Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Cloudflare comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.6
Cloudflare WAF offers quick ROI, crucial protection for e-commerce, saves bandwidth, and balances cost with valuable free features.
Sentiment score
6.9
AWS WAF enhances security and cost efficiency by integrating with AWS, reducing the need for additional security personnel.
Sentiment score
6.1
Cloudflare improves performance, security, and financial outcomes with affordable plans, enhancing user satisfaction and operational efficiency significantly.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
Owner at Hga consulting
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
For the small project I was working on, using the basic tier provided a huge improvement at zero cost.
Security Specialist at a tech services company with 1,001-5,000 employees
In terms of return on investment with Cloudflare, it costs my time to set them up, but basically once they're set up, it's done.
Owner at Hga consulting
 

Customer Service

Sentiment score
6.3
Cloudflare WAF support is mixed; responsive for some, but Indian customers face call availability and administrative issues.
Sentiment score
6.7
AWS WAF support receives mixed reviews, praised for responsiveness and expertise, yet criticized for cost and inconsistent communication.
Sentiment score
6.9
Cloudflare's customer service is praised for promptness, but technical support feedback varies, especially favoring Enterprise tier users.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
Owner at Hga consulting
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
IT Manager at Amla Commerce
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
Security Engineer at a computer software company with 1,001-5,000 employees
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
Cloudflare does not offer hands-on technical support to fix customer problems but rather a self-service model.
Senior Consultant CDN at a comms service provider with 10,001+ employees
I would rate the technical support with Cloudflare as excellent every time I've had to call them.
Owner at Hga consulting
We use other solutions where support is available through Slack channels and is more interactive, with someone responding within a couple of minutes or seconds.
General Manager at bKash Limited
 

Scalability Issues

Sentiment score
7.7
Cloudflare Web Application Firewall offers impressive scalability and automated management, but additional features may incur costs for smaller organizations.
Sentiment score
7.8
AWS WAF excels in scalability and auto-scaling, efficiently handling traffic for businesses of all sizes, though improvements are possible.
Sentiment score
7.9
Users praise Cloudflare's scalability, flexibility, and seamless tier transitions for maintaining high performance under increasing traffic and demands.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
IT Manager at Amla Commerce
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
It is a SaaS tool, but the fact that they have workloads deployed across the world proves that it is a highly scalable tool.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
The tool offers very good performance, even during high-traffic periods.
Engineer at SITMEXICO
I rate the solution’s scalability an eight out of ten.
Independent Consultant at Unaikui
 

Stability Issues

Sentiment score
8.2
Cloudflare Web Application Firewall is praised for stability, high performance, effective protection, daily use, and minimal downtime.
Sentiment score
8.3
AWS WAF is highly rated for stability due to reliable performance, strong protection, and effective redundancy features.
Sentiment score
7.5
Cloudflare is generally stable and reliable, with some initial setup challenges but excellent performance and positive user feedback.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
IT Manager at Amla Commerce
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
Security Engineer at a computer software company with 1,001-5,000 employees
We faced issues with AWS WAF when writing the custom rules.
Infrastructure Lead at Danat Fz LLC
I rate the solution’s stability an eight out of ten.
Independent Consultant at Unaikui
The service is very stable with no impacts during high-traffic periods.
Engineer at SITMEXICO
 

Room For Improvement

Cloudflare WAF needs feature enhancements, better usability, improved support, advanced DDoS protection, and solutions for latency and alerts.
AWS WAF requires improved integration, usability, security features, and flexible pricing to better support global users and services.
Cloudflare needs enhancements in speed, support, reliability, pricing, and documentation, while expanding integration, security, and analytics capabilities.
The product can improve by having more multitenancy capability, which is currently not available.
Network Architect at a computer software company with 11-50 employees
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
Owner at Hga consulting
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
CTO at PlayNirvana
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
Security Engineer at a computer software company with 1,001-5,000 employees
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Infrastructure Lead at Danat Fz LLC
Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF.
Security Analyst at M2P Fintech
Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor.
Managed Services Manager at Adapture Technology Group
Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements.
General Manager at bKash Limited
There are some performance considerations when it comes to dynamic content that involves fetching data from databases or using APIs.
Senior Solutions Architect at Think Power Solutions
 

