We use Imperva DDoS for DDoS protection and security.
Manager- Secure Web Defense- Perimeter Security at a financial services firm with 10,001+ employees
A fairly stable solution that can be used for DDoS protection and security
Pros and Cons
- "Imperva DDoS is fairly stable, and its availability is quite high."
- "Imperva DDoS does not provide version control."
What is our primary use case?
What is most valuable?
Imperva DDoS is fairly stable, and its availability is quite high. I haven't faced any downtime or system instability issues with the solution.
What needs improvement?
Imperva DDoS does not provide version control. After I make any changes on any portal, I would want to roll back my changes and go back to a stable version if something goes wrong. That particular feature is not there on the UI portal.
They have this roundabout way wherein I can use different tools to integrate, do the versioning, and manage it on my own. It's not directly available, but I can use it indirectly.
For how long have I used the solution?
I have been using Imperva DDoS for two to three years.
Buyer's Guide
Imperva DDoS
January 2025
Learn what your peers think about Imperva DDoS. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,997 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Imperva DDoS is a scalable product.
How was the initial setup?
The solution's initial setup is a bit difficult and not very easy. It's not that time-consuming if you have expertise. Once you get your hands on it, it's pretty straightforward.
What other advice do I have?
Imperva DDoS is deployed on-cloud in our organization.
I would recommend Imperva DDoS to users because it's a fairly stable product.
Overall, I rate Imperva DDoS an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Senior Manager at a outsourcing company with 10,001+ employees
Enables us to monitor all web activity, which is passed through WAF cloud services
Pros and Cons
- "The most valuable features are DDoS protection."
- "Incapsula services also provides load balancing services for their service IP address environment. So far, with monitoring their services, the IP address was only changed once."
What is our primary use case?
All our web services go to the Incapsula cloud application environment for monitoring on the production service.
All the web application protection is under Incapsula because they provide the WAF protection services. Our web services are registered under their cloud environment so all our customers visit our web services. All the web services are under the web application firewall protector.
I think it's from their own cloud solution. I don't think the cloud solution is from Amazon because the IP address does not belong to Amazon. It belonged to Incapsula themselves, so their solution is under their own network cloud environment. Our own data center environment is using the Incapsula cloud service. I think it's a hybrid cloud to include all the private and the public services.
What is most valuable?
The most valuable features are DDoS protection. The Incapsula environment helps us monitor all the web activity. All the web activity is passed through their WAF cloud services, then that can help us to monitor those activities. That can help protect against DDoS hacking.
For how long have I used the solution?
We started implementing WAF under Incapsula in 2019 or 2020.
What do I think about the stability of the solution?
It's very stable because Incapsula services also provides load balancing services for their service IP address environment. So far, with monitoring their services, the IP address was only changed once. Their services are very stable.
What do I think about the scalability of the solution?
We implement the WAF production environment, or the web services, which is needed to provide traffic to the customer. We implement those services under the Incapsula WAF protection.
We have about one thousand people using the solution globally.
How are customer service and support?
If the scale is 1 to 10, technical support is a 9. Our global service team is more than 10 people. We have a whole Incapsula service team as well as our all global staff team.
Which solution did I use previously and why did I switch?
We are using our own firewall with the web application services. We used our own firewall before implementing with Incapsula, but we are also implementing it now under Incapsula cloud solutions.
How was the initial setup?
It's very simple because the domain name service is done with the CNAME. We just registered back in our DNS environment. After that, if the domain is resolved by our customer, then they will resolve the domain name which is provided by the Incapsula environment. That means all the network traffic will go through the Incapsula cloud services, and all the network activity can be monitored and protected by Incapsula WAF.
Deployment is simple and very fast. After they define the domain and service, we do some changes, and it takes within one hour. Within 15 minutes, it can transfer all the services from our site. All the network routing paths will pass through the Incapsula WAF cloud environment. It's very fast.
What's my experience with pricing, setup cost, and licensing?
The license is on a yearly basis.
What other advice do I have?
I would rate this solution 9 out of 10.
Because of all these services, you need to look at the company's services budget. If you have the budget and you can implement the web application for tech, or if you just want to move to the cloud, or you're just using your own firewall to do all those protections, Incapsula is a good option. This one just depends on the IT infrastructure budget in your own company or environment.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Imperva DDoS
January 2025
Learn what your peers think about Imperva DDoS. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,997 professionals have used our research since 2012.
