No more typing reviews! Try our Samantha, our new voice AI agent.
You need to sign in or sign up before continuing.
AWS Security Specialist at a computer software company with 1,001-5,000 employees
Real User
Oct 14, 2023
Helps to protect internet system applications
Pros and Cons
  • "The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections."
  • "We should be able to do proper whitelisting."

What is our primary use case?

We use AWS WAF to protect internet system applications. 

What is most valuable?

The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections. 

What needs improvement?

We should be able to do proper whitelisting. 

For how long have I used the solution?

I have been working with the solution for four years. 

Buyer's Guide
AWS WAF
March 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

My company has more than 10,000 users. The tool is scalable. 

How are customer service and support?

AWS WAF's tech support is not complicated. 

How was the initial setup?

AWS WAF's deployment is easy. 

What was our ROI?

We have seen ROI with the tool's use.

What's my experience with pricing, setup cost, and licensing?

AWS WAF has reasonable pricing. 

What other advice do I have?

You need to consider the use cases before implementing the solution. I rate it a ten out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
CVO at Megaaisec
Real User
Jul 26, 2023
Helps to implement response recovery procedures
Pros and Cons
  • "One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services."
  • "I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy."

What is our primary use case?

One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services.

What needs improvement?

I believe there is a need to move towards real-time analysis with the help of AI and intelligent systems in the future. This would reduce the reliance on manual work and enhance the functionality of detection protection. By incorporating AI-driven data analysis and data science techniques, we can improve the solution's user-friendliness, security compatibility, and accuracy.

For how long have I used the solution?

I have been using the solution for almost a decade.

What do I think about the stability of the solution?

AWS WAF is stable. 

What do I think about the scalability of the solution?

The solution is scalable.

How was the initial setup?

The initial setup was easy.

What about the implementation team?

Our in-house engineers implemented the solution. They are already familiar with AWS and hold AWS certifications.

What other advice do I have?

Overall, I rate the solution an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
AWS WAF
March 2026
Learn what your peers think about AWS WAF. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,444 professionals have used our research since 2012.
Prakash-Kumar - PeerSpot reviewer
CEO at Axcess.io
Real User
Top 20
Apr 9, 2023
Good support, extremely stable, and scalable
Pros and Cons
  • "The stability of AWS WAF is valuable."
  • "The cost management has room for improvement."

What is our primary use case?

We are an AWS service provider and we use the solution for the cloud and to provide service to other users.

What is most valuable?

The stability of AWS WAF is valuable.

What needs improvement?

The cost management has room for improvement.

For how long have I used the solution?

I have been using the solution for eight years.

What do I think about the stability of the solution?

I give the stability a ten out of ten.

What do I think about the scalability of the solution?

I give the scalability a nine out of ten.

How are customer service and support?

The technical support is helpful.

What's my experience with pricing, setup cost, and licensing?

The price is average.

What other advice do I have?

I give the solution a ten out of ten.

The solution is a public cloud platform and we have millions of users.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1940067 - PeerSpot reviewer
Regional Security Team Lead at a computer software company with 1,001-5,000 employees
Real User
Sep 10, 2022
Stable web application firewall used to protect against common vulnerabilities with a powerful CDN component
Pros and Cons
  • "The simple configuration and the scalability have been most valuable. We are able to scale across all of our different AWS instances."
  • "The simple configuration and the scalability have been most valuable, and we are able to scale across all of our different AWS instances."
  • "This solution could be improved if the configuration steps were more specific to WAF, compared to other cloud services."
  • "This solution could be improved if the configuration steps were more specific to WAF, compared to other cloud services."

What is our primary use case?

We use this solution to protect our web applications against common vulnerabilities. The CDN component is also quite powerful. We use this solution alongside Azure WAF.

What is most valuable?

The simple configuration and the scalability have been most valuable. We are able to scale across all of our different AWS instances.

What needs improvement?

This solution could be improved if the configuration steps were more specific to WAF, compared to other cloud services. 

For how long have I used the solution?

I have been using this solution for two years. 

What do I think about the stability of the solution?

