Listing Thumbnail

    Imperva - Managed Rules for IP Reputation on AWS WAF

     Info
    Sold by: Imperva 
    Deployed on AWS
    Imperva's Managed Rules for IP Reputation allow you to take a proactive approach to threat prevention and security management by providing an extensive IP whitelist/blacklist that is regularly monitored and updated.
    4.5

    Overview

    Imperva's Managed Rules for IP Reputation allows you to take a proactive approach to security by providing an extensive IP whitelist/blacklist which is regularly monitored and updated. Imperva's reputation feed leverages crowd-sourcing from aggregated attack data to update its list with newly detected malicious sources, taking the burden off of IT teams to account for undiscovered threats.

    Highlights

    • Proactive approach to threat prevention and security management; Automated protection regularly monitored and updated; Integrates seamlessly with AWS WAF

    Details

    Sold by

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Imperva - Managed Rules for IP Reputation on AWS WAF

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (2)

     Info
    Dimension
    Cost/unit
    Charge per month in each available region (pro-rated by the hour)
    $40.00
    Charge per million requests in each available region
    $0.40

    Vendor refund policy

    non-refundable

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    For issues related specifically to an Imperva ruleset, you can contact Imperva support by email.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    6 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    IP Reputation Management
    Extensive IP whitelist/blacklist that is regularly monitored and updated to identify and block malicious sources
    Threat Intelligence Integration
    Crowd-sourced aggregated attack data leveraged to detect and update newly identified malicious IP sources
    AWS WAF Integration
    Seamless integration with AWS WAF for automated threat prevention and security management
    Automated Threat Detection
    Automated protection mechanism that continuously monitors and updates threat intelligence without manual intervention
    Managed Rule Set
    Pre-configured managed rules for IP reputation that reduce operational burden on security teams for threat identification
    Malicious IP Reputation Database
    Utilizes ThreatDB collected and analyzed from 700,000 websites across 171 countries to create and maintain a Malicious IP Reputation list for threat identification.
    Third-Party Validated Detection
    Achieves top-tier detection rate for malicious traffic, validated by independent third-party testing firm.
    Threat Intelligence Integration
    Integrates Cyber Threat Intelligence (CTI) from Cloudbric Labs to identify and block traffic from various threat IP sources.
    Real-Time Threat Information
    Provides real-time information about threats and vulnerabilities affecting web applications.
    AWS WAF Integration
    Operates as managed rules for AWS WAF to protect websites and web applications against malicious IP traffic.
    Threat Intelligence Integration
    Rulesets regularly updated with latest threat alerts using Cyber Threat Intelligence
    OWASP Top 10 Coverage
    Comprehensive protection against all OWASP Top 10 Web Application Threats
    Code Injection Prevention
    Managed rules targeting code injection techniques including SQLi, NoSQLi, and OS command injection
    Technology-Specific Vulnerability Protection
    Dedicated rules for known exploits in Apache Struts2, Apache Tomcat, Oracle WebLogic, WordPress, Drupal, and Joomla
    Malicious Bot Detection
    Malicious Bots rulesets included for bot-based threat mitigation

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    -
    -
    -
    -
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    52 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    73%
    23%
    0%
    2%
    2%
    11 AWS reviews
    |
    41 external reviews
    External reviews are from G2 .
    ZechariahAkinpelu

    Managed rules have strengthened API defenses and now automate protection against evolving attacks

    Reviewed on Jul 23, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Imperva Managed Rules on AWS WAF  protects our web-facing applications and APIs hosted on AWS  by defending against OWASP Top 10 attacks. We use it for bot traffic management and to guard against different attacks including injection and server-side request forgery to protect our web-facing applications and APIs in our AWS  environment.

    A specific example of how I have used Imperva Managed Rules on AWS WAF  to protect our web applications and APIs occurred when we experienced an influx of traffic and investigated a possible distributed denial-of-service attack from ranges in the target environment. We were able to enable Imperva to guard against the bot attack by activating Imperva Managed Rules alongside AWS to automatically block different forms of attacks such as SQL injection, which we were simultaneously receiving. We effectively blocked SQL injection, XSS attempts, and malicious bot traffic while allowing legitimate API requests. The managed rules significantly reduced false positives compared to our earlier custom rule sets, improved visibility into attack patterns, and reduced the time our team spends analyzing.

