We primarily use this solution for monitoring and blocking to ensure protection against application layer attacks. These include application-related core rules, database-specific attacks, Linux-based attacks and some custom rules deployed. These rules assist us in blocking specific attacks that come from the internet into our cloud infrastructure.
Senior security engeneer at a media company with 1,001-5,000 employees
Customizable features and a great solution for monitoring
Pros and Cons
- "The customizable features are good."
- "We have received good support from the customer service and support team."
- "The product could be improved by expanding the weightage units of rules we have when writing policy."
What is our primary use case?
What is most valuable?
The customizable features are good. For example, we can write our own rules and match character and size limits.
What needs improvement?
The product could be improved by expanding the weightage units of rules we have when writing policy. Currently, our company uses WAF policy and Web ACL but is limited to only 1500 units of rules.
For how long have I used the solution?
We have been using this solution for three years and are currently using version two. We deploy this solution on Amazon public cloud.
Buyer's Guide
AWS WAF
September 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,683 professionals have used our research since 2012.
What do I think about the stability of the solution?
This solution is stable.
What do I think about the scalability of the solution?
This solution is scalable because it provides many features.
How are customer service and support?
We have received good support from the customer service and support team. They identify our problems and assist in resolving any issues we have.
How was the initial setup?
Our initial setup was straightforward, and deployment by automation only took a few minutes.
What's my experience with pricing, setup cost, and licensing?
I cannot comment on licensing costs and pricing as I am unsure of the exact costs.
What other advice do I have?
I rate AWS WAF an eight out of ten. I would advise new customers to choose custom policies because they provide more flexibility in guarding against attacks on cloud infrastructures. Additionally, it protects both regional and global servers.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solution architect at NTT
Protects web applications against attacks; stable and scalable firewall with a straightforward setup
Pros and Cons
- "Stable and scalable web application firewall. Setting it up is straightforward."
- "I'm satisfied with AWS WAF, and I've had no issues with it."
- "Technical support for AWS WAF needs improvement."
- "Technical support for AWS WAF could still be improved, e.g. support could be faster, more knowledgeable, and friendlier."
What needs improvement?
Support for AWS WAF needs improvement.
For how long have I used the solution?
I've been using AWS WAF for a very short period, e.g. just a few weeks.
What do I think about the stability of the solution?
I find AWS WAF to be a stable product.
What do I think about the scalability of the solution?
AWS WAF is a scalable product.
How are customer service and support?
Technical support for AWS WAF could still be improved, e.g. support could be faster, more knowledgeable, and friendlier.
How was the initial setup?
The initial setup for AWS WAF was straightforward. It could take between two days to two weeks.
What about the implementation team?
We implemented AWS WAF through our in-house team and a consultant.
What other advice do I have?
I've been using a mix of AWS products, including AWS WAF.
I'm satisfied with AWS WAF, and I've had no issues with it. I can't really find fault in the product. It's a good product.
We have hundreds of AWS WAF users within our company. We also have plans of increasing the number of users of the product.
The advice I would give to people who want to start using AWS WAF is that it's a good option if they're migrating to the cloud. It can take up a lot of legacy systems, e.g. it's scalable. Most of my customers are on the cloud, and for anyone who's struggling, it would be good to start anytime. Start small and scale, rather than just going fully onto the cloud.
Users need to pay for the product license.
My rating for AWS WAF is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
AWS WAF
September 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,683 professionals have used our research since 2012.
Solution Architect at a non-profit with 10,001+ employees
A stable solution, but installation, navigation and configuration are overly complex and the price is not efficient for small customers
Pros and Cons
- "The solution is stable."
- "I like the scalability, as it provides platform, infrastructure and software as a service."
- "While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex."
- "The pricing should be more affordable, especially as it pertains to small clients."
What is our primary use case?
While I cannot say for certain, I believe that we are using the latest version.
What is most valuable?
I like the scalability, as it provides platform, infrastructure and software as a service. These are the best features. When it comes to the API Gateway, such as Amazon Web Application Framework, the web application will be protected by all industry standard security aspects. We are talking about encryption, firewalls, SSL and TLS. Basically, all web exploit policies and rules will be applied, so that one's web or mobile app can be highly secured.
In terms of hosting the instances, the solution takes care of all necessary scaling to ensure that the application load is balanced. The horizontal or vertical scaling can be automatically removed. As such, AWS provides many services and features.
What needs improvement?
The pricing should be more affordable, especially as it pertains to small clients.
While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex. These could stand improvement and bring down my rating of the product.
Customer support should also be improved.
For how long have I used the solution?
I have been using AWS WAF for around two years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
While it can vary according to the service involved, installation, configuration and navigation are, broadly speaking, complex.
What's my experience with pricing, setup cost, and licensing?
The solution could be more cost-efficient for small customers.
What other advice do I have?
The solution may be expensive for smaller customers and vendors, although it would be recommended for large ones who can afford it.
