No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2806845 - PeerSpot reviewer
Especialista De Seguridad Informatica 3 at a retailer with 10,001+ employees
MSP
Top 20
Mar 5, 2026
Advanced protections have blocked most web attacks and now simplify daily threat management
Pros and Cons
  • "Before Radware Cloud WAF Service, our customers had almost four or five million requests, and they were not always clean, but now with Radware Cloud WAF Service, we see that we block almost 95 or 96 percent of the attacks that we are receiving."
  • "I also want the possibility of seeing traffic in real time because I only see a dashboard with the security events, but in regards to real time, I don't see something that tells me how the traffic behavior is."

What is our primary use case?

I use Radware Cloud WAF Service to protect customers from cyber attacks, mostly SQL injections, cross-site scripting, and degradation with DDoS attacks.

Almost every day, cyber attackers are trying to disrupt the correct functionality of the application for our customers, so I review the console in Radware Cloud WAF Service, searching for strange behavior. If I see something that is not in place, I mostly block via geolocation or IP address or by activating the advanced protection from the applications in the tenant for the customers.

Mostly, I also create different types of rules with Radware Cloud WAF Service, varying from redirections to blacklisting, to whitelisting, exceptions, rate limiting, and others to better protect the customers.

What is most valuable?

The best features Radware Cloud WAF Service offers are mostly the advanced protections because you only need to activate them, and they protect against a lot of today's most common OWASP attacks.

The advanced protections help me in my day-to-day work with Radware Cloud WAF Service because they are very effective as they attack mostly the OWASP Top 10, and they are easy to use because you only need to activate them, and by default, they block a vast gamut of cyber attacks today.

Before our customers purchased Radware Cloud WAF Service, they had a lot of breaches in their network, and after, we successfully lowered the attack rates, and by that, we protect their applications better.

Before Radware Cloud WAF Service, our customers had almost four or five million requests, and they were not always clean, but now with Radware Cloud WAF Service, we see that we block almost 95 or 96 percent of the attacks that we are receiving.

What needs improvement?

I think the things I want to improve in Radware Cloud WAF Service are, for example, the possibility to upload CSV files with IOCs, so we can load a lot of IOCs in one load instead of loading them one by one manually.

I also want the possibility of seeing traffic in real time because I only see a dashboard with the security events, but in regards to real time, I don't see something that tells me how the traffic behavior is.

For how long have I used the solution?

I have been using Radware Cloud WAF Service for almost three years now.

Buyer's Guide
Radware Cloud WAF Service
August 2026
Learn what your peers think about Radware Cloud WAF Service. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,069 professionals have used our research since 2012.

What do I think about the stability of the solution?

Radware Cloud WAF Service is mostly stable.

What do I think about the scalability of the solution?

I think Radware Cloud WAF Service scales pretty well because we add more applications or users, and we don't have a problem with that.

How are customer service and support?

I have a good experience with customer support for Radware Cloud WAF Service; they tend to respond quickly to our cases and they help us really well with the cases.

Which solution did I use previously and why did I switch?

I used Cloudflare and Imperva before Radware Cloud WAF Service, and we switched mostly because the security in Radware Cloud WAF Service console is easier to administrate than in the other providers.

What was our ROI?

Unfortunately, I don't have metrics for return on investment because I only administrate the console.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing for Radware Cloud WAF Service is good.

Which other solutions did I evaluate?

I evaluated Cloudflare and Imperva before choosing Radware Cloud WAF Service.

What other advice do I have?

I invite others looking into using Radware Cloud WAF Service to try it and see all the different protections that the console can provide. I would rate this solution an 8 out of 10.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Mar 5, 2026
Flag as inappropriate
PeerSpot user
reviewer2889597 - PeerSpot reviewer
Sr. Neetwork and security Engineer at a outsourcing company with 201-500 employees
Real User
Top 20
Sep 2, 2026
Unified dashboard has simplified security operations and reduces false positives with AI models
Pros and Cons
  • "The best features Radware Cloud WAF Service offers are that the platform integrates application DDoS protections into a single unified dashboard, which is much better for me."
  • "Radware Cloud WAF Service can be improved in security features, as they can mitigate DDoS attacks and security threats."

What is our primary use case?

My main use case for Radware Cloud WAF Service is that I can say the overall experience provides application security for integrating web protections, port management, and mitigations. The platform offers many services. The AI-driven security model helps reduce false positives and improve capability. I can give you a quick, specific example of how I use Radware Cloud WAF Service for port management or with the AI security model.

How has it helped my organization?

Radware Cloud WAF Service has positively impacted my organization because it has a single integrated web dashboard and a unified cloud service. It has helped me manage all services in a single system.

A specific way this has improved my day-to-day work and my organization's operations is that the biggest advantage is having a single system.

What is most valuable?

The best features Radware Cloud WAF Service offers are that the platform integrates application DDoS protections into a single unified dashboard, which is much better for me.

