I use AWS WAF to protect web applications and web traffic. It handles application input and throughput - typical web application firewall tasks.
Director of Security Architecture at a healthcare company with 10,001+ employees
Helps to protect web applications and web traffic but needs improvements in usability and functionality
Pros and Cons
- "We integrate AWS WAF with several platforms within cloud hosting and other security solutions and provisions in our business. Regarding AI, it's been around for about 20 years, so it's not new. It's just a new buzzword. I've been in security for 30 years and remember using AI when I started 25-30 years ago. We have multiple forms of AI within our business."
- "I'd like to see improvements in its usability and functionality. I'm also concerned about being too dependent on the cloud provider's WAF version. For security, using multiple vendors and not putting all our eggs in one basket is better."
What is our primary use case?
What is most valuable?
We integrate AWS WAF with several platforms within cloud hosting and other security solutions and provisions in our business. Regarding AI, it's been around for about 20 years, so it's not new. It's just a new buzzword. I've been in security for 30 years and remember using AI when I started 25-30 years ago. We have multiple forms of AI within our business.
What needs improvement?
We're considering replacing it shortly, so I've looked at alternatives like Aqua and others.
I'd like to see improvements in its usability and functionality. I'm also concerned about being too dependent on the cloud provider's WAF version. For security, using multiple vendors and not putting all our eggs in one basket is better.
The functionality I'd like to see improved is mainly around the applications and cloud integration elements.
For how long have I used the solution?
I have been working with the product for three years.
Buyer's Guide
AWS WAF
August 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
909,647 professionals have used our research since 2012.
What do I think about the stability of the solution?
We haven't encountered any stability issues.
What do I think about the scalability of the solution?
The solution is scalable and my company has 30,000 users.
How are customer service and support?
The solution's support is quite good and fair.
Which solution did I use previously and why did I switch?
I see several pros and cons when I compare AWS WAF to other WAF products. The main advantages are that the AWS Firewall functionality integrates well, it's easy to deploy and select, and the implementation is straightforward. The integration with AWS is also very good. However, the main drawback is that while it works well in the AWS environment, it doesn't necessarily work as well for other cloud or on-premise setups.
How was the initial setup?
The initial setup of the AWS WAF solution always has complexities, regardless of which solution you choose. Our organization is multi-tenant, multi-hosted, multi-cloud, multi-located, and international, so we always face challenges during implementation. No matter how good the product is, there will always be challenges.
For implementation, we usually follow a TOGAF model for project planning. Sometimes, we use a waterfall approach, but we stick to TOGAF mostly. Some parts of the business use Agile, but I don't typically use Agile for WAFs.
From a maintenance perspective, AWS WAF isn't any more difficult to maintain than other solutions. I've had experience with nearly all the WAFs out there, and they're all pretty much the same in terms of maintenance, regardless of the service provider.
What other advice do I have?
I rate the overall solution a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Architect at Vodworks
Offers a highly configurable rules system and solid stability
Pros and Cons
- "The most valuable feature of AWS WAF is its highly configurable rules system."
- "One area for improvement in AWS WAF could be the limitation on the number of rules, particularly those from third-party sources, within the free tier."
What is our primary use case?
AWS WAF is primarily used to prevent intrusion into web applications. You can also use it to protect virtual machines within the AWS cloud. The main process involves creating rules to block common threats like SQL injection and cross-site scripting. These rules can be selected from built-in options. After configuring the firewall settings, you create a target group and attach your web application to it. The firewall filters incoming traffic based on the selected rules, blocking any suspicious activity.
What is most valuable?
The most valuable feature of AWS WAF is its highly configurable rules system. You can set up rules based on specific criteria like SQL injection, general web threats, and even advanced features like DDoS protection and region-based blocking. The richness of available rules, including options for custom rule configurations from third-party partners, enhances its effectiveness.
What needs improvement?
One area for improvement in AWS WAF could be the limitation on the number of rules, particularly those from third-party sources, within the free tier. Users may face budget constraints when trying to implement additional rules beyond the free tier limit.
