TrustRadius: an HG Insights company

F5 Distributed Cloud WAF (Web Application Firewall) Reviews & Insights

Score9 out of 10

285 Reviews and Ratings

Learn More

Contact about F5 Distributed Cloud WAF (Web Application Firewall)

Please fill out the form below to get in touch.

F5

Connect with F5

What are you interested in?

Already have an account?

You hereby consent to have TrustRadius share the information supplied on this form with F5 so that F5 and TrustRadius may contact you in regard to the information requested.

Top industries

Based on 5 HG Insights installations.

Powered by

Community Insights for F5 Distributed Cloud WAF (Web Application Firewall)

Synthesised from 40 verified reviews.


Synthesised from 40 reviews | Last Published June 22, 2026


F5 Distributed Cloud WAF is primarily used by organizations to safeguard web applications and APIs, including public-facing and internal systems, against a broad spectrum of cyber threats. In TrustRadius reviews, users frequently deploy it to defend against OWASP Top 10 risks, DDoS attacks, and zero-day vulnerabilities, with many highlighting its robust security capabilities, particularly in DDoS protection and API security.

Reviewers also note the product's positive impact on business objectives through improved security posture and reduced total cost of ownership, often simplifying application security across diverse environments. However, a significant portion of reviewers, 60%, cited concerns regarding the platform's complex UI/UX and challenging policy configuration. Despite these usability challenges, overall sentiment indicates appreciation for its advanced protection and multi-environment management capabilities.


  • Robust protection against DDoS attacks and malicious traffic
  • Effective API security and discovery features
  • Simplified deployment and unified policy management across environments
  • Strong defense against OWASP Top 10 vulnerabilities and bot attacks
  • Improved security posture and reduced total cost of ownership
  • Complex and unintuitive user interface (UI/UX)
  • Challenging policy configuration and extensive tuning requirements
  • Concerns regarding cost transparency and pricing models
  • Prevalence of false positives requiring manual adjustments
  • Desire for more advanced automation and AI capabilities
What other products like F5 Distributed Cloud WAF (Web Application Firewall) have you used or evaluated?

From 40 reviews | Last Published June 22, 2026

Reviewers frequently evaluate a range of alternative or complementary solutions to F5 Distributed Cloud WAF, with Akamai products being the most commonly cited at 18% of reviews. Many users consider various Akamai offerings, including their API protection, bot management, and content delivery network services, often alongside other security tools. Imperva Application Firewall and other F5 products, such as F5 Distributed Cloud API Security and BIG-IP Advanced Firewall Manager, are each mentioned by 10% of reviewers, indicating their relevance in competitive evaluations or existing infrastructure. A similar proportion of reviewers, 10%, also referenced a broader category of Web Application Firewalls and related services, encompassing solutions from Cisco, Amazon, and CheckPoint, suggesting a diverse landscape of security considerations. Cloudflare is also noted as an alternative or complementary product by 5% of the review base. These evaluations highlight a common practice of assessing multiple vendor solutions to address web application security and related infrastructure needs.

Akamai Products

Akamai Prolexic, Akamai Edge DNS, Akamai CDN and Akamai Bot Manager

Imperva Products

Akamai App & API Protector and Imperva Application Firewall

F5 Products

F5 Distributed Cloud WAF (Web Application Firewall)

What are the 3-5 most important use cases for this product in your organization?

From 64 reviews | Last Published June 11, 2026

Reviewers predominantly identify web application security as a critical use case for this product, with 8% of reviewers highlighting its role in safeguarding web applications. This primarily involves protection against common vulnerabilities like the OWASP Top 10 and blocking malicious bots. Closely related, 5% of reviewers also emphasize the product's utility in API security, specifically for ensuring compliance with organizational policies and broader security standards. This focus on security extends to compliance and auditing requirements, which 5% of reviewers cited as an important application, particularly for organizations in regulated industries that require robust traffic segmentation. Beyond these core security functions, reviewers also noted the product's value in threat detection and alerting, with 3% appreciating its ability to centralize real-time threat identification and response. An emerging use case, mentioned by 3% of reviewers, involves integrating the product into CI/CD pipelines to facilitate DevSecOps practices and validate WAF configurations early in the development lifecycle.

