I am working with an integration and security company that collaborates with various vendors. I am currently dealing with F5 Advanced WAF.
F5 Advanced WAF with LTM, IPI, and Threat Campaigns (PAYG, 25Mbps)
F5, Inc. | 17.5.1-0.0.7Linux/Unix, CentOS 7.3 - 64-bit Amazon Machine Image (AMI)
External reviews
External reviews are not included in the AWS star rating for the product.
Bot protection capabilities enhance application security
What is our primary use case?
What is most valuable?
The whole mechanism of F5 Advanced WAF is effective. It contains the logic of both negative and positive security combined, providing added value to the company I work with to protect their applications.
What needs improvement?
I do not have anything in mind right now that needs improvement. Generally, it works well. If we need any specific feature, we approach F5 directly.
For how long have I used the solution?
I have probably used it for ten years or so.
How are customer service and support?
I do not need them much because my team is professional. If there is a bug, the support is usually understanding and resolves issues.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
The price is affordable and satisfactory.
What other advice do I have?
One of the best features is the bot protection capabilities. I rate the product eight out of ten.
Client-side and mobile app protection with 24/7 support for security
What is our primary use case?
F5 Advanced Web Application Firewall (AWAF) is primarily used in financial sectors like banking to secure web applications against advanced threats, ensuring compliance with industry regulations. Our Key use cases include:
- Protection Against OWASP Top 10: Safeguarding banking applications from SQL injection, XSS, and other common vulnerabilities.
- Bot Mitigation: Detecting and blocking malicious bots to prevent account takeovers, credential stuffing, and fraud.
- DDoS Protection: Defending against application-layer DDoS attacks to ensure service availability.
- PCI DSS Compliance: Enforcing security policies to meet compliance standards for protecting sensitive customer data.
- API Security: Securing APIs used in banking platforms from abuse and unauthorized access.
- Threat Intelligence: Leveraging threat intelligence to identify and mitigate zero-day attacks.
- Application Traffic Control: Managing and monitoring application traffic to ensure optimal performance and security.
These use cases help financial institutions maintain secure and resilient applications, critical for trust and compliance.
How has it helped my organization?
F5 Advanced WAF has significantly enhanced our organization's security posture by protecting critical banking applications against sophisticated threats. It ensures compliance with regulatory standards, improves customer trust through robust bot mitigation, and enhances application performance by mitigating DDoS attacks and securing APIs. Additionally, it provides real-time threat intelligence and streamlined security management, reducing downtime and operational risks.
What is most valuable?
Bot Protection: Mitigates automated attacks like credential stuffing.
API Security: Safeguards APIs against exploitation.
Advanced Threat Detection: Protects against OWASP Top 10 vulnerabilities and zero-day threats.
DDoS Mitigation: Ensures application availability during attacks.
Behavioral Analytics: Detects and mitigates anomalous traffic patterns.
Granular Policy Control: Enables precise security policy customization.
Threat Intelligence Integration: Offers real-time updates for proactive protection.
What needs improvement?
- Ease of Deployment: Simplify initial setup and policy configuration.
- UI Enhancements: Improve user interface for better navigation and usability.
- Integration: Enhance compatibility with third-party tools like SIEMs and DevOps pipelines.
- Performance Optimization: Reduce latency during high traffic volumes.
Suggested Features for Next Release:
- AI-Driven Threat Detection: Advanced machine learning for proactive defense.
- Comprehensive API Protection: Extended support for GraphQL and WebSocket APIs.
- Cloud-Native Integration: Better functionality in hybrid and multi-cloud environments.
- Automated Policy Suggestions: AI-based recommendations for policy tuning.
For how long have I used the solution?
It's been two years that I've been working with this solution.
What do I think about the stability of the solution?
I am not experiencing any significant instability.
What do I think about the scalability of the solution?
F5 AWAF offers excellent scalability, enabling organizations to protect applications seamlessly across on-premises, cloud, and hybrid environments. It can handle increasing traffic volumes with minimal latency, ensuring consistent security for both small-scale deployments and enterprise-grade architectures. With its ability to integrate into CI/CD pipelines and auto-scale in cloud environments, F5 AWAF supports dynamic application growth without compromising performance or protection.
How are customer service and support?
Customer service is very responsive. If the issue persists beyond my local support capabilities, I open a ticket with F5, and they respond quickly. I rate their technical support 9 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Not now just I have checked the comparision and collect reviews from peerspoot and Quadrant
How was the initial setup?
The initial setup experience is straightforward, and I did not face any complexities. I recommend deploying the F5 AWAF solution on a single appliance with LTM.
What's my experience with pricing, setup cost, and licensing?
