Try our new research platform with insights from 80,000+ expert users
Trivikram Rajendreaprabhu - PeerSpot reviewer
Senior security engeneer at a media company with 1,001-5,000 employees
Real User
Top 10
Aug 9, 2022
Customizable features and a great solution for monitoring
Pros and Cons
  • "The customizable features are good."
  • "The product could be improved by expanding the weightage units of rules."

What is our primary use case?

We primarily use this solution for monitoring and blocking to ensure protection against application layer attacks. These include application-related core rules, database-specific attacks, Linux-based attacks and some custom rules deployed. These rules assist us in blocking specific attacks that come from the internet into our cloud infrastructure.

What is most valuable?

The customizable features are good. For example, we can write our own rules and match character and size limits.

What needs improvement?

The product could be improved by expanding the weightage units of rules we have when writing policy. Currently, our company uses WAF policy and Web ACL but is limited to only 1500 units of rules.

For how long have I used the solution?

We have been using this solution for three years and are currently using version two. We deploy this solution on Amazon public cloud.

Buyer's Guide
AWS WAF
December 2025
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,422 professionals have used our research since 2012.

What do I think about the stability of the solution?

This solution is stable. 

What do I think about the scalability of the solution?

This solution is scalable because it provides many features.

How are customer service and support?

We have received good support from the customer service and support team. They identify our problems and assist in resolving any issues we have.

How was the initial setup?

Our initial setup was straightforward, and deployment by automation only took a few minutes.

What's my experience with pricing, setup cost, and licensing?

I cannot comment on licensing costs and pricing as I am unsure of the exact costs.

What other advice do I have?

I rate AWS WAF an eight out of ten. I would advise new customers to choose custom policies because they provide more flexibility in guarding against attacks on cloud infrastructures. Additionally, it protects both regional and global servers.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1143783 - PeerSpot reviewer
Advisory and IT Transformation Consultant at a tech services company with 10,001+ employees
Real User
Aug 5, 2022
Helps secure applications, highly stable, and good support
Pros and Cons
  • "The most valuable feature of AWS WAF is the extra layer of security that I have when connecting to my web applications."
  • "AWS WAF could improve by making the overall management easier. Many people that have started working with AWS WAF do not have an easy time. They should make it easy to use."

What is most valuable?

The most valuable feature of AWS WAF is the extra layer of security that I have when connecting to my web applications.

What needs improvement?

AWS WAF could improve by making the overall management easier. Many people that have started working with AWS WAF do not have an easy time. They should make it easy to use. 

The AWS WAF documentation sometimes is not clear and could improve for all levels of people using the solution, such as developers. The interface could be easier to use.

For how long have I used the solution?

I have been using AWS WAF for approximately three years.

What do I think about the stability of the solution?

AWS WAF is a highly stable solution.

What do I think about the scalability of the solution?

We have approximately 35 applications that are using the AWS WAF.

How are customer service and support?

The support from AWS WAF is good, I have used them often. 

Which solution did I use previously and why did I switch?

I was previously using Cisco and I switched to AWS WAF because I was working mostly with cloud environments and needed more services. Additionally, I have used Microsoft Azure.

How was the initial setup?

The initial setup is AWS WAF complex. The steps to complete the implementation could be easier, such as making the web traffic go through the WAF and then through the web service. The information for connectivity could be documented or done easier. The whole process can take approximately 20 minutes.

What's my experience with pricing, setup cost, and licensing?

The price of AWS WAF is expensive if you do not know how to manage your software up or down. I price of the solution is average amongst the other competitors but it would be better if it was less expensive.

What other advice do I have?

My advice to others is they should give AWS WAF a try. It works well, secures the applications, and it improves them against attacks.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
AWS WAF
December 2025
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,422 professionals have used our research since 2012.
reviewer1530864 - PeerSpot reviewer
Engineer at a renewables & environment company with 501-1,000 employees
Real User
Jan 11, 2022
A basic WAF with limited controls, but cheap and better than having no WAF in place.
Pros and Cons
  • "As a basic WAF, it's better than nothing. So if you need something simple out of the box with default features, AWS WAF is good."
  • "We don't have much control over blocking, because the WAF is managed by AWS."

What is our primary use case?