This unified approach helps by providing a single pane of glass and operational advantage. Radware Cloud WAF Service provides 24/7 managed service that includes threat response, support, and AI-driven security features consisting of both positive and negative security models, which has really helped me.

I think the accuracy and reliability of the output from Radware Cloud WAF Service's AI capabilities are a positive security baseline. They can use the AI model so that capabilities can be improved and block zero-day exploits while reducing false positives, and also can provide API protection to stop multi-vector attacks with the help of AI.

Radware Cloud WAF Service has helped reduce my false positives through context awareness by looking at the entire request, not just a single keyword or pattern that might trigger an old rule, reducing noise and cloud scales. It also uses machine learning to analyze normal user behavior and separate valid requests from attacks, which is why it can be helpful for this cause. This may also be with the help of global threat intelligence.

What needs improvement?

Radware Cloud WAF Service can be improved in security features, as they can mitigate DDoS attacks and security threats.

On a scale of one to ten, I rate Radware Cloud WAF Service an eight out of ten because I think there are some security threats and dashboard reporting features which can be advanced with better dashboarding.

They can improve the scalability of Radware Cloud WAF Service.

For how long have I used the solution?

We have been using Radware Cloud WAF Service for two years.

What do I think about the stability of the solution?

Radware Cloud WAF Service is stable.

How are customer service and support?

The customer support is good compared to other web services from other vendors, and our TAC team provides remote support and resolves my queries on time and within SLA.

Which solution did I use previously and why did I switch?

We were previously using other services before Radware Cloud WAF Service because we have a better relationship with Radware, so currently we are using Radware Cloud WAF Service.

What other advice do I have?

I rate the customer support nine out of ten.

I will give advice to others looking into using Radware Cloud WAF Service that support is essential. If we are using any services, support is required from the vendor. I want to suggest that support, scalability, services, dashboard, and user interface are all good.

I use the API Discovery feature. The API Discovery feature is easy to use as I thought the physical form of the software features into API protection generally offers several security benefits for operational challenges and the engineering team, such as visibility, traffic controls, and data guards. Common challenges can be observed during my team's work when it comes to API, including partial alarm setup efforts and speed impact.

The use of CDN services offered by Radware in conjunction with Radware Cloud WAF Service is easy, as we can use the CDN for fully managed setup, single configuration portal, SSL management, and transport client-side tracking with the help of CDN services.

I assess Radware Cloud WAF Service for integrating with other systems and applications in my environment using the web page. I assess Radware Cloud WAF Service's ability to protect against zero-day attacks as effective because Radware Cloud Web Services mitigates zero-day attacks by combining automated quality security models with AI and analysis and virtual patching.

I assess Radware Cloud WAF Service for blocking unknown threats and attacks as effective because it handles unknown threats and attacks such as zero-day exploits through global threat intelligence and machine learning anomaly detection. My overall rating for this review is eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Radware Cloud WAF Service
August 2026
Learn what your peers think about Radware Cloud WAF Service. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,069 professionals have used our research since 2012.
RaynielBadiola - PeerSpot reviewer
Technical Director at Secur Links
Real User
Top 5
Jul 22, 2026
Advanced protection has mitigated ddos and zero-day threats while simplifying app security
Pros and Cons
  • "Radware Cloud WAF Service can immediately determine the cause of problems and easily mitigates the vulnerabilities and attacks that it sees."

    What is our primary use case?

    The use case involves protecting applications by redirecting them to Radware Cloud WAF Service. The implementation depends on the number of applications you want to protect.

    How has it helped my organization?

    There are definitely improvements to the organization.

    What is most valuable?

    The main feature is to mitigate DDoS attacks. Radware Cloud WAF Service also provides cloud WAF services for applications to be protected, especially web applications, particularly under the OWASP Top 10 vulnerabilities.

    Cloud has a behavioral-based feature that can eliminate false positives.

    Radware Cloud WAF Service has behavioral-based AI or machine learning capability that minimizes or eliminates zero-day attacks.

    It is very important because it can eliminate zero-day using the behavioral-based feature of Radware Cloud WAF Service. It also has negative and positive security models. The positive security model determines those signature-based vulnerabilities and attacks. The negative and behavioral models eliminate zero-day attacks.

    What needs improvement?

    There is no room for improvement that I can see at this time because it is very straightforward.

    I do not think it needs improvement as it already has an AI component. Radware Cloud WAF Service has agentic AI as well, which allows you to chat with them to inquire about current vulnerabilities and resolutions. The AI will eventually provide recommendations. At this time, I do not see anything to improve. They have just added these AI features.

    For how long have I used the solution?

    I have been using this solution for about 15 plus years.

    What do I think about the stability of the solution?

    In terms of stability, I rate it as nine out of 10.

    What do I think about the scalability of the solution?

    I rate it as eight.

    How are customer service and support?

    In terms of technical support, they are very responsive. The moment you open a case with them, they will respond to your case within a few minutes.

    How was the initial setup?

    The implementation actually depends on the requirements of the customers and how many applications there are to be protected. It will only take a couple of hours, or maybe an hour, to implement the initial setup. It is up to the customer to add applications that they want to protect.

