Global Network and Cyber Security Project Manager at a manufacturing company with 10,001+ employees
Real User
Easy to operate
Pros and Cons
  • "The configurability of the tools and the ease of operation to be the most valuable feature of Imperva."
  • "Imperva Web Application Firewall is very expensive."

What is our primary use case?

We use the latest version with all the functionality, not only WAF. Additionally, we use all the security capability that is possible to enable on Imperva including device security tools like API security.

We use this solution to protect the website for the company.

What is most valuable?

I find the configurability of the tools and the ease of operation to be the most valuable feature of Imperva.

For how long have I used the solution?

I have three years of experience with Imperva Web Application Firewall.

What do I think about the stability of the solution?

This solution is very stable.

Buyer's Guide
Imperva Web Application Firewall
March 2024
Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Scalability is very good.

How are customer service and support?

Imperva's technical support is very good.

Which solution did I use previously and why did I switch?

I used to work with Fortinet Web Application Firewall but it was not good.

How was the initial setup?

The initial setup of Imperva is easy to do and only takes a few minutes to deploy.

What's my experience with pricing, setup cost, and licensing?

Imperva Web Application Firewall is very expensive.

Which other solutions did I evaluate?

I have worked with Azure and find both solutions good. However, Imperva does have more advanced features than Azure.

What other advice do I have?

I am very happy with this solution. I would rate the technical aspect a 10 out of 10, however because of the financial cost, I rate it an 8 out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Security Architect at a individual & family service with 1,001-5,000 employees
Real User
Stable and easy-to-manage solution with good technical support service
Pros and Cons
  • "The solution is scalable."
  • "It is complicated to integrate the solution's on-cloud version with other platforms."

What needs improvement?

It is complicated to integrate the solution's on-cloud version with other platforms. 

For how long have I used the solution?

I have been using the solution for six years.

What do I think about the stability of the solution?

It is a stable solution.

What do I think about the scalability of the solution?

The solution is scalable. We have 20 applications hosted on its on-premises version and around five applications on mobile infrastructure. A team of three administrators manages the operations.

How are customer service and support?

The solution's technical support is good.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used F5 and Barracuda before. Both solutions are easy to use.

How was the initial setup?

The solution's initial setup is easy and takes two or three days to complete.

What about the implementation team?

We implemented the solution with the help of its reseller.

What other advice do I have?

The solution is stable and easy to manage. I rate it a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Imperva Web Application Firewall
March 2024
Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,740 professionals have used our research since 2012.
Senior Software Developer at a computer software company with 1,001-5,000 employees
Real User
Stable, protects well against a variety of attacks, especially DDoS
Pros and Cons
  • "The solution has been quite stable. I have not seen any bugs at all."
  • "Sometimes our web application firewall will slow down."

What is our primary use case?

We primarily use the solution for database security.

Basically, the solution is a web application firewall that is used to protect against multiple types of attacks online. It is used for web attacks - mostly DDoS attacks, cross-site scripting attacks, or SQL injection attacks. 

There is also multiple HTTP protocol compliance. If there is any violation it will be detected by this application. It is used for detecting an illegal file type, illegal URL, or bots. 

The solution can prevent a geolocation attack also. If any application is not allowed from certain countries, it will not allow access. We can detect everything via the web application firewall. 

What is most valuable?

The solution offers good security against a variety of web attacks.

The protection from DDoS attacks is very useful. The DDoS attack is a very powerful attack that can harm a company's services. If an application is deployed to any web server or database our service will slow and will go down. A user would not be able to access our service until we can fix the issue. It's a deal if a company can avoid getting hit with DDoS attacks and having something that can effectively protect a company is extremely useful.

The solution has been quite stable. I have not seen any bugs at all.

What needs improvement?

Until now, it is good. There are no issues. As an analyst, I simply monitor. I don't really get too far into the technical aspects of the solution.

Occasionally, I've noticed that the web application firewall was down. If we are not using proper storage, proper memory, proper CPU, and if multiple attacks happen at one time, they will be detected by our web application firewall. Sometimes our web application firewall will slow down. In that sense, it needs some improvement. We do have a precaution for if the solution goes down. We basically, need to increase the memory and the storage and the CPU utilization, so that we can prevent our company from malicious activity. 

I cannot say which type of memory or storage should be improved. The requirements depend on the organization. What organizations need and which type of configurations would work best as per their requirements depend completely on that.

For how long have I used the solution?

I've been working with the solution for about three years or so. It's been a while. I've been mostly working with it over the last 12 months or so.

