It helped us to define wherever there was illicit traffic between our webs, and improved the control we achieved.
Security Consultant at a security firm with 501-1,000 employees
Gives us the ability to differentiate between a positive and a false-positive intruder action
Pros and Cons
- "Gives us the ability to trace each connection, and to have logs to be able to differentiate between a positive and a false-positive intruder action."
- "I miss being able to integrate the dashboard with other BI tools we are using. We have to export and import data to be able to present it, and doing so is a lot of work."
How has it helped my organization?
What is most valuable?
The ability to trace each connection, and to have logs to be able to differentiate between a positive and a false-positive intruder action.
It is handy to retrieve and download the logs to line up separate actions to identify possible intruder behaviour.
What needs improvement?
At that moment, I miss being able to integrate the dashboard with other BI tools we are using. We have to export and import data to be able to present it, and doing so is a lot of work.
For how long have I used the solution?
One to three years.
Buyer's Guide
Imperva DDoS
April 2025

Learn what your peers think about Imperva DDoS. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
857,028 professionals have used our research since 2012.
What do I think about the stability of the solution?
Not at all.
It was a bit pointless to know how many sites were offline every time a spot in the world decided to do maintenance, but we like it as we can handle worldwide issues, knowing what is going on there.
What do I think about the scalability of the solution?
No issues at all, it fulfills our expectations in terms of scalability.
How are customer service and support?
Great.
Which solution did I use previously and why did I switch?
We had used many local, and some cloud-based solutions (like Azure, Advanced Nagios, Centreon). We switched for the scalability of the solution, the reporting features it has, as well as the availability to fine tune the solution.
How was the initial setup?
It was straightforward, but we had to fine tune it.
The initial setup blocked some cookies and data from our scrapers which, they said, they never received from us. We investigated and found the WAF was blocking them. It was a lot of work.
What's my experience with pricing, setup cost, and licensing?
It's worth it. It's a fine solution for medium/big companies worried about attacks that happen in the wild.
Which other solutions did I evaluate?
Centreon and Azure.
What other advice do I have?
My best advice could be, if you don't have the staff to carry out security in a proper way, have a tool do it, but use a specialized tool like this one, and don't re-invent the wheel.
Also, in our case, we soon realized that we needed an expert to fine tune it and to obtain all the features we wanted.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Head Of Information Security at IronFX Global Limited
We are able to bring a new website live within minutes, without false positive alerts
Pros and Cons
- "IncapRules is one of the most valuable features, as you can create your own security and access control rules on top of your security policy. Using IncapRules we were able to easily block Layer 7 DDoS attacks several times."
- "Real-time monitoring is also a great tool, as you may watch several parameters in real time."
- "Incapsula takes care of the CDN infrastructure and bandwidth volume, providing several enterprise "load balancing" features."
- "It would be better if we were able to manage and apply changes to multiple websites/web applications, and search WAF logs for multiple websites, via the Incapsula dashboard."
How has it helped my organization?
There is no need to have an in-house WAF to manage and maintain. We are now able to bring a new website live within minutes, without false positive alerts. It has Improved user/customer experience and website performance.
What is most valuable?
IncapRules is one of the most valuable features, as you can create your own security and access control rules on top of your security policy. Using IncapRules we were able to easily block Layer 7 DDoS attacks several times.
Real-time monitoring is also a great tool, as you may watch several parameters in real time.
What needs improvement?
It would be better if we were able to manage and apply changes to multiple websites/web applications, and search WAF logs for multiple websites, via the Incapsula dashboard.
For how long have I used the solution?
Three to five years.
What do I think about the stability of the solution?
The first year we faced one or two incidents, but since then we not had any stability issues.
What do I think about the scalability of the solution?
No issues with scalability. You need not worry about scalability. Incapsula takes care of the CDN infrastructure and bandwidth volume, providing several enterprise "load balancing" features.
How are customer service and technical support?
Incapsula’s support personnel is very good, positive, and most of them passionate. Sometimes a second-level support might be required for more complex requests. Additionally, you may see a slight delay in replying to support tickets, but you are able to contact them via phone for critical cases and prompt response.
Which solution did I use previously and why did I switch?
