No more typing reviews! Try our Samantha, our new voice AI agent.

F5 Rules for AWS WAF vs Imperva Managed Rules on AWS WAF comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

F5 Rules for AWS WAF
Ranking in Business Rules Management
5th
Average Rating
8.2
Reviews Sentiment
7.7
Number of Reviews
9
Ranking in other categories
Web Application Firewall (WAF) (20th)
Imperva Managed Rules on AW...
Ranking in Business Rules Management
7th
Average Rating
8.2
Number of Reviews
5
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Business Rules Management category, the mindshare of F5 Rules for AWS WAF is 1.6%, up from 0.2% compared to the previous year. The mindshare of Imperva Managed Rules on AWS WAF is 1.0%. It is calculated based on PeerSpot user engagement data.
Business Rules Management Mindshare Distribution
ProductMindshare (%)
F5 Rules for AWS WAF1.6%
Imperva Managed Rules on AWS WAF1.0%
Other97.4%
Business Rules Management
 

Featured Reviews

Vibin Thomas - PeerSpot reviewer
Technical Team Lead - Content Security at Valuepoint Systems
Advanced protection has reduced web attacks and improves application performance and operations
One area where F5 Rules for AWS WAF can be improved is in simplifying the tuning process. While F5 Rules for AWS WAF is powerful, fine-tuning it to match specific application behavior can sometimes be complex and time-consuming, especially for teams without deep WAF expertise. Another improvement could be enhanced visibility and reporting. Although AWS WAF provides logs, having more intuitive and built-in dashboards or clearer categorization of rule triggers would make it easier to quickly identify and analyze attack patterns. Additionally, expanding the capabilities around bot management and behavior analysis would be beneficial compared to some dedicated bot management solutions. More advanced detection techniques could further strengthen the protection against sophisticated automated traffic. Finally, providing more predefined templates or best practice recommendations for different application types would help speed up the deployment and reduce the initial configuration effort.
BasilJiji - PeerSpot reviewer
System engineer at a retailer with 10,001+ employees
Edge protection has reduced junk traffic and now safeguards APIs with automated threat intelligence
The best feature I would say is the compliance. It satisfies enterprise audit criteria for web application profiling that is required by PCI DSS and HIPAA. Also, it aligns fully with my security compliance matrices, the OWASP Top 10 alignment, and standard core rules to defend against injection attacks, cross-site scripting, and path traversal. These are the major features. The managed rule set proves that modern security does not have to be slow or complicated. It turns threat intelligence into a utility function that I can enable with a few clicks. It has eliminated the heavy operational burden of threat research. Instead of my internal security engineers spending hours tracking new malicious IPs or writing custom regex signatures to deal with emerging exploits, Imperva automatically updates the rule set in the background.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"In the past few years, we have zero security incidents, indicating a return on investment."
"F5 Rules for AWS WAF has positively impacted our organization for security through the implementation of traffic rules in our application."
"F5 Rules for AWS WAF's OWASP protection and bot protection have reduced attacks on my applications by 72 to 90%."
"I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF."
"F5 Rules for AWS WAF is a strong, enterprise-focused solution for organizations that need robust web application security, centralized policy management, and better visibility into application layer threats within AWS environments."
"After implementing F5 Rules for AWS WAF, we observed a reduction of approximately 60 to 70% in web application security incidents reaching our application team, particularly blocking common threats like bot traffic and SQL injections without impacting our downstream systems."
"F5 Rules for AWS WAF is definitely recommended. It is a good tool for anyone to try and see if it matches their use case, and it is something that an organization can really benefit from."
"Overall, the combination of reduced manual effort, improved security posture, and better application performance has delivered a strong return on investment."
"The managed rule set proves that modern security does not have to be slow or complicated."
"Automatic updates are the best features Imperva Managed Rules on AWS WAF offers."
"Imperva Managed Rules on AWS WAF has impacted my organization positively to a very good extent, as along with the default AWS WAF rules, Imperva Managed Rules on AWS WAF is giving more edge on layer seven security for protecting the applications at the organization, making them good-to-go rules."
"Imperva Managed Rules on AWS WAF offers continuous threat intelligence updates as the best feature, as they have a rapid response to newly discovered attack techniques and base their detection logic on real-world threat data with easy integration with AWS."
"Imperva Managed Rules on AWS WAF has positively impacted my organization by addressing trust issues my customer had regarding security configuration for their application."
 

