So, if I were to get a WAF that also doubled as a load balancer, does anyone have any advice on a good option? I've been looking at F5, Netscaler, Fortiweb, Armorlogic, and Baracuda. I'd consider Imperva as well, but it doesn't have load balancing capabilities. Most of the reviews I've found are dated, so I'd love to hear some opinions!
Also, I have a question on implementation. Do you see problems with deploying a WAF/Load Balancer as a virtual machine on the same ESX server as the web servers? I prefer to have them as physically separate and have some concerns about putting them on the same box, but I'm not sure if I'm just over-thinking it.