We were using Akamai and we switched to Incapsula mainly due to the WAF effectiveness and total cost.
How was the initial setup?
Not only the initial, but also the final setup, is straightforward.
What's my experience with pricing, setup cost, and licensing?
For enterprise contracts you will be in touch with a dedicated account manager who will guide you regarding licensing.
Which other solutions did I evaluate?
We evaluated Akamai. Akamai had a bigger CDN network and probably better performance worldwide (especially on the Chinese mainland) but their WAF is very pure and not effective at all.
What other advice do I have?
Go for it and request a free trial.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Imperva DDoS
April 2025

Learn what your peers think about Imperva DDoS. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
857,028 professionals have used our research since 2012.
System Administator at a tech services company with 201-500 employees
With the WAF, our web services can't be exploited remotely.
What is most valuable?
- DDoS protection
- CDN
- WAF
- Good API for managing services
How has it helped my organization?
Thanks to Incapsula, we got easily manageable DDoS protection; HTTP2 and SSL certificates for all the services; CDN in good locations; and we're now sure that our web services can't be exploited remotely because of the WAF feature. Also, we can chose to whitelist/blacklist network(s) access to specific services/resources.
For how long have I used the solution?
I have used it for a few years.
What was my experience with deployment of the solution?
We have not encountered any deployment issues.
What do I think about the stability of the solution?
We had a few hiccups in the past, but they were small with no impact to important services.
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and technical support?
They need to work on the customer support; in my opinion, this is their weakest point. Some of their support representatives really have no idea how their service works.
Which solution did I use previously and why did I switch?
We did not previously use a different solution.
What about the implementation team?
An in-house team implemented it.
Which other solutions did I evaluate?
Before choosing this product, we did not evaluate other options.
What other advice do I have?
Try it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Application Security Architect at a hospitality company with 10,001+ employees
The WAF can identify, block, whitelist or blacklist as needed.
What is most valuable?
Hands down, the WAF is the most valuable feature; being able to identify, block, whitelist or blacklist as needed, are all valuable.
How has it helped my organization?
We now have visibility into our traffic in a scope that we never had before, especially being able to review bot vs human traffic and country of origin.
What needs improvement?
Reporting and the main Sites dashboard could use refinement. We have a lot of sites, and scrolling through the dashboard becomes cumbersome.
For how long have I used the solution?
I have used it for six months.
What was my experience with deployment of the solution?
The only deployment issue we encountered was getting Incapsula and Akamai to play nice. However, the Incapsula engineers were very helpful in helping us configure our sites in the WAF correctly.
What do I think about the stability of the solution?
We have not encountered any stability issues.
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and technical support?
Customer Service:
I have yet to need customer service.
Technical Support:I rate the level of technical support as very high.
Which solution did I use previously and why did I switch?
We had not used a WAF before deploying Incapsula.
How was the initial setup?
The setup was straightforward and simple.
What about the implementation team?
We implemented it ourselves with the guidance of the Incapsula team.
What was our ROI?
It is too soon to tell regarding ROI.
What's my experience with pricing, setup cost, and licensing?
Know your bandwidth requirements.
Which other solutions did I evaluate?
Before choosing this product, we evaluated so, so, so many other options.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Cyber Defense & Offensive Security at Habib Bank Limited
I like the content monitoring feature which I haven't seen in other WAF solutions.
What is most valuable?
Content monitoring is a marvelous feature that I haven't seen in other Web Application Firewalls. It also has a good content filter. We do a lot of penetration testing on our servers, and the Imperva standalone solution for identifying a payload and its signature by deep analysis was very good.
How has it helped my organization?
We never used to know about threat and attack signatures. By using Imperva WAF, we could identify our weak points where an attacker was trying to gain access.
What needs improvement?
They could improve by minimizing false positive results. Although this occurs less with Imperva, we would like to see some further improvements.
