Arbor DDoS vs F5 BIG-IP Advanced Firewall Manager (AFM) comparison

Cancel
You must select at least 2 products to compare!
NETSCOUT Logo
7,887 views|5,587 comparisons
94% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Arbor DDoS and F5 BIG-IP Advanced Firewall Manager (AFM) based on real PeerSpot user reviews.

Find out in this report how the two Distributed Denial of Service (DDOS) Protection solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
To learn more, read our detailed Arbor DDoS vs. F5 BIG-IP Advanced Firewall Manager (AFM) Report (Updated: March 2024).
768,246 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The technical support of Arbor DDoS is good.""The stability is okay and we have not encountered problems with the solution.""The solution provides good protection against volumetric DDoS attacks.""Analytics and its attack mitigation capabilities are valuable features of the solution.""The quality of the technical support provided by Arbor DDoS is premium.""We can reduce the bandwidth to minimize the attack level. If we see more than 2.5 GBs we drop it directly.""Our customers are very happy when we provide them with the interface... They can check how many attacks they have faced and how many attacks have been blocked.""The product allows us to check real-time progress, including latency and network activities."

More Arbor DDoS Pros →

"The most valuable feature of F5 BIG-IP AFM is all of my workers enjoy using it.""The decryption is great.""The solution is very straightforward. The usability is great.""We use the solution for load balancing and WAF (web application firewall).""F5 BIG-IP Advanced Firewall Manager's most valuable feature is load balance. It is readily available and uncomplicated.""It excels in preventing downtime and maintaining application performance, which is crucial for our clients' security and operational continuity.""Its performance and ease of use are valuable.""It blocks various attacks and mitigates disasters from occurring."

More F5 BIG-IP Advanced Firewall Manager (AFM) Pros →

Cons
"The look and feel of the management console is a little old, excessively simple. If you compare it with other solutions, the look and feel of the console is like you're using technology from five or six years ago. It doesn't show all the technology that is actually behind it. It looks like an older solution, even though it is not.""Auto mitigation is a feature provided when DDoS is observed on any of link/customer (configured under auto mitigation). It automatically starts mitigation with default filters. In default filter mode, there could be an impact on the customer’s link,""An improvement to Arbor DDoS would be to make evaluation licenses and virtual machines available.""There is always room for improvement for any product or service. If we can bring in more agility when deploying services, that is definitely a scope which we can work towards. Nowadays, everything is being offered as a service model. It is not that we have to deploy the physical hardware, many things move up to the cloud, or even can be delivered in the VNS form in the customer's environment as well. So, in that space, if we can add more features to make it more seamless for customers to use and make it available through some marketplace, not only at the hyperscalers, but also for any on-prem deployment, that definitely would be a big plus.""On the application layer, they could have a better distributed traffic flow. They could improve that a bit. For network data it is very effective, but the application layer can be improved.""Arbor Pravail APS devices do not sync features or config the backup enough. This needs to be improved.""The upgrade process is mildly complex requiring treatment of the custom embedded OS separately from the application. The correlation of the underling OS to the application version can be easily missed.""Sometimes it blocks legitimate traffic. If a legitimate user is trying to access the server continuously, the product suspects that this is a DoS traffic file. That is a case where it needs to improve. It needs machine-learning."

More Arbor DDoS Cons →

"For configuring the firewall, every single vendor on the planet has pretty much the same logic when it comes to firewalls, and F5 has a completely different approach and completely different behavior.""We would have preferred to have support when we first started""Firstly, geolocation currently relies on manual updates. It has to move to automatic updates. There are no automatic updates for this feature. If some IPs, countries, or service providers move to another country, now you will be allow IPs that you previously denied. This is because you depend on the database, which doesn't update automatically. This is really a very important area that they need to improve.""F5 could provide a distributed cloud version.""It doesn't compare to next generation firewalls""Deployment times vary according to the customer. It needs to be heavily configured. You need to look and you need to observe the behavior of the traffic before you can start configuring everything. It can take time.""F5 BIG-IP Advanced Firewall Manager's pricing and technical support services need improvement.""The solution doesn't really meet our requirements for an edge firewall."

