I rate F5 BIG-IP Advanced Firewall Manager an eight out of ten from other users. It holds a challenger’s position in Gartner, closer to leader products. Its migration feature is complicated for on-premise versions compared to Palo Alto, Fortinet, etc. I recommend the product to businesses with a considerable budget. I recommend Fortinet to other users.
The solution has great functionality and many capabilities. I recommend the solution for businesses because you get all the needed functionality in one place. Overall, I rate this solution a nine out of ten.
Learn what your peers think about F5 BIG-IP Advanced Firewall Manager (AFM). Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
My advice to others is if you start to apply the initial design in your network, can achieve more benefits using the F5 BIG-IP AFM module as it can work as a perimeter firewall. It it has many features, such as DDoS, GTM, and Global Traffic Management. I rate F5 BIG-IP AFM an eight out of ten. I gave a high rating because there are many use cases this solution can be used for and it can be used similarly to an orchestrator in the network.
Before choosing a solution, it is important to do background research and conduct evaluations across comparable products. I rate the solution an eight out of ten.
We're resellers. We're using the latest version of the solution. Chances are, as a standalone product, you can find a better firewall at the same price. It's limited with functionalities, so there is nothing really nice about AFM except that if you already have an F5 stack of solutions on hardware or on virtual infrastructure, and you are adding this license, in that case, it makes sense. Any other case doesn't simply work. That doesn't make sense. I'd rate the product five out of ten.
I would advise doing your homework. Do your research, and make sure you understand what the product is for so that you do not deploy it where it will not fit your needs. This is not a next-gen firewall. It is not meant to compete against next-gen firewalls. It is meant primarily for DNS type of things. That doesn't mean it can't do next-gen tasks, but the way I see it and the way I understand it, it is more for data centers. I would rate it an eight out of ten.
Head: Cyber and Information Research Centre at Council for Scientific and Industrial Research
Real User
2022-05-08T05:57:54Z
May 8, 2022
F5 BIG-IP Advanced Firewall Manager (AFM) is a popular big brand name behind it. However, it is expensive. Everything that is being used by large corporations is going to have a high cost. I rate F5 BIG-IP Advanced Firewall Manager (AFM) a seven out of ten.
Contracted IP Development Engineer at a media company with 10,001+ employees
Real User
2020-03-16T06:56:22Z
Mar 16, 2020
While some companies have now started to move these devices from on-premises to the cloud, most companies prefer not to do this due to security reasons. I'd rate the solution eight out of ten. It's a good product, but it may not be the absolute best on the market. Companies should examine NGINX or Palo Alto or others and compare them to see what would work best for their organization. I would recommend the solution. It's great for protecting servers from attacks. With controllers plus the firewall, you will only need one device to protect everything.
Founder / Senior Security Architect at a tech services company with 1-10 employees
Reseller
2020-03-03T08:47:42Z
Mar 3, 2020
We are a reseller of F5. We're not a customer. I'd advise companies considering implementing the solution to understand the architecture and the flow of the service before setting it up. I'd rate the solution nine out of ten.
Senior Security Engineer at a tech services company with 201-500 employees
Real User
2019-12-04T05:40:00Z
Dec 4, 2019
It's a good solution only for a published service. If you are publishing services outside the company, it's very good for us, but the biggest lesson is that it cannot be applied internally to replace a data center firewall. Sometimes, a company will introduce F5 to the place as a data center firewall. It's not a replacement for the DC firewall. It cannot replace the data center firewall but can be added to the service. I would rate this as eight out of ten.
