TrustRadius: an HG Insights company

HAProxy Community Edition vs. Imperva Web Application Firewall (WAF)

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    HAProxy Community Edition

    Score9.3 out of 10
    N/AHAProxy Community Edition is a free, open source reverse-proxy offering high availability, load balancing, and proxying for TCP and HTTP-based applications. It is presented as suited for very high traffic web sites.

    $0

    Imperva Web Application Firewall (WAF)

    Score8.7 out of 10
    N/AThe Imperva Web Application Firewall (WAF) is based on technology acquired with Incapsula and the former WebSphere WAF.N/A
    Pricing
    HAProxy Community EditionImperva Web Application Firewall (WAF)
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    HAProxy Community EditionImperva Web Application Firewall (WAF)
    Free Trial
    NoNo
    Free/Freemium Version
    YesNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details——
    More Pricing Information
    Best Alternatives
    HAProxy Community EditionImperva Web Application Firewall (WAF)
    Small Businesses
    No answers on this topic
    No answers on this topic
    Medium-sized Companies
    F5 BIG-IP
    Score9.2 out of 10
    F5 Big-IP Advanced WAF
    Score9.4 out of 10
    Enterprises
    F5 BIG-IP
    Score9.2 out of 10
    F5 Big-IP Advanced WAF
    Score9.4 out of 10
    All AlternativesView all alternativesView all alternatives
    User Ratings
    HAProxy Community EditionImperva Web Application Firewall (WAF)
    Likelihood to Recommend
    9.0
    (7 ratings)
    9.5
    (4 ratings)
    Usability
    9.1
    (2 ratings)
    9.5
    (3 ratings)
    Support Rating
    9.7
    (2 ratings)
    9.1
    (1 ratings)
    User Testimonials
    HAProxy Community EditionImperva Web Application Firewall (WAF)
    Likelihood to Recommend
    Open Source
    It prevents a single server failure from being a downtime event by adding redundancy to every layer of your architecture. A load balancer facilitates redundancy for the backend layer (web/app servers), but for a true high availability setup, you need to have redundant load balancers as well. So it is well suited for all production related servers and less suited for individual servers that do not require redundancy.
    Incentivized
    Read full review
    Imperva, a Thales company
    I recommend Imperva specially if you have a big environment with thousand of websites because of its ease to use and availability. Imperva delivers a reliable solution with great capability to contain cyber attacks and even fraud preventions in some cases. The only scenario it's less appropriate is if your focus is anti fraud instead of a solution to block cyber attacks.
    Incentivized
    Read full review
    Pros
    Open Source
    • Low-Cost Load Balancer
    • Intelligent Request Routing based on URL and/or URI
    • Extremely flexible load balancing and healthchecks, can do almost anything including HTTP, HTTPS, PostgreSQL, etc.
    • SSL Termination
    Incentivized
    Read full review
    Imperva, a Thales company
    • Block some dynamic attacks such as SQL injection.
    • Block unfriendly accesses based on geographic source.
    • Helps us implement SSL in cases where the original server can't (yet).
    Read full review
    Cons
    Open Source
    • A few, rare times each year, HAProxy CPU utilization spikes to 100% and server has to be rebooted - this may be related to HAProxy OR it could be an external factor causing this.
    Incentivized
    Read full review
    Imperva, a Thales company
    • Attack Correlation Validation - This specific policy produces a lot of false positives as well as the SQL injection policies. Of course it is difficult to tell what a legitimate query is on a public facing web app.
    • Profiling - I tend to spend more time than any other feature tuning the Web App Profiles. Plugins are used to help cope with this, but on extremely large web apps we are forced to turn off the profiling feature.
    Incentivized
    Read full review
    Usability
    Open Source
    It is very easy to use. I was able to find a lot of documents for it on the internet. Very good community support. There are lots of examples available to try. We mostly use a command-line user interface to interact with it. The CLI is also super easy to use and very easy to interact with
    Incentivized
    Read full review
    Imperva, a Thales company
    It's easy and works great. The onboarding process, although easy, can sometimes take too long for SSL and domain validation, but its not a big deal.
    Incentivized
    Read full review
    Support Rating
    Open Source
    We haven't used customer support. We mostly used the community version. We build a multi-node HAProxy cluster with HA to the proxy itself using opensource plugins available. With the support available on the internet and the documents available we don't need to use much customer support.
    Incentivized
    Read full review
    Imperva, a Thales company
    We haven't needed support from Imperva since implementation. But during that time, their personnel were very quick to respond to questions. Since then, it's been largely doing its thing for us (which is exactly what we'd hoped).
    Read full review
    Alternatives Considered
    Open Source
    We chose HA Proxy because it is cheaper than a hardware balancer, it is an open-source solution with a large community behind it and with constant updates. It also allows custom scripts according to needs.HA Proxy is a solution used in many internet sites like GitHub, Reddit, Twitter, and Tuenti.
    Incentivized
    Read full review
    Imperva, a Thales company
    I believe there's no comparison as Imperva is a much more reliable and powerfull WAF. AWS WAF lacks of several features Imperva have and is not that simple to configure neither have a clean web console. I consider Imperva WAF a whole superior level of cyber security solution and it's consider to be one of the leader in this segment.
    Incentivized
    Read full review
    Return on Investment
    Open Source
    • Significantly lower investment vs competitors. In the case of F5s we have Virtual Editions so we're paying for the hardware to run it on top of the several thousand dollar licenses that are required for each pair and we currently have a pair of F5s per client so there's a huge potential for cost savings there.
    • Requires our network engineers to learn a new skill or our Systems engineers to take on the responsibility of managing the load balancers. It's not a huge difference either way, but it does impact the way we have done business in the past.
    Incentivized
    Read full review
    Imperva, a Thales company
    • Meet compliance requirements - Check.
    • Better Insight into web application - Absolutely great, checks all the traffic against RFC standards and will alert on common development mistakes that duplicate application traffic or provide attack vectors for potential attackers.
    • Have had several issues blocking a customer without producing alerts, while it happened only one week out of 2 years of working with the devices, it did produce a lot of headaches.
    Incentivized
    Read full review
    ScreenShots