We have been using this product for last 1 years, it's result is very impressive. But due to the excessive load on the Web site where thousands of requests are generated from legitimate users, however the request in which any sequential or specialised characters are requested would be directly blocked by impreva . Currently imperva blocks the special character request generated from the user, as I conduct a test where I am parsing the encoded html values of the same special characters to the input field, imperva bypasses these encoded values for example : ' i.e. %27 or / i.e %2F, the WAF bypasses these encoded characters. I hope that this device should have a capability to detect the pattern which is associated with Xss or Xsrf, rather then by not blocking the request which contains any special characters.
For how long have I used the solution?
I have used it for one year.
What do I think about the stability of the solution?
We did not encounter any stability issues.
What do I think about the scalability of the solution?
We never encountered any scalability issues.
How are customer service and technical support?
We were impressed with the technical support.
Which solution did I use previously and why did I switch?
We have examined different vendor WAF solutions but this solution was unique.
How was the initial setup?
Initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
Pricing was a little higher but when compared to performance; it's very cheap.
Which other solutions did I evaluate?
We evaluated Akamai and F5.
What other advice do I have?
Imperva Incapsula WAF is an awesome solution for implementing a WAF with good support and reliable hardware performance.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network and Security Engineer at a consumer goods company with 1,001-5,000 employees
The dashboard shows us traffic, security, and real-time utilization. The default configuration usually does the trick for us.
What is most valuable?
- Very easy to configure, which quickly allows us to add significant security to our websites.
- Nice dashboard, which shows us details about traffic, security, performance, real-time utilization and an activity log.
- Easy to configure caching, content optimization and other advanced settings, which allows us to improve the customer experience if necessary, or keep the defaults if any change is unnecessary.
How has it helped my organization?
With our IT infrastructure more secure, our customers receive a great website experience without encountering website defacements and other fallout from attacks on our web servers. Our IT department is not spending the time we used to on website remediation after attacks.
What needs improvement?
An Incapsula website configuration instance can be in a "Pending DNS changes" state, where further work is needing to be done by the customer, while website access is otherwise fully functional. While in this state, the PCI Compliance Report for the website in question, which I have set to email me monthly, doesn't get generated and sent. Imperva should decouple the "Pending DNS changes" state from the process that periodically emails the PCI Compliance Report. Until that happens, the workaround is to manually generate the report monthly.
For how long have I used the solution?
Since May 2014.
What do I think about the stability of the solution?
We haven’t had any stability issues. I get emails about internal Incapsula technical issues that they’re working on. However, they haven’t ever impacted me as an administrator and I’m unaware of any customers experiencing issues getting to our websites.
What do I think about the scalability of the solution?
Incapsula scales nicely.
How are customer service and technical support?
Technical support is excellent.
Which solution did I use previously and why did I switch?
Prior to Incapsula, we only used inline IPS, anti-virus, etc. Incapsula is our first web application firewall.
How was the initial setup?
Initial setup was very easy. The default configuration usually has done the trick for us. We simply haven’t needed to deviate much from default. Online documentation is good and if we still had questions, we contacted support who helped us make configuration changes to address our needs.
What's my experience with pricing, setup cost, and licensing?
Gain an understanding of pricing for the various advanced features and figure out what features you need to meet your objectives. We have done very well with the first tier feature package to address the needs at our two data centers and our cloud environments.
Which other solutions did I evaluate?
We got a feel for pricing and capabilities of other competing systems. However, Incapsula came highly recommended by our trusted security VAR as they had many customers who experienced great results with it. With that ringing endorsement, and the reasonable cost, we tried it out, loved it, and have been using it ever since.
What other advice do I have?
Do a proof-of-concept. It’s quick and easy to set up, and you’ll have Incapsula support to help you if needed. Embrace the ease-of-use of the administrative interface and marvel “can a WAF really be this easy?!”. Monitor the dashboard and enjoy the results. The ease of testing Incapsula and then implementing it into production is one of the most remarkable product experiences in my IT career. It’s clear that Incapsula engineers are busy behind the scenes, which is in contrast to my appreciation of what I would otherwise be doing tuning other WAF options.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Service Manager at a tech services company with 51-200 employees
Provides PCI-level IDS/IPS.
What is most valuable?
- Easy-to-set-up CDN with PCI-level IDS/IPS
How has it helped my organization?
We offer Incapsula for every customer project we host, as a default.
What needs improvement?
The default service is great!
For how long have I used the solution?