What do I think about the stability of the solution?
AWS WAF is stable, but I haven't tested it extensively with high request volumes.
What do I think about the scalability of the solution?
In our IT organization, the usage of AWS varies by project, with approximately 50-60% of projects using AWS or Cloudflare. For our internal websites like BroadWorks.com, we use Cloudflare, while for client projects, about 60-70% make use of AWS WAF.
How was the initial setup?
Setting up AWS WAF for initial installation was relatively straightforward, even for someone without extensive DevOps experience like myself. While it wasn't overly complex, it also wasn't overly simple. With the help of AWS documentation and resources, I was able to complete the setup within two to three days.
What's my experience with pricing, setup cost, and licensing?
Whether AWS WAF is worth the monthly investment of $50 to $60 depends on your budget and preferences. While AWS WAF offers robust features, there are also free tools available like ModSecurity that require more configuration but can still provide adequate protection.
Which other solutions did I evaluate?
While AWS is a top choice, Cloudflare is also considered for smaller projects due to pricing. Overall, AWS WAF offers reasonable features compared to competitors like Cloudflare, GCP, and Azure.
What other advice do I have?
Before using AWS WAF for the first time, it is important to consider where your infrastructure is hosted and where you want to implement the firewall. If you are already on AWS, AWS WAF would naturally be a suitable choice. Determine the level of security required based on your application's domain, such as financial applications needing more stringent security measures. Select appropriate rules for your use case, considering both conventional web rules and AWS Shield for critical applications. Additionally, after setting up AWS WAF, conduct thorough testing using vulnerability scanners like ThoughtSpot, Acunetix, or Nessus to ensure the effectiveness of your setup.
For beginners with around six months to a year of AWS experience, learning to use AWS WAF shouldn't be too difficult. However, integrating it with web applications across different cloud platforms might pose some challenges. Overall, experienced AWS users should find it manageable, while beginners may need some time to get used to it.
Overall, I would rate AWS WAF as a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
AWS WAF
August 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
909,647 professionals have used our research since 2012.
Manager, Engineering at a retailer with 10,001+ employees
A highly stable solution that helps mitigate different kinds of bot attacks and SQL injection attacks
Pros and Cons
- "AWS WAF helps mitigate different kinds of bot attacks and SQL injection that happen within the retail industry."
- "The solution's pricing could be improved."
What is our primary use case?
We use AWS WAF to protect our application from different kinds of attacks. We use AWS WAF for retail customers.
What is most valuable?
Our retail application is vulnerable to a lot of bot attacks. AWS WAF helps mitigate different kinds of bot attacks and SQL injection that happen within the retail industry.
What needs improvement?
The solution's pricing could be improved. You cannot add multiple rules within AWS WAF's CPU.
For how long have I used the solution?
I have been using AWS WAF for more than three years.
What do I think about the stability of the solution?
Since AWS manages the solution, it is fairly stable.
I rate AWS WAF a nine out of ten for stability.
What do I think about the scalability of the solution?
AWS WAF is a scalable solution.
I rate AWS WAF an eight out of ten for scalability.
How are customer service and support?
I am satisfied with the solution’s technical support.
How would you rate customer service and support?
Positive
How was the initial setup?
On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup an eight out of ten.
What about the implementation team?
The solution's deployment takes a few minutes.
What's my experience with pricing, setup cost, and licensing?
There is no licensing at all. We have to pay for it as we use it.
On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven or eight out of ten.
What other advice do I have?
Integrating AWS WAF with other AWS services in our infrastructure is fairly easy. There are different tools through which we can do it.
AWS WAF is a fairly easy solution. Users need to build a few rules by themselves based on the vulnerability attack within the application.
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
A stable and reasonably priced solution that protects organizations from hackers and other security threats
Pros and Cons
- "If hackers try to insert bugs, the tool blocks it."
- "It will be helpful if the product recommends rules that we can implement."
What is our primary use case?
We use the product to protect the environment from DDoS and SQL injection attacks. We implement WAF in the public site.
What is most valuable?
