Try our new research platform with insights from 80,000+ expert users
Physical Designer at Semtech Corporation
Real User
Does what it is supposed to do, probably not in the best way and not in the best UI
Pros and Cons
  • "The access instruction feature is the most valuable. This is what we use the most."
  • "It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful. It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one. Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right."

What is our primary use case?

The regular use case is basically for blocking or giving access to different vendors to different domains. We also use it for managing and identifying the attacks and new rules that we should implement for our public domains to tune up the application firewall or tool, whatever makes more sense for us.

We're using it through the web console and API. We're just using the managed service.

How has it helped my organization?

Our organization is launching a lot of betas. We are creating a lot of new different systems for different customers. AWS WAF helps us a lot to make sure that the right customer gets the right access to the system.

What is most valuable?

The access instruction feature is the most valuable. This is what we use the most.

What needs improvement?

It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful.

It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one.

Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right.

Buyer's Guide
AWS WAF
November 2024
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.

For how long have I used the solution?

I have been using AWS WAF for about six months.

What do I think about the stability of the solution?

Stability-wise, it works as expected.

What do I think about the scalability of the solution?

I definitely see places where it can be more designed to scale. In addition to amazon resources, there is some stuff from other vendors that we wanted to protect. WAF was not a solution for us because we don't have a way to integrate with those things. That was the biggest challenge that we faced. In terms of the number of users, our end users could be in the thousands.

How are customer service and support?

It is okay.

How was the initial setup?

It was okay. We went for the cloud formation, and our deployments happen probably every week.

What about the implementation team?

Everything is managed through cloud formation. After implementation, three or four hours a week are required for maintenance.

What's my experience with pricing, setup cost, and licensing?

We are kind of doing a POC comparison to see what works best. Pricing-wise, AWS is one of the most attractive ones. It is fairly cheap, and we like the pricing part. We're trying to see what makes more sense operation-wise, license-wise, and pricing-wise.

What other advice do I have?

I won't recommend it at the moment because I don't have a full picture to recommend it or say that it is bad or good. I'll probably just keep testing and go with it for probably another six months or a year, and then I can probably recommend it or not. 

Other vendors are also providing solutions for D-DOS protection and WAF. It would be nice to see something outside the box for AWS WAF to make it compete with other vendors.

I would rate AWS WAF a seven out of ten. It does what it is supposed to do, probably not in the best way and not in the best UI, but it works. We like the pricing part, but management is the thing that we don't love the most. If things keep improving, we're definitely going to scale with AWS WAF.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Uddeshya Kumar - PeerSpot reviewer
Product Owner at SecLogic Limited
Real User
Top 5Leaderboard
A stable solution that is easy to deploy and provides a helpful support team
Pros and Cons
  • "The tool’s stability is very good."
  • "The cost must be reduced."

What is our primary use case?

We use the solution for filtering traffic. We do not want our developers to use unnecessary websites. So, we filter the websites using the tool.

What is most valuable?

All the features are good. AWS Lambda and S3 are valuable tools. We have to use these tools when we build applications.

What needs improvement?

The cost must be reduced.

For how long have I used the solution?

I have been using the solution for a year. I use the latest version.

What do I think about the stability of the solution?

The tool’s stability is very good. It is better than GCP.

What do I think about the scalability of the solution?

The tool’s scalability is good. We have almost 20 users.

How are customer service and support?

The support is helpful.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We also use GCP.

How was the initial setup?

The initial setup is very easy. Everything is on the cloud. The deployment takes one full day.

What about the implementation team?

We deploy the product in-house. We need one senior solution architect and one junior solution architect to deploy the tool. We have a team of analysts for experiments. We need only one person to maintain the solution.

What's my experience with pricing, setup cost, and licensing?

The product is expensive.

What other advice do I have?

We use almost 40 services. Overall, I rate the product an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
AWS WAF
November 2024
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
Prasanth MG - PeerSpot reviewer
Software Engineer at Readyly
Real User
Top 5Leaderboard
Allows us to set up security rules and has a good scalability
Pros and Cons
  • "The solution's initial setup process is easy."
  • "The solution could be more reliable."

What is our primary use case?

We use the solution as a firewall to protect the network from malicious requests.

How has it helped my organization?

The solution helps our organization to comply with our security standards.

What is most valuable?

