Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Fastly comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
74
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.6
Number of Reviews
58
Ranking in other categories
Web Application Firewall (WAF) (1st)
Fastly
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
7
Ranking in other categories
CDN (6th), Web Application Firewall (WAF) (17th), Distributed Denial-of-Service (DDoS) Protection (8th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Kavin Kalaiarasu - PeerSpot reviewer
AWS's cloud-native security simplifies rule enforcement but needs better DDoS integration
The dashboarding could be improved, and the default metrics provided by AWS WAF could be upgraded. The rate at which AWS updates their managed rule sets could be better. Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF. Instead, they are part of AWS Shield. Providing DDoS protection as part of their WAF solution would be beneficial.
Nick Wilsdon - PeerSpot reviewer
An easily scalable and stable product that provides exceptional support
The product should provide improved bot detection and management. The product should also provide support for code management. Everybody working in CDN is currently looking for ways to better manage code deployment with various authorization levels and synchronization with our lower environments. Matching up what's happening in CDN with what's happening on the origin regarding testing would always be useful.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is its usability."
"Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications."
"The technical support is good."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"Even when there is a high load on our servers, Cloudflare is able to cache the data and serve it to users, ensuring they can still access the website."
"Easier http to https redirect using page rules"
"It's very user-friendly."
"The simplicity of the overall dashboard makes it a great product for a user like me who has less understanding of the internet than a developer or other more technical people. It gives me peace of mind. I also love the easy customization of the Page Rules."
"AWS WAF is a stable solution. The performance of the solution is very good."
"The most valuable feature of AWS WAF is its highly configurable rules system."
"The product’s availability, ease of configuration, and documentation are valuable."
"We do not have to maintain the solution."
"The most valuable feature is the addition of managed tools that help us create customizable rules. In case we want to block a particular request, we can make use of those rules."
"The tool’s stability is very good."
"I believe the most impressive features are integration and ease of use. The best part of AWS WAF is the cloud-native WAF integration. There aren't any hidden deployments or hidden infrastructure which we have to maintain to have AWS WAF. AWS maintains everything; all we have to do is click the button, and WAF will be activated. Any packet coming through the internet will be filtered through."
"The automation of blocking for security attacks is valuable, with AWS applying rate limiting."
"Fastly uses configuration versioning, where you can deploy a new version in less than one minute."
"The product's initial setup phase is straightforward."
"Its initial setup process is straightforward."
"Support is good; the product works as advertised. We have a Slack connection with them. So we can basically ask for help, live, engage, and ring when they respond. Very quickly."
"Rate limiting is a good feature that protects from volumetric attacks."
"The product helps our organization to access sites located in different regions quickly."
"Compute@Edge features are valuable to me."
 

Cons

"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"DNS Management."
"The solution could work at being less expensive. It costs a lot to use it."
"For large enterprises, the pricing is okay. However, the enterprise price for small projects is a bit high. A mid-tier pricing option would be beneficial."
"It should confirm audit findings of the assigned area with auditees to ensure that the audit conclusions are based on an accurate understanding of the issues."
"There could be more courses with engineers. I like e-learning, however, having a specialist in a classroom is more comfortable for me."
"Cloudflare's console should be made more user-friendly."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"The dashboarding could be improved, and the default metrics provided by AWS WAF could be upgraded."
"There is room for improvement in pricing."
"It will be helpful if the product recommends rules that we can implement."
"The rate at which AWS updates their managed rule sets could be better. Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF."
"I would like to see it more tightly integrated with other AWS services."
"One area that could be improved is the DDoS protection."
"One area for improvement in AWS WAF could be the limitation on the number of rules, particularly those from third-party sources, within the free tier."
"We haven't faced any problems with the solution."
"What I don't like about Fastly is that they charge a heavy price."
"Fastly's customer service area needs improvement."
"Support is not that great."
"The product should provide improved bot detection and management."
"Stronger analytics would be helpful, like showing configurations that haven't served a certain amount of traffic in a while. With many properties, things can get lost track of - duplicates or unused configurations not properly decommissioned."
"It is missing a "staging" platform to deploy a test configuration with all of the real settings, which would allow us to properly test before putting it into production."
"The solution's pricing could be better."
 

Pricing and Cost Advice

"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"The cost primarily depends on the size of the organization."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"That is one of the great features. I was able to access the majority of the features and services for free."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"The price is reasonable."
"A free version of the solution is available."
"You need an additional AWS subscription for this product if you are buying a managed tool."
"There are different scale options available for WAF."
"For Kubernetes microservices, AWS is more expensive compared to OCI. AWS costs approximately 70 cents per hour, while OCI is 50% cheaper."
"The pricing is good and manageable."
"I would rate AWS WAF's pricing a seven out of ten."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven or eight out of ten."
"There are no costs in addition to the standard licensing fees."
"AWS WAF has reasonable pricing."
"I've generally found Fastly to be very competitive in pricing, especially around Compute@Edge."
"You need to pay a premium price for the tool."
"Fastly is less expensive than one of its competitors."
"The pricing has been very competitive."
"The solution is cheaper than other products in the market."
"In my opinion, Fastly is priced competitively."
"It is an expensive solution."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
842,296 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
13%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
16%
Financial Services Firm
14%
Manufacturing Company
8%
Government
6%
Computer Software Company
17%
Comms Service Provider
10%
Financial Services Firm
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What do you like most about Fastly?
Support is good; the product works as advertised. We have a Slack connection with them. So we can basically ask for h...
What needs improvement with Fastly?
What I don't like about Fastly is that they charge a heavy price. The pricing is different per region. If you have a ...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
Twitter, Airbnb, Alaska Airlines, Pinterest, Vimeo, The Guardian, The New York Times, Ticketmaster, The Drupal Association, Opera, about.com, imgur, Etsy, Foursquare, GitHub, New Relic, shopify, Shazam, Firebase
Find out what your peers are saying about AWS WAF vs. Fastly and other solutions. Updated: March 2025.
842,296 professionals have used our research since 2012.