Try our new research platform with insights from 80,000+ expert users

Cloudflare Web Application Firewall vs Sucuri comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
71
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Cloudflare Web Application ...
Average Rating
8.4
Reviews Sentiment
8.9
Number of Reviews
21
Ranking in other categories
Web Application Firewall (WAF) (7th)
Sucuri
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
6
Ranking in other categories
Web Application Firewall (WAF) (21st), Distributed Denial-of-Service (DDoS) Protection (17th), Domain Name System (DNS) Security (12th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
SachidDoshi - PeerSpot reviewer
Offers a huge signature repository and is superiorly effective in mitigating DDoS attacks
The solution's learning curve can still be further reduced, which presently stands at two or three months. The product has a custom rule set that users can modify and manifest as needed. The vendor can probably shorten the learning curve using cutting-edge technologies like AI. The solution provider can also work around the web applications and identify the toolset that needs to be implemented to deploy the solution in less time. The vendor has launched a SASE product that can function with Cloudflare Web Application Firewall, but many improvements are needed in terms of features, such as the web filtering feature, and CASB has not yet been added.
David Shlingbaum - PeerSpot reviewer
Simple solution and good WAF
Sucuri could provide help for specific security alerts in-line instead of requiring users to search for it in the help section. Users get errors or EBAs, and if they want to read about it, they need to find it in the help section of the site. It would be more helpful to allow users to see more information and tips immediately from within the alert.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is very good at mitigating threats."
"I get a lot of value from Cloudflare's API because it enables you to build a separate environment inside the solution. You can create a domain for performing test requests before you move to the production environment and connect various domains."
"Cloudflare allows us to self-host services such as Rocket.Chat and Node-RED, in high-availability mode, thanks to round robin DNS which allows us to share one hostname between our two locations."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"The UI is good."
"Generally, I am satisfied with this product."
"The most valuable feature of Cloudflare DNS is its global reach and it is always evolving."
"It is a SaaS solution unlike much of the competition."
"The product has a valuable security control functionality."
"We like that there's load balancing, firewall capabilities, DDoS protection, et cetera, all covered by Cloudflare."
"Some of the most valuable features of Cloudflare Web Application Firewall include its DNS zone setup and the zero trust policy."
"The integration of Cloudflare with Cloud Suite is its most valuable feature."
"It's pretty convenient and pretty easy to set up and run. And then kind of for static content, it also offers caching."
"Does a good job preventing web application attacks."
"The security features are valuable. The particular feature we use is called OWASP."
"The initial setup was very easy."
"The most valuable part is the analytics and visualization."
"The initial setup was straightforward. Straight forward because the plugin can simply be installed and then it does its job. It's not complex, there is no learning curve. The online scan is simple, you put in the website address and the scan gives us a report on the browser itself. It's simple to use."
"Domain name scanning since it allows us to scan all our domain names and determine whether it has malware or if is reported as phishing."
"I use it as a WAF, which is basically a web firewall to monitor and block traffic to our web server."
"It significantly eases the workload and streamlines the initial setup required to protect a website."
 

Cons

"Latencies are always a problem."
"It would be helpful if the solution could continue evolving to compete with the other solutions on the market."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"The solution could use more analytics on the backend to give us more insights into everything. More reports would be helpful."
"There should be a specific price list for enterprise-level customers."
"For the free and Pro plans, Cloudflare could use a simple bot to provide information to users. This would improve support, especially for less advanced users who utilize the free components."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"DNS Management."
"It would be ideal if the solution offered better log integration and more integration with different platforms."
"The notification part could be improved. It's very much connected to Web Application Firewall, rate-limiting, and DDoS protection."
"The platform's control features related to real-time authentication and response time need improvement."
"The dashboard could be more user-friendly."
"Support can be challenging at times."
"The blocked logs are difficult to read at times."
"Their documentation could be better. They don't have documentation that explains everything well. They have documentation for everything you're looking for, but they lack a single piece of documentation to tie everything together. As a new user or beginner, it took us a little bit of time to figure out how to put all these things in place."
"A key challenge arises when dealing with numerous integrations with HVAC systems. Depending on the specifics, there might be some configuration mismatches, which necessitate specific support."
"I would rate this solution an eight out of ten. The reason is that we have found sometimes customers or Google saying that there is something wrong with the website but Sucuri says that the site is clean so we do have to look at the site manually which means that the Sucuri scan does not pick up anything and everything."
"Confident score: Currently it does not have one and there are cases that most websites flagged are false-positives."
"It would greatly benefit customers if they implemented an online chat or messaging system for quicker assistance."
"In terms of improvement, the cost factor is always there."
"Sucuri could provide help for specific security alerts in-line instead of requiring users to search for it in the help section."
"The main improvement I would like to see is support for .NET applications. If they could include this feature, I would include more sites in the protection."
 

Pricing and Cost Advice

"A free version of the solution is available."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"The product's pricing is minimal compared to other products."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"We are using the free tier of the solution."
"The product's pricing is cheap."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"The cost primarily depends on the size of the organization."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"It is not too pricey."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"The annual licensing fee is $10,000 USD."
"The solution is expensive."
"We pay $210 per month for CloudFlare WAF."
"It starts at $20 and can easily go up to $200 monthly"
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"It stands out as a more cost-effective option compared to other cloud-based security services like Cloudflare or JetPass."
"The ROI has been very good. Because of the solution, I have a tax break. The site developers were not always experienced people. We used to pay more for cleaning up the site when it was infected. Now, we have peace of mind knowing that the solution will clean up the site and that we won't have to go through the unnecessary process of restoring it from a backup. The protection on the WAF and the measures for backups have also prevented our site from going down."
"I’d simply say it’s really worth it."
"Sucuri offers different plans, both the standard plan and an advanced plan. So there are different plans to choose from."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
824,067 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
13%
Comms Service Provider
7%
Financial Services Firm
7%
Educational Organization
28%
Computer Software Company
12%
Financial Services Firm
8%
Manufacturing Company
5%
Educational Organization
46%
Computer Software Company
9%
Manufacturing Company
6%
Financial Services Firm
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about Cloudflare Web Application Firewall?
The product has a valuable security control functionality.
What is your experience regarding pricing and costs for Cloudflare Web Application Firewall?
From my perspective, the price of Cloudflare Web Application Firewall is quite affordable, rating around an eight or ...
What needs improvement with Cloudflare Web Application Firewall?
The dashboard could be more user-friendly, and a console approach like Cloudflare CLI could enhance its usability.
What do you like most about Sucuri?
The initial setup was very easy.
What is your experience regarding pricing and costs for Sucuri?
The pricing is very reasonable. Sucuri offer other features as an add-on, such as backup, but these have an additiona...
What needs improvement with Sucuri?
The main improvement I would like to see is support for .NET applications. If they could include this feature, I woul...
 

Also Known As

Cloudflare DNS
Cloudflare WAF
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
crunchbase, udacity, marketo, okcupid, zendesk
The Loft Salon, Tom McFarlin, WPBeginner, Taylor Town, Everything Everywhere, Financial Ducks in a Row, Chubstr, Real Advice Gal, Sujan Patel, Wallao, List25, School the World
Find out what your peers are saying about Cloudflare Web Application Firewall vs. Sucuri and other solutions. Updated: December 2024.
824,067 professionals have used our research since 2012.