TrustRadius: an HG Insights company

F5 Distributed Cloud WAF (Web Application Firewall) Reviews & Insights

Score9 out of 10

282 Reviews and Ratings

Learn More

Contact about F5 Distributed Cloud WAF (Web Application Firewall)

Please fill out the form below to get in touch.

F5

Connect with F5

What are you interested in?

Already have an account?

You hereby consent to have TrustRadius share the information supplied on this form with F5 so that F5 and TrustRadius may contact you in regard to the information requested.

Top industries

Based on 5 HG Insights installations.

Powered by

Community Insights for F5 Distributed Cloud WAF (Web Application Firewall)

Synthesised from 52 verified reviews.


Synthesised from 52 reviews | Last Published June 12, 2026


F5 Distributed Cloud WAF is primarily used by organizations to secure web-facing applications and APIs, addressing critical security challenges across public, internal, and marketing websites. In TrustRadius reviews, users deploy it for robust application protection, enhancing overall security posture, and effective threat mitigation against various cyber threats. Reviewers frequently highlight its strong capabilities in defending against DDoS attacks, a feature noted by 23% of users.

The platform also offers benefits in simplified application security, unified policy management across diverse environments, and resulting time savings for security teams. However, reviewers frequently identify challenges with the complexity of the UI/UX and navigation, a concern for 38% of users. Policy configuration and tuning are also cited as areas needing improvement, alongside a desire for more robust and customizable reporting and analytics. Despite these complexities, the overall sentiment indicates that the WAF delivers tangible value by safeguarding digital assets.


  • Robust DDoS attack mitigation
  • Strong API protection capabilities
  • Comprehensive bot protection and OWASP Top 10 defense
  • Simplified application security across environments
  • Unified policy management for hybrid/multi-cloud infrastructures
  • Complex UI/UX and navigation challenges
  • Difficulties with policy configuration and tuning
  • Limited and less customizable reporting and analytics
  • Concerns regarding cost and pricing transparency
  • Need for improvement in reducing false positives
What other products like F5 Distributed Cloud WAF (Web Application Firewall) have you used or evaluated?

From 52 reviews | Last Published June 12, 2026

Reviewers frequently identify a diverse set of web application firewall (WAF) and security solutions that they have used or evaluated in conjunction with F5 Distributed Cloud WAF. Akamai products are the most commonly cited alternatives, mentioned by 13% of reviewers, encompassing a range of services from WAF and API protection to bot management and content delivery. Other significant competitors and related technologies include Imperva products, cited by 8% of reviewers, specifically their Application Firewall offerings. Reviewers also mention other F5 products, such as F5 Distributed Cloud API Security and F5 BIG-IP Advanced Firewall Manager, indicating a broader engagement with the F5 ecosystem by 8% of the sample. A similar proportion of reviewers, 8%, refer to a variety of other web application firewall solutions from different vendors, highlighting the competitive landscape. Cloudflare is also noted as an alternative or complementary service by 4% of reviewers, often alongside Akamai and Imperva offerings.

Akamai Products

Akamai Prolexic, Akamai Edge DNS, Akamai CDN and Akamai Bot Manager

Imperva Products

Akamai App & API Protector and Imperva Application Firewall

F5 Products

F5 Distributed Cloud WAF (Web Application Firewall)

What are the 3-5 most important use cases for this product in your organization?

From 64 reviews | Last Published June 11, 2026

Reviewers predominantly identify web application security as a critical use case for this product, with 8% of reviewers highlighting its role in safeguarding web applications. This primarily involves protection against common vulnerabilities like the OWASP Top 10 and blocking malicious bots. Closely related, 5% of reviewers also emphasize the product's utility in API security, specifically for ensuring compliance with organizational policies and broader security standards. This focus on security extends to compliance and auditing requirements, which 5% of reviewers cited as an important application, particularly for organizations in regulated industries that require robust traffic segmentation. Beyond these core security functions, reviewers also noted the product's value in threat detection and alerting, with 3% appreciating its ability to centralize real-time threat identification and response. An emerging use case, mentioned by 3% of reviewers, involves integrating the product into CI/CD pipelines to facilitate DevSecOps practices and validate WAF configurations early in the development lifecycle.