This is a stable solution. We rely on AWS's other cloud services and we've never experienced any stability issues. 

What do I think about the scalability of the solution?

This is a scalable solution. 

How are customer service and support?

Our support experience has been quite good. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

The main reason we switched from using CloudFlare to AWS is to have a native offering because all of our cloud solutions are on AWS. This made it simpler compared to using a third party and easier to reroute traffic.

How was the initial setup?

It depends on your AWS configuration, but what we've experienced is that the rule policy configuration is really straightforward. It took a couple of weeks. 

What about the implementation team?

We had in-house expertise.

What's my experience with pricing, setup cost, and licensing?

We have a medium amount of traffic per month and the cost is in the hundreds rather than in the thousands. I don't know the exact number.

What other advice do I have?

I would advise others to ensure they understand what can be done internally and then what you need expertise for externally. If you have the expertise internally, it can be easily configured. Keep the SIEM configuration as simple as possible, rather than trying to modify and configure too many things.

I would rate this solution an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer939417 - PeerSpot reviewer
IT Auditor & Compliance Officer at a tech vendor with 51-200 employees
Real User
Jan 29, 2022
Well integrated, suitable for all sized businesses, but serverless needs improvement
Pros and Cons
  • "AWS WAF has a lot of integrated features and services. For example, there are security services that can be integrated very well for our customers."
  • "AWS WAF has a lot of integrated features and services, for example, there are security services that can be integrated very well for our customers."
  • "The serverless product from AWS WAF could be improved. For example, they have only one serverless series, Lambda, but they should extend and improve it. Additionally, the firewall rules are not very easy to configure."
  • "The serverless product from AWS WAF could be improved. For example, they have only one serverless series, Lambda, but they should extend and improve it. Additionally, the firewall rules are not very easy to configure."

What is our primary use case?

We are using AWS WAF for business purposes for clients. We host our client's platforms on AWS WAF.

What is most valuable?

AWS WAF has a lot of integrated features and services. For example, there are security services that can be integrated very well for our customers.

What needs improvement?

The serverless product from AWS WAF could be improved. For example, they have only one serverless series, Lambda, but they should extend and improve it. Additionally, the firewall rules are not very easy to configure.

For how long have I used the solution?

I have used AWS WAF for approximately five years.

What do I think about the stability of the solution?

I have found AWS WAF to be stable.

What do I think about the scalability of the solution?

The scalability of AWS WAF is very good.

The solution can be used in small to large-sized businesses.

How are customer service and support?

The customer service has been fine, we had no issues with them. We have been satisfied.

How was the initial setup?

The setup of AWS WAF is very easy.

What's my experience with pricing, setup cost, and licensing?

The price of AWS WAF is reasonable, it is not expensive and it is not cheap.

What other advice do I have?

I would recommend this solution to others.

I rate AWS WAF a seven out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
reviewer1234011 - PeerSpot reviewer
Cloud architect at a tech vendor with 1-10 employees
Real User
Jan 16, 2022
Good integration with AWS services, and no installation is required
Pros and Cons
  • "This is not a product that you need to install. You just use it."
  • "Overall, this is a good product and I recommend it."
  • "I would like to see it more tightly integrated with other AWS services."
  • "I would like to see it more tightly integrated with other AWS services."

What is our primary use case?

We use this product for our web application firewall. It is used for production services.

I am not a direct customer but I have installed it for one of my clients.

What is most valuable?

The most valuable feature is that it is integrated with other AWS services.

What needs improvement?

I would like to see it more tightly integrated with other AWS services.

For how long have I used the solution?

I have been working intermittently with AWS WAF over the past two years.

What do I think about the scalability of the solution?

AWS WAF is extremely scalable.

At this point, we don't have any plans to increase our usage of it.

Which solution did I use previously and why did I switch?

Prior to AWS WAF, I was using a Cisco web application firewall. However, when I started using AWS, I switched.

How was the initial setup?

This is not a product that you need to install. You just use it.

The only people that need to work with it are those who configure it.

What's my experience with pricing, setup cost, and licensing?

