Find out in this report how the two Web Application Firewall (WAF) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
For the small project I was working on, using the basic tier provided a huge improvement at zero cost.
In terms of return on investment with Cloudflare, it costs my time to set them up, but basically once they're set up, it's done.
The return on investment for me is significant as time is the critical aspect.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
Cloudflare does not offer hands-on technical support to fix customer problems but rather a self-service model.
I would rate the technical support with Cloudflare as excellent every time I've had to call them.
We use other solutions where support is available through Slack channels and is more interactive, with someone responding within a couple of minutes or seconds.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
It is a SaaS tool, but the fact that they have workloads deployed across the world proves that it is a highly scalable tool.
The tool offers very good performance, even during high-traffic periods.
Cloudflare's scalability is quite good; it is very easy to scale whenever we want to include multiple domains.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
We faced issues with AWS WAF when writing the custom rules.
The service is very stable with no impacts during high-traffic periods.
Cloudflare's reliability and uptime has met my expectations; it has been quite good in general.
The product can improve by having more multitenancy capability, which is currently not available.
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF.
Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements.
There are some performance considerations when it comes to dynamic content that involves fetching data from databases or using APIs.
What Cloudflare is doing internally is that it is stepping ahead in areas like detection and protection.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
I find it to be cheap.
I rate the product’s pricing a five out of ten, where one is cheap, and ten is expensive.
The tool is a premium product, so it is very expensive.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
The cloud-native nature of AWS is crucial since most of our workload is in AWS, making AWS WAF native to Amazon Web Services.
Techniques like minification and image compression reduce the size of assets, leading to better performance and faster user load times.
The solution has been able to compare it to the market, and I think the product has taken great strides in automating quite a bit of things, and they use a lot of AI.
Most of our DNS records that are presented to the internet are proxied whenever possible, providing another layer of defense from our perspective.
| Product | Mindshare (%) |
|---|---|
| AWS WAF | 4.8% |
| Imperva Application Security Platform | 7.7% |
| Fortinet FortiWeb | 6.0% |
| Other | 81.5% |
| Product | Mindshare (%) |
|---|---|
| Cloudflare | 14.0% |
| Imperva Application Security Platform | 8.5% |
| Arbor DDoS | 7.2% |
| Other | 70.3% |


| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 6 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 22 |
| Midsize Enterprise | 12 |
| Large Enterprise | 26 |
| Company Size | Count |
|---|---|
| Small Business | 46 |
| Midsize Enterprise | 11 |
| Large Enterprise | 26 |
Cloudflare Web Application Firewall integrates DDoS protection, load balancing, and firewall capabilities. Its ease of use, configurability, and robust security measures make it a versatile choice for protecting web applications.
Cloudflare Web Application Firewall provides a comprehensive defense against threats with advanced reporting and robust security measures. It includes DNS integration, rate limiting, and extensive rule sets, all within a SaaS model that allows API configurability. Users value its caching, scalability, and pricing, although enhancements are needed in rate-limiting and third-party integration. Improvements in customer support, especially in India, real-time controls, and user documentation are also desired. Users seek a more intuitive dashboard, better log management, and improved alert systems, along with multitenancy capabilities and enhanced reporting.
What are the key features of Cloudflare Web Application Firewall?Cloudflare Web Application Firewall finds application in industries like banking and retail by acting as a comprehensive security gateway, managing authentication and authorization while protecting web applications from malicious Layer 7 traffic. It also implements load balancing, CDN, and zero-trust policies, supported by advanced reporting, analytics tools, and threat scoring to meet specific industry needs.
AWS WAF provides configurable rules, integration with AWS services, and scalable protection against web threats like SQL injections and DDoS attacks. Its automation and reliable performance are highly valued by users.
AWS WAF is a web application firewall offering significant security features like geo-restriction, custom rules, and IP filtering. Designed for seamless orchestration within AWS environments, it facilitates easy configuration and threat automation. Users benefit from its security policies, enhancing application performance by protecting against threats such as cross-site scripting. Despite its strengths, there is a call for enhanced user interfaces, better documentation, flexible pricing, and improved support. Expanding features like real-time analysis, bot protection, and AI integration can further elevate its utility.
What are the key features of AWS WAF?AWS WAF is extensively used in industries hosting applications on AWS, protecting sensitive data, and monitoring for unauthorized access. Custom and managed rules help cater to infrastructure needs, serving a vital role in maintaining application security across various sectors.
Cloudflare enhances web performance and security with features like CDN caching and DDoS mitigation while providing easy DNS management and intuitive setup through its user-friendly dashboard.
Cloudflare is recognized for its comprehensive web security and performance solutions. Speed improvements are achieved through caching mechanisms and DDoS protection, combining ease of DNS management with flexible page rules. The robust analytics and threat insight tools provide valuable data, assisted by a user-friendly dashboard allowing quick setup and configuration. An API offers dynamic DNS settings ensuring low latency and high performance across the globe.
What are Cloudflare's key features?Cloudflare finds utility across industries for DNS management and defense mechanisms. Its content delivery network assures fast content distribution and fortified security. Businesses integrate features like web application firewalls, load balancing, end-to-end SSL, and zero trust to protect websites from cyber threats while ensuring resilience and reliable performance.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.