Harkamal-Singh - PeerSpot reviewer
Solution architect at NTT
Real User
Protects web applications against attacks; stable and scalable firewall with a straightforward setup
Pros and Cons
  • "Stable and scalable web application firewall. Setting it up is straightforward."
  • "Technical support for AWS WAF needs improvement."

What needs improvement?

Support for AWS WAF needs improvement.

For how long have I used the solution?

I've been using AWS WAF for a very short period, e.g. just a few weeks.

What do I think about the stability of the solution?

I find AWS WAF to be a stable product.

What do I think about the scalability of the solution?

AWS WAF is a scalable product.

Buyer's Guide
AWS WAF
April 2024
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,479 professionals have used our research since 2012.

How are customer service and support?

Technical support for AWS WAF could still be improved, e.g. support could be faster, more knowledgeable, and friendlier.

How was the initial setup?

The initial setup for AWS WAF was straightforward. It could take between two days to two weeks.

What about the implementation team?

We implemented AWS WAF through our in-house team and a consultant.

What other advice do I have?

I've been using a mix of AWS products, including AWS WAF.

I'm satisfied with AWS WAF, and I've had no issues with it. I can't really find fault in the product. It's a good product.

We have hundreds of AWS WAF users within our company. We also have plans of increasing the number of users of the product.

The advice I would give to people who want to start using AWS WAF is that it's a good option if they're migrating to the cloud. It can take up a lot of legacy systems, e.g. it's scalable. Most of my customers are on the cloud, and for anyone who's struggling, it would be good to start anytime. Start small and scale, rather than just going fully onto the cloud.

Users need to pay for the product license.

My rating for AWS WAF is eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
AWS Security Specialist at a computer software company with 1,001-5,000 employees
Real User
Top 20
Helps to protect internet system applications
Pros and Cons
  • "The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections."
  • "We should be able to do proper whitelisting."

What is our primary use case?

We use AWS WAF to protect internet system applications. 

What is most valuable?

The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections. 

What needs improvement?

We should be able to do proper whitelisting. 

For how long have I used the solution?

I have been working with the solution for four years. 

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

My company has more than 10,000 users. The tool is scalable. 

How are customer service and support?

AWS WAF's tech support is not complicated. 

How would you rate customer service and support?

Positive

How was the initial setup?

AWS WAF's deployment is easy. 

What was our ROI?

We have seen ROI with the tool's use.

What's my experience with pricing, setup cost, and licensing?

AWS WAF has reasonable pricing. 

What other advice do I have?

You need to consider the use cases before implementing the solution. I rate it a ten out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
Buyer's Guide
AWS WAF
April 2024
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
769,479 professionals have used our research since 2012.
Infrastructure Engineer
Real User
Top 20
Useful for protecting against unauthorized access and data breaches but very expensive
Pros and Cons
  • "The most valuable feature is the capability to limit access based on geographical location by restricting specific IP addresses."
  • "I would like to see the addition of more advanced rate-limiting features in the next release. It would be beneficial to extend rate limiting beyond just web servers to the main node level."

What is our primary use case?

We use the AWS platform to implement custom security rules based on our company's SOP. We apply custom rules to protect specific APIs and specific endpoint URLs. This allows us to tailor our security measures to our specific needs and requirements.

How has it helped my organization?

AWS WAF has improved our organization by allowing us to restrict access to our services based on location, which means that only customers from specific locations can access our services. It helps protect against unauthorized access and data breaches.

What is most valuable?

The most valuable feature is the capability to limit access based on geographical location by restricting specific IP addresses.

What needs improvement?

In terms of improvement, AWS WAF works perfectly fine right now. I would like to see the addition of more advanced rate-limiting features in the next release. It would be beneficial to extend rate limiting beyond just web servers to the main node level.

For how long have I used the solution?

I have been using AWS WAF for three years.

What do I think about the stability of the solution?

I would rate the stability of the solution an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of AWS WAF an eight out of ten. All requests, about 100,000 per month, go through the AWS App, ensuring the entire infrastructure is compliant with it. We use it 24/7.

How are customer service and support?

