We use F5 Advanced WAF to protect web applications on HTTPS, APIs, and portals.
Cybersecurity Team Leader at Summit Technology Solution
Stable product with essential capabilities to protect the web applications
Pros and Cons
- "F5 Advanced WAF helps our engineers to learn the complete configuration, including fundamental and advanced policies."
- "Most customers encounter stability issues with the product's Big-IP logs."
What is our primary use case?
What is most valuable?
F5 Advanced WAF helps our engineers to learn the complete configuration, including fundamental and advanced policies.
What needs improvement?
Most customers encounter stability issues with the product's Big-IP logs. It works slowly while retrieving logs.
For how long have I used the solution?
We have been using F5 Advanced WAF since this year.
Buyer's Guide
F5 Advanced WAF
December 2024
Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
823,875 professionals have used our research since 2012.
What do I think about the stability of the solution?
The product is more stable than Fortinet.
What do I think about the scalability of the solution?
The product has modular appliances. It works well, scalability-wise.
How are customer service and support?
The technical support services are good. The team includes professional engineers to communicate with the customers regarding cases.
How was the initial setup?
It is easy to set up F5 Advanced WAF. Although, it is difficult to deploy and maintain compared to Fortinet. The deployment process involves gathering customer information regarding virtual servers to be protected. Later, we select the best design suitable for their requirements and start with license provisioning. Further, we configure LTM with special servers and nodes and proceed with configuring the security policy and advanced directory. It takes a week to protect the infrastructure fully. Once we have license provisioning, it is good to run.
What's my experience with pricing, setup cost, and licensing?
F5 Advanced WAF's pricing is high. Fortinet and some other vendors are more affordable.
What other advice do I have?
F5 Advanced WAF has good capabilities, powerful tools, and professional services. I advise others to compare pricing with vendors in terms of their use cases before purchasing the product.
I rate it a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Network Security Engineer at IIPL
Enhanced security with adaptive traffic management and policy learning
Pros and Cons
- "I appreciate the way F5 Advanced WAF builds policies by configuring a basic policy and queuing it in learning mode."
- "The GUI interface can be confusing due to similar-looking tabs for policy building, traffic learning, and event logs."
What is our primary use case?
Our clients mostly have their own applications, such as banking apps, and use F5 Advanced WAF to avoid vulnerabilities and threats on both the application layer and transport layer.
We create web policies for their apps and configure ASM signatures to prevent vulnerabilities. After configuring the policies, I monitor logs continuously to block vulnerability attacks and assist clients in addressing any issues.
How has it helped my organization?
One of the things that surprised me the most about F5 devices is their compatibility with the existing infrastructure of most customers. They can be easily integrated between the main firewall and back end servers, making it a seamless addition to enhance security.
What is most valuable?
The traffic learning feature stands out as the most valuable. When an app is accessed, the log generated in F5 Advanced WAF provides suggestions on what actions to take. This feature is particularly beneficial in new vulnerability scenarios, offering guidance based on learned data.
Additionally, I appreciate the way F5 Advanced WAF builds policies by configuring a basic policy and queuing it in learning mode. The solution learns from logs, and based on that learning, I configure ASM signatures.
What needs improvement?
The GUI interface can be confusing due to similar-looking tabs for policy building, traffic learning, and event logs. A more explanatory GUI would be beneficial. However, F5 solutions are a bit expensive compared to others, although they provide the best service and options.
For how long have I used the solution?
I have been working with F5 Advanced WAF for around six months.
What do I think about the stability of the solution?
The solution is very stable. I would rate it a nine out of ten for stability.
What do I think about the scalability of the solution?
F5 Advanced WAF is very scalable, and I would rate its scalability as nine out of ten.
How are customer service and support?
F5 support is excellent and deserves a ten out of ten. Their technical support is responsive and helpful, making the overall experience very satisfactory.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have not worked with many other vendors as extensively as F5, but I have some knowledge of FortiWAF. FortiWAF has fewer options compared to F5, particularly in features like iRULES, which offers more flexibility for traffic management and coding.
How was the initial setup?
The initial setup is not very lengthy. Once the device is on-premises, configuring and managing it is quite efficient, though the entire project from start to end may take about a month to a month and a half.
What about the implementation team?
I work with a team of five to six network engineers across different cities, providing support and collaboration for client deployments.
What was our ROI?
The return on investment is quite high with F5 solutions. Customers prefer F5 for their superior service and features, despite the higher cost.
What's my experience with pricing, setup cost, and licensing?
F5 is on the expensive side but offers superior solutions and options. Customers are willing to pay for the quality and features provided.
