TrustRadius: an HG Insights company

F5 Big-IP Advanced WAF

Score9.3 out of 10

28 Reviews and Ratings

What is F5 Big-IP Advanced WAF?

F5 Networks offers the Advanced Web Application Firewall (WAF) to provide bot defense, advanced application protection, anti-bot SDK, and other features.

Advanced Web Application Firewall Review

Use Cases and Deployment Scope

It helps us protect everything including our intranet, every company we have on Azure and also even an IBM Power 9AS/400 platform. So we have the left and also a full proxy for the non web application platform.

Pros

  • It provides us with a lot of flexibility for us to move from one data center to another transparently.
  • It provides us with the capabilities of doing VPN and using multifactor authentication and integrating with all the web platforms that we have in the company and Azure. So very flexible.

Cons

  • I believe that I haven't seen a version of F5 that works directly on Azure as a platform as a service as opposed to a VM. I believe that I have to provision the virtual edition on a virtual machine. I manage it as a virtual machine instead of a platform. I would like to see something that is self-provisioning and that I can use directly without having to have a machine that I have to manage and manage resources.

Return on Investment

  • In our case it has been great because the pricing is just right for all the features that we have on the platform and the flexibility. In fact, we acquired another license last year, so that's something that we're interested in. We are currently moving towards the cloud with our ERP systems and eliminating the IBM platform, so we would like to see that F5 virtual option available on Azure.

Usability

Alternatives Considered

Azure Web Application Firewall

F5 Big-IP Advanced Web Application Firewall

Use Cases and Deployment Scope

We are protecting endpoints of our product, we are facing a lot of attacks from crawlers etc. which is really exhausting for our performance.

Pros

  • Checking the signatures
  • Working with malicious addresses
  • Been pretty updated in this world

Cons

  • Ratelimiting
  • Easier whitelisting of things, more recommendations of actions
  • Nothing coming to my mind right now

Return on Investment

  • Its hard to set it across multiple VS as we would like

Usability

Alternatives Considered

F5 BIG-IP

Other Software Used

Cloudflare

Competitors like Barracuda Akamai Cloudflare and Imperva cannot compete with BIG IP WAF

Use Cases and Deployment Scope

We are protecting financial application using BIG IP advanced WAF

Pros

  • BOT Protection
  • Dos Protection
  • Layer 7 Protection
  • Cookie Security
  • Request Evaluation

Cons

  • Data Safe module
  • Via UI customized response page feature should be available for restricting the status codes like 4xx and 5xx
  • Every URI should have a unique Json/Xml profile

Return on Investment

  • Increased revenue due to more number of business vendor applications are deployed without paying any extra cost to F5 and more productivity came out
  • There is no negative impact as of now

Usability

Alternatives Considered

Barracuda Load Balancer ADC, Barracuda Web Application Firewall and Barracuda Application Protection

Other Software Used

CheckPoint, Forcepoint Data Loss Prevention, F5 Distributed Cloud WAF (Web Application Firewall)

The Advance WAF Protect the web apps from future attacks

Use Cases and Deployment Scope

F5 Big-IP Advanced WAF is deployed to protect the web apllications

Pros

  • Protect web applications from advanced thereats
  • Easy intergration with web applications
  • Customization with Irules

Usability

F5 Big-IP Advanced Web Application Firewall Review

Use Cases and Deployment Scope

We have been tasked by the ISO to put a WAF in front of every service line. These include the Universities learning management systems, Splunk, OpenShift, OKD, Jenkins, apache/tomcat environments, etc. The business problem is meeting a new security policy, and having an avenue to immediately put in fixes for any critical security vulnerabilities. We're fairly happy with the frequency of updates to the policy signatures.

Pros

  • Extensive policy signatures
  • Fairly easy to use UI for navigating traffic learning settings
  • Relatively good filtering

Cons

  • The UI for events. E.g., clicking the "Accept" button does nothing.
  • Traffic learning suggestions are often very incorrect. We were originally suggested to use "Automatic" learning, and had to completely scrap the policy due to the suggestions.
  • "All in one" dashboard for viewing application URL/parameter overrides per policy.

Return on Investment

  • We're an educational institution, so it's hard to state ROI.

Usability

Other Software Used

Splunk Enterprise, Red Hat OpenShift, Red Hat Ansible Automation Platform