F5 is relatively less expensive compared to other solutions as F5 is considered the best.
Which other solutions did I evaluate?
Not Now
What other advice do I have?
I rate F5 eight to nine out of ten. I recommend F5 to customers who require a robust solution and have the budget for it. However, for customers looking for modest pricing, I would not recommend the F5 solution.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Protects applications with versatile authentication features
What is our primary use case?
The primary use case for F5 Advanced WAF is to protect applications that are exposed to the internet. It is used to protect applications from known attacks, such as cross-site scripting and DDoS attacks.
What is most valuable?
F5 offers a versatile solution that can be integrated with APM in cases where integration with an external IDB is needed. It is useful for authentication backup if the on-prem directory service is unavailable.
Additionally, its WAF functionality is valuable for protecting applications from attacks. It is a versatile and strong solution that's easy to understand and deploy.
What needs improvement?
The DDoS capabilities should be enhanced. More advanced features related to DDoS would be beneficial.
For how long have I used the solution?
I have been working with F5 Advanced WAF since 2017, which is almost eight years.
What do I think about the stability of the solution?
The stability is high. It's a robust product with high availability, ensuring no disruptions for end-users if a node failure is detected. Our deployments are based on high availability clustering.
What do I think about the scalability of the solution?
F5 Advanced WAF is highly scalable, both in its physical and virtual forms. Its scalability is based on the search, making it adaptable for various needs.
How are customer service and support?
The support from F5 is excellent, with resources readily available online. The quality of support depends on the service SLA purchased, with various levels of service provided.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of F5 Advanced WAF is straightforward and easy to understand. Without prior training, I could build and publish applications using just the documentation.
What about the implementation team?
For standard and straightforward deployments, the implementation can be handled by a single person or a team based on the customer's size. Professional service can simplify the process significantly.
What's my experience with pricing, setup cost, and licensing?
The pricing is not cheap; I rate it a six out of ten.
While it reflects the advanced capabilities of the product, reconsideration of the pricing is suggested.
What other advice do I have?
For reverse proxy solutions, F5 Advanced WAF is the best choice.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Securing web applications with API and bot protection while enhancing IP intelligence
What is our primary use case?
The primary use case is to secure the organization's applications from web-based attacks, securing both web applications and APIs.
What is most valuable?
The product is used to secure web applications and has the ability to use API templates and bot protection features, such as blocking requests or presenting CAPTCHA pages to end users. We also implement Swagger files for API security and use custom profiles for device ID threshold management.
What needs improvement?
The main improvement needed is related to IP intelligence. Once we start receiving traffic from repetitive IP addresses, we have to report it to the SOC team to block it at the layer four level. Users would like to have an additional IP intelligence license to handle this within WAF itself without needing to engage with the SOC team.
For how long have I used the solution?
The solution has been used for three years.
How are customer service and support?
Customer service and support depend on the level of support subscribed to, such as silver or platinum support, which determines the response time.
How would you rate customer service and support?
Positive
How was the initial setup?
Deploying the solution involves an application learning and blocking phase. The process includes collecting application data, creating policies, and applying them to lower testing environments like QA or dev before moving to UAT and production. The learning phase is used to handle false positives and fine-tune the policies before going live.
What about the implementation team?
The in-house team manages and supports the WAF, handling incidents reported by end users when legitimate traffic is blocked. They update the policies to prevent the recurrence of similar blocks.
What's my experience with pricing, setup cost, and licensing?
The pricing and support service levels affect response times from customer service, depending on whether the support level is silver, platinum, etc.
Which other solutions did I evaluate?
What other advice do I have?
I rate F5 Advanced WAF an eight out of ten.
Which deployment model are you using for this solution?
Bot attack reduction and enhanced web security with reasonable pricing
What is our primary use case?
We use this solution for load balancing and web application firewall (WAF) services. We use the solution standalone and not integrated with other solutions.
How has it helped my organization?
It provides web application security and reduces bot attacks.
What is most valuable?
The web attack signatures are very important for detecting attacks, and the bot detection capability is an important feature that works well with F5 Advanced WAF.
What needs improvement?
The product could be more user-friendly for administrators. The user interface could be easier.
For how long have I used the solution?
I have been using it for almost three years.
What do I think about the stability of the solution?
The solution is very stable. I would rate its stability as nine out of ten.
What do I think about the scalability of the solution?
Very scalable. We use this solution for multiple customers and across data centers.
How are customer service and support?
The solution offers good support. That said, sometimes it takes too much time to reach the right person.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have also worked with Citrix NetScaler and F5 products, depending on customer needs.
How was the initial setup?
The initial configuration is not too difficult, but subsequent configurations can be complex because they depend on customer needs.
