TrustRadius: an HG Insights company

F5 Distributed Cloud WAF (Web Application Firewall) Reviews & Insights

Score9.2 out of 10

284 Reviews and Ratings

Learn More

Contact about F5 Distributed Cloud WAF (Web Application Firewall)

Please fill out the form below to get in touch.

F5

Connect with F5

What are you interested in?

Already have an account?

You hereby consent to have TrustRadius share the information supplied on this form with F5 so that F5 and TrustRadius may contact you in regard to the information requested.

Top industries

Based on 5 HG Insights installations.

Powered by

Community Insights for F5 Distributed Cloud WAF (Web Application Firewall)

Synthesised from 39 verified reviews.


Synthesised from 39 reviews | Last Published June 27, 2026


F5 Distributed Cloud WAF serves as a critical security layer for organizations, primarily protecting a wide array of public-facing and internal web applications and APIs. In TrustRadius reviews, users frequently deploy it to safeguard against OWASP Top 10 risks, general cyberattacks, and specialized threats like bots and DDoS attacks. Reviewers consistently praise its robust security capabilities, including effective DDoS and bot protection, alongside its relatively easy configuration and deployment.

While the platform offers significant benefits like unified policy management and multi-environment support, reviewers frequently cite the complexity of its UI/UX as a primary concern, with 46% finding it unintuitive. Policy configuration and tuning are also noted as challenging, sometimes leading to false positives. Despite these configuration and cost-related drawbacks, the overall sentiment indicates strong positive reception for the product's core security capabilities and its ability to deliver tangible value.


  • Robust DDoS protection capabilities
  • Easy initial configuration and deployment
  • Effective bot protection
  • Comprehensive API security
  • Unified policy management across diverse environments
  • Complex and unintuitive user interface (UI/UX)
  • Difficult policy configuration and tuning for intricate applications
  • Prevalence of false positives requiring extensive tuning
  • Concerns regarding cost and pricing model
  • Desire for enhanced automation and AI capabilities
What other products like F5 Distributed Cloud WAF (Web Application Firewall) have you used or evaluated?

From 39 reviews | Last Published June 27, 2026

Reviewers frequently identify a diverse range of alternative and complementary products when discussing F5 Distributed Cloud WAF. Akamai products are the most frequently cited, with 18% of reviewers mentioning various offerings such as Akamai App & API Protector, CDN, Bot Manager, and Prolexic, indicating a strong competitive presence in the market. Several other solutions are also consistently named by 10% of reviewers, including Imperva Application Firewall, other F5 products like F5 Distributed Cloud API Security and F5 BIG-IP Advanced Firewall Manager (AFM), and a broader category of Web Application Firewall solutions from vendors such as Cisco, Amazon, CheckPoint, and Palo Alto Networks. Additionally, Cloudflare is noted by 5% of reviewers as another significant alternative or co-existing service. These mentions collectively highlight a competitive landscape where organizations evaluate multiple vendors for WAF, API security, CDN, and bot management capabilities, often considering a mix of specialized and comprehensive platforms.

Akamai Products

Akamai Prolexic, Akamai Edge DNS, Akamai CDN and Akamai Bot Manager

Imperva Products

Akamai App & API Protector and Imperva Application Firewall

F5 Products

F5 Distributed Cloud WAF (Web Application Firewall)

What are the 3-5 most important use cases for this product in your organization?

From 64 reviews | Last Published June 11, 2026

Reviewers predominantly identify web application security as a critical use case for this product, with 8% of reviewers highlighting its role in safeguarding web applications. This primarily involves protection against common vulnerabilities like the OWASP Top 10 and blocking malicious bots. Closely related, 5% of reviewers also emphasize the product's utility in API security, specifically for ensuring compliance with organizational policies and broader security standards. This focus on security extends to compliance and auditing requirements, which 5% of reviewers cited as an important application, particularly for organizations in regulated industries that require robust traffic segmentation. Beyond these core security functions, reviewers also noted the product's value in threat detection and alerting, with 3% appreciating its ability to centralize real-time threat identification and response. An emerging use case, mentioned by 3% of reviewers, involves integrating the product into CI/CD pipelines to facilitate DevSecOps practices and validate WAF configurations early in the development lifecycle.