Which other solutions did I evaluate?
I have some knowledge of FortiWAF, but F5 provides more options, especially with features like iRULES for managing traffic.
What other advice do I have?
I would recommend F5 Advanced WAF to other users. It provides excellent features, flexibility, and support.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Last updated: Oct 29, 2024
Flag as inappropriateBuyer's Guide
F5 Advanced WAF
December 2024
Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
823,875 professionals have used our research since 2012.
Head of Presales at a tech vendor with 10,001+ employees
Expandable with helpful support and great threat intelligence functionality
Pros and Cons
- "The solution is stable."
- "The deployment side is quite complex."
What is our primary use case?
It's considered one of the modules for the LTM box. It's all modules for the LTM box.
It is actually to protect the customer web application which is published on the internet. It's actually to protect that, and nowadays, we also have this threat intelligence. You will link to the F5 centra, the depository of the threat intelligence database. We always have the latest update on the common threat that is happening currently. You will notify the customer if there's an issue.
What is most valuable?
The threat intelligence function is great. Nowadays, there is more awareness on the security side. They'd have a real-time update from F5. It provides peace of mind on the security side for the customer.
It is an add-on module to protect the web application.
The solution can scale with planning.
The solution is stable.
Support is helpful.
What needs improvement?
The deployment side is quite complex. We'd like them to simplify the implementation process. I'm not sure whether they can do that, however, they have to be very detailed on configurations, and sharing of the policy. Anybody that configures this box, the WAF, they have to have knowledge of the application and some of the security portions there as well.
For how long have I used the solution?
We've had the solution since last year. We have deployed it to a customer.
What do I think about the stability of the solution?
It is stable. Actually, it evolved from ASM, what they call the Application Security Manager, and now they name it Advanced WAF. It's been around for a while. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
We'll size up based on the customer requirement with some buffer, maybe 20% to 30% for the future extension. There is also some consideration on the capacity planning and the size of the box. You can scale. You just need to plan ahead.
In terms of users, with Advanced WAF, normally their role is more related to the security side.
We just implemented the solution recently and we'll have to wait another three or four years before we change or upgrade the solution.
How are customer service and support?
I've dealt with technical support. We're quite satisfied with them. They're good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
F5 WAF is a web application, in the firewall domain, they have been in the market for a very long time. They know the requirements and the market trends very well. This is the reason why we normally chose F5.
How was the initial setup?
The solution is pretty difficult to set up. You really have to have a grasp o the product to configure it correctly.
The setup takes approximately two months. It's quite a long time. If the application is not ready, then the dependency will be on the application side. Therefore, the cycle is quite long. It depends on the application readiness.
We just need one to two people to handle deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
The licensing is charged yearly. It's considered expensive, however, there are more expensive WAFs on the market - like Imperva. F5 is second after Imperva in terms of cost. L1 to L3 support is included in the cost.
I'd rate the price of the solution at a four out of five in terms of how expensive it is.
Which other solutions did I evaluate?
We tend to stay with F5, however, we will look at pricing and try to negotiate based on that. We'd like to get a discount and look at the market to see the costs.
What other advice do I have?
I'd advise that new users need to know the requirement expectations, and then the criticality of the application that they're going to let the user use. Sometimes the application is public to the internet for a public user to log into and query the database. In that case, we're exposed to all kinds of external parties. So if you put something that is cheap in place, something that is not able to do the protection properly, then it will be a very big risk to the company.
I'd rate the solution ten out of ten. Our clients have been very happy with it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partners
Import Comliance Specialist at Silicon21
Empower critical applications with comprehensive protection and enhanced security capabilities
Pros and Cons
- "F5 Advanced WAF is a comprehensive community platform with a strong commitment, making it valuable for businesses."
- "I would like to see improved features in the F5 Advanced WAF solution, especially with a focus on enabling Kubernetes fully."
What is our primary use case?
I was in charge of the F5 on-premises solution, where I published several applications for certificate verification and protected various applications. Additionally, I was working with botnets.
What is most valuable?
F5 Advanced WAF is a comprehensive community platform with a strong commitment, making it valuable for businesses. The capabilities on GitHub are highly appreciated, allowing me to count on F5 for reliability.
What needs improvement?
I would like to see improved features in the F5 Advanced WAF solution, especially with a focus on enabling Kubernetes fully. The database needs better service discussions and updates on communication. Additional improvements could also be made in asset management for the data.
For how long have I used the solution?
I've been working with F5 for what seems like a lengthy period.
What do I think about the stability of the solution?
F5 is logistics-oriented, ensuring that the Webpack performs well in making every single case for the Stereo platform.