The solution allows us to set up rules for blocking malicious requests. We can configure a pool of such sources and choose what to do (allow/block/count) when a request comes from them.

What needs improvement?

The solution can include provisions to block requests targeted at specific URIs (/.env) which are obviously malicious. Also, sometimes it blocks legitimate requests. We have to keep changing some of our rules in this case. It would be great if they maintained the AWS-managed rule sets properly.

For how long have I used the solution?

We have been using the solution for the last eight months.

What do I think about the stability of the solution?

It is a stable solution. Although sometimes even legitimate requests fail.

I rate its stability an eight out of ten.

What do I think about the scalability of the solution?

It is a scalable solution. We have two users in our organization.

How was the initial setup?

The solution's initial setup process is easy.

What other advice do I have?

I advise others to set their security principles while building the software itself, as WAF is not entirely reliable. I rate it an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Manager, IT Infrastructure & Information Security at flyadeal
Real User
Provides good OWASP top 10 protection but needs improvement in security efficiency related to bad bots
Pros and Cons
  • "The security firewall plus the features that protect against database injections or scripting,"
  • "For now, there is no feature to protect against attack of the bad bots"

What is our primary use case?

I'm a manager and in charge of IT infrastructure and information security for an airline company. We're a customer of AWS WAF. We use the product to protect the websites that our customers access to book flights. It provides the sites with DDoS protection and OWASP top 10 application security.

What is most valuable?

The best features are the security firewall and the features that protect against database injections or scripting, and against overall OWASP top 10, but I have concerns about the cloud front which doesn't handle bot attacks properly, so it's not as effective as I would like it to be.

What needs improvement?

A significant improvement would be built in bots protection enhancement, or seamless integration with other products. For now, there are limited feature to protect against an attack from the bad bots so users go to third party solutions, which just complicates integration and operation.

A helpful additional feature would be to have a fully unified unique product, including the DDoS, with sophisticated attack capabilities including anti bot management. They should also take a look at reviewing the complexity of the integration with other third-party vendor solutions.

For how long have I used the solution?

I've been using the product for the last two years. We upgraded recently and I'm using the latest version. 

How are customer service and technical support?

Technical support is good. 

How was the initial setup?

Deployment is easy, it's not complex.The complexity is when you need it for integration with other third-party products. We also use CDN, part of the web solution from Amazon. 

What's my experience with pricing, setup cost, and licensing?

The price of the product is fair enough and one of the product's advantages. Their price is good compared to other vendors. 

What other advice do I have?

The main difference with other similar products is the security efficiency against the type of attacks because normally Amazon works with certain types of attacks and is unable to deal with most of the more sophisticated new attacks that are now the market. So if you compare AWS WAF to the leaders in the field like Imperva, Akamai or radware, they are still beyond these products.

I would recommend that if you don't have a critical heavy use website, and you have a simple business that doesn't require high protection or high-security efficiency, go with this product, but if you have something where security is critical you should go with the leaders in the market, companies like Akamai, Radware, PerimeterX or Imperva.

I would rate this product a seven out of 10. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Jefe subdepartamento Operaciones at a government with 10,001+ employees
Real User
Reasonably priced, stable, and offers excellent performance
Pros and Cons
  • "Their technical support has been quite good."
  • "We haven't faced any problems with the solution."

What is our primary use case?

I primarily use the solution as a gateway service and a transaction portal. 

What is most valuable?

We haven't had any issues with the solution so far.

The pricing of the product is very good. They make it very reasonable and it's very easy to afford.

Their technical support has been quite good.

The performance is excellent. It's reliable.

We've found the solution to be quite stable.

What needs improvement?

We haven't faced any problems with the solution. I can't speak to any missing features. Every aspect of it has been quite good.

For how long have I used the solution?

I've been using the solution for a while.

What do I think about the stability of the solution?

The stability has been very good. We've enjoyed a very reliable performance. There are no bugs or glitches. It doesn't crash or freeze. It's been good.

How are customer service and technical support?

Technical support has been quite good. We've found them helpful and responsive. We are quite satisfied with the level of support that is provided to us.

What's my experience with pricing, setup cost, and licensing?

The solution is very reasonably priced. 

What other advice do I have?

I'm just a customer and an end-user. I don't have a business relationship or partnership with AWS.

I have pretty good experience in AWS. I have a certificate in AWS.

