Any cloud-native application is where my clients might be using Check Point WAF (formerly CloudGuard WAF) to secure Layer 7 with low latency. It is one of the best in Layer 7 security.
Director at esupport Solutions Pvt ltd
Security has improved for cloud-native apps and now protects APIs with low latency and minimal tuning
Pros and Cons
- "Ease of deployment and efficiency, particularly for API security, are phenomenal."
- "As a reseller, the most difficult part is the lack of awareness."
What is our primary use case?
What is most valuable?
The biggest advantages of Check Point WAF (formerly CloudGuard WAF) are that it is lightweight and the integration into cloud-native applications is very easy. Check Point WAF (formerly CloudGuard WAF) produces false positives that are minimal. It has a learning process that is unique, adopting an education model approach. Ease of deployment and efficiency, particularly for API security, are phenomenal. The console is key, with Infinity Portal offering access to all kinds of Check Point products and a unique dashboard and reporting system.
Scaling is easy; once deployed, it takes care of everything without causing any concern for improving hardware or configurations. Check Point WAF (formerly CloudGuard WAF) reduces total cost of ownership, being cheaper compared to any other software.
What needs improvement?
As a reseller, the most difficult part is the lack of awareness. Check Point does not provide any kind of awareness programs to the customers, requiring partners to educate customers.
There are indeed some features missing, particularly connected with integration or with artificial intelligence. Check Point WAF (formerly CloudGuard WAF) faces certain issues with dual ISP tagging on entry-level devices since SD-WAN features were added.
For how long have I used the solution?
I have been selling Check Point WAF (formerly CloudGuard WAF) for almost three to four years.
Buyer's Guide
Check Point WAF (formerly CloudGuard WAF)
August 2026
Learn what your peers think about Check Point WAF (formerly CloudGuard WAF). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.
What do I think about the stability of the solution?
Regarding stability, I am not finding any issues; it is very stable.
What do I think about the scalability of the solution?
Check Point WAF (formerly CloudGuard WAF) is very easy to scale. Once deployed, you forget it; it takes care of everything.
How are customer service and support?
My impression of technical support for Check Point WAF (formerly CloudGuard WAF) is that it is adequate. The technical support team is really good.
If I were to rate support from zero to ten points, I would give them a ten, as they are the best.
Which solution did I use previously and why did I switch?
Check Point WAF (formerly CloudGuard WAF) is good; there are no questions asked.
What was our ROI?
In terms of pricing, Check Point WAF (formerly CloudGuard WAF) is not expensive; it is worth the investment. If there is no downtime or bottlenecks while accessing your application from the internet, that itself is the return on investment.
Which other solutions did I evaluate?
I can tell you specific issues or advantages with products such as FortiGate or Check Point perimeter firewall.
What other advice do I have?
From a technical perspective, I do not think Check Point is leading in the web application firewall space. Cloudflare, F5, and Barracuda WAFs are noteworthy. Check Point WAF (formerly CloudGuard WAF) can be configured with no prior training.
When I compare Check Point WAF (formerly CloudGuard WAF) with traditional WAFs, I find its learning curve to be simple.
Check Point has an excellent intelligence engine for zero-day attacks, unmatched by Palo Alto. I would rate this review a ten overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jun 1, 2026
Flag as inappropriateService Delivery Lead (General Manager)–IT Operations at WAISL Limited
Ai-driven cloud security has strengthened threat prevention and improved security posture
Pros and Cons
- "Check Point WAF (formerly CloudGuard WAF) is a SaaS platform that gives unified cloud-native security across my applications, workloads, and network, allowing me to automate security, prevent threats, ensure compliance, and manage my security posture well across all my cloud environments."
- "The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better."
What is our primary use case?
The main purpose is to have network security through machine learning, which can offer threat detection and intelligence for my endpoints, and I am looking for application security.
I am looking for an AI-based solution that can strengthen my cloud-native security, automate security, and better prevent threats.
