No more typing reviews! Try our Samantha, our new voice AI agent.
Adrian Milea - PeerSpot reviewer
Raiffeisen at Raiffeisen Bank Romania
Real User
Aug 25, 2022
Easy to deploy, implement, and manage
Pros and Cons
  • "The agility is great for us in terms of cloud services in general."
  • "The most important aspect for us is that AWS WAF is easy to deploy."
  • "For uniformity, AWS has a well-accepted framework. However, it'll be better for us if we could have some more documented guidelines on how the specific business should be structured and the roles that the cloud recommends."

What is our primary use case?

We primarily use the solution for load balancing. 

We have some microsites exposed through the AWS cloud. These are some sort of pilot and we are using WAF to learn how this new product fits with us, and are mostly in the testing phase with a limited impact application. We are obviously not migrating core applications or those which have a significant impact on availability or on integrity and confidentiality. Mostly we have it on microsites where we don't see a significant risk, and it is more of a learning exercise for us.

What is most valuable?

The most important aspect for us is that AWS WAF is easy to deploy. The ease of implementation, ease of management, and flexibility are great. We like the potential for pay as you grow as you have instant deployment, infrastructure as a code, or any other automation tools that can leverage these deployments. The most important thing for us is that it stays flexible and scalable. That is true not only with WAF but with all the cloud services where you can provision any product in minutes. 

With the cloud, you have these integrated tools that provide a single glass pane. 

You have automation, ease of export, or ease of seeing the logs and exporting to a SIEM; these aspects are also great. The agility is great for us in terms of cloud services in general.

Usually, if we're talking about standard WAF, this is easy to deploy and is good at protecting low to medium applications.

What needs improvement?

As of now, regarding WAF, I'm not sure what the minuses or pluses are. You have the native WAF, which you can deploy directly on the load balancer. However, you also have that store where you can actually deploy some other vendors' specifics. At this point, feature-wise, I don't see anything lacking, more or less. Obviously, if we want to migrate, which is not yet the case, there might be a significant impact.

For uniformity, AWS has a well-accepted framework. However, it'll be better for us if we could have some more documented guidelines on how the specific business should be structured and the roles that the cloud recommends. If every company is building its own framework based on their experience or their past experience, this might be subjective, and it'll end up with each company having its own framework, which can be good. However, it'll be better to have a standardized baseline that every company could build on. 

For how long have I used the solution?

We've been using the solution for more than a year at this point. 

Buyer's Guide
AWS WAF
June 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,270 professionals have used our research since 2012.

What do I think about the stability of the solution?

You have multiple availability zones and regions. The availability or durability is not something that we need to concern ourselves with very much here. Regarding the availability, I don't think this is something that the average company could match. They have a lot of availability zones, redundancy, and all the other things like that.

What do I think about the scalability of the solution?

It's scalable. Mostly, what I would look into is having cloud resiliency in the sense that we want multiple vendors, so if something happens with AWS, you'll need some sort of strategy and you'll need some other vendor to provide you with similar services. 

We have a number of users per application. It's hard to quantify how many users are on the solution in general. 

How are customer service and support?

For us, it's a bit of a different model where we have services provided by one central team or central entity. The others will have some sort of hub and spoke with the central entity providing or re-providing services to the other network units. The relationship with AWS is maintained by our central unit, and we somehow take services from the central unit and customize them per our needs. However, if we have some issues, this will be raised by the group. Issues may be resolved by AWS or an SME that works with us. 

How was the initial setup?

In terms of the initial setup, from what I heard, it initially being a new technology, you want to deploy it in a correct manner. Therefore, it will need more diligence in the first deployment as security is not something you can learn and adjust. You need to make it right from day one in order to avoid breaches. However, after that, with infrastructure as a code and the automatic deployment, it's easier. You just create your setup, and you use the rules and go. You have network access to a security group, which provides you with very general filtering for problematic traffic. 

From my experience, the cloud provides everything we need; however, we still lack the knowledge and framework in terms of who is doing what, et cetera.

It's quite different between on-premise and cloud. In the cloud, DevOps is doing a lot of things. On-premise, you have someone from infrastructure, someone installing the OS, and someone doing the vulnerability and patch management.