The technical support is slow to respond, and it's a paid service. I wouldn't recommend relying on it.

How would you rate customer service and support?

Negative

How was the initial setup?

The initial setup was simple and I did it myself. I would rate it an eight out of ten in terms of easiness. The deployment was in-house and it took five to ten minutes. It is mostly automated so it did not require much manual assistance. If errors or failures occur, reports are generated and shared with the relevant team for resolution. The deployment process involved specifying endpoint URLs in the web test code to enable automatic integration and we had to wait a little due to cooling time on the web test board. 

What's my experience with pricing, setup cost, and licensing?

The solution is really expensive. I would give it a ten out of ten in terms of costliness. You have to pay additionally for data transfer. 

What other advice do I have?

I would advise someone considering AWS WAF to start with testing on AWS but be cautious of data transfer costs, especially if the project is longer than four months because that is when the additional cost appears. You should assess if it's suitable for your specific use case and make sure to test it before committing to avoid unexpected expenses when moving to the cloud. Overall, I would rate the solution a six out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Flag as inappropriate
PeerSpot user
CVO at Megaaisec
Real User
Top 5
Helps to implement response recovery procedures
Pros and Cons
  • "One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services."
  • "I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy."

What is our primary use case?

One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services.

What needs improvement?

I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy.

For how long have I used the solution?

I have been using the solution for almost a decade.

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

The solution is scalable.

How was the initial setup?

The initial setup was easy.

What about the implementation team?

Our in-house engineers implemented the solution. They are already familiar with AWS and hold AWS certifications.

What other advice do I have?

Overall, I rate the solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Prakash-Kumar - PeerSpot reviewer
CEO at Axcess.io
Real User
Top 10
Good support, extremely stable, and scalable
Pros and Cons
  • "The stability of AWS WAF is valuable."
  • "The cost management has room for improvement."

What is our primary use case?

We are an AWS service provider and we use the solution for the cloud and to provide service to other users.

What is most valuable?

The stability of AWS WAF is valuable.

What needs improvement?

The cost management has room for improvement.

For how long have I used the solution?

I have been using the solution for eight years.

What do I think about the stability of the solution?

I give the stability a ten out of ten.

What do I think about the scalability of the solution?

I give the scalability a nine out of ten.

How are customer service and support?

The technical support is helpful.

What's my experience with pricing, setup cost, and licensing?

The price is average.

What other advice do I have?

I give the solution a ten out of ten.

The solution is a public cloud platform and we have millions of users.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Advisory and IT Transformation Consultant at a tech services company with 10,001+ employees
Real User
Top 5
Helps secure applications, highly stable, and good support
Pros and Cons
  • "The most valuable feature of AWS WAF is the extra layer of security that I have when connecting to my web applications."
  • "AWS WAF could improve by making the overall management easier. Many people that have started working with AWS WAF do not have an easy time. They should make it easy to use."

What is most valuable?

The most valuable feature of AWS WAF is the extra layer of security that I have when connecting to my web applications.

What needs improvement?

AWS WAF could improve by making the overall management easier. Many people that have started working with AWS WAF do not have an easy time. They should make it easy to use. 

The AWS WAF documentation sometimes is not clear and could improve for all levels of people using the solution, such as developers. The interface could be easier to use.

For how long have I used the solution?

I have been using AWS WAF for approximately three years.

What do I think about the stability of the solution?

AWS WAF is a highly stable solution.

What do I think about the scalability of the solution?

We have approximately 35 applications that are using the AWS WAF.

How are customer service and support?

The support from AWS WAF is good, I have used them often. 

Which solution did I use previously and why did I switch?

I was previously using Cisco and I switched to AWS WAF because I was working mostly with cloud environments and needed more services. Additionally, I have used Microsoft Azure.

How was the initial setup?

The initial setup is AWS WAF complex. The steps to complete the implementation could be easier, such as making the web traffic go through the WAF and then through the web service. The information for connectivity could be documented or done easier. The whole process can take approximately 20 minutes.

What's my experience with pricing, setup cost, and licensing?

The price of AWS WAF is expensive if you do not know how to manage your software up or down. I price of the solution is average amongst the other competitors but it would be better if it was less expensive.

