Try our new research platform with insights from 80,000+ expert users
Sita Thomas - PeerSpot reviewer
Associate Vice President - Engineering at a tech vendor with 11-50 employees
Real User
Top 5
Nov 28, 2024
Enhance security with flexible traffic filtering despite complex documentation
Pros and Cons
  • "One of the most valuable features of AWS WAF is its ability to filter web app traffic, allowing us to specify conditions such as IP addresses and HTTP headers."
  • "I find the documentation somewhat complex to implement during the initial stages."
  • "I find the documentation somewhat complex to implement during the initial stages."

What is our primary use case?

My usual use case involves monitoring incoming calls and services deployed in AWS cloud. Security and privacy are primary concerns, so we use AWS WAF to monitor and ensure that only appropriate calls are allowed. AWS Shield is also used to protect against DDoS attacks, but I'm using the basic free version due to budget constraints.

How has it helped my organization?

AWS WAF has helped to improve the security of our products by filtering web app traffic and specifying conditions such as IP addresses and HTTP headers. These features, along with others, have enhanced the overall security and effectiveness of our applications. The integration with IAM restricts access to the server, providing additional security.

What is most valuable?

One of the most valuable features of AWS WAF is its ability to filter web app traffic, allowing us to specify conditions such as IP addresses and HTTP headers. We can create rules accordingly to prevent attacks, like SQL injection and cross-site scripting. AWS WAF, combined with firewall manager, enhances security by allowing us to specify security rules. Custom rules are useful for allowing access to specific traffic, and AWS WAF handles false positives by limiting requests from certain IPs or setting geographic match conditions.

What needs improvement?

I find the documentation somewhat complex to implement during the initial stages. If it were made simpler and more user-friendly, with the right examples provided, it would be more helpful.

Buyer's Guide
AWS WAF
February 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,733 professionals have used our research since 2012.

For how long have I used the solution?

I have been working with AWS WAF for almost six years.

What do I think about the stability of the solution?

AWS WAF provides a stable environment by preventing unknown attacks, allowing us to deploy services securely. I rate the stability as nine out of ten. It ensures that our applications run without security concerns.

What do I think about the scalability of the solution?

I rate the scalability of AWS WAF as a seven out of ten. It adapts well to our needs and serves its purpose effectively.

How are customer service and support?

The customer service and support from AWS are excellent. I rate them ten out of ten. My interactions have been positive, with prompt responses to issues like quota requests and additional resource allocations.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before AWS WAF, we used Azure but did not deploy these specific solutions on it. We migrated to AWS to fully utilize their security features.

How was the initial setup?

The initial setup was complex, with a steep learning curve related to rules and implementation. I would rate the initial setup experience as a six out of ten, as it took substantial time to get everything functioning smoothly.

What about the implementation team?

We managed the deployment process internally without needing external assistance. Our team uses automated deployment strategies via GitLab, which automates deployment across various environments.

What was our ROI?

Using solutions deployed in AWS cloud enhances customer satisfaction since AWS is a well-known and widely accessible cloud service provider.

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable when using free credits; otherwise, it would be rated a six in terms of cost.

Which other solutions did I evaluate?

I did not evaluate other options extensively as AWS WAF with Firewall Manager seemed to offer the best security strategy.

What other advice do I have?

Properly go through the documentation and reference examples. Understand your use cases and apply the correct rules for the solution. AWS support can assist with setup and implementation. 

I rate the overall solution as nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Manikandan-R - PeerSpot reviewer
Senior Project Manager at a tech vendor with 10,001+ employees
Real User
Top 5
Mar 18, 2024
Sends useful alerts and enables to automate tasks by creating rules
Pros and Cons
  • "Rule groups are valuable."
  • "We must monitor and clean up the WAF manually."

What is our primary use case?

We use Managed Rules mostly.

How has it helped my organization?

ALB is integrated with WAF. When ALB spikes up, we know there’s something wrong. Usually, bots attack the applications.

What is most valuable?

Rule groups are valuable. We use it for DDoS. We do customizations with the help of Managed Rules in AWS. We use AWS WAF’s API to automate security tasks. The rule creation is similar to automation. We have enough understanding of how things work. It’s been one year since we have automated the tasks.

What needs improvement?

There are some limitations. We can add a maximum of four rate-based rules to the rule group. We must monitor and clean up the WAF manually. We cannot create rules if it goes above four. It requires manual intervention. We have to check, clean, and maintain it regularly. We do not want to do it. We are willing to pay extra if it can be improved. We need additional features so we do not have to do manual interventions.

For how long have I used the solution?

I have been using the solution for three years.