At the moment, it's just myself working with AWS WAF in my company, and our use case for it is normal, or what you would expect from a Web Application Firewall. That includes basic DoS blocking and malicious IP address blocking. It's not a big thing for us, and just takes care of our baseline security.

What is most valuable?

As a basic WAF, it's better than having nothing. So if you need something simple out of the box with default features, AWS WAF is good.

What needs improvement?

I think there's a lot wrong with AWS WAF. Here are the two main areas where I think it could be improved:

Blocking: We don't have much control over blocking, because the WAF is managed by AWS. What happens is that they will put down the rules on their side and we don't have proper visibility on that. So we'll have to track down the issues and see what is wrong or not. For example, with IP address blocking, it's difficult to find out which IPs are getting blocked. If we managed our own WAF completely, we wouldn't have this kind of problem. Right now, this aspect is half managed by us, and half managed by AWS. Because of this, I think it would be far more helpful to us if we went for our own tool instead.

Automation: As in, a lot of separate blocks if something goes wrong. For example, every company will have their own rules for automation, in terms of their goals for the product. Like, "I want my WAF to do this. I want my WAF to do that." But that's the kind of thing that I think we will only see when we do some POCs with our clients. 

For how long have I used the solution?

I have been working with AWS WAF for around one year now. 

What do I think about the stability of the solution?

The performance has been good, even though it could be better. At any rate, the WAF has not caused any lag on our side.

What do I think about the scalability of the solution?

It is scalable in my experience, but the lack of features doesn't take it very far in terms of actual usage. Eventually, customers will move away from it. If there's no one interested in managing the WAF, that's fine, then customers may keep using it. But for us, we are not planning to scale it out further.

How are customer service and support?

AWS technical support is good.

How would you rate customer service and support?

Neutral

How was the initial setup?

The setup is easy and nothing serious. You don't have to do a lot to get set up with it. Compared to other WAFs out there, I think AWS WAF is very simple, especially since most of it is managed by AWS.

What about the implementation team?

We haven't needed anyone from AWS to help us with the deployment or implementation. It's all me at this point.

What's my experience with pricing, setup cost, and licensing?

It's less cost and easy to setup

Which other solutions did I evaluate?

There are multiple other options which we could have gone for, but it depends on the budget, typically. I am especially interested in a WAF which has serious support for automation and more complex configuration options.

What other advice do I have?

For people who don't have any WAF currently, and who just need something basic, it's not a bad idea to go with AWS WAF for starters. But if you are someone who is looking for a fully-fledged and self-managed WAF, you should look elsewhere for a better tool. You should certainly not stick with AWS WAF if you are serious about managing your security and mitigating your risks.

Overall, I would recommend AWS WAF to others, but only under the conditions I have mentioned. If you have the budget and the resources, however, go for something else.

I would rate AWS WAF a five out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1498707 - PeerSpot reviewer
Solution Architect at a non-profit with 10,001+ employees
Real User
Aug 17, 2021
A stable solution, but installation, navigation and configuration are overly complex and the price is not efficient for small customers
Pros and Cons
  • "The solution is stable."
  • "While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex."

What is our primary use case?

While I cannot say for certain, I believe that we are using the latest version. 

What is most valuable?

I like the scalability, as it provides platform, infrastructure and software as a service. These are the best features. When it comes to the API Gateway, such as Amazon Web Application Framework, the web application will be protected by all industry standard security aspects. We are talking about encryption, firewalls, SSL and TLS. Basically, all web exploit policies and rules will be applied, so that one's web or mobile app can be highly secured.

In terms of hosting the instances, the solution takes care of all necessary scaling to ensure that the application load is balanced. The horizontal or vertical scaling can be automatically removed. As such, AWS provides many services and features. 

What needs improvement?

The pricing should be more affordable, especially as it pertains to small clients. 

While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex. These could stand improvement and bring down my rating of the product. 

Customer support should also be improved. 

For how long have I used the solution?

I have been using AWS WAF for around two years. 

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How was the initial setup?

While it can vary according to the service involved, installation, configuration and navigation are, broadly speaking, complex. 

What's my experience with pricing, setup cost, and licensing?

The solution could be more cost-efficient for small customers. 

What other advice do I have?

The solution may be expensive for smaller customers and vendors, although it would be recommended for large ones who can afford it. 

