Try our new research platform with insights from 80,000+ expert users
AntoineBlaud - PeerSpot reviewer
Security Data Scientist at a comms service provider with 10,001+ employees
Real User
Top 20
Useful in research of detection percentages but issues persist with custom rules upgrading
Pros and Cons
  • "I tested specific features and evaluated the solution against the Web Application Firewall. I conducted research to test different detection percentages. I did not use it directly for protection but for evaluation purposes."
  • "I encountered issues with NGINX App Protect while trying to upgrade custom rules."

What is our primary use case?

I tested specific features and evaluated the solution against the Web Application Firewall. I conducted research to test different detection percentages. I did not use it directly for protection but for evaluation purposes.

What needs improvement?

I encountered issues with NGINX App Protect while trying to upgrade custom rules. 

For how long have I used the solution?

I have been using the product for six months. 

How are customer service and support?

I haven't contacted the technical support team. 

Buyer's Guide
NGINX App Protect
March 2025
Learn what your peers think about NGINX App Protect. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
846,549 professionals have used our research since 2012.

What other advice do I have?

I rate NGINX App Protect an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Chief Technology Officer at a tech services company with 201-500 employees
Real User
A stable system with good security and load balancing
Pros and Cons
  • "The most valuable feature is that I can establish different services from the firewall."
  • "The configuration needs to be more flexible because it is difficult to do things that are outside of the ordinary."

What is our primary use case?

We use WAF as part of our security solution, protecting applications such as internet banking.

It is used both as a web application firewall and for load balancing. 

What is most valuable?

The most valuable feature is that I can establish different services from the firewall.

Using the standard configuration, it is very easy to set up.

What needs improvement?

The configuration needs to be more flexible because it is difficult to do things that are outside of the ordinary.

This solution would benefit from having a support portal that can be opened directly from the dashboard.

For how long have I used the solution?

We have been using the NGINX WAF for five years.

What do I think about the stability of the solution?

This solution is very much stable. Once it is working, it stays working. We use it on a daily basis.

What do I think about the scalability of the solution?

This solution is not really scalable. Both the virtual appliance and the physical appliance are limited in terms of how much traffic they can handle. If you need to scale up then you need to replace the box with a bigger one.

In my company, we have about 700 users. One of my customers has about 2,500 concurrent users, and another one has about 4,000. These are all internal users. I cannot tell how many external users are connecting from the internet, but it is an enormous number.

How are customer service and technical support?

It takes time to deal with technical support because they are pretty busy, but when you get the support it is very good. They know what they're talking about.

Which solution did I use previously and why did I switch?

Prior to using this solution, we tried open-source pfSense. However, most of my customers went to F5.

How was the initial setup?

The initial installation is very simple. However, there is one issue with security certificates.

Any system that you publish that is a secure system needs to have a certificate implemented, and that is always a struggle. We have plenty of customers with this solution, and every time that we get to the step involving the certificate, extra work is required. It never works smoothly. You always have to go and manipulate the certificate and the system just to set it up. I'm not sure about the latest systems, but in the old models, this could not even be done through the GUI. You had to use the command line, even though the certificate is visible in the GUI. A combination of commands is required just to make it work.

The length of time to deploy a basic system is very short. For more complex scenarios, it can be a long process.

What about the implementation team?

We do have a consultant to assist us with deployment. We do the initial configuration, but when it comes to things that don't work then we speak with F5 directly. 

We have two people in place to maintain this product. One is from IT and the other takes care of the networking aspect.

What's my experience with pricing, setup cost, and licensing?

The licensing fees for this solution are pretty expensive for what it does, but there is no alternative. The only alternative is Imperva, but that is even more expensive.

Which other solutions did I evaluate?

There is not much variety when it comes to web application firewalls that are also load-balancing solutions. Imperva is an alternative, although it is more expensive.

What other advice do I have?

My advice for anybody who is implementing this solution is to plan well. You have to make sure that you plan ahead and know what it is that you want to achieve, then gather all of the relevant information. Otherwise, if you start to configure it and then find out that you don't have the right application server, or the right policy, or the proper certificate to install and configure it, then the installation will be very long. On the other hand, if the plan is very good and you have all of the details in advance, along with the right people to test it, then it should be straightforward.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
NGINX App Protect
March 2025
Learn what your peers think about NGINX App Protect. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
846,549 professionals have used our research since 2012.
Ntwrkengine0887 - PeerSpot reviewer
Senior Network Engineer at a comms service provider with 1,001-5,000 employees
Reseller
Flexible and high availability
Pros and Cons
  • "The most valuable feature of NGINX App Protect is its flexibility."
  • "The setup of NGINX App Protect is complex. The full process took one week to complete. Additionally, we had to change the network infrastructure platform which took one month."

How has it helped my organization?

NGINX App Protect has improved the flexibility of services in our company and distributed new escalation applications. The downtime in our network has decreased substantially. In a short time, we can republish and resolve issues in our network.

