Try our new research platform with insights from 80,000+ expert users

FortiWeb Web Application Firewall (WAF) vs Imperva Web Application Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Ranking in Web Application Firewall (WAF)
5th
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
24
Ranking in other categories
No ranking in other categories
FortiWeb Web Application Fi...
Ranking in Web Application Firewall (WAF)
15th
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
24
Ranking in other categories
No ranking in other categories
Imperva Web Application Fir...
Ranking in Web Application Firewall (WAF)
7th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
52
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2025, in the Web Application Firewall (WAF) category, the mindshare of Cloudflare Web Application Firewall is 7.3%, up from 6.5% compared to the previous year. The mindshare of FortiWeb Web Application Firewall (WAF) is 1.2%, up from 0.4% compared to the previous year. The mindshare of Imperva Web Application Firewall is 5.6%, down from 6.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF)
 

Featured Reviews

SachidDoshi - PeerSpot reviewer
Offers a huge signature repository and is superiorly effective in mitigating DDoS attacks
The solution's learning curve can still be further reduced, which presently stands at two or three months. The product has a custom rule set that users can modify and manifest as needed. The vendor can probably shorten the learning curve using cutting-edge technologies like AI. The solution provider can also work around the web applications and identify the toolset that needs to be implemented to deploy the solution in less time. The vendor has launched a SASE product that can function with Cloudflare Web Application Firewall, but many improvements are needed in terms of features, such as the web filtering feature, and CASB has not yet been added.
Martin Ellmann - PeerSpot reviewer
Provides users with ease of policy configuration and good integration capabilities
The solution helps protect our company's web applications against common threats up to 99 percent. We feel very safe with the tool. Speaking about how the tool has effectively mitigated web security threats for an application, I would say that it is an application behind the web portal, so there are about a hundred or thousand people who can access a website. If it is a sensitive application, and we have to watch every access to it to make it really safe, that is the reason why we need WAF on the application. My company doesn't use AI with the tool. I recommend the product to others. I would say that others need to have it if they have a shopping website or something similar. I know it is hard to sell because we find it quite hard whenever my company tries to do so. The solution offers 100 percent integration with other Fortinet security products. The ease of policy configuration in the tool is okay. I rate the tool a nine to ten out of ten.
Mitesh D Patel - PeerSpot reviewer
Effectively defends against threats like cross-site scripting (XSS), SQL injection, and others
It does bring value. For example, consider a BFSI customer. Their application is critical and represents their brand. Without a WAF, an attack could take their application down, harming their reputation. It leads to hampering the customer's workflow. With an Imperva WAF, they protect against attacks like DDoS or SQL injection, ensuring their application remains available and customers are happy. That's the main benefit for both the customer and the organization. The impact depends on the customer's use case. If their business primarily operates online, a CDN is beneficial for traffic optimization. Moreover, the integration options depend on the specific use case of our customers. Generally, integration capabilities are good with SIEM (Security Information and Event Management) parts.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I'm highly satisfied. It's remarkably user-friendly, enabling me to quickly identify issues, and deploy solutions, and it offers the necessary features."
"The product has improved our security posture by blocking bad actors."
"The Cloudflare Web Application Firewall's most valuable feature is its ease of configuration."
"The setup process is very simple for me."
"Someone with a basic understanding of networking and security will be able to implement the firewall's basic features within 15 minutes."
"The security features are valuable. The particular feature we use is called OWASP."
"The product has a valuable security control functionality."
"Technical support has a very fast response time and they are helpful."
"The initial setup was easy since it was possible to get remote support for the product."
"The fact that I can log into the platform and see everybody, see logs, authentication failure, and see everything on one platform, is the most valuable feature."
"The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats."
"The platform's stability is good."
"FortiWeb Web Application Firewall blocks attacks from application layers and provides protection."
"The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection."
"The product's initial setup phase was easy."
"The good thing about Fortinet is that their enablement is very good in terms of training me and enabling resources on their technology."
"It has threat intelligence and we are using Incapsula. With threat intelligence, we can separate HTTP and HTTPS traffic. We can use Incapsula to send all the threat intelligence to the WAF."
"The solution integrates seamlessly with other tools and has a good alert mechanism."
"Protection is the best solution since it has profile functionality."
"The solution has been quite stable. I have not seen any bugs at all."
"Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva."
"The solution is very scalable. It is one of the most important features. You can also expand resources and features as well."
"The most valuable feature of Imperva, in addition to its strong knowledge base, is its effective protection for web applications."
"If you are using the appliance as opposed to the virtual deployment, it can stand as the network layer-two and provide real transparency."
 

