AWS WAF provides configurable rules, integration with AWS services, and scalable protection against web threats like SQL injections and DDoS attacks. Its automation and reliable performance are highly valued by users.


| Product | Mindshare (%) |
|---|---|
| AWS WAF | 4.8% |
| Imperva Application Security Platform | 7.6% |
| Fortinet FortiWeb | 6.5% |
| Other | 81.1% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Web Application Firewall (WAF) | Apr 30, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Apr 30, 2026 | Download |
| Comparison | AWS WAF vs Fortinet FortiWeb | Apr 30, 2026 | Download |
| Comparison | AWS WAF vs F5 Advanced WAF | Apr 30, 2026 | Download |
| Comparison | AWS WAF vs Imperva Application Security Platform | Apr 30, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| Prisma Cloud by Palo Alto Networks | 4.2 | 2.0% | 98% | 114 interviewsAdd to research |
| Imperva Application Security Platform | 4.3 | 7.6% | 95% | 143 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 22 |
| Midsize Enterprise | 11 |
| Large Enterprise | 20 |
| Company Size | Count |
|---|---|
| Small Business | 217 |
| Midsize Enterprise | 98 |
| Large Enterprise | 458 |
AWS WAF is a web application firewall offering significant security features like geo-restriction, custom rules, and IP filtering. Designed for seamless orchestration within AWS environments, it facilitates easy configuration and threat automation. Users benefit from its security policies, enhancing application performance by protecting against threats such as cross-site scripting. Despite its strengths, there is a call for enhanced user interfaces, better documentation, flexible pricing, and improved support. Expanding features like real-time analysis, bot protection, and AI integration can further elevate its utility.
What are the key features of AWS WAF?AWS WAF is extensively used in industries hosting applications on AWS, protecting sensitive data, and monitoring for unauthorized access. Custom and managed rules help cater to infrastructure needs, serving a vital role in maintaining application security across various sectors.
AWS WAF was previously known as AWS Web Application Firewall.
eVitamins, 9Splay, Senao International
| Author info | Rating | Review Summary |
|---|---|---|
| Infrastructure Lead at Danat Fz LLC | 4.0 | I've used AWS WAF for four years to block unauthorized access, finding custom regex rules valuable, though monitoring and bot detection need improvement; setup is manageable, but DDoS protection requires an additional solution. |
| DevOps Engineer at a tech vendor with 1,001-5,000 employees | 4.5 | I’ve used AWS WAF for over five years to block malicious traffic and IPs, finding it scalable, stable, and cost-effective, though the dashboard needs improvement. Its automation and managed rules significantly enhance my application’s security and performance. |
| Security Engineer at a computer software company with 1,001-5,000 employees | 4.0 | We use AWS WAF on our websites as part of our data protection strategy due to its seamless integration and ease within the AWS platform. Despite improvements needed in signature sets and limited stateful capabilities, it effectively enhances security and saves resources. |
| AWS DevOps SRE/Infrastructure Engineer at Capgemini | 4.0 | I manage infrastructure on AWS using services like KMS, EBS, and WAF version two. AWS WAF's automation in blocking security threats is valuable, though integrating with services like Kafka could be improved. While it can be costly, its security benefits are worth it. |
| Security Analyst at M2P Fintech | 3.5 | I use AWS WAF for its cloud-native functionality, ease of rule management, and better control within AWS infrastructure, though its dashboarding and metric functionalities need improvement. Previously, we switched from Imperva to AWS for cost optimization. |
| OCI/AWS Consultant at a government with 11-50 employees | 2.0 | I use AWS WAF to safeguard sensitive data by filtering HTTP traffic for web applications. While Oracle Cloud Infrastructure offered cost benefits, AWS was chosen for compliance. I appreciate its flexibility but see room for improvement in other AWS services. |
| Director of Security Architecture at a healthcare company with 10,001+ employees | 3.0 | I use AWS WAF to protect web applications, appreciating its integration and ease of deployment within AWS. However, I'm seeking alternatives due to concerns about dependency on AWS and the need for improved usability and functionality in multi-cloud environments. |
| Associate Vice President - Engineering at Fedo.ai | 4.5 | I use AWS WAF for monitoring incoming calls and enhancing security by filtering web app traffic. Its ability to prevent attacks like SQL injection is valuable, though documentation could be simpler. AWS enhances customer satisfaction and security. |