    Beyond bot management, we use Imperva Managed Rules on AWS WAF  to protect our web application from attacks and our API. We need to defend against different attack patterns, and we leverage the popular patterns specified by OWASP Top 10 for API protection. We use Imperva Managed Rules on AWS WAF  to provide third protection across multiple AWS workloads, supporting our compliance and helping us to rapidly respond to newly discovered vulnerabilities through managed rules without having to develop and deploy custom rules.

    My advice to others looking into using Imperva Managed Rules on AWS WAF would be to start by deploying the managed rules in a monitoring or count mode before enforcing them to identify false positives and tune policies based on your application's normal traffic. Additionally, combining managed rules with application-specific custom rules for comprehensive logging and monitoring, and regularly reviewing logs to optimize protection would be beneficial. Finally, keep the managed rule updates enabled to benefit from the latest threat intelligence while periodically validating that rules do not adversely affect legitimate traffic.

    What is most valuable?

    Some of the best features that Imperva Managed Rules on AWS WAF offers include continuous updates to managed rules, providing rapid protection against emerging threats without manual rule deployment. It also includes coverage of OWASP Top 10 and other common web attacks, going beyond that by covering bot and malicious IP detection that helps reduce automated attacks and credential stuffing attempts. Additionally, it integrates well with AWS WAF , making deployment and management straightforward within the AWS environment. We reduce the effort required to create and tune custom rules while maintaining strong protection, along with good visibility and logging which enables us to analyze attack patterns, tune policy, and respond to incidents more effectively.

    Continuous updates with Imperva Managed Rules on AWS WAF make deployment and management straightforward within the AWS environment, helping us configure things easily. The continuous updates enable our team to not have to constantly create and maintain custom signatures for newly disclosed vulnerabilities. Since Imperva released updated managed rules, we can apply protection much faster, reducing our exposure window while minimizing operational effort. AWS WAF  integration has also simplified our operations; we manage protection within our existing AWS security workflows, making it easier to deploy rules updates across our multiple applications, and it helps us monitor events through AWS logging and monitoring services.

    Since we started using Imperva Managed Rules on AWS WAF, the biggest positive impact has been stronger application security with less operational overhead. We have been able to block common web attacks more consistently and reduce false positives through rule tuning, responding more quickly to emerging threats via managed rules updates. This has improved the reliability of our security protections and allowed my security team to focus on more proactive security activities instead of continuously maintaining custom WAF rules.

    We have seen a number of metrics since deploying Imperva Managed Rules on AWS WAF. For instance, we have not encountered any breaches or attacks due to our web applications. We have also been able to reduce or stop some attack patterns and observed approximately a 40 to 50% reduction in the time we spend maintaining and updating WAF rules, as much of that work is handled through Imperva Managed Rules on AWS WAF updates. We have seen faster response to newly disclosed web application vulnerabilities, fewer false positives after tuning, and successful compromise of internal patient data has been noted due to the attack attributed earlier. This has enabled our team to focus more on proactive security initiatives rather than routinely managing the WAF.

    What needs improvement?

    Imperva Managed Rules on AWS WAF can be improved in several ways. First, better rule transparency would be beneficial, with more detailed explanations of why specific requests are blocked and what rules are designed to detect. More granular tuning options to reduce false positives without requiring custom exceptions would be helpful, as well as improved reporting and analytics. A richer dashboard that highlights attack trends, rule effectiveness, and actionable recommendations would enhance the overall experience.

    It would also be beneficial for Imperva Managed Rules on AWS WAF to have faster customization workflows, making it easier to test, deploy, and validate rule changes across different environments. Enhanced API-specific protection and visibility, particularly for modern REST and GraphQL APIs, with more detailed insights into API attack patterns and recommendations, would also improve usability.

    I rated Imperva Managed Rules on AWS WAF an eight out of ten because it provides strong security value and is reliable in production, but there is still room for improvement in usability and visibility. To rate it nine out of ten, I would like to see more detailed explanations of rule matches and blocking decisions to simplify troubleshooting, more granular policy tuning and exception management to reduce false positives, a richer dashboard, and actionable insights on threats and rule effectiveness.

    For how long have I used the solution?