What do I think about the stability of the solution?

We do not have any problems with the tool’s functionalities.

What do I think about the scalability of the solution?

We are very happy about the product’s scalability. We did not face any issues. My organization is an enterprise.

How are customer service and support?

We have a partnership. We can contact the consultants whenever we need anything. We don't have any problem with the support team.

How would you rate customer service and support?

Positive

How was the initial setup?

The installation was not difficult. We have a separate team to deploy the solution in our organization. We do not face any issues with maintenance.

What other advice do I have?

All our infrastructure is on AWS. My organization has been using AWS for the last eight years. Mid-size companies use ALB. We also use AWS Shield. Sometimes, we get alerts from AWS Shield. Our internal tools also send us alerts. We're completely on AWS. We do not integrate it with any other tool. Overall, I rate the product an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
AWS WAF
February 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
881,733 professionals have used our research since 2012.
Rohit Kesharwani - PeerSpot reviewer
Manager, Engineering at a retailer with 10,001+ employees
Real User
Top 5
Jan 30, 2024
A highly stable solution that helps mitigate different kinds of bot attacks and SQL injection attacks
Pros and Cons
  • "AWS WAF helps mitigate different kinds of bot attacks and SQL injection that happen within the retail industry."
  • "The solution's pricing could be improved."

What is our primary use case?

We use AWS WAF to protect our application from different kinds of attacks. We use AWS WAF for retail customers.

What is most valuable?

Our retail application is vulnerable to a lot of bot attacks. AWS WAF helps mitigate different kinds of bot attacks and SQL injection that happen within the retail industry.

What needs improvement?

The solution's pricing could be improved. You cannot add multiple rules within AWS WAF's CPU.

For how long have I used the solution?

I have been using AWS WAF for more than three years.

What do I think about the stability of the solution?

Since AWS manages the solution, it is fairly stable.

I rate AWS WAF a nine out of ten for stability.

What do I think about the scalability of the solution?

AWS WAF is a scalable solution.

I rate AWS WAF an eight out of ten for scalability.

How are customer service and support?

I am satisfied with the solution’s technical support.

How would you rate customer service and support?

Positive

How was the initial setup?

On a scale from one to ten, where one is difficult and ten is easy, I rate the solution's initial setup an eight out of ten.

What about the implementation team?

The solution's deployment takes a few minutes.

What's my experience with pricing, setup cost, and licensing?

There is no licensing at all. We have to pay for it as we use it.

On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven or eight out of ten.

What other advice do I have?

Integrating AWS WAF with other AWS services in our infrastructure is fairly easy. There are different tools through which we can do it.

AWS WAF is a fairly easy solution. Users need to build a few rules by themselves based on the vulnerability attack within the application.

Overall, I rate the solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
AshishGautam - PeerSpot reviewer
IT Project Manager at a healthcare company with 1,001-5,000 employees
Real User
Jan 4, 2024
Along with outstanding stability, the tool also offers good-quality technical support
Pros and Cons
  • "The product's initial setup phase was very simple."
  • "The area of reporting in the product needs to have a proper format."

What is our primary use case?

If I have hosted your web applications or web services on AWS, and if you need a segregation in terms of different aspects, like at a country level or area level, especially when your website is not reachable for a particular country or a particular area, then you need to implement WAF on top of the public network. If WAF actually works on top of the network to manage each request at a global level, WAF is the first layer that handles the internet's every request, and depending on your choice, you can either accept or deny such requests.

Currently, most organizations face security challenges, and with the rise in hacking in every sector, like healthcare, IT, manufacturing, or infrastructure sector that we're talking about. You have to at least implement WAF on top of your network as well as the local network so that it filters every network traffic that comes in from any country. In our company, Fortinet WAF is what we use on top of the network as an anonymous network, and within the network, we use F5.

What is most valuable?

Due to security concerns or reasons, I recommend others to use AWS WAF and control the requests from multiple countries from a hacking point of view.

What needs improvement?

The area of reporting in the product needs to have a proper format. If you want to find the event log for an event and IP address from another country, there is a need to do some rework after the reporting part is taken care of so that the management can easily read the reports. A technical person in the organization can always understand where a particular network traffic comes in or where traffic is blocked with the help of WAF, but those in the management department would never understand the concepts that a technical person can understand. The reporting part of AWS WAF needs to be improved.

For how long have I used the solution?

I have been using AWS WAF for five years.

What do I think about the stability of the solution?

It is a stable solution. Stability-wise, I rate the solution a ten out of ten.

What do I think about the scalability of the solution?

It is an easily scalable solution. Scalability-wise, I rate the solution a ten out of ten.

