Coming October 25: PeerSpot Awards will be announced! Learn more
Buyer's Guide
Web Application Firewall (WAF)
September 2022
Get our free report covering Fortinet, Microsoft, Imperva, and other competitors of F5 Advanced WAF. Updated: September 2022.
632,779 professionals have used our research since 2012.

Read reviews of F5 Advanced WAF alternatives and competitors

Carlos Pindado - PeerSpot reviewer
Director of business and digital transformation at SERNIVEL3
Real User
Top 20
Useful single location dashboard controls, stable, and helpful support
Pros and Cons
  • "You have the ability to control everything from one single dashboard."
  • "The solution could improve by being able to handle different use cases."

What is our primary use case?

We use Fortinet FortiWeb for industrial companies. We are making doing network segmentation inside the industrial park, which is quite difficult and we have to design, develop and maintain all of the different kinds of solutions. We brought Fortinet FortiWeb to protect against forbidden access and for special access for providers in the industry.

How has it helped my organization?

We do not use this solution for our organization but for clients' organizations. For example, one customer uses the solution for the protection of all their different applications. Additionally, the solution has protected the servers that are in the DMC, such as services for people in other countries that have to have access.

What is most valuable?

You have the ability to control everything from one single dashboard.

What needs improvement?

The solution could improve by being able to handle different use cases.

For how long have I used the solution?

I have used Fortinet FortiWeb within the past 12 months.

What do I think about the stability of the solution?

The stability is good.

What do I think about the scalability of the solution?

The scalability is quite good. The scalability has been good for each industry. You can integrate Fortinet FortiWeb with all kinds of products of the same vendor. This allows the ability for a lot of different functions that you don't have to have really competent staff because you do not have different vendors. You don't have to call another vendor for solving one ticket or problem. This made everything simple, it was very good.

We have approximately 2,000 people using this solution.

When our customers have acquired more industrial plants we will propose this solution for all those industrial plant customers.

How are customer service and support?

The technical support is good.

I would rate the technical support of Fortinet FortiWeb an eight out of ten.

Which solution did I use previously and why did I switch?

We previously used F5.

How was the initial setup?

The installation was straightforward and it took us approximately one month. There are a lot of services, approximately 15, and other parts to configure.

What about the implementation team?

We used consultants, technicians and, an integrator for the implementation.

We do not need more than three people to do the maintenance and support of Fortinet FortiWeb.

What was our ROI?

We have seen a return on investment. It has been decent but not the best. We choose to work with one large customer and it has been similar to an investment.

What's my experience with pricing, setup cost, and licensing?

We are on an annual license for this solution and the price is approximately €100.

Which other solutions did I evaluate?

We have evaluated a number of solutions, such as Citrix NetScaler.

What other advice do I have?

I would recommend those wanting to implement this solution to use good integrators, there are not too many people who know about this solution. I lived in Spain and there are not too many installations made, it's quite difficult to find people that know a lot about it. It's not a difficult installation and the vendor helped us a lot and is very helpful. You have professional services you can use from the vendor if you choose, but they are quite expensive for customers.

One of the biggest lessons I have learned from using Fortinet FortiWeb is Fortinet helps you a lot. They can develop something specifically for a customers' use case without any costs for them.

I rate Fortinet FortiWeb a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Co-owner at Akson d.o.o.
Real User
Has a good graphic user interface for beginners, but lacks real-time notifications, alerts, and artificial intelligence
Pros and Cons
  • "The advantage of Citrix Web App and API Protection is just its graphic user interface for beginners. The solution is nothing special, but we have to use it for the corporation. Another advantage of Citrix Web App and API Protection is that we have our copy to test things and get the know-how of it."
  • "An area for improvement in Citrix Web App and API Protection is for it to give real-time notifications and alerts. It would be practical if the solution warns you if there's an attack or if the load or traffic volume increases or decreases. An additional feature I'd like to see in Citrix Web App and API Protection is a prediction or artificial intelligence on what is happening, for example, attacks."

What is our primary use case?

Corporations we work for use Citrix Web App and API Protection for security compliance.

What is most valuable?

The advantage of Citrix Web App and API Protection is just its graphic user interface for beginners. The solution is nothing special, but we have to use it for the corporation. Another advantage of Citrix Web App and API Protection is that we have our copy to test things and get the know-how of it.

What needs improvement?

An area for improvement in Citrix Web App and API Protection is for it to give real-time notifications and alerts. It would be practical if the solution warns you if there's an attack or if the load or traffic volume increases or decreases.

An additional feature I'd like to see in Citrix Web App and API Protection is a prediction or artificial intelligence on what is happening, for example, attacks.

For how long have I used the solution?

I've been using Citrix Web App and API Protection for five or six years because of a corporate decision, but for me, the solution is of no use.

What do I think about the stability of the solution?

Citrix Web App and API Protection is a stable solution, but it doesn't have much use. We had a cluster setup in the past, and the solution lost connectivity, but it's been a year since the latest update, and that issue has been resolved.

