Arbor DDoS and F5 BIG-IP Advanced Firewall Manager compete in the DDoS protection and network security category. Arbor has the upper hand in user-friendliness and traffic visibility, while F5 AFM excels in integration with other F5 modules.
Features: Arbor DDoS includes predefined filters for easy attack mitigation, cloud signaling for coordination between on-premises and service provider protection, and real-time threat intelligence for proactive defense. Its hybrid approach provides multi-layer protection. F5 BIG-IP AFM offers unified network security by integrating with other F5 solutions, advanced WAF capabilities for robust application defense, and simplifies management with its modular integration.
Room for Improvement: Arbor DDoS users seek improvements in auto-mitigation features, scalability of hardware, and better third-party integration. They also suggest enhancements in reporting and reducing false positives. F5 AFM could benefit from a simpler user interface, improved reporting, and enhanced automation capabilities. Customers also desire more intuitive configuration logic and better integration with BIG-IQ.
Ease of Deployment and Customer Service: Arbor DDoS supports on-premises and hybrid cloud deployments and is known for its good technical support, though response times vary by region. F5 AFM also supports both deployment models, with responsive customer service noted for occasional delays. Both products offer strong technical expertise, with Arbor noted for deep product knowledge.
Pricing and ROI: Arbor DDoS is regarded as high-performing but expensive compared to competitors, with costs related to enterprise throughput and managed routers. Its clear licensing is a positive, though overall expenses are a concern. F5 AFM, while also costly, provides value through integrated features. Both deliver significant ROI by mitigating costly DDoS attacks and ensuring service uptime.
For the small project I was working on, using the basic tier provided a huge improvement at zero cost.
In terms of return on investment with Cloudflare, it costs my time to set them up, but basically once they're set up, it's done.
Cloudflare does not offer hands-on technical support to fix customer problems but rather a self-service model.
I would rate the technical support with Cloudflare as excellent every time I've had to call them.
I have primarily worked not with the tool's customer support but with the product's sales engineers and technical sales engineers, who seem to know their stuff.
The technical support team is very effective in resolving issues.
Although the team is good, they are not fast, and they lack the skills to manage dynamic attackers.
Support for Arbor DDoS deserves a rating of 10 because when there is a problem with implementation, the people I work with are the best.
The responses are generally fast and effective.
The customer service is excellent, and I rate it ten out of ten.
It is a SaaS tool, but the fact that they have workloads deployed across the world proves that it is a highly scalable tool.
The tool offers very good performance, even during high-traffic periods.
I rate the solution’s scalability an eight out of ten.
This would enhance the knowledge about scalability options available for Arbor DDoS, making it more accessible and useful for users.
They need to purchase boxes monthly to expand their bandwidths, and these new boxes can be added to the installed base very easily.
I find Arbor DDoS to be very scalable.
The solution is highly scalable, allowing me to add or remove nodes and manage traffic without interruption, which is essential for meeting application demands.
I rate the solution’s stability an eight out of ten.
The service is very stable with no impacts during high-traffic periods.
It is a very stable product.
Arbor DDoS is very stable.
Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor.
Areas like how assessment, discovery, and payload are dealt with and how it all comes into your organization can be considered when trying to make suggestions to Cloudflare for improvements.
There are some performance considerations when it comes to dynamic content that involves fetching data from databases or using APIs.
I would like to see an option to decrypt the traffic with Arbor DDoS, as some clients are interested in this, particularly for application layer attacks on port 443.
Enhancing the handshakes between Arbor DDoS and third-party solutions is essential for obtaining better and real-time data that supports any organization’s support team effectively.
I would like to see a roadmap for one or two years, and it is tough to predict what will happen in that timeframe without a clearer description.
Having advanced technology similar to other vendors like Palo Alto for zero-day attack prevention would be valuable.
The appliance and features could be enhanced further, especially in terms of security.
I find it to be cheap.
I rate the product’s pricing a five out of ten, where one is cheap, and ten is expensive.
The tool is a premium product, so it is very expensive.
The prices for Arbor DDoS are expensive.
For some customers, the cost is expensive, but for enterprises looking to protect their services, it is affordable.
The standard license is reasonably priced, but additional features like the WAF can be more expensive.