    What about the implementation team?

    We assist them to do the implementation together with the Radware Cloud team.

    For our team, as we are the integrator or the distributor, we only have one who is assisting the Radware team to do the implementation. Radware has only one technical or support team that does the implementation and configuration of cloud.

    What was our ROI?

    There is probably a little cost reduction for their cloud WAF or cloud DDoS subscription.

    What other advice do I have?

    It is very simple to integrate with other third-party products, such as SIEMs, and there are no problems integrating with them.

    Radware Cloud WAF Service can immediately determine the cause of problems and easily mitigates the vulnerabilities and attacks that it sees.

    I give Radware Cloud WAF Service a support rating of nine out of 10. My overall review rating for this solution is 9 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
    Last updated: Jul 22, 2026
    Flag as inappropriate
    PeerSpot user
    Vladimir Castro Paulino - PeerSpot reviewer
    Analista de Infraestructura at Expreso Brasilia S.A.
    Real User
    Top 20
    Apr 15, 2026
    Protection for web apps has improved and monitoring now provides clear attack visibility
    Pros and Cons
    • "Radware Cloud WAF Service has enabled me to save time by viewing and monitoring the traffic that my applications receive, since it isolates the attacks or threats that my web applications face."
    • "To make Radware Cloud WAF Service even more useful for my organization, I believe there should be greater integration with other tools, such as log tools."

    What is our primary use case?

    The main use case for which I use Radware Cloud WAF Service is the protection of web applications. I protect a web application from denial-of-service attacks using Radware Cloud WAF Service.

    What is most valuable?

    The best features that Radware Cloud WAF Service offers include the deployment, as it is very easy to implement, and the platform management is efficient.

    The specific aspects that make the implementation process simple in my experience are the integration and the redirection to the web applications.

    Radware Cloud WAF Service has enabled me to save time by viewing and monitoring the traffic that my applications receive, since it isolates the attacks or threats that my web applications face.

    What needs improvement?

    To make Radware Cloud WAF Service even more useful for my organization, I believe there should be greater integration with other tools, such as log tools.

    I would rate it a 9 and not a 10 because the dashboard is sometimes not as intuitive as it could be for displaying the necessary information. You have to take a few extra steps in order to view the information you need.

    For how long have I used the solution?

    I have been using Radware Cloud WAF Service for approximately 3 years.

    What do I think about the stability of the solution?

    I consider Radware Cloud WAF Service to be quite stable in its daily operation.

    What do I think about the scalability of the solution?

    I would rate the scalability of Radware Cloud WAF Service as good, as it adapts well to the growth of my needs.

    How are customer service and support?

    My experience with Radware Cloud WAF Service's customer support has been excellent, as the partner we have responds to us on time and as diligently as possible.

    Which solution did I use previously and why did I switch?

    Before using Radware Cloud WAF Service, we did not have any solution previously.

    What was our ROI?

    I have seen time savings due to the visualization and monitoring of the attacks on the applications since I started using Radware Cloud WAF Service.

    What's my experience with pricing, setup cost, and licensing?

    My experience with the pricing, implementation cost, and licensing of Radware Cloud WAF Service is that it costs what it is worth for what you receive.

    Which other solutions did I evaluate?

    Before choosing Radware Cloud WAF Service, I evaluated alternatives such as Barracuda and Cloudflare WAF.

    What other advice do I have?

    The advice I would give to other companies considering implementing Radware Cloud WAF Service is to take into account that it is an excellent tool for protecting their applications. I would rate this solution a 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Apr 15, 2026
    Flag as inappropriate
    PeerSpot user
    Roberto Carlos Castellar Ardila - PeerSpot reviewer
    Coordinador de Innovacion Tecnologica y SAP at Expreso Brasilia
    Real User
    Top 5
    Apr 16, 2026
    Cloud security has strengthened API protection and now reduces downtime for critical transactions
    Pros and Cons
    • "Other companies considering using Radware Cloud WAF Service will find a very robust tool that has different types of applications for managing all the APIs, all the applications, and controlling the security of all the entities."
    • "Something that could be added to Radware Cloud WAF Service would be a bit more training and not having to depend so much on the vendor, because sometimes when you have to configure advanced policies it requires a lot of experience and dependence on the vendor to provide support throughout the implementation of those advanced policies."

    What is our primary use case?

    Radware Cloud WAF Service protects the web applications that are the APIs and transactional systems. In the WAF, all the protection is configured for the website and internal ticket sales system. In addition to everything related to the tickets, all APIs are protected, which is very useful for the microservices architecture and all the integrations with the different providers.

    What is most valuable?

    The best features offered by Radware Cloud WAF Service are the ease of integration, in addition to all the security it offers, the high availability it has, and the automatic updating of the solutions.

    Radware Cloud WAF Service has had a positive impact with improvements in security. All issues related to incidents have been reduced, and it informs and gives control over any latency or any misuse that someone might try with an API.

