Our client has an internally hosted website, and they wanted us to help them in reducing the attack surface in their web application, so we use F5 Advanced WAF for that purpose.
SOC Analyst at a financial services firm with 1,001-5,000 employees
Stable and has a pool of resources for traffic distribution and management
Pros and Cons
- "The most valuable feature of F5 Advanced WAF is its ability to have a pool of resources that can distribute your traffic, and that is a plus for me. My company tried to look into a competitor, Imperva, but it was lacking that capability, so F5 Advanced WAF outperforms Imperva."
- "For me, an area for improvement in F5 Advanced WAF is the reporting as it isn't so clear. The vendor needs to work on the reporting capability of the solution. What I'd like to see in the next release of F5 Advanced WAF is threat intelligence to protect your web application, particularly having that capability out-of-the-box, and not needing to pay extra for it, similar to what's offered in FortiWeb, for example, any request that originates from a malicious IP will be blocked automatically by FortiWeb. F5 Advanced WAF should have the intelligence for blocking malicious IPs, or automatically blocking threats included in the license, instead of making it an add-on feature that users have to pay for apart from the standard licensing fees."
What is our primary use case?
What is most valuable?
The most valuable feature of F5 Advanced WAF is its ability to have a pool of resources that can distribute your traffic, and that is a plus for me. My company tried to look into a competitor, Imperva, but it was lacking that capability, so F5 Advanced WAF outperforms Imperva.
What needs improvement?
For me, an area for improvement in F5 Advanced WAF is the reporting as it isn't so clear. The vendor needs to work on the reporting capability of the solution.
What I'd like to see in the next release of F5 Advanced WAF is threat intelligence to protect your web application, particularly having that capability out-of-the-box, and not needing to pay extra for it, similar to what's offered in FortiWeb, for example, any request that originates from a malicious IP will be blocked automatically by FortiWeb. F5 Advanced WAF should have the intelligence for blocking malicious IPs, or automatically blocking threats included in the license, instead of making it an add-on feature that users have to pay for apart from the standard licensing fees.
For how long have I used the solution?
I've been using F5 Advanced WAF for about two years.
Buyer's Guide
F5 Advanced WAF
June 2025

Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What do I think about the stability of the solution?
F5 Advanced WAF is a super stable solution. I've not been aware of any issues with the solution whenever my company uses it.
What do I think about the scalability of the solution?
How scalable F5 Advanced WAF is would depend on what resources your client or the virtual server has. It all boils down to the allocated resources. For me, F5 Advanced WAF is pretty much scalable in terms of the resources I've assigned.
How are customer service and support?
I contact the technical support team of F5 Advanced WAF from time to time, and I would rate support eight out of ten. What the support team needs to improve is the SLA, particularly the speed of response.
How would you rate customer service and support?
Positive
How was the initial setup?
In terms of setting up F5 Advanced WAF, what was challenging was the network part, but the rest wasn't that difficult. It took almost two weeks to complete the setup for F5 Advanced WAF.
What about the implementation team?
We implemented F5 Advanced WAF ourselves.
What was our ROI?
It's hard to tell if the customer got ROI from F5 Advanced WAF because it's based on the initial deployment and approach. It would've been just a matter of time before the customer enjoyed ROI from the solution. My company never experienced a serious incident with the use of F5 Advanced WAF for the customer, so my assumption is at some point, the customer is realizing the ROI.
What's my experience with pricing, setup cost, and licensing?
The pricing for F5 Advanced WAF is comparable to a Rolls-Royce. Its price is a bit high when you compare it with other vendors. F5 Advanced WAF is a bit expensive. The customer was on a three-year plan and it was around $560,000.
Which other solutions did I evaluate?
We evaluated Imperva, but F5 Advanced WAF was able to outperform Imperva.
What other advice do I have?
I'm an administrator of F5 Advanced WAF for my customer, so I'm more of a user. I'm not a partner or reseller of F5. I'm just a consultant and administrator.
From what I recall, during the time of deployment, my company was using version 15 of F5 Advanced WAF, but I'm not so sure if there's been a new version or an upgrade after that version.
My company has less than ten users/administrators of F5 Advanced WAF.
My advice for people who want to implement the solution, though I might be biased because I've not used other solutions, but as far as I am concerned, F5 Advanced WAF is one of the most stable solutions I've ever used, so it's good to implement.