What do I think about the stability of the solution?

The solution is quite stable. There are no bugs or glitches - or at least, I haven't seen any problems on that front. It doesn't crash or freeze. It's reliable.

What do I think about the scalability of the solution?

Right now, it depends on the company and its needs. I can't speak to if there are plans to increase usage.

How are customer service and technical support?

I've never been in touch with technical support. I can't speak to how knowledgeable and responsive they are, having never communicated with them directly. As an analyst, it's not my responsibility to deal with technical issues directly.

Which solution did I use previously and why did I switch?

It's my understanding that this company has only used this solution. However, if I move somewhere else, it's possible that something else may be used.

How was the initial setup?

I wasn't part of the initial setup. I can't speak to how easy or difficult the process was.

What's my experience with pricing, setup cost, and licensing?

I am not sure of the exact licensing costs of the solution. The licensing is a management decision. The costs and payments are handled by them.

What other advice do I have?

We use the solution's latest version.

We have a partnership with Imperva within our company.

I'd rate the solution at a nine out of ten. We've been mostly quite happy with its capabilities.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Sonny Bernard - PeerSpot reviewer
Security Consultant at FPG Technologies and Solutions LTD
Real User
Useful database monitoring, simple dashboards, and scalable
Pros and Cons
  • "The most valuable features of Imperva Web Application Firewall are the monitoring of databases and the dashboards are easy to understand."
  • "Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better."

What is our primary use case?

We are using Imperva Web Application Firewall to monitor databases.

What is most valuable?

The most valuable features of Imperva Web Application Firewall are the monitoring of databases and the dashboards are easy to understand.

What needs improvement?

Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better.

For how long have I used the solution?

I have been using Imperva Web Application Firewall for approximately three months.

What do I think about the stability of the solution?

Imperva Web Application Firewall is stable.

What do I think about the scalability of the solution?

The scalability of the Imperva Web Application Firewall is good.

How was the initial setup?

The initial setup of the Imperva Web Application Firewall is complex.

I rate the initial setup of Imperva Web Application Firewall a four out of five.

What other advice do I have?

I rate Imperva Web Application Firewall a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Claudio Colombo - PeerSpot reviewer
CTO at Sorint.Lab
Reseller
It's easy to use and deploy
Pros and Cons
  • "Imperva is easy to use and deploy. The UI is excellent."
  • "I'd like the option to pick your bot protection."

What is most valuable?

Imperva is easy to use and deploy. The UI is excellent.

What needs improvement?

I'd like the option to pick your bot protection.

For how long have I used the solution?

I have used Imperva for seven years.

What do I think about the stability of the solution?

Imperva is stability.

What do I think about the scalability of the solution?

Imperva is scalable.

How are customer service and support?

Imperva support is good. 

How was the initial setup?

Setting up Imperva is easy, and it takes two days.

What's my experience with pricing, setup cost, and licensing?

The cost is reasonable. W have 50 clients and 10 websites per customer. 

What other advice do I have?

I rate Imperva Web Application Firewall nine out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Akhilesh Mishra - PeerSpot reviewer
Technical Lead at M.Tech
Reseller
Top 5Leaderboard
Useful DDoS protection, good support, and reliable
Pros and Cons
  • "The most valuable features of the Imperva Web Application Firewall are DDoS, malware, and the other malicious threat prevention it provides. Additionally, third-party integration is available. You can forward the log for further analysis."
  • "Imperva Web Application Firewall can improve by providing better features, such as improved prevention of zero-day attacks. Additionally, it should include a VR meta-analysis."

What is our primary use case?

Imperva Web Application Firewall is used for customers who are looking to secure their multiple applications and want to block the threats, such as DDoS and ransomware attacks. Imperva Web Application Firewall delivers three main things, data security, data availability, and access control. For data security, it prevents malware and malicious threats. For the data availability, by preventing threats, such as malware, data can be available each and every time. You are able to have Access control, you have the ability to control the access.

What is most valuable?

The most valuable features of the Imperva Web Application Firewall are DDoS, malware, and the other malicious threat prevention it provides. Additionally, third-party integration is available. You can forward the log for further analysis.

What needs improvement?

Imperva Web Application Firewall can improve by providing better features, such as improved prevention of zero-day attacks. Additionally, it should include a VR meta-analysis.

For how long have I used the solution?

I have been using the Imperva Web Application Firewall for approximately 15 years.

What do I think about the stability of the solution?

Imperva Web Application Firewall is stable, and the performance is good.

