Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Akamai App and API Protector comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Akamai App and API Protector
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
28
Ranking in other categories
Web Application Firewall (WAF) (8th), Distributed Denial-of-Service (DDoS) Protection (4th), Cloud and Data Center Security (10th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
8.0
Number of Reviews
57
Ranking in other categories
Web Application Firewall (WAF) (1st)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Deepesh  Singh - PeerSpot reviewer
Bot Manager and different features to manage threats
As a product, it has good capabilities, including professional support. However, it's risky for us to rely on AI for real-time traffic management. We use in-house analytics but avoid automatic actions due to their high impact. For example, I live in a developing country. Everyone has different types of phones, apps, and everything else. So, if someone is using a legacy phone, that is still a use case here. If AI decides that this is an end-of-life phone or end-of-life Android operating system, it starts blocking that traffic. We may potentially lose millions or probably thousands and hundreds of thousands of hits per second. Everything is all about how well we serve payments because we're into payments. So, AI is used for analytics but not for real-time decisions. We can't afford to block traffic based on AI models due to the variety of devices and operating systems our users have.
Rohit Kesharwani - PeerSpot reviewer
A highly stable solution that helps mitigate different kinds of bot attacks and SQL injection attacks
Integrating AWS WAF with other AWS services in our infrastructure is fairly easy. There are different tools through which we can do it. AWS WAF is a fairly easy solution. Users need to build a few rules by themselves based on the vulnerability attack within the application. Overall, I rate the solution a nine out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its ease of integration with Office 365 and the fact that it's a good product compared to what I had before"
"The most valuable feature of Cloudflare DNS is security."
"The DDoS protection is the most valuable aspect of the solution."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"I get a lot of value from Cloudflare's API because it enables you to build a separate environment inside the solution. You can create a domain for performing test requests before you move to the production environment and connect various domains."
"The solution offers the flexibility to control configuration rules."
"Cloudflare allows us to self-host services such as Rocket.Chat and Node-RED, in high-availability mode, thanks to round robin DNS which allows us to share one hostname between our two locations."
"The product has a good UI."
"The features are powerful and better than F5."
"Akamai Web Application Protector is a good solution that provides basic web application protection."
"I can attest to its benefits in terms of understanding and mitigating threats...The solution's technical support team seems to be pretty responsive."
"The solution can scale extremely well."
"The CDN and the WAF features are the best."
"All the solution's features are very good."
"Everything will be handled by Akamai's system before it reaches our infrastructure."
"The stability of AWS WAF is valuable."
"The most valuable feature is the scalability because it automatically scales up or scales down as per our requirements."
"The simple configuration and the scalability have been most valuable. We are able to scale across all of our different AWS instances."
"AWS WAF helps mitigate different kinds of bot attacks and SQL injection that happen within the retail industry."
"The most valuable feature of AWS WAF is the extra layer of security that I have when connecting to my web applications."
"Rule groups are valuable."
"The most valuable features are the geo-restriction denials and the web ACL."
"The most valuable feature is the security, making sure that files are protected, preventing unauthorized users from accessing the system."
 