    Denial-of-service issues and the downtime of those APIs have been mitigated by approximately 30%, since previously, over a period of time, there were quite a few outages. With this integration of the tool to mitigate all those issues, it has improved in that sense.

    What needs improvement?

    Something that could be added to Radware Cloud WAF Service would be a bit more training and not having to depend so much on the vendor, because sometimes when you have to configure advanced policies it requires a lot of experience and dependence on the vendor to provide support throughout the implementation of those advanced policies.

    The interface is quite intuitive, and there are no other improvements needed.

    For how long have I used the solution?

    Radware Cloud WAF Service has been used for approximately two years.

    What do I think about the stability of the solution?

    Radware Cloud WAF Service is quite stable.

    What do I think about the scalability of the solution?

    Radware Cloud WAF Service has been able to adapt as the organization has grown a lot in applications and APIs, and the tool has worked without any issues.

    How are customer service and support?

    The experience with Radware Cloud WAF Service's customer support has been quite positive. They have always assisted quickly and without any issues whenever assistance has been needed.

    Which solution did I use previously and why did I switch?

    No other solution was used before implementing Radware Cloud WAF Service.

    How was the initial setup?

    The process of integrating Radware Cloud WAF Service into the environment was very quick. Everything really was very fast, and with the documentation provided, it was possible to do it easily and achieve the objective, which was to integrate the platform.

    What about the implementation team?

    The organization is only a customer of the vendor.

    What was our ROI?

    All the benefits obtained have been in security, in prestige, and from using this type of tool for the operation.

    What's my experience with pricing, setup cost, and licensing?

    The cost of Radware Cloud WAF Service is actually a bit high, but given all these benefits, the investment makes sense.

    Which other solutions did I evaluate?

    Other options in the market were evaluated, looking at different alternatives from different vendors. Palo Alto and Check Point were evaluated before deciding on Radware Cloud WAF Service.

    What other advice do I have?

    Radware Cloud WAF Service is deployed in public cloud, directly on Radware's cloud in the public cloud. Being in the cloud is quite a strong point for Radware Cloud WAF Service.

    Other companies considering using Radware Cloud WAF Service will find a very robust tool that has different types of applications for managing all the APIs, all the applications, and controlling the security of all the entities.

    Everything important about Radware Cloud WAF Service has been covered in this interview. This interview is considered very complete and appropriate for the moment and for the product. This review has been given a rating of 9.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Apr 16, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2754852 - PeerSpot reviewer
    Deputy Manager at a energy/utilities company with 10,001+ employees
    Real User
    Top 20
    Sep 6, 2025
    Email alerts and early warnings effectively manage DDoS and zero-day threats
    Pros and Cons
    • "The most advanced feature is the DDoS protection and the way this web handles DDoS attacks, as I am currently working in the SOC team and managing the Radware administration part."
    • "The dashboard of Radware Cloud WAF Service could be more interactive and user-friendly."

    What is our primary use case?

    The core use cases for Radware Cloud WAF Service are web application firewall functionality, DDoS protection, and protection against zero-day vulnerability and emerging threats.

    What is most valuable?

    The most valuable aspect of Radware Cloud WAF Service is that it supports mode detection and provides email alerts on sudden alert spikes and early warnings. The most advanced feature is the DDoS protection and the way this web handles DDoS attacks, as I am currently working in the SOC team and managing the Radware administration part.

    Regarding zero-day attacks, Radware Cloud WAF Service helps us actively receive early warnings, and we raise those to the relevant teams. The services related to zero-day attacks and threat intelligence are very effective.

    What needs improvement?

    The dashboard of Radware Cloud WAF Service could be more interactive and user-friendly. While implementing it for the first time, it requires core technical knowledge, and without that knowledge, implementation can be quite challenging. However, the support from Radware is excellent when support cases are raised.

    For how long have I used the solution?

    I have been using Radware Cloud WAF Service for three and a half years in my career after joining my current organization.

    What do I think about the stability of the solution?

    Regarding stability, I have not experienced any lagging, crashing, or downtime in my experience with Radware Cloud WAF Service.

    What do I think about the scalability of the solution?

    Radware Cloud WAF Service is scalable; once we set up the entire service and it is up to date, we can onboard as many applications as our license allows.

    How are customer service and support?

    I have contacted Radware's technical support many times, and their quality is very good as we receive timely support according to the case priority. Their engineers are skilled and capable enough to resolve issues quickly.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have used alternatives to Radware Cloud WAF Service, specifically Akamai Web Service, which is a very popular service. One of its disadvantages is that it does not support custom ports like Radware does.

    How was the initial setup?

    The entire process of onboarding the application for the first time with Radware Cloud WAF Service requires core technical knowledge, but with the support of Radware, it becomes much easier.

    Which other solutions did I evaluate?

    The pricing of Radware Cloud WAF Service is lower compared to Akamai, and while the price in the industry is acceptable, it is not too expensive.

    What other advice do I have?