    I have been using Imperva Managed Rules on AWS WAF for the past five years.

    What do I think about the stability of the solution?

    Imperva Managed Rules on AWS WAF is stable.

    What do I think about the scalability of the solution?

    The scalability of Imperva Managed Rules on AWS WAF is good, and I would rate it nine out of ten, as it deploys through AWS WAF and scales well with our cloud-native applications and APIs without requiring additional infrastructure.

    How are customer service and support?

    My experience with customer support has been positive.

    Which solution did I use previously and why did I switch?

    Before adopting Imperva Managed Rules on AWS WAF, we primarily relied on native AWS managed rules combined with internally developed and deployed AWS WAF rules. We switched because we wanted broader threat coverage and more frequent managed rules updates driven by threat intelligence.

    What was our ROI?

    We have seen a significant return on investment from Imperva Managed Rules on AWS WAF. We have been able to reduce the time spent maintaining and updating our WAF by 50%, achieved faster responses to newly disclosed vulnerabilities with no need for additional headcounts to manage the WAF, resulting in low incident investigation effort and reduced operational costs. The total cost of ownership is very reasonable.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is positive.

    Which other solutions did I evaluate?

    We evaluated other options before choosing Imperva Managed Rules on AWS WAF, including F5, Cloudflare , and Akamai .

    What other advice do I have?

    Regarding Imperva Managed Rules on AWS WAF's AI capabilities, I rate its governance and security as good, although it is still evolving. The platform does a strong job of using threat intelligence and automated rule updates to protect against common web attacks, reducing manual effort and improving response to emerging threats. However, when it comes to AI-specific governance, such as protecting AI applications and LLMs, particularly in detecting prompt injections, monitoring AI-specific user patterns, and enforcing AI usage policies, it is not yet as advanced as dedicated AI security tools. Overall, its AI capabilities are valuable for enhancing traditional web application security, but organizations deploying generative AI or AI-powered APIs may need additional AI security controls and governance solutions alongside Imperva Managed Rules on AWS WAF.

    I would describe the accuracy and reliability of Imperva Managed Rules on AWS WAF as good, and rate it an eight out of ten because the managed rules are generally effective at identifying and blocking common web attacks with relatively low false positives.

    Overall, Imperva Managed Rules on AWS WAF is a strong solution for organizations running their web applications and APIs on AWS. It provides solid protection against common web attacks, reduces the operational burden of maintaining WAF rules, and benefits from regular threat intelligence updates. My overall rating for this solution is eight out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2795739

    Protection has reduced web attacks and now blocks malicious traffic before it reaches our sites

    Reviewed on Jul 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Imperva Managed Rules on AWS WAF  is to control the website under the WAF . A specific example of how I use Imperva Managed Rules on AWS WAF  to control my website is that we brought all our websites under the WAF  where all traffic should go through this WAF.

    What is most valuable?

    The specific feature that stood out to me when I used Imperva Managed Rules on AWS WAF was threat detection. Imperva Managed Rules on AWS WAF has positively impacted my organization by allowing us to reduce attacks. I noticed a reduction in successful attacks, so whenever there is any attack, we receive an alert, and the attacker is unable to reach the destination, allowing us to block them initially.

    What needs improvement?

    The settings available with Imperva Managed Rules on AWS WAF are fine and I find it good. The reporting can improve a little bit with Imperva Managed Rules on AWS WAF.

    For how long have I used the solution?

    I have been working in my current field for one year, with a total of 15 years of experience. I have been using Imperva Managed Rules on AWS WAF for three years.

    What do I think about the stability of the solution?

    Imperva Managed Rules on AWS WAF is stable.

    What do I think about the scalability of the solution?

    The scalability of Imperva Managed Rules on AWS WAF is good.

    How are customer service and support?

    The customer support for Imperva Managed Rules on AWS WAF is good with no issues.

    Which solution did I use previously and why did I switch?

    I am not using other solutions, so I did not previously use a different solution before Imperva Managed Rules on AWS WAF.

    How was the initial setup?

    I purchased Imperva Managed Rules on AWS WAF through the AWS Marketplace .

    What about the implementation team?

    I was not involved in the cost negotiation for Imperva Managed Rules on AWS WAF, so I apologize for not being able to answer about pricing, setup cost, and licensing.