More F5 BIG-IP Advanced Firewall Manager (AFM) Cons →

Pricing and Cost Advice
  • "Start with a small license. Measure your bandwidth requirements."
  • "Because the solutions from competitors are very different, it's not easy to compare. However, the licensing from Arbor is clear and understandable and the pricing is reasonable when looking at the market, in general."
  • "As far as I know, they are the best in this sector, in DDoS protection. They know it, I know, because their service prices are too high. They provide cloud DDoS protection for ISPs, but that is also too expensive."
  • "Arbor's products are very expensive. Their competitors are cheap when compared with Arbor."
  • "I'm a technical guy. But I know it's expensive compared to its competitors. After you have the on-premise solution, for your solution to be effective you have to subscribe to an "upper level," so there's another cost. There is also a subscription to cloud services, which is another cost."
  • "Pricing is slightly on the higher side."
  • "Arbor is striking a good balance between pricing and what they deliver."
  • "The solution is a bit costly if you're a small organization, but I think it's worth the price that they are charging."
  • More Arbor DDoS Pricing and Cost Advice →

  • "It is somewhat on the expensive side although it is worth the additional cost."
  • "It's very expensive, and you pay extra for the models."
  • "F5 BIG-IP Advanced Firewall Manager (AFM) is an expensive solution. They are one of the best in the market, but the price could be cheaper."
  • "F5 BIG-IP AFM is an affordable solution. There were not any additional fees other than the standard licensing."
  • "The solution is slightly on the higher priced side."
  • "The price of F5 BIG-IP AFM is a little more expensive than other firewalls on the market."
  • "F5 BIG-IP Advanced Firewall Manager is not an expensive solution."
  • "The product is expensive."
  • More F5 BIG-IP Advanced Firewall Manager (AFM) Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Distributed Denial of Service (DDOS) Protection solutions are best for your needs.
    768,246 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:I would say if it’s an ISP that will build a scrubbing center, Netscout/Arbor is a good solution. In all other solutions, Imperva is a great choice.
    Top Answer:Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
    Top Answer:The quality of the technical support provided by Arbor DDoS is premium.
    Top Answer:As per pricing, I would not say cheap, but little higher than cheap, but not very expensive. So you can say kind of value for money solutions.
    Top Answer:If you're looking for a plain vanilla firewall or IPS, then this is a good tool. If you compare it with the next-generation firewalls, then definitely this tool is not comparable. The next generation… more »
    Ranking
    Views
    7,887
    Comparisons
    5,587
    Reviews
    12
    Average Words per Review
    353
    Rating
    8.9
    Views
    652
    Comparisons
    412
    Reviews
    11
    Average Words per Review
    379
    Rating
    8.4
    Comparisons
    Also Known As
    Arbor Networks SP, Arbor Networks TMS, Arbor Cloud for ENT
    F5 AFM, F5 Advanced Firewall Manager
    Learn More
    Overview

    Arbor Networks, the security division of NETSCOUT, is driven to protect the infrastructure and ecosystem of the internet. It is the principle upon which we were founded in 2000; and remains the common thread that runs through all that we do today. Arbor’s approach is rooted in the study of network traffic. Arbor’s suite of visibility, DDoS protection and advanced threat solutions provide customers with a micro view of their network enhanced by a macro view of global internet traffic and emerging threats through our ATLAS infrastructure. Sourced from more than 300 service provider customers, ATLAS delivers intelligence based on insight into approximately 1/3 of global internet traffic. Supported by Arbor’s Security Engineering & Response Team (ASERT), smart workflows and rich user context, Arbor’s network insights help customers see, understand, and solve the most complex and consequential security challenges facing their organizations.

    With Arbor DDoS you can automatically identify and stop all types of DDoS attacks and other cyber threats before they impact the availability of business-critical services.


    Arbor DDoS is an intelligently automated combination of in-cloud and on-premises DDoS attack protection that is continuously backed by global threat intelligence and expertise.

    Arbor DDoS Features and Benefits:

    • Global DDoS Protection: Arbor DDoS is an all-in-one solution offering carrier-agnostic, global DDoS protection that is backed by world-class security intelligence as well as industry leading DDoS protection products.
    • Worldwide scrubbing centers: Arbor DDoS offers comprehensive protection from the largest DDoS attacks.
    • Cloud Only and/or Hybrid Protection: The solution provides the flexibility to design comprehensive DDoS protection that fits your specific environment. It can be deployed as a cloud-only and/or an intelligent combination of in-cloud and on-premise DDoS protection.
    • Global Threat Intelligence: Arbor DDoS protection is continuously armed with the latest global threat intelligence from Netscout’s response team.
    • Automated DDoS Attack Detection and Mitigation: DDoS attacks can be automatically detected and routed to Arbor Cloud global scrubbing centers for mitigation.
    • Managed Services: To manage and optimize your on-premise DDoS protection, you can rely upon the industry-leading expertise of Arbor Networks.
    • Multi-layered Approach: As part of a layered approach to DDoS protection, Arbor Cloud provides in-cloud protection from advanced and high-volume DDoS attacks, all without interrupting access to your applications or services. Arbor Cloud’s automated or on-demand traffic scrubbing service defends against volumetric DDoS attacks that are too large to be mitigated on premises.