    The combination of negative and behavioral-based positive security models provided by Radware Cloud WAF Service is very important for my organization's security strategy, as the main purpose of Radware WAF is security.

    Regarding maintenance, we receive quarterly reports, which are sufficient.

    On a scale of 1-10, I rate Radware Cloud WAF Service an 8.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Works at a energy/utilities company with 10,001+ employees
    Real User
    Top 20
    Sep 10, 2025
    Real-time protection and comprehensive capabilities enhance security management
    Pros and Cons
    • "What I appreciate most about Radware Cloud WAF Service is that it includes all the aspects that an organization wants to run smoothly, such as overall configuration and real-time protection methods, customization of rule creation, fast deployment, and vital visibility in environment maintenance."
    • "In some cases, if the configuration of rules is too strict or complex, there might be a possibility that genuine traffic gets blocked or considered a false positive."

    What is our primary use case?

    In my organization, we are focused on using various security measures to protect against threats, particularly those related to bots. The key product we have employed is Radware Cloud WAF Service, which primarily provides DDoS protection. This service helps us block large-scale attacks aimed at exploiting network vulnerabilities and other weaknesses in our applications.

    Additionally, we utilize the Radware Cloud WAF Service to safeguard our websites and application APIs from threats like SQL injection and other malicious activities, employing various authentication methods for enhanced security. I am also working on learning about bot management, as I have been assigned a task in this area. So far, I have been studying behavioral analysis and detection methods that can identify and block malicious bots effectively.

    I have worked with the API feature of Radware Cloud WAF Service and have experience with the GraphQL endpoint. While I haven't worked on advanced web attacks, I am familiar with common ones. As many applications heavily rely on APIs, it's obvious for attackers to target them. The WAF provides mobile and web app backend security for protection, and I have mainly used the bot detection and mitigation feature to detect and block malicious bot attacks.

    How has it helped my organization?

    Zero-day attacks can be particularly challenging because they exploit vulnerabilities that are not yet known to the software vendor. However, certain solutions can effectively address these threats. One of the key benefits of Radware Cloud WAF Service is its ability to detect potential vulnerabilities before they can be exploited by attackers.

    Currently, there is a growing trend towards using machine learning and AI models, which can provide proactive defenses against zero-day vulnerabilities. As we know, a zero-day vulnerability can pose significant risks to any organization or system. One concept that is crucial in this context is behavior-based analysis and detection. This involves analyzing incoming suspicious requests to identify patterns that do not align with normal behavior. When such anomalies are detected, the system can alert administrators to take appropriate action. Another important feature is virtual patching. This technique can block known vulnerabilities at the edge, even before an official patch is released by the vendor. This proactive approach helps mitigate risks while waiting for a formal solution.

    Source blocking is a method we employ in our organization to block incoming requests from specific sources based on the type of traffic. This approach helps us effectively identify and filter out malicious or unwanted traffic. By recognizing certain requests as malicious, we can prevent them from reaching our systems. We have blocked specific IP ranges, known malicious URLs, and other sources based on geographical locations, depending on our organization's needs. To strengthen our defenses, we use various filters tailored to our requirements, along with threat intelligence feeds and behavioral patterns. Overall, source blocking plays a crucial role in preventing attacks and enhancing our security posture, especially against brute force attacks originating from known malicious IPs.

    Radware Bot Manager, a security tool that helps identify and manage bot traffic and malicious bot attacks, is important for organizations that face heavy traffic loads. Bot Manager helps reduce bot attacks and secure us from threats. I have experience with behavior analytics, custom rules, and the bot detection engine, which focuses on identifying malicious bots and securing APIs from automated abuse.

    What is most valuable?

    What I appreciate most about Radware Cloud WAF Service is that it includes all the aspects that an organization wants to run smoothly, such as overall configuration and real-time protection methods, customization of rule creation, fast deployment, and vital visibility in environment maintenance. Its maintenance cost is very low unlike others, and the real-time dashboards show us who is attacking and what types of attacks are happening in our environment or any endpoints or devices being targeted.

    I appreciate the real-time protection part, especially against SQL injection and Zero-Day exploits. Radware Cloud WAF Service is beneficial for detecting Zero-Day vulnerabilities before they are exploited by attackers. With a focus on machine learning and AI models, it offers proactive defenses against these vulnerabilities. The WAF utilizes behavior-based analysis to identify anomalous requests and can virtually block known vulnerabilities at the edge before vendor patches are released.

    What needs improvement?

    In some cases, if the configuration of rules is too strict or complex, there might be a possibility that genuine traffic gets blocked or considered a false positive. The complexity can be lowered to improve the understanding for users or customers.

    For how long have I used the solution?

    I have been using Radware Cloud WAF Service for nearly one year.

    How are customer service and support?

    I have contacted the customer support of Radware and generally received responses within the scheduled framework, ensuring that my tasks are completed on time. I am quite satisfied with their customer support.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial deployment involves a specific set of stages that are quite transparent. There are several steps we typically encounter during this process. While I wouldn't describe the configuration as overly complex, I would categorize it as moderate in difficulty. I would rate it as moderate. It’s not too challenging, but it does require some attention.