    What was our ROI?

    I have seen a return on investment in terms of time saved since using Imperva Managed Rules on AWS WAF. The biggest time savings I noticed were in the investigation and attack surface as the attacks have been reduced, and we were able to bring down the attacks which previously consumed time during investigations.

    Which other solutions did I evaluate?

    Before choosing Imperva Managed Rules on AWS WAF, I evaluated AWS  native WAF as another option.

    What other advice do I have?

    My advice for others looking into using Imperva Managed Rules on AWS WAF is that they should conduct a proof of concept and should be able to buy the product based on their use case. I gave this review a rating of eight.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Goutham R

    Web security has blocked abusive API traffic and protects multiple sites from common attacks

    Reviewed on Jul 01, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Imperva Managed Rules on AWS WAF  is protecting many websites that come through Imperva WAF .

    A specific example of how I use Imperva Managed Rules on AWS WAF  with our websites is a recent scenario where our API was getting abused. I configured rules to rate limit the API, implement country-wise protection, and apply IP reputation protection policies, focusing on API endpoint protection. Based on requirements, I fine-tune those policies.

    The basic WAF  setup is in place where WAF protection is enabled for our websites and applications.

    What is most valuable?

    The best feature Imperva Managed Rules on AWS WAF offers is the WAF itself, which covers the top ten OWASP attacks.

    This coverage includes bot protection, SQL injection, and cross-site scripting, and everything it covers works very well.

    Imperva Managed Rules on AWS WAF has positively impacted our organization because we were able to protect our websites and rectify the open attack and abuse attack that was occurring.

    In terms of impact, we saw the attack pattern reducing on one of our services that was affected, and the billing for that service was high due to this attack. Imperva WAF policies have reduced that billing, and we can see the logs showing effective blocking.

    What needs improvement?

    Imperva Managed Rules on AWS WAF could improve by adding more parameters. There are other add-on features that come with it, such as advanced bot protection, because the normal feature does not provide good fingerprinting for bots. Advanced bot protection brings in real fingerprinting, and I believe the default mode should also have better fingerprinting for detecting bots.

    Additionally, reporting is not very strong in Imperva. I use reporting with data collected from Imperva to our SIEM  and make reports based on that data. Imperva reporting should be more advanced and include more metrics.

    For how long have I used the solution?

    I have been using Imperva Managed Rules on AWS WAF for six months.

    What do I think about the stability of the solution?

    Imperva Managed Rules on AWS WAF is stable.

    What do I think about the scalability of the solution?

    Imperva Managed Rules on AWS WAF has good scalability. It is scalable, and we can fine-tune based on the metrics.

    How are customer service and support?

    Customer support for Imperva Managed Rules on AWS WAF is very good.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    Regarding the features, we have integrated our Imperva with the solution. Integration is straightforward, and the data we get from Imperva is very good, allowing us to do extensive SOAR  automations where we can perform more monitoring and blocking. Ease  of use is straightforward.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is very good.

    Which other solutions did I evaluate?

    I did not evaluate many options before choosing Imperva Managed Rules on AWS WAF. This was suggested by my ops team, and I proceeded with that recommendation.

    What other advice do I have?

    Imperva Managed Rules on AWS WAF lacks direct access to the real instance behind it because it is a cloud service, and troubleshooting through that does not give us full visibility. We need to reach out to Imperva to see what is really happening behind it.

    Regarding Imperva Managed Rules on AWS WAF's AI capabilities, I believe its governance and security are top tier, with excellent governance and compliance aspects in place. Based on the logs, I can see the top ten OWASP attack patterns, and it blocks threats effectively.

    The accuracy and reliability of output for Imperva Managed Rules on AWS WAF are top-notch.

    My advice for others looking into Imperva Managed Rules on AWS WAF is to look into an on-premises solution rather than going with a cloud deployment.

    I would rate Imperva Managed Rules on AWS WAF an eight out of ten overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Indikad IS

    Improved bot defense has strengthened application security but needs deeper, AI-driven controls

    Reviewed on Jun 16, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Imperva Managed Rules on AWS WAF  is using Layer 7 particular OWASP 10 and SP10 based security rules. I had to enable the Layer 7-based attacks by setting up bots and related configurations, so that was the primary case. On WAF , I set up those rules for the particular finance application security part.

