I am working with an integration and security company that collaborates with various vendors. I am currently dealing with F5 Advanced WAF.
F5 Advanced WAF with LTM, IPI, and Threat Campaigns (PAYG, 25Mbps)
F5, Inc. | 17.5.1-0.0.7Linux/Unix, CentOS 7.3 - 64-bit Amazon Machine Image (AMI)
External reviews
External reviews are not included in the AWS star rating for the product.
Bot protection capabilities enhance application security
What is our primary use case?
What is most valuable?
The whole mechanism of F5 Advanced WAF is effective. It contains the logic of both negative and positive security combined, providing added value to the company I work with to protect their applications.
What needs improvement?
I do not have anything in mind right now that needs improvement. Generally, it works well. If we need any specific feature, we approach F5 directly.
For how long have I used the solution?
I have probably used it for ten years or so.
How are customer service and support?
I do not need them much because my team is professional. If there is a bug, the support is usually understanding and resolves issues.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
The price is affordable and satisfactory.
What other advice do I have?
One of the best features is the bot protection capabilities. I rate the product eight out of ten.
Enables flexible licensing and clear ROI evaluation
What is our primary use case?
I use F5 Advanced WAF to manage enterprise clients, focusing on licensing and support flexibility to accommodate various customer segments, including enterprises and mid-market customers.
What is most valuable?
F5 Advanced WAF provides two different licensing models. The subscription-based model offers competitive pricing, making it easier for me to see ROI. However, the perpetual license, despite an initial higher cost, lacks transparency regarding support expiration. Due to the subscription, I can compare it with other tools, but as a perpetual buyer, I am unaware of support expiration until after the purchase, allowing indicative ROI calculations but not actual ones.
Furthermore, F5 Advanced WAF offers features not available in other products, though I suggest consulting a technical expert for specific features.
What needs improvement?
F5 Advanced WAF sells perpetual licenses as perpetual assets during sales without informing me that support ends after a few years. I find out later and am required to pay for support without receiving updated versions. Deployment training for F5 Advanced WAF is lacking and restricts growth by being inaccessible and costly for partners.
For how long have I used the solution?
I provide the feedback based on my recent experience and judgment.
How are customer service and support?
I have interacted with F5's support, and while I have no major complaints, they could improve. I rate them eight out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
Deployment is easy for me, but enablement training is not easily available, accessible, or sufficiently supported.
What was our ROI?
I find it difficult to compute ROI for perpetual licenses due to the lack of upfront information about support expiry. Subscription models offer clearer ROI due to a more competitive pricing scheme.
What's my experience with pricing, setup cost, and licensing?
Subscription models have competitive pricing, while perpetual licenses involve an upfront higher cost, leading to ambiguity regarding support cessation.
Additional costs for deployment and training further impact my cost considerations.
Which other solutions did I evaluate?
I am interested in how F5 Advanced WAF features and pricing compare to alternatives like Fortinet and Check Point.
What other advice do I have?
I rate F5 Advanced WAF eight out of ten.
Despite a few issues, F5 Advanced WAF is performing well for me. Improving engagement and enablement for partners would enhance its value to GSI partners and service providers.
Overall, I see potential positive development for the product.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Comprehensive security solution provides robust protection against threats
What is our primary use case?
The AOF solution is used for any customer with applications to protect them. It provides security features to protect the application from threats such as SQL injections and challenges of the browser using AI.
What is most valuable?
The AOF solution provides numerous security features. It protects applications from various threats, including SQL injection, and ensures that the application behavior is from a human, not a bot. It includes DDoS protection which has been enhanced after migrating from SDM.
The solution is very effective as it includes security features important for financial applications where protection is necessary to avoid potential financial loss or penalties. It helps protect the core and backend of applications.
What needs improvement?
One improvement for AOF could be focusing on enhancing its AI engine to make it more mature.
For how long have I used the solution?
I have used the solution for almost two years.
What do I think about the stability of the solution?
F5 is very good in terms of stability with no issues reported during maintenance.
What do I think about the scalability of the solution?
F5 scalability is excellent. I have not experienced any issues with scalability.
