We are an AWS service provider and we use the solution for the cloud and to provide service to other users.
CEO at a tech consulting company with 11-50 employees
Good support, extremely stable, and scalable
Pros and Cons
- "The stability of AWS WAF is valuable."
- "The cost management has room for improvement."
What is our primary use case?
What is most valuable?
The stability of AWS WAF is valuable.
What needs improvement?
The cost management has room for improvement.
For how long have I used the solution?
I have been using the solution for eight years.
Buyer's Guide
AWS WAF
January 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
What do I think about the stability of the solution?
I give the stability a ten out of ten.
What do I think about the scalability of the solution?
I give the scalability a nine out of ten.
How are customer service and support?
The technical support is helpful.
What's my experience with pricing, setup cost, and licensing?
The price is average.
What other advice do I have?
I give the solution a ten out of ten.
The solution is a public cloud platform and we have millions of users.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Regional Security Team Lead at a computer software company with 1,001-5,000 employees
Stable web application firewall used to protect against common vulnerabilities with a powerful CDN component
Pros and Cons
- "The simple configuration and the scalability have been most valuable. We are able to scale across all of our different AWS instances."
- "This solution could be improved if the configuration steps were more specific to WAF, compared to other cloud services."
What is our primary use case?
We use this solution to protect our web applications against common vulnerabilities. The CDN component is also quite powerful. We use this solution alongside Azure WAF.
What is most valuable?
The simple configuration and the scalability have been most valuable. We are able to scale across all of our different AWS instances.
What needs improvement?
This solution could be improved if the configuration steps were more specific to WAF, compared to other cloud services.
For how long have I used the solution?
I have been using this solution for two years.
What do I think about the stability of the solution?
This is a stable solution. We rely on AWS's other cloud services and we've never experienced any stability issues.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
Our support experience has been quite good.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
The main reason we switched from using CloudFlare to AWS is to have a native offering because all of our cloud solutions are on AWS. This made it simpler compared to using a third party and easier to reroute traffic.
How was the initial setup?
It depends on your AWS configuration, but what we've experienced is that the rule policy configuration is really straightforward. It took a couple of weeks.
What about the implementation team?
We had in-house expertise.
What's my experience with pricing, setup cost, and licensing?
We have a medium amount of traffic per month and the cost is in the hundreds rather than in the thousands. I don't know the exact number.
What other advice do I have?
I would advise others to ensure they understand what can be done internally and then what you need expertise for externally. If you have the expertise internally, it can be easily configured. Keep the SIEM configuration as simple as possible, rather than trying to modify and configure too many things.
I would rate this solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
AWS WAF
January 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Cloud architect at a tech vendor with 1-10 employees
Good integration with AWS services, and no installation is required
Pros and Cons
- "This is not a product that you need to install. You just use it."
- "I would like to see it more tightly integrated with other AWS services."
What is our primary use case?
We use this product for our web application firewall. It is used for production services.
I am not a direct customer but I have installed it for one of my clients.
What is most valuable?
The most valuable feature is that it is integrated with other AWS services.
What needs improvement?
I would like to see it more tightly integrated with other AWS services.
For how long have I used the solution?
I have been working intermittently with AWS WAF over the past two years.
What do I think about the scalability of the solution?
AWS WAF is extremely scalable.
At this point, we don't have any plans to increase our usage of it.
Which solution did I use previously and why did I switch?
Prior to AWS WAF, I was using a Cisco web application firewall. However, when I started using AWS, I switched.
How was the initial setup?
This is not a product that you need to install. You just use it.
The only people that need to work with it are those who configure it.
What's my experience with pricing, setup cost, and licensing?
You need an additional AWS subscription for this product if you are buying a managed tool.
What other advice do I have?
Overall, this is a good product and I recommend it. My advice for anybody who is just getting started with it is to follow the instructions.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Principal Cloud Architect at a tech services company with 51-200 employees
Beneficial cloud service, flexible on-demand features, but requires better security
Pros and Cons
- "The most valuable features of AWS WAF are its cloud-native and on-demand."
- "The solution could improve by having better rules, they are very basic at the moment. There are more attacks coming and we have to use third-party solutions, such as FIA. The features are not sufficient to prevent all the attacks, such as DDoS. Overall the solution should be more secure."
What is our primary use case?
We use AWS WAF to prevent cyberattacks, such as SQL Injection attacks and cross-site scripting attacks. The end users' traffic has more threats and the web application gives good support.
What is most valuable?
The most valuable features of AWS WAF are its cloud-native and on-demand.
Any customer can leverage AWS WAF immediately, it has a basic set of rules that are available.
What needs improvement?
