Try our new research platform with insights from 80,000+ expert users

F5 BIG-IP Local Traffic Manager (LTM) vs Fortinet FortiWeb vs Imperva Web Application Firewall comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Application Delivery Controllers (ADC)
Web Application Firewall (WAF)
Web Application Firewall (WAF)
 

Featured Reviews

Bonieber  Orofeo - PeerSpot reviewer
Identifying compromised traffic and securing data has been a significant advantage
One of the most beneficial features of F5 BIG-IP Local Traffic Manager (LTM) ( /products/f5-big-ip-local-traffic-manager-ltm-reviews ) is its ability to identify compromised traffic and its capabilities in authentication. Additionally, the security aspect of it provides a significant advantage as it helps us secure our data, which is a major investment and benefit for us. Before using this system, we had difficulties in storing our data and managing the traffic that comes in and out.
Kacem CHAMMALI - PeerSpot reviewer
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.
Mitesh D Patel - PeerSpot reviewer
Effectively defends against threats like cross-site scripting (XSS), SQL injection, and others
It does bring value. For example, consider a BFSI customer. Their application is critical and represents their brand. Without a WAF, an attack could take their application down, harming their reputation. It leads to hampering the customer's workflow. With an Imperva WAF, they protect against attacks like DDoS or SQL injection, ensuring their application remains available and customers are happy. That's the main benefit for both the customer and the organization. The impact depends on the customer's use case. If their business primarily operates online, a CDN is beneficial for traffic optimization. Moreover, the integration options depend on the specific use case of our customers. Generally, integration capabilities are good with SIEM (Security Information and Event Management) parts.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The support from F5 BIG-IP LTM is good."
"It is an easy way to build application policies (graphical)."
"I was able to simply and quickly set up the WAF rules and security, and also set up easily complex policies and rules which gave me some great features to redirect."
"It is a fast and available solution."
"Along with load balancing, we perform a lot of packet inspections, URL rewriting, and SSL interceptions via iRule."
"The main reason that we suggest this product to our clients is the great integration with other security tools, such as IBM Guardium."
"The most valuable feature of F5 BIG-IP LTM is it helps our delivery team to make policies and rules for application."
"The most valuable features of the solution are in the area of DDoS and WAF."
"FortiWeb's ease of deployment is what we liked the most about it. Implementing FortiWeb was extremely fast and easy, which was a significant advantage. It comes with several preconfigured rule sets and templates."
"I have recently been looking at the SSL certificate features and the learning mode of the appliance. This appliance learns from the pattern of SSL attacks."
"It's easy to use and allows us to integrate solutions together."
"Both the internal firewall management and the cloud can be managed by a single console."
"The WAF profiles has been effective at mitigating web-based threats."
"The solution's most valuable feature is its security profile."
"We can block access using the IP address so no one can connect to our web server or website using the real IP."
"It is a good product. We have just blocked everything coming from some geographical locations or certain countries, and it has been working very efficiently when I look at logs, events, and incidents generated from the system. It is generating very good analytic reports about it. This is the most valuable thing about this solution. It has load balancing and almost everything that a web application firewall needs. It is very flexible and easy to learn and configure. It can be easily learned and configured by using the information available on different channels such as YouTube."
"The solution has been quite stable. I have not seen any bugs at all."
"The solution is stable."
"The compliance is the most valuable aspect."
"Imperva is easy to use and deploy. The UI is excellent."
"If you are using the appliance as opposed to the virtual deployment, it can stand as the network layer-two and provide real transparency."
"Very scalable and very stable firewall for web applications, with a good interface in its cloud version. Mitigation is its most valuable feature. The technical support for this product is also good."
"Its inline transferring mode is the most valuable because it is 100% transparent. When you change the IP, there is no change on the network side. If you can't and want to try to reach an IP, you can reach the server IP. There are many other advanced security features in it. The smallest appliances of Imperva can handle the highest traffic at a customer site. For example, a smaller appliance from Imperva can provide you the same security as an F5 product."
"There is a quick switch between any of the the nodes if something goes wrong, where there's a there's an attack against a specific area. The security setup is reasonably easy. It's not a problem to do setups and rules and integrations. And, yeah, just the the back end team is also very willing to insist if there's questions that that we cannot answer or with these questions that we do have"
 