How are customer service and support?
F5 customer support is good but not as excellent as Infoblox support due to complexity issues. I would rate F5 customer support as seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I recommend Infoblox because it's a leader in DNS security with more than 15 customers using it. It is very flexible in configuration, support, and scalability compared to F5.
How was the initial setup?
The initial setup involves sending a request, understanding requirements such as policy and application number, and ensuring prerequisites are ready. It uses policy virtual servers and the network WAF, taking about five or six days to implement.
What was our ROI?
The ROI is very impressive as it is crucial for financial applications to be protected efficiently. Ensuring application security is a significant milestone, crucial to prevent financial losses or penalties.
What's my experience with pricing, setup cost, and licensing?
The setup cost is normal, yet not the best in terms of the commercial aspect. Other competitors like Fortinet are cheaper than F5.
Which other solutions did I evaluate?
Fortinet and its FortiWeb product are competitors to F5. Fortinet has many products yet lacks concentration on a single part, unlike F5.
What other advice do I have?
For enterprises in the financial sector, having F5 is essential. I would rate the solution a ten out of ten.
Which deployment model are you using for this solution?
Client-side and mobile app protection with 24/7 support for security
What is our primary use case?
F5 Advanced Web Application Firewall (AWAF) is primarily used in financial sectors like banking to secure web applications against advanced threats, ensuring compliance with industry regulations. Our Key use cases include:
- Protection Against OWASP Top 10: Safeguarding banking applications from SQL injection, XSS, and other common vulnerabilities.
- Bot Mitigation: Detecting and blocking malicious bots to prevent account takeovers, credential stuffing, and fraud.
- DDoS Protection: Defending against application-layer DDoS attacks to ensure service availability.
- PCI DSS Compliance: Enforcing security policies to meet compliance standards for protecting sensitive customer data.
- API Security: Securing APIs used in banking platforms from abuse and unauthorized access.
- Threat Intelligence: Leveraging threat intelligence to identify and mitigate zero-day attacks.
- Application Traffic Control: Managing and monitoring application traffic to ensure optimal performance and security.
These use cases help financial institutions maintain secure and resilient applications, critical for trust and compliance.
How has it helped my organization?
F5 Advanced WAF has significantly enhanced our organization's security posture by protecting critical banking applications against sophisticated threats. It ensures compliance with regulatory standards, improves customer trust through robust bot mitigation, and enhances application performance by mitigating DDoS attacks and securing APIs. Additionally, it provides real-time threat intelligence and streamlined security management, reducing downtime and operational risks.
What is most valuable?
Bot Protection: Mitigates automated attacks like credential stuffing.
API Security: Safeguards APIs against exploitation.
Advanced Threat Detection: Protects against OWASP Top 10 vulnerabilities and zero-day threats.
DDoS Mitigation: Ensures application availability during attacks.
Behavioral Analytics: Detects and mitigates anomalous traffic patterns.
Granular Policy Control: Enables precise security policy customization.
Threat Intelligence Integration: Offers real-time updates for proactive protection.
What needs improvement?
- Ease of Deployment: Simplify initial setup and policy configuration.
- UI Enhancements: Improve user interface for better navigation and usability.
- Integration: Enhance compatibility with third-party tools like SIEMs and DevOps pipelines.
- Performance Optimization: Reduce latency during high traffic volumes.
Suggested Features for Next Release:
- AI-Driven Threat Detection: Advanced machine learning for proactive defense.
- Comprehensive API Protection: Extended support for GraphQL and WebSocket APIs.
- Cloud-Native Integration: Better functionality in hybrid and multi-cloud environments.
- Automated Policy Suggestions: AI-based recommendations for policy tuning.
For how long have I used the solution?
It's been two years that I've been working with this solution.
What do I think about the stability of the solution?
I am not experiencing any significant instability.
What do I think about the scalability of the solution?
F5 AWAF offers excellent scalability, enabling organizations to protect applications seamlessly across on-premises, cloud, and hybrid environments. It can handle increasing traffic volumes with minimal latency, ensuring consistent security for both small-scale deployments and enterprise-grade architectures. With its ability to integrate into CI/CD pipelines and auto-scale in cloud environments, F5 AWAF supports dynamic application growth without compromising performance or protection.