What do I think about the scalability of the solution?
F5 is scalable, especially for Stellar and virtualization processes. Customers can scale efficiently.
How are customer service and support?
F5's technical support team is commendable. They are professional and take high-priority prompts seriously.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
My experience includes comparing F5 with FortiWeb. F5 provides more security capabilities for applications than FortiWeb.
How was the initial setup?
The initial setup of the F5 Advanced WAF solution involves multiple stages and might require revisiting configurations based on customer needs. The setup can be complex compared to other options.
What about the implementation team?
I am part of the deployment and implementation team, and we follow a strategy that involves providing quality assurance to ensure data integrity and server protection. Collaboration and dialogue with customers are part of the implementation.
What was our ROI?
Customers have shown consistent ROI with F5 solutions, especially when daily requests come in for assistance.
What's my experience with pricing, setup cost, and licensing?
The user interface and sub-management prices can be a concern, however, they generally align with the industry's needs.
What other advice do I have?
I recommend the F5 Advanced WAF solution for everyone with critical applications. Security needs to be embedded within the full visualization pipeline, allowing significant savings. I rate F5 Advanced WAF at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Last updated: Nov 18, 2024
Flag as inappropriateTechnology Consultant at Netwiser
Bot attack reduction and enhanced web security with reasonable pricing
Pros and Cons
- "It provides web application security and reduces bot attacks."
- "The product could be more user-friendly for administrators."
What is our primary use case?
We use this solution for load balancing and web application firewall (WAF) services. We use the solution standalone and not integrated with other solutions.
How has it helped my organization?
It provides web application security and reduces bot attacks.
What is most valuable?
The web attack signatures are very important for detecting attacks, and the bot detection capability is an important feature that works well with F5 Advanced WAF.
What needs improvement?
The product could be more user-friendly for administrators. The user interface could be easier.
For how long have I used the solution?
I have been using it for almost three years.
What do I think about the stability of the solution?
The solution is very stable. I would rate its stability as nine out of ten.
What do I think about the scalability of the solution?
Very scalable. We use this solution for multiple customers and across data centers.
How are customer service and support?
The solution offers good support. That said, sometimes it takes too much time to reach the right person.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have also worked with Citrix NetScaler and F5 products, depending on customer needs.
How was the initial setup?
The initial configuration is not too difficult, but subsequent configurations can be complex because they depend on customer needs.
What's my experience with pricing, setup cost, and licensing?
I don't have direct knowledge of the pricing. From what I know, it is not too expensive compared to other solutions.
Which other solutions did I evaluate?
I am familiar with F5 and Citrix NetScaler solutions.
What other advice do I have?
I recommend this product to others because of its effectiveness in mitigating threats.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Last updated: Oct 31, 2024
Flag as inappropriateUnit Head - Network and Security Solutions at FPM Solutions
Their support engineers are experts who always provide the right solution,
Pros and Cons
- "F5 technical support is excellent. They are experts who always provide the right solution, and they understand the problem. Their response and resolution times are good."
- "Nevertheless, F5 products are generally considered to be hard to deploy."
What is our primary use case?
In Pakistan, the banking and financial sector requires F5 WAF solutions. I worked with other companies that had more clients, but my current company is a start-up. We have Palo Alto business, but we're trying to get F5 business.
What is most valuable?
F5 products are highly stable, top-notch solutions, and we have also the expertise to deploy and design the F5 and Palo Alto product lines. I have more than 10 years of experience with F5 and Palo Alto. I have deployed around F5 products for around seven or eight customers of F5.
What needs improvement?
F5 should consider adding network detection and response.
For how long have I used the solution?
We have been using F5 solutions for two years, including load balancers and Advanced WAF.
What do I think about the stability of the solution?
Advanced WAF is highly stable.
What do I think about the scalability of the solution?
F5 products are scalable, and they have an excellent R&D department. Their product is constantly maturing.
How are customer service and support?
F5 technical support is excellent. They are experts who always provide the right solution, and they understand the problem. Their response and resolution times are good.
How was the initial setup?
Advanced WAF is a difficult product for new users, but it's not too challenging if you have experience. Nevertheless, F5 products are generally considered to be hard to deploy.
What's my experience with pricing, setup cost, and licensing?
F5's hardware product line is called BIG-IP, and they have many software licenses for IP DNS, Advanced WAF, APM, anti-spam, etc. We have around 10 licenses.
What other advice do I have?
I rate F5 Advanced WAF 10 out of 10. I would highly recommend the entire F5 product line.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Sr. Cybersecurity Solutions Architect at BMB
A highly stable and scalable load balancing solution
Pros and Cons
- "Customers find the load balancer feature as the most valuable."