More than 2,000 to 2,500 employees in my company use the solution.

How are customer service and support?

The solution's technical support's response time and quality are very good. I rate the technical support a ten out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The product's initial setup phase was very simple.

The solution is deployed on the hybrid cloud model.

The product is deployed in a virtual environment and not in a physical one.

What's my experience with pricing, setup cost, and licensing?

I rate the product price a five on a scale of one to ten, where one is high price, and ten is low price. I recommend people check for the services that run in the AWS WAF account. Each service that uses AWS will need the user to pay for some costs. Most of the people who use the solution are not able to understand the number of services that are running in the product. Even though there is a feature to help understand top-level management, people fail to figure out the number of services that are running in the product.

Which other solutions did I evaluate?

Compared to AWS WAF, Fortinet is easy to use and deploy. From a technical point of view, Fortinet is easy to implement and handle. I recommend Fortinet over AWS WAF to others.

What other advice do I have?

I recommend Fortinet, as it is one of the best products, be it the virtual firewalls or the on-premises setup. If one wants to look for the on-premises setup, one must buy the hardware box.

I rate the overall tool a ten out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Aravind D - PeerSpot reviewer
Senior Cloud Engineer at a wholesaler/distributor with 10,001+ employees
Real User
Oct 12, 2023
A stable and reasonably priced solution that protects organizations from hackers and other security threats
Pros and Cons
  • "If hackers try to insert bugs, the tool blocks it."
  • "It will be helpful if the product recommends rules that we can implement."

What is our primary use case?

We use the product to protect the environment from DDoS and SQL injection attacks. We implement WAF in the public site.

What is most valuable?

WAF filters based on IPs. If hackers try to insert bugs, the tool blocks it.

What needs improvement?

Google uses an AI tool to provide insights about rules. It will be helpful if the product recommends rules that we can implement.

For how long have I used the solution?

I have been using the solution for six years.

What do I think about the stability of the solution?

The tool is stable.

What do I think about the scalability of the solution?

AWS takes care of the product's scalability, security, and performance. We do not have to maintain it.

Which solution did I use previously and why did I switch?

Google’s console is minimalistic. It provides AI tools that help us create rules.

How was the initial setup?

The deployment is very easy. It takes around five minutes. WAF plays an important role in the network. We need to implement WAF in the first level of security. We can implement it with the help of a console. We need one person to deploy the tool.

What's my experience with pricing, setup cost, and licensing?

We pay $0.8 per hour. The product’s pricing is reasonable.

What other advice do I have?

When we faced a DDoS attack before, we were not able to find the logs to identify the source of the attack. People who want to use the solution must have a basic knowledge about different attacks. Using the solution is easier if we know how the attacks happen. Overall, I rate the product a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Manager - Cyber Security and SOC at a recreational facilities/services company with 10,001+ employees
Real User
Aug 10, 2023
The product is stable, scalable, and easy to deploy, but the default content policy of the tool is not very strong
Pros and Cons
  • "The ease of deployment of the product is valuable to me."
  • "The default content policy available in the tool is not very strong compared to the competitors."

What is our primary use case?

The solution protects my customers’ web applications hosted in AWS.

What is most valuable?

The ease of deployment of the product is valuable to me. AWS WAF might be one of the easiest WAFs that can be deployed. The only constraint is that our application must be running in AWS.

What needs improvement?

The default content policy available in the tool is not very strong compared to the competitors. Most of the WAFs will have a default set of policies and rules that we need to enable, which will satisfy our requirements. However, for AWS, we must put some time and effort into creating our content policy to get optimal protection.

For how long have I used the solution?

I have been providing the solution for a year or more.

What do I think about the stability of the solution?

The product is stable. I have no complaints. I rate the stability a nine out of ten.

What do I think about the scalability of the solution?

The product is scalable. I rate the scalability a nine out of ten.

How are customer service and support?

The technical support is good. I have no complaints. The support team is fast, knowledgeable, and customer-friendly.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. It takes merely half an hour or less to deploy the solution. The solution is deployed on the cloud.

What about the implementation team?

Whether we need a consultant to help with the deployment depends on our knowledge of the cloud platform and our applications. It is a complex solution. We can do it ourselves if we know about WAFs, rule sets, and deployments. It is not a solution for a novice or someone unfamiliar with the security and application firewall. Such people might need the help of an administrator or consultant. We deployed the solution ourselves.

What's my experience with pricing, setup cost, and licensing?

Depending on how our AWS billing is configured, we are billed on a monthly or yearly billing cycle. The product is moderately priced. It is not too cheap but not too high either. There are no additional costs associated with the product.

