Manager, IS Security & Infrastructure at Fintech Kenya Limited
Real User
User-friendly with good performance and helps to secure digital assets
Pros and Cons
  • "It mitigates all of the availabilities of risks around web applications."
  • "Their portal is very limited and needs improvement."

What is our primary use case?

We are a reseller and integration partner, and we have customers who are using this solution in on-premises deployments.

How has it helped my organization?

This solution has helped in securing our clients' assets, which is key. It mitigates all of the availabilities of risks around web applications.

What is most valuable?

The most valuable feature of this solution is web application security.

This is a user-friendly solution.

This solution has good performance ratings.

What needs improvement?

I would like to see more support available for this product online. Some customers find this to be a real limitation.

The virtual processing could be improved.

Their portal is very limited and needs improvement.

Buyer's Guide
Imperva Web Application Firewall
March 2024
Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
769,334 professionals have used our research since 2012.

For how long have I used the solution?

We have been using this solution for close to five years.

What do I think about the stability of the solution?

This is a very stable solution.

What do I think about the scalability of the solution?

The solution is very scalable, but of course, the scalability comes with a cost.

How are customer service and support?

I think that technical support needs to be improved by making it more localized, or regionalized. Our support is currently coming from the US, and it is not very good. They need to take care of their global customers.

Which solution did I use previously and why did I switch?

We previously used Fortinet, but this solution has better performance ratings.

How was the initial setup?

I don't want to say that the initial setup is straightforward, but it is manageable. It requires a bit of technical knowledge.

What other advice do I have?

This is a solution that I highly recommend.

The biggest lesson that I have learned from this solution is that Imperva is not a one-house solution. They create a specialized solution, and that comes with a lot of value.

I would rate this solution a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Systems Analyst at a financial services firm with 501-1,000 employees
Real User
Top 20
An expensive solution that is scalable and stable
Pros and Cons
  • "Imperva Web Application Firewall is stable."
  • "The tool needs to improve CPU and storage memory."

What needs improvement?

The tool needs to improve CPU and storage memory. 

For how long have I used the solution?

I have been using the solution for a year. However, my company has been using it for six years. 

What do I think about the stability of the solution?

Imperva Web Application Firewall is stable. 

What do I think about the scalability of the solution?

The product is scalable, and my company has 20,000 users. One administrator manages the tool. 

What's my experience with pricing, setup cost, and licensing?

Imperva Web Application Firewall is expensive. 

What other advice do I have?

I rate the solution a nine out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
Imperva Web Application Firewall
March 2024
Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
769,334 professionals have used our research since 2012.
Technical Account Manager at a tech services company with 201-500 employees
Reseller
Easy to deploy with good cost savings and great scaling potential
Pros and Cons
  • "The solution is stable."
  • "I loved the approach of the cloud. The cloud has a lot of new features, like advanced web protection and DDoS protection. If those could also be on-boarded onto the on-prem versions, that would be ideal. They need to pay attention to both deployment options and not just favor one."

What is most valuable?

The product is very good. 

It's so easy to do the deployment. The installation is very straightforward. You can't even compare it to others on the market. It's that easy.

The features on offer are very nice.

The solution is stable.

The licensing setup makes the product easy to scale. 

The pricing is very good. 

What needs improvement?

I loved the approach of the cloud. The cloud has a lot of new features, like advanced web protection and DDoS protection. If those could also be on-boarded onto the on-prem versions, that would be ideal. They need to pay attention to both deployment options and not just favor one. 



For how long have I used the solution?

I've been using the solution for the last five years. I've used it for quite a while now. 

What do I think about the stability of the solution?

The stability of the product is good. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.

What do I think about the scalability of the solution?

We typically deal with medium-sized organizations.

The licensing model makes the solution very simple to scale. If a company wants to expand, it's not a problem.

How are customer service and technical support?

We need an improvement in the support. We need a lot of turnarounds. Whenever is a ticket open, it's something that has become a concern. 

