We use the solution for our applications. We have deployed multiple applications on the AWS platform. We use the tool to provide additional security to our applications.
Cloud Infrastructure Engineer at Pathlock
A scalable solution that provides excellent documentation and additional security to applications
Pros and Cons
- "The product’s availability, ease of configuration, and documentation are valuable."
- "The product must provide more features."
What is our primary use case?
What is most valuable?
The product’s availability, ease of configuration, and documentation are valuable.
What needs improvement?
The product has fewer features. It didn’t fulfill all our requirements when we installed it. It is getting better now, though. The product must provide more features.
For how long have I used the solution?
I have been using the solution for a few years.
Buyer's Guide
AWS WAF
February 2025
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.
What do I think about the stability of the solution?
I rate the product’s stability a nine out of ten.
What do I think about the scalability of the solution?
The product is highly scalable and highly available. I rate the scalability a nine out of ten. We have deployed three applications. We have two administrators for our infrastructure. The number of users varies according to our customers. We provide the user interface to our customers.
How are customer service and support?
The technical support team is good. The support persons provide prompt responses. They are always available and provide solutions to our queries.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup is very easy. We have proper documentation, so we have no issues. We have deployed the tool for additional security. It is a cloud solution. We need two members from the cloud infrastructure team and eight from the application support team for the deployment and maintenance of the tool.
What about the implementation team?
We deploy the tool ourselves.
What was our ROI?
The solution provides an additional layer of security.
What's my experience with pricing, setup cost, and licensing?
The solution is affordable.
What other advice do I have?
If a company needs an additional layer of security, it can use AWS WAF. I recommend the product to others. Overall, I rate the product a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
AWS Security Specialist at a computer software company with 1,001-5,000 employees
Helps to protect internet system applications
Pros and Cons
- "The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections."
- "We should be able to do proper whitelisting."
What is our primary use case?
We use AWS WAF to protect internet system applications.
What is most valuable?
The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections.
What needs improvement?
We should be able to do proper whitelisting.
For how long have I used the solution?
I have been working with the solution for four years.
What do I think about the stability of the solution?
AWS WAF is stable.
What do I think about the scalability of the solution?
My company has more than 10,000 users. The tool is scalable.
How are customer service and support?
AWS WAF's tech support is not complicated.
How would you rate customer service and support?
Positive
How was the initial setup?
AWS WAF's deployment is easy.
What was our ROI?
We have seen ROI with the tool's use.
What's my experience with pricing, setup cost, and licensing?
AWS WAF has reasonable pricing.
What other advice do I have?
You need to consider the use cases before implementing the solution. I rate it a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
AWS WAF
February 2025
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.
Manager, IT Infrastructure & Information Security at flyadeal
Provides good OWASP top 10 protection but needs improvement in security efficiency related to bad bots
Pros and Cons
- "The security firewall plus the features that protect against database injections or scripting,"
- "For now, there is no feature to protect against attack of the bad bots"
What is our primary use case?
I'm a manager and in charge of IT infrastructure and information security for an airline company. We're a customer of AWS WAF. We use the product to protect the websites that our customers access to book flights. It provides the sites with DDoS protection and OWASP top 10 application security.
What is most valuable?
The best features are the security firewall and the features that protect against database injections or scripting, and against overall OWASP top 10, but I have concerns about the cloud front which doesn't handle bot attacks properly, so it's not as effective as I would like it to be.
What needs improvement?
A significant improvement would be built in bots protection enhancement, or seamless integration with other products. For now, there are limited feature to protect against an attack from the bad bots so users go to third party solutions, which just complicates integration and operation.
A helpful additional feature would be to have a fully unified unique product, including the DDoS, with sophisticated attack capabilities including anti bot management. They should also take a look at reviewing the complexity of the integration with other third-party vendor solutions.
For how long have I used the solution?
I've been using the product for the last two years. We upgraded recently and I'm using the latest version.
How are customer service and technical support?
Technical support is good.
