

AWS WAF and Radware Cloud WAF Service compete in the web application firewall category. AWS WAF has the upper hand in cloud-native integration, while Radware excels in threat protection.
Features: AWS WAF offers scalability and integration with AWS services, flexibility in WAF rules management, and cloud-native integration. Radware Cloud WAF Service provides robust threat protection, API Discovery, and a CDN feature, offering comprehensive security measures.
Room for Improvement: AWS WAF users suggest enhancements in rule complexity automation, better support and documentation, and cost optimization. Radware could improve tool integration, streamline automated analytics, and enhance support speed and reporting simplification.
Ease of Deployment and Customer Service: AWS WAF benefits from simplicity in deployment and cloud compatibility, though customer service feedback varies. Radware's deployment is straightforward but faces integration challenges; their support is responsive but requires improvement in complex setups.
Pricing and ROI: AWS WAF pricing follows a flexible pay-as-you-go model, becoming costly with increased usage. Radware offers modular pricing, with bundled services adding value. Both products demonstrate positive ROI through security breach prevention, with AWS focusing on integration and Radware on threat protection.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
I wouldn't be able to give a number, but Radware Cloud WAF does save time for our staff due to the automation and excellent detection, which is invaluable.
With our on-prem solution, we spent a lot of time on maintenance tasks, OS updates, and ensuring appliances ran smoothly, but with Cloud WAF, all that is managed by the cloud team, allowing us to focus on alert analysis.
We get major insights from the analytics rules and dashboards, allowing us to pinpoint main issues.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
On a scale from one to ten, I would rate the technical support that Radware provides for Cloud WAF Service a perfect ten.
I would give the Radware technical support a ten out of ten. They are definitely outstanding.
The support provided by Radware's Emergency Response Team is excellent.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
The scalability of Radware Cloud WAF Service rates as a perfect ten out of ten, as we haven't encountered any scaling issues.
The scalability of the Radware Cloud WAF Service deserves a full ten, as it is definitely scalable.
In terms of scalability, it's also a 10 out of 10 because we are using Radware Cloud WAF Service for more than 60,000 employees in our organization, and it works perfectly fine.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
We faced issues with AWS WAF when writing the custom rules.
I have never encountered downtime, maintenance-related issues, or latency.
The stability of Radware Cloud WAF Service is excellent, and I would rate it as a ten.
The stability of Radware Cloud WAF Service is perfect; I would rate it a ten out of ten.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF.
It would be beneficial if we could perform POST requests and integrate our applications more effectively.
The documentation is not up to par, as while the platform's system is robust, the documentation, particularly for API integration, could be more developer-friendly with real-world use cases.
Improving dashboard capabilities to provide this information clearly for management is crucial.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Pricing could be more competitive, especially for smaller customers.
I find Radware Cloud WAF to be a quite expensive product compared to others.
The pricing is not cheap; it is expensive, but it is effective.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
The cloud-native nature of AWS is crucial since most of our workload is in AWS, making AWS WAF native to Amazon Web Services.
The most important aspect of Radware Cloud WAF is that it is over the cloud, offering a comprehensive solution that includes WAF, API protection, bots, and Layer 7 DDoS.
It has features such as API security that protect against advanced attacks, including business logic attacks.
The automated analytics for looking at events in Radware Cloud WAF Service are working for us; the automatic event correlation is very beneficial to analyze how the alerts and events occur and visualize the patterns of network traffic and other traffic going in and out from the application via Radware Cloud WAF Service.
| Product | Market Share (%) |
|---|---|
| AWS WAF | 5.8% |
| Radware Cloud WAF Service | 1.7% |
| Other | 92.5% |

| Company Size | Count |
|---|---|
| Small Business | 22 |
| Midsize Enterprise | 12 |
| Large Enterprise | 26 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 10 |
| Large Enterprise | 37 |
AWS Web Application Firewall (WAF) is a firewall security system that monitors incoming and outgoing traffic for applications and websites based on your pre-defined web security rules. AWS WAF defends applications and websites from common Web attacks that could otherwise damage application performance and availability and compromise security.
You can create rules in AWS WAF that can include blocking specific HTTP headers, IP addresses, and URI strings. These rules prevent common web exploits, such as SQL injection or cross-site scripting. Once defined, new rules are deployed within seconds, and can easily be tracked so you can monitor their effectiveness via real-time insights. These saved metrics include URIs, IP addresses, and geo locations for each request.
AWS WAF Features
Some of the solution's top features include:
Reviews from Real Users
AWS WAF stands out among its competitors for a number of reasons. Two major ones are its user-friendly interface and its integration capabilities.
Kavin K., a security analyst at M2P Fintech, writes, “I believe the most impressive features are integration and ease of use. The best part of AWS WAF is the cloud-native WAF integration. There aren't any hidden deployments or hidden infrastructure which we have to maintain to have AWS WAF. AWS maintains everything; all we have to do is click the button, and WAF will be activated. Any packet coming through the internet will be filtered through.”
Radware’s Cloud WAF provides enterprise-grade, continuously adaptive web application security protection. Based on Radware’s ICSA Labs certified, market-leading web application firewall, it provides full coverage of OWASP Top-10 threats and zero-day attacks, while implementing both negative and positive web application security models to automatically adapt protections to evolving threats and protected assets.
Radware’s Cloud WAF offers full web security protection including OWASP Top-10 coverage, advanced attack protection and 0-day attack protection by implementing both negative and positive web application security models. It provides organizations “frictionless” application protection by automatically detecting and protecting new web applications as they are added to the network through automatic policy generation technology.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.