We use Radware Cloud WAF Service for WAF protection and API protection.
IT Engineer at Adani Enterprises Ltd
Has managed high traffic efficiently and reduced false positives while maintaining strong API protection
Pros and Cons
- "In Radware Cloud WAF Service, the areas that have room for improvement include the costing part, as we faced some issues during the implementation and POC of this WAF technology."
What is our primary use case?
What is most valuable?
The best features of Radware Cloud WAF Service are its ability to manage high traffic, its scalability, and its reliability. Whenever we observe any detections or unusual traffic at a high rate, Radware manages the replication of web applications in such a way that no web applications are ever hampered, ensuring all traffic is managed effectively.
Radware Cloud WAF Service has significantly reduced our false positives, as Radware keeps its policies up to date with emerging tactics. This has led to very few false positives, which is one reason we have chosen to implement Radware WAF in our environment, given its favorable false positive ratio.
What needs improvement?
In Radware Cloud WAF Service, the areas that have room for improvement include the costing part, as we faced some issues during the implementation and POC of this WAF technology.
Additionally, the policy management can be improved, along with the graphical user interface for better visualization, so any new user can adapt to its graphics and find it easier to use.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for around three plus years.
Buyer's Guide
Radware Cloud WAF Service
September 2026
Learn what your peers think about Radware Cloud WAF Service. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,056 professionals have used our research since 2012.
How are customer service and support?
I would rate the support a perfect 10 out of 10 because the support is good.
What was our ROI?
We have seen a good amount of return on investment with Radware Cloud WAF Service, roughly 50 to 60%. By reviewing our alerts and traffic, we can assess what traffic has been blocked and how much it has saved our applications and infrastructure.
Given our critical web applications and our substantial environment, where many applications are onboarded on WAF, overall, we can say it has yielded good returns on investment.
Which other solutions did I evaluate?
When I compare Radware Cloud WAF Service with other WAF software, I notice that while Radware's technology is strong, the only cons we faced were related to costing and some policies. Other solutions are available in the market, but they also have their drawbacks.
What other advice do I have?
We use the CDN services offered by Radware with Radware Cloud WAF Service. The combination of CDN and Radware Cloud WAF Service is easy to use, and the security it offers is good, especially with the WAF plus DDoS integration, which is ideal for media and all types of streaming.
I assess Radware Cloud WAF Service for blocking unknown threats and attacks as effective because it updates its mitigation policies with day-to-day strategies, incorporating new and emerging tactics. Additionally, it blocks some traffic based on AI, which enhances its ability to manage intrusion threats.
The automated analytics for looking at events is positive, as it has inbuilt automations that reduce our manual intervention. Due to this, there is a quick incident response in case of any high alert or critical case, ensuring that proper mitigations have been taken care of for any incident, which allows for a rapid response over any alert.
Radware Cloud WAF Service for integrating with other systems and applications in our business is seamless, as we have integrated Radware WAF with our SIEM monitoring tool, Microsoft Sentinel. We can get centralized logs for every tool on Sentinel, and it was easy to implement and integrate with it. Throughout the integration with Sentinel, we received excellent support and good documentation.
I assess Radware Cloud WAF Service for its ability to protect against zero-day attacks as competent since it adapts behavioral models. If it observes any vulnerability that Radware WAF hasn't recognized in its recent models, it trains its models based on behavior to manage zero-day exploits, ensuring that if any sudden bot traffic or API abuse occurs, Radware mitigates it and blocks all such traffic effectively.
The combination of negative and behavior-based positive security models is crucial for our organization's security strategy because Radware assumes everything is allowed unless it observes any malicious activity or anomaly. In such cases, WAF only blocks when something malicious or specific signatures are observed, making it reliable for our applications and ensuring none are hampered by any false positives.
We use Radware Bot Manager. With Radware Bot Manager, we have discovered issues such as web scraping and DDoS bots from our incoming bot traffic that we weren't aware of before, as it provides detections for that and actively blocks all such DDoS traffic and bot traffic based on its AML algorithms. We have also enabled API bot protection.
We use the web DDoS protection offered by Radware. Radware Cloud WAF Service has helped in our business continuity by ensuring that no legitimate traffic is blocked. Only when something suspicious based on L3, L4, or L7 DDoS attacks or such signatures is observed does Radware block malicious traffic, guaranteeing reliability and continuity for our web applications.
The solution requires maintenance when we want to configure or tweak any policy, which is when we seek support from the tech team.
Our team includes 30 engineers who use Radware WAF. We will recommend this product to other users because we have suggested it to our peers. Looking at the solution this tool has provided us, we find it beneficial enough to promote it to others.
On a scale of 1-10, I rate this solution a 9.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
IT Security Engineer at Adani Enterprises Ltd
Saves significant time with user-friendly interface and proactive features
Pros and Cons
- "The features I find best about Radware Cloud WAF Service are its user-friendly GUI and the smooth deployment or onboarding process, and the dashboard allows me to see trends weekly, monthly, and daily for this particular application, enabling me to take action if I want to allow or block specific IPs or traffic."
- "I'm not sure about how much historical traffic data we can access. Knowing the ability to view traffic from six months back would be beneficial for audit and compliance purposes, especially if an attack happens on an application."
What is our primary use case?
My use case primarily involves the admin part, however, I haven't had a chance to do that yet. I'm using the tool for analysis purposes, such as monitoring application traffic trends and observing DDoS traffic and cloud requests, whatever hits we are getting from the internet on this application.