- "The tool needs to improve its pricing."
What is our primary use case?
It is used for application security and load balancing. As we have a few customers who are using banking applications, and stock market applications, they are more concerned about security and how to protect the product and their business applications. And that's why we offer security applications. Besides that, there are new features for load balancing in the F5.
What is most valuable?
Customers find the load balancer feature as the most valuable.
What needs improvement?
The tool needs to improve its pricing.
For how long have I used the solution?
I have been using it for two years.
What do I think about the stability of the solution?
It is a very stable product. It is the favourite product of banking customers in Egypt.
What do I think about the scalability of the solution?
It is a very scalable product. You can write down any iRule you want as it is very convenient.
Which solution did I use previously and why did I switch?
We used Citrix ADC, Fortinet FortiWeb, and Barracuda before F5 Advanced WAF. We switched to F5 Advanced WAF due to its efficiency and the port lockdown feature that the customers in Egypt like. Also since it's certified by Gartner, the customers feel confident using it.
How was the initial setup?
The initial setup was simple.
What other advice do I have?
If you are looking for a really good product, you should consider F5 Advanced WAF.
I would rate it a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
Security team leader at a aerospace/defense firm with 10,001+ employees
A reliable and user-friendly solution that provides positive and negative security and has antivirus and DDoS mitigation capabilities
Pros and Cons
- "The web application firewall itself is most valuable. It provides positive security and negative security. In negative security, it blocks a task such as cross-site scripting, code injection, etc. In positive security, it lets you specify and enforce things, such as the parameters allowed in username and password fields and the number of characters allowed in a field."
- "It also has antivirus and DDoS mitigation capabilities. We have enabled these features."
- "It is also quite intuitive and user-friendly. They have several webinars that are actually like labs. You can use these webinars to learn about how to use all features of the product."
- "Its price should be better. It is expensive."
What is our primary use case?
We have several websites that are exposed to external users. We have a website for interaction with supply chain customers. We also have a website that gives access to CRM functionality to allow our customers to open tickets and disputes. F5 WAF is at the front for security and attack mitigation. It ensures that users are able to access only allowed pages.
What is most valuable?
The web application firewall itself is most valuable. It provides positive security and negative security. In negative security, it blocks a task such as cross-site scripting, code injection, etc. In positive security, it lets you specify and enforce things, such as the parameters allowed in username and password fields and the number of characters allowed in a field.
It also has antivirus and DDoS mitigation capabilities. We have enabled these features.
It is also quite intuitive and user-friendly. They have several webinars that are actually like labs. You can use these webinars to learn about how to use all features of the product.
What needs improvement?
Its price should be better. It is expensive.
What do I think about the stability of the solution?
In general, it is stable and reliable. Over the past few months, several vulnerabilities were found in the product, but which product doesn't have vulnerabilities? The main question is how fast do you get the fix for it, and they provided the fix quite quickly. We had to upgrade it as soon as possible to mitigate the risks.
What do I think about the scalability of the solution?
I didn't try to expand it. We have two staff members who are using F5 Advanced WAF.
In terms of its usage, we are deploying it on all points through which we are exposing services, but we are currently not exposing too many services.
How are customer service and technical support?
I had only one case for which I had to call tech support. It wasn't a straightforward ticket. It was quite a challenging ticket. Eventually, they found a solution, but it took some time. It was challenging to find the bug in one of the previous versions. They also didn't know about it. We did the troubleshooting together until we found the problem.
Which solution did I use previously and why did I switch?
We were using another solution before switching to F5 Advanced WAF. We didn't have success with that solution because the integrator failed to deploy it properly. It was more complex and not user-friendly.
How was the initial setup?
It was a little bit complex. If you want to add an additional layer or model like APM with two-factor authentication, then it requires a little bit more integration.
What's my experience with pricing, setup cost, and licensing?
It is expensive. Its price should be better.
Its licensing is on a yearly basis. Its licensing is also based on the model. There are no additional costs.
What other advice do I have?
I would recommend this solution to other users. I will advise others to learn a little bit about how the HTTP protocol works. They should be familiar with the functionality of the product. They should not use it without understanding what they are actually doing.
I would rate F5 Advanced WAF a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free F5 Advanced WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
AWS WAF
Fortinet FortiWeb
NetScaler
Imperva Web Application Firewall
Cloudflare Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Buyer's Guide
Download our free F5 Advanced WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Does F5 Advanced WAF work with Azure App Service?
- Which is better, Barracuda Web Application Firewall or F5 Advanced WAF?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?