Web Application Security

Protecting Web Applications from OWASP Top 10 Threats

API Security

Securing APIs to comply with policy

Compliance and Auditing

Compliance and Audit Readiness

F5 Distributed Cloud WAF (Web Application Firewall) aims to reduce the complexity of securing apps anywhere - across multiple environments including on-premises, in and across cloud providers and at the edge. How have you benefited, at all, from being able to simplify the process of securing apps?

From 52 reviews | Last Published June 12, 2026

Reviewers consistently report that F5 Distributed Cloud WAF significantly simplifies the process of securing applications across various environments. A substantial 37% of reviewers directly cited 'Simplified App Security' as a key benefit, attributing it to easier deployment, intuitive interfaces, and reduced configuration complexities. This simplification is often linked to the platform's ability to offer 'Unified Policy Management,' noted by 19% of reviewers, enabling consistent security controls across hybrid and multi-cloud infrastructures from a single console. The resulting efficiencies translate into 'Time Savings' for operations and security teams, a benefit highlighted by 10% of the reviewers, particularly in faster deployment of new applications and reduced effort in managing security policies. The platform's robust 'Multi-Environment Support' (10% of reviewers) allows for seamless traffic handling and policy application across on-premises, cloud, and edge locations. Furthermore, the integration of 'AI/ML and Threat Protection,' mentioned by 8% of reviewers, contributes to more accurate security measures and effective mitigation of sophisticated attacks. While the overall sentiment is strongly positive, a small segment of reviewers (6%) indicated they are still in the early stages of adoption or expanding their use, and 4% suggested potential improvements in the UI/UX.

Simplified App Security

F5 Distributed Cloud WAF (Web Application Firewall) has made deploying apps and protecting them simpler and more efficient.

Unified Policy Management

More controlled applications and simplified management<br><br>Aplicaciones mas controladas y gestion simplificada

Time Savings

I have benefited from being able to simplify the process of securing apps because I've saved a ton of time with the F5 Distributed Cloud WAF (Web Application Firewall) and bot protections'

What are some additional ways that your organization might be able to use F5 Distributed Cloud WAF (Web Application Firewall) in the future?

From 64 reviews | Last Published June 11, 2026

Reviewers anticipate leveraging F5 Distributed Cloud WAF for several strategic future applications, primarily focusing on enhancing security integration and expanding protection across their digital assets. A key area for future expansion involves deeper integration into DevSecOps pipelines and CI/CD processes, cited by 5% of reviewers, aiming to automate security testing and embed WAF capabilities earlier in the development lifecycle. Organizations also foresee utilizing the WAF for more granular release management and access control, with 3% of reviewers noting its potential to manage feature rollouts for specific user groups without altering application code, alongside pre-production testing. Furthermore, the platform is expected to extend its threat detection capabilities to protect APIs and a broader array of websites, as mentioned by 3% of reviewers, indicating a desire for comprehensive coverage. Another emerging use case, highlighted by 3% of reviewers, includes the enforcement of advanced security features such as Zero Trust Network Access (ZTNA) and the application of AI-powered adaptive security measures. These future plans collectively suggest a move towards more integrated, automated, and expansive security postures.

DevSecOps and CI/CD Integration

Integration with DevSecOps Pipelines

Release Management and Access Control

We'll attempt to tag early access users in feature rollouts, and use the waf policies to control who can hit the new routes - all without changing the app code.

API and Website Protection

threat detection, and extend protection to APIs

What are some unexpected or innovative ways that your organization has been able to use F5 Distributed Cloud WAF (Web Application Firewall)?

From 64 reviews | Last Published June 11, 2026

Organizations are leveraging F5 Distributed Cloud WAF in several advanced and innovative ways that extend beyond conventional web application firewall functions. A notable application, cited by 5% of reviewers, involves enhancing API security and management, including the enforcement of business logic and the protection of IoT API endpoints. Reviewers also describe using the platform for security training and simulation, as well as for integrating security into CI/CD pipelines, both mentioned by 3% of reviewers. Furthermore, the WAF is being utilized to secure edge AI and IoT applications, a use case highlighted by 3% of reviewers. The flexibility of the platform is also demonstrated through its application in developing custom mitigation rules, which was also noted by 3% of the review sample. These applications suggest a trend towards using the F5 Distributed Cloud WAF as a versatile security tool capable of addressing emerging threats and operational requirements across diverse IT environments.