Depending on how you deploy, the activities need to be revised. You need to have this framework to work in the cloud, and it's more of a challenge in company philosophy rather than technical capabilities. Companies can find it challenging to migrate to new tools. Sometimes existing teams need to be re-educated. 

We have multiple applications, so usually, it takes a while to refine the framework with the responsibility inside the company. It's to be optimized. However, in terms of actual deployment, security-wise, it takes some time to do the security checks, including the scanning and vulnerability asset inventory. It might take two or three months per application.

What other advice do I have?

I definitely recommend not only AWS. I also recommend Azure as an option. We have the integration with Office and the entire portfolio. The cloud, in general, it's a new thing to consider. For example, you have this GDPR with data in Europe. However, in the case of most of the clouds, you can select your regions and you have some control. 

I'd rate the solution nine out of ten. 

There are a huge amount of products. I'm not saying it's a bad or a good thing. However, it can be quite confusing. There are VPC, EC2, and other instances, and there are a lot of other services that you can use like Macie, where you can filter sensitive information. There are a lot of tools that require hands-on and new capabilities. For me, being at the beginning of this journey for cloud migration, I've been mostly quite happy with the results.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1953606 - PeerSpot reviewer
Senior Administrator at a media company with 51-200 employees
Reseller
Top 20
Nov 12, 2024
Advanced security with effective OWASP filtering rules and easy connectivity
Pros and Cons
  • "They filter a lot of attacks out."
  • "Rule exclusion could be a bit more transparent."

What is our primary use case?

The primary use case for AWS WAF involves securing applications for our customers, who are mainly software developers. Their application is positioned behind the firewall.

How has it helped my organization?

DDoS attacks are being blocked by AWS WAF, which is something some of my customers really need as they are targeted quite often.

What is most valuable?

The most valuable feature of AWS WAF is the OWASP filtering rules. They filter a lot of attacks out. Moreover, the service includes DDoS protection.

What needs improvement?

Rule exclusion could be a bit more transparent. However, it works great overall.

For how long have I used the solution?

I have been working with AWS WAF for two years now.

What do I think about the stability of the solution?

AWS WAF is stable. I have no complaints regarding its stability.

What do I think about the scalability of the solution?

It is easy to scale up AWS WAF. I would rate it an eight out of ten on the scale of scalability.

How are customer service and support?

I have never needed customer support for AWS WAF.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

The old team I worked at is still using Enable Insight remote monitoring, but personally, I am now using Datadog.

How was the initial setup?

AWS WAF is easy to connect, and I would rate the overall setup process as a seven since it's still a lot of work.

What about the implementation team?

I manage the AWS WAF for my clients and am responsible for the implementation.

What was our ROI?

The return on investment is difficult to determine. When a successful hack attempt is stopped, the investment is already returned.

What's my experience with pricing, setup cost, and licensing?

The customers think AWS WAF is expensive. Compared to hardware solutions, it is slightly more expensive, but it includes extra services. Personally, I find it fairly priced.

Which other solutions did I evaluate?

I did not explicitly evaluate any alternate solutions for AWS WAF.

What other advice do I have?

If security is an issue and you want to be secure, you should use AWS WAF.

I'd rate the solution eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
AWS WAF
June 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,270 professionals have used our research since 2012.
Group IT Manager at Civcns
Real User
Feb 7, 2024
A highly stable product that provides a good interface and is easy to configure
Pros and Cons
  • "The interface is good."
  • "The price could be improved."

What is our primary use case?

We use the solution to secure our public web server and run our document management process. We have service-oriented web servers and interactive web servers.

What is most valuable?

Custom rules are valuable to us. We have country-specific rules that we apply. The solution meets all our requirements. We never had a problem with the tool. The interface is good. We never had downtime. The solution does its job.

What needs improvement?

The price could be improved.

For how long have I used the solution?

I have been using the solution for more than two years.

What do I think about the stability of the solution?

The tool is highly stable.

What do I think about the scalability of the solution?

