality, Jefferson County, Chunghwa Telecom, City of Boroondara, Dimension Data
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about Fortinet FortiDDoS vs. Imperva DDoS and other solutions. Updated: January 2025.
839,319 professionals have used our research since 2012.