We also use the geofencing feature, which helps us significantly. During the recent conflict between India and Pakistan, we used the geofencing on our application onboarded on Radware Cloud WAF Service to block specific regions, preventing any unwanted traffic.
What is most valuable?
The features I find best about Radware Cloud WAF Service are its user-friendly GUI and the smooth deployment or onboarding process. I've interacted with colleagues in engineering who have noted that application onboarding is straightforward.
The dashboard allows me to see trends weekly, monthly, and daily for this particular application, enabling me to take action if I want to allow or block specific IPs or traffic.
I use Radware Cloud WAF Service daily for monitoring purposes, which saves approximately half an hour to one hour. In total, I can estimate around ten to 14 hours per week saved.
For automated analytics related to events, we can create details on the dashboard concerning automated analysis. I haven't explored it much but believe it would be useful for our respective business units since we've deployed various applications in Radware and they are regularly monitored by the application owners to ensure no impact on availability.
My assessment of Radware's solution to protect against zero-day attacks is perfect. I give it the highest marks of ten out of ten. Whenever such an issue occurs, we can directly add the relevant details or signatures for specific IPs in the rules, creating analytic rules to detect and prevent such incidents, which is commendable.
We are using the source blocking feature, which I consider one of my favorites. With geofencing, we proactively blocked many regions, and during that process, we raised a support case with Radware, which they addressed promptly by adding the IP list for blocking. After that, we learned how to block source IPs from the console, and I appreciated their good support.
I don't have any information on using Radware Bot Manager right now. For compliance, we have another team, the audit team, that monitors compliance processes related to application availability. They are the primary owners of the compliance for applications onboarded to Cloud WAF, and I do not track their specific changes.
We are using Web DDoS protection, specifically for HTTP L7, and I find it very efficient. There are no application issues as we create analytics rules to monitor traffic, and the implementation or configuration of such rules is straightforward.
Radware Cloud WAF Service is proactive, with notifications about scheduled maintenance provided by the Radware team, which helps us prepare in advance. If any issues arise, we can reach out to the support team, which is beneficial.
What needs improvement?
I've not explored deeply enough to identify areas for improvement in Radware Cloud WAF Service, but I can mention the retention policy. I'm not sure about how much historical traffic data we can access. Knowing the ability to view traffic from six months back would be beneficial for audit and compliance purposes, especially if an attack happens on an application. There was a request in the past that we couldn't fulfill due to this limitation, so I'd like to know more about the retention policy.
For how long have I used the solution?
I have been using the solution since I joined the company in January 2023, so I have been using this tool for the past two years.
What do I think about the stability of the solution?
I would rate the stability of the service as a nine out of ten, which is quite good.
What do I think about the scalability of the solution?
Regarding scalability, I can give it a mark of nine out of ten based on my experiences, as it meets our needs effectively.
My cybersecurity team consists of over 100 users, and multiple business units access Cloud WAF with their applications. I can estimate that approximately 150 to 200 people use it.
How are customer service and support?
On a scale from one to ten, I would rate the technical support that Radware provides for Cloud WAF Service a perfect ten.
What was our ROI?
In terms of return on investment, we've saved around 30% to 40% of time and resources. We get major insights from the analytics rules and dashboards, allowing us to pinpoint main issues. This detailed summary of particular hits and application traffic is incredibly helpful. This efficiency also means we don't need to hire extra resources, as the Radware Cloud WAF Service interface is user-friendly.
What other advice do I have?
I would definitely recommend Radware Cloud WAF Service to other users and organizations given the features we've utilized and the excellent support we've received, earning it full marks. Overall, I would rate Radware Cloud WAF Service a nine out of ten, as it performs excellently.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Radware Cloud WAF Service
September 2026
Learn what your peers think about Radware Cloud WAF Service. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
916,056 professionals have used our research since 2012.
IT Manager at Adani Enterprises Ltd
Ease of use allows effective investigation and real-time anomaly detection
Pros and Cons
- "Radware Cloud WAF Service is great in terms of blocking unknown threats and attacks; everything seems perfect to me, and I have no complaints or issues regarding the blocking capability."
- "Radware Cloud WAF Service has drawbacks when compared to other WAF solutions, particularly because we were checking other solutions that support custom ports for application onboarding."
What is our primary use case?
Radware Cloud WAF Service is utilised for analysis. As part of a SOC team and Incident Response Manager role, the team investigates incoming traffic to onboarded applications, identifies potentially malicious traffic, and takes appropriate action. This includes creating and modifying WAF rules and making decisions about which traffic is allowed or blocked, as well as IP blocking and related measures.
How has it helped my organization?
Radware Cloud WAF Service effectively blocks unknown threats and attacks, with no issues regarding its blocking capabilities.
The automated analytics meet my expectations for event analysis.
Its real-time, behavior-based anomaly detection benefits our threat management by reliably detecting and blocking malicious traffic.
What is most valuable?
Radware Cloud WAF Service is easy to use and requires little experience or resources. Basic tasks can be completed with minimal effort.
Integration was seamless, and the source blocking feature works well.
What needs improvement?
Radware Cloud WAF Service could improve its application onboarding process, as it only supports ports 80, 443, and 1024–65535; key ports like 993 and 995 needed for SMTP are unsupported, limiting email app protection. For IP whitelisting, the current setup allows all traffic from a specific allowed(whitelisted) IP without detection, which exposes threat. A more granular approach—allowing both page- and IP-specific access while detecting threats—is recommended.