What's my experience with pricing, setup cost, and licensing?
I don't have direct knowledge of the pricing. From what I know, it is not too expensive compared to other solutions.
Which other solutions did I evaluate?
I am familiar with F5 and Citrix NetScaler solutions.
What other advice do I have?
I recommend this product to others because of its effectiveness in mitigating threats.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Enhanced web security and significant bot detection capabilities and good support
What is our primary use case?
We use the solution for load balancing and web application firewall (WAF) balancing. We operate in a data center and use it for web application security and services.
How has it helped my organization?
The solution provides strong web security, particularly against web attacks, and has effective bot detection that helps reduce bot attacks.
What is most valuable?
Web attack signatures are very important for detecting web attacks. The bot detection feature is also crucial in reducing bot attacks.
What needs improvement?
The product could be more user-friendly, particularly the user interface for administrators. Additionally, configuration can be quite complex and needs improvement to be less complex.
For how long have I used the solution?
I've been using it for almost three years.
What do I think about the stability of the solution?
The product is very stable. From one to ten, I would rate its stability at a nine out of ten.
What do I think about the scalability of the solution?
The solution is scalable. We use it for multiple customers and data centers, and I would rate its scalability as nine.
How are customer service and support?
The customer service is good. That siad, sometimes it takes too long to reach the right person. I would rate their effectiveness as an eight.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I am familiar with Citrix NetScaler and F5.
How was the initial setup?
The initial setup was not too challenging. Post-initial configurations can be complex.
What about the implementation team?
Two to three engineers are typically involved in maintenance operations.
What's my experience with pricing, setup cost, and licensing?
I don't know the exact pricing. It is not the cheapest yet not the most expensive. It depends on needs, budget, and vision.
Which other solutions did I evaluate?
I have experience with Citrix solutions.
What other advice do I have?
I recommend this product to others.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Geolocation feature works fine and minimize the effects of attacks
What is our primary use case?
We use F5 Advanced WAF to restrict attacks on our remote access VPN. We've implemented geolocations. Our APIs are exposed over the Internet, so we've utilized F5 Advanced WAF to protect those APIs, and it's integrated with our other applications.
How has it helped my organization?
The WAF solution works perfectly fine. If we face any issues, we get hotfixes from the solution experts. It is a little bit difficult to engage with a solution expert firsthand, but once they're engaged, they do whatever is best to resolve the issue.
We faced a lot of outside attacks on our VPNs and APIs, so the geolocation feature works perfectly fine for us. We use iRules as well. Our internal access VPN is advertised from a Cisco firewall, and above that, we have an F5 LTM. We have written some iRules on it to minimize the effects of attacks.
We are a PCI DSS-compliant organization, and we have a lot of security balance to improve our infrastructure. So we use this software to meet those requirements. It works well. So, F5 helped to meet compliance and regulatory requirements.
What is most valuable?
It's pretty smooth. Whichever load we put on it, we've observed minimal chances of the WAF exploiting the memory or sessions hanging.
The bot protection aspect works perfectly fine. All the solutions and features are renewed and they're working well. I don't see anything that can be improved.
We also leveraged AI initiatives.
What needs improvement?
Support is a little slow, but the solution itself is great. If I compare F5 and Fortinet, the main issue is the support. With Fortinet, it takes less time to engage a support engineer and get things sorted compared to F5.
For how long have I used the solution?
I have been using F5 Advanced WAF since last January.
I work for a US-based firm, and the project I deal with relies heavily on F5 and F5 LTMs.
I work on both F5 BIG-IP cloud and on-premises and F5 LTM.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
The physical hardware is not as scalable. We have to decide which version is best for us to procure because it is a costly device. So we try our best to get all the juice out of one box.
There's around 2500 users getting services from the F5. In my team, we are twelve engineers who are managing the infrastructure.
How are customer service and support?
Support is a little slow, but the solution itself is great. If I compare F5 and Fortinet, the main issue is the support. With Fortinet, it takes less time to engage a support engineer and get things sorted compared to F5.
I'll give F5 a five because it is difficult to engage an engineer and get the issue sorted. For Fortinet, I'd give them a nine.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup process of the F5 WAF product is straightforward. There isn't an issue in setting up from scratch. We use F5 with the cloud as well, especially in Azure and AWS.
The deployment took around half an hour for an engineer to get the basic infrastructure done.
It is not difficult to manage bug fixes, upgrades, and everything. It doesn't take much time. The dashboards are good. All the basic information is given to us on the first page, and it's easy to manage.
What was our ROI?
It brings a return on investment.
What's my experience with pricing, setup cost, and licensing?
It is a little bit costly, but it has all the features that are required.
