The three mainstream WAF (Web Application Firewall, a firewall that understands web content) products all block common attacks. The difference is where that protection happens. This page does not score or rank vendors; it simply lays the scenarios out for comparison.
Akamai, F5®, and Fortinet FortiWeb all block SQL injection (smuggling malicious commands into a database through a form), cross-site scripting (XSS, injecting malicious code into a page so visitors execute it), and DDoS (distributed denial of service, flooding a site with fake traffic). The difference is not whether they can block these, but where the blocking happens. Answer the following four questions first.
None of the three options is inherently better. Each fits a different scenario. They are listed from outside in by protection point, without scoring or ranking.
Protection point: the internet edge (per vendor public data: spanning 700+ cities). Traffic is cleaned before it reaches your data center.
Equipment needed: none. Point your domain (DNS) to Akamai and you are live.
Typical customer size: medium-large and up, with high external traffic and a high cost of downtime.
Added value: global acceleration comes as a bonus; per vendor public data, 32 scrubbing centers and 20+ Tbps of defense bandwidth.
Less suitable for: low-traffic brand websites; systems whose traffic cannot leave the data center.
See Akamai deployment servicesProtection point: the perimeter of your own data center. Traffic never leaves it.
Equipment needed: on-premises requires hardware or a virtual appliance license; a cloud service is also available to extend policy.
Typical customer size: medium-large, with an in-house data center and high audit requirements.
Added value: BIG-IP® is already a load balancer in front of your servers; adding the WAF module solves both "must not go down" and "must not get breached" at once. Container environments also have NGINX®.
Less suitable for: a single website that only needs a WAF, with no load balancing or disaster recovery requirement.
See F5 deployment servicesProtection point: inside your data center or cloud VPC; a FortiAppSec Cloud (formerly FortiWeb Cloud) option is also available.
Equipment needed: available as hardware, virtual machine, container, or cloud service.
Typical customer size: small to medium, or branch and internal systems within larger enterprises.
Added value: shares a management console and logs with existing FortiGate deployments, so there is one less system to learn.
Less suitable for: very high-traffic public services that need scrubbing at global points of presence.
See Fortinet deployment servicesThe most common setup for large customers is a two-stage architecture: outer layer plus inner layer.
For customers with higher traffic, two layers are most common:
The point of a two-layer architecture is division of labor: the edge handles volume, the data center handles detail. Adding a layer does not automatically mean more security. If one layer is enough, plan for only one.
Going live is not the finish line. Rules need ongoing tuning to match how the site actually behaves, or you end up either missing attacks or blocking legitimate customers. Vendor version updates and security advisory tracking are also part of annual maintenance. See Web & API Protection (WAF) and Services for details.
We source vendor products and support through authorized channels in Taiwan, and provide planning, deployment, migration, training, and annual maintenance services. As an independent systems integrator, we make selection decisions based on your actual environment.
The assessment starts with a current-state review and follows four steps.
Related reading: solution overview and single-vendor deployment services.
Book a current-state assessment See our servicesLeave your contact details and a description of your needs, and an engineer will get in touch to help assess architecture planning, deployment approach, and annual maintenance scope.