F5 BIG-IP software from Seattle-based F5 Networks is a load balancing and application protection solution suite available on cloud or via virtual editions, on a subscription or perpetual licensing basis.
N/A
Imperva Web Application Firewall (WAF)
Score 8.4 out of 10
N/A
The Imperva Web Application Firewall (WAF) is based on technology acquired with Incapsula and the former WebSphere WAF.
Porque nos es agnóstico a la tecnología implementada, de esta manera podemos evaluar en un futuro adquirir nuevas tecnologías y no depender de un solo vendor para implementar distintas necesidades que puedan surgir a futuro. Por lo tanto, se puede decir que los productos de F5 …
There's other, Kemp is one for that would be where we see the gap, where they do better in the mid-market space and then a 10 in the larger accounts. Those are probably the two that come to mind the most.
That's the one thing that really stood out. It was a lot easier to use from an administrator standpoint, so I think that's the one thing that really made our team decide to go with this product versus another competitor. Just ease of use.
Works really well. Like I was saying with the ease of use and I mean it's great hardware really fast, we've had zero issues with that, so it's been good
As I said previously, the F5 BIG-IP products are far and away the easiest, most robust and powerful application delivery platform I've ever worked on. The user experience was really the most noteworthy difference when using other products. The Kemp Load master platform was …
Ultimately, it was the easiest to work with that was still a "known" company (we've been burned too many times by up-and-comers). We needed something that gave us a lot of control but then didn't need its handheld on a daily basis. Imperva gives us a lot of that and we are …
Definitely in larger environments, more mature organizations that obviously have the budget to spend and want best in class. Where it struggles is those organizations that don't have the funding and money to spend on it and need more basic functionality. So I'd say that's smaller customers we've worked with and kind of mid-market. They tend to get scared when they get the quotes. Also we've had some struggles with account team consistency. So for the sales team, just a lot of turnover and a lot of missteps on customer calls.
If you are looking for a cheap product to meet the bare minimum requirements for PCI or any other compliance regulations, this is not the product. Also, the WAF portion only inspects on HTTP/HTTPS traffic which can be very limiting into other forms of web apps that utilize other protocols. The HTTP/HTTPS inspection that it does do is very in depth and well worth the investment.
The great thing is the IP address management that's happening. When you set up the network it's very easy and you don't have to keep on configuring everything together. Again, it's very streamlined and it's one of the biggest players there in the market for this work.
Alert Aggregation - Correlates different violations into perceived correlated attacks.
Ease of deployment - as one of the only WAFs that allow bridge mode deployment, this can be deployed with without downtime and no Network Architecture modifications. If the need for proxy is required at a later time, Transparent Reverse Proxy can be deployed within seconds and minimal configuration.
Custom Policies - Custom security policies are easy to configure.
Reporting - There are a good amount of pre-configured reports available by default.
Well, not necessarily the features. I find that we have to change our processes in order to kind of match what F5 BIG-IP does. And it's not a bad thing, it's just that a lot of my engineers want to do it their way, not they F5 BIG-IP way.
It's not difficult to understand the parts of application configurations and features. Setting up new virtual servers with multiple profiles, certificates, and nodes is easy for new users through the web interface, which also translates to programability in scripts, DevOps, or other configuration management use-cases. Users from different backgrounds such as networking and infrastructure can use F5 BIG-IP, while users who are familiar with API calls can easily configure objects without needing to understand the platform at all.
There are just a couple of points that are hard to find, that probably could be elsewhere. But these are minor; everything else is right where you'd expect it to be.
On the occasions when we've had to engage f5 support, they have been great. They have always resolved our issues quickly and been easy to work with and professional. The reason I give them a 10 out of 10, however, is because when we've had issues that have crossed over between the f5 BIG-IP, our Cisco switches, and our Microsoft IIS server the f5 support representatives have been extremely knowledgeable about every product and device involved and have been able to troubleshoot end-to-end without having to engage other vendors.
We haven't needed support from Imperva since implementation. But during that time, their personnel were very quick to respond to questions. Since then, it's been largely doing its thing for us (which is exactly what we'd hoped).
Ultimately, it was the easiest to work with that was still a "known" company (we've been burned too many times by up-and-comers). We needed something that gave us a lot of control but then didn't need its handheld on a daily basis. Imperva gives us a lot of that and we are still able to navigate it with ease.
I would say from a security perspective, because I manage security, availability is sort of the key area for us and making sure that is properly handled through BIG-IP, that is the biggest business success, I would say from the product perspective.