Cons

"They need to improve the interface and some of the functionalities."
"Certificate management needs improvement. I would like automated deployment of new certificates without manual intervention to be in the next release of this product."
"It's a very expensive solution."
"The GUI needs improvement."
"I would like F5 to incorporate the ability to create your own custom roles and customised permissions within the product set. I have seen many customers wanting to give a certain level of access for the purposes of out-of-hours servicing to out-of-hours staff or teams that fulfill an operations type role."
"The deployment can take some time because you can do a lot of configuring to meet the needs of the use cases for clients."
"An expensive solution for the minimal features we use."
"I would like them to have more flexible models."
"I would like to see more improvements with respect to threat intelligence."
"Sometimes, even if you follow the documentation, it doesn't work as expected."
"The GUI could be better. It's limited."
"The initial setup depends on familiarity with the product. It's manageable with the right expertise."
"Most of the deployment is done by our development team because they have some parameters that match the configuration. However, when we initially did the deployment we used a consultant company."
"Centralized configuration using FortiManager – like what exists for NGFW FortiGate appliances - would improve the configuration."
"We use Kubernetes, so I would like to have a plugin to configure FortiWeb Cloud automatically using Kubernetes Ingress. That would reduce the complexity of setting up an Ingress object in Kubernetes. Some competing solutions help you configure Ingress and Kubernetes automatically."
"The solution is not very scalable, to scale up would require another deployment with a new appliance and a change to the network."
"The reporting is missing some features, such as: only two export formats, and the time period does not include the last day, week, year."
"It would be useful if the solution used more intelligence in attack protection. For example, firewalls are to be dependent on the configuration, but if they could have some data science around it the solution would be even better. The profiling of the traffic, and making decisions surrounding that should be intelligence-based, instead of being based on the configuration of the firewall itself."
"Imperva Web Application Firewall can improve by providing better features, such as improved prevention of zero-day attacks. Additionally, it should include a VR meta-analysis."
"I'd like the option to pick your bot protection."
"In the past, I have bugs on the WAF. I've contacted Imperva about them. Future releases should be less buggy."
"There could be some limitations that from the converged infrastructure perspective: when you want to converge with everything and you want Imperva to get there easily because it's not a cloud component. For example, when you want to build servers and you're using OneView to manage your software-defined networks, implementing Imperva right away is not that simple. But if you're doing just a simple cloud infrastructure with servers in there, you're good to go. Also, we are not able, with Imperva, to block by signatures. Imperva by itself needs to be complemented with another service to do URL filtering."
"I am looking for more data enrichment. We should have the ability to add our own custom data to the system, to the live traffic."
"Support is one thing I wish Imperva could improve."
 

Pricing and Cost Advice

"It is the best solution, but that comes with an increased price."
"It is quite expensive as a product. Because it is very stable, it is also expensive."
"Unless the price difference is large, this is not the primary concern for the product. The performance and product-related issues (secure for VPN, multi-function for network device, etc.) are the keys."
"The price of F5 BIG-IP Local Traffic Manager (LTM) is too high."
"We purchased through the AWS Marketplace because it was a popular way to go, and we were intrigued. The price of this product is not an issue. They have good pricing and licensing."
"The tool is a bit expensive."
"I use a yearly subscription, which is the most expensive one now compared to its competitors."
"It is cheaper than the average on the market."
"It's an expensive solution, although there are no additional costs."
"There are no licensing costs."
"Cheaper than others."
"We are on an annual license for this solution and the price is approximately €100."
"The price of Fortinet FortiWeb is reasonable. This is one of the key factors of why we use this solution."
"It is fine now. We had to earlier negotiate the price."
"It is an expensive suite and it is an expensive solution, but it is a manageable one for an enterprise."
"The product is expensive. I rate the pricing a ten out of ten."
"The cost of this solution depends on the platform."
"The price is high compared to other solutions like FortiWeb."
"Everybody complains about the price of this solution."
"We sell three-year licenses for Imperva Web Application Firewall to our customers. The price is a little expensive."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
"The price of Imperva Web Application Firewalls is expensive compared to others."
"The price of this solution is a little bit high compared to competitors."
"Make sure you understand the way that Imperva charges. It's very affordable. However, I would like to see a package with the Virtual Patching included. You get to do patching separately."
report
Use our free recommendation engine to learn which Application Delivery Controllers (ADC) solutions are best for your needs.
856,856 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
13%
Government
8%
Manufacturing Company
6%
Educational Organization
32%
Computer Software Company
10%
Financial Services Firm
8%
Government
5%
Financial Services Firm
16%
Computer Software Company
12%
Insurance Company
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What needs improvement with F5 BIG-IP?
The price needs improvement as it is quite costly.
What is your primary use case for F5 BIG-IP?
We're using F5 BIG-IP Local Traffic Manager (LTM) ( /products/f5-big-ip-local-traffic-manager-ltm-reviews ) for our a...
What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
Fortinet FortiWeb is cost-effective compared to solutions like F5. It offers strong performance for the price, provid...
What needs improvement with Fortinet FortiWeb?
The cloud-based security service of Fortinet FortiWeb could be enhanced to match the level of providers like Cloudfla...
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you hav...
DDoS solutions: Any other solutions to consider aside from Radware DDoS Protection Service and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot ...
 

Also Known As

F5 BIG-IP, BIG-IP LTM, F5 ASM, Viprion, F5 BIG-IP Virtual Edition , Crescendo Networks Application Delivery Controller, BIG IP
No data available
No data available
 

Overview

 

Sample Customers

Riken, TransUnion, Tepco Systems Administration, Daejeon University, G&T Bank, Danamon, CyberAgent Inc.
Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about NetScaler, F5, Microsoft and others in Application Delivery Controllers (ADC). Updated: May 2025.
856,856 professionals have used our research since 2012.