Try our new research platform with insights from 80,000+ expert users

Cloudflare Web Application Firewall vs NGINX App Protect comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Cloudflare Web Application ...
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
22
Ranking in other categories
Web Application Firewall (WAF) (7th)
NGINX App Protect
Average Rating
8.4
Reviews Sentiment
7.0
Number of Reviews
22
Ranking in other categories
Web Application Firewall (WAF) (15th), Container Security (22nd), API Security (4th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
SachidDoshi - PeerSpot reviewer
Offers a huge signature repository and is superiorly effective in mitigating DDoS attacks
The solution's learning curve can still be further reduced, which presently stands at two or three months. The product has a custom rule set that users can modify and manifest as needed. The vendor can probably shorten the learning curve using cutting-edge technologies like AI. The solution provider can also work around the web applications and identify the toolset that needs to be implemented to deploy the solution in less time. The vendor has launched a SASE product that can function with Cloudflare Web Application Firewall, but many improvements are needed in terms of features, such as the web filtering feature, and CASB has not yet been added.
Saurav Kumar - PeerSpot reviewer
Offers protection to users from external threats
NGINX App Protect secures our company's application, and it has helped me a lot, considering that we have critical infrastructure in India where we see how lots of attacks come onto our organization's servers. The tool offers protection against multiple threats present in India's IT ecosystem. The tool helps our company to make our payments secure, meaning it has the ability to provide a secure payment environment in India. Speaking about the improvements in our company's application performance since implementing NGINX App Protect, the gRPC support for the solution is very low. My company is not getting any proper documentation on how to deploy gRPC over NGINX App Protect. I recommend the product to those who plan to use it. People can use the product as their company's base server, WAF, or for its proxy manager, depending on the business requirements. My company follows PCI DSS compliance because we operate in a payment-related industry. Right now, my company follows all the standards, so we comply with all the requirements and policies. I rate the tool an eight out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The simplicity of the overall dashboard makes it a great product for a user like me who has less understanding of the internet than a developer or other more technical people. It gives me peace of mind. I also love the easy customization of the Page Rules."
"I rate its stability a ten out of ten."
"What I like best about Cloudflare is that my company can use it to trace and manage applications and monitor traffic. The solution tells you if there's a spike in traffic. Cloudflare also sends you a link to check your equipment and deployment and track it through peering, so it's a valuable tool."
"The UI is good."
"The DDoS protection is the most valuable aspect of the solution."
"The solution is stable, and the DNS servers are simple to use."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"It's very user-friendly."
"Cloudflare is cheaper compared to Azure WAF, which I have considered before."
"Does a good job preventing web application attacks."
"We like that there's load balancing, firewall capabilities, DDoS protection, et cetera, all covered by Cloudflare."
"The product has improved our security posture by blocking bad actors."
"The Cloudflare Web Application Firewall's most valuable feature is its ease of configuration."
"Someone with a basic understanding of networking and security will be able to implement the firewall's basic features within 15 minutes."
"It's pretty convenient and pretty easy to set up and run. And then kind of for static content, it also offers caching."
"It is configurable via API."
"The most valuable feature is that I can establish different services from the firewall."
"It has the best documentation features."
"The most valuable feature is that there is a link in the system that will help to analyze the security of an application when something abnormal is found."
"The tool's most valuable feature is the OWASP certification. Additionally, the tool's ability to enforce strong passwords and OTP within minutes is impressive. With its analytics and recommendations, it is a very good solution."
"The initial setup was simple and took three to four days."
"The tool is not complex and is very user-friendly."
"It is a stable solution."
"The stability of the product is very impressive since it handles 60,000 to 70,000 requests or transactions per second."
 

Cons

"Technical support is lacking."
"We are a product integrator and reseller, and we would like to have a better partner relationship, similar to a channel sales relationship. Sometimes we are on our own or get diverted by Cloudflare because they have direct sales, which competes with us and makes it difficult to build a relationship with this company since we want to be an MSP or a managed service provider for the solution."
"There are some issues with the CDN services."
"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"One area of improvement is in the Access Rules. Hypothetically, if we wanted to block or challenge traffic outside of the United States, the only way to currently do that (as far as I know) is to enter every single country outside of the United States. That could be a labor intensive job. A solution could be to enable users to create a rule where traffic is only allowed within a certain country."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"Cloudflare's console should be made more user-friendly."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"Support can be challenging at times."
"It would be ideal if the solution offered better log integration and more integration with different platforms."
"Its stability could be better."
"We have noticed some latency when the call goes through the firewall. That could be improved."
"Cloudflare Web Application Firewall should improve visibility for a customer."
"The learning curve was steep initially."
"The blocked logs are difficult to read at times."
"There could be an option to duplicate the cluster to maintain the consistency of rules."
"Its technical support could be better."
"The configuration needs to be more flexible because it is difficult to do things that are outside of the ordinary."
"Right now, the tool doesn't provide an option revolving around update feeds, specifically the signature update option in the UI."
"I encountered issues with NGINX App Protect while trying to upgrade custom rules."
"Areas for improvement would be if NGINX could scan for vulnerabilities and learn and update the signatures of DoS attacks."
"Setting policies and parameters through the UI should be more automated because the process is manual, where we can only edit one rule at a time."
"As far as scalability, it takes a long time for deployment."
"Currently, the policies have to be handled manually, and you have to create from scratch, which can be a bit time-consuming, in a large environment."
 

Pricing and Cost Advice

"The product's pricing is minimal compared to other products."
"We are using the free tier of the solution."
"The price is reasonable."
"The product's pricing is cheap."
"I give the price a five out of ten."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"The tool is a premium product, so it is very expensive."
"It is not too pricey."
"We pay $210 per month for CloudFlare WAF."
"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"The annual licensing fee is $10,000 USD."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"It starts at $20 and can easily go up to $200 monthly"
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"The solution's price is reasonable."
"The price of NGINX App Protect is not much different from the products that fall under the leader category of Gartner Magic Quadrant."
"NGINX is not expensive."
"The product's price is high."
"Really understand the licensing model, because we underestimated that."
"There are not any additional costs we had to pay to use NGINX App Protect."
"There is a monthly or annual subscription to use NGINX App Protect. There are not any additional costs to the subscription."
"Our licensing costs are about $40,000 a year."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
831,265 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
8%
Financial Services Firm
7%
Educational Organization
28%
Computer Software Company
13%
Financial Services Firm
8%
Manufacturing Company
5%
Computer Software Company
19%
Financial Services Firm
14%
Comms Service Provider
7%
Energy/Utilities Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Cloudflare Web Application Firewall?
The product has a valuable security control functionality.
What is your experience regarding pricing and costs for Cloudflare Web Application Firewall?
Cloudflare is cheaper compared to Azure WAF, which I have considered before.
What needs improvement with Cloudflare Web Application Firewall?
The rate limiting functionality could be enhanced, as we find it somewhat limited.
What needs improvement with NGINX App Protect?
The product's price is high, making it an area of concern where improvements are required. The tool's licensing model...
 

Also Known As

Cloudflare DNS
Cloudflare WAF
NGINX WAF, NGINX Web Application Firewall
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
crunchbase, udacity, marketo, okcupid, zendesk
Information Not Available
Find out what your peers are saying about Cloudflare Web Application Firewall vs. NGINX App Protect and other solutions. Updated: January 2025.
831,265 professionals have used our research since 2012.