I am looking for an AI-based solution and unified cloud-native security from the SaaS platform to improve my security posture.
What is most valuable?
Check Point WAF (formerly CloudGuard WAF) is a SaaS platform that gives unified cloud-native security across my applications, workloads, and network, allowing me to automate security, prevent threats, ensure compliance, and manage my security posture well across all my cloud environments.
It conducts security scoring and risk scoring, which helps prioritize my security needs, and the advanced threat detection is also very fine, providing actionable information for my current security threats by collecting and analyzing data through threat actors and IOCs, offering tactical, technical, and operational features.
What needs improvement?
The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better.
This all depends on how the rules are customized and configured, and it can also improve with planning during the initial configuration, including threat intelligence and APIs, so it could enhance how it defends against attacks and prompts injections.
It can find the threat actors behind it, and I find that strategically and technically it is effective, although the AI-related features could improve, especially as global AI capabilities evolve, which are advancing more than what Check Point WAF (formerly CloudGuard WAF) provides compared to competitors.
There are no glitches; I believe improvement could be made primarily in API Gateway and API security, especially by enabling enhanced AI-related features for better fine-tuning.
For how long have I used the solution?
I have experience of two years with the product.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is definitely a highly scalable solution without any doubt.
How are customer service and support?
The customer support is very good.
Which solution did I use previously and why did I switch?
Earlier, we had Microsoft Defender, which we replaced with Check Point WAF (formerly CloudGuard WAF), and we are now ensuring that policy enforcement and threat protection are better.
How was the initial setup?
The deployment and initial setup are really straightforward; they provide enough documentation, videos, and deployment documents that are really helpful to complete it faster.
What was our ROI?
The return on investment is very good as it has increased my security posture and the operational efficiency of my engineers.
What's my experience with pricing, setup cost, and licensing?
It is a little bit expensive, but the pricing model is acceptable, though a reduction would make it more competitive with leaders such as Palo Alto.
Which other solutions did I evaluate?
I purchased from a different source.
What other advice do I have?
The configurations are pretty easy, and it is plug-and-play, which gives me regular updates.
I would assess the solution as positive in this regard.
All the integrations are pretty easy through API connectivity, which I can recommend more, and it also helps with modern AI-based vulnerabilities to conduct token tests and improve detection.
I would rate this review a 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 13, 2026
Flag as inappropriateBuyer's Guide
Check Point WAF (formerly CloudGuard WAF)
August 2026
Learn what your peers think about Check Point WAF (formerly CloudGuard WAF). Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.
Network & Security Engineer at Arrow PC Network Pvt Ltd
AI-driven protection has reduced attack impact and now secures web apps and APIs in real time
Pros and Cons
- "Check Point CloudGuard WAF has really reduced the headache of IT engineers and has helped me in security through machine learning."
- "Check Point CloudGuard WAF can be improved in several ways. We have faced slowness issues in our network after onboarding it on any application."
What is our primary use case?
I use Check Point CloudGuard WAF for web application and API protection. I can provide a scenario where I used Check Point CloudGuard WAF to defend against an SQL injection attack on a web app. It detects query patterns via machine learning and then blocks requests instantly without needing any rule writing.
What is most valuable?
Check Point CloudGuard WAF offers various capabilities including AI-based threat prevention, API security, DDoS protection at multi-layer, L3 and L7 protection, bot protection, behavioral analysis, and fingerprinting.
AI-based threat prevention stands out for me because instead of relying on static signatures that have been added in the cloud, it uses behavioral baselines. For example, if I'm using an application with behavioral application capabilities, it provides me high security using AI-based threat prevention. Behavioral learning mode has been divided into various phases. The first phase is the learning mode where it automatically learns. Whenever I onboard any app, it observes the traffic for a short duration or builds a statistical model for that application, and no manual training is required. In phase two, enforcement mode, any new request is evaluated against known attack patterns via machine learning.