My rating for F5 Advanced WAF is nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Sr. Architect at NBC Universal
Easy event identification, highly stable, and customizable
Pros and Cons
- "The most valuable features of F5 Advanced WAF are the easy identification of events and customization. We can pinpoint our settings."
- "F5 Advanced WAF could improve resource usage, it is CPU intensive. Additionally, adding automated remediation would be a benefit. For example, an easy button alerts us of the events that are occurring, and what we want to do at the time. An automated approach where somebody could be alerted very quickly. Instead of going and reconfiguring everything, an automated approach is what I'm looking at."
What is our primary use case?
We are using F5 Advanced WAF to protect certain environments. It protects us against everything, such as botnets, web scraping attacks, and foreign entities attacks. It allows us to hone in on exactly the area that we need to focus on. It's a web-based firewall.
How has it helped my organization?
F5 Advanced WAF has benefited our company by protecting us against revenue loss. It's prevented hacks that would have taken us offline or caused us a loss of revenue in different areas.
What is most valuable?
The most valuable features of F5 Advanced WAF are the easy identification of events and customization. We can pinpoint our settings.
What needs improvement?
F5 Advanced WAF could improve resource usage, it is CPU intensive. Additionally, adding automated remediation would be a benefit. For example, an easy button alerts us of the events that are occurring, and what we want to do at the time. An automated approach where somebody could be alerted very quickly. Instead of going and reconfiguring everything, an automated approach is what I'm looking at.
For how long have I used the solution?
I have been using F5 Advanced WAF for approximately five years.
What do I think about the stability of the solution?
We can scale the F5 Advanced WAF very easily. We could configure it to be a canned solution or a customized solution. It goes from canned to full customization to what we need.
What do I think about the scalability of the solution?
After we sized F5 Advanced WAF just right and identified the correct way to configure it, it's very stable.
The solution is not being extensively used.
Which solution did I use previously and why did I switch?
We have used other solutions previously and in parallel.
How was the initial setup?
Generally, F5 Advanced WAF initial setup is straightforward. However, our environment was more complex and it took us a little more time to customize the solution to where we needed it to be. Additionally, the customization didn't rectify everything. We had to do customization to a certain event to prevent attacks that it wasn't catching, but that might not necessarily be the solutions' fault. It could be more of our setup than the solution's fault and not being able to run the latest version or the newer version could be more of a limitation on our ability to put it in the right place.
The whole implementation to have the solution run at the level we wanted it to take approximately five months.
Our company's environment is one that we can't put a canned solution in front of. Our environment, cannot have a canned solution that might fit everybody else because of how customized this environment is. It does need a lot of tuning to meet our environment's requirements.
I rate the initial setup of F5 Advanced WAF a three out of five.
What about the implementation team?
We did the implementation of this solution in-house. We have a very small group that is managing it. However, because it's for external users it's not a company use solution. Managing it, it's a very small subset of users that will manage the solution and the environment behind it. It is for external customers only.
What was our ROI?
We have received a return on investment by using F5 Advanced WAF which has saved us from losing revenue.
I rate the return of investment from F5 Advanced WAF a four out of five.
What other advice do I have?
My advice to others would be to define the parameters well in the beginning, and then they will be fine. They could define it as a regular canned solution and go from there, instead of working it as not a canned solution. Define the environment and what you need to protect, that way you can build a base protection profile that you could deploy elsewhere instead of building the policy to the environment first because then customizing cannot be deployed easily.
I rate F5 Advanced WAF an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
F5 Advanced WAF
June 2025

Learn what your peers think about F5 Advanced WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Network Security Consultant at GBM
Powerful and easy-to-use security features for compliance or integration
Pros and Cons
- "It is easy to obtain dashboard compliance because security policy views are included."
- "The solution should include RASP for another level of protection at the code itself."
What is our primary use case?
Our company uses the solution for customer use cases to replicate environments, perform integrations, and check for changes or issues. We have many internal users because we have a wide database of customers.
Most customers have WAF or Advanced WAF but if you dig deep from a high-level perspective, then you find issues with configurations or missing security enhancements.
The platform is capable of doing many API integrations and other things. Customers with public websites use our client-facing service to upload attachments. Often, customers are not integrating the solution with a malware sandboxing tool. This feature is natively in-the-box so protection can be enabled with a few steps. We determine if attachments are uploading malicious files because there isn't protection in the normal solution. We find out if customers are doing vulnerability or risk assessments. Integration tools such as Qualys help because we can import a file to resolve F5 issues.