Vice President, Global IT Security at a insurance company with 5,001-10,000 employees
Scalable, with good protection on offer and stable performance
Pros and Cons
- "The solution is very good at intercepting traffic before it gets to our data centers."
- "The salespeople tend to exaggerate its capabilities, which can cost you money if you don't verify the information."
What is our primary use case?
We primarily use the solution for all our corporate websites for port 80 and 443 redirect and protecting all the web pages that we have in our environment.
What is most valuable?
The solution is very good at intercepting traffic before it gets to our data centers. It saves us some security hits and top-level bad guy stuff. It's very good at protecting us. It keeps anything malicious off of our infrastructure.
What needs improvement?
We did have a major complaint, however, they fixed it after about a year and a half of complaining. It's not a problem anymore. I don't recall really having any issues with the solution beyond what they have fixed.
The salespeople tend to exaggerate its capabilities, which can cost you money if you don't verify the information.
For how long have I used the solution?
I've dealt with the solution for two years at this point.
What do I think about the stability of the solution?
The stability of the solution is very good. I've never heard of any outages that I'm aware of. It doesn't crash or freeze. There aren't bugs or glitches. It's reliable.
What do I think about the scalability of the solution?
The scalability is just based on the number of licenses and in our case, we've maxed out our licenses. They are extremely expensive, and therefore it would be costly to scale.
How are customer service and technical support?
I haven't had to call technical support, however, from what I've heard, they're okay. They are not great, not bad, just right down the middle.
How was the initial setup?
The infrastructure team did all the certificates on that side. My team took care of security. It's the security settings we set up. There was a lot of complexity in the initial configuration based on our proprietary apps and having to disable or change some settings to allow some stuff to work. That's kind of a normal thing. No matter what WAF you would have, you'd have the same issue.
What's my experience with pricing, setup cost, and licensing?
The licensing of the solution is quite high. Licenses are quite expensive. I'm not sure if they really offer the value that they ultimately charge.
The cost is somewhere around $10,000 a site. For every site, you pay individually. For every DNS entry, you have you pay.
What other advice do I have?
We are just customers and end users.
We're using the WAF. It's the web-based version. Whatever's the current and newest version is what we're using.
I'd advise potential new users to not believe salespeople. That's kind of a standard thing across the industry, however, we were told one thing at the sales side, and then, after we purchased, it was not true what they said. That's extremely disappointing as it actually costs us tens of thousands of dollars more due to the fact that what they said could happen, how their licensing model works, doesn't work the way the sales guy said. That's a giant disappointment.
Overall, the solution does what it says it will do. I'd rate it at an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Consultant at a tech services company with 10,001+ employees
Provides valuable cache control features like cache purging and cache rule propagation. The dashboard is not accessible on occasion.
What is most valuable?
- Extensive cache control like cache purging and cache rule propagation
- Availability features
- Cross-datacenter solution (active and passive environments)
- CDN and DDoS protection with 24/7 support
How has it helped my organization?
Automatic failover between primary and secondary sites enables high availability and accelerates disaster recovery. As soon as it detects that the primary site has gone down, it automatically kick-starts our standby data center.
What needs improvement?
The dashboard is not accessible on occasion. This is probably due to a high load. However, the sites’ protection seems intact.
For how long have I used the solution?
We have been using this solution for four years.
What do I think about the stability of the solution?
There are no stability issues as of now.
What do I think about the scalability of the solution?
There are no scalability issues, but the custom SSL has a terrible price point that puts it out of range for our clients. If they need custom or EV SSL, they are paying significantly more than their overall hosting.
How are customer service and technical support?
The technical support is impressive.
Which solution did I use previously and why did I switch?
We used Akamai previously, but due to full PCI DSS compliance, we needed a proprietary solution for two-factor authentication. We then switched to Incapsula.
How was the initial setup?
The setup was so straightforward. It didn’t require to us to make any major changes.
What's my experience with pricing, setup cost, and licensing?
If you don't have custom SSL, get it!
Which other solutions did I evaluate?
We switched to Incapsula from Akamai.
What other advice do I have?
Imperva has a very impressive core feature set. Imperva has made security analysts scratch their heads. We allow them in from the inside so they can actually hit something worthwhile.
We are very confident in the reports we get from Imperva. Its bot identification has allowed us to plan bandwidth appropriately.