    What other advice do I have?

    I would rate Radware Cloud WAF Service a nine out of ten.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Jefe especialista de ciberseguridad at a insurance company with 1,001-5,000 employees
    Real User
    Top 20
    Apr 27, 2026
    Security has strengthened customer transactions and now protects critical online services
    Pros and Cons
    • "Radware Cloud WAF Service is very top-notch and we in the banking institution are happy with it."
    • "The only improvement I have directly for Radware is its costs, because they are very high."

    What is our primary use case?

    Our primary use case for Radware Cloud WAF Service is DDoS attacks that we suffer against some servers, which in this case affect the services provided to customers.

    We directly proceeded to activate the module from Radware Cloud WAF Service for the site that was being affected, and the impact on the customer was service downtime, but after an estimated period of time, the service was restored for the customers.

    At that time, Radware Cloud WAF Service helped a lot because it provided the cybersecurity that the site itself needs, as they are transactional, and it made us see directly that all the WAF modules are necessary for our institution and for the protection of the services or sites that we provide to customers.

    What is most valuable?

    From my perspective, the best features of Radware Cloud WAF Service are that it has very low false positives and additionally has a very user-friendly interface and easy configuration.

    With a very easy-to-use interface, Radware Cloud WAF Service becomes very easy for us as users to perform a search or investigation related to any specific issue that is being blocked and by having low false positives, it makes the search or investigation of a specific issue easier to carry out.

    It has had the best possible impact, since we have more than 25 sites exposed to the Internet that are transactional. By providing this security layer, we directly provide better results and better security for customers who can access our sites, and we can avoid any type of infection.

    We have directly seen improvement in the main dashboards of Radware Cloud WAF Service; they have become more specific in the direct migration of the site itself.

    What needs improvement?

    The only improvement I have directly for Radware is its costs, because they are very high.

    Having support directly from the manufacturer of Radware Cloud WAF Service and not from the partner would be beneficial, since support becomes a bit slower and more tedious through the current channel.

    Regarding costs of Radware Cloud WAF Service, it was a bit tedious because management did not want to approve them due to how high they are.

    What do I think about the stability of the solution?

    I consider Radware Cloud WAF Service to be very stable.

    What do I think about the scalability of the solution?

    I would rate the scalability of Radware Cloud WAF Service a nine.

    How are customer service and support?

    As I mentioned, sometimes it can be a bit tedious because we have a partner and we have to escalate it to them and then they escalate it to Radware.

    Which solution did I use previously and why did I switch?

    Since I joined the banking institution, we have been using Radware's WAF.

    How was the initial setup?

    The configuration has been very easy, we have not had any issues, and when acquiring the license, it is released very easily at the time of purchase and thus protects the sites.

    Which other solutions did I evaluate?

    I don't have information on this matter, since it is handled directly by the management of the banking institution.

    What other advice do I have?

    Radware Cloud WAF Service is very top-notch and we in the banking institution are happy with it.

    The sites that are onboarded for protection in Radware Cloud WAF Service should be transactional in order to avoid costs for sites that are not worth protecting or are not a main target for attackers.

    Radware Cloud WAF Service is an exceptional tool and very useful for protecting sites.

    I gave this product a rating of nine out of ten.

    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Apr 27, 2026
    Flag as inappropriate
    PeerSpot user
    Kartik Pandit - PeerSpot reviewer
    Manager - SOC at a energy/utilities company with 10,001+ employees
    Real User
    Top 5
    Sep 9, 2025
    User-friendly interface significantly improves threat blocking and strengthens web application defenses
    Pros and Cons
    • "The interface is quite concise and clear, and it is easy to navigate."
    • "Malicious user agents are something that we get frequently and it has been blocking the majority of the threats, almost about 97-98% of threats are blocked, almost to 99% itself."
    • "They can work more on the documentation part. The documentation I found is quite vague."

    What is our primary use case?

    Since many of our businesses are on this application and web applications, we have a huge environment. There are more than hundreds of applications that we have. We are using it for WAF-based production, for bot and for DDoS protection.

    What is most valuable?

    The interface is quite concise and clear, and it is easy to navigate. I have worked with other WAFs, however, Radware Cloud WAF Service is quite easy to navigate compared to others. 

    I have never had a problem with the application or any websites. Many threats are getting blocked here. Since I joined this organization and had the opportunity to compare early deployment statistics with current ones, we can see that many threats have been blocked, resulting in a very good return on investment.

    With Bot Manager, we get many detections which are actually blocked, especially related to application headers. Malicious user agents are something that we get frequently and it has been blocking the majority of the threats, almost about 97-98% of threats are blocked, almost to 99% itself.

    Our first line of defense for our web applications, especially on the cloud, is Radware Cloud WAF Service. Whatever comes through, including reconnaissance attempts, different types of targeted attacks, targeted threat vectors and many APT groups targeting our environment, they are getting blocked in the recon phase itself thanks to the Bot Manager.