For one use case, a customer might have enabled the tech signature for a specific tech but an IP exclusion or public IP exclusion is a bit risky.
Another use case is for database security where we utilize the solution's very comprehensive security features. We can make a SQL database more visible to database security and order logs for the logins to the station tool.
What is most valuable?
It is very powerful to be able to enable database security integration for an administrator or customers.
The integration between modules is good. You can license the APM policy manager, integrate, and make security posters for VPN clients. You can natively integrate the login pages to ensure client machines and websites are protected.
The solution includes the typical load balancing offered by other vendors but has enhanced security compliance features that are powerful and easy to configure.
It is easy to obtain dashboard compliance because security policy views are included.
What needs improvement?
The solution requires a bit of advanced knowledge. They are trying to make configurations less complicated by including guides, particularly for application protection in the cloud. Nothing is complicated but it takes a hands-on approach and a few hours to a few months to become familiar with how the solution works.
The solution should include RASP which is runtime application security protection. Imperva includes RASP but the solution does not at this point. RASP would provide another level of application protection at the code itself.
For how long have I used the solution?
I am a certified F5 engineer and have been using the solution for four years.
I am a partner so I use both the on-premises and the public cloud solution. To get certification, you need to complete a lot of labs and training on your own. You must go into detail with everything and get your hands dirty.
I use the public cloud solution for my own labs. There is a free F5 public cloud tenant that includes other features for setting up a lab or application.
The solution's virtual edition can be deployed in other cloud services such as Azure, AWS, and OCI. The virtual edition takes the on-premises version to the cloud so it is not difficult to implement. The only difference is the cloud-native version includes the WARP feature that is used for web application API protection.
What do I think about the stability of the solution?
The solution is definitely stable so I rate stability a nine out of ten.
What do I think about the scalability of the solution?
The solution is quite scalable so I rate scalability a nine out of ten.
How are customer service and support?
To be honest, I have not needed support because I have the knowledge to fix anything unless it is a bug within the solution.
How was the initial setup?
The initial setup is not complex so I rate it a ten out of ten.
For on-premises, it might take two weeks to deploy security policies which depend on application traffic. You choose a policy set type from fundamental, comprehensive, or rapid according to your needs. Then, you apply the policy.
For example, you can deploy a quick policy for a nonfinancial side to protect from common threats. In this case, you choose the rapid security policy, choose the application language, and add the SQL or PHP server technology to implement the attack signature. This is helpful because you don't need to apply all of the OS signatures if you only have Windows. Just pull the Windows signature and it will be plugged.
Then you proceed to the staging model for awhile to pick up the negative security model. You can proceed with a mix of negative and unboxing security models. After that, you start deploying, defining URL parameters, and setting other policies. You put it to staging and make edits. If you don't find too many suggestions or false positives, then you deploy it in blocking mode to the vendor.
After two or three weeks, if the owner is fine with the policies and number of false positives, then you put it to blocking.
What about the implementation team?
We implement the solution for customers. Implementation can be done by one person who is knowledgeable about the product and procedures.
IT managers generally do not dig deep inside the solution because there is quite a bit of detail. They have a high-level overview but certified experts dig deep into configurations.
What's my experience with pricing, setup cost, and licensing?
I am not sure about pricing but licenses are available on Google.
What other advice do I have?
The solution is not about improving functionality but about improving the security of an infrastructure itself. You are improving the security profile so that data is not exposed to an attacker.
I definitely recommend that everyone use the solution and rate it a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer:
Sr. Architect at NBC Universal
Protects our environment and is easy to use and scalable for our needs
Pros and Cons
- "Identification, ease of use, and ease of modifying it to most of our needs are valuable."
- "There should be more ability to rate limit certain scenarios. The majority of the time, it is either on or off. For certain types of use cases, there should be the ability to rate limit, not just enable or disable."
What is our primary use case?
It protects our public entities. Its use case is very directed at a resolution of security.
How has it helped my organization?
It protects our environment. It protects our entities.
What is most valuable?
Identification, ease of use, and ease of modifying it to most of our needs are valuable.
What needs improvement?
There should be more ability to rate limit certain scenarios. The majority of the time, it is either on or off. For certain types of use cases, there should be the ability to rate limit, not just enable or disable.
