No more typing reviews! Try our Samantha, our new voice AI agent.

Atomic ModSecurity Rules vs F5 Advanced WAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Ranking in Web Application Firewall (WAF)
6th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
No ranking in other categories
Atomic ModSecurity Rules
Ranking in Web Application Firewall (WAF)
29th
Average Rating
9.0
Reviews Sentiment
7.8
Number of Reviews
1
Ranking in other categories
No ranking in other categories
F5 Advanced WAF
Ranking in Web Application Firewall (WAF)
3rd
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
72
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Web Application Firewall (WAF) category, the mindshare of Cloudflare Web Application Firewall is 3.8%, down from 5.8% compared to the previous year. The mindshare of Atomic ModSecurity Rules is 0.8%, down from 1.0% compared to the previous year. The mindshare of F5 Advanced WAF is 3.9%, down from 8.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
F5 Advanced WAF3.9%
Cloudflare Web Application Firewall3.8%
Atomic ModSecurity Rules0.8%
Other91.5%
Web Application Firewall (WAF)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
Vahid Babaey - PeerSpot reviewer
PhD Student at University of North Carolina at Charlott
Open rules have enabled me to secure web apps against obfuscated SQL injection and XSS attacks
The best feature Atomic ModSecurity Rules offers is the open source aspect. I believe that because it's open source, all of the developers, programmers, and security experts are able to update this WAF and provide more rules, creating a more secure WAF for all of the clients and customers around the world. By accessing Atomic ModSecurity Rules, it has helped me significantly. Because of this open source feature, I am able to generate new rules and update the WAF and use this WAF in my research and also give it to other clients and customers to use the updated WAF. All of this is done just because of the open-source feature, because it can be updated.
reviewer2797602 - PeerSpot reviewer
Senior Security Systems Engineer at a tech services company with 11-50 employees
Granular security policies have protected critical applications and ensure safe user and admin access
Improvements could be made regarding the log information from the backend CLI. There are enhancements needed; if a request gets blocked on the TCP layer, there should be traces or data to verify which source generated these requests, including the source and port information for initiation. These data are missing from F5 Advanced WAF. Besides that, another improvement could be refining the bot detection to minimize false positives; it should be able to verify more granularly between legitimate and non-legitimate clients. Overall, I find everything else good. A wish list feature I have is for the Technical Assistance Center (TAC) to respond more promptly. Their response time needs improvement; while they do not take excessive time, it can be enhanced, especially given it is a security product.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Someone with a basic understanding of networking and security will be able to implement the firewall's basic features within 15 minutes."
"We extensively use the solution every day. The solution is very stable; we haven’t seen any glitches."
"I have not had any issues with this solution, and I would recommend it to others who are interested in using it."
"Very glad the WAF rulesets works out of box, and requires very little tuning or maintenance."
"Some of the most valuable features of Cloudflare Web Application Firewall include its DNS zone setup and the zero trust policy."
"We like that there's load balancing, firewall capabilities, DDoS protection, et cetera, all covered by Cloudflare."
"It protects web applications efficiently."
"Caching is the most valuable feature of Cloudflare Web Application Firewall."
"The best feature Atomic ModSecurity Rules offers is the open source aspect, because all of the developers, programmers, and security experts are able to update this WAF and provide more rules, creating a more secure WAF for all of the clients and customers around the world."
"I appreciate the way F5 Advanced WAF builds policies by configuring a basic policy and queuing it in learning mode."
"Identification, ease of use, and ease of modifying it to most of our needs are valuable."
"Customers find the load balancer feature as the most valuable."
"The most valuable feature is that it is secure."
"There are a lot of good features."
"It's flexible and powerful, and the users can input their own rules to the system."
"It's a fairly easy-to-use and user-friendly tool. My administrators and team also like its ability to customize the rules per the requirements."
"This solution inspects your traffic and based on that, automatically create distinct qualities for you, so you can add this to the policy already created. That's what I like most."
 

Cons

"Their documentation could be better. They don't have documentation that explains everything well."
"The notification part could be improved. It's very much connected to Web Application Firewall, rate-limiting, and DDoS protection."
"The dashboard could be more user-friendly."
"The product can improve by having more multitenancy capability, which is currently not available."
"There could be an option to duplicate the cluster to maintain the consistency of rules."
"The blocked logs are difficult to read at times."
"WAF doesn't directly affect bandwidth costs. It saves costs on protection. However, with the correct setup, it's difficult to determine if it saves costs overall due to the fixed enterprise plan fee."
"Cloudflare Web Application Firewall should include port forwarding features."
"Additionally, I know that ModSecurity can block only SQL injection and XSS attacks, no more types of attacks."
"We get false positives sometimes."
"The product could be more user-friendly for administrators."
"You have to buy another module with an extra license, to have the authentication feature."
"The BNS module needs improvement."
"The interface is old-looking, it's not modern, which is why it's not always comfortable to use."
"I think the solution is already being phased out."
"I think the price is very high. This is what I hear from the customers."
"The solution is pretty difficult to set up. You really have to have a grasp of the product to configure it correctly."
 

Pricing and Cost Advice

"The solution is expensive."
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"The solution's pricing option needs to be more transparent for enterprise clients."
"We pay $210 per month for CloudFlare WAF."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"It is not too pricey."
"The annual licensing fee is $10,000 USD."
Information not available
"It's more expensive than other solutions and depending on the modules, there can be additional fees."
"F5 Advanced WAF pricing structure should be adjusted to meet the need of small to medium-sized companies."
"There are different licenses available to use F5 Advanced WAF, such as BT, ASM, and LPM."
"A yearly license for F5 Advanced WAF is expensive."
"There are various plans available for Fortinet FortiWeb Cloud WAF as a Service, including a trial version."
"The price of the solution is reasonable when compared with other products, such as FortiWeb. I am very satisfied with the price."
"It is expensive. Its price should be better. Its licensing is on a yearly basis. Its licensing is also based on the model. There are no additional costs."
"The price of F5 Advanced WAF could improve it is expensive."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
909,153 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
16%
Financial Services Firm
9%
Comms Service Provider
9%
Outsourcing Company
8%
Comms Service Provider
29%
Hospitality Company
12%
Construction Company
9%
Government
9%
Financial Services Firm
15%
Computer Software Company
9%
Comms Service Provider
9%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
No data available
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise16
Large Enterprise31
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What needs improvement with Atomic ModSecurity Rules?
Atomic ModSecurity Rules can be improved by first studying and reading the structure of new obfuscated attacks, then ...
What is your primary use case for Atomic ModSecurity Rules?
My main use case for Atomic ModSecurity Rules is in my research, which tries to make websites secure against web atta...
What advice do you have for others considering Atomic ModSecurity Rules?
I would rate Atomic ModSecurity Rules nine out of ten. I chose nine out of ten because I have not studied other WAFs....
What is your experience regarding pricing and costs for F5 Advanced WAF?
F5 Advanced WAF is somewhat costly compared to other vendors, but it is worth the investment due to the stability it ...
What needs improvement with F5 Advanced WAF?
Improvements could be made regarding the log information from the backend CLI. There are enhancements needed; if a re...
What is your primary use case for F5 Advanced WAF?
My main use case for F5 Advanced WAF is to protect external and internal applications from cyber attacks and to preve...
 

Also Known As

Cloudflare WAF
No data available
No data available
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Information Not Available
MAXIMUS, Vivo, American Systems, Bangladesh Post Office, City Bank
Find out what your peers are saying about Imperva, Fortinet, F5 and others in Web Application Firewall (WAF). Updated: August 2026.
909,153 professionals have used our research since 2012.