NGINX, a business unit of F5 Networks, powers over 65% of the world's busiest websites and web applications. NGINX started out as an open source web server and reverse proxy, built to be faster and more efficient than Apache. Over the years, NGINX has built a suite of infrastructure software products o tackle some of the biggest challenges in managing high-transaction applications. NGINX offers a suite of products to form the core of what organizations need to create…
N/A
Oracle Dyn WAF
Score 9.0 out of 10
N/A
Oracle Dyn Web Application Security Platform extends beyond just typical Web Application Firewall (WAF) capabilities to offer Access Control, Bot Management, application DDoS protection and API security.
All of those are paid solutions with very good features, but they also offer dedicated scenarios for web application hosting. If you run applications on on-premises web servers and don't have a Microsoft licence agreement, Nginx is a very good and reliable option, based on …
In our organization, we use different solutions depending on if the database is on premise or in the cloud. We went from multiple solutions across different departments towards a more consolidated model to achieve standardization and economies of scale. We’ve mainly moved …
How does it compare? We use Apache ATP server and we also use Tom Cat also owned by Apache, but both Apache, ATP, and MKA. They are relatively older than GX and so they're one problem for Apache and MKA they need more power, more memory, and more space.
NGINX have higher market share which obviously show to us it is the preferred choice of most of the customers. Both of platform competes in the Web and Application server areas, but due the security features of NGINX be more flexible this in my opinion makes more sense.
Apache is a market leader but NGINX is new and has new features. Lightweight and can handle static requests. We use EC2 and I believe NGINX is more suited when it comes to scalability.
After a long period of cyber security research and close encounters with distributed denial of service attacks, I chose to deploy Oracle Dyn Web Application Security Platform to safeguard our apps. Oracle Dyn provides my company with the security it needs for its important …
I have not used any other similar products to date, although I'm not sure what other use cases they could cover, I would be interested to try them out.
I already put this in earlier, but to repeat - they were easier to work with, more technically capable and knowledgeable and not just trying to sell us on something. Their willingness to solve for our problems and work with us made them the clear winner.
After several years involved with the issue of cyber security and having been very close with distributed denial of service attacks, having used several companies to protect our applications, I decided to opt for Oracle Dyn Web Application Security Platform. Definitely, Oracle …
At the time we chose Zenedge, Dyn WAF was the clear leader. AWS WAF is almost 100% manual with no preset rules. Akamai and CloudFlare both excelled in CDN and Anti-DDoS services, but not in WAF services. Since that time, however, several competitors have appeared as well as …
[NGINX] is very well suited for high performance. I have seen it used on servers with 1k current connections with no issues. Despite seeing it used in many environments I've never seen software developers use it over apache, express, IIS in local dev environments so it may be more difficult to setup. I've also seen it used to load balance again without issues.
Dyn WAF is a good product, don't get me wrong. Zenedge was constantly improving the product, adding new features on a regular basis. It works very well for dynamic websites, helping weed out SQL Injection, XSS, XSRF, and other attacks. We have also used this product to protect REST API endpoints. Again, the product works very well to repel attacks.
Straight-forward configuration format that users of all skill levels can learn, and yet is powerful enough for the huge breadth of features that Nginx provides.
Massive scale right out the box. We've never had a Nginx instance overwhelmed by requests, and if we did it would be trivial to spin up more Nginx instances to handle the load.
SSL termination means that we can deliver content over HTTPS without needing our individual services to require TLS support. This saves us a lot of time and headache while keeping us secure.
Nginx is open-source and free, meaning that anyone can use it to power their services, from individual projects to billion-dollar websites.
With Oracle Dyn Web Application Security Platform we have a complete dashboard (dojo) to manage, configure, visualize, all the features and functionalities of the platform in a very simple and friendly way.
Oracle Dyn Web Application Security Platform support is something out of the ordinary. Oracle engineers are available 24/7, every day. There is no requirement that can not be satisfactorily addressed by them. The response time, by different ways, is almost instantaneous.
It is very easy to communicate with any Oracle official to discuss any topic.
Despite being a service with all the features to provide 100% protection, my experience is that the cost of Oracle Dyn Web Application Security Platform is worth it.
Customer support can be strangely condescending, perhaps it's a language issue?
I find it a little weird how the release versions used for Nginx+ aren't the same as for open source version. It can be very confusing to determine the cross-compatibility of modules, etc., because of this.
It seems like some (most?) modules on their own site are ancient and no longer supported, so their documentation in this area needs work.
It's difficult to navigate between nginx.com commercial site and customer support. They need to be integrated together.
I'd love to see more work done on nginx+ monitoring without requiring logging every request. I understand that many statistics can only be derived from logs, but plenty should work without that. Logging is not an option in many environments.
This tool is really easy to use and configure. Consumes very less system resources. It is highly modular and configurable. You can easily use it with other tools like certbot for SSLs. You can configure basic security with configuration and headers
Community support is great, and they've also had a presence at conferences. Overall, there is no shortage of documentation and community support. We're currently using it to serve up some WordPress sites, and configuring NGINX for this purpose is well documented.
All of those are paid solutions with very good features, but they also offer dedicated scenarios for web application hosting. If you run applications on on-premises web servers and don't have a Microsoft licence agreement, Nginx is a very good and reliable option, based on Linux distributions and available as freeware.
I already put this in earlier, but to repeat - they were easier to work with, more technically capable and knowledgeable and not just trying to sell us on something. Their willingness to solve for our problems and work with us made them the clear winner.
Our websites are noticeably faster, causing an increase in customer satisfaction.
Nginx has such a low memory/resource footprint that we save money from not needing multiple large, expensive servers.
Ability to load balance traffic, have server-redundancy, and have high-availability allows for 100% uptime and provides cost-effective solutions to alternatives that can cost a lot.