Web Application Security

Protecting Web Applications from OWASP Top 10 Threats

API Security

Securing APIs to comply with policy

Compliance and Auditing

Compliance and Audit Readiness

F5 Distributed Cloud WAF (Web Application Firewall) aims to reduce the complexity of securing apps anywhere - across multiple environments including on-premises, in and across cloud providers and at the edge. How have you benefited, at all, from being able to simplify the process of securing apps?

From 40 reviews | Last Published June 22, 2026

Reviewers frequently report that F5 Distributed Cloud WAF significantly simplifies the process of securing applications, with 48% specifically highlighting this benefit. This simplification is primarily achieved through streamlined deployment and the ability to apply consistent security policies across diverse environments. A quarter of reviewers emphasize the product's unified policy management capabilities, allowing for a single, centralized platform to control security across both cloud and on-premises applications. This approach helps consolidate and simplify the management of multiple applications, ensuring a consistent security posture regardless of location. The platform's multi-environment support, noted by 13% of reviewers, enables organizations to send traffic and apply policies uniformly across various endpoints, including co-locations and different cloud providers. These efficiencies translate into considerable time savings, as cited by 13% of the reviews, by reducing the effort spent on tasks like debugging WAF policies, chasing false positives, and accelerating the deployment of new protections. Furthermore, 10% of reviewers appreciate the advanced threat protection features, particularly those leveraging AI and machine learning, which help prevent false alarms and provide granular visibility into traffic for enhanced security.

Simplified App Security

F5 Distributed Cloud WAF (Web Application Firewall) has made deploying apps and protecting them simpler and more efficient.

Unified Policy Management

Instead of coordinating firewall rules across multiple clouds, and on-prem environments manually, teams can apply one global policy via the F5 Distributed Cloud console or API.

Time Savings

I have benefited from being able to simplify the process of securing apps because I've saved a ton of time with the F5 Distributed Cloud WAF (Web Application Firewall) and bot protections'

What are some additional ways that your organization might be able to use F5 Distributed Cloud WAF (Web Application Firewall) in the future?

From 64 reviews | Last Published June 11, 2026

Reviewers anticipate leveraging F5 Distributed Cloud WAF for several strategic future applications, primarily focusing on enhancing security integration and expanding protection across their digital assets. A key area for future expansion involves deeper integration into DevSecOps pipelines and CI/CD processes, cited by 5% of reviewers, aiming to automate security testing and embed WAF capabilities earlier in the development lifecycle. Organizations also foresee utilizing the WAF for more granular release management and access control, with 3% of reviewers noting its potential to manage feature rollouts for specific user groups without altering application code, alongside pre-production testing. Furthermore, the platform is expected to extend its threat detection capabilities to protect APIs and a broader array of websites, as mentioned by 3% of reviewers, indicating a desire for comprehensive coverage. Another emerging use case, highlighted by 3% of reviewers, includes the enforcement of advanced security features such as Zero Trust Network Access (ZTNA) and the application of AI-powered adaptive security measures. These future plans collectively suggest a move towards more integrated, automated, and expansive security postures.

DevSecOps and CI/CD Integration

Integration with DevSecOps Pipelines

Release Management and Access Control

We'll attempt to tag early access users in feature rollouts, and use the waf policies to control who can hit the new routes - all without changing the app code.

API and Website Protection

threat detection, and extend protection to APIs

What are some unexpected or innovative ways that your organization has been able to use F5 Distributed Cloud WAF (Web Application Firewall)?

From 64 reviews | Last Published June 11, 2026

Organizations are leveraging F5 Distributed Cloud WAF in several advanced and innovative ways that extend beyond conventional web application firewall functions. A notable application, cited by 5% of reviewers, involves enhancing API security and management, including the enforcement of business logic and the protection of IoT API endpoints. Reviewers also describe using the platform for security training and simulation, as well as for integrating security into CI/CD pipelines, both mentioned by 3% of reviewers. Furthermore, the WAF is being utilized to secure edge AI and IoT applications, a use case highlighted by 3% of reviewers. The flexibility of the platform is also demonstrated through its application in developing custom mitigation rules, which was also noted by 3% of the review sample. These applications suggest a trend towards using the F5 Distributed Cloud WAF as a versatile security tool capable of addressing emerging threats and operational requirements across diverse IT environments.

API Security & Management

Business Logic Enforcement & Feature Flags

Security Training & Simulation

Using Voltmesh to simulate attack traffic across regions during tabletop exercises. We spun up synthetic traffic from multiple edges to test failovers, WAF rules and geo based throttling

CI/CD Integration

Auto-adaptive security using CI/CD feedback loops

What positive or negative impact (i.e. Return on Investment or ROI) has F5 Distributed Cloud WAF (Web Application Firewall) had on your overall business objectives?