Which solution did I use previously and why did I switch?

I'm not currently working with any other solution. I just use this product. 

Previously, I did work with F5 and Fortinet. However, Imperva is superior to both of these products.

How was the initial setup?

The initial setup is easy and the solution is very simple to deploy.

What's my experience with pricing, setup cost, and licensing?

The solution is very affordable and the cloud is making it even easier in terms of cost savings. 

What other advice do I have?

We are resellers and we are based in Kenya. We're actually doing the whole suite. I'm working with Database Security and I'm also doing the Web Application Firewall, both of which are on-prem and on the cloud. I'm also doing the DRA.

It's the best in breed in terms of a solution you can put in place.

I'd rate the solution at an nine out of ten. We're quite happy with its overall capabilities. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Manager at a tech services company with 1,001-5,000 employees
Real User
Top 20
An easy-to-use solution that integrates seamlessly to block OWSAP attacks
Pros and Cons
  • "The solution integrates seamlessly with other tools and has a good alert mechanism."
  • "The solution works for particular zones but isn't always the best solution for all zones."

What is our primary use case?

The solution is used to detect and block application attacks on the internet perimeter. We integrate the solution with SOAR and Phantom to automate our playbook and block URLs.

How has it helped my organization?

The solution reduces the risk of attacks and that benefits our clients. 

What is most valuable?

The solution integrates seamlessly with other tools and has a good alert mechanism. 

The solution provides good protection against OWASP top-ten attacks.

What needs improvement?

The solution works for particular zones but isn't always the best solution for all zones. 

The solution's pricing could be improved. 

For how long have I used the solution?

I have been using the solution for five years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

We implemented the SA solution and have not tried to scale it beyond our client's 10,000 users. 

How are customer service and support?

I do not have experience with escalating issues because our internal support team handles vendor support. 

Which solution did I use previously and why did I switch?

We have not switched solutions but prefer this solution for on-premises. When we need a tool that is cloud-based, we prefer other solutions. 

How was the initial setup?

The initial setup was not complex and integration was easy. 

What about the implementation team?

The solution was implemented by the supplier. 

What's my experience with pricing, setup cost, and licensing?

The solution's pricing is an issue. 

Which other solutions did I evaluate?

We use many tools for the application layer including Imperva, Infoblox Secure DNS, and Palo Alto. 

What other advice do I have?

The solution is a leader in the market and is easy to use.

I rate the solution a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
GA Consultant Cyber Security at a tech services company with 51-200 employees
Real User
Suits large enterprises, supports different application sources, and provides tight control
Pros and Cons
  • "Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva."
  • "It should be more user-friendly. Like other web solutions, it would be helpful to be able to easily do policy configuration and identification inside the application. Understanding the in-depth configuration of a policy is somewhat difficult for an engineer, and they can improve that."

What is our primary use case?

We have an Akamai cloud-based solution for it. We have an in-house customer, and they have their own Akamai cloud for WAF. As a solution provider, we are working with their private Akamai WAF. 

What is most valuable?

Configuration for different application sources is most valuable. We can segregate the traffic that an application is carrying and identify the sizing in Imperva.

It is quite proficient in terms of logs reports, and it provides tight control for policy configuration. So, there can't be any unwanted applications on the internal LAN site. It is quite restrictive, which is a plus point. The sizing of an application is quite easy to understand while we are configuring and deploying Imperva.

What needs improvement?

It should be more user-friendly. Like other web solutions, it would be helpful to be able to easily do policy configuration and identification inside the application. Understanding the in-depth configuration of a policy is somewhat difficult for an engineer, and they can improve that. 

For how long have I used the solution?

I have about two to three years of experience with Imperva. I'm working as a GA consultant for cybersecurity and information security. I'm working on different security solutions such as WAF, IAM, DDoS, Azure firewall proxy, and antivirus. I work with different customers, and I also do the architecture review or assessment.