What other advice do I have?

My advice to others is they should give AWS WAF a try. It works well, secures the applications, and it improves them against attacks.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Solution Architect at a non-profit with 10,001+ employees
Real User
A stable solution, but installation, navigation and configuration are overly complex and the price is not efficient for small customers
Pros and Cons
  • "The solution is stable."
  • "While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex."

What is our primary use case?

While I cannot say for certain, I believe that we are using the latest version. 

What is most valuable?

I like the scalability, as it provides platform, infrastructure and software as a service. These are the best features. When it comes to the API Gateway, such as Amazon Web Application Framework, the web application will be protected by all industry standard security aspects. We are talking about encryption, firewalls, SSL and TLS. Basically, all web exploit policies and rules will be applied, so that one's web or mobile app can be highly secured.

In terms of hosting the instances, the solution takes care of all necessary scaling to ensure that the application load is balanced. The horizontal or vertical scaling can be automatically removed. As such, AWS provides many services and features. 

What needs improvement?

The pricing should be more affordable, especially as it pertains to small clients. 

While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex. These could stand improvement and bring down my rating of the product. 

Customer support should also be improved. 

For how long have I used the solution?

I have been using AWS WAF for around two years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How was the initial setup?

While it can vary according to the service involved, installation, configuration and navigation are, broadly speaking, complex. 

What's my experience with pricing, setup cost, and licensing?

The solution could be more cost-efficient for small customers. 

What other advice do I have?

The solution may be expensive for smaller customers and vendors, although it would be recommended for large ones who can afford it. 

Our organization has only a few years, consisting of the internal team, who are making use of the solution. 

I rate AWS WAF as a six out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Physical Designer at Semtech Corporation
Real User
Does what it is supposed to do, probably not in the best way and not in the best UI
Pros and Cons
  • "The access instruction feature is the most valuable. This is what we use the most."
  • "It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful. It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one. Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right."

What is our primary use case?

The regular use case is basically for blocking or giving access to different vendors to different domains. We also use it for managing and identifying the attacks and new rules that we should implement for our public domains to tune up the application firewall or tool, whatever makes more sense for us.

We're using it through the web console and API. We're just using the managed service.

How has it helped my organization?

Our organization is launching a lot of betas. We are creating a lot of new different systems for different customers. AWS WAF helps us a lot to make sure that the right customer gets the right access to the system.

What is most valuable?

The access instruction feature is the most valuable. This is what we use the most.

What needs improvement?

It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful.

It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one.

Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right.

For how long have I used the solution?

I have been using AWS WAF for about six months.

What do I think about the stability of the solution?

Stability-wise, it works as expected.

What do I think about the scalability of the solution?

I definitely see places where it can be more designed to scale. In addition to amazon resources, there is some stuff from other vendors that we wanted to protect. WAF was not a solution for us because we don't have a way to integrate with those things. That was the biggest challenge that we faced. In terms of the number of users, our end users could be in the thousands.

How are customer service and technical support?

It is okay.

How was the initial setup?

It was okay. We went for the cloud formation, and our deployments happen probably every week.

What about the implementation team?

Everything is managed through cloud formation. After implementation, three or four hours a week are required for maintenance.

What's my experience with pricing, setup cost, and licensing?

We are kind of doing a POC comparison to see what works best. Pricing-wise, AWS is one of the most attractive ones. It is fairly cheap, and we like the pricing part. We're trying to see what makes more sense operation-wise, license-wise, and pricing-wise.

What other advice do I have?

I won't recommend it at the moment because I don't have a full picture to recommend it or say that it is bad or good. I'll probably just keep testing and go with it for probably another six months or a year, and then I can probably recommend it or not. 

Other vendors are also providing solutions for D-DOS protection and WAF. It would be nice to see something outside the box for AWS WAF to make it compete with other vendors.

I would rate AWS WAF a seven out of ten. It does what it is supposed to do, probably not in the best way and not in the best UI, but it works. We like the pricing part, but management is the thing that we don't love the most. If things keep improving, we're definitely going to scale with AWS WAF.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.