Real-time response is really helpful when onboarding any application with Check Point CloudGuard WAF. When we onboard any application, it creates a statistical model of that application, and according to that, it observes known attack patterns, then blocks them instantly, providing another layer of security.
Check Point CloudGuard WAF has really reduced the headache of IT engineers and has helped me in security through machine learning.
What needs improvement?
Check Point CloudGuard WAF can be improved in several ways. We have faced slowness issues in our network after onboarding it on any application. The cost can be higher than traditional WAF solutions, and its heavy reliance on AI also means we have less manual control. Maximum work is done via AI, so that can be reduced.
The cost can be decreased, and regarding manual controls, I just wanted to say that relying directly on AI is not good for our environment because AI is copying our data.
According to other traditional OEMs, we experience a few issues with pricing. The pricing is high compared to other vendors, and I have already mentioned the high reliance on AI, which can be a concern.
Customer support can be improved because we have to reach out to the distributors for support. That could be directly controlled by the OEM.
For how long have I used the solution?
I have been using Check Point CloudGuard WAF for more than a year.
What do I think about the stability of the solution?
Check Point CloudGuard WAF is really stable.
What do I think about the scalability of the solution?
Its scalability is strongly stable. It allows cloud-native elastic scaling and is delivered via SaaS and a deployment agent.
The performance of Check Point CloudGuard WAF has improved compared to other traditional OEMs, and it is easy to use due to AI and machine learning. Management is also straightforward, but it can be improved for new users by providing specific training.
Which solution did I use previously and why did I switch?
I was not using any solution previously. Check Point CloudGuard WAF is my first solution.
What was our ROI?
It has saved me time.
What's my experience with pricing, setup cost, and licensing?
Pricing is a little bit high compared to other OEMs, and the setup cost was handled by a partner.
Which other solutions did I evaluate?
I have not evaluated any other options.
What other advice do I have?
I want to strongly advise this product to other users. Not because of pricing—while the pricing is a little high, the level of security provided is much more critical. I would rate this product an 8.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Apr 15, 2026
Flag as inappropriateSecurity Consultant at a computer software company with 501-1,000 employees
Unified security has reduced alert fatigue and improved zero-day protection for our applications
Pros and Cons
- "Check Point WAF (formerly CloudGuard WAF) helps my clients reduce total cost of ownership, and the return on investment was really high for Check Point WAF (formerly CloudGuard WAF), and it was the only product with GenAI security features compared to other WAF products."
- "A gap for improvement for Check Point WAF (formerly CloudGuard WAF) is the learning curve, as better training modules could help end customers, and pricing and reporting functionality could also be improved."
What is our primary use case?
The customers I have worked with were primarily using Check Point WAF (formerly CloudGuard WAF) as an application security solution, mostly leveraging Check Point CloudGuard for various purposes such as protecting their application servers from the top 10 OWASP attacks and for Zero-Day protection.
My clients were not working separately with Check Point WAF (formerly CloudGuard WAF); they were receiving a unified platform that included firewall, email security, and endpoint security, so the integration effectively eliminated silos in their environment.
What is most valuable?
Check Point WAF (formerly CloudGuard WAF) was valuable primarily because the data center was in Dubai, making it convenient for customers in the region, and the user interface was really helpful and easy to understand.
Check Point WAF (formerly CloudGuard WAF) helps my clients reduce total cost of ownership, and the return on investment was really high for Check Point WAF (formerly CloudGuard WAF), and it was the only product with GenAI security features compared to other WAF products.
Check Point WAF (formerly CloudGuard WAF) provides benefits such as reduction in alert fatigue with fewer false positives, Zero-Day protection, and the introduction of GenAI LLM features that customers really appreciate.
What needs improvement?
A gap for improvement for Check Point WAF (formerly CloudGuard WAF) is the learning curve, as better training modules could help end customers, and pricing and reporting functionality could also be improved.
For how long have I used the solution?
I have been working with Check Point WAF (formerly CloudGuard WAF) for almost two years.
What do I think about the stability of the solution?
I can rate stability at approximately 8.5.