What is most valuable?

The most valuable feature of NGINX App Protect is its flexibility.

For how long have I used the solution?

I have been using NGINX App Protect for approximately three years.

What do I think about the stability of the solution?

NGINX App Protect is stable.

What do I think about the scalability of the solution?

The scalability of NGINX App Protect is decent.

We have approximately 500 people using the solution in my organization. We have IT specialists that work with the core mobile network.

How are customer service and support?

We do not have technical support in Iran, we only use our own knowledge about the solution.

Which solution did I use previously and why did I switch?

I did not use a similar solution previous to NGINX App Protect.

How was the initial setup?

The setup of NGINX App Protect is complex. The full process took one week to complete. Additionally, we had to change the network infrastructure platform which took one month.

I rate the setup difficulty of NGINX App Protect a four out of five.

What about the implementation team?

We used an IT expert for the implementation of NGINX App Protect. We have three people who provide support for NGINX App Protect.

What was our ROI?

We have received a return on investment, NGINX App Protect was a good investment.

What's my experience with pricing, setup cost, and licensing?

I rate the price of NGINX App Protect a three out of five.

There are not any additional costs we had to pay to use NGINX App Protect.

What other advice do I have?

We have a complex project and we found some of our applications did not work as intended. However, moving forward we do not find we will experience this level of complexity.

I rate NGINX App Protect a nine out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
VijayLalwani - PeerSpot reviewer
Manager - Cyber Security at a financial services firm with 10,001+ employees
Real User
Great auto-learning and protection
Pros and Cons
  • "NGINX App Protect's best features are auto-learning, which creates a profile of applications that are deployed, bot protection, and force protection, which lets you configure your brute force policy and alert for and prevent brute force attacks."
  • "NGINX App Protect would be improved with integration with Shape and F5 WAF, which would make it easy for users to manage all their web application security with a single solution."

What is most valuable?

NGINX App Protect's best features are auto-learning, which creates a profile of applications that are deployed, bot protection, and force protection, which lets you configure your brute force policy and alert for and prevent brute force attacks.

What needs improvement?

NGINX App Protect would be improved with integration with Shape and F5 WAF, which would make it easy for users to manage all their web application security with a single solution. In the next release, I'd like to see some enhancements in bot protection, API security, and mobile application security.

For how long have I used the solution?

I've been using NGINX App Protect for four years.

What do I think about the stability of the solution?

NGINX App Protect is stable but has some areas for improvement, including HTML5 availability. I would rate its stability eight out of ten.

How are customer service and support?

NGINX's technical support is good, but sometimes their response time is delayed, or they don't have the technical skills to resolve issues. We're seeing these issues despite having premium support.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I previously used Imperva WAF.

What other advice do I have?

I would give NGINX App Protect a rating of eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Manager - Cyber Security (SOC) at a financial services firm with 10,001+ employees
Real User
Easy to analyze security abnormalities, stable, and the support is good
Pros and Cons
  • "The most valuable feature is that there is a link in the system that will help to analyze the security of an application when something abnormal is found."
  • "Setting policies and parameters through the UI should be more automated because the process is manual, where we can only edit one rule at a time."

What is our primary use case?

We use this solution to protect our entire set of web applications. This includes protecting against vulnerabilities as a result of programming errors.

What is most valuable?

The most valuable feature is that there is a link in the system that will help to analyze the security of an application when something abnormal is found.

What needs improvement?

This firewall should support more of the network layers.

Profiling capability should be improved.

Setting policies and parameters through the UI should be more automated because the process is manual, where we can only edit one rule at a time.

For how long have I used the solution?

I have been using the NGINX Web Application Firewall for more than a year and a half.

What do I think about the stability of the solution?

In terms of stability, this solution is much better than Imperva.

What do I think about the scalability of the solution?

In terms of scalability, depending on the application, there is a limit to how many policies I can design.

How are customer service and technical support?

The technical support for this solution has improved. Imperva used to be better, but now, NGINX is more responsive.

Which solution did I use previously and why did I switch?

I have also used Imperva. The stability and interface are better in the NGINX WAF. For example, it is easier to create new policies. Technical support from NGINX is also more responsive than that of Imperva.

How was the initial setup?

The initial setup was complex in terms of deployment and fine-tuning.

We have more than ten applications so it took us between four and five months to deploy.

What about the implementation team?

We had to contract a third-party consultant to assist us with the deployment. We are satisfied with their work

What other advice do I have?

Based on my experience, this solution is better than the other choices on the market.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Security at a insurance company with 501-1,000 employees
Real User
Top 20
With an easy setup phase in place, the tool offers high stability and good scalability
Pros and Cons
  • "It is a stable solution."
  • "The product's user interface is an area with shortcomings as it can be quite confusing for users, making it an area where improvements are required."

What is most valuable?

The most valuable feature of the solution is that IVF and ICSI are covered under the firewall option offered by the tool. I don't have a specific feature I like the most since I look at features through comparisons of different firewall products and the features of such tools.