The service earns eight out of ten for reducing false positives, but some legitimate traffic is still blocked due to header parameters. Whitelisting helps, but further improvements and AI-driven behavior analysis could enhance accuracy.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for more than two years.
What do I think about the stability of the solution?
The stability of Radware Cloud WAF Service is perfect; I would rate it a ten out of ten.
What do I think about the scalability of the solution?
I find the scalability of Radware Cloud WAF Service to be perfect, rating it a ten out of ten.
How are customer service and support?
I would rate their technical support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have several other tools for threat management, but we primarily rely on Radware Cloud WAF Service. It effectively identifies, detects, and blocks malicious traffic. This is the main feature we are looking for, and Radware Cloud WAF Service performs exceptionally well in this regard.
What was our ROI?
Implementing Radware Cloud WAF Service saves 20–30 minutes per traffic analysis incident.
Which other solutions did I evaluate?
I notice that Radware Cloud WAF Service has drawbacks when compared to other WAF solutions, particularly because we were checking other solutions that support custom ports for application onboarding. Many custom-built applications run on different ports, and that is something that needs to be addressed; it should support custom ports. Other WAFs in the market currently support custom ports, which poses a major drawback for Radware Cloud WAF Service.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Jefe especialista de ciberseguridad at a insurance company with 1,001-5,000 employees
Security has strengthened customer transactions and now protects critical online services
Pros and Cons
- "Radware Cloud WAF Service is very top-notch and we in the banking institution are happy with it."
- "The only improvement I have directly for Radware is its costs, because they are very high."
What is our primary use case?
Our primary use case for Radware Cloud WAF Service is DDoS attacks that we suffer against some servers, which in this case affect the services provided to customers.
We directly proceeded to activate the module from Radware Cloud WAF Service for the site that was being affected, and the impact on the customer was service downtime, but after an estimated period of time, the service was restored for the customers.
At that time, Radware Cloud WAF Service helped a lot because it provided the cybersecurity that the site itself needs, as they are transactional, and it made us see directly that all the WAF modules are necessary for our institution and for the protection of the services or sites that we provide to customers.
What is most valuable?
From my perspective, the best features of Radware Cloud WAF Service are that it has very low false positives and additionally has a very user-friendly interface and easy configuration.
With a very easy-to-use interface, Radware Cloud WAF Service becomes very easy for us as users to perform a search or investigation related to any specific issue that is being blocked and by having low false positives, it makes the search or investigation of a specific issue easier to carry out.
It has had the best possible impact, since we have more than 25 sites exposed to the Internet that are transactional. By providing this security layer, we directly provide better results and better security for customers who can access our sites, and we can avoid any type of infection.
We have directly seen improvement in the main dashboards of Radware Cloud WAF Service; they have become more specific in the direct migration of the site itself.
What needs improvement?
The only improvement I have directly for Radware is its costs, because they are very high.
Having support directly from the manufacturer of Radware Cloud WAF Service and not from the partner would be beneficial, since support becomes a bit slower and more tedious through the current channel.
Regarding costs of Radware Cloud WAF Service, it was a bit tedious because management did not want to approve them due to how high they are.
What do I think about the stability of the solution?
I consider Radware Cloud WAF Service to be very stable.
What do I think about the scalability of the solution?
I would rate the scalability of Radware Cloud WAF Service a nine.
How are customer service and support?
As I mentioned, sometimes it can be a bit tedious because we have a partner and we have to escalate it to them and then they escalate it to Radware.
Which solution did I use previously and why did I switch?
Since I joined the banking institution, we have been using Radware's WAF.
How was the initial setup?
The configuration has been very easy, we have not had any issues, and when acquiring the license, it is released very easily at the time of purchase and thus protects the sites.
Which other solutions did I evaluate?
I don't have information on this matter, since it is handled directly by the management of the banking institution.
What other advice do I have?
Radware Cloud WAF Service is very top-notch and we in the banking institution are happy with it.
The sites that are onboarded for protection in Radware Cloud WAF Service should be transactional in order to avoid costs for sites that are not worth protecting or are not a main target for attackers.
Radware Cloud WAF Service is an exceptional tool and very useful for protecting sites.
I gave this product a rating of nine out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Apr 27, 2026
Flag as inappropriateSOC Analyst at Adani Enterprises Ltd
A robust solution with good behavior analysis capabilities for protecting organizations
Pros and Cons
- "Radware Cloud WAF Service is a ten out of ten for blocking unknown threats and attacks, using artificial intelligence and machine learning to analyze traffic, detect anomalies, and automate responses to cyber threats in real time."
- "The dashboard needs improvement as some users find it complex."
What is our primary use case?
Our use case for Radware Cloud WAF Service is as a web application firewall. It is a security device or service that monitors, filters, and blocks the traffic between a web application and the Internet to protect it from cyber attacks.
How has it helped my organization?
Radware Cloud WAF Service is a ten out of ten for blocking unknown threats and attacks. I am very satisfied. My impressions of the automated analytics for looking at events is ten out of ten.
The automated analytics technique is basically on the next level. It uses artificial intelligence and machine learning to analyze traffic, detecting anomalies, and automating the response to cyber threats in real time. Its proactive threat protection reduces false positive alerts and enhances mitigations.
