Try our new research platform with insights from 80,000+ expert users
reviewer1498707 - PeerSpot reviewer
Solution Architect at a non-profit with 10,001+ employees
Real User
A stable solution, but installation, navigation and configuration are overly complex and the price is not efficient for small customers
Pros and Cons
  • "The solution is stable."
  • "While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex."

What is our primary use case?

While I cannot say for certain, I believe that we are using the latest version. 

What is most valuable?

I like the scalability, as it provides platform, infrastructure and software as a service. These are the best features. When it comes to the API Gateway, such as Amazon Web Application Framework, the web application will be protected by all industry standard security aspects. We are talking about encryption, firewalls, SSL and TLS. Basically, all web exploit policies and rules will be applied, so that one's web or mobile app can be highly secured.

In terms of hosting the instances, the solution takes care of all necessary scaling to ensure that the application load is balanced. The horizontal or vertical scaling can be automatically removed. As such, AWS provides many services and features. 

What needs improvement?

The pricing should be more affordable, especially as it pertains to small clients. 

While the complexity of the installation can vary from one service to another, overall, I would say that it and the configuration and navigation are somewhat complex. These could stand improvement and bring down my rating of the product. 

Customer support should also be improved. 

For how long have I used the solution?

I have been using AWS WAF for around two years. 

Buyer's Guide
AWS WAF
June 2025
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How was the initial setup?

While it can vary according to the service involved, installation, configuration and navigation are, broadly speaking, complex. 

What's my experience with pricing, setup cost, and licensing?

The solution could be more cost-efficient for small customers. 

What other advice do I have?

The solution may be expensive for smaller customers and vendors, although it would be recommended for large ones who can afford it. 

Our organization has only a few years, consisting of the internal team, who are making use of the solution. 

I rate AWS WAF as a six out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Physical Designer at Semtech Corporation
Real User
Does what it is supposed to do, probably not in the best way and not in the best UI
Pros and Cons
  • "The access instruction feature is the most valuable. This is what we use the most."
  • "It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful. It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one. Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right."

What is our primary use case?

The regular use case is basically for blocking or giving access to different vendors to different domains. We also use it for managing and identifying the attacks and new rules that we should implement for our public domains to tune up the application firewall or tool, whatever makes more sense for us.

We're using it through the web console and API. We're just using the managed service.

How has it helped my organization?

Our organization is launching a lot of betas. We are creating a lot of new different systems for different customers. AWS WAF helps us a lot to make sure that the right customer gets the right access to the system.

What is most valuable?

The access instruction feature is the most valuable. This is what we use the most.

What needs improvement?

It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful.

It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one.

Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right.

For how long have I used the solution?

I have been using AWS WAF for about six months.

What do I think about the stability of the solution?

Stability-wise, it works as expected.

What do I think about the scalability of the solution?

I definitely see places where it can be more designed to scale. In addition to amazon resources, there is some stuff from other vendors that we wanted to protect. WAF was not a solution for us because we don't have a way to integrate with those things. That was the biggest challenge that we faced. In terms of the number of users, our end users could be in the thousands.

How are customer service and technical support?

It is okay.

How was the initial setup?

It was okay. We went for the cloud formation, and our deployments happen probably every week.

What about the implementation team?

Everything is managed through cloud formation. After implementation, three or four hours a week are required for maintenance.

What's my experience with pricing, setup cost, and licensing?

We are kind of doing a POC comparison to see what works best. Pricing-wise, AWS is one of the most attractive ones. It is fairly cheap, and we like the pricing part. We're trying to see what makes more sense operation-wise, license-wise, and pricing-wise.

What other advice do I have?

I won't recommend it at the moment because I don't have a full picture to recommend it or say that it is bad or good. I'll probably just keep testing and go with it for probably another six months or a year, and then I can probably recommend it or not. 

Other vendors are also providing solutions for D-DOS protection and WAF. It would be nice to see something outside the box for AWS WAF to make it compete with other vendors.

I would rate AWS WAF a seven out of ten. It does what it is supposed to do, probably not in the best way and not in the best UI, but it works. We like the pricing part, but management is the thing that we don't love the most. If things keep improving, we're definitely going to scale with AWS WAF.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
AWS WAF
June 2025
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
Principal Engineer at a tech services company with 51-200 employees
Real User
Use this product to make it possible to deploy web applications securely
Pros and Cons
  • "This product supplies options for web security for applications accessing sensitive information."
  • "The technical support does not respond to bugs in the coding of the product."

What is our primary use case?