WAF filters based on IPs. If hackers try to insert bugs, the tool blocks it.
What needs improvement?
Google uses an AI tool to provide insights about rules. It will be helpful if the product recommends rules that we can implement.
For how long have I used the solution?
I have been using the solution for six years.
What do I think about the stability of the solution?
The tool is stable.
What do I think about the scalability of the solution?
AWS takes care of the product's scalability, security, and performance. We do not have to maintain it.
Which solution did I use previously and why did I switch?
Google’s console is minimalistic. It provides AI tools that help us create rules.
How was the initial setup?
The deployment is very easy. It takes around five minutes. WAF plays an important role in the network. We need to implement WAF in the first level of security. We can implement it with the help of a console. We need one person to deploy the tool.
What's my experience with pricing, setup cost, and licensing?
We pay $0.8 per hour. The product’s pricing is reasonable.
What other advice do I have?
When we faced a DDoS attack before, we were not able to find the logs to identify the source of the attack. People who want to use the solution must have a basic knowledge about different attacks. Using the solution is easier if we know how the attacks happen. Overall, I rate the product a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
The product is stable, scalable, and easy to deploy, but the default content policy of the tool is not very strong
Pros and Cons
- "The ease of deployment of the product is valuable to me."
- "The default content policy available in the tool is not very strong compared to the competitors."
What is our primary use case?
The solution protects my customers’ web applications hosted in AWS.
What is most valuable?
The ease of deployment of the product is valuable to me. AWS WAF might be one of the easiest WAFs that can be deployed. The only constraint is that our application must be running in AWS.
What needs improvement?
The default content policy available in the tool is not very strong compared to the competitors. Most of the WAFs will have a default set of policies and rules that we need to enable, which will satisfy our requirements. However, for AWS, we must put some time and effort into creating our content policy to get optimal protection.
For how long have I used the solution?
I have been providing the solution for a year or more.
What do I think about the stability of the solution?
The product is stable. I have no complaints. I rate the stability a nine out of ten.
What do I think about the scalability of the solution?
The product is scalable. I rate the scalability a nine out of ten.
How are customer service and support?
The technical support is good. I have no complaints. The support team is fast, knowledgeable, and customer-friendly.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward. It takes merely half an hour or less to deploy the solution. The solution is deployed on the cloud.
What about the implementation team?
Whether we need a consultant to help with the deployment depends on our knowledge of the cloud platform and our applications. It is a complex solution. We can do it ourselves if we know about WAFs, rule sets, and deployments. It is not a solution for a novice or someone unfamiliar with the security and application firewall. Such people might need the help of an administrator or consultant. We deployed the solution ourselves.
What's my experience with pricing, setup cost, and licensing?
Depending on how our AWS billing is configured, we are billed on a monthly or yearly billing cycle. The product is moderately priced. It is not too cheap but not too high either. There are no additional costs associated with the product.
What other advice do I have?
I would recommend the solution to others. If a web application is completely hosted in AWS, then AWS WAF is a good choice. We can easily adopt it. Overall, I rate the solution a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Project Manager at Synopsys Inc
Sends useful alerts and enables to automate tasks by creating rules
Pros and Cons
- "Rule groups are valuable."
- "We must monitor and clean up the WAF manually."
What is our primary use case?
We use Managed Rules mostly.
How has it helped my organization?
ALB is integrated with WAF. When ALB spikes up, we know there’s something wrong. Usually, bots attack the applications.
What is most valuable?
Rule groups are valuable. We use it for DDoS. We do customizations with the help of Managed Rules in AWS. We use AWS WAF’s API to automate security tasks. The rule creation is similar to automation. We have enough understanding of how things work. It’s been one year since we have automated the tasks.
What needs improvement?
There are some limitations. We can add a maximum of four rate-based rules to the rule group. We must monitor and clean up the WAF manually. We cannot create rules if it goes above four. It requires manual intervention. We have to check, clean, and maintain it regularly. We do not want to do it. We are willing to pay extra if it can be improved. We need additional features so we do not have to do manual interventions.
