Imperva Web Application Firewall Other Advice

EG
IT Security Analyst at Banco de Fomento Angola

My advice for people considering using Imperva is that it is crucial to first define what you need from a security solution. Once their requirements are clear, you should thoroughly evaluate Imperva and its features to ensure it aligns with their needs. Based on my experience, I highly recommend Imperva and would confidently endorse this solution to others. Overall, I would rate Imperva Web Application Firewall as a nine out of ten.

View full review »
RullySaputra - PeerSpot reviewer
Technical Consultant at Truvisor

I would recommend it. Overall, I would rate the solution an eight out of ten. 

View full review »
BK
Manager for Implementation and Administration at Commercial Bank of Ethiopia

We stopped using Imperva Web Application Firewall mostly because at the time we need to upgrade our devices to the latest version. After four years, we didn't pay the license for the solution because we were updating our team solution also. After one year, when we tried to upgrade it, Imperva ask us for the last one-year license renewal and they didn't accept our devices. They wanted us to purchase the new versions for approximately $859, which was too expensive for our budget. The cost with implementation is approximately $2,000,000 because we were expected to deploy eight devices. There were other products that were cheaper and they could meet our mandatory requirements.

If companies want to use Imperva Web Application Firewall they will need to place their bids and they might have a budget for the solution it is a good solution.

I would recommend this solution to others.

I rate Imperva Web Application Firewall a nine out of ten.

View full review »
Buyer's Guide
Imperva Web Application Firewall
March 2024
Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,857 professionals have used our research since 2012.
FG
Director, Information System Security at a financial services firm with 201-500 employees

I can highly recommend Imperva WAF for financial institutions. It's a good solution and I think it's important for financial institutions, particularly those who conduct online banking, to make use of a solid WAF such as this.

I would rate Imperva WAF a nine out of ten.

View full review »
HV
Technical Consultant - Presales at a tech services company with 51-200 employees

When a client comes to us saying that they want to implement Imperva, the first thing that we ask them is if they are willing to spend that much. If they say yes, then we do not even compare it to any other product. We just go for Imperva. Feature-wise, we are confident of it. Any customer would go for it in terms of features.

Overall, I would rate Imperva Web Application Firewall a nine out of ten.

View full review »
Fairuz Zazli - PeerSpot reviewer
Lead Client Service Manager at Nexagate Sdn Bhd

We are users and also we are resellers.

The version we are using is the latest version. 

It has many valuable options or features. You just need to know what you need for your organization. If not, Imperva will probably tend to sell you almost everything. You just need to know what are the options that you need for your organization. Apart from that, the whole process is quite fast and it's quite reliable.

I'd rate the solution an eight out of ten.

View full review »
MG
Application Security Engineer at a insurance company with 10,001+ employees

My advice to anyone considering Imperva Web Application Firewall is that they can safely go to this environment without having a second thought. I have done so much testing. I did so many use cases. It never failed so far.

On a scale of one to ten, I would give Imperva Web Application Firewall a 10.

View full review »
IOANNIS  Katsaounis - PeerSpot reviewer
Solutions Architect at Uni Systems

I would rate the product a nine out of ten. I discussed with the security teams and they consider the tool a state-of-the-art product. 

View full review »
AD
Global Network and Cyber Security Project Manager at a manufacturing company with 10,001+ employees

I am very happy with this solution. I would rate the technical aspect a 10 out of 10, however because of the financial cost, I rate it an 8 out of 10.

View full review »
AT
Security Architect at a individual & family service with 1,001-5,000 employees

The solution is stable and easy to manage. I rate it a nine out of ten.

View full review »
RK
Senior Software Developer at a computer software company with 1,001-5,000 employees

We use the solution's latest version.

We have a partnership with Imperva within our company.

I'd rate the solution at a nine out of ten. We've been mostly quite happy with its capabilities.

View full review »
Sonny Bernard - PeerSpot reviewer
Security Consultant at FPG Technologies and Solutions LTD

I rate Imperva Web Application Firewall a nine out of ten.

View full review »
Claudio Colombo - PeerSpot reviewer
CTO at Sorint.Lab

I rate Imperva Web Application Firewall nine out of 10.

View full review »
Akhilesh Mishra - PeerSpot reviewer
Technical Lead at M.Tech

I do the maintenance and upgrades of the solution if it requires it. I would recommend this solution to everyone. 

I rate Imperva Web Application Firewall a nine out of ten.

