Try our new research platform with insights from 80,000+ expert users
reviewer1407915 - PeerSpot reviewer
Information System Security Manager at a pharma/biotech company with 10,001+ employees
Real User
A very secure platform for protecting our website and web applications
Pros and Cons
  • "It blocks all types of attacks."
  • "It's quite expensive."

What is our primary use case?

We are using this solution for web application firewall protection for the website and web application. I'm a user of this product and work as an information systems security manager. 

What is most valuable?

I'm very happy with the solution. The most valuable aspect of it is that it blocks all types of attacks.

What needs improvement?

I think the product could be improved by reducing the price. It would help if they came up with pricing options because as it is now if you're a big company and use the site often, it's more expensive. 

For how long have I used the solution?

I've been using this solution for almost four years. 

Buyer's Guide
Imperva DDoS
January 2025
Learn what your peers think about Imperva DDoS. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,997 professionals have used our research since 2012.

What do I think about the stability of the solution?

Stability and scalability are fine. 

How are customer service and support?

I don't use the technical support, but my colleagues do and they haven't mentioned any problems. 

What other advice do I have?

I would rate this solution a nine out of 10. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user574089 - PeerSpot reviewer
Security Architect at a financial services firm with 501-1,000 employees
Vendor
The anti-DDoS protection has distributed nodes around the world.

What is most valuable?

Infrastructure protection (anti-DDoS): Imperva anti-DDoS protection has the well-known value of having lots of distributed nodes around the world, making it the best value for DDoS protection. They also include protection against almost all known DDoS attack methods.

How has it helped my organization?

The product has given us DDoS protection.

What needs improvement?

The management interface needs improving. Even with a recent version of the interface, you cannot do all the changes that you would like. As an example, if you want to change one of your protected public IP addresses, you need to request this from support, and it takes a long time.

For how long have I used the solution?

I have used it for 10 months.

What do I think about the stability of the solution?

There were stability issues. One node went down and we completely lost the connectivity of our public IP addresses.

What do I think about the scalability of the solution?

We have not encountered any scalability issues.

How are customer service and technical support?

We rate technical support as really bad. It took one month to solve an issue with one node and give us an alternative solution. Apart from the management interface, support service has to improve their response times (based on our experience with them).

Which solution did I use previously and why did I switch?

We did not previously use any other solutions.

How was the initial setup?

Initial setup was simple, except for the GRE tunnel issues and MTU tuning.

What's my experience with pricing, setup cost, and licensing?

We think that this product is fairly priced considering other products.

Which other solutions did I evaluate?

We evaluated Arbor Networks.

What other advice do I have?

Check the SLAs carefully.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Imperva DDoS
January 2025
Learn what your peers think about Imperva DDoS. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,997 professionals have used our research since 2012.
it_user504216 - PeerSpot reviewer
Systems Administrator at a financial services firm with 501-1,000 employees
Vendor
Added security is the biggest bonus, as our websites have highly sensitive data.

Valuable Features

The added security is the biggest bonus feature, as our websites are not usually under extreme load but do have highly sensitive data. A good WAF can be difficult enough to configure even without many of the advanced security features that Imperva Incapsula includes: SQL injection prevention, bot attack recognition and notification, and DDoS.

Improvements to My Organization

Our audit experience is made much more simple due to having this solution. It is an answer to many security issues. We have all of the same sites available and audited internally. This extra layer of security helps with the external 'monitoring and alerting' and keeps that heavy administration portion to those who can handle it at scale a lot easier.

Room for Improvement

The API is lackluster but especially for 'customers'. The only thing we wanted to use the API for was only available to resellers.

Use of Solution

I have been using it for 5+ years.

Stability Issues

I have not encountered any stability issues at all.

Scalability Issues

We have a multitude of DNS names for essentially the same site. Despite that, we have to pay for each of these separately as different sites. This model is unfortunate for us but we find the service to be worth it. I could see this being a potential issue, while it is not yet.

Customer Service and Technical Support

I have had to contact support only once for API support and it was a good experience.

Initial Setup

Initial setup was simple but admittedly handled by a different person. I have set up and decommissioned sites with ease.

Pricing, Setup Cost and Licensing

You get a better bang for your buck with converged DNS site names. If you use separate DNS for smaller portions of a site, it will increase your licensing cost.

Other Solutions Considered

Before choosing this product, I did not evaluate other options.

