Try our new research platform with insights from 80,000+ expert users

A10 Networks Thunder SSL Insight (SSLi) vs NSFOCUS Web Application Firewall comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

A10 Networks Thunder SSL In...
Average Rating
9.0
Number of Reviews
3
Ranking in other categories
SSL/TLS Decryption (2nd)
NSFOCUS Web Application Fir...
Average Rating
7.0
Reviews Sentiment
8.0
Number of Reviews
1
Ranking in other categories
Web Application Firewall (WAF) (43rd)
 

Mindshare comparison

A10 Networks Thunder SSL Insight (SSLi) and NSFOCUS Web Application Firewall aren’t in the same category and serve different purposes. A10 Networks Thunder SSL Insight (SSLi) is designed for SSL/TLS Decryption and holds a mindshare of 32.5%, up 24.8% compared to last year.
NSFOCUS Web Application Firewall, on the other hand, focuses on Web Application Firewall (WAF), holds 0.4% mindshare, up 0.2% since last year.
SSL/TLS Decryption Market Share Distribution
ProductMarket Share (%)
A10 Networks Thunder SSL Insight (SSLi)32.5%
GigaSMART26.2%
Symantec SSL Visibility Appliance21.4%
Other19.900000000000006%
SSL/TLS Decryption
Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
NSFOCUS Web Application Firewall0.4%
F5 Advanced WAF9.2%
Microsoft Azure Application Gateway7.8%
Other82.6%
Web Application Firewall (WAF)
 

Featured Reviews

CH
We used to have to bypass on the firewall, proxy, and IPS; now we can do it in one place
For us, it would be great if it supported SSL operations according to Active Directory users. For example, if we want to bypass one of the servers or a client's internet access for SSL interception, we have to do it according to the IP address. It would be better if we could do it according to the Active Directory username. A10 says they kind of support that but we haven't tested it. Another thing is SNI. A10 intercepts all the traffic according to the SNI, the server name indicator. It would be better if it intercepted traffic according to the IP addresses. A10 can only understand that a website is within the banking category or the website is in the social media category, according to the SNI. Without SNI, there is no way to understand it; there is no bypass operation. It would be better if worked without SNI as well. Also, the solution comes with web categories like banking and social media. There are suspicious URLs, malicious URLs, etc. It would be better if it had an application category as well. For example, it would be helpful if we had the chance to bypass all Office 365 applications: OneDrive, Skype, Outlook, etc. According to Microsoft, we need to bypass SSL for all Office 365 applications but we need to create custom categories and put all the Microsoft URLs in them and then we can bypass. It would be great if an application category could recognize Dropbox, for example. For now, we have to put the Dropbox URLs in one custom category and bypass them. Application categories could be very useful.
it_user933945 - PeerSpot reviewer
Offers Application Protection Against Web Attacks
There is a need for expanded licensing terms and options. There's also a need for improved and more agile customization features. The user needs to be able to manage each policy as required; the functionality needs to empower the user. There should be a complete suite of desktop provider policies available to users. Overall, it needs to be more user-friendly.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"With the Thunder SSLi, we're better protected. We can stop use of VPN and proxies. We are better protected against dirty traffic coming back to our schools. Having a secure decrypt zone with the equipment lowers the chances that our security infrastructure could possibly miss an attack."
"We have several proxies in our environment, so we localized internet traffic between these proxies. Instead of getting a really huge proxy box, according to our size, we can use three boxes and share the traffic with A10's load-balancer feature."
"Its most valuable feature is its ability to do its job accurately, effectively, and very quickly. The amount of traffic that we have going through our system is astounding... The delay with the SSL decryption turned on is almost unnoticeable."
"Since we are using this tool for protection purposes we really appreciate the hybrid security abilities; the main idea here is that we powerful protection our application needs."
 

Cons

"I would like them to have a better UI (better universal design)."
"It would be great if it supported SSL operations according to Active Directory users. For example, if we want to bypass one of the servers or a client's internet access for SSL interception, we have to do it according to the IP address. It would be better if we could do it according to the Active Directory username. A10 says they kind of support that but we haven't tested it."
"There is one thing I would like to see changed. In their features for setting things up, there is a templating system that would normally assist clients. However, we had a better time setting up the device either through the command line or through the interface and not using the templates that were pre-installed. So there is room for improvement to the templates for initial installation."
"There is a need for expanded licensing terms and options. There's also a need for improved and more agile customization features. The user needs to be able to manage each policy as required; the functionality needs to empower the user. There should be a complete suite of desktop provider policies available to users. Overall, it needs to be more user-friendly."
 

Pricing and Cost Advice

"When you purchase the equipment, you purchase the licensing and warranty. It's all fairly standard. We haven't been caught with anything surprising."
"Our licensing costs, yearly, are just under $15,000. Your initial cost of acquisition is obviously going to be more than $15,000..."
"We always pay for support. Any organization of our size who doesn't is asking for problems."
Information not available
report
Use our free recommendation engine to learn which SSL/TLS Decryption solutions are best for your needs.
868,229 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Government
9%
Manufacturing Company
9%
Recreational Facilities/Services Company
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
 

Also Known As

Thunder SSLi
NSFOCUS WAF, NSFOCUS Web Application Security
 

Overview

 

Sample Customers

Klein Independent School District
2016 G20 Summit
Find out what your peers are saying about Broadcom, A10 Networks, Fidelis Security and others in SSL/TLS Decryption. Updated: September 2025.
868,229 professionals have used our research since 2012.