What do I think about the scalability of the solution?
I can say scalability is a 9.
How are customer service and support?
Technical support is rated at 10.
Which solution did I use previously and why did I switch?
I am currently working with Palo Alto as the product I replaced Check Point WAF (formerly CloudGuard WAF) with. I totally moved to Palo Alto from Check Point WAF (formerly CloudGuard WAF).
How was the initial setup?
The initial setup for Check Point WAF (formerly CloudGuard WAF) is simple; it is not that complex as long as a customer has a basic understanding of how WAF works.
Deployment was really easy for Check Point WAF (formerly CloudGuard WAF); it does not have any complex deployment requirements.
Which other solutions did I evaluate?
Barracuda is the main competitor of Check Point WAF (formerly CloudGuard WAF), along with Fortinet, but Barracuda excels in application security and is doing great in this space.
What other advice do I have?
No product can provide 100% protection, but Check Point WAF (formerly CloudGuard WAF) uses multi-method protection with AI machine learning to detect abnormalities, alongside features like ThreatCloud for real-time analysis of potential zero-day threats. I will highly recommend Check Point WAF (formerly CloudGuard WAF) to other users. I have given this review an overall rating of 8.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: May 28, 2026
Flag as inappropriateNetwork & Security Engineer at Arrow PC Network Pvt.Ltd.
Cloud protection has reduced manual effort and now improves web and API security operations
Pros and Cons
- "Check Point CloudGuard WAF delivers clear efficiency gains over traditional WAFs in three main areas: operations, accuracy, and cost optimization."
- "While Check Point CloudGuard WAF is a strong solution, it could be improved in a few areas such as simplifying and customizing the user interface and reporting database."
What is our primary use case?
Check Point CloudGuard WAF's primary use is protecting web applications and APIs from application layer attacks in the cloud. I also use it to protect public-facing apps.
What is most valuable?
Check Point CloudGuard WAF offers the best features through its dual ML engine with attack-based and context-based capabilities. The dual engine directly reduces the operational load and improves detection quality for my team on a day-to-day basis.
Additionally, it allows for less policy tuning. Check Point CloudGuard WAF has positively impacted my organization by reducing my manual effort. It reduces up to 2x my operational effects, leading to lower false positives.
What needs improvement?
While Check Point CloudGuard WAF is a strong solution, it could be improved in a few areas such as simplifying and customizing the user interface and reporting database. Improving API security depth is also necessary.
For how long have I used the solution?
I have been using Check Point CloudGuard WAF for the last one year.
What do I think about the stability of the solution?
Check Point CloudGuard WAF is stable in my experience.
What do I think about the scalability of the solution?
Check Point CloudGuard WAF is highly scalable and designed for cloud-native environments.
How are customer service and support?
The customer support is really good. I would rate the customer support an eight on a scale of one to ten.
Which solution did I use previously and why did I switch?
Before Check Point CloudGuard WAF, we did not use any WAF solution.
What was our ROI?
I have seen a return on investment as it is a time-saver product.
What other advice do I have?
Check Point CloudGuard WAF delivers clear efficiency gains over traditional WAFs in three main areas: operations, accuracy, and cost optimization. I do utilize Check Point CloudGuard WAF alongside other Check Point products. We use Check Point firewalls, security gateway, and load balancer, and they work together with Check Point CloudGuard WAF in our environment. My advice for others looking into using Check Point CloudGuard WAF is to first validate the use case and plan the deployment architecture. I would rate this product a nine on a scale of one to ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Mar 23, 2026
Flag as inappropriateHas blocked web-based threats and reduced attack success using real-time detection and intelligence
Pros and Cons
- "Check Point CloudGuard WAF has positively impacted my organization by significantly improving both security and operational efficiency, with a noticeable reduction in web-based threats, especially automated attacks and vulnerability exploits, thanks to its real-time prevention and reputation filter that has streamlined my workflow through automatic policy updates and integration smoothly with my CI/CD pipelines, allowing my DevOps teams to deploy security without delays."