I have used it for two years.
What was my experience with deployment of the solution?
Sometimes, the SSL setup can be a bit slow/inconsistent.
What do I think about the stability of the solution?
There was only one minor incident with service availability, if I remember correctly.
What do I think about the scalability of the solution?
Nope; we have not encountered any scalability issues.
How are customer service and technical support?
Customer Service:
Some tickets seem to hang for some reason and some of the more-technical tickets seem to go through lot of different people before they get solved, but generally the customer service has been good.
Technical Support:General documentation is good enough that we haven't needed technical support that much, but the answers have been good once you go through the "Off-the-shelf" answers.
Which solution did I use previously and why did I switch?
We did try CloudFlare, but the pricing didn't suit our use case too well.
How was the initial setup?
The initial setup is fairly straightforward for a technical person.
What about the implementation team?
An in-house team implemented it all the way.
What was our ROI?
ROI is ~90%.
What's my experience with pricing, setup cost, and licensing?
Pricing is a good match for the features we use.
Which other solutions did I evaluate?
Before choosing this product, we also evaluated CloudFlare because it appeared first in Google.
What other advice do I have?
Basic setup is simple but, as with any caching/WAF setup, there are tricks you need to learn. But it works really nice out of the box!
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Consultant at a tech services company with 10,001+ employees
Provides valuable cache control features like cache purging and cache rule propagation. The dashboard is not accessible on occasion.
What is most valuable?
- Extensive cache control like cache purging and cache rule propagation
- Availability features
- Cross-datacenter solution (active and passive environments)
- CDN and DDoS protection with 24/7 support
How has it helped my organization?
Automatic failover between primary and secondary sites enables high availability and accelerates disaster recovery. As soon as it detects that the primary site has gone down, it automatically kick-starts our standby data center.
What needs improvement?
The dashboard is not accessible on occasion. This is probably due to a high load. However, the sites’ protection seems intact.
For how long have I used the solution?
We have been using this solution for four years.
What do I think about the stability of the solution?
There are no stability issues as of now.
What do I think about the scalability of the solution?
There are no scalability issues, but the custom SSL has a terrible price point that puts it out of range for our clients. If they need custom or EV SSL, they are paying significantly more than their overall hosting.
How are customer service and technical support?
The technical support is impressive.
Which solution did I use previously and why did I switch?
We used Akamai previously, but due to full PCI DSS compliance, we needed a proprietary solution for two-factor authentication. We then switched to Incapsula.
How was the initial setup?
The setup was so straightforward. It didn’t require to us to make any major changes.
What's my experience with pricing, setup cost, and licensing?
If you don't have custom SSL, get it!
Which other solutions did I evaluate?
We switched to Incapsula from Akamai.
What other advice do I have?
Imperva has a very impressive core feature set. Imperva has made security analysts scratch their heads. We allow them in from the inside so they can actually hit something worthwhile.
We are very confident in the reports we get from Imperva. Its bot identification has allowed us to plan bandwidth appropriately.
Identification for good bots (people who hit our site using automation, but for good business reasons) has allowed us to work with our customers who use our services in new ways.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Imperva DDoS Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Distributed Denial-of-Service (DDoS) Protection CDN Web Application Firewall (WAF)Popular Comparisons
Cloudflare
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
AWS WAF
F5 Advanced WAF
Fortinet FortiWeb
NetScaler
Arbor DDoS
Akamai
Imperva Web Application Firewall
Akamai App and API Protector
Azure Web Application Firewall
Radware DDoS
Amazon CloudFront
Buyer's Guide
Download our free Imperva DDoS Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- F5 vs. Imperva WAF?
- We are looking at managed DNS providers and want to know what others are using
- Prolexic vs. Arbor Networks: How do they compare?
- Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
- How does a WAF help to protect against DDoS attacks?
- DDoS solutions: Any other solutions to consider aside from Radware DDoS Protection Service and F5 Silverline DDoS Protection?
- Which is the best DDoS solution and why?
- When evaluating DDoS Protection, what aspect do you think is the most important to look for?
- What is the difference between denial of service and distributed denial of service?
- How does BGP routing help to mitigate DDoS attacks?