How are customer service and support?
Customer service is very responsive. If the issue persists beyond my local support capabilities, I open a ticket with F5, and they respond quickly. I rate their technical support 9 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Not now just I have checked the comparision and collect reviews from peerspoot and Quadrant
How was the initial setup?
The initial setup experience is straightforward, and I did not face any complexities. I recommend deploying the F5 AWAF solution on a single appliance with LTM.
What's my experience with pricing, setup cost, and licensing?
F5 is relatively less expensive compared to other solutions as F5 is considered the best.
Which other solutions did I evaluate?
Not Now
What other advice do I have?
I rate F5 eight to nine out of ten. I recommend F5 to customers who require a robust solution and have the budget for it. However, for customers looking for modest pricing, I would not recommend the F5 solution.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Protects applications with versatile authentication features
What is our primary use case?
The primary use case for F5 Advanced WAF is to protect applications that are exposed to the internet. It is used to protect applications from known attacks, such as cross-site scripting and DDoS attacks.
What is most valuable?
F5 offers a versatile solution that can be integrated with APM in cases where integration with an external IDB is needed. It is useful for authentication backup if the on-prem directory service is unavailable.
Additionally, its WAF functionality is valuable for protecting applications from attacks. It is a versatile and strong solution that's easy to understand and deploy.
What needs improvement?
The DDoS capabilities should be enhanced. More advanced features related to DDoS would be beneficial.
For how long have I used the solution?
I have been working with F5 Advanced WAF since 2017, which is almost eight years.
What do I think about the stability of the solution?
The stability is high. It's a robust product with high availability, ensuring no disruptions for end-users if a node failure is detected. Our deployments are based on high availability clustering.
What do I think about the scalability of the solution?
F5 Advanced WAF is highly scalable, both in its physical and virtual forms. Its scalability is based on the search, making it adaptable for various needs.
How are customer service and support?
The support from F5 is excellent, with resources readily available online. The quality of support depends on the service SLA purchased, with various levels of service provided.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of F5 Advanced WAF is straightforward and easy to understand. Without prior training, I could build and publish applications using just the documentation.
What about the implementation team?
For standard and straightforward deployments, the implementation can be handled by a single person or a team based on the customer's size. Professional service can simplify the process significantly.
What's my experience with pricing, setup cost, and licensing?
The pricing is not cheap; I rate it a six out of ten.
While it reflects the advanced capabilities of the product, reconsideration of the pricing is suggested.
What other advice do I have?
For reverse proxy solutions, F5 Advanced WAF is the best choice.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Harness comprehensive security to protect web applications from modern threats
What is our primary use case?
F5 Advanced WAF is used for the protection of applications from current web threats, including DDoS attacks. It provides a comprehensive security solution that incorporates different protection levels.
What is most valuable?
The most valuable feature of F5 Advanced WAF is its extensive set of capabilities for application protection, including DDoS prevention, and its ability to work with Pentesters and external scanners to observe user activity and eliminate false positives. This comprehensive approach to application security enables an organization to protect its web applications from diverse web threats effectively.
What needs improvement?
All features of Advanced WAF offer numerous functions, which means tuning configuration is not simple. It's a powerful tool yet can be complex for new users. Future updates should ensure not to break the current state, as users are concerned the new version may not meet current standards.
For how long have I used the solution?
I have been using F5 Advanced WAF for more than ten years.
What do I think about the stability of the solution?
F5 Advanced WAF is considered a stable product, and I would rate it as ten out of ten in terms of stability.
What do I think about the scalability of the solution?
The solution's scalability is solid, with the option to increase capabilities through licensing and adding modules in the virtual edition. However, it requires additional expenses, so I would rate it as a seven or eight out of ten.
How are customer service and support?
F5 provides one of the best technical supports, though there have been a few cases where customers were dissatisfied due to response speed. However, in general, their support is highly efficient and knowledgeable.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
In the past, Imperva was the leading solution, however, now F5 is preferred as it offers a superior solution according to customer feedback.
