Try our new research platform with insights from 80,000+ expert users

FortiWeb Web Application Firewall (WAF) vs Imperva Web Application Firewall comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
75
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
FortiWeb Web Application Fi...
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
23
Ranking in other categories
Web Application Firewall (WAF) (16th)
Imperva Web Application Fir...
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
52
Ranking in other categories
Web Application Firewall (WAF) (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
IgnitiusMolepo - PeerSpot reviewer
Protects internal applications and prevents target attacks
The tool secures our critical applications, especially the mobile money application, which is often targeted by attacks. The solution provides rapid protection and has proven reliable against various threats. It blocks malicious traffic, including dormant and DDoS attacks, and offers integrated Web Application Firewall features to safeguard against compromises. You can set it up for customer-facing web applications because customers don't necessarily know all the IP addresses. It uses a source-based approach where any source accessing the application is defined by its IP. When accessing the application, it checks if they are using HTTP or HTTPS and blocks them if necessary. The tool's performance and security reporting capabilities contribute positively to IT security management. Consolidating management within the solution makes it easier for IT to handle the solutions. All functionalities managed on a single box reduce the number of boxes needed for management.
Abdullah Jin - PeerSpot reviewer
Offers bot protection and DDoS Protection and protects public-facing portals
Support is one thing I wish Imperva could improve. They follow the phone model and keep rotating you from one customer service person to another. The layer one support isn't very clear about the workings of the product. My feedback is primarily about Imperva Cloud, not on-premise. On-premise is a whole new story. Support is the issue for Imperva Cloud. It's also a bit pricey. It's a premium service and very expensive. The licensing model is not very straightforward. Every feature is priced separately, and to enjoy maximum protection, you'll have to spend a lot of money. The licensing model is a bit complex, and each feature is very pricey. For example, API security and web application protection are two separate license packages.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features of the solution are performance and security."
"I rate its stability a ten out of ten."
"The attacker won't have details since my public IP is anonymous. It offers us good privacy."
"Cloudflare has many features."
"New and innovative way to protect the client's data."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"The features of Cloudflare were found to be more beneficial and led to the decision to utilize it over other options."
"What I like best about Cloudflare is that my company can use it to trace and manage applications and monitor traffic. The solution tells you if there's a spike in traffic. Cloudflare also sends you a link to check your equipment and deployment and track it through peering, so it's a valuable tool."
"The solution's integration with other products is easy. Its most valuable feature is the antivirus engine. The tool helps us comply with GDPR and KVKK standards."
"It is good for web tracking applications."
"The good thing about Fortinet is that their enablement is very good in terms of training me and enabling resources on their technology."
"The most valuable feature is the tool's integration with load-balancing applications, similar to FortiADC. Its importance depends on customer requirements, such as whether they prioritize application load balancing or layer seven protection."
"The platform's stability is good."
"It improves latency by optimizing traffic routing."
"The fact that I can log into the platform and see everybody, see logs, authentication failure, and see everything on one platform, is the most valuable feature."
"The product is easy to configure."
"There are a number of features that are valuable such as the account takeover and various antivirus features."
"Imperva monitors all traffic, even customer access, to the web application. Then, Imperva uses features like signatures to identify attacks like cross-site scripting or SQL injection."
"The tool's profiling feature maps all the web application directories and related components on the profile directory. It has improved the security of my client's website applications."
"We can prevent attacks or issues even before they happen."
"The most valuable features of the Imperva Web Application Firewall are DDoS, malware, and the other malicious threat prevention it provides. Additionally, third-party integration is available. You can forward the log for further analysis."
"The most valuable feature of Imperva, in addition to its strong knowledge base, is its effective protection for web applications."
"Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva."
"Imperva is easy to use and deploy. The UI is excellent."
 

