F5 Distributed Cloud WAF (Web Application Firewall) Review Insights

Score9.2 out of 10

284 Reviews and Ratings

Learn More

Contact about F5 Distributed Cloud WAF (Web Application Firewall)

Please fill out the form below to get in touch.

F5

Connect with F5

What are you interested in?

Already have an account?

You hereby consent to have TrustRadius share the information supplied on this form with F5 so that F5 and TrustRadius may contact you in regard to the information requested.

Back to Reviews

Insights from F5 Distributed Cloud WAF (Web Application Firewall) Reviewers

Based on 39 verified reviews published in the last 18 months

What other products like F5 Distributed Cloud WAF (Web Application Firewall) have you used or evaluated?

39 answered

Reviewers evaluating or using F5 Distributed Cloud WAF frequently mention a range of other security and application delivery products. Akamai products were the most commonly cited alternatives or complementary solutions, appearing in 18% of reviews. These often included Akamai's WAF, CDN, and bot management offerings. Other significant competitors or related technologies mentioned by reviewers include Imperva products, cited by 10% of the sample, and other F5 solutions, also mentioned by 10% of reviewers. The broader category of Web Application Firewalls, encompassing various vendors and services, was also noted by 10% of the reviewers, indicating a diverse competitive landscape. Cloudflare, another prominent content delivery network and security provider, was mentioned by 5% of the reviewers in conjunction with their evaluations. This suggests that organizations often consider a portfolio of security and delivery solutions, with several key players frequently appearing in their assessments.

Akamai Products

7 mentions

Reviewers frequently cite Akamai's suite of products as alternatives or complementary solutions to F5 Distributed Cloud…

Reviewers frequently cite Akamai's suite of products as alternatives or complementary solutions to F5 Distributed Cloud WAF, with 18% of the sample mentioning them. Specific Akamai offerings like App & API Protector, CDN, Bot Manager, and Prolexic were commonly referenced, indicating a broad consideration of Akamai's security and delivery portfolio in similar use cases.

Imperva Products

4 mentions

Imperva's application security offerings, particularly their Application Firewall, are noted by 10% of reviewers as pro…

Imperva's application security offerings, particularly their Application Firewall, are noted by 10% of reviewers as products used or evaluated alongside F5 Distributed Cloud WAF. This suggests Imperva is a recognized competitor in the web application firewall space, often considered in parallel with other leading solutions.

F5 Products

4 mentions

Beyond the specific F5 Distributed Cloud WAF, 10% of reviewers also mentioned other F5 products, such as F5 Distributed…

Beyond the specific F5 Distributed Cloud WAF, 10% of reviewers also mentioned other F5 products, such as F5 Distributed Cloud API Security and F5 BIG-IP Advanced Firewall Manager. This indicates that organizations often consider a broader range of F5's security and application delivery solutions, potentially evaluating different offerings within the same vendor ecosystem.

Web Application Firewall

4 mentions

A general category of Web Application Firewall solutions, including products from various vendors like Cisco, Amazon, C…

A general category of Web Application Firewall solutions, including products from various vendors like Cisco, Amazon, CheckPoint, and Palo Alto Networks, was mentioned by 10% of reviewers. This highlights the diverse market for WAFs and indicates that organizations often evaluate multiple solutions from different providers to meet their specific application security needs.

Cloudflare

2 mentions

Cloudflare's services, encompassing CDN and security features, were mentioned by 5% of reviewers as products used or ev…

Cloudflare's services, encompassing CDN and security features, were mentioned by 5% of reviewers as products used or evaluated in conjunction with F5 Distributed Cloud WAF. This suggests that Cloudflare is considered a relevant player in the broader web security and performance landscape, often alongside other dedicated WAF solutions.

What are the 3-5 most important use cases for this product in your organization?

64 answered

Reviewers predominantly identify web application security as a critical use case for this product, with 8% of reviewers highlighting its role in safeguarding web applications. This primarily involves protection against common vulnerabilities like the OWASP Top 10 and blocking malicious bots. Closely related, 5% of reviewers also emphasize the product's utility in API security, specifically for ensuring compliance with organizational policies and broader security standards. This focus on security extends to compliance and auditing requirements, which 5% of reviewers cited as an important application, particularly for organizations in regulated industries that require robust traffic segmentation. Beyond these core security functions, reviewers also noted the product's value in threat detection and alerting, with 3% appreciating its ability to centralize real-time threat identification and response. An emerging use case, mentioned by 3% of reviewers, involves integrating the product into CI/CD pipelines to facilitate DevSecOps practices and validate WAF configurations early in the development lifecycle.