Identification for good bots (people who hit our site using automation, but for good business reasons) has allowed us to work with our customers who use our services in new ways.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager Technique at a computer software company with 11-50 employees
Good support, easy and quick deployment, and valuable DDoS protection and WAF features
Pros and Cons
- "DDoS protection and WAF are the most valuable features. It is easy to deploy a service. It is easy and quick to deploy to a new website."
- "Its price could be improved. It is quite expensive. It will be good if we could export the configuration. Currently, to control the configuration, we need to go to each website, which is not very convenient."
What is our primary use case?
Our primary use case is DDoS protection. We are using it to protect access to internet sites. It is a SaaS solution, so everybody has the latest version.
What is most valuable?
DDoS protection and WAF are the most valuable features. It is easy to deploy a service. It is easy and quick to deploy to a new website.
What needs improvement?
Its price could be improved. It is quite expensive.
It will be good if we could export the configuration. Currently, to control the configuration, we need to go to each website, which is not very convenient.
For how long have I used the solution?
I have been using this solution for six years.
What do I think about the scalability of the solution?
Its capacity is okay for us, and we don't need to scale it or expand its usage.
How are customer service and technical support?
Their technical support is good. We get a quick response from them.
How was the initial setup?
It was simple. It is very easy and quick to deploy.
What about the implementation team?
It was done in-house.
What's my experience with pricing, setup cost, and licensing?
It is expensive.
What other advice do I have?
I would recommend this solution to others. It has been working fine for us, and it has all the features that we need. I would advise others to know the exact bandwidth that is required for the project because the cost is based on the bandwidth. You must evaluate the required bandwidth beforehand.
I would rate Imperva Incapsula a nine out of ten. Technically, it is a very good solution.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Application Security Architect at a hospitality company with 10,001+ employees
The WAF can identify, block, whitelist or blacklist as needed.
What is most valuable?
Hands down, the WAF is the most valuable feature; being able to identify, block, whitelist or blacklist as needed, are all valuable.
How has it helped my organization?
We now have visibility into our traffic in a scope that we never had before, especially being able to review bot vs human traffic and country of origin.
What needs improvement?
Reporting and the main Sites dashboard could use refinement. We have a lot of sites, and scrolling through the dashboard becomes cumbersome.
For how long have I used the solution?
I have used it for six months.
What was my experience with deployment of the solution?
The only deployment issue we encountered was getting Incapsula and Akamai to play nice. However, the Incapsula engineers were very helpful in helping us configure our sites in the WAF correctly.
What do I think about the stability of the solution?
We have not encountered any stability issues.
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and technical support?
Customer Service:
I have yet to need customer service.
Technical Support:I rate the level of technical support as very high.
Which solution did I use previously and why did I switch?
We had not used a WAF before deploying Incapsula.
How was the initial setup?
The setup was straightforward and simple.
What about the implementation team?
We implemented it ourselves with the guidance of the Incapsula team.
What was our ROI?
It is too soon to tell regarding ROI.
What's my experience with pricing, setup cost, and licensing?
Know your bandwidth requirements.
Which other solutions did I evaluate?
Before choosing this product, we evaluated so, so, so many other options.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Web Manager at a university with 501-1,000 employees
CloudFlare vs. Incapsula
What is most valuable?
Incapsula:
- Strength of DDoS and WAF
- Simple dashboard
- Analytics
- SSL
CloudFlare:
- Ease of use
- Simple dashboard
- DNS management
- CDN
- SSL
How has it helped my organization?
Incapsula:
It has provided heightened visibility and awareness at management level on the actual threat landscape; it paves the way for easier approval for security-related implementations/projects.
It provides free SSL certs that can be used on website domains that I did not purchase SSL certs for.
Some protection and CDN caching realized, even though I’m on the free tier.
What needs improvement?
Incapsula:
- Allow easier scripting of firewall rules.
- Enable more custom actions to trigger turning on/off Incapsula settings (current actions are quite limited).
- Allow setting up of user groups to manage different groups of sites with viewer/operations/admin levels of privileges. This is quite a typical requirement for enterprise clients who will have multiple teams taking care of different sites, plus an overall IT security team who oversees everything.
CloudFlare:
- Improve the strength of WAF/DDoS.
- Reduce the rate of false positives.
For how long have I used the solution?
I have used Incapsula for about a year.
I have used CloudFlare for almost a year.
What do I think about the stability of the solution?
Incapsula: The dashboard occasionally is not accessible (probably due to high load) but the sites protected seem intact.