Cons

"If they improve on the placement of their data centers, it would be better. I'm living in a remote area. I would like to connect to them without any kind of lag."
"It should confirm audit findings of the assigned area with auditees to ensure that the audit conclusions are based on an accurate understanding of the issues."
"The analytics, basically the dashboard, doesn't have much to it."
"There could be more courses with engineers. I like e-learning, however, having a specialist in a classroom is more comfortable for me."
"We have noticed multiple instances where Cloudflare falsely indicates that our servers are down, even when there is no actual load on them. This makes it challenging for us to identify the exact issue."
"The solution could be more user-friendly."
"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"There should be a specific price list for enterprise-level customers."
"I don't see any issues with the tool apart from the pricing aspect of the product. The price of the product is an area where improvements are required."
"The price is a little higher than the competitors."
"WAF needs more signatures on FortiWeb and updates the database continuously to protect against new attacks."
"There is room for improvement in pricing, and actually, the price is a bit higher because on the same terms I purchased, the support subscription is so high."
"The technical support team is bad."
"If some of my customers want to migrate from F5 to Fortinet Firewall, or the Fortinet WAF solution, there are some migration issues since I cannot migrate all the elements quickly using Fortinet Firewall."
"For users not familiar with Fortinet, it could be beneficial to provide more user-friendly analytics and reporting."
"We haven't faced any significant issues with FortiWeb Web Application Firewall. But they can lower the pricing, since it is a concern, especially in South Africa and the technical support, could be more responsive at times."
"I think that better bot protection is needed in this solution."
"Sometimes, support tickets don't get addressed quickly."
"They recently separated the WAF and the DAM management gateways in order for each of these to be managed from different areas, so I believe it now requires additional investments for what was previously a single complete solution."
"Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better."
"There's always room for improvement. Occasionally, there might be false-positive alerts."
"The Imperva Web Application Firewall automations are good, but there is still room for improvement with them."
"It would be useful if the solution used more intelligence in attack protection. For example, firewalls are to be dependent on the configuration, but if they could have some data science around it the solution would be even better. The profiling of the traffic, and making decisions surrounding that should be intelligence-based, instead of being based on the configuration of the firewall itself."
"The process to upgrade from one version to another can be a lot simpler than it is currently."
 

Pricing and Cost Advice

"So far I use free tier and happy with it. You can subscribe to business package if needed."
"We are using the free version."
"We don't have any issues with the price."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"The price of the solution is expensive."
"A free version of the solution is available."
"The tool is a premium product, so it is very expensive."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"FortiWeb Web Application Firewall is not expensive."
"It is a cost-effective product. If you need an extra module in the product, there will be an extra cost in addition to the licensing fee."
"I would rate the pricing a four out of ten."
"I rate the product price a four on a scale of one to ten, where one is a high price, and ten is a low price."
"The tool is really expensive."
"FortiWeb WAF is priced well for customers compared to other vendors' solutions."
"The product provides very good prices to customers. The price is set well and offers great value for money."
"FortiWeb has a good presence because of its price."
"Everybody complains about the price of this solution."
"It is a very affordable solution."
"There is a license for this solution and we purchase the license annually with no additional fees."
"The price of this solution is a little bit high compared to competitors."
"Imperva Web Application Firewall is expensive."
"It's an excellent product, but it can be very costly."
"The tool is expensive."
"There are some licenses that you have to buy to use some features. Its price could be better. Price is always important because, at the end of the day, customers have a budget. If you can meet the budget, you can sell, and if you don't, you cannot sell."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
849,686 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
17%
Computer Software Company
14%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
16%
Financial Services Firm
13%
Manufacturing Company
10%
Comms Service Provider
8%
Financial Services Firm
17%
Computer Software Company
13%
Insurance Company
8%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about FortiWeb Web Application Firewall (WAF)?
The most valuable features of the solution are SD-WAN, filtration, web filter, application filter, and IPS.
What is your experience regarding pricing and costs for FortiWeb Web Application Firewall (WAF)?
FortiWeb uses a subscription-based license, but there is also an option for a perpetual license. It's not the cheapes...
What needs improvement with FortiWeb Web Application Firewall (WAF)?
There are some issues pertaining to the migration. If some of my customers want to migrate from F5 to Fortinet Firewa...
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you hav...
DDoS solutions: Any other solutions to consider aside from Radware DDoS Protection Service and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot ...
 

Also Known As

Cloudflare DNS
No data available
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Information Not Available
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about FortiWeb Web Application Firewall (WAF) vs. Imperva Web Application Firewall and other solutions. Updated: April 2025.
849,686 professionals have used our research since 2012.