For how long have I used the solution?
I have been using the solution for three years.
What do I think about the stability of the solution?
We do not have any problems with the tool’s functionalities.
What do I think about the scalability of the solution?
We are very happy about the product’s scalability. We did not face any issues. My organization is an enterprise.
How are customer service and support?
We have a partnership. We can contact the consultants whenever we need anything. We don't have any problem with the support team.
How would you rate customer service and support?
Positive
How was the initial setup?
The installation was not difficult. We have a separate team to deploy the solution in our organization. We do not face any issues with maintenance.
What other advice do I have?
All our infrastructure is on AWS. My organization has been using AWS for the last eight years. Mid-size companies use ALB. We also use AWS Shield. Sometimes, we get alerts from AWS Shield. Our internal tools also send us alerts. We're completely on AWS. We do not integrate it with any other tool. Overall, I rate the product an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Director at AM Equipment & Services Private Limited
An easy-to-use and easy-to-configure solution that provides high stability
Pros and Cons
- "AWS WAF is very easy to use and configure on AWS."
- "It would be good if the solution provided managed WAF services."
What is our primary use case?
When customers onboard a web application and want a WAF to protect it, they ask us to configure AWS WAF for them.
What is most valuable?
AWS WAF is very easy to use and configure on AWS. It is easy to make rules and very fast to set it up on AWS.
What needs improvement?
AWS WAF provides only basic protection, and they should provide more features like other third-party competitors. The world is now moving towards managed services. It would be good if the solution provided managed WAF services. If AWS WAF could detect that some attack is about to happen and alert the user, we can write some rules and stop that from happening.
For how long have I used the solution?
I have been using AWS WAF for five years.
What do I think about the stability of the solution?
We have never faced any stability issues with AWS WAF.
I rate AWS WAF ten out of ten for stability.
What do I think about the scalability of the solution?
AWS WAF is more suited for small and medium businesses.
I rate AWS WAF a nine out of ten for scalability.
How was the initial setup?
The solution’s initial setup is simple.
What's my experience with pricing, setup cost, and licensing?
AWS WAF has reasonable pricing.
Which other solutions did I evaluate?
Third-party competitors like F5 and Imperva have more features than AWS WAF.
What other advice do I have?
Overall, I rate AWS WAF a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
DevOps Engineer at SEKAI
Easy to configure and stable solution
Pros and Cons
- "The most valuable feature is that it is very easy to configure. It just takes a couple of minutes."
- "There is room for improvement in pricing."
What is our primary use case?
For AWS WAF, currently, we use this new application. This is another service provided by AWS for the sales business, and it's used for education. So, AWS WAF works in conjunction with AWS Cognito. We observe this when there's some kind of bot attempting to access our application or when you're trying to use a bot as a control mechanism to transcribe or manage a high volume of traffic through our endpoints.
AWS WAF manages both human traffic and bot-controlled traffic, and it can redirect you to a catch-up mechanism or sometimes simply for use. So, we've implemented different kinds of mechanisms within AWS WAF.
How has it helped my organization?
We use it in the production environment. From time to time, we can see the metrics for the generated traffic on both the WAF and the infrastructure
These metrics are presented on the dashboard. We review this information and conclude that regular monitoring, along with dashboard evaluations, reaffirms the effectiveness of the system. This allows us to ensure that the investment we're making is justified and worthwhile.
What is most valuable?
The most valuable feature is that it is very easy to configure. It just takes a couple of minutes.
What needs improvement?
There is room for improvement in pricing.
The pricing for each rule group is a bit too high. It's a monthly subscription, and it can get quite expensive for rules that I won't use for my application. For example, I might create a rule group that costs $10, and I only use one of the rules in the group. That's $10 for a rule that I'm not even using! So, the pricing could be more flexible, or there could be a way to get discounts for unused rules.
So, AWS WAF should have a pay-as-you-go pricing model, where I can only pay for the rules that I use.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
It is a stable solution to some extent.
What do I think about the scalability of the solution?