What other advice do I have?
I would recommend F5 Advanced WAF to other users looking to implement it.
My advice:
A lot of organizations are financially constrained when buying devices. So if the organization is capable of maintaining and managing a device like F5, we suggest F5. Otherwise, we suggest other solutions, like Fortinet or Citrix.
Overall, I would rate it an eight out of ten because of the support.
Which deployment model are you using for this solution?
A cost-effective solution for load balancing with data loss prevention
What is our primary use case?
We use the solution for load balancing.
What needs improvement?
They should improve the capability, and then they should work on the virtualization of NGINX. Currently, most environments are virtualized. F5 Advanced WAF will not be able to protect it.
For how long have I used the solution?
I have been using F5 Advanced WAF as a reseller for 5 years.
How are customer service and support?
Technical support is good but not enough. It takes a lot of time to get support.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is not so easy nor not so complex. There is a learning phase, and there are policies to apply. It complies with regulations. Recently, we used it for Formula One, and it proved very effective.
What was our ROI?
ROI is covered in one year. You can see how it protects and mitigates damages in the network.
What's my experience with pricing, setup cost, and licensing?
The product is not so expensive. It depends on the assets.
What other advice do I have?
There are other solutions for data loss prevention, such as Symantec and IP solutions. There are options available for DNS blocking. While these solutions may specialize in certain aspects, They offer comprehensive coverage across various areas. Each vendor specializes in different aspects, but F5 Advanced WAF excels in its particular domain.
I recommend the solution. Most of the environment is going to virtualization.
Overall, I rate the solution an 8 out of 10.
Efficiently protect web servers exposed to the external network and robust stability
What is our primary use case?
Primarily, the Advanced WAF sits behind our network perimeter. It centralizes traffic flow to our network, filters requests, and identifies any potential threats.
How has it helped my organization?
It helps us detect threats or malicious requests coming into the network, protecting it from being hacked. It helps guard against issues like cross-site scripting (XSS) and other similar threats.
So, F5 Advanced WAF helped mitigate bot traffic for our web applications.
Moreover, my experience is that it's pretty straightforward to use. Our firewall team handles requests through a change management tool within scheduled change windows. However, F5 is our only firewall solution.
What is most valuable?
It's a valuable tool to protect web servers exposed to the external network. With numerous web applications running on Apache or IIS servers, the F5 Advanced WAF's threat detection capabilities protect the network before traffic reaches those servers.
It's a fairly easy-to-use and user-friendly tool. My administrators and team also like its ability to customize the rules per the requirements.
What needs improvement?
The self-service aspect could be improved.
The user interface (UI) also seems a bit outdated. Making it more user-friendly would be beneficial.
For how long have I used the solution?
We've been using it for approximately five to six years.
What do I think about the stability of the solution?
I would rate the stability a ten out of ten. It is a stable product.
What do I think about the scalability of the solution?
It is pretty good. I would rate the scalability a seven out of ten.
Ssometimes, the way our enterprise handles change requests might slow things down because of the internal rules and processes. But these changes, once approved, do take effect immediately on the firewall itself.
We have a change window twice a week for these requests. I don't think the limitation is with the firewall itself; it's more about our internal procedures.
What other advice do I have?
Overall, I would rate the solution an eight out of ten because I have seen that not too much customization is required during setup. The change requests we submit are usually clear and easily applied.
Overall, the policies work well, and the threat detection is good. It catches deviations and anomalies effectively.
From a recommendation standpoint, it's a fairly easy tool to use. However, you definitely need some knowledge about scripting, OWASP fundamentals, threat detection, and general cybersecurity principles to get the most out of it.
The central point of all the applications being scrubbed and checked
What is our primary use case?
We use the solution to secure web applications running in the organization.
What is most valuable?
F5 is one of the best products. We use it for multiple segments within our organization and applications. It is a central point of all the applications being scrubbed and checked.
What needs improvement?
The customer service could be improved.
For how long have I used the solution?
I have been using F5 Advanced WAF for more than ten years.
What do I think about the stability of the solution?
The product is stable.
I rate the solution’s stability a seven out of ten.
What do I think about the scalability of the solution?
The solution is scalable.
Our entire organization and clients use the solution.
How was the initial setup?
The initial setup is easy since I have used the technology for almost 20 years. Some applications require more attention depending on what you are doing and trying to achieve with the particular module. You need some assistance from the team in configuring the different components within the application through the web.
What was our ROI?
The solution is worth the money that you spend.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive.
What other advice do I have?
Whatever you are looking for can be done on the platform. Some features may not be available with IO components. A few features give you the flexibility that no other product can.
Overall, I rate the solution an eight out of ten.