Our organization has only a few years, consisting of the internal team, who are making use of the solution.
I rate AWS WAF as a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Physical Designer at Semtech Corporation
Does what it is supposed to do, probably not in the best way and not in the best UI
Pros and Cons
- "The access instruction feature is the most valuable. This is what we use the most."
- "AWS WAF helps us a lot to make sure that the right customer gets the right access to the system."
- "It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful. It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one. Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right."
- "Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support."
What is our primary use case?
The regular use case is basically for blocking or giving access to different vendors to different domains. We also use it for managing and identifying the attacks and new rules that we should implement for our public domains to tune up the application firewall or tool, whatever makes more sense for us.
We're using it through the web console and API. We're just using the managed service.
How has it helped my organization?
Our organization is launching a lot of betas. We are creating a lot of new different systems for different customers. AWS WAF helps us a lot to make sure that the right customer gets the right access to the system.
What is most valuable?
The access instruction feature is the most valuable. This is what we use the most.
What needs improvement?
It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful.
It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one.
Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right.
For how long have I used the solution?
I have been using AWS WAF for about six months.
What do I think about the stability of the solution?
Stability-wise, it works as expected.
What do I think about the scalability of the solution?
I definitely see places where it can be more designed to scale. In addition to amazon resources, there is some stuff from other vendors that we wanted to protect. WAF was not a solution for us because we don't have a way to integrate with those things. That was the biggest challenge that we faced. In terms of the number of users, our end users could be in the thousands.
How are customer service and technical support?
It is okay.
How was the initial setup?
It was okay. We went for the cloud formation, and our deployments happen probably every week.
What about the implementation team?
Everything is managed through cloud formation. After implementation, three or four hours a week are required for maintenance.
What's my experience with pricing, setup cost, and licensing?
We are kind of doing a POC comparison to see what works best. Pricing-wise, AWS is one of the most attractive ones. It is fairly cheap, and we like the pricing part. We're trying to see what makes more sense operation-wise, license-wise, and pricing-wise.
What other advice do I have?
I won't recommend it at the moment because I don't have a full picture to recommend it or say that it is bad or good. I'll probably just keep testing and go with it for probably another six months or a year, and then I can probably recommend it or not.
Other vendors are also providing solutions for D-DOS protection and WAF. It would be nice to see something outside the box for AWS WAF to make it compete with other vendors.
I would rate AWS WAF a seven out of ten. It does what it is supposed to do, probably not in the best way and not in the best UI, but it works. We like the pricing part, but management is the thing that we don't love the most. If things keep improving, we're definitely going to scale with AWS WAF.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Product Owner at a tech vendor with 11-50 employees
A stable solution that is easy to deploy and provides a helpful support team
Pros and Cons
- "The tool’s stability is very good."
- "The cost must be reduced."
What is our primary use case?
We use the solution for filtering traffic. We do not want our developers to use unnecessary websites. So, we filter the websites using the tool.
What is most valuable?
All the features are good. AWS Lambda and S3 are valuable tools. We have to use these tools when we build applications.
What needs improvement?
The cost must be reduced.
For how long have I used the solution?
I have been using the solution for a year. I use the latest version.
What do I think about the stability of the solution?
The tool’s stability is very good. It is better than GCP.
What do I think about the scalability of the solution?
The tool’s scalability is good. We have almost 20 users.
How are customer service and support?
The support is helpful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We also use GCP.
How was the initial setup?
The initial setup is very easy. Everything is on the cloud. The deployment takes one full day.
What about the implementation team?
We deploy the product in-house. We need one senior solution architect and one junior solution architect to deploy the tool. We have a team of analysts for experiments. We need only one person to maintain the solution.
What's my experience with pricing, setup cost, and licensing?
The product is expensive.
What other advice do I have?
We use almost 40 services. Overall, I rate the product an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Infrastructure Engineer at Pathlock
A scalable solution that provides excellent documentation and additional security to applications
Pros and Cons
- "The product’s availability, ease of configuration, and documentation are valuable."
- "The product must provide more features."
What is our primary use case?
We use the solution for our applications. We have deployed multiple applications on the AWS platform. We use the tool to provide additional security to our applications.
What is most valuable?
The product’s availability, ease of configuration, and documentation are valuable.
What needs improvement?
The product has fewer features. It didn’t fulfill all our requirements when we installed it. It is getting better now, though. The product must provide more features.
For how long have I used the solution?
I have been using the solution for a few years.
What do I think about the stability of the solution?
I rate the product’s stability a nine out of ten.
What do I think about the scalability of the solution?
The product is highly scalable and highly available. I rate the scalability a nine out of ten. We have deployed three applications. We have two administrators for our infrastructure. The number of users varies according to our customers. We provide the user interface to our customers.
How are customer service and support?
The technical support team is good. The support persons provide prompt responses. They are always available and provide solutions to our queries.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup is very easy. We have proper documentation, so we have no issues. We have deployed the tool for additional security. It is a cloud solution. We need two members from the cloud infrastructure team and eight from the application support team for the deployment and maintenance of the tool.
