Try our new research platform with insights from 80,000+ expert users

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

AWS WAF is easy to deploy and configure, taking minimal time for initial setup.
The scalability of AWS WAF meets various requirements by automatically adjusting resource usage.
AWS WAF provides valuable security features, effectively blocking threats and protecting against database injections and scripting attacks.
The integration with AWS allows AWS WAF to offer cloud-native security, leveraging existing infrastructure seamlessly.
AWS WAF offers customizable rules and managed tools to create specific security measures, including geo-restriction denials.

CONS

AWS WAF needs improvement in automated rule management and threat detection capabilities.
Cost management and billing structure for AWS WAF could be more intuitive, especially around the tagging system.
Additional documentation and transparency are needed for AWS WAF, particularly for new features and updates.
There is a need for enhanced DDoS protection and advanced security features in AWS WAF.
AWS WAF requires better integration with third-party solutions and more flexible management of security rules.
 

AWS WAF Pros review quotes

VS
Aug 5, 2020
This product supplies options for web security for applications accessing sensitive information.
Adrian Milea - PeerSpot reviewer
Aug 3, 2022
The agility is great for us in terms of cloud services in general.
it_user1376373 - PeerSpot reviewer
Jul 5, 2020
AWS has flexibility in terms of WAF rules.
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.
RG
Nov 11, 2020
The access instruction feature is the most valuable. This is what we use the most.
reviewer1530864 - PeerSpot reviewer
Jan 11, 2022
As a basic WAF, it's better than nothing. So if you need something simple out of the box with default features, AWS WAF is good.
Kavin Kalaiarasu - PeerSpot reviewer
Oct 13, 2022
I believe the most impressive features are integration and ease of use. The best part of AWS WAF is the cloud-native WAF integration. There aren't any hidden deployments or hidden infrastructure which we have to maintain to have AWS WAF. AWS maintains everything; all we have to do is click the button, and WAF will be activated. Any packet coming through the internet will be filtered through.
AshishGautam - PeerSpot reviewer
Dec 27, 2023
The product's initial setup phase was very simple.
NetworkAf67c - PeerSpot reviewer
Mar 11, 2019
The most valuable feature is the security, making sure that files are protected, preventing unauthorized users from accessing the system.
Sita Thomas - PeerSpot reviewer
Nov 27, 2024
One of the most valuable features of AWS WAF is its ability to filter web app traffic, allowing us to specify conditions such as IP addresses and HTTP headers.
KO
Aug 9, 2023
The most valuable feature is that it is very easy to configure. It just takes a couple of minutes.
 

AWS WAF Cons review quotes

VS
Aug 5, 2020
The technical support does not respond to bugs in the coding of the product.
Adrian Milea - PeerSpot reviewer
Aug 3, 2022
For uniformity, AWS has a well-accepted framework. However, it'll be better for us if we could have some more documented guidelines on how the specific business should be structured and the roles that the cloud recommends.
it_user1376373 - PeerSpot reviewer
Jul 5, 2020
When users choose the free service, there isn't great support available to them.
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,020 professionals have used our research since 2012.
RG
Nov 11, 2020
It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful. It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one. Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right.
reviewer1530864 - PeerSpot reviewer
Jan 11, 2022
We don't have much control over blocking, because the WAF is managed by AWS.
Kavin Kalaiarasu - PeerSpot reviewer
Oct 13, 2022
It would be better if AWS WAF were more flexible. For example, if you take a third-party WAF like Imperva, they maintain the rule set, and these rule sets are constantly updated. They push security insights or new rules into the firewall. However, when it comes to AWS, it has a standard set of rules, and only those sets of rules in the application firewalls trigger alerts, block, and manage traffic. Alternative WAFs have something like bot mitigation or bot control within the WAF, but you don't have such things in AWS WAF. I will say there could have been better bot mitigation plans, there could have been better dealer mitigation plans, and there could be better-updated rule sets for every security issue which arises in web applications. In the next release, I would like to see if AWS WAF could take on DDoS protection within itself rather than being in a stand-alone solution like AWS Shield. I would also like a solution like a bot mitigation.
AshishGautam - PeerSpot reviewer
Dec 27, 2023
The area of reporting in the product needs to have a proper format.
NetworkAf67c - PeerSpot reviewer
Mar 11, 2019
They have to do more to improve, to innovate more features. They need to increase the security. It has to be more active in detecting threats.
Sita Thomas - PeerSpot reviewer
Nov 27, 2024
I find the documentation somewhat complex to implement during the initial stages.
KO
Aug 9, 2023
There is room for improvement in pricing.