View full review »
SS
Acquisitions Leader at a healthcare company with 10,001+ employees

My advice is to follow the three, two, one backup rule, this solution is very suitable for this. Make sure you are defining your mean time for recovery of the backup, and try to see that it makes the mean time.

I rate Imperva Web Application Firewall a nine out of ten.

View full review »
OS
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services

I think it's perfect. It's a very good application. When you do large-scale deployment you want to protect your physical web application with Imperva, trust me. It gives me peace of mind.

These are guys are from Israel and you should see that place. These guys are the best I have ever seen. They do all kinds of stuff and there is nothing that they cannot do. These people are incredible. They can configure and develop anything, customized, if you want it. Everything has a price, but they can do it right now. They don't have a "no."

We use Imperva with Incapsula so we have web security, we have DDoS protection, we have content delivery networking, we have load-balancing. We do everything with Incapsula cloud. For example, if you have an internet threat, that threat is trying to access your web application. Depending on the threat that you are receiving, the activity monitor is going to be triggered. Once that activity monitor gets triggered, the vulnerability management is going to defend you. It doesn't work for everything the same way. It's very intelligent.

Without tuning, it blocked 88 percent of the vulnerabilities, and when we tuned it, it blocked 98 percent. Whatever was not blocked didn't harm us. We use a third-party for tuning. We tell them what to do it and they do it. They get it done fast, sometimes in two to three days. It depends on what you're asking for. If you're asking for more accuracy, they go the distance to solve your problem. For example, the other day I had some keywords, some attack signatures that they were looking at for false-positives and false negatives, which are two different things. One of the main reasons we got Imperva is that we wanted to block attacks while limiting the number of false positives. I wanted the application scanner not to generate false positives by creating violations. I gave them the information, and the next day it was solved.

To put it in a high-level perspective, you are paying to see the things that are important, but you get a lot of noise. I wanted to reduce that noise. They allowed me to do that. 

Make sure you have the right testing methodology for Virtual Patching. If you want to take your patching to under 30 days, this is the product for you. We reduced it to five days. I think we are the only company where the patching is under five days. We are only doing it at the database-level right now. But we took it down to five days. 

There are proper ways to test a WAF, but the main advice I can give you is that you should not just generate attack traffic. The most effective method, for me, would be to generate both attack and legitimate traffic. That kind of approach will give you a way to rate the ability of the WAF to detect malicious traffic and to distinguish malicious traffic from good traffic. Provide real-world testing scenarios, in which the WAF must block attacks and avoid blocking good traffic at the same time. You will be able to measure how many false positives you're getting. That is the best way to test a WAF: Don't only to generate attack traffic.

Another piece of advice, and here I will jump  to the main fears of this environment - SQL injections, cross-site scripting, which I hate, DT's (Directory Traversals) - is that you need to provide another layer here which is IPS. IPS products will all rely on signatures. They are going to be created by the scanner to stop anything, that's just the basics of threat prevention. If these signatures are easy to circumvent, by using comments and encoding at the same time, they will be available for the WAF to stop any kind of session or cookie tampering. What I'm saying is that there should be technical attack protection. You should be thinking not only about WAF but combining WAF and IPS.

You need to find an IPS that works with it. Imperva has something similar to an IPS, it's not an IPS per se. For example, an IPS cannot detect or stop fraud malware. For that, you need to add certain other levels of security and combine it with employee training. If you get the web application, which is called SecureSphere, the WAF, it will protect you against web page fraud because they go by black IPs. So you can help the IPS on that side and the IPS can help you letting you know what to block from the internal network. You should be considering a combination of WAF and IPS.

Another thing to take into consideration for people who are starting, with respect to deploying a WAF, is that they should validate the accuracy of the solution and the ability it has to protect any application and help you with monitoring and management. It's not just technical stuff.

View full review »
RiaanDu Preez - PeerSpot reviewer
Senior Cyber Security Specialist Architect at Cyberlinx

I would definitely recommend the solution. I rate the solution an eight out of ten. 

View full review »
Anuraj Nair - PeerSpot reviewer
Presales Engineer at SNSIN

I recommend this solution to others.

I rate Imperva Web Application Firewall an eight out of ten.

View full review »
Fauzan Adhima - PeerSpot reviewer
Technical Support Engineer at PT. Sinergy Informasi Pratama

I rate Imperva Web Application Firewall a nine out of ten. 

View full review »
AA
Solutions Engineer at a tech services company with 1,001-5,000 employees

We are partners. I rate the product's integration with our client's IT infrastructure a nine out of ten. It is easily integrated since many configurations are needed to onboard Imperva into a client’s infrastructure fully. Overall, I rate the product a nine out of ten.