We use the API discovery feature for API protection, which includes bot mitigation, API protection, and distributed denial of service DDoS protection. The API discovery feature helps us reduce overhead costs by providing a capability to automatically identify and inventory the APIs exposed by the protected web application. API discovery includes endpoint and schema learning, identification of shadow and zombie APIs, behavior analysis, and integration with API security.
We use CDN services offered by Radware Cloud WAF Service together with Akamai for our control delivery network, which connects end users from the nearest location to optimize user experience.
Radware Cloud WAF Service integrations provide a comprehensive view of our web application security by centralizing web logs into the SIEM platform for advanced detection, analysis, and incident response. It allows for correction of WAF events with other data security tools, automating workflows, and improving threat hunting. Integrated SIEM and setting up dashboards and correction rules within the SIEM gives us actionable insights.
The implementation has saved us over 90% of time. For zero-day attacks, it is effective because it uses real-time threat intelligence and machine learning. It applies adaptive behavior analysis to detect anomalies in traffic patterns and generates dynamic security policies. While signature-based detection is used for known threats, Radware's solution also implements positive security models.
The combination of negative and behavioral based positive security models involves broad detection. These combinations allow for policies, thereby avoiding false positives and false negatives. There are supervised and good networks, unsupervised cluster detection, and adaptive learning for action.
The source blocking feature blocks real-time automated cybersecurity threats from malicious IP addresses by correcting security events across multiple protection models. It automatically blocks them from accessing any protected application for a configurable duration.
We use Radware Bot Manager, which provides three-layered protection: preemptive protection that blocks malicious IP addresses and identities, behavioral risk detection with employment scene analyzer to distinguish between human and bot traffic, and options to stop or challenge bots.
Radware Bot Manager has helped in our compliance efforts with a ten out of ten rating. It provides website secure connection and automates protection against threats such as account takeover, credential stuffing, brute force attacks, and payment abuse or spam.
The real-time BLA detection and mitigation affects our threat management positively. Deep tech inspection involves analyzing network traffic flows, and Radware Cloud WAF Service scores ten out of ten. It inspects the actual content of packets to identify, classify, and act upon data and applications in real time.
We use web DDoS protection, specifically the L7 HTTP, which helps us with its AI-powered and behavior-based algorithms to generate signatures in real time and rapidly detect and mitigate L7 DDoS attacks without harm to the organization.
What is most valuable?
The best features of Radware Cloud WAF Service, which we use on a daily basis, include natural self-cooling properties. Radware offers us advanced and automated features such as continuous traffic learning, adaptive AI-driven policies, and automatic app mapping and API security protection. It also prevents us from zero-day threats, including OWASP Top Ten.
It is robust and protects our organization from vulnerabilities, including zero-day exploits, bot attacks, and DDoS attacks. Additionally, it offers behavior analysis and provides hybrid deployment flexibility for both on-premises and cloud environments. These are the key benefits of Radware.
Radware Cloud WAF Service has reduced our false positives to over 90%.
What needs improvement?
In terms of areas for improvement, the price is somewhat high. More use of tools such as AI and ML is needed. AI-powered DDoS defense tools and behavior DDoS protections are in place. They should also improve visibility, control, and user interface. The dashboard needs improvement as some users find it complex.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for more than two to three years.
What do I think about the stability of the solution?
I would rate the stability of Radware Cloud WAF Service as good.
What do I think about the scalability of the solution?
For scalability, I would rate it a ten out of ten.
There are 20 to 30 users in my organization working with the solution.
How are customer service and support?
I would rate Radware's support for Cloud WAF Service as top notch.
How was the initial setup?
The deployment of Radware Cloud WAF Service was easy. It took about a month.
The solution does not require any maintenance.
What was our ROI?
We have seen more than 10% return on investment.
What other advice do I have?
Radware Cloud WAF Service was purchased through a partner.
In comparison with other WAF software, Radware Cloud WAF Service is at the top level. It provides the best outcome and next-gen detection. I would definitely recommend Radware Cloud WAF Service to other users because as an organization, we use it daily, and the tools provide the best outcome to secure and monitor organization traffic.
I would overall rate Radware Cloud WAF Service a ten out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Associate at a financial services firm with 201-500 employees
Security has improved as we block DDoS and bot attacks and free our team for other work
Pros and Cons
- "Since using Radware Cloud WAF Service, there are reductions in attacks."
- "There is one thing that needs to be improved in Radware Cloud WAF Service. When I am onboarding any kind of application and while bypassing those applications, it takes too much time."
What is our primary use case?
My main use case for Radware Cloud WAF Service is to prevent attacks. We have web applications for our company, and we need to prevent those web apps from various kinds of attacks such as DDoS or injection attacks.
How has it helped my organization?
We have stronger security now with Radware Cloud WAF Service.
Since using Radware Cloud WAF Service, there are reductions in attacks. Previously, the traffic was too high, so the chances of DDoS were very high. Now we are seeing that traffic is limited and genuine, resulting in a reduction of attack attempts.
I would say the improvement is around 80%, and as I already mentioned, it really reduces unnecessary traffic.
It really frees up the IT team for other projects. Since Radware Cloud WAF Service is monitoring our web apps traffic and mitigating potential attacks, this saves our time.
What is most valuable?