What do I think about the scalability of the solution?

The solution is best suited for enterprise-sized businesses. It is a scalable solution.

How are customer service and support?

The Technical support is good from Imperva Web Application Firewall.

Which solution did I use previously and why did I switch?

I have used another solution previously which was good. However, Imperva Web Application Firewall had more features.

How was the initial setup?

The deployment of the Imperva Web Application Firewall is simple. However, it is not very user-friendly. It would be a benefit because the customers would have a better time with the installation.

What about the implementation team?

I did the implementation Imperva Web Application Firewall myself and it took approximately three days.

What's my experience with pricing, setup cost, and licensing?

Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price.

What other advice do I have?

I do the maintenance and upgrades of the solution if it requires it. I would recommend this solution to everyone. 

I rate Imperva Web Application Firewall a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
PeerSpot user
Acquisitions Leader at a healthcare company with 10,001+ employees
Real User
Reliable, and has easy backup and restore functions
Pros and Cons
  • "The most important feature I have found to be the ease in how to do the backup and restores."
  • "The process to upgrade from one version to another can be a lot simpler than it is currently."

What is our primary use case?

We are using this solution for backing up all of our day-to-day use data and the ability to restore it when we want. For example, when there is a catastrophe or disaster.

What is most valuable?

The most important feature I have found to be the ease in how to do the backup and restores.

What needs improvement?

The process to upgrade from one version to another can be a lot simpler than it is currently.

For how long have I used the solution?

I have been using this solution for six years.

What do I think about the stability of the solution?

When it comes to stability the solution work well.

What do I think about the scalability of the solution?

The solution in my experience has been scalable. In my organization we have approximately 10,000 users using the solution, the whole company uses it.

How was the initial setup?

The initial setup was straightforward. We have a team that does the maintenance of the solution.

What's my experience with pricing, setup cost, and licensing?

There is a license for this solution and we purchase the license annually with no additional fees.

What other advice do I have?

My advice is to follow the three, two, one backup rule, this solution is very suitable for this. Make sure you are defining your mean time for recovery of the backup, and try to see that it makes the mean time.

I rate Imperva Web Application Firewall a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
Consultant
Gives me peace of mind, blocks everything we need it to block
Pros and Cons
  • "It has threat intelligence and we are using Incapsula. With threat intelligence, we can separate HTTP and HTTPS traffic. We can use Incapsula to send all the threat intelligence to the WAF."
  • "There could be some limitations that from the converged infrastructure perspective: when you want to converge with everything and you want Imperva to get there easily because it's not a cloud component. For example, when you want to build servers and you're using OneView to manage your software-defined networks, implementing Imperva right away is not that simple. But if you're doing just a simple cloud infrastructure with servers in there, you're good to go. Also, we are not able, with Imperva, to block by signatures. Imperva by itself needs to be complemented with another service to do URL filtering."

What is our primary use case?

Our primary use case is to protect our cloud production environment.

How has it helped my organization?

We have a co-location that we do with our QA and Dev and our pre-production environment. We do everything there. We built it for the production environment so we deploy everything in the cloud. We have the web application firewall in the cloud, after the proxy.

What is most valuable?

It has threat intelligence and we are using Incapsula. With threat intelligence, we can separate HTTP and HTTPS traffic. We can use Incapsula to send all the threat intelligence to the WAF.

The interface is very user-friendly. You get used to it. It's very convenient.

What needs improvement?

There could be some limitations rom the converged infrastructure perspective: when you want to converge with everything and you want Imperva to get there easily, because it's not a cloud component. For example, when you want to build servers and you're using OneView to manage your software-defined networks, implementing Imperva right away is not that simple. But if you're doing just a simple cloud infrastructure with servers in there, you're good to go.

Also, we are not able, with Imperva, to block by signatures. Imperva by itself needs to be complemented with another service to do URL filtering. That's why you need Incapsula.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

No issues with stability. It has never crashed.

What do I think about the scalability of the solution?

Scalability is affordable. There are no issues with the process of scaling.

They have centralized management, in terms of scalability. They have centralized policy control, they have centralized application profile information. On the dashboard they have Signature Update, Monitoring, Reporting. They clearly thought about the large-scale when they made this product.

How are customer service and technical support?

We use a partner here in Puerto Rico for Imperva. We have a guy in our shop every day, full-time.

Which solution did I use previously and why did I switch?

We used Fortigate. We switched because it's not a WAF. When you have a WAF, you want that WAF to do all kinds of configurations, to promote the firewall, to work the way you want it. Imperva came with everything, the whole package.