There are two things that we primarily use AWS WAF (Amazon Web Services Web Application Firewall) for. One use is within the company. Within the company, the intended use is to deploy our applications. It is like working with the cloud. We can start an application in S3 (Simple Storage Service), and use profiles for access to data.  

The other use is that most of our clients use a similar infrastructure. They are either using AWS, Azure or maybe Google Cloud Platform (GCP). We deploy this solution for them.  

Both uses are different. One is for the cloud solutions like AWS, Azure and GCP, and one is for the local server access. That is how you want to secure a server. You are securing a server, database, app servers, and ATA gateways. The other one is for implementing security for the AWS. You want to have both running side-by-side.  

Let me give you an example. Suppose, most of the people working for your company are connected from external locations with company-provided laptops or systems. I want to check all devices to make sure that they are being used in a secure way and not creating any breach of security. Those checks cannot be taken care of reliably from the AWS perspective. This is why you need two solutions.  

What is most valuable?

The most valuable feature is the ability to use the product to enhance security in deploying web applications.  

What needs improvement?

We have not implemented WAF completely. We are working around that issue right now in the AWS. We are creating log files and then we are using Kibana for analysis. Out WAF deployment is not perfected yet so it is not implemented as our long-term solution. It will take another month to complete the setup. I do not have the big picture on it yet in a live environment, so my view of what will need to be improved under load is limited.  

I think one thing that should be available is that if there are technical problems in the AWS, then there should be automated alerts to AWS. Calling support is not that easy. It would be better to automatically send emails to them to report that there is a bug in their programming.  

I have an idea for a new feature to consider. I think the security area and other things that they provide are good, and I know there are third-party integrations. It provides a lot of value. The problem is that the 'value' of the solution makes it very costly. That is a big thing. $20,000 for this solution seems like a lot.  

Right now we are limited to only MySQL and PostgreSQL databases. There should be other options and also a way to check the security of it. I think AWS should develop and make available some kind of a management screen so we can see the logs, which servers are using the service, and how the security is performing. All we can see right now is if there are any security breaches. This is not enough information to evaluate the performance of the system.  

For example, there are a lot of people using MongoDB databases. Over the last two years, a lot of them got hacked. Mongo should have had a way to alert end users if its facilities get hacked. A manager or some administrator should receive an email saying that this or that account got hacked and there was a security breach. This would be enough notification to prompt taking other appropriate actions.  

There should also be a report or alerts which tell us that the configuration is having security issues. I think there is something called PVE security rules which might be implemented. Of course, Cisco's security rules could also be implemented. Once the rules are implemented, we know for certain if they are providing a secure connection or not. We need some type of check on the configuration that can create alerts for potential security issues and to have proper notifications.  

For how long have I used the solution?

We have been in the implementation process with the product for some time but it is not yet live because we are not totally satisfied with the setup.  

How are customer service and technical support?

I am not satisfied with AWS technical support. It is a long story. Two years back I contacted support because their code was not working. The solution itself was not perfect and there was a bug in the system. It was creating a lot of issues and there is no way to contact support. 

I tried to contact them to tell them that they had a problem with AWS, they wanted me to pay them $200 to tell them there was a problem with their product — which is very strange. What I did instead was to send an email to their sales department at AWS to explain to them that there was a coding issue and that the software was not working as it was supposed to. After many months, they replied that this was not a problem for the sales department. They said they would forward the issue to the technical support team. When the technical support team received the information, they asked for money again to solve the problem in the coding of their own product.  

I just wanted to tell them that they had a problem. They gave me a run-around and would not even look at the issue that was on their end which must have affected more clients than just me. So I think in that way, the technical support is not good. If there is a problem or a bug within the AWS services, there is no way to contact anyone for a resolution. That is a problem and not a good way to run technical support.  

Which solution did I use previously and why did I switch?

We were using ManageEngine. A problem with using ManageEngine was that ManageEngine can help in securing the servers and API gateways and app servers, but it cannot help to tell if there is any breach in security from a company-provided laptop. We needed a better solution that covered this vulnerability.  

How was the initial setup?

This product is not straightforward to set up and deploy. In the area of database security, it is especially complex. This is especially true when you want to do security for the cloud. There may be applications that will allow software on the cloud to access your in-house servers. If your in-house servers are available and there is a database, you want to secure it. You can do that more easily in-house than you can on the cloud but you have to be sure it is configured and secured properly.  

What's my experience with pricing, setup cost, and licensing?