    What needs improvement?

    They can work more on the documentation part. The documentation I found is quite vague. There can be more practical examples, and since we are a paid customer, they can give us arranged training. They can arrange sessions or trainings regarding using Radware Cloud WAF Service and what further things we can do. I recently learned about source blocking, so training or sessions can be organized, along with improving documentation with practical examples.

    For how long have I used the solution?

    I have been using it for two and a half years since joining the new company. The company has been using the solution for quite a long time.

    What do I think about the stability of the solution?

    In the last two and a half years, I have not seen any kind of lags or issues.

    What do I think about the scalability of the solution?

    Scalability is good. Our organization is quite big, so we keep on adding applications behind it. I never found an issue with lagging or non-working components due to scaling limitations. The solution is providing scalability in all aspects.

    How are customer service and support?

    The speed and quality was good. We got a good quick turnaround time, especially in cases where we were actually under attacks and wanted blocking to work as soon as possible.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    In my previous company, I have worked with other WAFs, including the F5 WAF and the cloud native WAF. I have also worked with Akamai. I found Radware Cloud WAF Service to be better compared to others.

    How was the initial setup?

    The initial setup was quite easy. I moved around, did some R&D on my own, and it was easy to navigate.There are clear and concise filters that I can apply. Everything was on the screen. Whatever I wanted to try or do was available on the screen. I could move around in the console and try all kinds of experiments. It was quite easy and user-friendly.

    What was our ROI?

    Since I joined this organization and had the opportunity to compare early deployment statistics with current ones, we can see that many threats have been blocked, resulting in a very good return on investment.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is something that is decided by the top management. I am more of an operations person.

    Which other solutions did I evaluate?

    We do not use the CDN services.

    What other advice do I have?

    I have not used the API Discovery completely, however, I have checked out the API security that comes under the WAF part, specifically the threat detection part that we are focused on. I am hearing about source blocking for the first time, which would be helpful as we would not have to manually block it.

    We are using the DDoS protection and it has been blocking many DDoS attacks that we have observed. Many times when traffic slips through our DDoS protection pipelines, they are definitely getting blocked by Radware Cloud WAF Service, including anomalous rate limiting.

    It took me about a week to learn the system, as I am a quick learner. There is no required maintenance as it is already taken care of by Radware. We get notifications regarding maintenance upgrades and everything, mainly for the IP blocking parts.

    On a scale of one to ten, I rate this solution a nine.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Application Supervisor at a government with 1,001-5,000 employees
    Real User
    Top 20
    Jun 23, 2025
    Eliminates maintenance tasks and strengthens security with AI-driven and API security functionalities
    Pros and Cons
    • "It has features such as API security that protect against advanced attacks, including business logic attacks. It comes with additional functionalities such as bot protection and AI-driven threat signatures, along with threat intelligence, making it much more than the traditional WAF that we have on-prem."
    • "Radware Cloud WAF Service offers better protection and can even provide significantly better security."
    • "The dashboard of Radware Cloud WAF Service has room for improvement. While it works effectively, it can feel complex and might need some initial guidance, but once users become familiar with it, the operation becomes smooth."

    What is our primary use case?

    We have both infrastructure protection and web application protection. Infrastructure protection is against network-level denial of service attacks, and we use the application protection for our web application firewall, which provides layer seven security.

    How has it helped my organization?

    Being a cloud service, it removes the maintenance tasks for system uptime and the maintenance of on-prem appliances. It gives security analysts much more time for SOC work in analyzing alerts and threats. With on-premises solutions, there is a lot of maintenance involved to ensure that everything is functioning properly. Much time is dedicated to maintaining on-premises products. In contrast, as a cloud product, we don't have to worry about issues related to high availability or managing multiple instances of security solutions. Maintenance tasks such as operating system upgrades and other related issues are handled for us. This allows us to focus our efforts on SOC analysis work without the burden of these maintenance responsibilities.

    It helps reduce the number of false positives and also addresses sophisticated attacks that may not be detected by our traditional systems on-premises.

    Alerts help us quickly narrow down the issue, allowing us to spend less time on analysis and more time addressing active threats as they occur. Automation plays a significant role in this process.

    Bot Manager has been quite positive. I find it to be more than just your traditional method of examining signatures or even looking at user agent headers. It goes beyond that; it analyzes the behavioral patterns of requests. Bots have become more advanced, often trying to imitate human behavior as closely as possible. With this bot protection, certain traffic gets blocked and flagged as bot traffic. However, when I review the requests from a human perspective, it can be challenging to identify what was actually bot traffic. Fortunately, the system provides a description of why a particular request was blocked and flagged as bot traffic. Bot traffic is a lot compared to normal human traffic, about 50% more. That alone frees up a lot of compute for our applications. The performance of the applications is significantly better because the bot's traffic is effectively filtered in the cloud. Only clean traffic reaches the applications, ensuring optimal performance.