I have not had any deployments that are exactly the same. For example, if I deployed everything as a solution for customer A and for customer B I do deployments with the same set of applications, and even then there are differences in the deployment. In all the experiences I have had, they have never been the same in my entire four-year experience installing the product. That shows how broad F5 is in its ability to manage situations and customize the experience for specific organizations. It is usually the case that customers tell us what they want to achieve. They tell us what the need is in their network or in their infrastructure, or they tell us the solution that they expect as a result and then we make a recommendation. If we make the recommendation and they are impressed with the capabilities that the solution can achieve, then they go for it if they have the budget. If they do not have the budget or they don't like what we propose we can give them a different plan. In most cases, our customers have taken the time and have done their research very well. They just say, "okay, we need this product or solution and I want this product deployed." In most cases, we don't even get to do a recommendation because they have done their research. They have come to a conclusion as to what product meets their needs whether it is because of the name or the advertising. In my opinion, it may not always be the best solution, but they are the client so we give them what they ask for. The dashboard and the interface for F5 are fantastic. That is really something that is remarkable. It is unlike any other solutions that I've worked with. For example with Cisco, many of the things that you want to do you have to take care of on the command line. It is not very convenient. With F5 you find everything in the interface. There is hardly anything that you want to do with F5 that you can't do from the GUI. In terms of analytic reporting, the product has very good detailed analytics that comes with the product that you can access on the dashboard. There is also analytics and analysis with visibility reporting. The module that is dedicated for that gives you a fine grain access into everything that you want to see and report on immediately. With everything I want to do for the client in F5, the GUI allows me and maybe this makes a big difference for me in the evaluation of the product because of its ease of use. The dashboard is fantastic and the GUI is excellent. What I find most impressive about F5 is that, as long as you know what you want to do, as long as we know what you want to achieve, you find the solution there. Let me restrict this example to the LTM (local traffic manager). Let's say, for instance, you want to deploy your application and then there is a feature you want to add or you want to introduce some kind of logic you want to introduce that you cannot find in GUI or it doesn't even come packaged with the box. If you have an idea of what you want to do, you can program it in. There is a feature you can use to introduce some programmability into the box. It really just comes down to you knowing what exactly you want to achieve. If it doesn't come already pre-programmed as part of the package, this feature will allow you to program it in yourself. There is hardly anything you would want to do that F5 cannot do for you. On a scale from one to ten, where one is the worst and ten being the best, I would rate this product as a nine. The only reason I will not give them a ten is because of the cost. But based on functionality and ease of deployment, scalability, reliability, overall security and functionality, I give them nine.
Computer & Network Security Professional at a financial services firm with 10,001+ employees
Real User
2019-06-26T05:25:00Z
Jun 26, 2019
There should be more qualified support, like training videos or how to install features. I would rate the solution 8 out of 10. If the user interface was more user-friendly, I'd rate it higher.
F5 BIG-IP Advanced Firewall Manager (AFM) is a high-performance, full-proxy network security solution designed to protect networks and data centers against incoming threats that enter the network. Built on F5’s industry-leading BIG-IP hardware and software platforms, BIG-IP AFM provides a scalable platform that delivers the flexible performance and control needed to mitigate aggressive distributed denial-of-service (DDoS) and protocol attacks before they overwhelm and degrade applications and...
Overall, I would rate the solution an eight out of ten.
Overall, i would rate the solution a seven out of ten.
Overall, I would rate F5 BIG-IP Advanced Firewall Manager as an eight out of ten.
I rate the product a ten out of ten.
I rate F5 BIG-IP Advanced Firewall Manager an eight out of ten from other users. It holds a challenger’s position in Gartner, closer to leader products. Its migration feature is complicated for on-premise versions compared to Palo Alto, Fortinet, etc. I recommend the product to businesses with a considerable budget. I recommend Fortinet to other users.
The solution has great functionality and many capabilities. I recommend the solution for businesses because you get all the needed functionality in one place. Overall, I rate this solution a nine out of ten.
My advice to others is if you start to apply the initial design in your network, can achieve more benefits using the F5 BIG-IP AFM module as it can work as a perimeter firewall. It it has many features, such as DDoS, GTM, and Global Traffic Management. I rate F5 BIG-IP AFM an eight out of ten. I gave a high rating because there are many use cases this solution can be used for and it can be used similarly to an orchestrator in the network.
Before choosing a solution, it is important to do background research and conduct evaluations across comparable products. I rate the solution an eight out of ten.
We're resellers. We're using the latest version of the solution. Chances are, as a standalone product, you can find a better firewall at the same price. It's limited with functionalities, so there is nothing really nice about AFM except that if you already have an F5 stack of solutions on hardware or on virtual infrastructure, and you are adding this license, in that case, it makes sense. Any other case doesn't simply work. That doesn't make sense. I'd rate the product five out of ten.
I would advise doing your homework. Do your research, and make sure you understand what the product is for so that you do not deploy it where it will not fit your needs. This is not a next-gen firewall. It is not meant to compete against next-gen firewalls. It is meant primarily for DNS type of things. That doesn't mean it can't do next-gen tasks, but the way I see it and the way I understand it, it is more for data centers. I would rate it an eight out of ten.