Cons

"There are potential false positives in F5 Rules for AWS WAF that sometimes require tuning."
"It's too early to talk about a return on investment with F5 Rules for AWS WAF."
"One area where F5 Rules for AWS WAF can be improved is in simplifying the tuning process."
"F5 Rules for AWS WAF could be improved with deeper integration with Infrastructure as Code tools like Terraform for simplification, as well as more AI-driven recommendations for rules tuning to reduce false positives and better dashboards for visibility at the CXO level."
"An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these rule sets."
"F5 Rules for AWS WAF can be improved by simplifying the tuning process to reduce false positives and providing more built-in dashboards for better visibility and further customization."
"From an improvement standpoint, one area where F5 Rules for AWS WAF could improve is in simplifying policy management and making advanced configurations more intuitive, especially for teams that are newer to enterprise WAF technologies."
"The additional costs for F5 Rules for AWS WAF are quite high, as F5 managed rules require a separate subscription on top of the standard AWS WAF charges; it would be great if it would be pre-integrated."
"Imperva Managed Rules on AWS WAF keeps updating its rule sets, but the company could increase the number of rules on a yearly basis and incorporate more rules aligned with artificial intelligence security."
"Imperva Managed Rules on AWS WAF can usually have false positives sometimes, blocking legitimate traffic and struggling with complex search queries, particularly with large JSON requests and certain GraphQL requests, which makes us initially deploy the rules in monitoring mode before switching to blocking mode to ensure all our use cases are supported."
"For improvement, it would be better to have access to deeper configuration levels in Imperva Managed Rules on AWS WAF."
"Other issues include that the marketplace sellers do not allow me to modify individual parameters inside the vendor's compiled rule set, meaning any false positive must be handled by a custom override rule."
"Sometimes the rules act as a black box with Imperva Managed Rules on AWS WAF because you cannot see the underlying rule logic or regular expressions, which can be challenging when troubleshooting false positives on complex API payloads."
report
Use our free recommendation engine to learn which Business Rules Management solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
35%
Comms Service Provider
18%
Energy/Utilities Company
6%
Outsourcing Company
5%
Construction Company
38%
University
23%
Manufacturing Company
7%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Large Enterprise6
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for F5 Rules for AWS WAF?
My experience with pricing and licensing has been generally positive. Since F5 Rules for AWS WAF is available through the AWS Marketplace, the licensing model is straightforward and aligns well wit...
What needs improvement with F5 Rules for AWS WAF?
From an improvement standpoint, one area where F5 Rules for AWS WAF could improve is in simplifying policy management and making advanced configurations more intuitive, especially for teams that ar...
What is your primary use case for F5 Rules for AWS WAF?
My main use case for F5 Rules for AWS WAF is strengthening web application security for internet-facing applications hosted on AWS. I mainly use F5 Rules for AWS WAF to improve protection against c...
What is your experience regarding pricing and costs for Imperva Managed Rules on AWS WAF?
The experience was very efficient. The product uses a transparent, pay-as-you-go consumption-based pricing model that is billed through the AWS Marketplace. It eliminates heavy upfront contract cos...
What needs improvement with Imperva Managed Rules on AWS WAF?
There are many improvements I would identify. The native AWS integration plugs directly into my existing Web ACLs along with the native AWS managed rule sets without conflict. There are no software...
What is your primary use case for Imperva Managed Rules on AWS WAF?
My main use case is proactive edge security and IP reputation management. I use Imperva Managed Rules on AWS WAF's IP reputation rule group attached to my main application load balancer. Because Im...
 

Overview

Find out what your peers are saying about F5 Rules for AWS WAF vs. Imperva Managed Rules on AWS WAF and other solutions. Updated: June 2026.
900,644 professionals have used our research since 2012.