View full review »
Kevin Juma - PeerSpot reviewer
Technology Operations Manager, Global IT at a tech services company with 11-50 employees

I would say: take Imperva Web Application Firewall into consideration because of its simplicity. 

View full review »
MJ
SOAR Consultant at a tech services company with 1,001-5,000 employees

I'm working as a cyber security consultant and I provide Imperva Web Application Firewall and other similar solutions to customers.

We are working in the Middle East, e.g. we are deploying solutions to different organizations.

I don't have any input on the pricing for Imperva Web Application Firewall, as that part is covered by the research team.

I don't have advice for people looking into implementing this solution, except that everyone has different opinions and different requirements. Every organization has different requirements, and their choices will be based on their requirements. If all their requirements are fulfilled by Imperva Web Application Firewall, then they'll want to implement or use it.

I've giving Imperva Web Application Firewall a score of seven out of ten.

View full review »
Roi-Nahari - PeerSpot reviewer
CEO at CyberApp

Overall, Imperva is a pretty good product.

I am working with the development team for Imperva in Israel, and I have submitted some feature requests for things that I think should be changed. Everything that should be fixed, we have a discussion on it and it is probable that these things will be fixed.

My advice to anybody who is implementing this solution is to first go and learn the attack surfaces because you need to protect the assets from attack. In order to do this, you need to understand the attacks. Let's say that a good defense is a good offense.

The biggest lesson that I have learned from working with this solution is to back up the system all of the time. Do it step by step, and be very precise. Have plans for each and every move, all of the time.

I would rate this solution a nine out of ten.

View full review »
GO
Manager, IS Security & Infrastructure at Fintech Kenya Limited

This is a solution that I highly recommend.

The biggest lesson that I have learned from this solution is that Imperva is not a one-house solution. They create a specialized solution, and that comes with a lot of value.

I would rate this solution a nine out of ten.

View full review »
TC
Systems Analyst at a financial services firm with 501-1,000 employees

I rate the solution a nine out of ten. 

View full review »
DK
Technical Account Manager at a tech services company with 201-500 employees

We are resellers and we are based in Kenya. We're actually doing the whole suite. I'm working with Database Security and I'm also doing the Web Application Firewall, both of which are on-prem and on the cloud. I'm also doing the DRA.

It's the best in breed in terms of a solution you can put in place.

I'd rate the solution at an nine out of ten. We're quite happy with its overall capabilities. 

View full review »
Mitesh D Patel - PeerSpot reviewer
Senior Technical Consultant- Cyber Security at Ivalue Infosolution

Overall, I would rate the solution a nine out of ten. More and more customers are adopting web application firewalls to secure their web applications.

View full review »
VL
Manager at a tech services company with 1,001-5,000 employees

The solution is a leader in the market and is easy to use.

I rate the solution a nine out of ten. 

View full review »
SS
GA Consultant Cyber Security at a tech services company with 51-200 employees

I would rate it an eight out of 10.

View full review »
it_user577338 - PeerSpot reviewer
Sr. Consultant at a tech services company with 51-200 employees

Be prepared to obtain every piece of documentation that comes with the product. Thoroughly research it to obtain a clear understanding of how to implement the product and ensure you have a dedicated Imperva first-response engineer that can answer your questions without going through a normal support channel. Be patient when encountering a bug or a feature failure, as well as discrepancies between the product interface and/or behavior with the accompanied documentation. Their support is not prepared to jump in and start working on a fix or update the documentation.

In many cases, the documentation remains outdated referring to old releases regardless how long you’ve been asking for an update. Their instructional videos are also out of date, but references to them are consistently sent by their support whenever you may have a question. And finally, thoroughly document your deployment and license-related information, because every email to technical support is responded with an automated reply requesting this information. Not replying to this automated email with correct info will lead to further delays.

View full review »
EM
Senior Presales Engineer at a tech services company with 11-50 employees

I would rate the solution a nine out of ten. The solution is very mature and covers everything for its use cases. 

View full review »
NV
Specialist Engineer at Entel Networks S.A

I would rate the solution as an 8 out of 10, simply because of the difficulty of operation management. It's a complicated tool to keep.

View full review »
it_user255885 - PeerSpot reviewer
Senior Security Analyst at a tech services company with 501-1,000 employees

All products are good, and I believe narrowing the choice of manufacturer is best done when you do proof of concepts in-house and you can see which of your choices is best matched to your needs.