Web Application Security

5 mentions

Reviewers frequently highlight the product's primary role in securing web applications against a range of threats, with…

Reviewers frequently highlight the product's primary role in securing web applications against a range of threats, with 8% of reviewers specifically mentioning this use case. Its capabilities include defending against well-known vulnerabilities such as the OWASP Top 10 and effectively blocking automated attacks and malicious bots. The product also supports traffic segmentation, which is crucial for clients in highly regulated sectors.

API Security

3 mentions

Securing APIs represents another significant use case for the product, as noted by 5% of reviewers. Organizations lever…

Securing APIs represents another significant use case for the product, as noted by 5% of reviewers. Organizations leverage its features to ensure their APIs comply with internal policies and external security standards, providing a layer of protection for critical data and services exposed through APIs.

Compliance and Auditing

3 mentions

The product is valued for its contribution to compliance and audit readiness, a use case cited by 5% of reviewers. It a…

The product is valued for its contribution to compliance and audit readiness, a use case cited by 5% of reviewers. It assists organizations in meeting various security standards and regulatory requirements, particularly through features like traffic segmentation that are essential for clients operating in tightly regulated industries.

Threat Detection and Alerting

2 mentions

Reviewers also identify the product's role in enhancing threat detection and alerting capabilities, with 3% of reviewer…

Reviewers also identify the product's role in enhancing threat detection and alerting capabilities, with 3% of reviewers noting its importance. It provides security teams with real-time threat detection and helps centralize response efforts, improving overall security posture.

CI/CD Integration

2 mentions

An emerging use case for the product involves its integration into CI/CD pipelines, mentioned by 3% of reviewers. This…

An emerging use case for the product involves its integration into CI/CD pipelines, mentioned by 3% of reviewers. This allows for the early validation of WAF configurations and supports broader DevSecOps initiatives, embedding security practices earlier into the software development lifecycle.

F5 Distributed Cloud WAF (Web Application Firewall) aims to reduce the complexity of securing apps anywhere - across multiple environments including on-premises, in and across cloud providers and at the edge. How have you benefited, at all, from being able to simplify the process of securing apps?

39 answered

Reviewers frequently report that F5 Distributed Cloud WAF simplifies the process of securing applications, with nearly half of the reviewers (49%) specifically highlighting benefits related to simplified app security. This simplification is often attributed to the platform's ability to unify security policies and manage applications across diverse environments. Many users, representing 26% of reviewers, noted the advantage of unified policy management, which enables consistent security postures regardless of application location. The streamlined approach also translates into tangible time savings for 13% of reviewers, accelerating deployment and reducing the effort involved in managing security. Furthermore, the platform's multi-environment support, also cited by 13% of reviewers, allows for consistent protection across on-premises, cloud, and edge deployments. While the overall sentiment is strongly positive regarding simplification, a small number of reviewers (8%) indicated they are still in the early stages of adoption or have not yet fully leveraged the multi-environment capabilities, and 5% suggested that the user interface could be improved.

Simplified App Security

19 mentions

A significant portion of reviewers, 49%, indicated that F5 Distributed Cloud WAF has simplified the process of securing…

A significant portion of reviewers, 49%, indicated that F5 Distributed Cloud WAF has simplified the process of securing applications. This simplification is attributed to easier deployment, more efficient protection, and the ability to apply consistent security policies across various environments without extensive manual configuration or debugging of WAF policies.

Unified Policy Management

10 mentions

Reviewers frequently commend the platform's ability to centralize and unify security policy management, a benefit noted…

Reviewers frequently commend the platform's ability to centralize and unify security policy management, a benefit noted by 26% of the reviews. This allows teams to apply a single global policy across multiple cloud and on-premise environments, leading to more controlled applications, simplified management, and a better overall view of the security posture.

Time Savings

5 mentions

The simplification offered by F5 Distributed Cloud WAF translates into considerable time savings for users, as reported…

The simplification offered by F5 Distributed Cloud WAF translates into considerable time savings for users, as reported by 13% of reviewers. This is achieved by reducing the time spent on configuring security, chasing false positives, and accelerating the time-to-market for new applications with basic WAF protections.

Multi-Environment Support

5 mentions

The platform's capability to secure applications across various environments, including multiple clouds and on-premises…

The platform's capability to secure applications across various environments, including multiple clouds and on-premises setups, is a key benefit for 13% of reviewers. This flexibility allows organizations to manage security for workloads regardless of their location, facilitating consistent protection in hybrid environments.