The solution could improve by having better rules, they are very basic at the moment. There are more attacks coming and we have to use third-party solutions, such as FIA. The features are not sufficient to prevent all the attacks, such as DDoS. Overall the solution should be more secure.
For how long have I used the solution?
I have been using AWS WAF for approximately four years.
What do I think about the stability of the solution?
This is a very stable solution.
What do I think about the scalability of the solution?
AWS WAF is scalable.
We have approximately five customers using this solution.
How are customer service and support?
The technical support is very good. They are responsive and knowledgeable, they have always come back with a resolution or a workaround to help us.
How was the initial setup?
The initial setup took approximately 15 mins, it is easy.
What about the implementation team?
We have a team that does the support for the solution.
What's my experience with pricing, setup cost, and licensing?
AWS WAF is pay-as-you-go, I only pay for what I'm using. There is no subscription or any payment upfront, I can terminate use at any time. Which is an advantage.
What other advice do I have?
The first version of AWS WAF was not mature but the second version is very mature.
I would recommend this solution to others because instead of choosing a third-party solution which will take time, and you will have to be in negotiations. It is good to start with AWS WAF for their minimal primary security firewall to save their workload. AWS WAF is available on-demand from day one.
I rate AWS WAF a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Jefe subdepartamento Operaciones at a government with 10,001+ employees
Reasonably priced, stable, and offers excellent performance
Pros and Cons
- "Their technical support has been quite good."
- "We haven't faced any problems with the solution."
What is our primary use case?
I primarily use the solution as a gateway service and a transaction portal.
What is most valuable?
We haven't had any issues with the solution so far.
The pricing of the product is very good. They make it very reasonable and it's very easy to afford.
Their technical support has been quite good.
The performance is excellent. It's reliable.
We've found the solution to be quite stable.
What needs improvement?
We haven't faced any problems with the solution. I can't speak to any missing features. Every aspect of it has been quite good.
For how long have I used the solution?
I've been using the solution for a while.
What do I think about the stability of the solution?
The stability has been very good. We've enjoyed a very reliable performance. There are no bugs or glitches. It doesn't crash or freeze. It's been good.
How are customer service and technical support?
Technical support has been quite good. We've found them helpful and responsive. We are quite satisfied with the level of support that is provided to us.
What's my experience with pricing, setup cost, and licensing?
The solution is very reasonably priced.
What other advice do I have?
I'm just a customer and an end-user. I don't have a business relationship or partnership with AWS.
I have pretty good experience in AWS. I have a certificate in AWS.
I'd rate the solution at a ten out of ten. We've been extremely satisfied with the solution.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
AWS Security Specialist at a tech services company with 501-1,000 employees
Easy to scale, flexible, quite efficient, and the geo-restriction capabilities are helpful
Pros and Cons
- "The most valuable features are the geo-restriction denials and the web ACL."
- "On the UI side, I would like it if they could bring back the geolocation view on the corner."
What is our primary use case?
We use this solution for online web applications.
What is most valuable?
The most valuable features are the geo-restriction denials and the web ACL.
I enjoy using it because it is very easy.
Also, it's quite efficient.
What needs improvement?
The service itself is fine. On the UI side, I would like it if they could bring back the conditions view which had geo match, IP sets and etc. When using WAF classic you could see this option on the left side of the console. Currently IP sets and regex strings is there but geo match does not seem to be included, not sure if geo matching is still supported.
For how long have I used the solution?
I have been using AWS WAF for almost three years.
We are using the newest version of AWS WAF, which is Version 2.
What do I think about the stability of the solution?
It's a stable solution. I have not experienced any issues.
What do I think about the scalability of the solution?
There are approximately 1,000 people who are using this solution on a daily basis.
It is easy to scale. Just ensure that you cover the relevant resources within it. You can cover multiple resources such as CDN or use them in your AOD.
It's quite scalable.
How are customer service and technical support?
I have not contacted technical support.
Which solution did I use previously and why did I switch?
I have always used AWS. It's been the focus for the last three years.
How was the initial setup?
The initial setup was simple.
It took less than an hour to deploy.
What about the implementation team?
The implementation was completed internally.
What's my experience with pricing, setup cost, and licensing?
It's quite affordable. It's in the middle.
Everything is included with the usage that you take up when you implement the service.
What other advice do I have?
The product does not require any maintenance. You need to ensure how you consider your rules. You have to make sure that all of your considerations for your protection are done really well. Do regular updates to improve on the different threats and intrusion.
I would recommend the product because it is very flexible and you are able to use it with multiple services within AWS.
I would rate AWS WAF a solid ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Physical Designer at a manufacturing company with 1,001-5,000 employees
Does what it is supposed to do, probably not in the best way and not in the best UI
Pros and Cons
- "The access instruction feature is the most valuable. This is what we use the most."