I'd rate the solution at a ten out of ten. We've been extremely satisfied with the solution.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1143783 - PeerSpot reviewer
Advisory and IT Transformation Consultant at a tech services company with 10,001+ employees
Real User
Top 20
A straightforward setup with a quick deployment with good auto-management features
Pros and Cons
  • "The initial setup was very straightforward. Deployment took about ten minutes or less."
  • "They should work to define more threats, add more security, and make it more compliant with more security companies."

What is our primary use case?

The primary use of the solution is for perimeter security. I use it to secure my application and infrastructure.

What is most valuable?

Fast deployment and auto-manage are the most valuable aspects of the solution. The auto-manage primarily reacts and has to do all the little things like putting in the ACL, etc. 

What needs improvement?

The solution could be faster in detecting threats.

They should work to define more threats, add more security, and make it more compliant with more security companies.

The solution could always be more automated.

For how long have I used the solution?

I've been using the solution for three years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

The solution is easily scalable.

How are customer service and technical support?

I have a number for WAF, but I've never used technical support.

Which solution did I use previously and why did I switch?

I previously used a different solution. The complex setup and installation were the main differences between that and WAF. I've worked with system compliance for many years, and it usually involves complex solutions. You have to know the CLF, etc. Cisco, for example, is so complex that you need to know many things. Whereas with WAF, you have to put up your host, your network, and you have the solution up and running.

How was the initial setup?

The initial setup was very straightforward. Deployment took about ten minutes or less. You only need one person to handle deployment and maintenance.

What about the implementation team?

I implemented the solution myself.

What other advice do I have?

We use the public cloud deployment model.

I use everything AWS. I need it to work for me, and it does. I hope that the solution continues to improve, but for me, it's perfect right now.

For those considering implementing the solution, I would advise that they understand how networks work because sometimes they can be quite complex. Many architects do not understand the basic concepts of networking.

I would recommend the solution. I would rate it nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
CVO at Megaaisec
Real User
Top 5
Helps to implement response recovery procedures
Pros and Cons
  • "One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services."
  • "I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy."

What is our primary use case?

One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services.

What needs improvement?

I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy.

For how long have I used the solution?

I have been using the solution for almost a decade.

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

The solution is scalable.

How was the initial setup?

The initial setup was easy.

What about the implementation team?

Our in-house engineers implemented the solution. They are already familiar with AWS and hold AWS certifications.

What other advice do I have?

Overall, I rate the solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1940067 - PeerSpot reviewer
Regional Security Team Lead at a computer software company with 1,001-5,000 employees
Real User
Stable web application firewall used to protect against common vulnerabilities with a powerful CDN component
Pros and Cons
  • "The simple configuration and the scalability have been most valuable. We are able to scale across all of our different AWS instances."
  • "This solution could be improved if the configuration steps were more specific to WAF, compared to other cloud services."

What is our primary use case?

We use this solution to protect our web applications against common vulnerabilities. The CDN component is also quite powerful. We use this solution alongside Azure WAF.

What is most valuable?

The simple configuration and the scalability have been most valuable. We are able to scale across all of our different AWS instances.

What needs improvement?

This solution could be improved if the configuration steps were more specific to WAF, compared to other cloud services. 

For how long have I used the solution?

I have been using this solution for two years. 

What do I think about the stability of the solution?

This is a stable solution. We rely on AWS's other cloud services and we've never experienced any stability issues. 

What do I think about the scalability of the solution?

This is a scalable solution. 

How are customer service and support?

Our support experience has been quite good. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

The main reason we switched from using CloudFlare to AWS is to have a native offering because all of our cloud solutions are on AWS. This made it simpler compared to using a third party and easier to reroute traffic.

How was the initial setup?

It depends on your AWS configuration, but what we've experienced is that the rule policy configuration is really straightforward. It took a couple of weeks. 

What about the implementation team?

We had in-house expertise.

What's my experience with pricing, setup cost, and licensing?

We have a medium amount of traffic per month and the cost is in the hundreds rather than in the thousands. I don't know the exact number.

What other advice do I have?

I would advise others to ensure they understand what can be done internally and then what you need expertise for externally. If you have the expertise internally, it can be easily configured. Keep the SIEM configuration as simple as possible, rather than trying to modify and configure too many things.

I would rate this solution an eight out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.
Updated: November 2024
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.