    The detection for bad bots and layer seven anomaly detection is ingrained within the logic. First of all, it examines normal signatures and user agents. Additionally, there is a significant reliance on AI-driven signatures that it looks out for. It also incorporates threat intelligence, which may include insights from various sources. Another important aspect is IP reputation, which is gathered from other clients with whom these bots have interacted. Overall, I think this solution is very effective; it has worked well for us and is actually blocking the traffic as advertised.

    We rely heavily on Web DDoS protection, with about ninety percent of our services being application-based. Therefore, ensuring their security is very important to us. Radware provides the security we need and guarantees that the traffic reaching our web applications and servers is clean. This gives us peace of mind. While we monitor our systems closely, knowing that Radware Cloud WAF Service has our back is essential. Overall, it plays a crucial role in our business continuity as a security solution.

    What is most valuable?

    As compared to the traditional WAF that had on-prem systems, Radware Cloud WAF Service has many functionalities, such as AI-driven functionalities. It has features such as API security that protect against advanced attacks, including business logic attacks. It comes with additional functionalities such as bot protection and AI-driven threat signatures, along with threat intelligence, making it much more than the traditional WAF that we have on-prem. This is a key advantage I've seen since we onboarded it.

    What needs improvement?

    The dashboard of Radware Cloud WAF Service has room for improvement. While it works effectively, it can feel complex and might need some initial guidance, but once users become familiar with it, the operation becomes smooth.

    For how long have I used the solution?

    We have been using Radware Cloud WAF Service since the beginning of this year. It has not yet been a full year.

    What do I think about the stability of the solution?

    I would rate the stability of Radware Cloud WAF Service a nine out of ten. While the functionality is a 10 out of 10, occasional internet connectivity issues cause temporary access problems.

    What do I think about the scalability of the solution?

    The scalability of Radware Cloud WAF Service rates as a perfect ten out of ten, as we haven't encountered any scaling issues.

    In the security team, four of us work with this solution. We have about 4,000 employees.

    How are customer service and support?

    Technical support from Radware rates as a nine out of ten, as their support is very good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Radware Cloud WAF Service is the first cloud WAF solution we have used. We were using only an on-premises physical appliance.

    As compared to our on-premises solution, Radware Cloud WAF Service offers better protection and can even provide significantly better security. In baseline protection, it matches our on-premises solution but has additional functionalities, including AI-driven signatures. This upgrade brings many more security features that we didn't have before. Overall, I would rate it much higher.

    Radware Cloud WAF Service works well. There are many instances that we could not flag bot traffic using our traditional on-premises WAF. We use them concurrently. We compare the clean rate of what passes through the cloud instance with what passes through our on-premises instance. It has freed up many of the compute resources we have on-premises. Thus, much of the malicious traffic is stripped away at the cloud level before the clean traffic reaches our on-premises sites.

    How was the initial setup?

    The deployment of the Radware Cloud WAF Service was quite easy and took about two to three days, thanks to the helpful and responsive support team from Radware.

    Apart from fine-tuning the security policies, much of the maintenance work is effectively handled in the background by the Radware team. As a result, there is very little to no maintenance required on our end.

    What about the implementation team?

    We were supported by Radware's onboarding team. They prepared our dashboard.

    What was our ROI?

    The Radware Cloud WAF Service saves us a significant amount of time, estimating around 30% to 40%.

    With our on-prem solution, we spent a lot of time on maintenance tasks, OS updates, and ensuring appliances ran smoothly, but with Cloud WAF, all that is managed by the cloud team, allowing us to focus on alert analysis.

    What other advice do I have?

    For false positives, you need to properly tune the detection rules. In the beginning, it operates in a learning mode, which Radware refers to as "reporting mode." This mode simply reports on what is happening but doesn’t actively block any threats. When you transition to active protection, it’s crucial to take care when defining your threat signatures. If you don't, there can be some false positives. However, with excellent support from the onboarding team, we were able to resolve those issues very quickly, and after that, everything went smoothly. In the initial stages, it can be a bit tricky. There are some false positives, but they can be adjusted and fine-tuned. Once in a while, a false positive occurs, but we now have the knowledge on how to mitigate that.

    A lot of applications are currently hosted on-premises. With a Cloud WAF, you need to redirect traffic to the cloud instance, and then the traffic is routed back. Initially, our main challenge was addressing internal threats, specifically insider threats. These applications are accessible both within our environment and to external users. However, since we began using cloud protection, it has primarily catered to external source traffic, leaving internal source traffic unprotected. Fortunately, Radware quickly developed a secure pathway functionality that can also redirect internal traffic to be inspected in the cloud. This feature is something we haven't implemented yet, but it is definitely on our agenda for implementation very soon.

    The application protection from Radware Cloud WAF Service has API security, which protects the APIs we define against the different OWASP Top 10 API security threats.

    I would rate the Radware Cloud WAF Service as a nine out of ten. Overall, it is a very effective solution that meets our expectations and blocks traffic as advertised.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Buyer's Guide
    Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros sharing their opinions.