Other Advice

Keep your sites strongly secured but sleep easier knowing Imperva Incapsula continuously baffles our penetration testers.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Senior Manager, Software Development at a music company with 1,001-5,000 employees
Vendor
We've found the caching, CDN, and Web Application Firewall features valuable, giving us an extra layer of PCI compliance.

Valuable Features

  • Caching and CDN
  • WAF

Improvements to My Organization

We are using caching and CDN heavily, for certain campaigns we ended up in 80%+ of all the traffic served by Incapsula without passing to the origin servers.

We were PCI-complaint before using Incapsula; however, it is always better to have one more layer of security.

No DDOS attacks for now, but let's see once we face it.

Room for Improvement

Caching rules are really basic now and lots of space for improvement here.

- For example, Incapsula does not check the protocol (HTTP vs. HTTPS) when serving cached pages.

- There is no possibility to create a caching rule based on a regular expression.

Deployment Issues

No issues encountered.

Stability Issues

No issues encountered.

Scalability Issues

No issues encountered.

Customer Service and Technical Support

Their support team is great and you get a response/resolution within five minutes of submitting a support ticket.

Pricing, Setup Cost and Licensing

You can save some licenses/money if you have your own load balancer. No matter how many websites your load balancer is serving, you will need only one Incapsula ‘website’. We’ve managed to use two Incapsula ‘websites’ to serve approximately 150 real websites.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user67500 - PeerSpot reviewer
Developer with 51-200 employees
Vendor
We Use Incapsula's DDoS Protection Service to Maximize Availability and Performance

In September 2013, our online store was the victim of a prolonged three-week application-level DDoS attack. Mitigating this type of Layer 7 DDoS attack is a major challenge for security solutions, since malicious bot traffic often appears to be requests from legitimate users. During this attack, our existing anti-DDoS solution was not able to effectively filter out the malicious traffic, which meant that innocent e-commerce customers were blocked from accessing the sites or were forced to unnecessarily fill out CAPTCHA challenges.

As an e-commerce company, website security is central to our core business. We needed a DDoS protection solution that would enable us to maintain "business as usual" even under attack, with minimum disruption to the user experience. Minimizing false positives was a crucial requirement, since the easiest way to lose a customer is to block her from accessing the site.

Realizing that our previous solution was not equipped to handle this type of sophisticated application-level DDoS attack, we sought a DDoS Protection service capable of correctly filtering all types of DDoS attacks from legitimate website traffic, without affecting the online experience for our customers.

During our search for a new solution, we came across Incapsula and were impressed by industry comparisons such as the one appearing on TopTenReviews.com showing the clear superiority of Incapsula over our existing service in terms of professionalism, performance and security.

We decided to give Incapsula a try and initially activated their service on our French domain. It quickly became clear to us that Incapsula was the right solution to handle the DDoS attacks that we face. After only six days, we signed a contract and moved our other domains to Incapsula's service as well.

We are now using Incapsula's always-on DDoS Protection service to secure our online stores against the largest and smartest types of DDoS attacks - including network, protocol and application level (Layers 3, 4 & 7) attacks – with minimal business disruption.

Incapsula is now a key component of our security infrastructure. When under DDoS, traffic is routed through Incapsula for screening, where malicious traffic and DDOS attacks are blocked automatically.

By using Incapsula's DDoS Protection, we have achieved concrete benefits:

  • Intelligent mitigation of sophisticated application layer attacks - Incapsula uses advanced traffic analysis algorithms, granular mitigation rules and an enterprise-grade WAF to differentiate legitimate website visitors (humans, search engines, etc.) from automated or malicious clients.
  • Transparent mitigation with less than 0.1% False Positives - Incapsula applies a set of progressive and non-intrusive challenges that are designed to ensure the optimal balance between strong DDoS protection and an uninterrupted user experience, without the need for annoying delay and CAPTCHA screens.
  • "Always on" DDoS protection - Automatic "always on" DDoS mitigation and 24x7 monitoring are effective in stopping "hit & run" DDoS attacks can wreak havoc with solutions that need to be manually turned on and off on every burst.
  • Cloud-based mitigation of network DDoS attacks - Incapsula mitigates high-volume network attacks through a global network of multi-gigabyte scrubbing centers
  • Dedicated NOC team – An experienced team of Network Operations Center (SOC) engineers performs 24x7 security monitoring and assists with DDoS mitigation as needed.