The tool is highly scalable. Almost all AWS products are highly scalable. I am the only user in my organization. The solution is running regularly. We check the logs whenever we have some issues. We do not include it in our security management system. It's a very small application. We use it to manage some documents.

How was the initial setup?

The initial setup is easy. The deployment took an hour. The setup and maintenance is easy. We do not face any issues with configuration.

What about the implementation team?

We deployed the solution in-house.

What's my experience with pricing, setup cost, and licensing?

The solution is reasonably priced.

What other advice do I have?

We never had DDoS attacks. We do not check logs deeply. The service is a very small portion of our application server. It is not a business-critical service. We check logs only when we have any performance or connectivity issues. Overall, I rate the product a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Amr Kassem - PeerSpot reviewer
Security implmentation engineer at a security firm with 51-200 employees
Real User
Top 20
Jun 23, 2023
The product is highly scalable and has a helpful support team, but it should improve the features that mitigate DDoS attacks
Pros and Cons
  • "We do not have to maintain the solution."
  • "The product should improve the DDoS-related features."

What is our primary use case?

We use the solution for publishing important applications. These sites are accessed by hundred to one million users every day.

What is most valuable?

We do not have to maintain the solution. Amazon maintains the product.

What needs improvement?

We have a lot of issues related to attacks on our cloud. There is a limitation on how to mitigate the issues in the solution. The product should improve the DDoS-related features.

The solution should provide an advanced tool for DDoS migration and a better reporting method. Compared to other solutions, we do not get all the information we need for reporting.

For how long have I used the solution?

I am dealing with the solution right now.

What do I think about the stability of the solution?

The solution is stable. It does not depend on the data centre or browser consumption.

What do I think about the scalability of the solution?

The product has high scalability. I can increase the resources without any effort.

How are customer service and support?

The support team is very helpful.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is too simple on the AWS. It is not complex at all. If we take certain courses and view a lot of videos on how to implement the solution, it is very easy. Support helps us with the deployment.

What about the implementation team?

Our teams do not manage the product. The deployment process includes adding a new customer, reserving their information on the cloud, creating the nodes, publishing the service and testing it on the old security aspects. Then, the solution is deployed on the cloud. 

The time taken for deployment depends on the customer's requirements. Usually, there is a delay due to missing information from the customers. One or two engineers can handle the deployment. We do not need a big team for it.

What other advice do I have?

We have decided to use Cloudflare to integrate with AWS, and most of our issues have been resolved. I would recommend the solution. However, it depends on the customer’s data confidentiality. If there are confidential data on the servers, they should not be on the cloud. They can use the cloud solution if the data is normal and not critical. Overall, I rate the product a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
Chief Technology Officer at GyFTR - Vouchagram India Pvt Ltd
Real User
Jan 1, 2023
An easy-to-manage, menu-driven solution with no coding
Pros and Cons
  • "The web solution effectively protects from vulnerabilities and cyber attacks."
  • "The solution should identify why it blocks particular websites."

What is our primary use case?

Our company uses the solution with F5 to secure applications from the injection, the track, and vulnerabilities. 

We use the built-in solution provided by SGO for the web. 

What is most valuable?

The web solution effectively protects from vulnerabilities and cyber attacks. 

The solution is menu driven and operates with no coding.

It is easy to manage and use the solution. 

What needs improvement?

The solution should identify why it blocks particular websites. The solution performs high-level blocks but doesn't provide very much detail. For example, a particular IT is blocked due to a vulnerability but we are not able to identify the reason for the block. Our developers or IT staff need to be able to identify vulnerabilities to fix applications. 

We would like output that tracks how many concurrent requests come through a particular application gateway, the response times for requests, and the latency parameters. 

For how long have I used the solution?

I have been using the solution for two years. 

What do I think about the stability of the solution?

The solution is very stable so I rate stability a ten out of ten. 

How was the initial setup?

The setup is easy so I rate it a nine out of ten. 

What about the implementation team?

We implemented through a third party and it only took a few minutes. 

What's my experience with pricing, setup cost, and licensing?

The pricing is good and manageable. I rate pricing a ten out of ten. 

What other advice do I have?