Cons

"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"The product support needs to be accessible from more places, a wider area of coverage."
"I think the APIs are a little bit hard for us to work with. The APIs could be more open so that we could integrate better with our SolarWinds or our monitoring solution."
"It should have easier documentation for the configuration. It's very technical and people who aren't technical should also be able to do the configuration."
"Even if I wanted to, I wouldn't be able to buy Cloudflare in my country."
"The reporting can definitely be improved to offer a lot more explanation on something that may have happened or has actually happened."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"Akamai needs to focus on quickly responding to risks, even those that may potentially be of zero threat..Maybe some of the documentation is a little confusing. They have a lot of different places where you can go to get information, and some of the information is quite out of date."
"One area where Akamai can improve is the captcha part. Cloudflare provides a captcha if there are a certain number of threats. For example, I can assign that if there are 10 requests within a second from a single IP, it should send a captcha to the user. The user should fill in the captcha, and only after that, the user should be able to access our website. This captcha feature should be built into Bot Manager. I love this captcha feature of Cloudflare."
"The solution could offer even more integrations."
"It's fine for a simple tool, but as I recall, if you encounter a lot of bots, scrapers, and other things, you'll need this tool bot and this other thing they offer called Bot Manager."
"There are some issues with pushing configurations across a network. It still takes about 20 minutes and that means to retract it's another 20 minutes."
"They are already very flexible, but room for improvement is there. Reports generation could be better and should be improved."
"Akamai App and API Protector is very new to me, so I do not have any insights on improvement areas for the product. However, when we ask for some help, it can take some time. We understand that the job is done by professionals, but if that time can be reduced, it would be great."
"The pricing could be reduced a bit."
"They should make the implementation process faster."
"We don't have much control over blocking, because the WAF is managed by AWS."
"The solution is cloud-based, and therefore the billing model that comes with it could be more intuitive, in my opinion. It's very easy to not fully understand how you tag things for billing and then you can quite easily run up a high bill without realizing it. The solution needs to be more intuitive around the tagging system, which enables the billing. Right now, I have a cloud architect that does that on our behalf and it isn't something that a business user could use because it still requires quite a lot of technical knowledge to do effectively."
"It will be helpful if the product recommends rules that we can implement."
"The user experience, the interface, is lacking. Sometimes it's hard to find certain areas that it has alerted on."
"It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful. It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one. Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right."
"We should be able to do proper whitelisting."
"In a future release I would like to see automation. There's no interaction between the applications and that makes it tedious. We have to do the preparation all over again for each of our other applications."
 

Pricing and Cost Advice

"There are no additional costs beyond the standard licensing fees."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The cost primarily depends on the size of the organization."
"So far I use free tier and happy with it. You can subscribe to business package if needed."
"We don't have any issues with the price."
"That is one of the great features. I was able to access the majority of the features and services for free."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"Akamai Web Application Protector is an expensive product."
"The price they are offering is quite reasonable for premium customers, but it's very expensive if you're a small and medium-sized enterprises."
"Its price is slightly high. Every company has a justification for the high price. Overall, it feels worth the money based on how the service has been structured, but we do negotiate it."
"The product’s price is high."
"Based on the billing discussions in the DevOps team, Akamai's cost does not seem to be a major thing. However, LOE is an issue. When it comes to support, we know that even all the competitors do this. For a 30-minute issue, they give us a LOE of one or two hours. That is a basic practice, but that is something we worry about."
"The solution is expensive."
"It's more expensive than others, but the ROI is good for large-scale infrastructure."
"If you want quality, you have to pay the price. Its price is fair. Their account managers are also very helpful. They help you a lot with pricing even though they are working with Akamai."
"Its price is fair. There is a very fair amount that they charge. It has a pay-as-you-go model, so it pretty much depends on how much a user uses it. As per the cloud norms, the more you use, the more you pay. I would rate it a five out of ten in terms of pricing."
"The product is moderately priced."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven or eight out of ten."
"You need an additional AWS subscription for this product if you are buying a managed tool."
"It's cheap."
"It's quite affordable. It's in the middle."
"AWS WAF has reasonable pricing."
"The price is average."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
823,795 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
7%
Financial Services Firm
7%
Financial Services Firm
26%
Computer Software Company
14%
Manufacturing Company
8%
Insurance Company
5%
Computer Software Company
16%
Financial Services Firm
14%
Manufacturing Company
8%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What is your experience regarding pricing and costs for Akamai Web Application Protector?
The price is higher than others. It could be about 80% to 70% more expensive than other tools. So, it’s not just a sl...
What needs improvement with Akamai Web Application Protector?
It could have better analytics and reporting visibility in the OEM console.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
 

Also Known As

Cloudflare DNS
Akamai Web Application Protector, Akamai Kona Site Defender, Akamai Kona DDoS Defender
AWS Web Application Firewall
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Douglas Omaha Technology Commission, ZALORA, PrintPlanet
eVitamins, 9Splay, Senao International
Find out what your peers are saying about AWS WAF vs. Akamai App and API Protector and other solutions. Updated: December 2024.
823,795 professionals have used our research since 2012.