We are using AWS WAF for business purposes for clients. We host our client's platforms on AWS WAF.
IT Auditor & Compliance Officer at a tech vendor with 51-200 employees
Well integrated, suitable for all sized businesses, but serverless needs improvement
Pros and Cons
- "AWS WAF has a lot of integrated features and services. For example, there are security services that can be integrated very well for our customers."
- "The serverless product from AWS WAF could be improved. For example, they have only one serverless series, Lambda, but they should extend and improve it. Additionally, the firewall rules are not very easy to configure."
What is our primary use case?
What is most valuable?
AWS WAF has a lot of integrated features and services. For example, there are security services that can be integrated very well for our customers.
What needs improvement?
The serverless product from AWS WAF could be improved. For example, they have only one serverless series, Lambda, but they should extend and improve it. Additionally, the firewall rules are not very easy to configure.
For how long have I used the solution?
I have used AWS WAF for approximately five years.
Buyer's Guide
AWS WAF
September 2025

Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
What do I think about the stability of the solution?
I have found AWS WAF to be stable.
What do I think about the scalability of the solution?
The scalability of AWS WAF is very good.
The solution can be used in small to large-sized businesses.
How are customer service and support?
The customer service has been fine, we had no issues with them. We have been satisfied.
How was the initial setup?
The setup of AWS WAF is very easy.
What's my experience with pricing, setup cost, and licensing?
The price of AWS WAF is reasonable, it is not expensive and it is not cheap.
What other advice do I have?
I would recommend this solution to others.
I rate AWS WAF a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner

Cloud architect at a tech vendor with 1-10 employees
Good integration with AWS services, and no installation is required
Pros and Cons
- "This is not a product that you need to install. You just use it."
- "I would like to see it more tightly integrated with other AWS services."
What is our primary use case?
We use this product for our web application firewall. It is used for production services.
I am not a direct customer but I have installed it for one of my clients.
What is most valuable?
The most valuable feature is that it is integrated with other AWS services.
What needs improvement?
I would like to see it more tightly integrated with other AWS services.
For how long have I used the solution?
I have been working intermittently with AWS WAF over the past two years.
What do I think about the scalability of the solution?
AWS WAF is extremely scalable.
At this point, we don't have any plans to increase our usage of it.
Which solution did I use previously and why did I switch?
Prior to AWS WAF, I was using a Cisco web application firewall. However, when I started using AWS, I switched.
How was the initial setup?
This is not a product that you need to install. You just use it.
The only people that need to work with it are those who configure it.
What's my experience with pricing, setup cost, and licensing?
You need an additional AWS subscription for this product if you are buying a managed tool.
What other advice do I have?
Overall, this is a good product and I recommend it. My advice for anybody who is just getting started with it is to follow the instructions.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
AWS WAF
September 2025

Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
Principal Cloud Architect at a tech services company with 51-200 employees
Beneficial cloud service, flexible on-demand features, but requires better security
Pros and Cons
- "The most valuable features of AWS WAF are its cloud-native and on-demand."
- "The solution could improve by having better rules, they are very basic at the moment. There are more attacks coming and we have to use third-party solutions, such as FIA. The features are not sufficient to prevent all the attacks, such as DDoS. Overall the solution should be more secure."
What is our primary use case?
We use AWS WAF to prevent cyberattacks, such as SQL Injection attacks and cross-site scripting attacks. The end users' traffic has more threats and the web application gives good support.
What is most valuable?
The most valuable features of AWS WAF are its cloud-native and on-demand.
Any customer can leverage AWS WAF immediately, it has a basic set of rules that are available.
What needs improvement?
The solution could improve by having better rules, they are very basic at the moment. There are more attacks coming and we have to use third-party solutions, such as FIA. The features are not sufficient to prevent all the attacks, such as DDoS. Overall the solution should be more secure.
For how long have I used the solution?
I have been using AWS WAF for approximately four years.
What do I think about the stability of the solution?
This is a very stable solution.
What do I think about the scalability of the solution?
AWS WAF is scalable.
We have approximately five customers using this solution.
How are customer service and support?
The technical support is very good. They are responsive and knowledgeable, they have always come back with a resolution or a workaround to help us.
How was the initial setup?
The initial setup took approximately 15 mins, it is easy.
What about the implementation team?
We have a team that does the support for the solution.
What's my experience with pricing, setup cost, and licensing?
AWS WAF is pay-as-you-go, I only pay for what I'm using. There is no subscription or any payment upfront, I can terminate use at any time. Which is an advantage.
What other advice do I have?
The first version of AWS WAF was not mature but the second version is very mature.
I would recommend this solution to others because instead of choosing a third-party solution which will take time, and you will have to be in negotiations. It is good to start with AWS WAF for their minimal primary security firewall to save their workload. AWS WAF is available on-demand from day one.
I rate AWS WAF a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Azure Front Door
Microsoft Azure Application Gateway
F5 Advanced WAF
Fortinet FortiWeb
NetScaler
Cloudflare Web Application Firewall
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
Fastly
NGINX App Protect
Barracuda Web Application Firewall
F5 Distributed Cloud Services
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What are the limitations of AWS WAF vs alternative WAFs?
- Can you share your experience on migration from Akamai Kona Site to Amazon CloudFront and AWS WAF?
- How does AWS WAF compare to Microsoft Azure Application Gateway?
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?