Imperva Web Application Firewall is used for protecting web applications.
Presales Engineer at SNSIN
Flexible, good performance, and helpful support
Pros and Cons
- "The most valuable features of the Imperva Web Application Firewall are performance and flexibility. We can extend or customize the box itself."
- "Imperva Web Application Firewall could improve the console by making it easier to use."
What is our primary use case?
What is most valuable?
The most valuable features of the Imperva Web Application Firewall are performance and flexibility. We can extend or customize the box itself.
What needs improvement?
Imperva Web Application Firewall could improve the console by making it easier to use.
For how long have I used the solution?
I have been using Imperva Web Application Firewall for approximately six years.
Buyer's Guide
Imperva Web Application Firewall
January 2025
Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.
What do I think about the stability of the solution?
Imperva Web Application Firewall is stable.
What do I think about the scalability of the solution?
The stability of the Imperva Web Application Firewall is good.
We have approximately three or four clients using this solution.
How are customer service and support?
The support from Imperva Web Application Firewall is very good. They are handling support well, giving suggestions, and solving the issues.
How was the initial setup?
The initial setup of the Imperva Web Application Firewall is straightforward. The process for us is simple, we have been doing it for years.
What about the implementation team?
We have one person that does the deployment of the Imperva Web Application Firewall.
What's my experience with pricing, setup cost, and licensing?
We sell three-year licenses for Imperva Web Application Firewall to our customers. The price is a little expensive.
What other advice do I have?
I recommend this solution to others.
I rate Imperva Web Application Firewall an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Software Developer at a computer software company with 1,001-5,000 employees
Stable, protects well against a variety of attacks, especially DDoS
Pros and Cons
- "The solution has been quite stable. I have not seen any bugs at all."
- "Sometimes our web application firewall will slow down."
What is our primary use case?
We primarily use the solution for database security.
Basically, the solution is a web application firewall that is used to protect against multiple types of attacks online. It is used for web attacks - mostly DDoS attacks, cross-site scripting attacks, or SQL injection attacks.
There is also multiple HTTP protocol compliance. If there is any violation it will be detected by this application. It is used for detecting an illegal file type, illegal URL, or bots.
The solution can prevent a geolocation attack also. If any application is not allowed from certain countries, it will not allow access. We can detect everything via the web application firewall.
What is most valuable?
The solution offers good security against a variety of web attacks.
The protection from DDoS attacks is very useful. The DDoS attack is a very powerful attack that can harm a company's services. If an application is deployed to any web server or database our service will slow and will go down. A user would not be able to access our service until we can fix the issue. It's a deal if a company can avoid getting hit with DDoS attacks and having something that can effectively protect a company is extremely useful.
The solution has been quite stable. I have not seen any bugs at all.
What needs improvement?
Until now, it is good. There are no issues. As an analyst, I simply monitor. I don't really get too far into the technical aspects of the solution.
Occasionally, I've noticed that the web application firewall was down. If we are not using proper storage, proper memory, proper CPU, and if multiple attacks happen at one time, they will be detected by our web application firewall. Sometimes our web application firewall will slow down. In that sense, it needs some improvement. We do have a precaution for if the solution goes down. We basically, need to increase the memory and the storage and the CPU utilization, so that we can prevent our company from malicious activity.
I cannot say which type of memory or storage should be improved. The requirements depend on the organization. What organizations need and which type of configurations would work best as per their requirements depend completely on that.
For how long have I used the solution?
I've been working with the solution for about three years or so. It's been a while. I've been mostly working with it over the last 12 months or so.
What do I think about the stability of the solution?
The solution is quite stable. There are no bugs or glitches - or at least, I haven't seen any problems on that front. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
Right now, it depends on the company and its needs. I can't speak to if there are plans to increase usage.
How are customer service and technical support?
I've never been in touch with technical support. I can't speak to how knowledgeable and responsive they are, having never communicated with them directly. As an analyst, it's not my responsibility to deal with technical issues directly.
Which solution did I use previously and why did I switch?
It's my understanding that this company has only used this solution. However, if I move somewhere else, it's possible that something else may be used.
How was the initial setup?
I wasn't part of the initial setup. I can't speak to how easy or difficult the process was.
What's my experience with pricing, setup cost, and licensing?
I am not sure of the exact licensing costs of the solution. The licensing is a management decision. The costs and payments are handled by them.
What other advice do I have?
We use the solution's latest version.
We have a partnership with Imperva within our company.
I'd rate the solution at a nine out of ten. We've been mostly quite happy with its capabilities.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Imperva Web Application Firewall
January 2025
Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.
Specialist Engineer at Entel Networks S.A
Valuable compliance features and has good stability
Pros and Cons
- "The compliance is the most valuable aspect."
- "It's a complicated tool to keep."
What is our primary use case?
The primary use was to cover the database. Imperva we recognized on the market as the best solution for techs on databases. The banks here in Chile always ask for these types of solutions.
What is most valuable?
The compliance is the most valuable aspect.
What needs improvement?
I just need it to be a stable and normal version. I'd want to hear about the new features to see which I would need.
For how long have I used the solution?