How was the initial setup?
Deploying the solution, including initial configuration, licensing, addressing, and enabling WAF, could take one to three hours. However, for a comprehensive setup, considering external factors and optimizations, the process could take up to a month.
What about the implementation team?
I handle installations and other related aspects by myself, without any additional help.
What was our ROI?
There are numerous benefits for end customers, as a secure application helps prevent potential breaches and ensures the safety of customers' data, especially in sensitive sectors like banking.
What's my experience with pricing, setup cost, and licensing?
F5 Advanced WAF is not cheap. That said, it offers numerous features and is known as one of the best solutions in its segment. It provides significant value by offering comprehensive protection for high-stakes environments.
Which other solutions did I evaluate?
I work with other vendors, such as Broadcom, Qualys, BeyondTrust, and Trend Micro, depending on the customer's needs and the vision of my company.
What other advice do I have?
I would fully recommend F5 Advanced WAF for its feature-rich offerings and high detection rate of threats. I rate it a ten out of ten as it is one of the best solutions available.
Which deployment model are you using for this solution?
Securing web applications with API and bot protection while enhancing IP intelligence
What is our primary use case?
The primary use case is to secure the organization's applications from web-based attacks, securing both web applications and APIs.
What is most valuable?
The product is used to secure web applications and has the ability to use API templates and bot protection features, such as blocking requests or presenting CAPTCHA pages to end users. We also implement Swagger files for API security and use custom profiles for device ID threshold management.
What needs improvement?
The main improvement needed is related to IP intelligence. Once we start receiving traffic from repetitive IP addresses, we have to report it to the SOC team to block it at the layer four level. Users would like to have an additional IP intelligence license to handle this within WAF itself without needing to engage with the SOC team.
For how long have I used the solution?
The solution has been used for three years.
How are customer service and support?
Customer service and support depend on the level of support subscribed to, such as silver or platinum support, which determines the response time.
How would you rate customer service and support?
Positive
How was the initial setup?
Deploying the solution involves an application learning and blocking phase. The process includes collecting application data, creating policies, and applying them to lower testing environments like QA or dev before moving to UAT and production. The learning phase is used to handle false positives and fine-tune the policies before going live.
What about the implementation team?
The in-house team manages and supports the WAF, handling incidents reported by end users when legitimate traffic is blocked. They update the policies to prevent the recurrence of similar blocks.
What's my experience with pricing, setup cost, and licensing?
The pricing and support service levels affect response times from customer service, depending on whether the support level is silver, platinum, etc.
Which other solutions did I evaluate?
What other advice do I have?
I rate F5 Advanced WAF an eight out of ten.
Which deployment model are you using for this solution?
Comprehensive threat protection enhances security while user interface improvement needed
What is our primary use case?
I use and recommend F5 Advanced WAF as a web application firewall to protect various applications. It is particularly effective in load balancing and enforcing security policies.
How has it helped my organization?
F5 Advanced WAF efficiently handles traffic and secures web applications, protecting sensitive data best for governmental organization. It ensures compliance with security standards by providing features like PCI DSS checks.
What is most valuable?
F5 Advanced WAF provides valuable features like signature-based protection, which includes up-to-date threat signatures for common attacks such as SQL injections and DoS protection. It also supports a load balancer for enhanced security and traffic management.
What needs improvement?
There are opportunities for improvement in updating the user interface to a more modern look. Additionally, the speed of technical support and community responses could be enhanced.
For how long have I used the solution?
I have been working with F5 Advanced WAF for two years.
What do I think about the stability of the solution?
F5 Advanced WAF is very stable when configured properly.
What do I think about the scalability of the solution?
F5 Advanced WAF is highly scalable and can handle large amounts of traffic due to its advanced load balancing capabilities.
How are customer service and support?
The technical support team provides responses within a day for critical issues, however, the community support can be slow, sometimes taking up to two weeks for a response.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
I have also used open-source WAF solutions such as OpenAppSec.
How was the initial setup?
The initial setup of F5 Advanced WAF is complex and requires detailed planning, especially for configuration files and management interfaces.