For my use cases, it is a scalable solution. There are less than 2,000 end users using this solution in our organization.
How are customer service and support?
I reached out to support when I was setting it up initially, I had some questions. And we have some kind of first-line support with AWS. So I reached out to them whenever I had questions.
However, the support depends on the support we are paying for. The support we are paying for is cheap support. I'm on the standard support plan, so my SLA is four hours. There's a phone queue, so I can't always get through right away. But the support engineers are knowledgeable and can usually point me in the right direction.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is fairly easy. AWS does everything for us—just some clicks.
What about the implementation team?
There is no maintenance required. AWS also upgrades new offerings. AWS does all these things. Like, it does why it's very expensive. And they give us the metrics.
What other advice do I have?
Just evaluate these simple things you need. And don't try to put too many features at the beginning because you might not need them. Every application is designed differently.
Every business and customer is also very different, so if your application is more susceptible to some kind of engineering traffic then it's going to be very expensive.
Overall, I would rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Junior Associate - IT at a tech services company with 201-500 employees
Can block sudden surges of users on the website and provides protection against DDoS attacks
Pros and Cons
- "The most valuable feature is the addition of managed tools that help us create customizable rules. In case we want to block a particular request, we can make use of those rules."
- "One area that could be improved is the DDoS protection."
What is our primary use case?
We are using it to monitor the requests on our site, to block sudden surges of users on our website, and also to prevent DDoS attacks.
What is most valuable?
The addition of managed tools that help us create customizable rules. In case we want to block a particular request, we can make use of those rules.
What needs improvement?
One area that could be improved is the DDoS protection. We had a DDoS attack recently, and even though we had set a limit of 1,000 requests per five minutes, AWS WAF was not able to block all of the requests.
AWS wasn't able to clarify all the DDoS attacks. It may have been due to a wrong configuration in the rules, but AWS didn't block all the requests.
For how long have I used the solution?
It's been deployed in a project for one year.
What do I think about the stability of the solution?
I would rate the stability a ten out of ten. It is a very stable solution. There are over 16 end users using the solution.
What do I think about the scalability of the solution?
I would rate the scalability a nine out of ten. There is room for improvement.
How was the initial setup?
The initial setup is easy. You don't need to do too many things.
What about the implementation team?
The deployment was done manually on the console, there is no need of propriety. It took around an hour and half.
What's my experience with pricing, setup cost, and licensing?
The pricing totally depends on the number of requests entering the WAF. For example, in case we have a DDoS type of attack, at that time, the price will surge quickly. For example, it will go up to two hundred dollars within three to four days. So it totally depends on the number of requests it is processing.
There are additional costs to the standard license because it totally depends on the number of incoming requests.
What other advice do I have?
Overall, I would rate the solution an eight out of ten.
I would recommend that understanding how the rules work exactly and finding patterns based on those rules is the most important thing in AWS WAF. It's quite easy to deploy at first, but afterward, it's essential to know how to handle it properly. Enabling the managed tools of AWS can sometimes block legitimate requests too. So, it's important to understand the type of requests you want to allow and how to configure the rules accordingly. It's quite an interesting aspect of AWS WAF.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Security Analyst at M2P Fintech
A user-friendly web application firewall with a useful integration feature, but it could be more flexible
Pros and Cons
- "I believe the most impressive features are integration and ease of use. The best part of AWS WAF is the cloud-native WAF integration. There aren't any hidden deployments or hidden infrastructure which we have to maintain to have AWS WAF. AWS maintains everything; all we have to do is click the button, and WAF will be activated. Any packet coming through the internet will be filtered through."
- "It would be better if AWS WAF were more flexible. For example, if you take a third-party WAF like Imperva, they maintain the rule set, and these rule sets are constantly updated. They push security insights or new rules into the firewall. However, when it comes to AWS, it has a standard set of rules, and only those sets of rules in the application firewalls trigger alerts, block, and manage traffic. Alternative WAFs have something like bot mitigation or bot control within the WAF, but you don't have such things in AWS WAF. I will say there could have been better bot mitigation plans, there could have been better dealer mitigation plans, and there could be better-updated rule sets for every security issue which arises in web applications. In the next release, I would like to see if AWS WAF could take on DDoS protection within itself rather than being in a stand-alone solution like AWS Shield. I would also like a solution like a bot mitigation."