Setup Cost

Cloudflare Web Application Firewall offers affordable, flexible pricing with no upfront costs, noted for competitiveness and included support services.
AWS WAF offers cost-effective, pay-as-you-go pricing, starting at $5 monthly, valued for integration with AWS services.
Enterprise users find Cloudflare cost-effective, with valuable upgrades and competitive pricing, despite unclear enterprise price lists.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
Security Engineer at a computer software company with 1,001-5,000 employees
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Infrastructure Lead at Danat Fz LLC
I find it to be cheap.
Engineer at SITMEXICO
I rate the product’s pricing a five out of ten, where one is cheap, and ten is expensive.
Senior Solutions Architect at Think Power Solutions
The tool is a premium product, so it is very expensive.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
 

Valuable Features

Cloudflare Web Application Firewall provides comprehensive security features, easy setup, scalability, and competitive pricing with praised performance and stability.
AWS WAF offers threat blocking, scalability, automation, and seamless integration, enhancing security and performance with easy deployment and affordability.
Cloudflare provides caching, DDoS protection, and CDN services with enhanced security features, making it vital for optimized web performance.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
Network Architect at a computer software company with 11-50 employees
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
IT Manager at Amla Commerce
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
Owner at Hga consulting
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
Infrastructure Lead at Danat Fz LLC
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
The cloud-native nature of AWS is crucial since most of our workload is in AWS, making AWS WAF native to Amazon Web Services.
Security Analyst at M2P Fintech
Techniques like minification and image compression reduce the size of assets, leading to better performance and faster user load times.
Senior Solutions Architect at Think Power Solutions
The solution has been able to compare it to the market, and I think the product has taken great strides in automating quite a bit of things, and they use a lot of AI.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
Most of our DNS records that are presented to the internet are proxied whenever possible, providing another layer of defense from our perspective.
Senior Security Engineer at ManpowerGroup
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
Web Application Firewall (WAF) (7th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Web Application Firewall (WAF) (4th)
Cloudflare
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
78
Ranking in other categories
CDN (1st), WAN Optimization (4th), Distributed Denial-of-Service (DDoS) Protection (2nd), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (10th)
 

Mindshare comparison

Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
AWS WAF5.3%
Imperva Application Security Platform8.1%
Fortinet FortiWeb7.5%
Other79.1%
Web Application Firewall (WAF)
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Cloudflare16.2%
Arbor DDoS8.7%
Imperva Application Security Platform8.5%
Other66.6%
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
M.A. Faisal - PeerSpot reviewer
General Manager at bKash Limited
Advanced protection has secured critical web workloads and provides clear traffic visibility
From a security perspective, there remains a security loophole, as some browsers in the market can bypass the Turnstile solution, which requires approximately 40 seconds to do so. From a performance perspective, this is acceptable. We also tried Google reCAPTCHA, and that can also be bypassed. From a security perspective, I would say neither solution is completely secured. Regarding uptime, we have faced a couple of incidents due to Cloudflare in recent years, so I cannot say we receive 100% uptime for our region. We sometimes face challenges, including downtime and other issues. As a result, we are not receiving 100% uptime from Cloudflare's solution. Since most of our customers are in this region, we need alternatives. We need something more competitive than Cloudflare. Unfortunately, in Bangladesh, Cloudflare has three points of presence already, and we cannot find any other solution provider in Bangladesh as an alternative, which presents another challenge. Competitor solutions have more attack signatures, which ensure better security compared to Cloudflare's predefined configurations. Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements. Cloudflare could improve in this area. Additionally, regarding visibility, Cloudflare has static visibility, but they could adopt dynamic graph features for their customers.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
883,712 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Security Expert with 51-200 employees
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Manufacturing Company
9%
Financial Services Firm
8%
Comms Service Provider
7%
Financial Services Firm
15%
Computer Software Company
12%
Manufacturing Company
9%
Government
6%
Financial Services Firm
10%
Comms Service Provider
10%
Computer Software Company
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise26
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise26
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
 

Also Known As

Cloudflare WAF
AWS Web Application Firewall
Cloudflare DNS
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
eVitamins, 9Splay, Senao International
Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Find out what your peers are saying about AWS WAF vs. Cloudflare and other solutions. Updated: February 2023.
883,712 professionals have used our research since 2012.