

Find out in this report how the two Web Application Firewall (WAF) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
Operational efficiency has improved; we no longer have staff consistently monitoring backend servers during deployment or scaling events, as HAProxy's health checks and hitless reloads allow us to push changes with minimal manual intervention.
This resulted in a drastic decrease in costs and, at the same time, the accuracy of the hits coming on HAProxy was almost around 100% or 99.99%.
I estimate seeing a return on investment with HAProxy, as it significantly reduced staff requirements and enhanced scaling capabilities, particularly when transitioning from NGINX, which faced issues.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
Since we are utilizing the open-source edition, community forums, mailing lists, and GitHub have been invaluable, with typically someone having encountered the same problems we faced.
My interactions with HAProxy's customer support were limited, but the feedback from my team indicated satisfactory service.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
We manage an automatic load balancing feature where we add HAProxy servers dynamically behind the application load balancer to handle more traffic.
HAProxy's scalability is excellent; as our traffic expands, it handles load increases effortlessly.
For scalability, HAProxy meets my needs, supporting our initial horizontal scaling and then adapting to vertical scaling in a VMware environment.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
We faced issues with AWS WAF when writing the custom rules.
This reliability serves as a key reason for our choice, providing us with confidence even when faced with heavy traffic.
The hot reload feature of HAProxy also really helped us so that we never had to shut it down to reload it.
We have reduced a lot of servers, replacing them with one or two HAProxy servers which deliver better performance, accuracy, and an almost 100% success rate with requests.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
The level of granularity is not great, and as you cross a certain threshold, the cost goes up by twenty or thirty percent every time.
The configuration syntax is powerful yet can become overwhelming for newcomers; a more beginner-friendly interface or a native GUI without relying on third-party tools would ease the onboarding process.
An easier desktop interface to connect to a remote server and make changes on my PC would be beneficial.
The reloading functionality is effective as it allows soft reloads without interrupting traffic patterns.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Since we use the open-source edition, there are no licensing fees, with the main cost being the infrastructure running on EC2 instances in AWS, which helps maintain low expenses.
Setting up HAProxy didn't cost anything for me.
The pricing remains competitive compared to other vendors.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
The specific outcomes showing how AWS WAF has helped our organization include improving our security posture by reducing the attack surface and reducing malicious attacks.
By moving all SSL termination to the load balancer, I now manage certificates in a single place, and I can also utilize Let's Encrypt with HAProxy's built-in ACME support, making renewal automatic.
HAProxy positively impacted our organization by exceeding scalability expectations, initially projected at 200k requests but ultimately handling over 15 million transactions per second without any issues.
As a production engineer at that time, I definitely wanted to ensure that the system could handle massive connections, especially since we operated an e-commerce platform where we could not lose any customer calls.
| Product | Mindshare (%) |
|---|---|
| AWS WAF | 4.2% |
| HAProxy | 1.9% |
| Other | 93.9% |


| Company Size | Count |
|---|---|
| Small Business | 22 |
| Midsize Enterprise | 12 |
| Large Enterprise | 28 |
| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 15 |
| Large Enterprise | 16 |
AWS WAF provides configurable rules, integration with AWS services, and scalable protection against web threats like SQL injections and DDoS attacks. Its automation and reliable performance are highly valued by users.
AWS WAF is a web application firewall offering significant security features like geo-restriction, custom rules, and IP filtering. Designed for seamless orchestration within AWS environments, it facilitates easy configuration and threat automation. Users benefit from its security policies, enhancing application performance by protecting against threats such as cross-site scripting. Despite its strengths, there is a call for enhanced user interfaces, better documentation, flexible pricing, and improved support. Expanding features like real-time analysis, bot protection, and AI integration can further elevate its utility.
What are the key features of AWS WAF?AWS WAF is extensively used in industries hosting applications on AWS, protecting sensitive data, and monitoring for unauthorized access. Custom and managed rules help cater to infrastructure needs, serving a vital role in maintaining application security across various sectors.
HAProxy delivers reliability, high performance, and efficient load balancing solutions. Its open-source model ensures cost-effectiveness and scalability, ideal for managing extensive infrastructure demands with minimal latency while offering seamless integration with modern platforms.
HAProxy is renowned for its robust performance in load balancing across TCP and HTTP protocols, featuring multiple algorithms such as round-robin. Users appreciate its customizable configuration and seamless SSL termination, which make it an excellent choice for managing complex infrastructures. The platform's open-source nature supports scalability, reducing costs while providing flexible proxy operations. HAProxy efficiently handles high concurrency, enabling smooth traffic management and ensuring stability within diverse systems.
What key features does HAProxy offer?HAProxy is extensively used in load balancing implementations across various sectors. Companies deploy it for managing high traffic, Layer 4 and Layer 7 applications, and SQL databases. It supports microservices architecture, performs SSL offloading, and manages email services like SMTP. As a reverse proxy, HAProxy delivers high availability for systems like Redis, RabbitMQ, and Apache while integrating with Docker and Kubernetes. Its features enhance web application firewall capabilities and traffic routing, making it suitable for industries demanding reliable and efficient network management.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.