CloudFlare: I have not used it enough to provide useful information.
What do I think about the scalability of the solution?
Incapsula: The only issue so far is with the dashboard.
CloudFlare: I have not used it enough to provide useful information.
How are customer service and technical support?
Incapsula: Technical support provides fast response via email tickets, and fairly responsive local technical/account reps.
CloudFlare: I have hardly utilized their technical support so far.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
For both Incapsula and CloudFlare, initial setup was very easy.
What's my experience with pricing, setup cost, and licensing?
Incapsula:
Pricing is described on their website, but for enterprise agreements, clarify with local reps, as there might be a need for customized needs/pricing. Be clear on how they handle domains and subdomains.
CloudFlare:
Pricing and licensing is very clearly described on their website; 1 site = 1 domain. Clarify how to support subdomains.
Which other solutions did I evaluate?
We evaluated Incapsula and CloudFlare.
What other advice do I have?
Incapsula:
You need to understand how DNS works (e.g., A records vs CNAME, TXTs etc.), how SSL works and how to set it up, and how web servers work with domains and proxy servers. It is not for the layman, as the dashboard assumes some level of understanding in these topics. Some settings can break your site, so do perform some tests on a development site before turning features on/off in the dashboard. The good thing is that most settings are reversible and take effect quite quickly, so if things do go wrong, it will not stay broken for too long.
Also, use extra caution when dealing with TLDs, as the product does not handle your DNS, so for onboarding of domains using A records, you may need to ask Incapsula support for advice and assistance as it requires assigning the A record to a CNAME or IP address (network folks might understand the problem here).
CloudFlare:
You need to understand how DNS works (e.g., A records vs CNAME, TXTs etc.), how SSL works and how to set it up, and how web servers work with domains and proxy servers. It is not for the layman, as the dashboard assumes some level of understanding in these topics. Some settings can break your site, so do perform some tests on a development site before turning features on/off in the dashboard. The good thing is that most settings are reversible and take effect quite quickly, so if things do go wrong, it will not stay broken for too long.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CTO at CyberApp
Scalable solution for good technical support services
Pros and Cons
- "It is a stable solution."
- "It needs to be improved every time there are new attacks."
What is most valuable?
The solution has the best volumetric DDoS attacks feature.
What needs improvement?
The solution needs to be improved every time there are new attacks. They need to add new features and techniques to prevent the attacks.
For how long have I used the solution?
We have been using the solution for seven years.
What do I think about the stability of the solution?
I rate the solution's stability an eight out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. It is suitable for medium and enterprise businesses.
How are customer service and support?
The solution's technical support services are fine.
Which solution did I use previously and why did I switch?
Compared with the competitors, the solution provides better security features, including web protection firewall and DDoS protection.
How was the initial setup?
The solution's initial setup process is complicated. You need to include the right security policy and discover the attack trends. The time taken for implementation depends on the project requirements.
What's my experience with pricing, setup cost, and licensing?
The solution's price is reasonable. Although, it is a bit expensive for small companies. The cost of its licenses depends on the specific project requirement.
What other advice do I have?
I advise others to study their requirements while choosing DDoS protection thoroughly. They should know if the CDN is limited to their region or has a global reach. Also, DDoS attacks appear in different ways every single time. Thus, it is challenging to implement. It is crucial to know its surface, nature, and how to implement the security measures.
I rate the solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Imperva DDoS Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Distributed Denial-of-Service (DDoS) Protection CDN Web Application Firewall (WAF)Popular Comparisons
Cloudflare
Arbor DDoS
Akamai App and API Protector
Radware DDoS Protection Service
AWS Shield
Azure DDoS Protection
Fastly
F5 Silverline Managed Services
Prolexic
Fortinet FortiDDoS
Corero
Sucuri
Nexusguard DDoS Protection
A10 Thunder TPS
Buyer's Guide
Download our free Imperva DDoS Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- F5 vs. Imperva WAF?
- We are looking at managed DNS providers and want to know what others are using
- Prolexic vs. Arbor Networks: How do they compare?
- Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
- How does a WAF help to protect against DDoS attacks?
- DDoS solutions: Any other solutions to consider aside from Radware DefensePro and F5 Silverline DDoS Protection?
- Which is the best DDoS solution and why?
- When evaluating DDoS Protection, what aspect do you think is the most important to look for?
- What is the difference between denial of service and distributed denial of service?
- How does BGP routing help to mitigate DDoS attacks?