As far as pricing considerations, there are other competitors to consider. All the solutions are not easy and all will not do exactly the same thing or even what you need. SecureSphere is expensive, I think $20,000 per year. If you go for ManageEngine or any other solution, they also go for close to $10,000. It depends on how many applications you are running and how many servers you have. They can easily run into close to $10,000 a year. Database security and application security are generally costly solutions.  

AWS is not that costly by comparison. They are maybe close to $40 per month. I think it was between $29 or $39.  

What other advice do I have?

On a scale from one to ten where one is the worst and ten is the best, I would rate this product as a seven or an eight. I do not like to give it a solid rating as of now because we are still in the process of implementing it. Once we have completed the implementation, we will be able to give you a proper answer. As recent as two weeks we were still considering ManageEngine, but we did finally decide in our comparisons that it cannot provide all of the features that we are looking for.  

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Head of Digital Product Office at a energy/utilities company with 10,001+ employees
Real User
An excellent solution that's extremely scalable, very stable, and has great AI functionality
Pros and Cons
  • "The ability to take multiple data sets and match those data sets together is the solution's most valuable feature. The data lake that comes with it is very useful because that allows us to match data sets with different configurations that we wouldn't normally be able to match."
  • "The solution is cloud-based, and therefore the billing model that comes with it could be more intuitive, in my opinion. It's very easy to not fully understand how you tag things for billing and then you can quite easily run up a high bill without realizing it. The solution needs to be more intuitive around the tagging system, which enables the billing. Right now, I have a cloud architect that does that on our behalf and it isn't something that a business user could use because it still requires quite a lot of technical knowledge to do effectively."

What is our primary use case?

We primarily use the solution for its rich insights to improve customer experience.

What is most valuable?

The ability to take multiple data sets and match those data sets together is the solution's most valuable feature. The data lake that comes with it is very useful because that allows us to match data sets with different configurations that we wouldn't normally be able to match.

The AI functionality and the machine learning are very good.

What needs improvement?

The solution is cloud-based, and therefore the billing model that comes with it could be more intuitive, in my opinion. It's very easy to not fully understand how you tag things for billing and then you can quite easily run up a high bill without realizing it. The solution needs to be more intuitive around the tagging system, which enables the billing. Right now, I have a cloud architect that does that on our behalf and it isn't something that a business user could use because it still requires quite a lot of technical knowledge to do effectively.

For how long have I used the solution?

I've been using the solution for almost a year.

What do I think about the stability of the solution?

The solution is very stable.

What do I think about the scalability of the solution?

The solution is extremely scalable.

How are customer service and technical support?

We have Amazon managed services, and, as part of our agreement, we have the lower end of that managed service. The solution is not a business-critical system for us, so we have a four hour SLA for resolution. That's pretty good. We're very satisfied with technical support.

Which solution did I use previously and why did I switch?

Previous to this solution, we used Microsoft Azure.

Amazon allows you to provision more services once you have the initial platform in place. Using Amazon Marketplace, it's so simple to provide additional services and functionality so it allows you to grow the capability of the platform with very little integration into other systems because it's all built into the marketplace. With Azure, it's only capable of some products and they don't have APIs available to integrate as well as Amazon does. 

How was the initial setup?

The initial setup was straightforward. Deployment took about three months. For the setup of the platform, we had six people. For the maintenance of the platform, we now have three people maintaining it.

What about the implementation team?

We brought Amazon on to set everything up for us. They made implementation very easy. 

What other advice do I have?

We use the public cloud deployment model. We use the Amazon cloud.

From a technology perspective, Amazon is very simple. It requires, in order for it to run effectively, quite a mature cloud-based culture within your organization, however. My advice to others would be to get their operating model internally right before going ahead with the implementation.

I would rate the solution nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Uddeshya Kumar - PeerSpot reviewer
Product Owner at SecLogic Limited
Real User
Top 5
A stable solution that is easy to deploy and provides a helpful support team
Pros and Cons
  • "The tool’s stability is very good."
  • "The cost must be reduced."

What is our primary use case?

We use the solution for filtering traffic. We do not want our developers to use unnecessary websites. So, we filter the websites using the tool.

What is most valuable?

All the features are good. AWS Lambda and S3 are valuable tools. We have to use these tools when we build applications.

What needs improvement?

The cost must be reduced.

For how long have I used the solution?

I have been using the solution for a year. I use the latest version.

What do I think about the stability of the solution?

The tool’s stability is very good. It is better than GCP.

What do I think about the scalability of the solution?

The tool’s scalability is good. We have almost 20 users.