I've been using the solution for 2 years.
What do I think about the stability of the solution?
I find this solution stable. We have 2,000 users in financial services.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
The setup initially was simple, but when we tried to run it we had problems with the log parameters and it was complicated to use. The operation was complicated to use, but that is just the experience of my team. It took two months to deploy. The setup and installation of the technologies took one week, and after that, one month to set up the parameters and after that, in order to set up the logs, it took about two weeks. So two months total. We have three engineers, including an architect and a security engineer. We also had a fourth engineer that knew the application.
What's my experience with pricing, setup cost, and licensing?
We have a yearly license, but I'm unsure of the pricing.
Which other solutions did I evaluate?
We didn't evaluate other options, just Imperva.
What other advice do I have?
I would rate the solution as an 8 out of 10, simply because of the difficulty of operation management. It's a complicated tool to keep.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Technical Lead at M.Tech
Useful DDoS protection, good support, and reliable
Pros and Cons
- "The most valuable features of the Imperva Web Application Firewall are DDoS, malware, and the other malicious threat prevention it provides. Additionally, third-party integration is available. You can forward the log for further analysis."
- "Imperva Web Application Firewall can improve by providing better features, such as improved prevention of zero-day attacks. Additionally, it should include a VR meta-analysis."
What is our primary use case?
Imperva Web Application Firewall is used for customers who are looking to secure their multiple applications and want to block the threats, such as DDoS and ransomware attacks. Imperva Web Application Firewall delivers three main things, data security, data availability, and access control. For data security, it prevents malware and malicious threats. For the data availability, by preventing threats, such as malware, data can be available each and every time. You are able to have Access control, you have the ability to control the access.
What is most valuable?
The most valuable features of the Imperva Web Application Firewall are DDoS, malware, and the other malicious threat prevention it provides. Additionally, third-party integration is available. You can forward the log for further analysis.
What needs improvement?
Imperva Web Application Firewall can improve by providing better features, such as improved prevention of zero-day attacks. Additionally, it should include a VR meta-analysis.
For how long have I used the solution?
I have been using the Imperva Web Application Firewall for approximately 15 years.
What do I think about the stability of the solution?
Imperva Web Application Firewall is stable, and the performance is good.
What do I think about the scalability of the solution?
The solution is best suited for enterprise-sized businesses. It is a scalable solution.
How are customer service and support?
The Technical support is good from Imperva Web Application Firewall.
Which solution did I use previously and why did I switch?
I have used another solution previously which was good. However, Imperva Web Application Firewall had more features.
How was the initial setup?
The deployment of the Imperva Web Application Firewall is simple. However, it is not very user-friendly. It would be a benefit because the customers would have a better time with the installation.
What about the implementation team?
I did the implementation Imperva Web Application Firewall myself and it took approximately three days.
What's my experience with pricing, setup cost, and licensing?
Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price.
What other advice do I have?
I do the maintenance and upgrades of the solution if it requires it. I would recommend this solution to everyone.
I rate Imperva Web Application Firewall a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Manager, IS Security & Infrastructure at Fintech Kenya Limited
User-friendly with good performance and helps to secure digital assets
Pros and Cons
- "It mitigates all of the availabilities of risks around web applications."
- "Their portal is very limited and needs improvement."
What is our primary use case?
We are a reseller and integration partner, and we have customers who are using this solution in on-premises deployments.
How has it helped my organization?
This solution has helped in securing our clients' assets, which is key. It mitigates all of the availabilities of risks around web applications.
What is most valuable?
The most valuable feature of this solution is web application security.
This is a user-friendly solution.
This solution has good performance ratings.
What needs improvement?
I would like to see more support available for this product online. Some customers find this to be a real limitation.
The virtual processing could be improved.
Their portal is very limited and needs improvement.
For how long have I used the solution?
We have been using this solution for close to five years.
What do I think about the stability of the solution?
This is a very stable solution.
What do I think about the scalability of the solution?
The solution is very scalable, but of course, the scalability comes with a cost.
How are customer service and technical support?
I think that technical support needs to be improved by making it more localized, or regionalized. Our support is currently coming from the US, and it is not very good. They need to take care of their global customers.
Which solution did I use previously and why did I switch?
We previously used Fortinet, but this solution has better performance ratings.
How was the initial setup?
I don't want to say that the initial setup is straightforward, but it is manageable. It requires a bit of technical knowledge.
What other advice do I have?
This is a solution that I highly recommend.
The biggest lesson that I have learned from this solution is that Imperva is not a one-house solution. They create a specialized solution, and that comes with a lot of value.
I would rate this solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Consultant at FPG Technologies and Solutions LTD
Useful database monitoring, simple dashboards, and scalable
Pros and Cons
- "The most valuable features of Imperva Web Application Firewall are the monitoring of databases and the dashboards are easy to understand."
- "Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better."
What is our primary use case?
We are using Imperva Web Application Firewall to monitor databases.
What is most valuable?
The most valuable features of Imperva Web Application Firewall are the monitoring of databases and the dashboards are easy to understand.
What needs improvement?
Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better.
For how long have I used the solution?
