F5 BIG-IP Advanced Firewall Manager (AFM) vs. NETSCOUT Arbor DDoS Protection

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
F5 BIG-IP Advanced Firewall Manager (AFM)
Score 8.4 out of 10
N/A
F5 Networks offers the F5 BIG-IP Advanced Firewall Manager, a firewall software combining a number of features including DDoS, DNS security, and other protections.N/A
NETSCOUT Arbor DDoS Protection
Score 10.0 out of 10
N/A
NETSCOUT Arbor DDoS Protection security software offers protection across multiple layers of the OSI model. It provides security measures for Layer 2 (Data Link layer) through Layer 7 (Application layer), ensuring complete protection for network infrastructure.N/A
Pricing
F5 BIG-IP Advanced Firewall Manager (AFM)NETSCOUT Arbor DDoS Protection
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
F5 BIG-IP Advanced Firewall Manager (AFM)NETSCOUT Arbor DDoS Protection
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
F5 BIG-IP Advanced Firewall Manager (AFM)NETSCOUT Arbor DDoS Protection
Features
F5 BIG-IP Advanced Firewall Manager (AFM)NETSCOUT Arbor DDoS Protection
Firewall
Comparison of Firewall features of Product A and Product B
F5 BIG-IP Advanced Firewall Manager (AFM)
8.6
Ratings
0% below category average
NETSCOUT Arbor DDoS Protection
-
Ratings
Identification Technologies8.00 Ratings00 Ratings
Visualization Tools7.00 Ratings00 Ratings
Content Inspection9.00 Ratings00 Ratings
Policy-based Controls8.00 Ratings00 Ratings
Active Directory and LDAP10.00 Ratings00 Ratings
Firewall Management Console7.00 Ratings00 Ratings
Reporting and Logging8.00 Ratings00 Ratings
VPN10.00 Ratings00 Ratings
High Availability9.00 Ratings00 Ratings
Stateful Inspection9.00 Ratings00 Ratings
Proxy Server10.00 Ratings00 Ratings
Best Alternatives
F5 BIG-IP Advanced Firewall Manager (AFM)NETSCOUT Arbor DDoS Protection
Small Businesses
pfSense
pfSense
Score 9.9 out of 10
Cloudflare
Cloudflare
Score 8.7 out of 10
Medium-sized Companies
Quantum Firewalls and Security Gateways
Quantum Firewalls and Security Gateways
Score 9.6 out of 10
Cloudflare
Cloudflare
Score 8.7 out of 10
Enterprises
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Palo Alto Networks Virtualized Next-Generation Firewalls - VM Series
Score 10.0 out of 10
Akamai App & API Protector
Akamai App & API Protector
Score 8.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
F5 BIG-IP Advanced Firewall Manager (AFM)NETSCOUT Arbor DDoS Protection
Likelihood to Recommend
8.3
(0 ratings)
-
(0 ratings)
Support Rating
9.0
(0 ratings)
-
(0 ratings)
User Testimonials
F5 BIG-IP Advanced Firewall Manager (AFM)NETSCOUT Arbor DDoS Protection
Likelihood to Recommend
We were able to eliminate a firewall from our network architecture by integrating the module into our existing F5 BIG-IP Advanced Firewall Manager (AFM). This allowed us to save on tech refresh costs, since the F5 was able to handle the module without much additional strain on the device. However, if a firewall had features that the AFM lacked, then using that firewall in tandem with an F5 would be preferable.
Read full review
Good fit
  • If you receive layer 7 attacks on a regular basis targeting critical infrastructure that needs to stay up, this is a good fit in conjuction with out-of-band TMS or in-band APS. This is obviously going to be contingent on your budget.
Not a good fit
  • If you are looking to mitigate large volume attacks that are saturating your uplinks to the Internet and taking your entire network down, this (or any on-premesis solution, for that matter) is not the solution for you. Look into any external DDoS scrubbing service to let them take the blow and return only the clean traffic to you.
  • The Peakflow system has many features similar to an IPS with the ability to block traffic based on layer 7 signatures, but country code, etc and may be tempting to use this as an IDS/IPS solution. This will cause issues for a few reasons, cheif among them is that the system is not intended for permananent or indefinite mitigations. Additionally, signitures are only updated on software version upgrades.
Read full review
Pros
  • Port based controls
  • Ease of using address objects
Read full review
  • Arbor's layer 7 countermeasures are very good out of the box, but it is very easy to reconfigure values and see the impact in real-time.
  • Peakflow SP provides fairly detailed traffic analysis and breakdown for top-N data such as top talkers, top ASNs, top ports and so on. They offer "SP Insight" as a product to build in more powerful reporting on the already-collected metrics with an interface very similar to Kibana or one of its many forks. We are not licensed for that so I can't speak to its capabilities.
  • Arbor allows for a good amount of automation. Fast flood detection ensures that if pre-determined thresholds are quickly exceeded, preconfigured mitigations can be started or in the event of an extremely large volumetric attack you can trigger an Arbor Cloud (sold separately) mitigation or a remotely-triggered blackhole announcement to drop traffic to the attacked destination IP address(es) upstream.
  • ATAC (Arbor support) is very helpful. The level of support our organization maintains covers ATAC performing all update functions to all Arbor appliances - SP and TMS.
Read full review
Cons
  • More intuitive user interface
  • Better naming conventions
  • Fewer navigation steps to prevent abstraction
Read full review
  • Arbor is a highly expensive company. this was the major reason behind not going for the Arbor sightline in the first place. Although its features are good but the cost is unjustifiable.
  • The implementation and the understanding of this tool are full of complexity and perplexity.
  • I am looking forward to having a new update on it. They used to update their versions quite frequently but it's been a long time they haven’t updated or maybe it is not in their priority lists right now.
Read full review
Support Rating
F5 Advanced Firewall Manager has been a solid, strong solution to both keep our systems safe and being seamless for our end users. Most of the time, the end-user is not impacted and does not even know F5 Advanced Firewall Manager is running which is exactly what we are looking for.
Read full review
No answers on this topic
Alternatives Considered
Both F5 [BIG-IP Advanced Firewall Manager] and Radware require training as they are not easy to use. But Radware uses some configuration that needs deep learning and proper labs. From an admin's perspective, Configuration and management for F5 [BIG-IP Advanced Firewall Manager are] less. Also, the cost of implementing F5 [BIG-IP Advanced Firewall Manager] is lesser than that of Radware Alteon.
Read full review
We chose Cisco because we had past experience with some Cisco products and we were ready to invest a high cost for Cisco Secure but unfortunately it didn’t come up to our expectations and left us in despair. The speed, the price and the analytics of Cisco, everything was just average but when we moved to Arbor we came to realize that market still have some good network analytics tool.
Read full review
Return on Investment
  • Easy maintenance reduces support hours.
  • Consistent experience reduces user learning curve.
Read full review
  • Arbor is good in empower us to monitor the issues in the network.
  • We can get better traffic analytics and reports are quite detailed.
  • The price is quite high which makes it a little hard choice for us.
Read full review
ScreenShots