How are customer service and support?

The support is helpful.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We also use GCP.

How was the initial setup?

The initial setup is very easy. Everything is on the cloud. The deployment takes one full day.

What about the implementation team?

We deploy the product in-house. We need one senior solution architect and one junior solution architect to deploy the tool. We have a team of analysts for experiments. We need only one person to maintain the solution.

What's my experience with pricing, setup cost, and licensing?

The product is expensive.

What other advice do I have?

We use almost 40 services. Overall, I rate the product an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Ashish  Paikrao - PeerSpot reviewer
Cloud Infrastructure Engineer at Pathlock
Real User
Top 5Leaderboard
A scalable solution that provides excellent documentation and additional security to applications
Pros and Cons
  • "The product’s availability, ease of configuration, and documentation are valuable."
  • "The product must provide more features."

What is our primary use case?

We use the solution for our applications. We have deployed multiple applications on the AWS platform. We use the tool to provide additional security to our applications.

What is most valuable?

The product’s availability, ease of configuration, and documentation are valuable.

What needs improvement?

The product has fewer features. It didn’t fulfill all our requirements when we installed it. It is getting better now, though. The product must provide more features.

For how long have I used the solution?

I have been using the solution for a few years.

What do I think about the stability of the solution?

I rate the product’s stability a nine out of ten.

What do I think about the scalability of the solution?

The product is highly scalable and highly available. I rate the scalability a nine out of ten. We have deployed three applications. We have two administrators for our infrastructure. The number of users varies according to our customers. We provide the user interface to our customers.

How are customer service and support?

The technical support team is good. The support persons provide prompt responses. They are always available and provide solutions to our queries.

How would you rate customer service and support?

Positive

How was the initial setup?

The setup is very easy. We have proper documentation, so we have no issues. We have deployed the tool for additional security. It is a cloud solution. We need two members from the cloud infrastructure team and eight from the application support team for the deployment and maintenance of the tool.

What about the implementation team?

We deploy the tool ourselves.

What was our ROI?

The solution provides an additional layer of security.

What's my experience with pricing, setup cost, and licensing?

The solution is affordable.

What other advice do I have?

If a company needs an additional layer of security, it can use AWS WAF. I recommend the product to others. Overall, I rate the product a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
AWS Security Specialist at a computer software company with 1,001-5,000 employees
Real User
Top 20
Helps to protect internet system applications
Pros and Cons
  • "The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections."
  • "We should be able to do proper whitelisting."

What is our primary use case?

We use AWS WAF to protect internet system applications. 

What is most valuable?

The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections. 

What needs improvement?

We should be able to do proper whitelisting. 

For how long have I used the solution?

I have been working with the solution for four years. 

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

My company has more than 10,000 users. The tool is scalable. 

How are customer service and support?

AWS WAF's tech support is not complicated. 

How would you rate customer service and support?

Positive

How was the initial setup?

AWS WAF's deployment is easy. 

What was our ROI?

We have seen ROI with the tool's use.

What's my experience with pricing, setup cost, and licensing?

AWS WAF has reasonable pricing. 

What other advice do I have?

You need to consider the use cases before implementing the solution. I rate it a ten out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1399293 - PeerSpot reviewer
Superintendent of Cloud Platforms at a manufacturing company with 1,001-5,000 employees
Real User
Protects public-facing web applications but pricing is expensive
Pros and Cons
  • "We preferred the product based on its cost. AWS WAF is an out-of-the-box solution and integrates with the AWS services that we use. It's natively integrated with AWS."
  • "We have issues with reporting, troubleshooting, and analytics. AWS WAF needs to bring costs down."

What is our primary use case?

We use the product for the protection of our public-facing web applications. 

What is most valuable?

We preferred the product based on its cost. AWS WAF is an out-of-the-box solution and integrates with the AWS services that we use. It's natively integrated with AWS

What needs improvement?

We have issues with reporting, troubleshooting, and analytics. AWS WAF needs to bring costs down. 

For how long have I used the solution?

I have been working with the solution for 18 months. 

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

We use Amazon enterprise support. It is good but expensive. 

Which solution did I use previously and why did I switch?

We used Cloudflare and Palo Alto before. We chose AWS WAF since it integrates with native services. 

How was the initial setup?

The tool's setup is complex but it is easy after installation. 

What's my experience with pricing, setup cost, and licensing?

I would rate AWS WAF's pricing a seven out of ten. 

What other advice do I have?

I would rate AWS WAF a seven out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.
Updated: June 2025
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.