It is a very CPU-intensive application. I understand why, but I'm hoping that they could optimize the CPU utilization a little bit better.
For how long have I used the solution?
I have been using this solution for eight years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is very scalable for what we need. It is a public-facing service. So, everybody on the internet would be able to utilize this type of service.
We are exploring areas to increase its usage.
How are customer service and support?
I would rate them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used other public entities for similar use cases.
How was the initial setup?
It is pretty straightforward. A typical setup for these types of projects takes three months.
What about the implementation team?
It is all done in-house. We do everything in-house.
In its maintenance, I and other people are involved. The daily operations, which include modifying policies, are up to the individual application owners because they understand their applications a lot better than I or our standard operating team would. So, their usage might go higher than mine.
What was our ROI?
We have very much seen an ROI. It protects our revenue stream.
What's my experience with pricing, setup cost, and licensing?
The way we deployed it, I would rate it a four out of five in terms of pricing.
What other advice do I have?
I would advise doing your homework. It could be very simplified, or it could be very complex, but definitely, do your homework with the owners of the application because they understand the application more than certain people.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Team Leader at Summit Technology Solution
Stable product with essential capabilities to protect the web applications
Pros and Cons
- "F5 Advanced WAF helps our engineers to learn the complete configuration, including fundamental and advanced policies."
- "Most customers encounter stability issues with the product's Big-IP logs."
What is our primary use case?
We use F5 Advanced WAF to protect web applications on HTTPS, APIs, and portals.
What is most valuable?
F5 Advanced WAF helps our engineers to learn the complete configuration, including fundamental and advanced policies.
What needs improvement?
Most customers encounter stability issues with the product's Big-IP logs. It works slowly while retrieving logs.
For how long have I used the solution?
We have been using F5 Advanced WAF since this year.
What do I think about the stability of the solution?
The product is more stable than Fortinet.
What do I think about the scalability of the solution?
The product has modular appliances. It works well, scalability-wise.
How are customer service and support?
The technical support services are good. The team includes professional engineers to communicate with the customers regarding cases.
How was the initial setup?
It is easy to set up F5 Advanced WAF. Although, it is difficult to deploy and maintain compared to Fortinet. The deployment process involves gathering customer information regarding virtual servers to be protected. Later, we select the best design suitable for their requirements and start with license provisioning. Further, we configure LTM with special servers and nodes and proceed with configuring the security policy and advanced directory. It takes a week to protect the infrastructure fully. Once we have license provisioning, it is good to run.
What's my experience with pricing, setup cost, and licensing?
F5 Advanced WAF's pricing is high. Fortinet and some other vendors are more affordable.
What other advice do I have?
F5 Advanced WAF has good capabilities, powerful tools, and professional services. I advise others to compare pricing with vendors in terms of their use cases before purchasing the product.
I rate it a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Unit Head - Network and Security Solutions at FPM Solutions
Their support engineers are experts who always provide the right solution,
Pros and Cons
- "F5 technical support is excellent. They are experts who always provide the right solution, and they understand the problem. Their response and resolution times are good."
- "Nevertheless, F5 products are generally considered to be hard to deploy."
What is our primary use case?
In Pakistan, the banking and financial sector requires F5 WAF solutions. I worked with other companies that had more clients, but my current company is a start-up. We have Palo Alto business, but we're trying to get F5 business.
What is most valuable?
F5 products are highly stable, top-notch solutions, and we have also the expertise to deploy and design the F5 and Palo Alto product lines. I have more than 10 years of experience with F5 and Palo Alto. I have deployed around F5 products for around seven or eight customers of F5.
What needs improvement?
F5 should consider adding network detection and response.
For how long have I used the solution?
We have been using F5 solutions for two years, including load balancers and Advanced WAF.
What do I think about the stability of the solution?
Advanced WAF is highly stable.
What do I think about the scalability of the solution?
F5 products are scalable, and they have an excellent R&D department. Their product is constantly maturing.
How are customer service and support?
F5 technical support is excellent. They are experts who always provide the right solution, and they understand the problem. Their response and resolution times are good.
How was the initial setup?
Advanced WAF is a difficult product for new users, but it's not too challenging if you have experience. Nevertheless, F5 products are generally considered to be hard to deploy.
What's my experience with pricing, setup cost, and licensing?
F5's hardware product line is called BIG-IP, and they have many software licenses for IP DNS, Advanced WAF, APM, anti-spam, etc. We have around 10 licenses.