Web Application Security

Protecting Web Applications from OWASP Top 10 Threats

API Security

Securing APIs to comply with policy

Compliance and Auditing

Compliance and Audit Readiness

F5 Distributed Cloud WAF (Web Application Firewall) aims to reduce the complexity of securing apps anywhere - across multiple environments including on-premises, in and across cloud providers and at the edge. How have you benefited, at all, from being able to simplify the process of securing apps?

From 39 reviews | Last Published June 27, 2026

F5 Distributed Cloud WAF (Web Application Firewall) significantly simplifies the process of securing applications across diverse environments, a benefit highlighted by nearly half (49%) of reviewers. This simplification is largely attributed to the platform's ability to provide unified policy management, which 26% of reviewers noted allows for consistent security application across on-premises, cloud, and hybrid infrastructures. Reviewers frequently report time savings, with 13% indicating that the solution accelerates deployment and reduces the effort associated with managing security policies. The WAF's robust multi-environment support, also cited by 13% of reviewers, enables organizations to maintain a cohesive security posture regardless of where their applications are hosted. Furthermore, 10% of the feedback points to the platform's advanced AI/ML capabilities for threat protection, enhancing its effectiveness in mitigating risks and preventing false alarms.

Simplified App Security

F5 Distributed Cloud WAF (Web Application Firewall) has made deploying apps and protecting them simpler and more efficient.

Unified Policy Management

Instead of coordinating firewall rules across multiple clouds, and on-prem environments manually, teams can apply one global policy via the F5 Distributed Cloud console or API.

Time Savings

I have benefited from being able to simplify the process of securing apps because I've saved a ton of time with the F5 Distributed Cloud WAF (Web Application Firewall) and bot protections'

What are some additional ways that your organization might be able to use F5 Distributed Cloud WAF (Web Application Firewall) in the future?

From 64 reviews | Last Published June 11, 2026

Reviewers anticipate leveraging F5 Distributed Cloud WAF for several strategic future applications, primarily focusing on enhancing security integration and expanding protection across their digital assets. A key area for future expansion involves deeper integration into DevSecOps pipelines and CI/CD processes, cited by 5% of reviewers, aiming to automate security testing and embed WAF capabilities earlier in the development lifecycle. Organizations also foresee utilizing the WAF for more granular release management and access control, with 3% of reviewers noting its potential to manage feature rollouts for specific user groups without altering application code, alongside pre-production testing. Furthermore, the platform is expected to extend its threat detection capabilities to protect APIs and a broader array of websites, as mentioned by 3% of reviewers, indicating a desire for comprehensive coverage. Another emerging use case, highlighted by 3% of reviewers, includes the enforcement of advanced security features such as Zero Trust Network Access (ZTNA) and the application of AI-powered adaptive security measures. These future plans collectively suggest a move towards more integrated, automated, and expansive security postures.

DevSecOps and CI/CD Integration

Integration with DevSecOps Pipelines

Release Management and Access Control

We'll attempt to tag early access users in feature rollouts, and use the waf policies to control who can hit the new routes - all without changing the app code.

API and Website Protection

threat detection, and extend protection to APIs

What are some unexpected or innovative ways that your organization has been able to use F5 Distributed Cloud WAF (Web Application Firewall)?

From 64 reviews | Last Published June 11, 2026

Organizations are leveraging F5 Distributed Cloud WAF in several advanced and innovative ways that extend beyond conventional web application firewall functions. A notable application, cited by 5% of reviewers, involves enhancing API security and management, including the enforcement of business logic and the protection of IoT API endpoints. Reviewers also describe using the platform for security training and simulation, as well as for integrating security into CI/CD pipelines, both mentioned by 3% of reviewers. Furthermore, the WAF is being utilized to secure edge AI and IoT applications, a use case highlighted by 3% of reviewers. The flexibility of the platform is also demonstrated through its application in developing custom mitigation rules, which was also noted by 3% of the review sample. These applications suggest a trend towards using the F5 Distributed Cloud WAF as a versatile security tool capable of addressing emerging threats and operational requirements across diverse IT environments.

API Security & Management

Business Logic Enforcement & Feature Flags

Security Training & Simulation

Using Voltmesh to simulate attack traffic across regions during tabletop exercises. We spun up synthetic traffic from multiple edges to test failovers, WAF rules and geo based throttling

CI/CD Integration

Auto-adaptive security using CI/CD feedback loops

What positive or negative impact (i.e. Return on Investment or ROI) has F5 Distributed Cloud WAF (Web Application Firewall) had on your overall business objectives?

