Best WAF Solution
What do you like best about the product?
The best thing I like about Imperva WAF is that as an Administrator, it makes our life easy. If you have thousands of web applications so you don't need to integrate manually one by one. Instead, we can the scan the subnet and add the required web applications. It's only possible with Imperva.
What do you dislike about the product?
I'm not sure if it's a downside of Imperva, but I think the Solution should be but cost friendly.
What problems is the product solving and how is that benefiting you?
We have inhouse applications which are available publically to open internet. We wanted a Solution which gives us the Control as well as it prevents the attacks on applications. Imperva completely fulfills our requirement.
Recommendations to others considering the product:
As already mentioned scanning and adding the web applications is USP of Imperva WAF and not available with other Vendors. So it's very useful for Administrators.
Its work
Best set of rules for AWS WAF. Works fine.
The main problem is the speed of updating the reputation lists. Several hours pass from the moment a bot appears until it is blacklisted
Easy to use, and quick to set up.
What do you like best about the product?
Imperva makes it easy to setup, provided you know how to change the DNS settings for your site/application.
What do you dislike about the product?
License recovery is annoying. If we deploy a license count to one site, removing that site and reusing the license on another domain is difficult.
What problems is the product solving and how is that benefiting you?
DDOS protection, and blocking attempts from unfriendly IP addresses
Recommendations to others considering the product:
Make sure you have a DNS individual on your implementation team, who understands the types of records, and how to change them.
Too broad without granular controls
I really wanted to be able to use this but there doesn't appear to be any granular control, e.g the ability to include known attack IPs but exclude IPs on lists for not having reverse DNS on the IP they send mail from. In our brief examination of how the list would work (using it to count vs block) it would have been blocking clients we would have wanted to allow.
Having the ability to turn on/off specific inclusion criteria in the list, or the vendor providing various confidence level lists would allow me to possibly use this.