If considering a one-stop solution that provides load balancing, DNS security, AAA authentication, and firewalling on the same hardware, the cost is reasonable.
The most valuable features of the solution are performance and security.
Techniques like minification and image compression reduce the size of assets, leading to better performance and faster user load times.
The solution has been able to compare it to the market, and I think the product has taken great strides in automating quite a bit of things, and they use a lot of AI.
That is an attack over 10 gigabit per second, and if an attack enters the telecommunication network, that will be a disaster for their customer, their services, and so on.
We have many updates for the library of different attacks, and they have artificial intelligence that automatically learns the process during different attacks.
The platform offers quick mitigation of attacks because Arbor DDoS uses BGP Flowspec, enabling very quick mitigation.
The solution provides behavioral analysis via AI to detect malicious traffic.
The most valuable features for me are stability, availability, and security, along with the ability to manage multiple features to secure my applications.
| Product | Market Share (%) |
|---|---|
| Cloudflare | 17.8% |
| Arbor DDoS | 10.2% |
| F5 BIG-IP Advanced Firewall Manager (AFM) | 1.2% |
| Other | 70.8% |

| Company Size | Count |
|---|---|
| Small Business | 46 |
| Midsize Enterprise | 8 |
| Large Enterprise | 25 |
| Company Size | Count |
|---|---|
| Small Business | 25 |
| Midsize Enterprise | 14 |
| Large Enterprise | 29 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 5 |
| Large Enterprise | 14 |
Cloudflare enhances web performance and security with features like CDN caching and DDoS mitigation while providing easy DNS management and intuitive setup through its user-friendly dashboard.
Cloudflare is recognized for its comprehensive web security and performance solutions. Speed improvements are achieved through caching mechanisms and DDoS protection, combining ease of DNS management with flexible page rules. The robust analytics and threat insight tools provide valuable data, assisted by a user-friendly dashboard allowing quick setup and configuration. An API offers dynamic DNS settings ensuring low latency and high performance across the globe.
What are Cloudflare's key features?Cloudflare finds utility across industries for DNS management and defense mechanisms. Its content delivery network assures fast content distribution and fortified security. Businesses integrate features like web application firewalls, load balancing, end-to-end SSL, and zero trust to protect websites from cyber threats while ensuring resilience and reliable performance.
Arbor DDoS offers a comprehensive defense system against DDoS attacks, integrating a user-friendly GUI and advanced threat mitigation technologies for enhanced network protection.
Arbor DDoS is recognized for its ability to manage high-volume DDoS attacks efficiently, providing extensive protection through real-time traffic analysis and automated threat detection. It utilizes advanced techniques such as blackhole and BGP Flowspec for effective threat management. Arbor's cloud signaling allows users to handle and mitigate volumetric attacks while maintaining service availability. Though it provides robust security features, users note potential improvements in auto-mitigation, scalability, and AI integration. Challenges like an outdated graphical interface, hardware stability, and false positives need addressing to further enhance its usability and integration with third-party systems.
What are the key features of Arbor DDoS?Internet service providers and telecom companies commonly adopt Arbor DDoS to protect their networks and infrastructure from DDoS attacks. It is also implemented in financial and government sectors to ensure web application security and maintain high availability. Arbor DDoS supports a hybrid approach, utilizing both on-premise and cloud solutions to manage traffic efficiently and sustain service quality during attacks.
F5 BIG-IP Advanced Firewall Manager (AFM) is a high-performance, full-proxy network security solution designed to protect networks and data centers against incoming threats that enter the network. Built on F5’s industry-leading BIG-IP hardware and software platforms, BIG-IP AFM provides a scalable platform that delivers the flexible performance and control needed to mitigate aggressive distributed denial-of-service (DDoS) and protocol attacks before they overwhelm and degrade applications and infrastructure availability.
For service providers, BIG-IP AFM IPS does even more, protecting the network edge and performing traffic inspection and protocol adherence for prevalent service provider protocols such as SS7, Diameter, HTTP/2, GTP, SCTP and SIP traffic coming into the network over UDP, TCP, and SCTP.
We monitor all Distributed Denial-of-Service (DDoS) Protection reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.