- "It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful. It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one. Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right."
What is our primary use case?
The regular use case is basically for blocking or giving access to different vendors to different domains. We also use it for managing and identifying the attacks and new rules that we should implement for our public domains to tune up the application firewall or tool, whatever makes more sense for us.
We're using it through the web console and API. We're just using the managed service.
How has it helped my organization?
Our organization is launching a lot of betas. We are creating a lot of new different systems for different customers. AWS WAF helps us a lot to make sure that the right customer gets the right access to the system.
What is most valuable?
The access instruction feature is the most valuable. This is what we use the most.
What needs improvement?
It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful.
It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one.
Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right.
For how long have I used the solution?
I have been using AWS WAF for about six months.
What do I think about the stability of the solution?
Stability-wise, it works as expected.
What do I think about the scalability of the solution?
I definitely see places where it can be more designed to scale. In addition to amazon resources, there is some stuff from other vendors that we wanted to protect. WAF was not a solution for us because we don't have a way to integrate with those things. That was the biggest challenge that we faced. In terms of the number of users, our end users could be in the thousands.
How are customer service and technical support?
It is okay.
How was the initial setup?
It was okay. We went for the cloud formation, and our deployments happen probably every week.
What about the implementation team?
Everything is managed through cloud formation. After implementation, three or four hours a week are required for maintenance.
What's my experience with pricing, setup cost, and licensing?
We are kind of doing a POC comparison to see what works best. Pricing-wise, AWS is one of the most attractive ones. It is fairly cheap, and we like the pricing part. We're trying to see what makes more sense operation-wise, license-wise, and pricing-wise.
What other advice do I have?
I won't recommend it at the moment because I don't have a full picture to recommend it or say that it is bad or good. I'll probably just keep testing and go with it for probably another six months or a year, and then I can probably recommend it or not.
Other vendors are also providing solutions for D-DOS protection and WAF. It would be nice to see something outside the box for AWS WAF to make it compete with other vendors.
I would rate AWS WAF a seven out of ten. It does what it is supposed to do, probably not in the best way and not in the best UI, but it works. We like the pricing part, but management is the thing that we don't love the most. If things keep improving, we're definitely going to scale with AWS WAF.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
President at a tech services company with 1-10 employees
It is a scalable, stable solution but needs simpler setup and pricing schemes.
Pros and Cons
- "Its best feature is that it is on the cloud and does not require local hardware resources."
- "The pricing model is complicated."
- "The setup is complicated."
What is our primary use case?
My whole business is cloud cost management. What I do is help people manage expenses. That encompasses everything from cleaning up software as a service subscriptions to optimizing AWS. My use cases for AWS WAF have to do with cloud research only.
What is most valuable?
The best part about it is that it is a cloud solution.
What needs improvement?
The complexity of deploying turnkey solutions could be simplified.
They actually have too many different things that you can tinker with and too many different ways to do the same thing. It may be helpful if the product were to be more directed and if it used best practices with technical and non-technical users in mind.
For how long have I used the solution?
We have been using WAF (Web Application Firewall) for six months.
What do I think about the stability of the solution?
WAF is very stable.
What do I think about the scalability of the solution?
I believe WAF is very scalable.
We have only two staff in our organization who are using AWS WAF.
How are customer service and technical support?
Technical support is more-or-less fair. That is where most technical support falls these days.
How was the initial setup?
The initial setup is really sorta complex. That is something which could probably be made easier.
What's my experience with pricing, setup cost, and licensing?
The licensing costs are variable. For me, it is under a hundred dollars a month.
The range of your costs with Amazon Web Services is going to be different depending on a lot of factors. It can go as low as actually being free all the way up to millions of dollars. It depends on the organization and how the service is used.
What other advice do I have?
On a scale of one to ten where one is the worst and ten is the best, I would rate this product as a seven-out-of-ten. A change in the pricing structure that favors the client and simplification is something they would have to do to improve to make that score closer to a ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Fortinet FortiWeb
Azure Front Door
Microsoft Azure Application Gateway
F5 Advanced WAF
NetScaler
Cloudflare Web Application Firewall
Akamai App and API Protector
F5 Distributed Cloud Services
Azure Web Application Firewall
Radware Alteon
Fastly
NGINX App Protect
Check Point CloudGuard WAF
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the limitations of AWS WAF vs alternative WAFs?
- Can you share your experience on migration from Akamai Kona Site to Amazon CloudFront and AWS WAF?
- How does AWS WAF compare to Microsoft Azure Application Gateway?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?