What do I think about the stability of the solution?

Its stability is quite good. It is not at all an issue. 

It is also quite good performance-wise. We are confident about its performance.

What do I think about the scalability of the solution?

It is for large-scale enterprises where the traffic is huge, and there are many internet-facing applications, which is a plus point of Imperva.

We don't have the HA mode for the respective solution in Imperva, which has to be there when we have the DC and DR locations. We can activate only one solution at DC, but while we are conducting the drills between DC and DR, it is quite difficult to import all the configurations at the DR location in Imperva. It takes time.

How are customer service and support?

Their support is good. It is not an issue. Whenever we have any questions or concerns, we're getting an appropriate solution for our queries. 

Some of the clients have had direct support from Imperva, and some of the clients had a third-party vendor. We also get support from a local Imperva employee. When I was working for a bank, there was good support from this person who was working with Imperva. 

How was the initial setup?

The support for the setup is very good from the provider, but it can be difficult for an engineer to have an in-depth understanding of the configuration of a policy for an application.

What other advice do I have?

I would rate it an eight out of 10.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
PeerSpot user
Sr. Consultant at a tech services company with 51-200 employees
Consultant
Scan policies allow us to group multiple targets and standardize our database scanning. Technical support is probably the biggest drawback.

What is most valuable?

The most valuable feature is the grouping of multiple targets via the scan policy. It is valuable because of the large number of targets and governmental requirements to conduct periodic scans.

How has it helped my organization?

With acquisition of a license to use the product, we received the ability to standardize database scanning and data protection across the enterprise around one product.

What needs improvement?

Many features are buried under not-straight-forward options and, at times, hard to find screens. Very few import features have clearly defined format requirements. Agent installation for data usage/blocking activities on target boxes requires the involvement of OS admins and DBA’s, which complicates coordination of installation and delays implementation. The discovery feature does not accurately discover the instances and instead identifies auxiliary end points (SQL – 1434) and TCP listeners (Oracle – 1521).

For how long have I used the solution?

I’ve used and administered Imperva SecureSphere for 2 years.

What do I think about the stability of the solution?

Periodically, the site stops functioning and the appliance requires a reboot to restore functionality.

What do I think about the scalability of the solution?

Scalability capabilities are well thought through by product development. Installation of additional MX servers and gateways on remote networks ensures coverage of scanning and data usage monitoring/data protection capabilities.

How are customer service and technical support?

Technical support is probably the biggest drawback. No contact with technical support ever results in an immediate response and the solution is usually preceded with series of emails, going on for up to a week, before a live person gets on the phone. But, even then, their task is to observe the manifestation of the problem and request a collection of additional information (logs, traces, etc.) without any attempt to solve the problem during the call/WebEx session. Their technical support staff has at most two or three engineers that have a good working knowledge of the product, but most of the time, a level one technician is running the case. When support staff finally gets on the phone, their first statement is a disclaimer that they are on the call ONLY to collect information and that the customer should not expect any resolution.

This pattern of providing technical support greatly differs from what IBM offers for their Guardium product (competitor solution).

Which solution did I use previously and why did I switch?

We attempted to use several previous solutions. One was Tenable SecurityCenter with its custom, XML-like scripting where each check had to be written by the Database Security Specialist (myself). We also attempted to use AppDetectivePRO, though its performance, lack of customization, scalability, and licensing costs prevented us from continuing with it.

How was the initial setup?

The setup is very straightforward considering that it’s either a physical or virtual (OVF template) appliance. The wizard-like initial setup and configuration are somewhat awkward, but can be completed after reviewing the instructional videos available to the customers.

What's my experience with pricing, setup cost, and licensing?

Licensing should be chosen based on the current infrastructure setup and growth plans. Purchasing appliances of different types may lead to unnecessary/unjustified expenditures and ultimately lead to complications in administration.

Which other solutions did I evaluate?