How was the initial setup?

The initial setup was a little bit complex. But a third-party took care of everything. It's not like putting milk on cereal when you are working with these kinds of configurations. The effectiveness of a web application is going to come from the analysis of what your organization needs. If you don't have that information before you go into Imperva, you're going to have a lot to do when you get there. You need to know what you're doing. It's not something you can take out of the box and put in your infrastructure. It's somewhat hardcore to deal with these kinds of solutions. 

What's my experience with pricing, setup cost, and licensing?

Make sure you understand the way that Imperva charges. It's very affordable. However, I would like to see a package with the Virtual Patching included. You get to do patching separately.

Which other solutions did I evaluate?

We had F5, Akamai, Fortinet, Barracuda. We may have looked at Juniper as well, I don't remember. Not too many companies have a WAF. Not all the firewall companies are WAF makers.

What other advice do I have?

I think it's perfect. It's a very good application. When you do large-scale deployment you want to protect your physical web application with Imperva, trust me. It gives me peace of mind.

These are guys are from Israel and you should see that place. These guys are the best I have ever seen. They do all kinds of stuff and there is nothing that they cannot do. These people are incredible. They can configure and develop anything, customized, if you want it. Everything has a price, but they can do it right now. They don't have a "no."

We use Imperva with Incapsula so we have web security, we have DDoS protection, we have content delivery networking, we have load-balancing. We do everything with Incapsula cloud. For example, if you have an internet threat, that threat is trying to access your web application. Depending on the threat that you are receiving, the activity monitor is going to be triggered. Once that activity monitor gets triggered, the vulnerability management is going to defend you. It doesn't work for everything the same way. It's very intelligent.

Without tuning, it blocked 88 percent of the vulnerabilities, and when we tuned it, it blocked 98 percent. Whatever was not blocked didn't harm us. We use a third-party for tuning. We tell them what to do it and they do it. They get it done fast, sometimes in two to three days. It depends on what you're asking for. If you're asking for more accuracy, they go the distance to solve your problem. For example, the other day I had some keywords, some attack signatures that they were looking at for false-positives and false negatives, which are two different things. One of the main reasons we got Imperva is that we wanted to block attacks while limiting the number of false positives. I wanted the application scanner not to generate false positives by creating violations. I gave them the information, and the next day it was solved.

To put it in a high-level perspective, you are paying to see the things that are important, but you get a lot of noise. I wanted to reduce that noise. They allowed me to do that. 

Make sure you have the right testing methodology for Virtual Patching. If you want to take your patching to under 30 days, this is the product for you. We reduced it to five days. I think we are the only company where the patching is under five days. We are only doing it at the database-level right now. But we took it down to five days. 

There are proper ways to test a WAF, but the main advice I can give you is that you should not just generate attack traffic. The most effective method, for me, would be to generate both attack and legitimate traffic. That kind of approach will give you a way to rate the ability of the WAF to detect malicious traffic and to distinguish malicious traffic from good traffic. Provide real-world testing scenarios, in which the WAF must block attacks and avoid blocking good traffic at the same time. You will be able to measure how many false positives you're getting. That is the best way to test a WAF: Don't only to generate attack traffic.

Another piece of advice, and here I will jump  to the main fears of this environment - SQL injections, cross-site scripting, which I hate, DT's (Directory Traversals) - is that you need to provide another layer here which is IPS. IPS products will all rely on signatures. They are going to be created by the scanner to stop anything, that's just the basics of threat prevention. If these signatures are easy to circumvent, by using comments and encoding at the same time, they will be available for the WAF to stop any kind of session or cookie tampering. What I'm saying is that there should be technical attack protection. You should be thinking not only about WAF but combining WAF and IPS.

You need to find an IPS that works with it. Imperva has something similar to an IPS, it's not an IPS per se. For example, an IPS cannot detect or stop fraud malware. For that, you need to add certain other levels of security and combine it with employee training. If you get the web application, which is called SecureSphere, the WAF, it will protect you against web page fraud because they go by black IPs. So you can help the IPS on that side and the IPS can help you letting you know what to block from the internal network. You should be considering a combination of WAF and IPS.

Another thing to take into consideration for people who are starting, with respect to deploying a WAF, is that they should validate the accuracy of the solution and the ability it has to protect any application and help you with monitoring and management. It's not just technical stuff.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Imperva Web Application Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Buyer's Guide
Download our free Imperva Web Application Firewall Report and get advice and tips from experienced pros sharing their opinions.