You need an additional AWS subscription for this product if you are buying a managed tool.

What other advice do I have?

Overall, this is a good product and I recommend it. My advice for anybody who is just getting started with it is to follow the instructions.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1230804 - PeerSpot reviewer
Principal Cloud Architect at a tech services company with 51-200 employees
Real User
Jan 13, 2022
Beneficial cloud service, flexible on-demand features, but requires better security
Pros and Cons
  • "The most valuable features of AWS WAF are its cloud-native and on-demand."
  • "AWS WAF is pay-as-you-go, I only pay for what I'm using; there is no subscription or any payment upfront, and I can terminate use at any time, which is an advantage."
  • "The solution could improve by having better rules, they are very basic at the moment. There are more attacks coming and we have to use third-party solutions, such as FIA. The features are not sufficient to prevent all the attacks, such as DDoS. Overall the solution should be more secure."
  • "The solution could improve by having better rules, they are very basic at the moment."

What is our primary use case?

We use AWS WAF to prevent cyberattacks, such as SQL Injection attacks and cross-site scripting attacks. The end users' traffic has more threats and the web application gives good support.

What is most valuable?

The most valuable features of AWS WAF are its cloud-native and on-demand.

Any customer can leverage AWS WAF immediately, it has a basic set of rules that are available.

What needs improvement?

The solution could improve by having better rules, they are very basic at the moment. There are more attacks coming and we have to use third-party solutions, such as FIA. The features are not sufficient to prevent all the attacks, such as DDoS. Overall the solution should be more secure.

For how long have I used the solution?

I have been using AWS WAF for approximately four years.

What do I think about the stability of the solution?

This is a very stable solution.

What do I think about the scalability of the solution?

AWS WAF is scalable.

We have approximately five customers using this solution.

How are customer service and support?

The technical support is very good. They are responsive and knowledgeable, they have always come back with a resolution or a workaround to help us.

How was the initial setup?

The initial setup took approximately 15 mins, it is easy.

What about the implementation team?

We have a team that does the support for the solution.

What's my experience with pricing, setup cost, and licensing?

AWS WAF is pay-as-you-go, I only pay for what I'm using. There is no subscription or any payment upfront, I can terminate use at any time. Which is an advantage.

What other advice do I have?

The first version of AWS WAF was not mature but the second version is very mature.

I would recommend this solution to others because instead of choosing a third-party solution which will take time, and you will have to be in negotiations. It is good to start with AWS WAF for their minimal primary security firewall to save their workload. AWS WAF is available on-demand from day one.

I rate AWS WAF a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
it_user1556748 - PeerSpot reviewer
Jefe subdepartamento Operaciones at a government with 10,001+ employees
Real User
May 6, 2021
Reasonably priced, stable, and offers excellent performance
Pros and Cons
  • "Their technical support has been quite good."
  • "The performance is excellent."
  • "We haven't faced any problems with the solution."

What is our primary use case?

I primarily use the solution as a gateway service and a transaction portal. 

What is most valuable?

We haven't had any issues with the solution so far.

The pricing of the product is very good. They make it very reasonable and it's very easy to afford.

Their technical support has been quite good.

The performance is excellent. It's reliable.

We've found the solution to be quite stable.

What needs improvement?

We haven't faced any problems with the solution. I can't speak to any missing features. Every aspect of it has been quite good.

For how long have I used the solution?

I've been using the solution for a while.

What do I think about the stability of the solution?

The stability has been very good. We've enjoyed a very reliable performance. There are no bugs or glitches. It doesn't crash or freeze. It's been good.

How are customer service and technical support?

Technical support has been quite good. We've found them helpful and responsive. We are quite satisfied with the level of support that is provided to us.

What's my experience with pricing, setup cost, and licensing?

The solution is very reasonably priced. 

What other advice do I have?

I'm just a customer and an end-user. I don't have a business relationship or partnership with AWS.

I have pretty good experience in AWS. I have a certificate in AWS.

I'd rate the solution at a ten out of ten. We've been extremely satisfied with the solution.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free AWS WAF Report and get advice and tips from experienced pros sharing their opinions.