From 40 reviews | Last Published June 22, 2026

Reviewers frequently report that F5 Distributed Cloud WAF positively impacts business objectives, primarily through significant enhancements to security and reductions in operational costs. A majority of reviewers, 55%, highlighted an improved security posture, citing the product's effectiveness in protecting customer data, defending against OWASP and zero-day threats, and reducing the risk of data breaches. This sentiment is reinforced by another 30% of reviewers who specifically noted general improvements in security, including strengthened cybersecurity posture and application protection. Beyond security, a substantial portion of the feedback, 28%, pointed to a positive return on investment through reduced total cost of ownership (TCO) and lower overhead costs, often attributed to the absence of hardware requirements. Furthermore, the solution is seen to accelerate business processes, with 10% of reviewers noting faster deployment and onboarding times for applications. An equal percentage of reviewers, 10%, also observed improved performance and availability, leading to increased uptime and reduced downtimes for customers. These combined benefits suggest that F5 Distributed Cloud WAF contributes to business objectives by fortifying defenses, optimizing costs, and enhancing operational agility and reliability.

Improved Security Posture

helped us in keeping our customers data safe

Improved Security

TBD, but we expect an improved security posture given policies are auto tuned based on all customers traffic rather then our internal traffic only

Reduced Costs / TCO

Lower total cost

Besides F5 Distributed Cloud WAF (Web Application Firewall), what other software do you regularly use? How likely would you be to recommend it to a friend or colleague?

From 40 reviews | Last Published June 22, 2026

Reviewers frequently mentioned a range of other software used alongside F5 Distributed Cloud WAF, indicating a diverse ecosystem of security and network management tools. The most commonly cited product was F5 BIG-IP, mentioned by 28% of reviewers, often encompassing various modules like Local Traffic Manager (LTM) and Access Policy Manager (APM). Other prominent solutions included Cloudflare and AWS WAF, each noted by 10% of reviewers, suggesting a tendency to integrate with cloud-native or CDN-based security offerings. Fortinet FortiGate and Splunk were also significant, each cited by 8% of the sample, highlighting the use of comprehensive firewall solutions and security information and event management (SIEM) platforms. Across these frequently mentioned tools, sentiment was consistently mixed, indicating that while they are widely adopted, reviewers also perceive areas for improvement or have specific use-case-dependent experiences. This suggests that organizations often leverage a combination of specialized tools to address their security and traffic management needs, with no single solution universally lauded without reservation.

F5 BIG-IP

F5 BIG-IP Local Traffic Manager (LTM)

Cloudflare

Cloudflare Zero Trust Services

AWS WAF

AWS WAF

Describe how you use F5 Distributed Cloud WAF (Web Application Firewall) in your organization. What are the business problems the product addresses and what is the scope of your use case?

From 40 reviews | Last Published June 22, 2026

F5 Distributed Cloud WAF is widely adopted by organizations primarily for safeguarding their web applications and APIs, with 68% of reviewers highlighting its role in application protection. The product is frequently deployed to secure both public-facing and internal web applications, including marketing websites, government services, and core banking systems. A significant aspect of its utility, cited by 57% of reviewers, is enhancing overall application security by defending against a broad spectrum of cyber threats, such as OWASP Top 10 risks, DDoS attacks, SQL injections, and zero-day vulnerabilities. Reviewers consistently report that the WAF effectively mitigates these threats, with 45% specifically noting its capabilities in threat blocking, geo-blocking, and rapid response to malicious activities. The scope of use cases often extends to protecting sensitive data and ensuring compliance with regulations like PCI DSS, GDPR, and HIPAA. While the primary sentiment is positive, some reviewers, representing 15% of the sample, offered mixed feedback regarding ease of use and experience, noting that initial configuration can be complex despite overall appreciation for its mobility and user experience.

Application Protection

We use F5 Distributed Cloud WAF as a critical layer of our security architecture to protect both public-facing and internal web applications.

Application Security

F5 Distributed Cloud WAF (Web Application Firewall) help us in enhacing the security of our online websites and social media pages and make our digital presence much stronger.

Threat Mitigation

but this software helps in keeping these data safe from hackers and fraudsters.

Loading Reviews List....

Video reviews