The product that was evaluated and was chosen as the recommendation was IBM Guardium. Unfortunately, its licensing cost was a lot higher. Therefore, the management decided not to proceed with the purchase.

What other advice do I have?

Be prepared to obtain every piece of documentation that comes with the product. Thoroughly research it to obtain a clear understanding of how to implement the product and ensure you have a dedicated Imperva first-response engineer that can answer your questions without going through a normal support channel. Be patient when encountering a bug or a feature failure, as well as discrepancies between the product interface and/or behavior with the accompanied documentation. Their support is not prepared to jump in and start working on a fix or update the documentation.

In many cases, the documentation remains outdated referring to old releases regardless how long you’ve been asking for an update. Their instructional videos are also out of date, but references to them are consistently sent by their support whenever you may have a question. And finally, thoroughly document your deployment and license-related information, because every email to technical support is responded with an automated reply requesting this information. Not replying to this automated email with correct info will lead to further delays.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
it_user577338 - PeerSpot reviewer
it_user577338Sr. Consultant at a tech services company with 51-200 employees
Consultant

A much more mature product in this regard is BeyondInsight. Highly customizable and flexible when it comes to scanning.

Senior Presales Engineer at a tech services company with 11-50 employees
Real User
Top 5
A cloud-based solution for traffic inspection that offers good up-time
Pros and Cons
  • "The solution is cloud-based and offers us good uptime. It has combined web and API security. Therefore, with one license, you access both application security and also API security."
  • "I would like to improve the tool's turnaround time in terms of support."

What is our primary use case?

We use the solution for traffic inspection. 

What is most valuable?

The solution is cloud-based and offers us good uptime. It has combined web and API security. Therefore, with one license, you access both application security and also API security.

What needs improvement?

I would like to improve the tool's turnaround time in terms of support. 

For how long have I used the solution?

I have been working with the solution for three years. 

What do I think about the stability of the solution?

I have never had any issues on stability. 

What do I think about the scalability of the solution?

The tool is scalable. 

How was the initial setup?

The solution's setup is straightforward. 

What's my experience with pricing, setup cost, and licensing?

The tool is expensive. 

What other advice do I have?

I would rate the solution a nine out of ten. The solution is very mature and covers everything for its use cases. 

Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
PeerSpot user
Specialist Engineer at Entel Networks S.A
Reseller
Valuable compliance features and has good stability
Pros and Cons
  • "The compliance is the most valuable aspect."
  • "It's a complicated tool to keep."

What is our primary use case?

The primary use was to cover the database. Imperva we recognized on the market as the best solution for techs on databases. The banks here in Chile always ask for these types of solutions.

What is most valuable?

The compliance is the most valuable aspect.

What needs improvement?

I just need it to be a stable and normal version. I'd want to hear about the new features to see which I would need.

For how long have I used the solution?

I've been using the solution for 2 years.

What do I think about the stability of the solution?

I find this solution stable. We have 2,000 users in financial services.

What do I think about the scalability of the solution?

The solution is scalable.

How was the initial setup?

The setup initially was simple, but when we tried to run it we had problems with the log parameters and it was complicated to use. The operation was complicated to use, but that is just the experience of my team. It took two months to deploy. The setup and installation of the technologies took one week, and after that, one month to set up the parameters and after that, in order to set up the logs, it took about two weeks. So two months total. We have three engineers, including an architect and a security engineer. We also had a fourth engineer that knew the application.

What's my experience with pricing, setup cost, and licensing?

We have a yearly license, but I'm unsure of the pricing.

Which other solutions did I evaluate?

We didn't evaluate other options, just Imperva.

What other advice do I have?

I would rate the solution as an 8 out of 10, simply because of the difficulty of operation management. It's a complicated tool to keep.

Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
PeerSpot user
Buyer's Guide
Download our free Imperva Web Application Firewall Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2024
Buyer's Guide
Download our free Imperva Web Application Firewall Report and get advice and tips from experienced pros sharing their opinions.