What other advice do I have?

I would recommend the solution to others. If a web application is completely hosted in AWS, then AWS WAF is a good choice. We can easily adopt it. Overall, I rate the solution a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Aditya Mehta - PeerSpot reviewer
Director at a consultancy with 51-200 employees
Real User
Top 10
Nov 28, 2023
An easy-to-use and easy-to-configure solution that provides high stability
Pros and Cons
  • "AWS WAF is very easy to use and configure on AWS."
  • "It would be good if the solution provided managed WAF services."

What is our primary use case?

When customers onboard a web application and want a WAF to protect it, they ask us to configure AWS WAF for them.

What is most valuable?

AWS WAF is very easy to use and configure on AWS. It is easy to make rules and very fast to set it up on AWS.

What needs improvement?

AWS WAF provides only basic protection, and they should provide more features like other third-party competitors. The world is now moving towards managed services. It would be good if the solution provided managed WAF services. If AWS WAF could detect that some attack is about to happen and alert the user, we can write some rules and stop that from happening.

For how long have I used the solution?

I have been using AWS WAF for five years.

What do I think about the stability of the solution?

We have never faced any stability issues with AWS WAF.

I rate AWS WAF ten out of ten for stability.

What do I think about the scalability of the solution?

AWS WAF is more suited for small and medium businesses.

I rate AWS WAF a nine out of ten for scalability.

How was the initial setup?

The solution’s initial setup is simple.

What's my experience with pricing, setup cost, and licensing?

AWS WAF has reasonable pricing.

Which other solutions did I evaluate?

Third-party competitors like F5 and Imperva have more features than AWS WAF.

What other advice do I have?

Overall, I rate AWS WAF a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
DevOps Engineer at a tech services company with 11-50 employees
Real User
Aug 15, 2023
Easy to configure and stable solution
Pros and Cons
  • "The most valuable feature is that it is very easy to configure. It just takes a couple of minutes."
  • "There is room for improvement in pricing."

What is our primary use case?

For AWS WAF, currently, we use this new application. This is another service provided by AWS for the sales business, and it's used for education. So, AWS WAF works in conjunction with AWS Cognito.  We observe this when there's some kind of bot attempting to access our application or when you're trying to use a bot as a control mechanism to transcribe or manage a high volume of traffic through our endpoints. 

AWS WAF manages both human traffic and bot-controlled traffic, and it can redirect you to a catch-up mechanism or sometimes simply for use. So, we've implemented different kinds of mechanisms within AWS WAF.

How has it helped my organization?

We use it in the production environment. From time to time, we can see the metrics for the generated traffic on both the WAF and the infrastructure

These metrics are presented on the dashboard. We review this information and conclude that regular monitoring, along with dashboard evaluations, reaffirms the effectiveness of the system. This allows us to ensure that the investment we're making is justified and worthwhile.

What is most valuable?

The most valuable feature is that it is very easy to configure. It just takes a couple of minutes. 

What needs improvement?

There is room for improvement in pricing. 

The pricing for each rule group is a bit too high. It's a monthly subscription, and it can get quite expensive for rules that I won't use for my application. For example, I might create a rule group that costs $10, and I only use one of the rules in the group. That's $10 for a rule that I'm not even using! So, the pricing could be more flexible, or there could be a way to get discounts for unused rules.

So, AWS WAF should have a pay-as-you-go pricing model, where I can only pay for the rules that I use. 

For how long have I used the solution?

I have been using this solution for three years. 

What do I think about the stability of the solution?

It is a stable solution to some extent.

What do I think about the scalability of the solution?

For my use cases, it is a scalable solution. There are less than 2,000 end users using this solution in our organization.

How are customer service and support?

I reached out to support when I was setting it up initially, I had some questions. And we have some kind of first-line support with AWS. So I reached out to them whenever I had questions.

However, the support depends on the support we are paying for. The support we are paying for is cheap support. I'm on the standard support plan, so my SLA is four hours. There's a phone queue, so I can't always get through right away. But the support engineers are knowledgeable and can usually point me in the right direction. 

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup is fairly easy. AWS does everything for us—just some clicks. 

What about the implementation team?

There is no maintenance required. AWS also upgrades new offerings. AWS does all these things. Like, it does why it's very expensive.  And they give us the metrics.

What other advice do I have?

Just evaluate these simple things you need. And don't try to put too many features at the beginning because you might not need them. Every application is designed differently. 

Every business and customer is also very different, so if your application is more susceptible to some kind of engineering traffic then it's going to be very expensive.

Overall, I would rate the solution an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2026
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.