What other advice do I have?
I rate F5 Advanced WAF 10 out of 10. I would highly recommend the entire F5 product line.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT Manager at Technology Evaluation Center
A robust solution for large companies that includes vCMP-like visualization
Pros and Cons
- "The solution uses AI to protect against botnet attacks."
- "The solution should include protection against web page attacks like what is available in FortiWeb."
What is our primary use case?
Our company installs the solution for customers who require more features than are available with FortiADC.
One of our customers is a bank that has API for both web and mobile applications. We use the solution to load balance and provide protection for the API requests that come from customers to the application server. With more than 200,000 DNS requests per second, the solution's advanced features are the best fit to the customer's needs.
What is most valuable?
The solution uses AI to protect against botnet attacks.
The solution has a vCMP-like feature that allows you to visualize more than two TMOS at the same time on your hardware. This feature is not available with other solutions.
What needs improvement?
The solution should include protection against web page attacks like what is available in FortiWeb.
The solution should integrate with Kubernetes. I believe there is a new ADC planned for the end of 2022 that will accomplish this goal.
For how long have I used the solution?
I have been using the solution for six years.
What do I think about the stability of the solution?
The solution is super stable with extra chassis space.
We sometimes use solution to its maximum capacity and it is still stable with no crashes.
What do I think about the scalability of the solution?
The solution is super scalable.
FortiADC is a good solution for small or mid-sized companies but F5 can handle the largest companies.
Across all of our customers, we have more than a million users at the same time with no issues.
How are customer service and support?
I have not needed technical support.
How was the initial setup?
The initial setup is more complex than FortiADC and takes about twice the amount of time.
What about the implementation team?
Our company provides setup and deployment for our customers.
What's my experience with pricing, setup cost, and licensing?
The solution is very expensive so should only be used in the right environment. I believe each device costs around $20,000 and includes a three-year license.
I rate the cost a ten out of ten.
Which other solutions did I evaluate?
We do not consider other options for large companies but do install FortiADC for small to mid-sized companies.
What other advice do I have?
It is important to know your network and assess your needs such as dust protection, VAT, and load balancing before deciding if FortiADC or F5 are the best solution.
F5 is expensive so is only appropriate for large companies with high-level use.
I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
F5 Product Manager at Westcon-Comstor
A solution that would benefit with more documentation regarding bot protection
Pros and Cons
- "The most valuable features of F5 Advanced WAF are the security features and the protection."
- "F5 Advanced needs to improve its bot protection. The solution needs to have machine learning to learn the behavior of the customer to recognize the human versus the bot. This is a difficult feature to explain to our customers. I would like documentation about the bot feature to make it easier for the customer to understand."
What is our primary use case?
We are distributors in Vietnam. We consult for our customers and I am a Product Manager. We use F5 Advanced WAF as a firewall for our website applications and the websites of our customers.
What is most valuable?
The most valuable features of F5 Advanced WAF are the security features and the protection.
In the future, I would like to see F5 include AI in the hardware of F5 Advanced WAF.
What needs improvement?
F5 Advanced needs to improve its bot protection. The solution needs to have machine learning to learn the behavior of the customer to recognize the human versus the bot. This is a difficult feature to explain to our customers. I would like documentation about the bot feature to make it easier for the customer to understand.
For how long have I used the solution?
I have been using F5 Advanced WAF for two years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
F5 Advanced WAF is scalable.
How are customer service and support?
We tend to handle our own technical support for our customers. My experience with F5 support is a three out of five overall. They need to improve the information and training of the receiver.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was neither easy nor difficult. I would rate setup as a four out of five.
What's my experience with pricing, setup cost, and licensing?
The pricing of F5 Advanced WAF is more expensive than other solutions like Radware and CD18, it is quite high. I rate the product a one out of five for price, with one being expensive.
What other advice do I have?
Overall, I would rate F5 Advanced WAF an eight out of ten overall.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:

Buyer's Guide
Download our free F5 Advanced WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
AWS WAF
Fortinet FortiWeb
NetScaler
Cloudflare Web Application Firewall
Imperva Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Gigamon Deep Observability Pipeline
Radware Alteon
NGINX App Protect
Buyer's Guide
Download our free F5 Advanced WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Does F5 Advanced WAF work with Azure App Service?
- Which is better, Barracuda Web Application Firewall or F5 Advanced WAF?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy