We use the solution for load balancing.
System Engineer at DShield
A cost-effective solution for load balancing with data loss prevention
Pros and Cons
- "It protects and mitigates damage in the network."
- "They should work on the virtualization of NGINX."
What is our primary use case?
What needs improvement?
They should improve the capability, and then they should work on the virtualization of NGINX. Currently, most environments are virtualized. F5 Advanced WAF will not be able to protect it.
For how long have I used the solution?
I have been using F5 Advanced WAF as a reseller for 5 years.
How are customer service and support?
Technical support is good but not enough. It takes a lot of time to get support.
Buyer's Guide
F5 Advanced WAF
December 2024
Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
823,875 professionals have used our research since 2012.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is not so easy nor not so complex. There is a learning phase, and there are policies to apply. It complies with regulations. Recently, we used it for Formula One, and it proved very effective.
What was our ROI?
ROI is covered in one year. You can see how it protects and mitigates damages in the network.
What's my experience with pricing, setup cost, and licensing?
The product is not so expensive. It depends on the assets.
What other advice do I have?
There are other solutions for data loss prevention, such as Symantec and IP solutions. There are options available for DNS blocking. While these solutions may specialize in certain aspects, They offer comprehensive coverage across various areas. Each vendor specializes in different aspects, but F5 Advanced WAF excels in its particular domain.
I recommend the solution. Most of the environment is going to virtualization.
Overall, I rate the solution an 8 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Last updated: Apr 30, 2024
Flag as inappropriateInformation Security Manager at Chong Hua Hospital
High availability, many features, and scales well
Pros and Cons
- "The most valuable features of F5 Advanced WAF are the overall capabilities, there is not a comparable solution on the market."
- "F5 Advanced WAF could improve the reporting. It's a bit difficult to populate, them. If you're not so familiar with the functions, such as where to find the logs and other settings."
What is our primary use case?
We are using F5 Advanced WAF for the applications that we are publishing mainly for intrusion prevention and proxy features.
What is most valuable?
The most valuable features of F5 Advanced WAF are the overall capabilities, there is not a comparable solution on the market.
What needs improvement?
F5 Advanced WAF could improve the reporting. It's a bit difficult to populate, them. If you're not so familiar with the functions, such as where to find the logs and other settings.
In a future release, it would be beneficial to have a DNS boost feature.
For how long have I used the solution?
I have been using F5 Advanced WAF for approximately five years.
What do I think about the stability of the solution?
I rate the stability of F5 Advanced WAF a ten out of ten.
What do I think about the scalability of the solution?
We have approximately 300 users using this solution in my organization.
I rate the scalability of F5 Advanced WAF a nine out of ten.
Which solution did I use previously and why did I switch?
I was previously using NGINX App Protect and we switched to F5 Advanced WAF because the GUI was better.
How was the initial setup?
The full implementation of the solution took approximately eight hours. There are sections of the configuration at can be difficult.
What about the implementation team?
We used a third party to do the implementation.
What other advice do I have?
I rate F5 Advanced WAF an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
F5 Advanced WAF
December 2024
Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
823,875 professionals have used our research since 2012.
F5 Product Manager at Westcon-Comstor
A solution that would benefit with more documentation regarding bot protection
Pros and Cons
- "The most valuable features of F5 Advanced WAF are the security features and the protection."
- "F5 Advanced needs to improve its bot protection. The solution needs to have machine learning to learn the behavior of the customer to recognize the human versus the bot. This is a difficult feature to explain to our customers. I would like documentation about the bot feature to make it easier for the customer to understand."
What is our primary use case?
We are distributors in Vietnam. We consult for our customers and I am a Product Manager. We use F5 Advanced WAF as a firewall for our website applications and the websites of our customers.
What is most valuable?
The most valuable features of F5 Advanced WAF are the security features and the protection.
In the future, I would like to see F5 include AI in the hardware of F5 Advanced WAF.
What needs improvement?
F5 Advanced needs to improve its bot protection. The solution needs to have machine learning to learn the behavior of the customer to recognize the human versus the bot. This is a difficult feature to explain to our customers. I would like documentation about the bot feature to make it easier for the customer to understand.
For how long have I used the solution?
I have been using F5 Advanced WAF for two years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
F5 Advanced WAF is scalable.
How are customer service and support?
We tend to handle our own technical support for our customers. My experience with F5 support is a three out of five overall. They need to improve the information and training of the receiver.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was neither easy nor difficult. I would rate setup as a four out of five.
What's my experience with pricing, setup cost, and licensing?
The pricing of F5 Advanced WAF is more expensive than other solutions like Radware and CD18, it is quite high. I rate the product a one out of five for price, with one being expensive.
What other advice do I have?
Overall, I would rate F5 Advanced WAF an eight out of ten overall.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Director at ST Electronics
Is flexible, powerful, stable, and scalable
Pros and Cons
- "It's flexible and powerful, and the users can input their own rules to the system."
- "The pricing could be more flexible."
What is our primary use case?
I use it for load balancing.
What is most valuable?
It's flexible and powerful, and the users can input their own rules to the system.
What needs improvement?
The pricing could be more flexible.
For how long have I used the solution?
I've been using it for three to four years.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
F5 Advanced WAF is a scalable solution. We have 20 people using it in our company, mainly from our operations team.
How are customer service and support?
F5 has a partner in Singapore, and he's very supportive.
How was the initial setup?
It is reasonably easy to set up and took about a month.
What about the implementation team?
I used a third party for the deployment.
What's my experience with pricing, setup cost, and licensing?
The cost is slightly above average.
What other advice do I have?
I would rate this solution at eight on a scale from one to ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Territory Manager at a computer software company with 51-200 employees
Useful balancer, simple policy changes, and scalable
Pros and Cons
- "The most valuable features of F5 Advanced WAF are the balancer and you can change policies very easily."
- "The overall price of F5 Advanced WAF could improve."
What is our primary use case?
F5 Advanced WAF can be deployed on-premise or in the cloud. When it comes to local governmental organizations, it's mostly on-premises solutions they use. However, we recommend using virtual ones.
F5 Advanced WAF is used for protecting applications.
What is most valuable?
The most valuable features of F5 Advanced WAF are the balancer and you can change policies very easily.
What needs improvement?
The overall price of F5 Advanced WAF could improve.
For how long have I used the solution?
I have been familiar with F5 Advanced WAF for approximately one year.
What do I think about the stability of the solution?
I have not had any customers complaining about the stability.
What do I think about the scalability of the solution?
F5 Advanced WAF is scalable.
How was the initial setup?
The initial setup of F5 Advanced WAF is easy.
I rate the setup of F5 Advanced WAF a four out of five.
What about the implementation team?
The ease of maintenance of F5 Advanced WAF depends from customer to customer. If the company had someone trained or they have an inside person who is reliable for this maintenance, they typically do not have any problems.
What's my experience with pricing, setup cost, and licensing?
The price of F5 Advanced WAF could improve it is expensive.
There can be extra features added at an additional cost.
I rate the price of F5 Advanced WAF a three out of five.
Which other solutions did I evaluate?
Our clients pick this solution over others because it is one of the leading companies in the category.
What other advice do I have?
I can recommend F5 Advanced WAF to any customer because we have experience, and referrals from customers using it within different models. If it comes to WAF, LTM, or whatever. I'm very happy to sell it because it is one of the leading vendors within its line. Our customers within the financial market, such as banking organizations, are very happy with it.
I rate F5 Advanced WAF a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Technology Consultant at Netwiser
Enhanced web security and significant bot detection capabilities and good support
Pros and Cons
- "Web attack signatures are very important for detecting web attacks."
- "The product could be more user-friendly, particularly the user interface for administrators."
What is our primary use case?
We use the solution for load balancing and web application firewall (WAF) balancing. We operate in a data center and use it for web application security and services.
How has it helped my organization?
The solution provides strong web security, particularly against web attacks, and has effective bot detection that helps reduce bot attacks.
What is most valuable?
Web attack signatures are very important for detecting web attacks. The bot detection feature is also crucial in reducing bot attacks.
What needs improvement?
The product could be more user-friendly, particularly the user interface for administrators. Additionally, configuration can be quite complex and needs improvement to be less complex.
For how long have I used the solution?
I've been using it for almost three years.
What do I think about the stability of the solution?
The product is very stable. From one to ten, I would rate its stability at a nine out of ten.
What do I think about the scalability of the solution?
The solution is scalable. We use it for multiple customers and data centers, and I would rate its scalability as nine.
How are customer service and support?
The customer service is good. That siad, sometimes it takes too long to reach the right person. I would rate their effectiveness as an eight.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I am familiar with Citrix NetScaler and F5.
How was the initial setup?
The initial setup was not too challenging. Post-initial configurations can be complex.
What about the implementation team?
Two to three engineers are typically involved in maintenance operations.
What's my experience with pricing, setup cost, and licensing?
I don't know the exact pricing. It is not the cheapest yet not the most expensive. It depends on needs, budget, and vision.
Which other solutions did I evaluate?
I have experience with Citrix solutions.
What other advice do I have?
I recommend this product to others.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Last updated: Oct 31, 2024
Flag as inappropriateFounder at Fencesense
iRules has the ability to prevent the end-user and infrastructure from external threats
Pros and Cons
- "iRules are quite appealing when it comes to F5."
What is our primary use case?
For me, the primary use case is to secure web applications from external threats, including cross-site scripting, SQL injection attacks, file inclusion vulnerabilities, and many more. The tool has simplified protection against web applications and recent threats that might be visible. If your applications are vulnerable, it gets protected by F5.
What is most valuable?
It is a very flexible solution. iRules is quite appealing when it comes to F5, and they apply it throughout their solution. BIG-IP is a known platform, and it is a part of F5 now. Application delivery or web application firewalls, F5 understands these terms and then suggests better data policies. But you have to do the work on your application's performance first. You have to look in the logs and understand the total attack you should prevent when we put it in the circuit protection mode, which works perfectly well.
iRules truly excites me because it has the ability to prevent the end-user and infrastructure from external threats.
Even if the F5’s default signatures and the default behavior are unable to help you, you can customize iRules to reach the objectives.
What needs improvement?
I don't like the management control of F5.
Moreover, if you are not an expert, it would be really difficult to set it up.
For how long have I used the solution?
I have been using the product for fifteen years or more.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is definitely a scalable solution.
How was the initial setup?
The initial setup is quite straightforward. I didn't experience any complexity. It could be difficult for somebody who is not familiar with application load balancers or web applications. It takes a month to understand the entire architecture. It primarily depends upon how great deployment could be.
What about the implementation team?
It usually takes about five to seven days to configure and deploy the F5 Advanced WAF in production mode. It is essential to ensure that your configuration works properly before putting it into production mode.
When you have already designed it, it takes around five to seven days to set up. But it takes more than a month to understand the entire architecture of the F5.
What other advice do I have?
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
SOC Analyst at a financial services firm with 1,001-5,000 employees
Gives the ability to play around with the ciphers and has a immediate display of the support IDs when a real blockage occurs
Pros and Cons
- "My favorite feature of F5 is the ability to play around with the ciphers. I also like the ability to have an immediate display of the support IDs when a real blockage occurs. The protection offered is great."
- "The reporting portion of F5 Advance WAF is not great. They need to work out something better, as it is very basic. You only see the top IPs, I think there is more they can offer."
What is our primary use case?
We host public-facing web applications or APIs. There are web applications that are owned by the company that is exposed to the outside. The internal infrastructure is within the premise. We use F5 to protect them. It's an HA model, and we have two sites.
How has it helped my organization?
We need to have an extra layer of protection. We were previously exposed to the public API. The deployment and the rate of deploying web-based applications had increased. After we introduced the web application firewall, it increased our ability to expose more of the services to the public.
What is most valuable?
My favorite feature of F5 is the ability to play around with the ciphers. I also like the ability to have an immediate display of the support IDs when a real blockage occurs. The protection offered is great.
What needs improvement?
The reporting portion of F5 Advance WAF is not great. They need to work out something better, as it is very basic. You only see the top IPs, I think there is more they can offer.
For how long have I used the solution?
I have been using F5 Advanced WAF for four years, since 2018.
What do I think about the stability of the solution?
F5 Advanced WAF is a stable solution.
What do I think about the scalability of the solution?
For the initial deployment, from what we were planning to implement, it was scalable.
We now have other requirements that we need to engage with. They believe we need to increase our license, so we can accommodate more features.
How are customer service and support?
There have been issues in the availability of quick support. For general issues there is no concern. The issue is when you need support right away, but it is not available.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution was deployed using network security. At the time of deployment, the appliance was there, but we did not have any person that was able to accomplish the deployment. It took six months to deploy.
What was our ROI?
We have definitely seen a ROI by using F5 Advanced WAF.
What's my experience with pricing, setup cost, and licensing?
As far as the pricing of F5 Advanced WAF I would rate it a four out of five depending on what features I am looking for. Imperva is more expensive.
The price has remained consistent at a constant rate. There have not been any increases or any unforeseen increases when we're renewing our license. The price is fixed.
Which other solutions did I evaluate?
I reviewed Imperva only to compare pricing.
What other advice do I have?
On the initial engagement, you should try to look on how best you can accommodate the quick support features, as this was a big struggle for us.
Overall, I would rate F5 Advanced WAF an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free F5 Advanced WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
AWS WAF
Fortinet FortiWeb
NetScaler
Imperva Web Application Firewall
Cloudflare Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Buyer's Guide
Download our free F5 Advanced WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Does F5 Advanced WAF work with Azure App Service?
- Which is better, Barracuda Web Application Firewall or F5 Advanced WAF?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?