AI/ML and Threat Protection

4 mentions

What are some additional ways that your organization might be able to use F5 Distributed Cloud WAF (Web Application Firewall) in the future?

64 answered

Reviewers anticipate leveraging F5 Distributed Cloud WAF for several strategic future applications, primarily focusing on enhancing security integration and expanding protection across their digital assets. A key area for future expansion involves deeper integration into DevSecOps pipelines and CI/CD processes, cited by 5% of reviewers, aiming to automate security testing and embed WAF capabilities earlier in the development lifecycle. Organizations also foresee utilizing the WAF for more granular release management and access control, with 3% of reviewers noting its potential to manage feature rollouts for specific user groups without altering application code, alongside pre-production testing. Furthermore, the platform is expected to extend its threat detection capabilities to protect APIs and a broader array of websites, as mentioned by 3% of reviewers, indicating a desire for comprehensive coverage. Another emerging use case, highlighted by 3% of reviewers, includes the enforcement of advanced security features such as Zero Trust Network Access (ZTNA) and the application of AI-powered adaptive security measures. These future plans collectively suggest a move towards more integrated, automated, and expansive security postures.

DevSecOps and CI/CD Integration

3 mentions

Organizations plan to integrate F5 Distributed Cloud WAF more deeply into their DevSecOps and CI/CD pipelines. This int…

Organizations plan to integrate F5 Distributed Cloud WAF more deeply into their DevSecOps and CI/CD pipelines. This integration is seen as a way to automate security testing and embed WAF policies earlier in the software development lifecycle, enhancing overall security posture proactively. This potential was noted by 5% of reviewers.

Release Management and Access Control

2 mentions

Reviewers anticipate using the WAF for advanced release management and access control strategies. This includes leverag…

Reviewers anticipate using the WAF for advanced release management and access control strategies. This includes leveraging WAF policies to control access to new features for specific user groups during rollouts without requiring changes to application code, and for pre-production application testing and hardening. This use case was mentioned by 3% of reviewers.

API and Website Protection

2 mentions

Future plans involve expanding the F5 Distributed Cloud WAF's protection to a wider range of digital assets. Specifical…

Future plans involve expanding the F5 Distributed Cloud WAF's protection to a wider range of digital assets. Specifically, reviewers intend to extend threat detection and security measures to APIs and potentially scale protection to thousands of websites, contingent on successful proof-of-concept implementations. This expansion was cited by 3% of reviewers.

Advanced Security Features

2 mentions

Organizations are exploring the implementation of more sophisticated security capabilities using the WAF. This includes…

Organizations are exploring the implementation of more sophisticated security capabilities using the WAF. This includes enforcing Zero Trust Network Access (ZTNA) principles and leveraging AI-powered adaptive security to enhance their defensive posture against evolving threats. This forward-looking application was highlighted by 3% of reviewers.

What are some unexpected or innovative ways that your organization has been able to use F5 Distributed Cloud WAF (Web Application Firewall)?

64 answered

Organizations are leveraging F5 Distributed Cloud WAF in several advanced and innovative ways that extend beyond conventional web application firewall functions. A notable application, cited by 5% of reviewers, involves enhancing API security and management, including the enforcement of business logic and the protection of IoT API endpoints. Reviewers also describe using the platform for security training and simulation, as well as for integrating security into CI/CD pipelines, both mentioned by 3% of reviewers. Furthermore, the WAF is being utilized to secure edge AI and IoT applications, a use case highlighted by 3% of reviewers. The flexibility of the platform is also demonstrated through its application in developing custom mitigation rules, which was also noted by 3% of the review sample. These applications suggest a trend towards using the F5 Distributed Cloud WAF as a versatile security tool capable of addressing emerging threats and operational requirements across diverse IT environments.

API Security & Management

3 mentions

Reviewers are utilizing F5 Distributed Cloud WAF to secure their API ecosystems, moving beyond basic protection to impl…

Reviewers are utilizing F5 Distributed Cloud WAF to secure their API ecosystems, moving beyond basic protection to implement more sophisticated controls. This includes enforcing business logic and discovering API behaviors, which helps in identifying and mitigating complex threats. The WAF is also instrumental in securing API endpoints for Internet of Things (IoT) devices, extending protection to a rapidly growing attack surface.