    Imperva Managed Rules on AWS WAF  has helped my finance application specifically by allowing us to identify bots and adapt to attacks that were changing over time. Once I identified Imperva's product capability and set up those rules, I was able to rectify the attacks that I was not able to prevent with previous products.

    What is most valuable?

    In my opinion, the best features Imperva Managed Rules on AWS WAF  offers include malicious bot detection and app-specific protections. I have seen that the malicious bot detector was able to identify the changing nature of the attack, helping me manage it from Imperva.

    Imperva Managed Rules on AWS WAF has positively impacted my organization by addressing trust issues my customer had regarding security configuration for their application. My customers expected us to be consultants, and unfortunately, previous products did not have that capability. Imperva's ability to identify the best configuration was amazing.

    Regarding positive outcomes after switching to Imperva Managed Rules on AWS WAF, I have control over security incidents and have seen a decrease in incidents. This helped improve the trustworthiness with the customer, along with improved application reliability and stability. These are the proactive and positive results based on my scenarios with Imperva.

    What needs improvement?

    For improvement, it would be better to have access to deeper configuration levels in Imperva Managed Rules on AWS WAF. For example, if my application is using Nginx or a certain middle-level application tool with different runtimes and middleware products, I would want to go to a more granular level to help fix vulnerabilities at the best level.

    In terms of needed improvements, I think integrating AI with knowledge bases and adding SRE configurations for an agentic approach would benefit my resolution part, especially since I work on applications that need immediate protection. Improvements in agentic-based resolution to minimize MTTR on SRE and AI-enabled documentation finding would be a great approach to develop.

    Regarding the governance and security of Imperva Managed Rules on AWS WAF's AI capabilities, I see the security in application security as present, but there does need to be improvement in governance. I have to manage uploads and downloads when using applications like the Inland Revenue Department for document scanning.

    What do I think about the stability of the solution?

    Imperva Managed Rules on AWS WAF is stable and provides an improved approach.

    What do I think about the scalability of the solution?

    Imperva Managed Rules on AWS WAF scalability is a key point, as it works properly with my application running on microservices, allowing it to manage legitimate, scalable traffic with WAF configurations.

    How are customer service and support?

    I had very few incidents requiring customer support for Imperva Managed Rules on AWS WAF. Before that, I was able to manage most issues myself. Although I don't have extensive experience, the level of support I received during the incidents was very much supportive.

    I would rate customer support as an eight on a scale of one to ten.

    How was the initial setup?

    When it comes to configuring and managing malicious bot detection and app-specific protections, the configuration was not an issue, although I had to run it on a few cycles. I set it up and it was not the proper configuration in the first phase. In the second phase, I added a few additional configurations with several application attributes that helped me protect the application properly. Fine-tuning the rules required work in a few phases, but overall, the configuration was smooth.

    What other advice do I have?

    I wanted to add timestamps of bot-based activity, as I don't want unwanted latency for my applications, but I also require security. If I could configure timestamp-based rules to identify the particular configuration, that would be a better approach.

    I rate Imperva Managed Rules on AWS WAF a seven on a scale of one to ten, as I believe there is room for improvement. When comparing it to the previous WAF product, Fortinet, I would give Fortinet around three marks.

    I chose seven specifically due to my experience managing applications and the high standard of behavior management from Imperva, particularly in managing the behavioral changes of Layer 7 attacks through malicious bot protection, which is the key reason for my rating of seven.

    My advice for others looking into using Imperva Managed Rules on AWS WAF is to focus on security since application security is critical. I cannot compare the product cost with others because a single incident can result in significant losses. Choosing the best product with the capability of protecting your application is essential. Imperva with AWS WAF  configuration enables a high level of global availability of WAF settings that help manage many security challenges.

    Before concluding, I would say there should be a focus on the governance aspect of Imperva Managed Rules on AWS WAF, as applications have many integrations with other systems. Compromising another application could challenge my application, so managing other integrations effectively in governance would be beneficial. My overall rating for Imperva Managed Rules on AWS WAF is seven out of ten.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Ayodeji Bayo-Makinde

    We have strengthened web threat protection and now focus our small team on higher‑value security work

    Reviewed on Jun 13, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I use Imperva Managed Rules on AWS WAF  in front of AWS WAF  to extend the native capabilities, leveraging Imperva's threat intelligence and web application security expertise to provide pre-configured protections against common web attacks while also helping to reduce operational burden on the team.