Our organization has only a few years, consisting of the internal team, who are making use of the solution. 

I rate AWS WAF as a six out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ashish  Paikrao - PeerSpot reviewer
Cloud Infrastructure Engineer at a computer software company with 201-500 employees
Real User
Top 5Leaderboard
Jan 10, 2024
A scalable solution that provides excellent documentation and additional security to applications
Pros and Cons
  • "The product’s availability, ease of configuration, and documentation are valuable."
  • "The product must provide more features."

What is our primary use case?

We use the solution for our applications. We have deployed multiple applications on the AWS platform. We use the tool to provide additional security to our applications.

What is most valuable?

The product’s availability, ease of configuration, and documentation are valuable.

What needs improvement?

The product has fewer features. It didn’t fulfill all our requirements when we installed it. It is getting better now, though. The product must provide more features.

For how long have I used the solution?

I have been using the solution for a few years.

What do I think about the stability of the solution?

I rate the product’s stability a nine out of ten.

What do I think about the scalability of the solution?

The product is highly scalable and highly available. I rate the scalability a nine out of ten. We have deployed three applications. We have two administrators for our infrastructure. The number of users varies according to our customers. We provide the user interface to our customers.

How are customer service and support?

The technical support team is good. The support persons provide prompt responses. They are always available and provide solutions to our queries.

How would you rate customer service and support?

Positive

How was the initial setup?

The setup is very easy. We have proper documentation, so we have no issues. We have deployed the tool for additional security. It is a cloud solution. We need two members from the cloud infrastructure team and eight from the application support team for the deployment and maintenance of the tool.

What about the implementation team?

We deploy the tool ourselves.

What was our ROI?

The solution provides an additional layer of security.

What's my experience with pricing, setup cost, and licensing?

The solution is affordable.

What other advice do I have?

If a company needs an additional layer of security, it can use AWS WAF. I recommend the product to others. Overall, I rate the product a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
AWS Security Specialist at a computer software company with 1,001-5,000 employees
Real User
Oct 14, 2023
Helps to protect internet system applications
Pros and Cons
  • "The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections."
  • "We should be able to do proper whitelisting."

What is our primary use case?

We use AWS WAF to protect internet system applications. 

What is most valuable?

The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections. 

What needs improvement?

We should be able to do proper whitelisting. 

For how long have I used the solution?

I have been working with the solution for four years. 

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

My company has more than 10,000 users. The tool is scalable. 

How are customer service and support?

AWS WAF's tech support is not complicated. 

How would you rate customer service and support?

Positive

How was the initial setup?

AWS WAF's deployment is easy. 

What was our ROI?

We have seen ROI with the tool's use.

What's my experience with pricing, setup cost, and licensing?

AWS WAF has reasonable pricing. 

What other advice do I have?

You need to consider the use cases before implementing the solution. I rate it a ten out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Real User
Jul 26, 2023
Helps to implement response recovery procedures
Pros and Cons
  • "One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services."
  • "I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy."

What is our primary use case?

One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services.

What needs improvement?

I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy.

For how long have I used the solution?

I have been using the solution for almost a decade.

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

The solution is scalable.

How was the initial setup?

The initial setup was easy.

What about the implementation team?

Our in-house engineers implemented the solution. They are already familiar with AWS and hold AWS certifications.

What other advice do I have?

Overall, I rate the solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Prakash-Kumar - PeerSpot reviewer
CEO at a tech consulting company with 11-50 employees
Real User
Top 20
Apr 9, 2023
Good support, extremely stable, and scalable
Pros and Cons
  • "The stability of AWS WAF is valuable."
  • "The cost management has room for improvement."

What is our primary use case?

We are an AWS service provider and we use the solution for the cloud and to provide service to other users.

What is most valuable?

The stability of AWS WAF is valuable.

What needs improvement?

The cost management has room for improvement.

For how long have I used the solution?

I have been using the solution for eight years.

What do I think about the stability of the solution?

I give the stability a ten out of ten.

What do I think about the scalability of the solution?

I give the scalability a nine out of ten.

How are customer service and support?

The technical support is helpful.

What's my experience with pricing, setup cost, and licensing?

The price is average.

What other advice do I have?

I give the solution a ten out of ten.

The solution is a public cloud platform and we have millions of users.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.