Cloudflare vs Imperva Web Application Firewall comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cloudflare
Average Rating
8.4
Number of Reviews
57
Ranking in other categories
CDN (1st), Distributed Denial of Service (DDOS) Protection (1st), Cloud Security Posture Management (CSPM) (13th)
Imperva Web Application Fir...
Average Rating
8.6
Number of Reviews
47
Ranking in other categories
Web Application Firewall (WAF) (6th)
 

Mindshare comparison

As of June 2024, in the Distributed Denial of Service (DDOS) Protection category, the mindshare of Cloudflare is 15.5%, down from 19.3% compared to the previous year. The mindshare of Imperva Web Application Firewall is 0.7%, down from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial of Service (DDOS) Protection
Unique Categories:
CDN
23.5%
Cloud Security Posture Management (CSPM)
2.4%
Web Application Firewall (WAF)
7.0%
 

Featured Reviews

RI
Jun 1, 2023
A stable and scalable DNS management tool to secure websites and servers
The most valuable feature of the solution is the proxy, so I can hide my servers. So no one can scan them, especially for port scanning, since we were hacked once. I did buy a VPS server, and I was just getting started. So I started MongoDB and left the port open. Someone scanned the website and saw the open port, and since I was just starting, I didn't set a password. He managed to get in, and he locked the database and locked all the data (ransomware). When using Cloudflare, I was sure that no one knew my real server IP address.
VL
Aug 31, 2022
An easy-to-use solution that integrates seamlessly to block OWSAP attacks
The solution is used to detect and block application attacks on the internet perimeter. We integrate the solution with SOAR and Phantom to automate our playbook and block URLs The solution reduces the risk of attacks and that benefits our clients.  The solution integrates seamlessly with other…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"Easier http to https redirect using page rules"
"The simplicity of the overall dashboard makes it a great product for a user like me who has less understanding of the internet than a developer or other more technical people. It gives me peace of mind. I also love the easy customization of the Page Rules."
"It's very user-friendly."
"It is easier to configure and develop documentation to see how we have configured firewalls."
"Smaller businesses have seen great ROI due to the low investment and strong performance."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"From what I've seen so far, there are no negatives to report as of yet"
"The solution is scalable."
"The solution is stable."
"Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva."
"The WAF itself has been very valuable to me because it has such a complete range of features. Another reason why I like it is because it also takes care of the total overview of the traffic over the network."
"There is a quick switch between any of the the nodes if something goes wrong, where there's a there's an attack against a specific area. The security setup is reasonably easy. It's not a problem to do setups and rules and integrations. And, yeah, just the the back end team is also very willing to insist if there's questions that that we cannot answer or with these questions that we do have"
"Imperva is easy to use and deploy. The UI is excellent."
"The tool's profiling feature maps all the web application directories and related components on the profile directory. It has improved the security of my client's website applications."
"It has fewer false positives"
 

Cons

"The pricing could be improved."
"The product needs to improve its automation."
"It should have easier documentation for the configuration. It's very technical and people who aren't technical should also be able to do the configuration."
"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"It should confirm audit findings of the assigned area with auditees to ensure that the audit conclusions are based on an accurate understanding of the issues."
"They lack a good way to manage DNS as a company, since everything is relegated to single account logins until you get to the higher levels. They have come out with a paid feature to remedy this, but I have not had a chance to fully review it yet to know if it fixes the access problem."
"In the last two years, there has been a certain amount of downtime when using the VDM."
"For the free and Pro plans, Cloudflare could use a simple bot to provide information to users. This would improve support, especially for less advanced users who utilize the free components."
"The signature updates could be faster. Sometimes we have to upload signatures to the Imperva portal for checking and analysis before we can use them."
"The process to upgrade from one version to another can be a lot simpler than it is currently."
"Imperva Web Application Firewall is a good system, but we found that the visibility of the diverse-path server, e.g. where the traffic is coming from, the different IPs, etc., needs improvement."
"The support for the on-premises version needs improvement."
"There could be some limitations that from the converged infrastructure perspective: when you want to converge with everything and you want Imperva to get there easily because it's not a cloud component. For example, when you want to build servers and you're using OneView to manage your software-defined networks, implementing Imperva right away is not that simple. But if you're doing just a simple cloud infrastructure with servers in there, you're good to go. Also, we are not able, with Imperva, to block by signatures. Imperva by itself needs to be complemented with another service to do URL filtering."
"The UI interface needs improvement."
"There's always room for improvement. Occasionally, there might be false-positive alerts."
"It would be nice to have more security control over mobile applications so I would suggest adding more mobile security features. It would also be beneficial to see improvements in regards to interface bandwidth performance, CPU time, and RAM size. Learning capability of the device is quite weak."
 

Pricing and Cost Advice

"The cost primarily depends on the size of the organization."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"There are no additional costs beyond the standard licensing fees."
"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"The product's pricing is cheap."
"There is a license for this solution and we purchase the license annually with no additional fees."
"The solution's pricing is an issue."
"Imperva Web Application Firewall is expensive."
"It's an excellent product, but it can be very costly."
"We sell three-year licenses for Imperva Web Application Firewall to our customers. The price is a little expensive."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
"There are some licenses that you have to buy to use some features. Its price could be better. Price is always important because, at the end of the day, customers have a budget. If you can meet the budget, you can sell, and if you don't, you cannot sell."
"The price of this solution is a little bit high compared to competitors."
report
Use our free recommendation engine to learn which Distributed Denial of Service (DDOS) Protection solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Educational Organization
38%
Computer Software Company
11%
Financial Services Firm
8%
Manufacturing Company
4%
Financial Services Firm
18%
Computer Software Company
14%
Manufacturing Company
7%
Insurance Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GRE tunnels. We have decreased site load times on Mobile 3G from 8 to 1,6 seconds ...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What is your experience regarding pricing and costs for Cloudflare?
The tool's pricing is moderate. I rate the product’s pricing a five out of ten, where one is cheap, and ten is expensive.
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you have to look for other ADC's like F5, Imperva, Radware, Fortinet, etc.
DDoS solutions: Any other solutions to consider aside from Radware DefensePro and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot of DDoS attacks that were well managed (even not seen by the customer) by Imperv...
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about Cloudflare vs. Imperva Web Application Firewall and other solutions. Updated: February 2023.
787,779 professionals have used our research since 2012.