Radware Cloud WAF Service offers blocking and monitoring logs, so if I want to block any kind of traffic, I can block it, and if I want to monitor, then I can monitor. These fields are good.
Automated application mapping is good.
I am accessing Radware Cloud WAF Service for blocking unknown threats and attacks in terms of API DDoS, geo-blocking, data leak prevention, and bot protection.
Bot protection is really helpful for our organization to mitigate bot traffic and identify and block that traffic so that we can prevent unnecessary attacks.
Automated analysis in Radware Cloud WAF Service is good and really helpful for us to identify the events and the traffic in those events to clarify bot traffic or unnecessary traffic and genuine traffic so that we can take the required action accordingly.
With our existing application APIs and SIM monitoring tools, Radware Cloud WAF Service makes it easier to centralize security visibility and correlate the WAF events with other security and application data.
What needs improvement?
There is one thing that needs to be improved in Radware Cloud WAF Service. When I am onboarding any kind of application and while bypassing those applications, it takes too much time. This time needs to be lessened because it may be causing business impact sometimes.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for around one and a half years.
What do I think about the stability of the solution?
Radware Cloud WAF Service is pretty stable.
What do I think about the scalability of the solution?
Radware Cloud WAF Service is pretty scalable. I can access any kind of feature and any kind of application onboarding. There are no limitations or other restrictions.
How are customer service and support?
Customer support is good and punctual. I am rating the customer support a ten.
What was our ROI?
Radware Cloud WAF Service is a time-saving product.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing of Radware Cloud WAF Service are good. It is pretty costly, but it is worth it.
Which other solutions did I evaluate?
I evaluated other options before choosing Radware Cloud WAF Service, but that information is confidential and cannot be shared.
What other advice do I have?
Overall, I am rating Radware Cloud WAF Service as a nine. It is a good product, but it is not perfect, as I have told you about the improvements needed for this tool. Although it is a good tool, that is why I am giving it a nine.
I have not quite used the AI capabilities of Radware Cloud WAF Service as of now, but I will use it and then provide feedback.
Radware Cloud WAF Service is a good service that can be used with AI upgradation. Customer support is pretty good, and it can mitigate unnecessary traffic and prevent DDoS or bot attacks mostly. It is a pretty good tool to use for web apps.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Oct 8, 2026
Flag as inappropriateLider Ciberseguridad at a consumer goods company with 201-500 employees
Security policies have protected our cloud applications and reduce false positives for our team
Pros and Cons
- "Radware Cloud WAF Service has helped reduce my false positives because it has positive and negative intelligence and the capability to analyze traffic and build patterns."
What is our primary use case?
My main use case for Radware Cloud WAF Service is protecting our applications. I did not have a specific example to share about how I use Radware Cloud WAF Service.
How has it helped my organization?
Radware Cloud WAF Service has positively impacted my organization because it protects our different applications from various cyber attacks.
In the dashboard of Radware Cloud WAF Service, it shows me the different attacks, which is a measurable outcome I have noticed.
Radware Cloud WAF Service has helped reduce my false positives because it has positive and negative intelligence and the capability to analyze traffic and build patterns.
Radware Cloud WAF Service has helped free up my IT team for other projects, allowing the engineer to use their time in other activities.
What is most valuable?
The best features Radware Cloud WAF Service offers are AC and increment AC.
The increment AC feature of Radware Cloud WAF Service is important for us because it helps protect the different applications we have in various languages.
I assess Radware Cloud WAF Service for blocking unknown threats and attacks as excellent, as it blocks different threats and attacks, for example, the application.
My impressions of Radware Cloud WAF Service's automated analytics for looking at events is excellent because it reduces the time for identifying attacks.
I do not have the API Discovery feature services offered by Radware Cloud WAF Service.
I assess Radware Cloud WAF Service for integrating with other systems and applications in my environment as excellent because it is very easy.
Radware Cloud WAF Service protects against zero-day attacks because it analyzes the traffic effectively.
What needs improvement?
Radware Cloud WAF Service can improve by enhancing security for the different applications. I do not have any improvements needed for Radware Cloud WAF Service that I have not mentioned yet.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for six months now.
What do I think about the stability of the solution?
My service, Radware Cloud WAF Service, is stable.
What do I think about the scalability of the solution?
At this moment, we have twenty-one applications, and I think Radware Cloud WAF Service is very scalable because I do not have a higher number of applications in the service for my needs.
How are customer service and support?
I find Radware Cloud WAF Service's customer support to be good. I rate the customer support of Radware Cloud WAF Service a ten on a scale of one to ten.
Which solution did I use previously and why did I switch?
I previously used a different solution before choosing Radware Cloud WAF Service.
What was our ROI?
I have seen a return on investment with Radware Cloud WAF Service.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Radware Cloud WAF Service has been very good.
Which other solutions did I evaluate?
I evaluated five options before choosing Radware Cloud WAF Service.
What other advice do I have?
My experience with Radware Cloud WAF Service has been excellent. I rate Radware Cloud WAF Service a ten on a scale from one to ten. I chose ten as my rating because of the excellent control and tools that Radware Cloud WAF Service provides for my company. I do not know the AI capacities of Radware Cloud WAF Service regarding its governance and security. I do not know the AI capacity of Radware Cloud WAF Service in terms of its accuracy and reliability of output. My advice to others looking into using Radware Cloud WAF Service is that it is confident, easy to implement, and has very good, excellent tools without false positives. I provided an overall rating of ten for Radware Cloud WAF Service.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner, Reseller
Last updated: Oct 7, 2026
Flag as inappropriateApplication Supervisor at a government with 1,001-5,000 employees
Eliminates maintenance tasks and strengthens security with AI-driven and API security functionalities
Pros and Cons
- "It has features such as API security that protect against advanced attacks, including business logic attacks. It comes with additional functionalities such as bot protection and AI-driven threat signatures, along with threat intelligence, making it much more than the traditional WAF that we have on-prem."
- "Radware Cloud WAF Service offers better protection and can even provide significantly better security."
- "The dashboard of Radware Cloud WAF Service has room for improvement. While it works effectively, it can feel complex and might need some initial guidance, but once users become familiar with it, the operation becomes smooth."
What is our primary use case?
We have both infrastructure protection and web application protection. Infrastructure protection is against network-level denial of service attacks, and we use the application protection for our web application firewall, which provides layer seven security.
How has it helped my organization?
Being a cloud service, it removes the maintenance tasks for system uptime and the maintenance of on-prem appliances. It gives security analysts much more time for SOC work in analyzing alerts and threats. With on-premises solutions, there is a lot of maintenance involved to ensure that everything is functioning properly. Much time is dedicated to maintaining on-premises products. In contrast, as a cloud product, we don't have to worry about issues related to high availability or managing multiple instances of security solutions. Maintenance tasks such as operating system upgrades and other related issues are handled for us. This allows us to focus our efforts on SOC analysis work without the burden of these maintenance responsibilities.
It helps reduce the number of false positives and also addresses sophisticated attacks that may not be detected by our traditional systems on-premises.
Alerts help us quickly narrow down the issue, allowing us to spend less time on analysis and more time addressing active threats as they occur. Automation plays a significant role in this process.
Bot Manager has been quite positive. I find it to be more than just your traditional method of examining signatures or even looking at user agent headers. It goes beyond that; it analyzes the behavioral patterns of requests. Bots have become more advanced, often trying to imitate human behavior as closely as possible. With this bot protection, certain traffic gets blocked and flagged as bot traffic. However, when I review the requests from a human perspective, it can be challenging to identify what was actually bot traffic. Fortunately, the system provides a description of why a particular request was blocked and flagged as bot traffic. Bot traffic is a lot compared to normal human traffic, about 50% more. That alone frees up a lot of compute for our applications. The performance of the applications is significantly better because the bot's traffic is effectively filtered in the cloud. Only clean traffic reaches the applications, ensuring optimal performance.
The detection for bad bots and layer seven anomaly detection is ingrained within the logic. First of all, it examines normal signatures and user agents. Additionally, there is a significant reliance on AI-driven signatures that it looks out for. It also incorporates threat intelligence, which may include insights from various sources. Another important aspect is IP reputation, which is gathered from other clients with whom these bots have interacted. Overall, I think this solution is very effective; it has worked well for us and is actually blocking the traffic as advertised.
We rely heavily on Web DDoS protection, with about ninety percent of our services being application-based. Therefore, ensuring their security is very important to us. Radware provides the security we need and guarantees that the traffic reaching our web applications and servers is clean. This gives us peace of mind. While we monitor our systems closely, knowing that Radware Cloud WAF Service has our back is essential. Overall, it plays a crucial role in our business continuity as a security solution.
What is most valuable?
As compared to the traditional WAF that had on-prem systems, Radware Cloud WAF Service has many functionalities, such as AI-driven functionalities. It has features such as API security that protect against advanced attacks, including business logic attacks. It comes with additional functionalities such as bot protection and AI-driven threat signatures, along with threat intelligence, making it much more than the traditional WAF that we have on-prem. This is a key advantage I've seen since we onboarded it.
What needs improvement?
The dashboard of Radware Cloud WAF Service has room for improvement. While it works effectively, it can feel complex and might need some initial guidance, but once users become familiar with it, the operation becomes smooth.
For how long have I used the solution?
We have been using Radware Cloud WAF Service since the beginning of this year. It has not yet been a full year.
What do I think about the stability of the solution?
I would rate the stability of Radware Cloud WAF Service a nine out of ten. While the functionality is a 10 out of 10, occasional internet connectivity issues cause temporary access problems.
What do I think about the scalability of the solution?
The scalability of Radware Cloud WAF Service rates as a perfect ten out of ten, as we haven't encountered any scaling issues.
In the security team, four of us work with this solution. We have about 4,000 employees.
How are customer service and support?
Technical support from Radware rates as a nine out of ten, as their support is very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Radware Cloud WAF Service is the first cloud WAF solution we have used. We were using only an on-premises physical appliance.
As compared to our on-premises solution, Radware Cloud WAF Service offers better protection and can even provide significantly better security. In baseline protection, it matches our on-premises solution but has additional functionalities, including AI-driven signatures. This upgrade brings many more security features that we didn't have before. Overall, I would rate it much higher.
Radware Cloud WAF Service works well. There are many instances that we could not flag bot traffic using our traditional on-premises WAF. We use them concurrently. We compare the clean rate of what passes through the cloud instance with what passes through our on-premises instance. It has freed up many of the compute resources we have on-premises. Thus, much of the malicious traffic is stripped away at the cloud level before the clean traffic reaches our on-premises sites.
How was the initial setup?
The deployment of the Radware Cloud WAF Service was quite easy and took about two to three days, thanks to the helpful and responsive support team from Radware.
Apart from fine-tuning the security policies, much of the maintenance work is effectively handled in the background by the Radware team. As a result, there is very little to no maintenance required on our end.
What about the implementation team?
We were supported by Radware's onboarding team. They prepared our dashboard.
What was our ROI?
The Radware Cloud WAF Service saves us a significant amount of time, estimating around 30% to 40%.
With our on-prem solution, we spent a lot of time on maintenance tasks, OS updates, and ensuring appliances ran smoothly, but with Cloud WAF, all that is managed by the cloud team, allowing us to focus on alert analysis.
What other advice do I have?
For false positives, you need to properly tune the detection rules. In the beginning, it operates in a learning mode, which Radware refers to as "reporting mode." This mode simply reports on what is happening but doesn’t actively block any threats. When you transition to active protection, it’s crucial to take care when defining your threat signatures. If you don't, there can be some false positives. However, with excellent support from the onboarding team, we were able to resolve those issues very quickly, and after that, everything went smoothly. In the initial stages, it can be a bit tricky. There are some false positives, but they can be adjusted and fine-tuned. Once in a while, a false positive occurs, but we now have the knowledge on how to mitigate that.
A lot of applications are currently hosted on-premises. With a Cloud WAF, you need to redirect traffic to the cloud instance, and then the traffic is routed back. Initially, our main challenge was addressing internal threats, specifically insider threats. These applications are accessible both within our environment and to external users. However, since we began using cloud protection, it has primarily catered to external source traffic, leaving internal source traffic unprotected. Fortunately, Radware quickly developed a secure pathway functionality that can also redirect internal traffic to be inspected in the cloud. This feature is something we haven't implemented yet, but it is definitely on our agenda for implementation very soon.
The application protection from Radware Cloud WAF Service has API security, which protects the APIs we define against the different OWASP Top 10 API security threats.
I would rate the Radware Cloud WAF Service as a nine out of ten. Overall, it is a very effective solution that meets our expectations and blocks traffic as advertised.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Network Engineer at a financial services firm with 10,001+ employees
Efficiently protects from threats and integrates well with our systems and applications
Pros and Cons
- "The features I find most valuable about Radware Cloud WAF Service are primarily rate-limiting, geo-blocking, web DDoS protection, and some other basic features."
- "Radware Cloud WAF Service has improved our efficiency by about 95%."
- "Additionally, alert messages for DDoS attacks or other things take time to reach us, causing delays in our response."
What is our primary use case?
Our use cases for Radware Cloud WAF Service include all of our applications, such as online banking applications, as I work for a bank. It works effectively. Our payment systems also operate through this service, and we have a few applications running over the web.
How has it helped my organization?
Radware Cloud WAF Service works very well for blocking unknown threats and attacks. We haven't seen any issues with that. Whenever we experienced any threat, we got accurate blocking. We haven't had any issues.
Automated analytics for looking at events are good. We have no issues with it. It gives us precise and accurate information. It helps us a lot. We're able to allowlist and check port managers and all of that.
Radware Cloud WAF Service has helped us reduce false positives by 100%. It's accurate and has significantly aided our efforts. Radware Cloud WAF Service has improved our efficiency by about 95%.
From the networking perspective, Radware Cloud WAF Service integrates very effectively with our systems and applications. However, other business units in the company find it somewhat difficult to adapt to Radware's methodology. For our networking team, we are fully utilizing it without issues, and we're looking to move everything to Radware Cloud WAF Service for our online banking, connecting backend devices to Radware Cloud WAF Service instead of F5 for load balancing. This is a big project involving eight countries, not just South Africa, and as network professionals, we truly enjoy working with Radware Cloud WAF Service.
Radware Cloud WAF Service has handled zero-day attacks effectively. It has been very helpful and has prevented numerous issues. The last time we were attacked as a bank was around 2017, before COVID, resulting in only about five minutes of downtime. Since then, smaller attacks have been mitigated by both Radware Cloud WAF Service and the Radware DPX boxes on-premises.
Radware's combination of negative and behavior-based positive security models is very important for our security strategy because threats come from various sources and can spoof our network. Our firewall system isn't strong enough to detect or block these threats, but with Radware, we feel completely safe and secure, allowing us to remain calm in the face of potential attacks.
We are using the automated source blocking feature of Radware Cloud WAF Service, and it's superb. We have been using it for less than six months, and so far, we haven't regretted the decision. The proactive and holistic approach of Radware Cloud WAF Service has been very effective in protecting our applications. After moving to Radware Cloud WAF Service, we got to know about hidden attacks that we couldn't identify before. In the past, we could not identify the problem. There've been certain failures or issues that we suspected to be related to the backend of the app or F5, but they were not. They were attacks that were hiding behind the radar.
We use the Radware Bot Manager and have had a positive experience with it. We can block bad bots effectively, and since we started using it about two years ago, we haven't encountered any problems. Bot Manager helps with our compliance efforts, but I haven't had much contact with them—most discussions happen with my colleague Paul, who has worked with Radware since day one.
The real-time BLA detection and mitigation from Radware Cloud WAF Service hasn't negatively impacted us. We've had minimal downtime, about five to seven minutes, but since then, we have experienced everything operating smoothly.
Web DDoS protection is good. Our layer 7 protection is working very well. In the past, we couldn't do anything about it. We were getting so many attacks. We haven't had any issues since we started using it.
What is most valuable?
The features I find most valuable about Radware Cloud WAF Service are primarily rate-limiting, geo-blocking, web DDoS protection, and some other basic features.
What needs improvement?
When it comes to support, I would suggest having a dedicated number for our clients for better identification in case of issues, as the varying numbers make it easy to miss important calls.
Additionally, alert messages for DDoS attacks or other things take time to reach us, causing delays in our response.
I see potential in adding threat intelligence, and I don't have issues with the responsiveness or user-friendliness of the Radware console. It's definitely user-friendly for me.
For how long have I used the solution?
We have been using it for the past five to six years.
What do I think about the stability of the solution?
I have noticed occasional lag in the mornings, but it's not an everyday occurrence. Logging out and back in usually resolves it.
What do I think about the scalability of the solution?
Scalability with Radware Cloud WAF Service is 100%. Everything works perfectly in that regard.
How are customer service and support?
I have contacted technical support, and they're very quick and responsive. There may be a pronunciation barrier for some of my colleagues, but overall, the support is satisfactory. I would rate the support from Radware a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial deployment of Radware Cloud WAF Service was very easy. It took less than 45 minutes.
What about the implementation team?
Just one person was required for the deployment from our end.
What other advice do I have?
I would rate Radware Cloud WAF Service a ten out of ten. Everything is working efficiently with Radware Cloud WAF Service, and it is truly a good product.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Assistant Manager, Information Security Department at a financial services firm with 501-1,000 employees
Security has improved as we filter malicious traffic and protect trading web applications
Pros and Cons
- "Radware Cloud WAF Service has positively impacted my organization by making the traffic manageable, and approximately 90% of the traffic is genuine traffic."
- "Sometimes we need to bypass the application from Radware Cloud WAF Service to our LB, and that process takes too much time, which I think Radware needs to improve by reducing the time."
What is our primary use case?
Radware Cloud WAF Service is primarily used to protect our web applications. We have various kinds of applications related to trading apps and our company web app, so we need to protect them from DoS and DDoS web attacks. For those main applications and managing the traffic for those applications, we are using Radware Cloud WAF Service. With this service, we have successfully mitigated some DoS attacks and some DDoS attacks, and we have prevented some attacks as well by blocking some IPs and implementing country geo-blocking. Geo-blocking is the most helpful feature from Radware Cloud WAF Service.
How has it helped my organization?
Radware Cloud WAF Service has positively impacted my organization by making the traffic manageable, and approximately 90% of the traffic is genuine traffic. It has really helped us find attacks and mitigate or prevent them.
We measure that 90% genuine traffic by observing multiple incidents where we can see how the traffic is functioning. Sometimes the traffic flow is too high, and we can apply our judgment on what kind of traffic and the amount of traffic needed for our applications, helping us prevent much higher traffic and attacks such as DoS attacks.
What is most valuable?
Radware Cloud WAF Service offers excellent features, with geo-blocking being the best. Geo-blocking is a very good feature that helps us block an entire country; for instance, we can block all traffic from Pakistan to prevent access to our web apps.
Geo-blocking is the feature that is mostly helpful, but there is also one more feature which is customized IP blocking. It is helpful for us to block some customized IPs from attackers to prevent zero-day attacks.
Radware Cloud WAF Service's AI capabilities are really good and helpful for us, and I think they are still in the learning phase, so we will monitor how they improve.
What needs improvement?
Sometimes we need to bypass the application from Radware Cloud WAF Service to our LB, and that process takes too much time, which I think Radware needs to improve by reducing the time.
The main point is that it takes too much time to bypass the application.
The accuracy and reliability of the output from Radware Cloud WAF Service meet my expectations, but they still need to be improved properly.
For how long have I used the solution?
I have been using Radware Cloud WAF Service for one and a half years.
What do I think about the stability of the solution?
Radware Cloud WAF Service is 98% stable.
What do I think about the scalability of the solution?
Radware Cloud WAF Service's scalability is good and pretty good.
How are customer service and support?
Customer support is proper and good for us; we get regular responses from Radware, so it is good.
Which solution did I use previously and why did I switch?
This is our first solution as a Cloud WAF.
What was our ROI?
We have saved money and time by using Radware Cloud WAF Service to mitigate DoS attacks and clean up the mess.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing for Radware Cloud WAF Service is good.
Which other solutions did I evaluate?
We evaluated other options, but it is confidential.
What other advice do I have?
Radware Cloud WAF Service is a good service, and the support is always available; if we have any incidents and require immediate support, we can contact Radware team, and they respond immediately. Other services are also good. I advise others looking into using Radware Cloud WAF Service to go ahead and use it, as it can properly protect web apps. I rate Radware Cloud WAF Service a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Oct 7, 2026
Flag as inappropriateBuyer's Guide
Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Cloudflare Web Application Firewall
Imperva Application Security Platform
Fortinet FortiWeb
Check Point WAF (formerly CloudGuard WAF)
Akamai App and API Protector
Azure Front Door
Aikido Security
F5 Advanced WAF
Microsoft Azure Application Gateway
F5 Distributed Cloud Services
Radware Alteon
Buyer's Guide
Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- How does a WAF help to protect against DDoS attacks?
- NGFW with URL Filtering vs Web Proxy
- What's right for me? Fortinet or Citrix?

