How was the initial setup?
Deployment is easy, it's not complex.The complexity is when you need it for integration with other third-party products. We also use CDN, part of the web solution from Amazon.
What's my experience with pricing, setup cost, and licensing?
The price of the product is fair enough and one of the product's advantages. Their price is good compared to other vendors.
What other advice do I have?
The main difference with other similar products is the security efficiency against the type of attacks because normally Amazon works with certain types of attacks and is unable to deal with most of the more sophisticated new attacks that are now the market. So if you compare AWS WAF to the leaders in the field like Imperva, Akamai or radware, they are still beyond these products.
I would recommend that if you don't have a critical heavy use website, and you have a simple business that doesn't require high protection or high-security efficiency, go with this product, but if you have something where security is critical you should go with the leaders in the market, companies like Akamai, Radware, PerimeterX or Imperva.
I would rate this product a seven out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Software Engineer at Readyly
Allows us to set up security rules and has a good scalability
Pros and Cons
- "The solution's initial setup process is easy."
- "The solution could be more reliable."
What is our primary use case?
We use the solution as a firewall to protect the network from malicious requests.
How has it helped my organization?
The solution helps our organization to comply with our security standards.
What is most valuable?
The solution allows us to set up rules for blocking malicious requests. We can configure a pool of such sources and choose what to do (allow/block/count) when a request comes from them.
What needs improvement?
The solution can include provisions to block requests targeted at specific URIs (/.env) which are obviously malicious. Also, sometimes it blocks legitimate requests. We have to keep changing some of our rules in this case. It would be great if they maintained the AWS-managed rule sets properly.
For how long have I used the solution?
We have been using the solution for the last eight months.
What do I think about the stability of the solution?
It is a stable solution. Although sometimes even legitimate requests fail.
I rate its stability an eight out of ten.
What do I think about the scalability of the solution?
It is a scalable solution. We have two users in our organization.
How was the initial setup?
The solution's initial setup process is easy.
What other advice do I have?
I advise others to set their security principles while building the software itself, as WAF is not entirely reliable. I rate it an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security implmentation engineer at a security firm with 51-200 employees
The product is highly scalable and has a helpful support team, but it should improve the features that mitigate DDoS attacks
Pros and Cons
- "We do not have to maintain the solution."
- "The product should improve the DDoS-related features."
What is our primary use case?
We use the solution for publishing important applications. These sites are accessed by hundred to one million users every day.
What is most valuable?
We do not have to maintain the solution. Amazon maintains the product.
What needs improvement?
We have a lot of issues related to attacks on our cloud. There is a limitation on how to mitigate the issues in the solution. The product should improve the DDoS-related features.
The solution should provide an advanced tool for DDoS migration and a better reporting method. Compared to other solutions, we do not get all the information we need for reporting.
For how long have I used the solution?
I am dealing with the solution right now.
What do I think about the stability of the solution?
The solution is stable. It does not depend on the data centre or browser consumption.
What do I think about the scalability of the solution?
The product has high scalability. I can increase the resources without any effort.
How are customer service and support?
The support team is very helpful.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is too simple on the AWS. It is not complex at all. If we take certain courses and view a lot of videos on how to implement the solution, it is very easy. Support helps us with the deployment.
What about the implementation team?
Our teams do not manage the product. The deployment process includes adding a new customer, reserving their information on the cloud, creating the nodes, publishing the service and testing it on the old security aspects. Then, the solution is deployed on the cloud.
The time taken for deployment depends on the customer's requirements. Usually, there is a delay due to missing information from the customers. One or two engineers can handle the deployment. We do not need a big team for it.
What other advice do I have?
We have decided to use Cloudflare to integrate with AWS, and most of our issues have been resolved. I would recommend the solution. However, it depends on the customer’s data confidentiality. If there are confidential data on the servers, they should not be on the cloud. They can use the cloud solution if the data is normal and not critical. Overall, I rate the product a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Integrator
CEO at Axcess.io
Good support, extremely stable, and scalable
Pros and Cons
- "The stability of AWS WAF is valuable."