From 39 reviews | Last Published June 27, 2026

F5 Distributed Cloud WAF has a predominantly positive impact on organizations' business objectives, primarily by enhancing security and reducing operational costs. A significant majority of reviewers, 56%, reported an improved security posture, citing protection against advanced threats and data breaches. This sentiment is reinforced by an additional 26% of reviewers who highlighted general improvements in security and cybersecurity posture, including meeting regulatory requirements. Beyond security, the platform also contributes to financial efficiencies, with 26% of reviewers noting reduced costs or a lower total cost of ownership due to factors like less hardware dependency. Operational benefits extend to faster deployment and onboarding, mentioned by 10% of the sample, enabling quicker application delivery. Furthermore, an equal proportion of reviewers, 10%, experienced improved performance and availability, leading to increased uptime and reduced downtimes for their services. The overall sentiment suggests that the product delivers tangible value across security, cost, and operational efficiency domains.

Improved Security Posture

helped us in keeping our customers data safe

Improved Security

TBD, but we expect an improved security posture given policies are auto tuned based on all customers traffic rather then our internal traffic only

Reduced Costs / TCO

Lower total cost

Besides F5 Distributed Cloud WAF (Web Application Firewall), what other software do you regularly use? How likely would you be to recommend it to a friend or colleague?

From 39 reviews | Last Published June 27, 2026

Reviewers frequently identify a range of security and networking solutions used in conjunction with F5 Distributed Cloud WAF. F5 BIG-IP products are the most commonly mentioned, cited by 28% of reviewers, often for traffic management and advanced WAF capabilities. Cloudflare and AWS WAF also emerged as notable alternatives or complementary services, each mentioned by 10% of the sample. Additionally, reviewers noted the use of Fortinet FortiGate firewalls and Splunk for security information and event management, both mentioned by 8% of the respondents. The landscape of tools used alongside or instead of F5 Distributed Cloud WAF is diverse, encompassing traditional hardware appliances, cloud-native services, and specialized security platforms, reflecting varied organizational needs for load balancing, web application protection, and broader security infrastructure. While specific sentiments vary by product, the overall trend indicates a reliance on established vendors for critical security and network functions.

F5 BIG-IP

F5 BIG-IP Local Traffic Manager (LTM)

Cloudflare

Cloudflare Zero Trust Services

AWS WAF

AWS WAF

Describe how you use F5 Distributed Cloud WAF (Web Application Firewall) in your organization. What are the business problems the product addresses and what is the scope of your use case?

From 39 reviews | Last Published June 27, 2026

F5 Distributed Cloud WAF is primarily utilized by organizations as a critical security layer for protecting a wide range of applications and services. A significant majority of reviewers, 69%, employ the product for application protection, safeguarding both public-facing and internal web applications, including marketing websites, public services, and core banking systems. The scope of use frequently extends to protecting against OWASP Top 10 risks and general cyberattacks. Closely related, 59% of reviewers highlight the product's role in application security, emphasizing its effectiveness in enhancing the security posture of online websites and APIs against threats like bots and DDoS attacks. The product consistently addresses threat mitigation, with 46% of reviewers noting its ability to stop zero-day attacks, SQL injections, and XSS, contributing to a robust, layered defense strategy. It is valued for its real-time protection updates and rapid response capabilities. Beyond general application protection, 15% of reviewers specifically leverage the WAF for web application protection, focusing on securing dynamic websites and public-facing portals for themselves and their clients, aiming to reduce the attack surface and improve service availability. While many reviewers express positive sentiments regarding the ease of use and experience, also cited by 15%, some find the configuration complex and note the cost as a potential drawback. Despite these concerns, the overall sentiment across the reviews indicates a strong positive reception for the product's security capabilities and its role in addressing critical business problems related to web application and API defense.

Application Protection

We use F5 Distributed Cloud WAF as a critical layer of our security architecture to protect both public-facing and internal web applications.

Application Security

F5 Distributed Cloud WAF (Web Application Firewall) help us in enhacing the security of our online websites and social media pages and make our digital presence much stronger.

Threat Mitigation

but this software helps in keeping these data safe from hackers and fraudsters.

Loading Reviews List....

Video reviews