What do I think about the scalability of the solution?

Citrix Web App and API Protection is a scalable solution.

Which solution did I use previously and why did I switch?

I didn't work with other solutions before working with Citrix Web App and API Protection, but my company is currently looking at F5, Nginx, and a cloud solution such as Cloudflare.

How was the initial setup?

The initial setup for Citrix Web App and API Protection was quite easy. We just installed it, configured the interfaces, and it worked. It only took one day until full production.

What's my experience with pricing, setup cost, and licensing?

The pricing for Citrix Web App and API Protection is unreasonable. I don't know the exact price, but I heard it's tens of thousands and it's a bit too much for the small country I live in.

What other advice do I have?

My company is working with Citrix Web App and API Protection, but the team doesn't like the solution.

The team used version 11 of Citrix Web App and API Protection. Version 12 of the solution stopped working on the exchange server because of authentication issues. It serves as a proxy, but you can do it with Apache or Nginx if you want. There's nothing special with the solution in terms of protection and no notification if there's an issue, so Citrix Web App and API Protection does not have much use.

About ten people use Citrix Web App and API Protection in my company.

My advice to people who want to implement the solution is "Better not start".

My rating for Citrix Web App and API Protection, if you have the solution, would be in the middle. There's no practical use for it for technical system administrators. I'm rating it six out of ten.

I don't know the exact relationship with Citrix, but it seems my company has the license for partners in terms of usage.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Flag as inappropriate
CTO at a tech services company with 11-50 employees
Real User
It is easy to deploy, manage, and expand
Pros and Cons
  • "Its inline transferring mode is the most valuable because it is 100% transparent. When you change the IP, there is no change on the network side. If you can't and want to try to reach an IP, you can reach the server IP. There are many other advanced security features in it. The smallest appliances of Imperva can handle the highest traffic at a customer site. For example, a smaller appliance from Imperva can provide you the same security as an F5 product."
  • "They can provide an option to create reports, automatically import the entire report, and create rules again. In a real-life crisis, it would be helpful to be able to import a report and generate security rules from that report. I should be able to create a simple query and import the reports automatically. It can maybe also tell us the format of the report."

What is most valuable?

Its inline transferring mode is the most valuable because it is 100% transparent. When you change the IP, there is no change on the network side. If you can't and want to try to reach an IP, you can reach the server IP. There are many other advanced security features in it.

The smallest appliances of Imperva can handle the highest traffic at a customer site. For example, a smaller appliance from Imperva can provide you the same security as an F5 product. 

What needs improvement?

They can provide an option to create a report, automatically import the entire report, and create rules again. In a real-life crisis, it would be helpful to be able to import a report and generate security rules from that report. I should be able to create a simple query and import the reports automatically. It can maybe also tell us the format of the report.

For how long have I used the solution?

I have been using this solution for more than nine years.

What do I think about the stability of the solution?

It is very stable.

What do I think about the scalability of the solution?

It is easy to scale up.

How are customer service and technical support?

After nine years with Imperva, we know mostly everything about it, and we are using it very deeply. None of the support can handle us when it comes to R&D. They are able to help us with all other categories.

How was the initial setup?

The initial setup is very easy. You can just plug it in, and it asks you some questions about the IP address, DNS, SSL, etc. After that, it asks you for license codes, and everything is online. It is easy to deploy. You don't have to change any network configuration.

What's my experience with pricing, setup cost, and licensing?

There are some licenses that you have to buy to use some features.

Its price could be better. Price is always important because, at the end of the day, customers have a budget. If you can meet the budget, you can sell, and if you don't, you cannot sell.

What other advice do I have?

In Turkey, we mostly have on-premises deployments. There are some Azure Amazon projects, but it is mostly deployed on-premises. It is not so easy to send Incapsula solutions to Turkey.

I would recommend this solution. It is easy to manage and expand. I would rate Imperva SecureSphere Web Application Firewall a ten out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cloud Security Architect at a computer software company with 10,001+ employees
Real User
Scalable, straightforward installation, but lacking stability

What is our primary use case?

We are using the Barracuda Web Application Firewall for website content and front-end web application protection.

For how long have I used the solution?

I have been using Barracuda Web Application Firewall for a few years.

What do I think about the stability of the solution?

I have found F5 more stable than Barracuda Web Application Firewall. They should improve the stability.

What do I think about the scalability of the solution?

Barracuda Web Application Firewall has been scalable in my experience.

Which solution did I use previously and why did I switch?

I have used similar solutions to Barracuda Web Application Firewall, such as F5 and there are not any major differences between them.

How was the initial setup?

The installation is straightforward.

What about the implementation team?

We need a minimum of three to four people to do the implementation and maintenance of the solution.

What other advice do I have?

I rate Barracuda Web Application Firewall a seven out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Web Application Firewall (WAF)
September 2022
Get our free report covering Fortinet, Microsoft, Imperva, and other competitors of F5 Advanced WAF. Updated: September 2022.
632,779 professionals have used our research since 2012.