API Security & Management

Business Logic Enforcement & Feature Flags

Security Training & Simulation

Using Voltmesh to simulate attack traffic across regions during tabletop exercises. We spun up synthetic traffic from multiple edges to test failovers, WAF rules and geo based throttling

CI/CD Integration

Auto-adaptive security using CI/CD feedback loops

What positive or negative impact (i.e. Return on Investment or ROI) has F5 Distributed Cloud WAF (Web Application Firewall) had on your overall business objectives?

From 52 reviews | Last Published June 12, 2026

F5 Distributed Cloud WAF significantly contributes to organizations' business objectives primarily through enhancing security and reducing operational costs. A substantial 42% of reviewers reported an improved security posture, citing better protection against threats like OWASP attacks, 0-day vulnerabilities, and SQL injection. This enhanced security is further supported by 21% of reviewers who noted a general improvement in security, including strengthened cybersecurity posture and meeting regulatory requirements. Beyond security, the platform demonstrates a positive impact on financial and operational efficiency. Approximately 17% of reviewers highlighted reduced costs and lower total cost of ownership, often due to decreased hardware requirements and support budgets. Furthermore, the solution improves deployment speed, with 8% of reviewers mentioning faster onboarding and quicker time to deploy applications. Another 8% also observed improved performance and availability, leading to increased uptime and reduced downtimes for customers. These combined benefits suggest that F5 Distributed Cloud WAF delivers tangible value by safeguarding digital assets while optimizing resource utilization.

Improved Security Posture

helped us in keeping our customers data safe

Improved Security

TBD, but we expect an improved security posture given policies are auto tuned based on all customers traffic rather then our internal traffic only

Reduced Costs / TCO

Lower total cost

Besides F5 Distributed Cloud WAF (Web Application Firewall), what other software do you regularly use? How likely would you be to recommend it to a friend or colleague?

From 52 reviews | Last Published June 12, 2026

Reviewers frequently utilize a range of security and networking software alongside F5 Distributed Cloud WAF, with F5's own BIG-IP platform being the most commonly cited complementary technology. F5 BIG-IP, including its Local Traffic Manager (LTM) and Access Policy Manager (APM) modules, was mentioned by 21% of reviewers, indicating its established presence in many environments. Cloud-native solutions are also prominent, with both Cloudflare and AWS WAF each noted by 8% of the sample, reflecting a trend towards integrated cloud security services. Furthermore, data analytics and security operations tools like Splunk are used by 6% of reviewers, often for logging and incident response. Cisco Security Products and Fortinet FortiGate, also mentioned by 6% of reviewers, highlight the continued reliance on traditional network security vendors for firewalls and broader security ecosystems. The overall sentiment towards these complementary tools is largely mixed, suggesting varied experiences and specific use cases driving their adoption.

F5 BIG-IP

F5 BIG-IP Local Traffic Manager (LTM)

Cloudflare

Cloudflare Zero Trust Services

AWS WAF

AWS WAF

Describe how you use F5 Distributed Cloud WAF (Web Application Firewall) in your organization. What are the business problems the product addresses and what is the scope of your use case?

From 52 reviews | Last Published June 12, 2026

Organizations primarily deploy F5 Distributed Cloud WAF to safeguard their web-facing applications and APIs, addressing critical security challenges. Reviewers frequently highlight its role in providing robust Application Protection, with 52% of reviewers noting its use for securing public-facing, internal, and external marketing websites, as well as critical services and portals. The product is seen as a crucial component for overall Application Security, with 44% of reviewers emphasizing its ability to enhance the security posture of online assets and protect against various cyber threats, including OWASP Top 10 risks. A significant aspect of its utility lies in Threat Mitigation, cited by 35% of reviewers, who value its effectiveness in blocking zero-day attacks, DDoS, SQL injections, and other malicious traffic. Furthermore, the WAF is specifically utilized for Web Application Protection for clients' portals and dynamic websites, ensuring comprehensive security for public-facing digital services. While 12% of reviewers appreciate the product's Ease of Use and Experience, some also point to complexities in configuration.

Application Protection

We use F5 Distributed Cloud WAF as a critical layer of our security architecture to protect both public-facing and internal web applications.

Application Security

F5 Distributed Cloud WAF (Web Application Firewall) help us in enhacing the security of our online websites and social media pages and make our digital presence much stronger.

Threat Mitigation

but this software helps in keeping these data safe from hackers and fraudsters.

Loading Reviews List....

Video reviews