- "Check Point CloudGuard WAF is a strong solution, but there are a few areas where it could be improved, particularly the user interface for managing custom rules and exceptions, which could be more intuitive and streamlined to reduce the learning curve for new users, especially when deploying for the first time."
What is our primary use case?
My main use case for Check Point CloudGuard WAF is protecting the public-facing web applications in my company because I need to show different webs to different clients, and I need to protect these web apps.
In addition to protecting public-facing web apps and APIs, I also use Check Point CloudGuard WAF for different purposes, such as providing protection to non-production environments, ensuring that vulnerabilities are caught early during deployment and testing, which helps identify misconfiguration or insecure code before it reaches production.
How has it helped my organization?
Check Point CloudGuard WAF has positively impacted my organization by significantly improving both security and operational efficiency, with a noticeable reduction in web-based threats, especially automated attacks and vulnerability exploits, thanks to its real-time prevention and reputation filter that has streamlined my workflow through automatic policy updates and integration smoothly with my CI/CD pipelines, allowing my DevOps teams to deploy security without delays.
AI-based threat detection and contextual machine learning to block known and zero-day attacks, according to Check Point, have led to a notable decrease in successful web-based attacks.
What is most valuable?
The best features that Check Point CloudGuard WAF offers in my experience include advanced threat detection with blocking OWASP Top 10 threats such as SQL injection, XSS, and CSRF with high accuracy, along with granular access controls such as geo-blocking and IP reputation filter.
The reputation filter has helped me significantly. For example, I was once notified of a spike in traffic targeting one of my login portals, which at first glance looked like normal user activity, but the reputation filter flagged the source IPs as part of a known botnet associated with credential stuffing attacks, leading to those IPs being blocked before they could even reach the authentication layer.
What needs improvement?
Check Point CloudGuard WAF is a strong solution, but there are a few areas where it could be improved, particularly the user interface for managing custom rules and exceptions, which could be more intuitive and streamlined to reduce the learning curve for new users, especially when deploying for the first time.
I think the documentation could be better. People need more intuitive documentation and easier steps for the first deployment.
For how long have I used the solution?
I have been using Check Point CloudGuard WAF for around three years.
What do I think about the stability of the solution?
Check Point CloudGuard WAF is stable in my experience with no downtime or reliability issues.
What do I think about the scalability of the solution?
Check Point CloudGuard WAF is very scalable and has handled growth or increased traffic well.
How are customer service and support?
The customer support for Check Point CloudGuard WAF is great. I have had great response time, and it has been very helpful for me.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
The experience with pricing, setup cost, and licensing for Check Point CloudGuard WAF is straightforward, with the service being available as a fully managed service, and the pricing depending on traffic volume, number of protected applications, and cloud provider. I do not have a problem with this area.
What was our ROI?
I have seen a return on investment, having more time in the department, which is the relevant metric of time saved.
What's my experience with pricing, setup cost, and licensing?
The experience with pricing, setup cost, and licensing for Check Point CloudGuard WAF is straightforward, with the service being available as a fully managed service, and the pricing depending on traffic volume, number of protected applications, and cloud provider. I do not have a problem with this area.
Which other solutions did I evaluate?
Before choosing Check Point CloudGuard WAF, I compared it with Azure WAF, but I had to select Check Point CloudGuard WAF.
I compare Check Point CloudGuard WAF with Azure WAF, noting that I need to centralize the security products, preferring different tools in Check Point Infinity Portal since they are from the same company.
What other advice do I have?
If you are considering using Check Point CloudGuard WAF, my top advice is to take full advantage of its automatic learning and threat intelligence features right from the start. Begin with the detect learning mode to observe traffic patterns and fine-tune policies before switching to full prevention, which helps reduce false positives and ensure a smoother deployment.
I do not utilize Check Point CloudGuard WAF alongside any other Check Point products.