    Reviews from Real Users:

    Below are some of the many reasons why PeerSpot users are giving Arbor DDoS an 8 out of 10 rating:

    "We use it not only for DDoS detection and protection, but we also use it for traffic analysis and capacity planning as well. We've also been able to extend the use of it to other security measures within our company, the front-line defense, not only for DDoS, but for any kind of scanning malware that may be picked up. It's also used for outbound attacks, which has helped us mitigate those and lower our bandwidth costs.” - Roman L, Sr. Security Engineer at Rackspace

    "We have taken on the Arbor Cloud subscription, which is really useful because you secure yourself for anything beyond your current mitigation capacity. This is a really good feature of Arbor that is available.” - Assistant General Manager at a comms service provider

    “It is fully mitigating the attacks. We've dealt with other ones where we didn't necessarily see that. The detection is very good. It's also very simple to use. Arbor is a single pane of glass, whereas with other solutions you might have a detection pane of glass and then have to go to a separate interface to deal with the mitigation. That single pane of glass makes it much simpler." - Erik N., Product Manager, MSx Security Services at TPx Communications

    F5 BIG-IP Advanced Firewall Manager (AFM) is a high-performance, full-proxy network security solution designed to protect networks and data centers against incoming threats that enter the network. Built on F5’s industry-leading BIG-IP hardware and software platforms, BIG-IP AFM provides a scalable platform that delivers the flexible performance and control needed to mitigate aggressive distributed denial-of-service (DDoS) and protocol attacks before they overwhelm and degrade applications and infrastructure availability.

    For service providers, BIG-IP AFM IPS does even more, protecting the network edge and performing traffic inspection and protocol adherence for prevalent service provider protocols such as SS7, Diameter, HTTP/2, GTP, SCTP and SIP traffic coming into the network over UDP, TCP, and SCTP.

    Sample Customers
    Xtel Communications
    City Bank, Ricacorp Properties, Miele, American Systems, Bangladesh Post Office
    Top Industries
    REVIEWERS
    Comms Service Provider55%
    Financial Services Firm16%
    Computer Software Company10%
    Media Company6%
    VISITORS READING REVIEWS
    Financial Services Firm17%
    Computer Software Company17%
    Comms Service Provider9%
    Government7%
    REVIEWERS
    Financial Services Firm50%
    Media Company21%
    Educational Organization14%
    Computer Software Company14%
    VISITORS READING REVIEWS
    Financial Services Firm21%
    Computer Software Company18%
    Insurance Company8%
    Government6%
    Company Size
    REVIEWERS
    Small Business36%
    Midsize Enterprise21%
    Large Enterprise43%
    VISITORS READING REVIEWS
    Small Business20%
    Midsize Enterprise17%
    Large Enterprise62%
    REVIEWERS
    Small Business30%
    Midsize Enterprise22%
    Large Enterprise48%
    VISITORS READING REVIEWS
    Small Business23%
    Midsize Enterprise17%
    Large Enterprise60%
    Buyer's Guide
    Arbor DDoS vs. F5 BIG-IP Advanced Firewall Manager (AFM)
    March 2024
    Find out what your peers are saying about Arbor DDoS vs. F5 BIG-IP Advanced Firewall Manager (AFM) and other solutions. Updated: March 2024.
    768,246 professionals have used our research since 2012.

    Arbor DDoS is ranked 2nd in Distributed Denial of Service (DDOS) Protection with 46 reviews while F5 BIG-IP Advanced Firewall Manager (AFM) is ranked 7th in Distributed Denial of Service (DDOS) Protection with 21 reviews. Arbor DDoS is rated 8.6, while F5 BIG-IP Advanced Firewall Manager (AFM) is rated 8.4. The top reviewer of Arbor DDoS writes "A critical solution for security, as it includes features that can automatically detect and prevent DDoS attacks". On the other hand, the top reviewer of F5 BIG-IP Advanced Firewall Manager (AFM) writes "Straightforward setup with very good granularity and performance". Arbor DDoS is most compared with Radware DefensePro, Cloudflare, Imperva DDoS, Corero and Akamai App and API Protector, whereas F5 BIG-IP Advanced Firewall Manager (AFM) is most compared with AWS Shield and Radware DefensePro. See our Arbor DDoS vs. F5 BIG-IP Advanced Firewall Manager (AFM) report.

    See our list of best Distributed Denial of Service (DDOS) Protection vendors.

    We monitor all Distributed Denial of Service (DDOS) Protection reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.