F5 BIG-IP Advanced Firewall Manager (AFM) is a popular big brand name behind it. However, it is expensive. Everything that is being used by large corporations is going to have a high cost. I rate F5 BIG-IP Advanced Firewall Manager (AFM) a seven out of ten.
I recommend this solution to others who are interested in using F5 Advanced Firewall. I would rate this solution a ten out of ten.
While some companies have now started to move these devices from on-premises to the cloud, most companies prefer not to do this due to security reasons. I'd rate the solution eight out of ten. It's a good product, but it may not be the absolute best on the market. Companies should examine NGINX or Palo Alto or others and compare them to see what would work best for their organization. I would recommend the solution. It's great for protecting servers from attacks. With controllers plus the firewall, you will only need one device to protect everything.
We are a reseller of F5. We're not a customer. I'd advise companies considering implementing the solution to understand the architecture and the flow of the service before setting it up. I'd rate the solution nine out of ten.
It's a good solution only for a published service. If you are publishing services outside the company, it's very good for us, but the biggest lesson is that it cannot be applied internally to replace a data center firewall. Sometimes, a company will introduce F5 to the place as a data center firewall. It's not a replacement for the DC firewall. It cannot replace the data center firewall but can be added to the service. I would rate this as eight out of ten.
I have not had any deployments that are exactly the same. For example, if I deployed everything as a solution for customer A and for customer B I do deployments with the same set of applications, and even then there are differences in the deployment. In all the experiences I have had, they have never been the same in my entire four-year experience installing the product. That shows how broad F5 is in its ability to manage situations and customize the experience for specific organizations. It is usually the case that customers tell us what they want to achieve. They tell us what the need is in their network or in their infrastructure, or they tell us the solution that they expect as a result and then we make a recommendation. If we make the recommendation and they are impressed with the capabilities that the solution can achieve, then they go for it if they have the budget. If they do not have the budget or they don't like what we propose we can give them a different plan. In most cases, our customers have taken the time and have done their research very well. They just say, "okay, we need this product or solution and I want this product deployed." In most cases, we don't even get to do a recommendation because they have done their research. They have come to a conclusion as to what product meets their needs whether it is because of the name or the advertising. In my opinion, it may not always be the best solution, but they are the client so we give them what they ask for. The dashboard and the interface for F5 are fantastic. That is really something that is remarkable. It is unlike any other solutions that I've worked with. For example with Cisco, many of the things that you want to do you have to take care of on the command line. It is not very convenient. With F5 you find everything in the interface. There is hardly anything that you want to do with F5 that you can't do from the GUI. In terms of analytic reporting, the product has very good detailed analytics that comes with the product that you can access on the dashboard. There is also analytics and analysis with visibility reporting. The module that is dedicated for that gives you a fine grain access into everything that you want to see and report on immediately. With everything I want to do for the client in F5, the GUI allows me and maybe this makes a big difference for me in the evaluation of the product because of its ease of use. The dashboard is fantastic and the GUI is excellent. What I find most impressive about F5 is that, as long as you know what you want to do, as long as we know what you want to achieve, you find the solution there. Let me restrict this example to the LTM (local traffic manager). Let's say, for instance, you want to deploy your application and then there is a feature you want to add or you want to introduce some kind of logic you want to introduce that you cannot find in GUI or it doesn't even come packaged with the box. If you have an idea of what you want to do, you can program it in. There is a feature you can use to introduce some programmability into the box. It really just comes down to you knowing what exactly you want to achieve. If it doesn't come already pre-programmed as part of the package, this feature will allow you to program it in yourself. There is hardly anything you would want to do that F5 cannot do for you. On a scale from one to ten, where one is the worst and ten being the best, I would rate this product as a nine. The only reason I will not give them a ten is because of the cost. But based on functionality and ease of deployment, scalability, reliability, overall security and functionality, I give them nine.
This is a good product. I would recommend this solution to anybody evaluating it. I would rate this solution a nine out of ten.
There should be more qualified support, like training videos or how to install features. I would rate the solution 8 out of 10. If the user interface was more user-friendly, I'd rate it higher.