Check Point CloudGuard WAF helps me block specific web-based attacks such as SQL injections or cross-site scripting with threat prevention.
Check Point CloudGuard WAF has helped me reduce my false positive rate to approximately fourteen percent, thanks to its adaptive threat prevention and machine learning capabilities.
The breach reduction capabilities of Check Point CloudGuard WAF are impressive, especially in how it proactively blocks zero-day threats and bot-driven attacks before they reach critical systems. For example, it stopped a credential stuffing attempt on my login portal using the reputation filter and input validation. I would rate this review a nine.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Support Executive at a computer software company with 501-1,000 employees
Has provided real-time protection against web attacks and improved visibility across hybrid environments
Pros and Cons
- "The best feature of Check Point CloudGuard WAF is its advanced threat prevention, which is integrated with Check Point threat cloud intelligence providing real-time protection against web application attacks, including zero-day threats, automatically sourced from the threat cloud, Check Point threat intelligence database, analyzing millions of indicators of compromise daily."
- "The User interface can be improved, especially for 1st time user."
- "The User interface can be improved, especially for 1st time user."
What is our primary use case?
The main use case of Check Point CloudGuard WAF is for application protection.
Check Point CloudGuard WAF provides protection from OWASP threats, and secures web applications from common vulnerabilities, such as SQL injection, cross-site scripting, cross-site request forgery, and remote file inclusions.
What is most valuable?
The best feature of Check Point CloudGuard WAF is advanced threat prevention integrated with Check Point threat cloud intelligence, which provides real-time protection against web application attacks including zero-day threats, automatically receiving updates from the threat cloud and analyzing millions of indicators of compromise daily.
Cloud intelligence means that Check Point CloudGuard continuously collects threat data from global resources such as firewalls and sandboxes, analyzing billions of IPs, URLs, and behaviors using machine learning, distributing updates, security signatures, and threat profiles to CloudGuard WAF in real-time, automatically applying updated protection without manual interventions.
For how long have I used the solution?
We have been using Check Point CloudGuard WAF for the last two years, and this is a very useful product.
What other advice do I have?
I monitor the volume of the type of traffic our web applications receive and understand the types and threats targeting our environment.
Check Point CloudGuard WAF effectively detects or blocks malicious SQL queries in real-time, protecting our web application from exploitation. To block SQL injection in Check Point CloudGuard WAF, I access the CloudGuard WAF console, log into the Check Point CloudGuard WAF management console using administrative credentials, then navigate to the security policies or application security section of the console, where the firewall rules of the protection are configured. In the web security policy setting, I verify that the SQL injection protection is enabled, which is typically a predefined feature within the WAF rule set activated to detect and block SQL injection attacks. Check Point CloudGuard WAF comes with predefined SQL injection attack signatures based on known patterns and payloads commonly used in SQL injection attacks, and I ensure the SQL injection signature set is enabled so that CloudGuard can detect and block common SQL injection techniques.
I find no issues in software testing details with our predefined feature-rich template, providing automated security incident handling with real-time visibility and control across multi-cloud environments.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Solution Engineer at a computer software company with 201-500 employees
Simplifies cloud security with quick integrations and highlights areas for enhanced customization
Pros and Cons
- "The automated policy creation and threat intelligence have helped my team by reducing manual configuration and saving time, and the threat intelligence updates ensure immediate protection against new threats, simplifying daily operations and improving response speed."
- "Check Point CloudGuard WAF could be improved by simplifying the initial setup for a faster deployment, making the dashboard and reporting more customizable, and offering a more accessible pricing model."
What is our primary use case?
My main use case for Check Point CloudGuard WAF is to protect web applications and APIs from OWASP Top 10, and it has helped to secure cloud workload and prevent unauthorized access to data leaks.
I use Check Point CloudGuard WAF to block SQL injection and cross-site scripting attacks, and we protect the API by enforcing strict access, automatically applying a security policy to new applications before deploying in the cloud.
What is most valuable?