Cons

"There could be an option to duplicate the cluster to maintain the consistency of rules."
"The product can improve by having more multitenancy capability, which is currently not available."
"Their documentation could be better. They don't have documentation that explains everything well. They have documentation for everything you're looking for, but they lack a single piece of documentation to tie everything together. As a new user or beginner, it took us a little bit of time to figure out how to put all these things in place."
"The product can improve by having more multitenancy capability, which is currently not available."
"The ModSecurity core rules need to be updated."
"A key challenge arises when dealing with numerous integrations with HVAC systems. Depending on the specifics, there might be some configuration mismatches, which necessitate specific support."
"The reporting could be more granular."
"They have some limitations with third-party integrations."
"The product is complicated to set up."
"FortiWeb Web Application Firewall (WAF) needs to update its attack prevention database."
"If some of my customers want to migrate from F5 to Fortinet Firewall, or the Fortinet WAF solution, there are some migration issues since I cannot migrate all the elements quickly using Fortinet Firewall."
"The price is a little higher than the competitors."
"There could be ADC offering as well."
"The tool's price and performance are areas of concern where improvements are required."
"FortiWeb could have an inbound load balancing pack."
"FortiWeb Web Application Firewall needs to improve its performance."
"There's always room for improvement. Occasionally, there might be false-positive alerts."
"The initial setup could be simplified. Every time you have to install the solution you have to get in touch with support or somebody that can to do that for you."
"It would be useful if the solution used more intelligence in attack protection. For example, firewalls are to be dependent on the configuration, but if they could have some data science around it the solution would be even better. The profiling of the traffic, and making decisions surrounding that should be intelligence-based, instead of being based on the configuration of the firewall itself."
"They can provide an option to create reports, automatically import the entire report, and create rules again. In a real-life crisis, it would be helpful to be able to import a report and generate security rules from that report. I should be able to create a simple query and import the reports automatically. It can maybe also tell us the format of the report."
"In the past, I have bugs on the WAF. I've contacted Imperva about them. Future releases should be less buggy."
"There could be some limitations that from the converged infrastructure perspective: when you want to converge with everything and you want Imperva to get there easily because it's not a cloud component. For example, when you want to build servers and you're using OneView to manage your software-defined networks, implementing Imperva right away is not that simple. But if you're doing just a simple cloud infrastructure with servers in there, you're good to go. Also, we are not able, with Imperva, to block by signatures. Imperva by itself needs to be complemented with another service to do URL filtering."
"It is complicated to integrate the solution's on-cloud version with other platforms."
"The solution works for particular zones but isn't always the best solution for all zones."
 

Pricing and Cost Advice

"Cloudflare Web Application Firewall is more affordable than other solutions."
"The solution is expensive."
"The solution's pricing option needs to be more transparent for enterprise clients."
"The annual licensing fee is $10,000 USD."
"It starts at $20 and can easily go up to $200 monthly"
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"We pay $210 per month for CloudFlare WAF."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"I rate the product price a four on a scale of one to ten, where one is a high price, and ten is a low price."
"The licensing cost of the product is pretty high compared to other OEMs in the market."
"FortiWeb Web Application Firewall's pricing is suited for small or medium organizations."
"It is a cheap solution."
"I rate the tool's pricing an eight out of ten."
"I would rate the pricing a four out of ten."
"The product provides very good prices to customers. The price is set well and offers great value for money."
"The tool is really expensive."
"The solution's pricing is an issue."
"It's an excellent product, but it can be very costly."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
"The price of Imperva Web Application Firewalls is expensive compared to others."
"The pricing is somewhat expensive. It is actually a huge investment when compared to other countries."
"There are a couple of different licensing models."
"Imperva Web Application Firewall is expensive."
"We sell three-year licenses for Imperva Web Application Firewall to our customers. The price is a little expensive."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
864,574 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
9%
Comms Service Provider
8%
Manufacturing Company
7%
Computer Software Company
12%
Government
11%
Financial Services Firm
9%
Manufacturing Company
9%
Financial Services Firm
16%
Computer Software Company
11%
Insurance Company
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Cloudflare Web Application Firewall?
The product has a valuable security control functionality.
What needs improvement with Cloudflare Web Application Firewall?
I cannot say much about areas of improvement for Cloudflare Web Application Firewall because I haven't gone through d...
What do you like most about FortiWeb Web Application Firewall (WAF)?
The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS.
What is your experience regarding pricing and costs for FortiWeb Web Application Firewall (WAF)?
The pricing for FortiWeb Web Application Firewall (WAF) is reasonable. That said, it depends on how many websites we ...
What needs improvement with FortiWeb Web Application Firewall (WAF)?
Their AI technology is good. Overall, Fortinet is only good. The improvement needed is in their response time. In the...
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you hav...
DDoS solutions: Any other solutions to consider aside from Radware DDoS Protection Service and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot ...
 

Also Known As

Cloudflare WAF
No data available
No data available
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Information Not Available
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about FortiWeb Web Application Firewall (WAF) vs. Imperva Web Application Firewall and other solutions. Updated: July 2025.
864,574 professionals have used our research since 2012.