I did, mentioned above. Their protection works but the scrubbing is aggressive. Websockets die, some UDP protocols get mangled, you get an email saying "attack mitigated" and then you spend two hours figuring out what broke.
For HTTP/S it is fine. For anything real-time or gaming, budget for the debugging time.