The best features Check Point CloudGuard WAF offers in my experience include automated policy upgrade with threat coverage intelligence, flexible deployment, and zero-day protection, which stand out to me the most.
The automated policy creation and threat intelligence have helped my team by reducing manual configuration and saving time, and the threat intelligence updates ensure immediate protection against new threats, simplifying daily operations and improving response speed.
Check Point CloudGuard WAF has positively impacted my organization by strengthening overall application security and data security, and it reduces manual workload for the security team while improving compliance in securing cloud workloads.
It has improved compliance and manual workflows through automated updates and reports, making it easier to meet compliance, with faster audits and readily available security evidence in reports, and it reduces time spent on manual rule creation and log reviews by automating policy enforcement.
What needs improvement?
Check Point CloudGuard WAF could be improved by simplifying the initial setup for a faster deployment, making the dashboard and reporting more customizable, and offering a more accessible pricing model.
For how long have I used the solution?
I have been using Check Point CloudGuard WAF for the past one year.
What do I think about the stability of the solution?
Check Point CloudGuard WAF is definitely stable in my experience.
How are customer service and support?
It has a user-friendly interface that makes monitoring and management easier with smooth integration with other Check Point and third-party security tools, and it provides a clear dashboard for visibility into attack and traffic patterns.
I would rate customer support as eight out of ten.
I chose this rating because sometimes the response will be delayed more than expected.
Customer support is good, but sometimes it takes longer than expected.
How would you rate customer service and support?
Positive
What was our ROI?
I have seen a return on investment from using Check Point CloudGuard WAF, considering both time and money.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing was good.
The experience with pricing, setup cost, and licensing is straightforward without any challenges.
What other advice do I have?
My advice for others looking into using Check Point CloudGuard WAF is to plan deployment with clear policies to maximize protection from the start and take advantage of automated updates and threat intelligence to reduce manual work, ensuring proper integration with your cloud environment.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Key Executive at ITBiz Solutions
Security has improved for critical web services and supports complex protection needs
Pros and Cons
- "Check Point WAF (formerly CloudGuard WAF) is easy to deploy and provides a complete solution."
- "The interface and deployment require qualified skills and a qualified engineer who knows this product very well."
What is our primary use case?
Check Point WAF (formerly CloudGuard WAF) is required by customers who have web resources and assets that are important to them and in production. These resources include internet shops, services, and financial services. Without a web application firewall, the business stops, and customers need to implement this solution. Insurance companies, banks, and similar organizations fall into this category.
What is most valuable?
Check Point WAF (formerly CloudGuard WAF) is easy to deploy and provides a complete solution.
Check Point's approach differs from others because it uses artificial intelligence elements and an AI-based approach. The WAF solution operates as a complex solution with multiple functionalities rather than a simple one.
The solution helps reduce the false positive rate. Productivity shows that only 10 to 25 percent will be false positives.
What needs improvement?
The interface and deployment require qualified skills and a qualified engineer who knows this product very well.
In general, Check Point products load the system somewhat and require more performance and better performance equipment on the customer side.
When compared to solutions specialized only on WAF, such as Imperva or Cloudflare, Check Point WAF (formerly CloudGuard WAF) is a lighter version and does not have as well-performed a load balancer or anti-DDoS option.
For how long have I used the solution?
We started using Check Point WAF (formerly CloudGuard WAF) two years ago.
What do I think about the scalability of the solution?
Check Point WAF (formerly CloudGuard WAF) scores eight to nine points on a ten-point scale for scalability. This scalability is one of the top features of Check Point solutions in general and especially for Check Point WAF (formerly CloudGuard WAF). It is a main approach of the Check Point team.
How are customer service and support?
I cannot be objective in this question because we have our own service team with engineers on our staff. We handle most tickets and cases ourselves.
What about the implementation team?
We operate as a partner company in projects and serve as an integrator for different solutions, including security solutions.
What's my experience with pricing, setup cost, and licensing?