What about the implementation team?
We deploy the tool ourselves.
What was our ROI?
The solution provides an additional layer of security.
What's my experience with pricing, setup cost, and licensing?
The solution is affordable.
What other advice do I have?
If a company needs an additional layer of security, it can use AWS WAF. I recommend the product to others. Overall, I rate the product a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
AWS Security Specialist at a computer software company with 1,001-5,000 employees
Helps to protect internet system applications
Pros and Cons
- "The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections."
- "We should be able to do proper whitelisting."
What is our primary use case?
We use AWS WAF to protect internet system applications.
What is most valuable?
The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections.
What needs improvement?
We should be able to do proper whitelisting.
For how long have I used the solution?
I have been working with the solution for four years.
What do I think about the stability of the solution?
AWS WAF is stable.
What do I think about the scalability of the solution?
My company has more than 10,000 users. The tool is scalable.
How are customer service and support?
AWS WAF's tech support is not complicated.
How would you rate customer service and support?
Positive
How was the initial setup?
AWS WAF's deployment is easy.
What was our ROI?
We have seen ROI with the tool's use.
What's my experience with pricing, setup cost, and licensing?
AWS WAF has reasonable pricing.
What other advice do I have?
You need to consider the use cases before implementing the solution. I rate it a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Superintendent of Cloud Platforms at a manufacturing company with 1,001-5,000 employees
Protects public-facing web applications but pricing is expensive
Pros and Cons
- "We preferred the product based on its cost. AWS WAF is an out-of-the-box solution and integrates with the AWS services that we use. It's natively integrated with AWS."
- "We have issues with reporting, troubleshooting, and analytics. AWS WAF needs to bring costs down."
What is our primary use case?
We use the product for the protection of our public-facing web applications.
What is most valuable?
We preferred the product based on its cost. AWS WAF is an out-of-the-box solution and integrates with the AWS services that we use. It's natively integrated with AWS.
What needs improvement?
We have issues with reporting, troubleshooting, and analytics. AWS WAF needs to bring costs down.
For how long have I used the solution?
I have been working with the solution for 18 months.
What do I think about the stability of the solution?
AWS WAF is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
We use Amazon enterprise support. It is good but expensive.
Which solution did I use previously and why did I switch?
We used Cloudflare and Palo Alto before. We chose AWS WAF since it integrates with native services.
How was the initial setup?
The tool's setup is complex but it is easy after installation.
What's my experience with pricing, setup cost, and licensing?
I would rate AWS WAF's pricing a seven out of ten.
What other advice do I have?
I would rate AWS WAF a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Helps to implement response recovery procedures
Pros and Cons
- "One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services."
- "I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy."
What is our primary use case?
One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services.
What needs improvement?
I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy.
For how long have I used the solution?
I have been using the solution for almost a decade.
What do I think about the stability of the solution?
AWS WAF is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
The initial setup was easy.
What about the implementation team?
Our in-house engineers implemented the solution. They are already familiar with AWS and hold AWS certifications.
What other advice do I have?
Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Engineer at Readyly
Allows us to set up security rules and has a good scalability
Pros and Cons
- "The solution's initial setup process is easy."
- "The solution could be more reliable."
What is our primary use case?
We use the solution as a firewall to protect the network from malicious requests.
How has it helped my organization?
The solution helps our organization to comply with our security standards.
What is most valuable?
The solution allows us to set up rules for blocking malicious requests. We can configure a pool of such sources and choose what to do (allow/block/count) when a request comes from them.
What needs improvement?
The solution can include provisions to block requests targeted at specific URIs (/.env) which are obviously malicious. Also, sometimes it blocks legitimate requests. We have to keep changing some of our rules in this case. It would be great if they maintained the AWS-managed rule sets properly.
For how long have I used the solution?
We have been using the solution for the last eight months.
What do I think about the stability of the solution?
It is a stable solution. Although sometimes even legitimate requests fail.
I rate its stability an eight out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. We have two users in our organization.
How was the initial setup?
The solution's initial setup process is easy.
What other advice do I have?
I advise others to set their security principles while building the software itself, as WAF is not entirely reliable. I rate it an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Cloudflare
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Cloudflare Web Application Firewall
NetScaler
Gigamon Deep Observability Pipeline
Fortinet FortiWeb
Azure Front Door
Akamai App and API Protector
Check Point WAF (formerly CloudGuard WAF)
F5 Advanced WAF
HAProxy
Microsoft Azure Application Gateway
F5 Distributed Cloud Services
Fastly
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the limitations of AWS WAF vs alternative WAFs?
- Can you share your experience on migration from Akamai Kona Site to Amazon CloudFront and AWS WAF?
- How does AWS WAF compare to Microsoft Azure Application Gateway?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?


















