


Imperva Application Security Platform and Azure Web Application Firewall compete in the web application security category. Imperva seems to have the upper hand due to its more comprehensive feature set, while Azure is favored for its seamless Microsoft integration and cost-effectiveness.
Features: Imperva provides robust security with DDoS protection, customizable profiling policies, and pre-configured settings for simplified maintenance. Azure Web Application Firewall offers seamless integration with Azure services, OWASP protection, and user-friendly dashboards, making configuration in Azure environments straightforward.
Room for Improvement: Imperva could improve analytics depth, policy management flexibility, and support services. Azure Web Application Firewall could enhance its documentation clarity and pricing competitiveness for mid to small-sized companies, as well as offer clearer integration guidance.
Ease of Deployment and Customer Service: Imperva's cloud deployment is straightforward, needing minimal expertise, but its support could be improved. Azure's strength lies in its natural fit within the Azure ecosystem for swift deployment; however, some users face challenges with response times.
Pricing and ROI: Imperva offers varied pricing based on deployment type, considered high but justified for its features, with considerable ROI noted in the financial sector. Azure's pricing is competitive, especially beneficial for users of Azure services, though its higher SKU plans might be costly for smaller businesses.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
Recently, they have been under serious attack with major exploits, such as Log4j, affecting Fortinet and Palo Alto, and even Cisco and VMware.
AI-based recommendations save on time and money.
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
I was able to save over seven million dollars last year as return on investment in the company.
I have seen a return on investment with Imperva Application Security Platform, as it is generally associated with time savings, because the review of alerts and the visibility it gives saves us significant operational time.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
They are good at troubleshooting and configuring things.
I am very satisfied with the response from Microsoft dedicated architects if it happens that I have to call for their support.
I reached out to their support, and they helped me resolve the issue effectively.
I would rate the technical support of Imperva DDoS as ten.
They need to work faster on the response time because of issues of urgent replies.
Responsive support addressing urgent needs.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
Some Azure applications, like the web application firewall, require a certain level of SKU for hosting setup.
For our company, Azure Web Application Firewall works effectively for scalability.
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
I have not even needed support after deployment, since it has remained stable.
It is easy to always scale to add more users.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
Very rarely do I see any latency issues.
It is also a stable product without much glitch or downtime.
One notable drawback is that, unlike Fortinet, which offers fast track labs and continuous enablement, Imperva Application Security Platform lacks lab access and fast track labs for enablement and product advertising.
The stability of Imperva DDoS is very good, as it seems they have a lot of servers around the world.
The product can improve by having more multitenancy capability, which is currently not available.
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
Upgrading the platform regularly is necessary for security, however, frequent updates every six months or year from Azure can be a maintenance overhead.
The pricing needs improvement, and I think for beginners it will be a little bit complicated, so the ease of use could be enhanced.
To convince my clients, a purely on-prem solution would be ideal since they are financial institutions.
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
It is even a lower cost compared to AWS and GCP.
Sometimes, when opting for a higher SKU, it's not the WAF itself that's costly but the additional requirements.
I would place Azure Web Application Firewall at an eight on a scale from one to 10, with one being cheap and 10 being expensive.
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
We have noticed faster response times and fewer security alerts because after doing some custom policy tuning, everything seemed to be aligned and we have fewer attacks to monitor and fewer alerts to monitor.
The pricing is not transparent to me; it's what the vendors give, or whatever the channel partner offers that you can negotiate on.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
With Microsoft, everything is within a single suite, making it easier to configure and plan.
It is almost impossible to access these assets from outside, requiring a very skilled attacker to obtain asset tokens of a customer using Azure.
It integrates effectively with things such as Sentinel and Defender for Cloud, so mostly it's the analytics and now the AI capabilities that have been introduced with Co-pilot.
The API security feature is particularly valuable because most attackers do not try to come in from where it is expected.
If someone attempts to access the server, the WAF blocks that SSRF alert, or RCE, Remote Code Execution alert, blocking immediately based on the signature, not only by the payload or the IP address.
It reduces the DDoS attacks and reduces the attacks from threat actors, including SQL Injection and zero-day attacks, by using dynamic application profiling from Imperva.
| Product | Mindshare (%) |
|---|---|
| Imperva Application Security Platform | 7.6% |
| Cloudflare Web Application Firewall | 4.7% |
| Azure Web Application Firewall | 2.5% |
| Other | 85.2% |
| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 6 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 6 |
| Large Enterprise | 12 |
| Company Size | Count |
|---|---|
| Small Business | 88 |
| Midsize Enterprise | 25 |
| Large Enterprise | 66 |
Cloudflare Web Application Firewall's intuitive dashboard enables users to build powerful rules through easy clicks and also provides Terraform integration. Every request to the WAF is inspected against the rule engine and the threat intelligence curated from protecting over 27 Million websites. Suspicious requests can be blocked, challenged or logged as per the needs of the user while legitimate requests are routed to the destination, agnostic of whether it lives on-premise or in the cloud. Analytics and Cloudflare Logs enable visibility into actionable metrics for the user.
Azure Web Application Firewall (WAF) provides centralized protection of your web applications from common exploits and vulnerabilities. Web applications are increasingly targeted by malicious attacks that exploit commonly known vulnerabilities. SQL injection and cross-site scripting are among the most common attacks.
To learn more about our solution, ask questions, and share feedback, join our Microsoft Security, Compliance and Identity Community.
Imperva Application Security Platform delivers comprehensive and continuous web threat protection. Renowned for its ease of use, it shields web applications and databases from various cyber threats while integrating seamlessly with cloud and on-premises environments.
Imperva Application Security Platform protects web environments by offering advanced security measures against threats like DDoS attacks, SQL injections, and cross-site scripting. As a robust web application firewall, it provides extensive monitoring and bot management capabilities. The platform integrates content delivery networks for enhanced performance and scalability, while real-time traffic analysis ensures consistent protection. Despite its strengths, improvements can be made in policy management and customization options. Users seek better integration with third-party tools and more competitive pricing models. The inclusion of AI for enhanced analytics is also anticipated.
What are the key features of Imperva Application Security Platform?Imperva Application Security Platform is implemented in industries needing strong database and application protection. Companies use it to enforce geolocation restrictions and manage bots, benefiting sectors like finance and e-commerce where data security and threat monitoring are critical. Its ability to protect and ensure data accessibility makes it integral to business operations prioritizing cyber resilience.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.