Security Training & Simulation

2 mentions

The F5 Distributed Cloud WAF is being employed creatively for internal security training and simulation exercises. Orga…

The F5 Distributed Cloud WAF is being employed creatively for internal security training and simulation exercises. Organizations are using its capabilities to simulate attack traffic across various regions, allowing them to test failover mechanisms, validate WAF rules, and assess geo-based throttling under realistic conditions. This approach helps in preparing teams for actual attack scenarios and improving overall security posture.

CI/CD Integration

2 mentions

Reviewers are finding innovative ways to integrate F5 Distributed Cloud WAF into their Continuous Integration/Continuou…

Reviewers are finding innovative ways to integrate F5 Distributed Cloud WAF into their Continuous Integration/Continuous Delivery (CI/CD) pipelines. This integration enables auto-adaptive security through feedback loops, allowing security policies to evolve with application changes. A key benefit is the mitigation of supply chain attacks, ensuring that security is a continuous process throughout the development lifecycle.

Edge & IoT Security

2 mentions

The platform is being deployed to secure applications at the edge and for Internet of Things (IoT) devices, addressing…

The platform is being deployed to secure applications at the edge and for Internet of Things (IoT) devices, addressing the unique security challenges of these environments. This includes using the WAF as a dedicated security layer for Edge AI and IoT applications. Protecting IoT API endpoints is a specific application, highlighting the WAF's capability to extend security to distributed and embedded systems.

Custom Rule Development

2 mentions

Organizations are leveraging the F5 Distributed Cloud WAF for developing custom mitigation rules, demonstrating its fle…

Organizations are leveraging the F5 Distributed Cloud WAF for developing custom mitigation rules, demonstrating its flexibility and adaptability to specific security needs. This involves integrating external threat intelligence feeds directly into these custom rules, allowing for highly tailored and responsive defense mechanisms. The ability to create 'other custom rules' suggests a broad capacity for addressing unique or evolving threats not covered by standard policies.

What positive or negative impact (i.e. Return on Investment or ROI) has F5 Distributed Cloud WAF (Web Application Firewall) had on your overall business objectives?

39 answered

F5 Distributed Cloud WAF has demonstrably contributed to organizations' business objectives, primarily through enhancing security posture and reducing operational costs. A significant majority of reviewers, 56%, reported an improved security posture, citing specific protections against advanced threats and data breaches. This enhanced security is complemented by a notable reduction in total cost of ownership, highlighted by 26% of reviewers, often due to the cloud-native architecture eliminating hardware requirements. Furthermore, the platform contributes to business agility by enabling faster deployment and onboarding of applications, a benefit noted by 13% of the reviewers. These factors collectively indicate a positive return on investment by safeguarding critical assets while optimizing resource allocation and accelerating time to market. Additionally, 13% of reviewers pointed to improved performance and availability as a key outcome.

Improved Security Posture

22 mentions

Reviewers consistently highlight F5 Distributed Cloud WAF's effectiveness in bolstering their security posture, with 56…

Reviewers consistently highlight F5 Distributed Cloud WAF's effectiveness in bolstering their security posture, with 56% explicitly mentioning this benefit. The product is credited with protecting sensitive customer data, defending against OWASP attacks, zero-day vulnerabilities, and SQL injection attempts, thereby reducing the risk of data breaches and significant incidents.

Improved Security

12 mentions

Beyond general posture, 31% of reviewers specifically noted improved security, often linking it to stronger cybersecuri…

Beyond general posture, 31% of reviewers specifically noted improved security, often linking it to stronger cybersecurity and application protection. This enhancement helps organizations meet regulatory requirements and provides robust defense against external adversaries.

Reduced Costs / TCO

10 mentions

A quarter of reviewers, 26%, pointed to significant cost reductions and a lower total cost of ownership as a key busine…

A quarter of reviewers, 26%, pointed to significant cost reductions and a lower total cost of ownership as a key business objective met by F5 Distributed Cloud WAF. This is often attributed to the absence of hardware requirements and streamlined management, leading to lower overhead.

Faster Deployment/Onboarding

5 mentions

The platform's ability to accelerate application delivery and deployment was a benefit for 13% of reviewers. They speci…

The platform's ability to accelerate application delivery and deployment was a benefit for 13% of reviewers. They specifically noted a quicker time to deploy compared to traditional WAF solutions and a faster time to value for new services.

Improved Performance / Availability

5 mentions

Reviewers also observed improvements in application performance and availability, with 13% mentioning benefits such as…

Reviewers also observed improvements in application performance and availability, with 13% mentioning benefits such as increased uptime and reduced downtimes. This contributes to a more reliable service for customers and overall operational stability.