View full review »
SO
Security Engineering at a computer software company with 5,001-10,000 employees

Imperva has different three parts - the Web Application Firewall (WAF), Incapsula for cloud, and DAM for database firewalls. This is in one central monitor.

We aren't using the latest version of the solution.

We use the solution as a customer as well as an integrator.

I'd rate the solution at a ten out of ten. It's very good. We've been quite happy with its overall capabilities.

View full review »
RG
Information Security Architect at a tech services company with 1,001-5,000 employees

I'd recommend Imperva WAF as a good product in terms of occupation perspective and strong WAF. I'd rate it as seven out of ten.

View full review »
TA
Chief Information Security Consultant at V-Tech

This is a good WAF solution that I would rate a nine out of ten.

View full review »
KL
Team Lead Senior Technical Engineer at a tech services company with 51-200 employees

You should understand the customer's website, what their website is. They need to configure the ciphers properly. Many engineers are not able to complete the project because they don't understand the customer's environment. 

Before doing an implementation, understand the customer's environment. The ciphers need to be configured properly. Some Imperva engineers are not able to complete the projects because they understand the customer's environment.

Know the ciphers being used and match the ciphers. You must ensure the same ciphers are being matched in the backend load balances. If the backend load or cipher is changed the same should be replicated in Imperva as well. Once this is complete it should be good.

I would rate this solution an eight out of ten.

View full review »
it_user663045 - PeerSpot reviewer
Cyber and Information Security Officer at a energy/utilities company with 10,001+ employees

I rate it a 10 out of 10 because of the ability to apply real-time changes or creations, export and import applications learned, and it's very easy to use. It also features system logs or incidents, granular configuration in relation to a SIEM. It is the best product on the market, in my opinion. Cyber security leader.

View full review »
it_user259980 - PeerSpot reviewer
Network Security Engineer at a tech services company with 501-1,000 employees

I would say to focus on the most convenient area for positioning the WAF in order to take the get the best out of it. In my case, we chose a WAF appliance, and it’s crucial where to put it. For instance, we chose to deploy it downstream from the load balancing network infrastructure for various reasons. One of them was to enable the WAF to see the private IP addresses that a vulnerability assessment tool in the private DMZ would see in order to use the WAF as an application firewall and as a virtual patching tool either.

View full review »
BD
CTO at a tech services company with 11-50 employees

In Turkey, we mostly have on-premises deployments. There are some Azure Amazon projects, but it is mostly deployed on-premises. It is not so easy to send Incapsula solutions to Turkey.

I would recommend this solution. It is easy to manage and expand. I would rate Imperva SecureSphere Web Application Firewall a ten out of ten. 

View full review »
JT
Solution Architect at Ostec

This is a security device, and it is used almost every day. It is not just used when there is an issue. Based on what the dashboard or the reports say, you can change policies to meet your security requirements or business needs.

Based on my experience, and what I know this product can do, I would never recommend another solution. I advise most of my customers to go for this.

I would rate this solution a nine out of ten.

View full review »
Mustapha - PeerSpot reviewer
Senior Security Engineer at a agriculture with 11-50 employees

My advice to anybody who is considering this solution is that if they want a stable product with good scalability then they can choose Imperva. The price is a little bit higher than that of the competitors, which largely impacts whether customers choose Imperva. In fact, if you don't care about budget then Imperva is the only solution for an application firewall.

My only complaint is that the user interface could be better.

I would rate this solution a nine out of ten.

View full review »
TA
Chief Information Security Consultant at V-Tech

The company has to deeply work on it. Also, with regard to support for the distributor, distributors have a big problem. We got the wrong consigning. It was kept for more than three months in a customs warehouse because of the issue of the problems on the distributor side. That is a big problem.

I would rate it an eight out of ten. Imperva is good because it doesn't also only monitor but it also does acquisition.

View full review »
SK
Head of IT at a computer software company with 11-50 employees

We are an integration company, so we are providing this as a solution to other customers. They're mostly enterprise-level clients.

I would recommend the solution. I'd rate it eight out of ten.

View full review »
it_user561657 - PeerSpot reviewer
Systems & Infrastructure Architect at a insurance company with 1,001-5,000 employees

While implementation is not hard, the process and resources for ongoing management should be thought through and agreed to before implementation.

View full review »
OO
Cloud Solutions Architect at Snapnet Limited

I handle the on-premises deployment model. We have the latest version of the solution. We also sell the product.

I would rate the solution nine out of ten.

View full review »
Buyer's Guide
Imperva Web Application Firewall
March 2024
Learn what your peers think about Imperva Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
768,857 professionals have used our research since 2012.