I have been using Imperva Web Application Firewall for approximately three months.
What do I think about the stability of the solution?
Imperva Web Application Firewall is stable.
What do I think about the scalability of the solution?
The scalability of the Imperva Web Application Firewall is good.
How was the initial setup?
The initial setup of the Imperva Web Application Firewall is complex.
I rate the initial setup of Imperva Web Application Firewall a four out of five.
What other advice do I have?
I rate Imperva Web Application Firewall a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr. Consultant at a tech services company with 51-200 employees
Scan policies allow us to group multiple targets and standardize our database scanning. Technical support is probably the biggest drawback.
What is most valuable?
The most valuable feature is the grouping of multiple targets via the scan policy. It is valuable because of the large number of targets and governmental requirements to conduct periodic scans.
How has it helped my organization?
With acquisition of a license to use the product, we received the ability to standardize database scanning and data protection across the enterprise around one product.
What needs improvement?
Many features are buried under not-straight-forward options and, at times, hard to find screens. Very few import features have clearly defined format requirements. Agent installation for data usage/blocking activities on target boxes requires the involvement of OS admins and DBA’s, which complicates coordination of installation and delays implementation. The discovery feature does not accurately discover the instances and instead identifies auxiliary end points (SQL – 1434) and TCP listeners (Oracle – 1521).
For how long have I used the solution?
I’ve used and administered Imperva SecureSphere for 2 years.
What do I think about the stability of the solution?
Periodically, the site stops functioning and the appliance requires a reboot to restore functionality.
What do I think about the scalability of the solution?
Scalability capabilities are well thought through by product development. Installation of additional MX servers and gateways on remote networks ensures coverage of scanning and data usage monitoring/data protection capabilities.
How are customer service and technical support?
Technical support is probably the biggest drawback. No contact with technical support ever results in an immediate response and the solution is usually preceded with series of emails, going on for up to a week, before a live person gets on the phone. But, even then, their task is to observe the manifestation of the problem and request a collection of additional information (logs, traces, etc.) without any attempt to solve the problem during the call/WebEx session. Their technical support staff has at most two or three engineers that have a good working knowledge of the product, but most of the time, a level one technician is running the case. When support staff finally gets on the phone, their first statement is a disclaimer that they are on the call ONLY to collect information and that the customer should not expect any resolution.
This pattern of providing technical support greatly differs from what IBM offers for their Guardium product (competitor solution).
Which solution did I use previously and why did I switch?
We attempted to use several previous solutions. One was Tenable SecurityCenter with its custom, XML-like scripting where each check had to be written by the Database Security Specialist (myself). We also attempted to use AppDetectivePRO, though its performance, lack of customization, scalability, and licensing costs prevented us from continuing with it.
How was the initial setup?
The setup is very straightforward considering that it’s either a physical or virtual (OVF template) appliance. The wizard-like initial setup and configuration are somewhat awkward, but can be completed after reviewing the instructional videos available to the customers.
What's my experience with pricing, setup cost, and licensing?
Licensing should be chosen based on the current infrastructure setup and growth plans. Purchasing appliances of different types may lead to unnecessary/unjustified expenditures and ultimately lead to complications in administration.
Which other solutions did I evaluate?
The product that was evaluated and was chosen as the recommendation was IBM Guardium. Unfortunately, its licensing cost was a lot higher. Therefore, the management decided not to proceed with the purchase.
What other advice do I have?
Be prepared to obtain every piece of documentation that comes with the product. Thoroughly research it to obtain a clear understanding of how to implement the product and ensure you have a dedicated Imperva first-response engineer that can answer your questions without going through a normal support channel. Be patient when encountering a bug or a feature failure, as well as discrepancies between the product interface and/or behavior with the accompanied documentation. Their support is not prepared to jump in and start working on a fix or update the documentation.
In many cases, the documentation remains outdated referring to old releases regardless how long you’ve been asking for an update. Their instructional videos are also out of date, but references to them are consistently sent by their support whenever you may have a question. And finally, thoroughly document your deployment and license-related information, because every email to technical support is responded with an automated reply requesting this information. Not replying to this automated email with correct info will lead to further delays.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Systems Analyst at a financial services firm with 501-1,000 employees
An expensive solution that is scalable and stable
Pros and Cons
- "Imperva Web Application Firewall is stable."
- "The tool needs to improve CPU and storage memory."
What needs improvement?
The tool needs to improve CPU and storage memory.
For how long have I used the solution?
I have been using the solution for a year. However, my company has been using it for six years.
What do I think about the stability of the solution?
Imperva Web Application Firewall is stable.
What do I think about the scalability of the solution?
The product is scalable, and my company has 20,000 users. One administrator manages the tool.
What's my experience with pricing, setup cost, and licensing?
Imperva Web Application Firewall is expensive.
What other advice do I have?
I rate the solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Imperva Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
F5 Advanced WAF
Fortinet FortiWeb
Cloudflare Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Buyer's Guide
Download our free Imperva Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Imperva WAF vs. Barracuda: Which One is Better?
- Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
A much more mature product in this regard is BeyondInsight. Highly customizable and flexible when it comes to scanning.