    Recently, we worked on creating a payment gateway, and we used Imperva Managed Rules on AWS WAF  to help stop threats such as SQL injection, cross-site scripting, command injection, local file inclusion, and path traversal, essentially all OWASP threats.

    You can also use the WAF  policy with Application Load Balancers , CloudFront distributions, and API Gateway endpoints on AWS , with most deployments being able to be completed in a few hours.

    Imperva Managed Rules on AWS WAF  is a very good tool, but you need to consider your use case, as it is well-suited for healthcare systems, financial applications, organizations with small security teams, those trying to improve compliance, and public-facing web applications exposed to the internet. However, if you have internal-only applications or small websites with minimal risk, and if your organization requires full control over detection rules, Imperva Managed Rules on AWS WAF would not work, and you must be willing to tune the WAF behavior even after deploying Imperva, or it will not work for you.

    What is most valuable?

    I use Imperva Managed Rules on AWS WAF because they have a rapid response to newly discovered attack techniques, and it is quickly updated, reducing the need for our internal security teams to create custom rules.

    Imperva Managed Rules on AWS WAF offers continuous threat intelligence updates as the best feature, as they have a rapid response to newly discovered attack techniques and base their detection logic on real-world threat data with easy integration with AWS .

    It has greatly reduced operational overhead, because without Imperva Managed Rules on AWS WAF, we would have to dedicate a team to analyze traffic attacks, write custom WAF rules, test the rules, and then maintain signatures. Imperva Managed Rules on AWS WAF helps to handle much of this maintenance work and allows our teams to focus on higher priorities.

    What needs improvement?

    Imperva Managed Rules on AWS WAF can usually have false positives sometimes, blocking legitimate traffic and struggling with complex search queries, particularly with large JSON requests and certain GraphQL requests, which makes us initially deploy the rules in monitoring mode before switching to blocking mode to ensure all our use cases are supported.

    Because the rules of Imperva Managed Rules on AWS WAF are vendor-managed, the detection methods are not fully transparent, and our security teams cannot inspect every signature, leading to troubleshooting that usually requires vendor documentation, which can make it a bit difficult.

    Imperva Managed Rules on AWS WAF is quite good for what it is, but it is still not suitable in some use cases such as internal-only applications, and if your organization requires full control over every detection rule, it does not work. Additionally, you need to tune the WAF behavior after deployment; it is not just a deploy and leave situation.

    For how long have I used the solution?

    I have been using Imperva Managed Rules on AWS WAF for about a year and six months.

    What do I think about the stability of the solution?

    Imperva Managed Rules on AWS WAF is fairly stable.

    What do I think about the scalability of the solution?

    On the AWS cloud, Imperva Managed Rules on AWS WAF is fairly scalable for what it is as a managed WAF rule, so I give it good marks in scalability.

    How are customer service and support?

    The customer support for Imperva Managed Rules on AWS WAF is quite good; I have used it once and received good responses. For my one experience, I would rate the customer support a nine, as it was good.

    Which solution did I use previously and why did I switch?

    I did not previously use any solution.

    How was the initial setup?

    I did purchase Imperva Managed Rules on AWS WAF through the AWS Marketplace .

    Which other solutions did I evaluate?

    I did evaluate F5 and Fortinet also before choosing Imperva Managed Rules on AWS WAF.

    What other advice do I have?

    I have not really made use of the AI capabilities of Imperva Managed Rules on AWS WAF, but from what I have heard from others, it seems it is quite standard for the market.

    For my end, the cost of Imperva Managed Rules on AWS WAF might sometimes be a bit high, making it not suitable for small websites with minimal risk because the cost outweighs the benefits in that case. However, for a big e-commerce platform or payment gateway, it is definitely a worthwhile investment.

    I can definitely speak to the fewer employees needed because the time and effort it would take to dedicate engineers or resources to create custom WAF rules is cut out by using Imperva Managed Rules on AWS WAF.

    I would rate this solution an eight overall.

    View all reviews