Try our new research platform with insights from 80,000+ expert users

Cloudflare Web Application Firewall vs NGINX App Protect comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.2
Number of Reviews
74
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Cloudflare Web Application ...
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
23
Ranking in other categories
Web Application Firewall (WAF) (6th)
NGINX App Protect
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
24
Ranking in other categories
Web Application Firewall (WAF) (15th), Container Security (22nd), API Security (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
SachidDoshi - PeerSpot reviewer
Offers a huge signature repository and is superiorly effective in mitigating DDoS attacks
The solution's learning curve can still be further reduced, which presently stands at two or three months. The product has a custom rule set that users can modify and manifest as needed. The vendor can probably shorten the learning curve using cutting-edge technologies like AI. The solution provider can also work around the web applications and identify the toolset that needs to be implemented to deploy the solution in less time. The vendor has launched a SASE product that can function with Cloudflare Web Application Firewall, but many improvements are needed in terms of features, such as the web filtering feature, and CASB has not yet been added.
Saurav Kumar - PeerSpot reviewer
Offers protection to users from external threats
NGINX App Protect secures our company's application, and it has helped me a lot, considering that we have critical infrastructure in India where we see how lots of attacks come onto our organization's servers. The tool offers protection against multiple threats present in India's IT ecosystem. The tool helps our company to make our payments secure, meaning it has the ability to provide a secure payment environment in India. Speaking about the improvements in our company's application performance since implementing NGINX App Protect, the gRPC support for the solution is very low. My company is not getting any proper documentation on how to deploy gRPC over NGINX App Protect. I recommend the product to those who plan to use it. People can use the product as their company's base server, WAF, or for its proxy manager, depending on the business requirements. My company follows PCI DSS compliance because we operate in a payment-related industry. Right now, my company follows all the standards, so we comply with all the requirements and policies. I rate the tool an eight out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Even when there is a high load on our servers, Cloudflare is able to cache the data and serve it to users, ensuring they can still access the website."
"The most valuable features of the solution are performance and security."
"I like Cloudflare's application gateway and DDoS protection."
"Smaller businesses have seen great ROI due to the low investment and strong performance."
"Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications."
"The tool is user-friendly."
"The most valuable feature of Cloudflare is that it has a free version. They give us the free version with the anti-DDoS features and also the load balancing solution."
"It's very user-friendly."
"Someone with a basic understanding of networking and security will be able to implement the firewall's basic features within 15 minutes."
"It is a SaaS solution unlike much of the competition."
"We like that there's load balancing, firewall capabilities, DDoS protection, et cetera, all covered by Cloudflare."
"It protects web applications efficiently."
"Does a good job preventing web application attacks."
"The initial setup process is simple."
"The product has a valuable security control functionality."
"The solution protects our application, which runs on the HTTP protocol, from DDoS attacks."
"The most valuable feature of NGINX App Protect is the reverse proxy."
"WAF is useful to track mitigation, inclusion, prevention, and the parametric firewall."
"The tool is not complex and is very user-friendly."
"I tested specific features and evaluated the solution against the Web Application Firewall. I conducted research to test different detection percentages. I did not use it directly for protection but for evaluation purposes."
"The policies are flexible based on the technologies you use."
"The stability of the product is very impressive since it handles 60,000 to 70,000 requests or transactions per second."
"It's very easy to deploy."
"The tool's most valuable feature is the OWASP certification. Additionally, the tool's ability to enforce strong passwords and OTP within minutes is impressive. With its analytics and recommendations, it is a very good solution."
 

Cons

"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"DNS Management."
"The analytics, basically the dashboard, doesn't have much to it."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"Cloudflare doesn't have a reverse lookup. We can only do a DNS lookup to get the IP address from the hostname. It doesn't work if you want to look up the hostname from an IPA address."
"I believe they currently have this feature, but there will most likely be integration with APIs so we can control some features through API."
"Areas like how assessment, discovery, and payload are dealt with and how it all comes into your organization can be considered when trying to make suggestions to Cloudflare for improvements."
"In the last two years, there has been a certain amount of downtime when using the VDM."
"I have experienced some difficulties with Cloudflare's support as a customer based in India."
"The platform's control features related to real-time authentication and response time need improvement."
"The dashboard could be more user-friendly."
"Its stability could be better."
"If they add logs history within the Cloudflare offering, that would be a great benefit."
"Cloudflare Web Application Firewall should improve visibility for a customer."
"The ModSecurity core rules need to be updated."
"The learning curve was steep initially."
"It would be better if it were easier to implement and if there was more information from F5 regarding hardware requirements and specifications to deploy the service, to avoid disruptions after implementation."
"It doesn't have more advanced features like no false-positive security, which you can configure in Advanced WAF."
"NGINX App Protect could improve security."
"The product's price is high, making it an area of concern where improvements are required. The tool's licensing model is also not good."
"Setting policies and parameters through the UI should be more automated because the process is manual, where we can only edit one rule at a time."
"The price of NGINX App Protect could improve."
"The configuration needs to be more flexible because it is difficult to do things that are outside of the ordinary."
"The integration of NGINX App Protect could improve."
 

Pricing and Cost Advice

"We don't have any issues with the price."
"The cost primarily depends on the size of the organization."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"That is one of the great features. I was able to access the majority of the features and services for free."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"We are using the free version."
"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"It is not too pricey."
"The annual licensing fee is $10,000 USD."
"It starts at $20 and can easily go up to $200 monthly"
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"We pay $210 per month for CloudFlare WAF."
"The solution is expensive."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"The price of NGINX App Protect is not much different from the products that fall under the leader category of Gartner Magic Quadrant."
"There are no additional fees."
"The pricing is reasonable because NGINX operates on an instance basis."
"Really understand the licensing model, because we underestimated that."
"NGINX is not expensive."
"The product's price is high."
"There is a monthly or annual subscription to use NGINX App Protect. There are not any additional costs to the subscription."
"There is a license needed to use NGINX App Protect."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
842,296 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
21%
Computer Software Company
13%
Comms Service Provider
9%
Financial Services Firm
8%
Educational Organization
25%
Computer Software Company
14%
Financial Services Firm
7%
Manufacturing Company
5%
Computer Software Company
19%
Financial Services Firm
14%
Comms Service Provider
7%
Retailer
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Cloudflare Web Application Firewall?
The product has a valuable security control functionality.
What is your experience regarding pricing and costs for Cloudflare Web Application Firewall?
Cloudflare is cheaper compared to Azure WAF, which I have considered before.
What needs improvement with Cloudflare Web Application Firewall?
The product can improve by having more multitenancy capability, which is currently not available. This improvement wo...
What needs improvement with NGINX App Protect?
The product's price is high, making it an area of concern where improvements are required. The tool's licensing model...
 

Also Known As

Cloudflare DNS
Cloudflare WAF
NGINX WAF, NGINX Web Application Firewall
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
crunchbase, udacity, marketo, okcupid, zendesk
Information Not Available
Find out what your peers are saying about Cloudflare Web Application Firewall vs. NGINX App Protect and other solutions. Updated: March 2025.
842,296 professionals have used our research since 2012.