

Prisma Cloud by Palo Alto Networks and AWS WAF are both formidable competitors in the cloud security domain. Prisma Cloud seems to have the upper hand due to its comprehensive cloud security suite that offers extensive multi-cloud environment protection.
Features: Prisma Cloud provides a dynamic workload identity creation, application dependency mapping, and automated forensics, making it a comprehensive solution for complex cloud architectures. It offers a sophisticated approach to compliance monitoring across multi-cloud setups. AWS WAF's focus is on web application security, leveraging customizable rules, geo-restriction denials, and integration with other AWS services for a seamless user experience.
Room for Improvement: Prisma Cloud could enhance its user interface for better intuitiveness and improve the integration between its acquired technologies. Pricing models and some security feature depths are other areas to address. AWS WAF would benefit from more advanced AI-driven threat detection features, improved automation, and better documentation to optimize configurations.
Ease of Deployment and Customer Service: Prisma Cloud supports various deployments like public, private, hybrid, and on-premises, which is favorable for diverse IT environments. Its customer service is generally well-received but can vary regionally. AWS WAF thrives in cloud-focused environments with seamless integration into AWS systems. The simplicity of its deployment and robust customer support infrastructure are well-regarded, though more proactive support could enhance the user experience.
Pricing and ROI: Prisma Cloud is often more costly, given its extensive features and structured licensing model, making it fit for larger enterprises. AWS WAF, however, utilizes a pay-as-you-go model, offering cost control and straightforward pricing, appealing to businesses within AWS environments. Both provide significant value with Prisma Cloud offering broad visibility across multiple clouds, and AWS WAF providing economical web application protection.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
It eliminates the need for additional hardware, making it a financially and technically sound investment.
Reputation and data security are the two most important things to a financial institution.
We may have prevented a security breach with remediation of the findings.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
They can respond with technical documentation or pass on the case to the next level because it requires the development of a new feature or changing a feature due to a bug.
Anywhere we raise a tech case, they revert back within an hour.
I would rate them a nine out of ten because whenever there are issues, they are able to resolve them within the timelines and SLAs.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
Scalability-wise, I rate the solution a nine out of ten.
We haven't had any issues scaling the solution.
There aren't any limits to Prisma Cloud's scalability.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
We faced issues with AWS WAF when writing the custom rules.
I would rate it a ten out of ten for stability.
Most of the time, when the client requires data, it is not available.
The cloud environment is dynamic, so the tool must be dynamic.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF.
Prisma Cloud is an excellent tool.
We could have deployed the runtime monitoring with Prisma Cloud by Palo Alto Networks, but within our organization at our company, it was very difficult to find who would be the owner for the alerts.
Even though documentation was available, it took a while for a new person to understand what integration meant, what will be achieved after the integration, or how the integration needed to be done on the Azure or AWS side.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
The cost was not on the higher side.
If you are using a single tool like Prisma Cloud, with a single license, you can monitor all environments, such as Google Cloud, Azure, AWS, and Oracle Cloud.
It is not a cheap product.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
The cloud-native nature of AWS is crucial since most of our workload is in AWS, making AWS WAF native to Amazon Web Services.
There is a wide range of integrations, and the compatibility with various cloud providers is very useful.
It provides a single pane of glass.
If I want to check how many of my S3s have encryption, I can write a Lambda function in Prisma Cloud and get that report.
| Product | Market Share (%) |
|---|---|
| AWS WAF | 5.8% |
| Prisma Cloud by Palo Alto Networks | 1.7% |
| Other | 92.5% |

| Company Size | Count |
|---|---|
| Small Business | 22 |
| Midsize Enterprise | 12 |
| Large Enterprise | 26 |
| Company Size | Count |
|---|---|
| Small Business | 36 |
| Midsize Enterprise | 22 |
| Large Enterprise | 56 |
AWS Web Application Firewall (WAF) is a firewall security system that monitors incoming and outgoing traffic for applications and websites based on your pre-defined web security rules. AWS WAF defends applications and websites from common Web attacks that could otherwise damage application performance and availability and compromise security.
You can create rules in AWS WAF that can include blocking specific HTTP headers, IP addresses, and URI strings. These rules prevent common web exploits, such as SQL injection or cross-site scripting. Once defined, new rules are deployed within seconds, and can easily be tracked so you can monitor their effectiveness via real-time insights. These saved metrics include URIs, IP addresses, and geo locations for each request.
AWS WAF Features
Some of the solution's top features include:
Reviews from Real Users
AWS WAF stands out among its competitors for a number of reasons. Two major ones are its user-friendly interface and its integration capabilities.
Kavin K., a security analyst at M2P Fintech, writes, “I believe the most impressive features are integration and ease of use. The best part of AWS WAF is the cloud-native WAF integration. There aren't any hidden deployments or hidden infrastructure which we have to maintain to have AWS WAF. AWS maintains everything; all we have to do is click the button, and WAF will be activated. Any packet coming through the internet will be filtered through.”
Prisma Cloud by Palo Alto Networks provides comprehensive cloud-native security solutions. It covers dynamic workload identity, automated forensics, and multi-cloud protection, ensuring robust security across diverse cloud platforms.
Prisma Cloud delivers advanced capabilities for managing cloud security across AWS, Azure, and GCP platforms. It offers dynamic workload identity creation, real-time monitoring, and seamless integration into CI/CD pipelines. With automation, centralized dashboards, and enhanced visibility, users effectively manage security misconfigurations and vulnerabilities. While optimizing cloud environments through runtime protection and compliance, Prisma Cloud faces challenges with its navigation, pricing, and limited automation capabilities. Users seek improvements in API security, role-based access controls, and documentation quality, emphasizing the need for enhanced customization and reporting features.
What are the important features of Prisma Cloud?
What benefits or ROI should users consider in reviews?
Industries like finance and telecom rely on Prisma Cloud for managing cloud security posture and container security. Teams utilize its capabilities across hybrid and multi-cloud settings to ensure compliance and robust threat protection. Features like misconfiguration detection and runtime monitoring are critical in promoting security objectives in these sectors.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.