I recommend the solution for protecting web applications. 

I rate the solution a ten out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2231622 - PeerSpot reviewer
Infrastructure Engineer
Real User
Sep 18, 2023
Useful for protecting against unauthorized access and data breaches but very expensive
Pros and Cons
  • "The most valuable feature is the capability to limit access based on geographical location by restricting specific IP addresses."
  • "I would like to see the addition of more advanced rate-limiting features in the next release. It would be beneficial to extend rate limiting beyond just web servers to the main node level."

What is our primary use case?

We use the AWS platform to implement custom security rules based on our company's SOP. We apply custom rules to protect specific APIs and specific endpoint URLs. This allows us to tailor our security measures to our specific needs and requirements.

How has it helped my organization?

AWS WAF has improved our organization by allowing us to restrict access to our services based on location, which means that only customers from specific locations can access our services. It helps protect against unauthorized access and data breaches.

What is most valuable?

The most valuable feature is the capability to limit access based on geographical location by restricting specific IP addresses.

What needs improvement?

In terms of improvement, AWS WAF works perfectly fine right now. I would like to see the addition of more advanced rate-limiting features in the next release. It would be beneficial to extend rate limiting beyond just web servers to the main node level.

For how long have I used the solution?

I have been using AWS WAF for three years.

What do I think about the stability of the solution?

I would rate the stability of the solution an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of AWS WAF an eight out of ten. All requests, about 100,000 per month, go through the AWS App, ensuring the entire infrastructure is compliant with it. We use it 24/7.

How are customer service and support?

The technical support is slow to respond, and it's a paid service. I wouldn't recommend relying on it.

How would you rate customer service and support?

Negative

How was the initial setup?

The initial setup was simple and I did it myself. I would rate it an eight out of ten in terms of easiness. The deployment was in-house and it took five to ten minutes. It is mostly automated so it did not require much manual assistance. If errors or failures occur, reports are generated and shared with the relevant team for resolution. The deployment process involved specifying endpoint URLs in the web test code to enable automatic integration and we had to wait a little due to cooling time on the web test board. 

What's my experience with pricing, setup cost, and licensing?

The solution is really expensive. I would give it a ten out of ten in terms of costliness. You have to pay additionally for data transfer. 

What other advice do I have?

I would advise someone considering AWS WAF to start with testing on AWS but be cautious of data transfer costs, especially if the project is longer than four months because that is when the additional cost appears. You should assess if it's suitable for your specific use case and make sure to test it before committing to avoid unexpected expenses when moving to the cloud. Overall, I would rate the solution a six out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1399293 - PeerSpot reviewer
Superintendent of Cloud Platforms at a manufacturing company with 1,001-5,000 employees
Real User
Aug 14, 2023
Protects public-facing web applications but pricing is expensive
Pros and Cons
  • "We preferred the product based on its cost. AWS WAF is an out-of-the-box solution and integrates with the AWS services that we use. It's natively integrated with AWS."
  • "We have issues with reporting, troubleshooting, and analytics. AWS WAF needs to bring costs down."

What is our primary use case?

We use the product for the protection of our public-facing web applications. 

What is most valuable?

We preferred the product based on its cost. AWS WAF is an out-of-the-box solution and integrates with the AWS services that we use. It's natively integrated with AWS

What needs improvement?

We have issues with reporting, troubleshooting, and analytics. AWS WAF needs to bring costs down. 

For how long have I used the solution?

I have been working with the solution for 18 months. 

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

We use Amazon enterprise support. It is good but expensive. 

Which solution did I use previously and why did I switch?

We used Cloudflare and Palo Alto before. We chose AWS WAF since it integrates with native services. 

How was the initial setup?

The tool's setup is complex but it is easy after installation. 

What's my experience with pricing, setup cost, and licensing?

I would rate AWS WAF's pricing a seven out of ten. 

What other advice do I have?

I would rate AWS WAF a seven out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Linux admin at Ameex Technologies
MSP
Jul 27, 2023
A stable tool offering good performance and technical support while needing an easy setup phase to get started
Pros and Cons
  • "AWS WAF is a stable solution. The performance of the solution is very good."
  • "AWS WAF should provide better protection to its users, and the security features need to improve."