- "Alternative WAFs have something like bot mitigation or bot control within the WAF, but you don't have such things in AWS WAF."
What is our primary use case?
We partner with many banks in India, and many partners use our portals to access their credit card or debit card information. So we use AWS WAF to protect our web application servers, app servers, and API servers from any malicious attacks which arise from the public internet. We also use AWS WAF for virtual patching of our servers to prevent any malicious requests from reaching the gateway to our internal systems.
What is most valuable?
I believe the most impressive features are integration and ease of use. The best part of AWS WAF is the cloud-native WAF integration. There aren't any hidden deployments or hidden infrastructure which we have to maintain to have AWS WAF. AWS maintains everything; all we have to do is click the button, and WAF will be activated. Any packet coming through the internet will be filtered through.
What needs improvement?
It would be better if AWS WAF were more flexible. For example, if you take a third-party WAF like Imperva, they maintain the rule set, and these rule sets are constantly updated. They push security insights or new rules into the firewall. However, when it comes to AWS, it has a standard set of rules, and only those sets of rules in the application firewalls trigger alerts, block, and manage traffic.
Alternative WAFs have something like bot mitigation or bot control within the WAF, but you don't have such things in AWS WAF. I will say there could have been better bot mitigation plans, there could have been better dealer mitigation plans, and there could be better-updated rule sets for every security issue which arises in web applications.
In the next release, I would like to see if AWS WAF could take on DDoS protection within itself rather than being in a stand-alone solution like AWS Shield. I would also like a solution like a bot mitigation.
For how long have I used the solution?
I have been using AWS WAF for a couple of years.
What do I think about the stability of the solution?
We haven't faced any issues over the past couple of years, so I believe AWS WAF is a stable product.
What do I think about the scalability of the solution?
Since we are AWS-native, it's very scalable. It can handle almost any infrastructure running within the AWS public cloud. We have around 20 portals, and about 20 products usually use AWS WAF. I'll say that about 15 people use AWS WAF to manage the traffic and filter out security issues. Those people are security analysts, SOC analysts, and layer 1 network analysts.
How are customer service and support?
In our business use case, sometimes it has triggered a false positive where it blocks some of our legitimate traffic. So we contact support to ask if this is legitimate and if we have to implement a new rule or if we have to allow such traffic and not mark it as a false positive. We have contacted them only for such occasions, and their support was really good.
On a scale from one to five, I would give technical support a four.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was very simple. It's just a click of a button.
What about the implementation team?
We already have web applications running on an AWS account, so it probably took about two minutes to implement this solution.
What's my experience with pricing, setup cost, and licensing?
For our infrastructure, we probably pay around $16,000 per month for AWS WAF. Because alternative WAF solutions provide even more features, I think the AWS WAF is a bit pricey
What other advice do I have?
I would say that I think it's easy to use, easy to deploy, and has all the basic WAF features. It has no advanced features like bot mitigation or DDoS protection built-in. If it had bot mitigation or advanced security filter patching features, I would probably give it a higher rating, like a nine.
On a scale from one to ten, I would give AWS WAF a seven.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Cloudflare
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Cloudflare Web Application Firewall
NetScaler
Fortinet FortiWeb
Gigamon Deep Observability Pipeline
Azure Front Door
F5 Advanced WAF
Microsoft Azure Application Gateway
Akamai App and API Protector
HAProxy
Check Point WAF (formerly CloudGuard WAF)
F5 Distributed Cloud Services
Fastly
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the limitations of AWS WAF vs alternative WAFs?
- Can you share your experience on migration from Akamai Kona Site to Amazon CloudFront and AWS WAF?
- How does AWS WAF compare to Microsoft Azure Application Gateway?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?




