What needs improvement?

The product's user interface is an area with shortcomings as it can be quite confusing for users, making it an area where improvements are required. The main menu can be quite confusing.

After you implement it, it's not so easy to understand how it works. Though in my company, we understand the basics of the product, if you want to explore the more advanced features, then the principal product doesn't explain it to us, which can be quite confusing when navigating through the main menu.

For how long have I used the solution?

I have been using NGINX App Protect for five years. I use the solution in my company.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

In our company, we never tried to use the scalability options provided by the tool.

How are customer service and support?

The solution's technical support is good. I rate the technical support an eight to nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, our company was using Fortinet. I don't know why my company switched from Fortinet to NGINX App Protect because it happened before I joined the organization.

How was the initial setup?

The product's initial setup phase was easy.

What's my experience with pricing, setup cost, and licensing?

The price of NGINX App Protect is not much different from the products that fall under the leader category of Gartner Magic Quadrant.

Which other solutions did I evaluate?

My company needs to expand its options to see if some other brand apart from NGINX App Protect is faster.

As the license for NGINX App Protect in our company will expire in a few months, my company wants to make a decision on whether to extend the services of the tool or not based on the research we do on other platforms in the market.

What other advice do I have?

My company is satisfied with the product.

For the user interface, I rate the product an eight out of ten.

For the functionalities of the product, I rate the tool a ten out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Md. Al Imran Chowdhury - PeerSpot reviewer
Cyber Security Analyst at Link3 Technologies
Real User
Top 5Leaderboard
A scalable solution for application firewall with easy deployment

What is our primary use case?

We use the solution for application firewall purposes. We use both mobile and web applications.

What needs improvement?

During the NGINX App Protect v1.1 upgrade, we encountered compatibility issues with our existing telecom infrastructure, specifically the load balancer and WAF. These issues manifested as difficulties with the HTTP 1.1 protocol. While attempting to solve the problem through upgrades, we ultimately opted for alternative solutions as the desired effect could not be achieved. This highlights the technical challenges of integrating NGINX App Protect with diverse network components.

For how long have I used the solution?

I have been using NGINX App Protect for more than five years.

What do I think about the stability of the solution?

The product is stable.

I rate the solution’s stability an eight-point five out of ten.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

The customer service’s response should be faster.

How was the initial setup?

The initial setup is straightforward. For deployment, we configured basic configuration, and after mounting, We observed our application for almost four months. After that, we proceed to enforcement blocking mode. Typically, all our applications are live, so we can't block it on day one. We observed it for a long time, like six months, and then we went into step-by-step blocking mode.

Three people are required for the solution's deployment.

What's my experience with pricing, setup cost, and licensing?

The product is expensive and has a subscription-based licence.

What other advice do I have?

NGINX App Protect's high price and limited support options can be a drawback. While troubleshooting basic issues is manageable, resolving advanced problems through paid support channels can be expensive and experience delays.

I recommend the solution if the client has no financial issues regarding their WAF or LTM solutions. Still, if they are budget constraints, one should think of other options like Fortinet.

Overall, I rate the solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Information Security Engineer at a computer software company with 1,001-5,000 employees
Real User
Beneficial reverse proxy, effective load balancer, and helpful support
Pros and Cons
  • "The most valuable feature of NGINX App Protect is the reverse proxy."
  • "The price of NGINX App Protect could improve."

What is our primary use case?

NGINX App Protect can be used as a reverse proxy, internet controller, and for caching.

How has it helped my organization?

NGINX App Protect has improved our organization by using the load balancer feature.

What is most valuable?

The most valuable feature of NGINX App Protect is the reverse proxy.

What needs improvement?

The price of NGINX App Protect could improve.

For how long have I used the solution?

I have been using NGINX App Protect for approximately two years.

What do I think about the stability of the solution?

NGINX App Protect is stable. It is lightweight and fast.

What do I think about the scalability of the solution?

The scalability of NGINX App Protect is good and it is easy to do.

How are customer service and support?

The experience I had with the technical support was good.

Which solution did I use previously and why did I switch?

We used another solution previously to NGINX App Protect. We switch to testing other solutions.

How was the initial setup?

The initial setup of NGINX App Protect is basic. The full deployment took approximately one day.

What about the implementation team?

We followed the documentation to do the implementation of NGINX App Protect in-house. We have one person that does the deployment and maintenance of the solution.

What was our ROI?

I have not seen a return on investment, it is too soon. We are only in the testing phase.

What's my experience with pricing, setup cost, and licensing?

There is a monthly or annual subscription to use NGINX App Protect. There are not any additional costs to the subscription.

I rate the price of NGINX App Protect a three out of five.

What other advice do I have?

I would recommend this solution to others because it performs well.

I rate NGINX App Protect a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free NGINX App Protect Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2025
Buyer's Guide
Download our free NGINX App Protect Report and get advice and tips from experienced pros sharing their opinions.