- "The cost management has room for improvement."
What is our primary use case?
We are an AWS service provider and we use the solution for the cloud and to provide service to other users.
What is most valuable?
The stability of AWS WAF is valuable.
What needs improvement?
The cost management has room for improvement.
For how long have I used the solution?
I have been using the solution for eight years.
What do I think about the stability of the solution?
I give the stability a ten out of ten.
What do I think about the scalability of the solution?
I give the scalability a nine out of ten.
How are customer service and support?
The technical support is helpful.
What's my experience with pricing, setup cost, and licensing?
The price is average.
What other advice do I have?
I give the solution a ten out of ten.
The solution is a public cloud platform and we have millions of users.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Solution Architect at a non-profit with 10,001+ employees
A stable solution, but installation, navigation and configuration are overly complex and the price is not efficient for small customers
Pros and Cons
- "The solution is stable."
- "While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex."
What is our primary use case?
While I cannot say for certain, I believe that we are using the latest version.
What is most valuable?
I like the scalability, as it provides platform, infrastructure and software as a service. These are the best features. When it comes to the API Gateway, such as Amazon Web Application Framework, the web application will be protected by all industry standard security aspects. We are talking about encryption, firewalls, SSL and TLS. Basically, all web exploit policies and rules will be applied, so that one's web or mobile app can be highly secured.
In terms of hosting the instances, the solution takes care of all necessary scaling to ensure that the application load is balanced. The horizontal or vertical scaling can be automatically removed. As such, AWS provides many services and features.
What needs improvement?
The pricing should be more affordable, especially as it pertains to small clients.
While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex. These could stand improvement and bring down my rating of the product.
Customer support should also be improved.
For how long have I used the solution?
I have been using AWS WAF for around two years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How was the initial setup?
While it can vary according to the service involved, installation, configuration and navigation are, broadly speaking, complex.
What's my experience with pricing, setup cost, and licensing?
The solution could be more cost-efficient for small customers.
What other advice do I have?
The solution may be expensive for smaller customers and vendors, although it would be recommended for large ones who can afford it.
Our organization has only a few years, consisting of the internal team, who are making use of the solution.
I rate AWS WAF as a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Product Owner at SecLogic Limited
A stable solution that is easy to deploy and provides a helpful support team
Pros and Cons
- "The tool’s stability is very good."
- "The cost must be reduced."
What is our primary use case?
We use the solution for filtering traffic. We do not want our developers to use unnecessary websites. So, we filter the websites using the tool.
What is most valuable?
All the features are good. AWS Lambda and S3 are valuable tools. We have to use these tools when we build applications.
What needs improvement?
The cost must be reduced.
For how long have I used the solution?
I have been using the solution for a year. I use the latest version.
What do I think about the stability of the solution?
The tool’s stability is very good. It is better than GCP.
What do I think about the scalability of the solution?
The tool’s scalability is good. We have almost 20 users.
How are customer service and support?
The support is helpful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We also use GCP.
How was the initial setup?
The initial setup is very easy. Everything is on the cloud. The deployment takes one full day.
What about the implementation team?
We deploy the product in-house. We need one senior solution architect and one junior solution architect to deploy the tool. We have a team of analysts for experiments. We need only one person to maintain the solution.
What's my experience with pricing, setup cost, and licensing?
The product is expensive.
What other advice do I have?
We use almost 40 services. Overall, I rate the product an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
F5 Advanced WAF
Fortinet FortiWeb
NetScaler
Imperva Web Application Firewall
Cloudflare Web Application Firewall
Imperva DDoS
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Barracuda Web Application Firewall
Fastly
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the limitations of AWS WAF vs alternative WAFs?
- Can you share your experience on migration from Akamai Kona Site to Amazon CloudFront and AWS WAF?
- How does AWS WAF compare to Microsoft Azure Application Gateway?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?