Regarding total cost of ownership, I cannot describe this accurately. Concerning the price for Check Point WAF (formerly CloudGuard WAF) and license costs, the pricing is good, and the approach could be better.
Which other solutions did I evaluate?
Regarding competitors, Cloudflare is the most popular and best-selling solution on the Ukrainian market now, and this trend will continue.
What other advice do I have?
Check Point WAF (formerly CloudGuard WAF) and more Check Point solutions are oriented toward cloud infrastructure, cloud, or hybrid infrastructure. I would give Check Point WAF (formerly CloudGuard WAF) an overall rating of nine points.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: May 26, 2026
Flag as inappropriateProject Manager at a tech vendor with 501-1,000 employees
Cloud security has improved and delivers live threat visibility and reduced attack surface
Pros and Cons
- "Check Point WAF (formerly CloudGuard WAF) is the best option on the market, and it is good for us."
- "In my opinion, there is some room for improvement regarding pricing, which we require, and much of it relates to the license base and support."
What is our primary use case?
I have been using Check Point WAF (formerly CloudGuard WAF) on a public cloud.
What is most valuable?
The features of Check Point WAF (formerly CloudGuard WAF) relate to addressing global attacks that we require. The threat map, which displays information on a live basis, helps us understand the types of points logs, and that is the best part.
I utilize Check Point WAF (formerly CloudGuard WAF) alongside other Check Point products. They integrate with internal systems-level security devices, which we are using to communicate internally. The integration makes the tools work better and is helping us significantly.
Beyond user-level benefits, we are receiving some advantages that are really helping us. Check Point WAF (formerly CloudGuard WAF) did reduce my total cost of ownership for my web application firewall, though not by a substantial amount, but it is acceptable.
What needs improvement?
In my opinion, there is some room for improvement regarding pricing, which we require, and much of it relates to the license base and support.
For how long have I used the solution?
I have been using it for more than two to three years, and I confirm that I am currently running on it.
What do I think about the stability of the solution?
Regarding my experience with the deployment, sometimes we encounter difficulties, but overall it is good, and we achieve our time-based objectives. I would rate the stability as eight to nine.
How are customer service and support?
I rate the technical support from one to ten as eight to nine.
Which solution did I use previously and why did I switch?
I did not work with other WAFs before Check Point WAF (formerly CloudGuard WAF).
How was the initial setup?
The initial setup is simplified, and I confirm that it is good for understanding.
What about the implementation team?
As of now, I have not integrated with third-party solutions because it is not required.
What was our ROI?
The investment regarding return on investment is not yet realized, but we are considering that investment base.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable, and I believe it is acceptable. I am satisfied with the timing.
What other advice do I have?
Check Point WAF (formerly CloudGuard WAF) is the best option on the market, and it is good for us. The potential attack surface level involves asking about vulnerabilities across the networks, which is why we confirm that it is really helping us.
I find Check Point WAF (formerly CloudGuard WAF) to be good, though I cannot say it is popular in my region.
I would recommend Check Point WAF (formerly CloudGuard WAF) to others, but it depends on the environment. I think it is currently suitable for any types of companies, specifically in the database, which we require.
I confirm that I do not require additional features for Check Point WAF (formerly CloudGuard WAF), and it is currently adequate. I rate this product nine out of ten overall.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 21, 2026
Flag as inappropriateBuyer's Guide
Download our free Check Point WAF (formerly CloudGuard WAF) Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Application Security Tools Data Loss Prevention (DLP) Web Application Firewall (WAF) DevSecOpsPopular Comparisons
Prisma Cloud by Palo Alto Networks
Imperva Application Security Platform
Cloudflare Web Application Firewall
CrowdStrike Falcon Cloud Security
PortSwigger Burp Suite Professional
Sonatype Lifecycle
OpenText Core Application Security
Buyer's Guide
Download our free Check Point WAF (formerly CloudGuard WAF) Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- What is the difference between "data protection in transit" vs "data protection at rest"?






