Since activating Incapsula on our sites, we have solved our DDoS problem and couldn't be more pleased with our overall website performance and security. Equally important, Incapsula's technical support and commercial teams have been very responsive throughout the initial rollout phase.

Disclosure: PeerSpot has made contact with the reviewer to validate that the person is a real user. The information in the posting is based upon a vendor-supplied case study, but the reviewer has confirmed the content's accuracy.
PeerSpot user
it_user2652 - PeerSpot reviewer
it_user2652Project Manager at a non-tech company with 10,001+ employees
Top 20Vendor

Nice and informative information. Could you share your customer service experience for the product Incapsula regarding license renewal and for critical DDOS incidents?

Associate Engineer - Network & Security at Connex Information Technologies
Real User
Secure, reliable, and has helpful technical support
Pros and Cons
  • "Technical support was very helpful."
  • "We had an issue when securing the web applications for DDoS protection."

What is our primary use case?

Imperva Incapsula is used for web applications. 

Our customers required the security of their web applications. We were asked to install this solution for their web solutions based on their throughputs and requirements.

What needs improvement?

We had an issue when securing the web applications for DDoS protection.

When using protection for some web applications, the customer may encounter a few issues.

For how long have I used the solution?

I have been working with Imperva Incapsula for several months.

We have deployed the cloud version, and we use the on-premise version for testing.

What do I think about the stability of the solution?

Imperva Incapsula is a stable solution.

What do I think about the scalability of the solution?

Imperva Incapsula is scalable.

We have two or three users in our company.

In order to increase our usage, We must publicize the fact that we have such a solution. I believe we had to use LinkedIn or some other solution to publish it. We need to inform our customers that we have a solution like this.

How are customer service and support?

Technical support was very helpful.

How was the initial setup?

The initial setup is not overly complex, but it could be easier.

What's my experience with pricing, setup cost, and licensing?

There is a license or subscription renewal that our customers pay.

What other advice do I have?

I would recommend this solution to others who are interested in using it.

I would rate Imperva Incapsula an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
System Adminisrator at a tech services company with 51-200 employees
Consultant
We're using the security rules to block all secured areas by IP.

What is most valuable?

Security rules and DDoS protection.

How has it helped my organization?

Well, just by using the security rules to block all secured areas by IP minimized the chance of sensitive data leaking outside.

What needs improvement?

I'd like it to work with Let's Encrypt.

For how long have I used the solution?

1.5 years

What was my experience with deployment of the solution?

No issues.

What do I think about the stability of the solution?

No issues.

What do I think about the scalability of the solution?

No issues.

How are customer service and technical support?

Customer Service:

Once going enterprise, support is excellent.

Technical Support:

Once going enterprise, support is excellent.

Which solution did I use previously and why did I switch?

CloudFlare and I switched because we needed more locations.

How was the initial setup?

Took us 10 minutes and we just waited for the DNS update.

What about the implementation team?

In house.

What was our ROI?

No ROI since we use it for protection. Its an additional expense with no ROI expectations.

What's my experience with pricing, setup cost, and licensing?

Always check the enterprise option, it gave us great rates.

Which other solutions did I evaluate?

We used CloudFlare in the past and we thought about working with Reblaze.

What other advice do I have?

Try it for 30 days, it will amaze you.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
AVP Product Development and Architecture at a media company with 1,001-5,000 employees
Vendor
Provides WAF configuration. I would like them to improve the reporting interface and filtering.

What is most valuable?

WAF configuration is the most valuable feature.

How has it helped my organization?

  • Reduced spammers during competitions
  • Bot reduction

What needs improvement?

Improve reporting interface and filtering.

For how long have I used the solution?

I have used it for two years.

What was my experience with deployment of the solution?

We have not encountered any deployment issues.

What do I think about the stability of the solution?

Mostly, we have not encountered any stability issues, except the occasional leak from the HK pod.

What do I think about the scalability of the solution?

We have not encountered any scalability issues.

How are customer service and technical support?

Customer Service:

Customer service is good.

Technical Support:

Technical support is good.

Which solution did I use previously and why did I switch?

We previously used Fortinet.

What was our ROI?

Our ROI is about 45% since deployment on reduction of our cloud bill.

What's my experience with pricing, setup cost, and licensing?

Pricing and licensing is extremely competitive.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Imperva DDoS Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free Imperva DDoS Report and get advice and tips from experienced pros sharing their opinions.