Try our new research platform with insights from 80,000+ expert users

Fortinet FortiWeb Cloud WAF-as-a-Service vs Imperva Web Application Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
75
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Fortinet FortiWeb Cloud WAF...
Average Rating
9.0
Reviews Sentiment
8.7
Number of Reviews
4
Ranking in other categories
Web Application Firewall (WAF) (28th)
Imperva Web Application Fir...
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
52
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Lilian Blaitt - PeerSpot reviewer
Efficiently identifies and addresses vulnerabilities while providing robust protection
It is a secure tool. It is user-friendly and easy to work with. It is possible to easily find vulnerabilities with the WAF. I understand that the return is good since I haven't had any significant attacks. The vulnerabilities I found were easy to close. I think the return is good. It is a good tool.
Abdullah Jin - PeerSpot reviewer
Offers bot protection and DDoS Protection and protects public-facing portals
Support is one thing I wish Imperva could improve. They follow the phone model and keep rotating you from one customer service person to another. The layer one support isn't very clear about the workings of the product. My feedback is primarily about Imperva Cloud, not on-premise. On-premise is a whole new story. Support is the issue for Imperva Cloud. It's also a bit pricey. It's a premium service and very expensive. The licensing model is not very straightforward. Every feature is priced separately, and to enjoy maximum protection, you'll have to spend a lot of money. The licensing model is a bit complex, and each feature is very pricey. For example, API security and web application protection are two separate license packages.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cloudflare has many features."
"It is a fast and secure DNS."
"I rate its stability a ten out of ten."
"I get a lot of value from Cloudflare's API because it enables you to build a separate environment inside the solution. You can create a domain for performing test requests before you move to the production environment and connect various domains."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"Cloudflare DNS is widely used, and it's good for websites. If we use Cloudflare DNS and update one record, it updates in their office instantly."
"It's very user-friendly."
"The solution is stable, and the DNS servers are simple to use."
"It is a secure tool."
"Fortinet FortiWeb offers a variety of protections, including machine learning that helps protect web applications."
"The company provides technical support, and they are mostly available 24/7."
"The technical support is really good."
"I rate the overall solution ten out of ten."
"It is user-friendly and easy to work with."
"The stability of the solution is excellent."
"It mitigates all of the availabilities of risks around web applications."
"It is easy to use and has good security."
"There are some features that are configured by default, so even without doing much, it can still provide a level of protection."
"The solution is very scalable. It is one of the most important features. You can also expand resources and features as well."
"Protection is the best solution since it has profile functionality."
"The solution integrates seamlessly with other tools and has a good alert mechanism."
"There is a quick switch between any of the the nodes if something goes wrong, where there's a there's an attack against a specific area. The security setup is reasonably easy. It's not a problem to do setups and rules and integrations. And, yeah, just the the back end team is also very willing to insist if there's questions that that we cannot answer or with these questions that we do have"
"Imperva has a complete picture of how the applications are utilizing it. It is handy. DDoS is good. It has an internally managed database. It is very easy to integrate. We have integrated it with SIEM services."
 

Cons

"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"I would like Cloudflare to offer a dedicated account manager for large enterprise clients like us."
"Cloudflare's console should be made more user-friendly."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"The reporting can definitely be improved to offer a lot more explanation on something that may have happened or has actually happened."
"It would be helpful if the solution could continue evolving to compete with the other solutions on the market."
"The pricing could be improved."
"There are some issues with the CDN services."
"The usability of the interface could be improved as it is not user-friendly."
"The usability of the interface could be improved as it is not user-friendly."
"I do not have any notes on improvement."
"The only thing I encountered was related to integration, mostly concerning translation."
"Sometimes our web application firewall will slow down."
"Some of the features should be included in the next release is a file integrating monitoring tool. This feature should be improved."
"Imperva Web Application Firewall can improve by adding more features to the dashboard. increasing the visibility of the real-time events, besides configuring the administration itself."
"I'd like the option to pick your bot protection."
"There could be some limitations that from the converged infrastructure perspective: when you want to converge with everything and you want Imperva to get there easily because it's not a cloud component. For example, when you want to build servers and you're using OneView to manage your software-defined networks, implementing Imperva right away is not that simple. But if you're doing just a simple cloud infrastructure with servers in there, you're good to go. Also, we are not able, with Imperva, to block by signatures. Imperva by itself needs to be complemented with another service to do URL filtering."
"They recently separated the WAF and the DAM management gateways in order for each of these to be managed from different areas, so I believe it now requires additional investments for what was previously a single complete solution."
"It is complicated to integrate the solution's on-cloud version with other platforms."
"The tool needs to improve CPU and storage memory."
 

Pricing and Cost Advice

"We are using the free tier of the solution."
"So far I use free tier and happy with it. You can subscribe to business package if needed."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"There are no additional costs beyond the standard licensing fees."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
Information not available
"There are a couple of different licensing models."
"Licensing can range from one to twenty thousand dollars annually. Additionally, some features, including software support, require an annual subscription as well."
"Imperva Web Application Firewall is expensive."
"It is a very affordable solution."
"Imperva’s pricing is a bit higher in the market since it offers a full-blown WAF."
"The price is high compared to other solutions like FortiWeb."
"The price of Imperva Web Application Firewalls is expensive compared to others."
"The price of this solution is a little bit high compared to competitors."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
850,043 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
17%
Computer Software Company
14%
Comms Service Provider
9%
Financial Services Firm
8%
No data available
Financial Services Firm
17%
Computer Software Company
13%
Insurance Company
8%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What is your experience regarding pricing and costs for Fortinet FortiWeb Cloud WAF-as-a-Service?
The price is not the cheapest, but it offers great value for money. I would rate it as an eight out of ten for pricing.
What needs improvement with Fortinet FortiWeb Cloud WAF-as-a-Service?
While we find the solution to be really good overall, some improvements could be made to the alerting system, specifi...
What is your primary use case for Fortinet FortiWeb Cloud WAF-as-a-Service?
We use Fortinet FortiWeb Cloud WAF-as-a-Service situated in front of our web-facing APIs. This includes everything th...
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you hav...
DDoS solutions: Any other solutions to consider aside from Radware DDoS Protection Service and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot ...
 

Also Known As

Cloudflare DNS
No data available
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Information Not Available
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about Fortinet FortiWeb Cloud WAF-as-a-Service vs. Imperva Web Application Firewall and other solutions. Updated: April 2025.
850,043 professionals have used our research since 2012.