What is our primary use case?

AWS WAF is a tool we use in my company since we don't currently have a firewall. We can be safer if we have a firewall, and the receive protection side can avoid any vulnerability attacks.

What is most valuable?

AWS WAF is a firewall we use from time to time in my company.

What needs improvement?

I don't think any improvement is needed in AWS WAF.

As technology develops and grows, AWS WAF will have to improve as a product.

AWS WAF should provide better protection to its users, and the security features need to improve.

For how long have I used the solution?

I have been using AWS WAF for six years. There is no specific version of the product since the vendor provides the services for the solution, and my company just uses it.

What do I think about the stability of the solution?

AWS WAF is a stable solution. The performance of the solution is very good.

Stability-wise, I rate the solution a ten out of ten.

What do I think about the scalability of the solution?

My company doesn't rely on AWS WAF's scalability since it's a tool that is totally on the cloud. If the tool goes down by any chance, AWS provides the solution on the steps that need to be taken.

Around 30 employees in my company use AWS WAF.

The product is not extensively used in my company.

My company has no plans to increase the number of users of AWS WAF. If our client wants to increase the number of users, we need to act on the server.

How are customer service and support?

The solution's technical support is good.

How was the initial setup?

The product's setup phase was pretty easy.

Sharing the code files and database configurations are the two steps we follow for deploying the product.

What about the implementation team?

The product's setup phase was carried out in-house.

What's my experience with pricing, setup cost, and licensing?

There are no separate licensing costs we pay for since it is included in the plan we purchase.

What other advice do I have?

AWS WAF has been releasing the product on a test-case basis.

It's always good to take precautionary methods for the production website. If everything goes fine, do work in your staging and UAT, not in the production part. The aforementioned details are the precautionary methods we have to follow.

Overall, I rate the solution a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Prasanth MG - PeerSpot reviewer
Software Engineer at Readyly
Real User
Jun 30, 2023
Allows us to set up security rules and has a good scalability
Pros and Cons
  • "The solution's initial setup process is easy."
  • "The solution could be more reliable."

What is our primary use case?

We use the solution as a firewall to protect the network from malicious requests.

How has it helped my organization?

The solution helps our organization to comply with our security standards.

What is most valuable?

The solution allows us to set up rules for blocking malicious requests. We can configure a pool of such sources and choose what to do (allow/block/count) when a request comes from them.

What needs improvement?

The solution can include provisions to block requests targeted at specific URIs (/.env) which are obviously malicious. Also, sometimes it blocks legitimate requests. We have to keep changing some of our rules in this case. It would be great if they maintained the AWS-managed rule sets properly.

For how long have I used the solution?

We have been using the solution for the last eight months.

What do I think about the stability of the solution?

It is a stable solution. Although sometimes even legitimate requests fail.

I rate its stability an eight out of ten.

What do I think about the scalability of the solution?

It is a scalable solution. We have two users in our organization.

How was the initial setup?

The solution's initial setup process is easy.

What other advice do I have?

I advise others to set their security principles while building the software itself, as WAF is not entirely reliable. I rate it an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Independent Consultant at Unaikui
Real User
May 11, 2023
The solution should improve the pricing, though it is very scalable and stable
Pros and Cons
  • "We can host any DB or application on the solution."
  • "The solution can improve its price."

What is our primary use case?

I use the solution for firewall protection. It can also be used for authentication and authorization.

What is most valuable?

AWS WAF is a great solution. We can host any DB or application on the solution.

What needs improvement?

The solution can improve its price.

For how long have I used the solution?

I have been using the solution for five years.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

The solution is very scalable. Approximately 1000 people in our organization use the solution.

How was the initial setup?

The initial setup is straightforward.

What about the implementation team?

When we had set it up for a large insurance company, the deployment took us over six weeks. We deployed the solution with an in-house team. We need quite a bit of technical staff to maintain the solution.

What other advice do I have?

I use the latest version of the solution. I have used Oracle and Azure too. Overall, I rate the solution a five out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2026
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.