Use Cases and Deployment Scope
We use Imperva Cloud WAF and Secure Sphere WAF on the On premise environment. Currently we manage over 4k websites worldwide, mostly onboarded on the Cloud WAF. The main features we use is the standard WAF Signature Rules, DDoS Protection, Bot Protection, Imperva managed certificates, Cache and custom rules to manipulate traffic. The Custom rules are very usefull to create rules for Rate Limit, Forward to diffent DCs rules, rewrite Headers and URLs, track parameters, block/alert malicious client types. We've been having great experience with performance and availability as Imperva have several PoPs spread across the globe and CDN combined works just fine for us. I consider the console very easy to use, one of the most complete WAFs and yet very simple to manage. The API definition for automated management is also very complete and easy to integrate with automation solutions. We always use API for repeated tasks like updating custom SSL certs for hundreds of websites at the same time. We also use a lot of ACL policies to block IPs, URLs or countries/regions, and the exception creation is very simple as well. Security and perfomance dashboards and events are perfect too.
Other Software Used
Splunk Enterprise Security, Datadog, F5 BIG-IP Local Traffic Manager (LTM)