F5 Distributed Cloud WAF leverages F5's Advanced WAF technology, delivering WAF-as-a-Service and combining signature- and behavior-based protection for web applications. It acts as an intermediate proxy to inspect application requests and responses to block and mitigate a broad spectrum of risks stemming from the OW ASP Top 10, persistent and coordinated threat campaigns, bots, and layer 7 DoS.
N/A
InterSystems Ensemble (legacy product)
Score 9.5 out of 10
N/A
Ensemble from global company InterSystems was a middleware and application infrastructure offering. It is a legacy product, now replaced by InterSystems IRIS.
It helps our website to manage well during high traffic seasons and Holidays. This plaform manages the website overall performance and also protect it against DDoS attacks during these High demand period. It also protects transactions done on our website for the booking of services and products buying by our customers and keep their data safe.
Layer seven attacks are becoming far more common. Traditionally it was always layered three, layer four, where you get an additional firewall, but with the application layer attacks become more frequent, more popular, et cetera. So having the web application firewall protecting us, and then with the recent Log4j, that's the most recent use case when it gave us that instant level of protection whilst we remediated the Log4j that we had that and the F5 Distributed Cloud WAF was protecting us.
I have a great relationship with the account manager, my account manager, and I think he drives the best price possible, um, for me, and I'm happy with that price.
F5 Distributed Cloud WAF is always innovating and evolving.
We run a very competitive proof value where we run numerous competitors against each other, and then we evaluate from that and then make the selection, and F5 Distributed Cloud WAF was the winner.
Easy to use: The simplicity of its programming language allows fast learning. Visual environment to generate complex code.
Robust: A fall of the system will not be a problem. Never again will information of the transactions in progress be lost. Never more messages lost.
Connect to the world: The most popular connection is possible to implement quickly. FTP, File folder, TCP, SMPT, REST.... all method are ready to use. Only define "where" and "how"
Fail over between devices feels unstable if there are thousands of objects attached to the traffic-group. Needs to be more simpler.
We have seen issues with malicious user detection where we have used open protocols due to legacy applications, and have been caught with legitimate traffic being blocked.
Given that Ensemble and Cache are one of if not the only true fully object orientated database/development technologies for massive transactional data systems its customizability is extensive and it just comes down to the creativity of the developer to get the products to pretty much do whatever they want to do with it. However, this is not necessarily obvious to newcomers to the technology.
The developer community could do with greater participation from the software developers/application specialists and engineers within InterSystems.
More extensive documentation and greater access to proven working solutions particularly in the realm of some of the lesser known or new and upcoming technologies.
We gave it an 8 because it protects our web apps well and is reliable. The WAF is flexible and meets most of our needs. It could improve in user interface and make integrations easier, but overall, it’s a solid and effective security tool for us.
I believe is a solution that was designed from the start to be simple and easy to use. Coming from Imperva, it simply eased the burden and complexity of managing and securing our apps on different environments (cloud and on-prem). It easy to scale and very quick to deploy (as a cloud waf should be), provide us with DevOps integrations, visibility and automatic insights from multiple events that guarantee peace of mind for us analysts and opp managers.
I have yet to raise an issue with InterSystems WRC that they have been unable to resolve to my satisfaction in the 20+ years that I have worked with their products.
It provides fewer false positives and a more granular approach to eliminating them, allowing us to focus on threats. Also, with the need to secure both on-premise and cloud-based web applications, we can only use Azure on the cloud part, but we still need to cover on-premise apps with WAF, so we would need to double the time to deploy and manage. Also, its flexibility of deployment scenarios offers us a faster time to deploy WAF without adjusting the app delivery process to WAF's existence.
Mirth is another integration platform that we have used but its development, in Java, made us always create new methods every time a new product was integrated. Every connection process had to be developed from the beginning and it was not easy to reuse code. Nor did it allow us to have an extensive catalog of HL7 messaging, having to perform the validation of each and every one of its fields manually.
The biggest gain for us was speed. Before F5 Distributed Cloud WAF, onboarding a new app to our WAF stack meant manual rule tuning, traffic sampling and regression testing. Right now, we spin up a service, tag it with the right policy and its ready (production ready) within hours
We have integrated 5 laboratories in a treatment monitoring system in less than a month of development. Being able to integrate the following in a period no longer than a week.