What about the implementation team?
Our internal team implemented F5 Advanced WAF with support from F5's sales engineers.
What was our ROI?
While F5 Advanced WAF is expensive, the investment is justified by its comprehensive security features.
What's my experience with pricing, setup cost, and licensing?
F5 Advanced WAF is notably costly, especially for small companies, however, it provides strong protection for its price.
Which other solutions did I evaluate?
l evaluated open-appsec as an alternative WAF solution.
What other advice do I have?
I would rate F5 Advanced WAF a seven out of ten.
It is important to learn the network and security landscape before deploying. Understanding cybersecurity concepts and signature-based attacks is crucial.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Empower critical applications with comprehensive protection and enhanced security capabilities
What is our primary use case?
I was in charge of the F5 on-premises solution, where I published several applications for certificate verification and protected various applications. Additionally, I was working with botnets.
What is most valuable?
F5 Advanced WAF is a comprehensive community platform with a strong commitment, making it valuable for businesses. The capabilities on GitHub are highly appreciated, allowing me to count on F5 for reliability.
What needs improvement?
I would like to see improved features in the F5 Advanced WAF solution, especially with a focus on enabling Kubernetes fully. The database needs better service discussions and updates on communication. Additional improvements could also be made in asset management for the data.
For how long have I used the solution?
I've been working with F5 for what seems like a lengthy period.
What do I think about the stability of the solution?
F5 is logistics-oriented, ensuring that the Webpack performs well in making every single case for the Stereo platform.
What do I think about the scalability of the solution?
F5 is scalable, especially for Stellar and virtualization processes. Customers can scale efficiently.
How are customer service and support?
F5's technical support team is commendable. They are professional and take high-priority prompts seriously.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
My experience includes comparing F5 with FortiWeb. F5 provides more security capabilities for applications than FortiWeb.
How was the initial setup?
The initial setup of the F5 Advanced WAF solution involves multiple stages and might require revisiting configurations based on customer needs. The setup can be complex compared to other options.
What about the implementation team?
I am part of the deployment and implementation team, and we follow a strategy that involves providing quality assurance to ensure data integrity and server protection. Collaboration and dialogue with customers are part of the implementation.
What was our ROI?
Customers have shown consistent ROI with F5 solutions, especially when daily requests come in for assistance.
What's my experience with pricing, setup cost, and licensing?
The user interface and sub-management prices can be a concern, however, they generally align with the industry's needs.
What other advice do I have?
I recommend the F5 Advanced WAF solution for everyone with critical applications. Security needs to be embedded within the full visualization pipeline, allowing significant savings. I rate F5 Advanced WAF at a nine out of ten.
Which deployment model are you using for this solution?
Bot attack reduction and enhanced web security with reasonable pricing
What is our primary use case?
We use this solution for load balancing and web application firewall (WAF) services. We use the solution standalone and not integrated with other solutions.
How has it helped my organization?
It provides web application security and reduces bot attacks.
What is most valuable?
The web attack signatures are very important for detecting attacks, and the bot detection capability is an important feature that works well with F5 Advanced WAF.
What needs improvement?
The product could be more user-friendly for administrators. The user interface could be easier.
For how long have I used the solution?
I have been using it for almost three years.
What do I think about the stability of the solution?
The solution is very stable. I would rate its stability as nine out of ten.
What do I think about the scalability of the solution?
Very scalable. We use this solution for multiple customers and across data centers.
How are customer service and support?
The solution offers good support. That said, sometimes it takes too much time to reach the right person.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have also worked with Citrix NetScaler and F5 products, depending on customer needs.
How was the initial setup?
The initial configuration is not too difficult, but subsequent configurations can be complex because they depend on customer needs.
What's my experience with pricing, setup cost, and licensing?
I don't have direct knowledge of the pricing. From what I know, it is not too expensive compared to other solutions.
Which other solutions did I evaluate?
I am familiar with F5 and Citrix NetScaler solutions.
What other advice do I have?
I recommend this product to others because of its effectiveness in mitigating threats.
I'd rate the solution eight out of ten.