Cloudflare DDoS protects against bots and DDoS attacks. I'm using the free version for my personal website.
IT Associate at GNRC Hospitals
The rate limiting feature helps restrict unwanted requests
Pros and Cons
- "The best feature is rate limiting. If I'm expecting 500 visits per hour, Cloudflare will limit the requests if I suddenly get 50,000."
- "The free plan has limitations. For example, I can only set up three rules, and the application firewall is unavailable."
What is our primary use case?
What is most valuable?
The best feature is rate limiting. If I'm expecting 500 visits per hour, Cloudflare will limit the requests if I suddenly get 50,000.
What needs improvement?
The free plan has limitations. For example, I can only set up three rules, and the application firewall is unavailable.
For how long have I used the solution?
I have used Cloudflare DDoS for about a year.
Buyer's Guide
Cloudflare One
June 2025

Learn what your peers think about Cloudflare One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
How was the initial setup?
The initial setup isn't difficult. When a user signs up for a Cloudflare account and adds domains, it automatically deploys basic protection.
What other advice do I have?
I rate Cloudflare DDoS 10 out of 10. Before you opt for Cloudflare DDoS, you should understand that every cloud provider includes DDoS. If you are hosting your services in AWS, Google Cloud, or Microsoft Azure, you already have DDoS, so secondary protection isn't necessary.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

An all-in-one solution that protects against attacks of all sizes
Pros and Cons
- "It will take the blow rather than our applications should an attack occur."
- "The initial onboarding was causing us some confusion."
What is our primary use case?
I'm just using the bare minimum amount of DDoS Protection out of the tier we use. We're a pretty small company, so we haven't been the target of any major DDoS attacks yet. That's why so far the basic DDoS is all we need.
If your company uses Cloudflare, then everyone in your environment inherits DDoS protection.
There is no such thing as maintaining this solution — everything is baked into it. Unless of course, you want to pay for the enterprise tier. Then maybe you could gain access to extra DDoS Protection.
How has it helped my organization?
In the case of an attack, Cloudflare provides an extra layer of security in front of our application server. It will take the blow rather than our applications should an attack occur. That's the whole idea. They protect us with this extra cushion.
What is most valuable?
We mostly use Cloudflare WAF, and gets basic Cloudflaire DDoS, caching as extra bonus . We like the factor these features are all integrated into 1 console, simple to manage. They work flawlessly in the background, nearly invisible to us.
What needs improvement?
The initial onboarding was causing us some confusion. Who's going to do what and what steps need to be taken? Once we got through it once, it became a no-brainer. At this point, I'm pretty happy with Cloudflare. Everything is straightforward once you've figured it out initially. It's just the very first day that can be a little confusing.
I recently sent some feedback to the company. There are thousands of rules in their WAF product, and I just wish I could have better insight. Right now, it's very superficial. You turn a radio button on or off for their rules, but when there's troubleshooting going on, it's very hard to figure out what's causing the rules to get triggered. With each rule, there may be hundreds to thousands of rules underneath it that are enabling the blocking.
Luckily for me, so far it hasn't occurred enough that it has required me to dig deep to figure out why or how to bypass it, but I could see this occurring a lot in a complex environment. It only happened to us three times, and I was always able to figure out a way to get through it.
For how long have I used the solution?
I have been using Cloudflare DDoS for roughly six months.
What do I think about the stability of the solution?
It's been very stable. Before we brought our server on behind Cloudflare, there was a reported outage which made us extremely concerned. However, since we've been onboarded, we have not noticed any downtime with Cloudflare.
What do I think about the scalability of the solution?
It's extremely scalable. That's the whole reason we use Cloudflare.
How are customer service and technical support?
Support has been good so far. Just the initial headache of onboarding. After onboarding, there was some tuning involved. We worked closely with support to get through that. Once we got the gist of it, we didn't really require support anymore. It's become very low maintenance.
Which solution did I use previously and why did I switch?
We are using AWS — that's our infrastructure. The only thing we compared on paper was the native AWS DDoS Protection. The reason we selected Cloudflare, is because it provides us with an extra security layer in front of our applications. It has all the security features built into one platform rather than managing different pieces. With AWS-native tools, I have to select AWS Web or AWS DDoS Protection. There are individual components I have to install and manage. With Cloudflare, because it's an all-in-one platform, everything is much easier.
What's my experience with pricing, setup cost, and licensing?
At this point, considering the size of our company and the traffic we have seen, there is no need for us to pay extra for the enterprise tier. That's our current state. Things could change; we'll have to wait and see. As our company grows and as we become more successful, it may attract more attacks.
If you were to just use a native AWS tool, it may be a little bit cheaper. But considering the headache of spending more time to figure out how to install and manage the individual pieces, cost-wise, I think Cloudflare would be the cheaper option.
What other advice do I have?
Before implementing this solution, consider the size of the individual company: their cost budget, their budget range, and their specific needs. What are they looking for? If you're looking for an all-in-one security tool with DDoS, WAF, and rate control, all in one package for a low price, Cloudflare seems to fit pretty well. It really depends on the individual company — what their application is based on.
Take TikTok for example. TikTok has heavy traffic laws, so their security needs will be very different from my company's needs. We're low profile, we don't generate tons of traffic. So, it really depends on your environment, your budget, all of those things.
Overall, on a scale from one to ten, I would give this solution a rating of nine.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Cloudflare One
June 2025

Learn what your peers think about Cloudflare One. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
856,873 professionals have used our research since 2012.
CTO at a retailer with 11-50 employees
Comes with better security, deployment, and scalability
Pros and Cons
- "Cloudflare DDoS is better than its competitors for its security, deployment, and scalability."
- "The tool should provide on-premise versions. Currently, all versions are cloud-based."
What is our primary use case?
We use the product for DNS security and DDoS.
What is most valuable?
Cloudflare DDoS is better than its competitors for its security, deployment, and scalability.
What needs improvement?
The tool should provide on-premise versions. Currently, all versions are cloud-based.
For how long have I used the solution?
I have been using the solution for six months.
How are customer service and support?
Cloudflare is a customer-oriented company and offers solid support.
How would you rate customer service and support?
Positive
How was the initial setup?
The tool's deployment is complex. I rate it a three out of ten.
What other advice do I have?
I rate the tool an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CTO at a tech services company with 51-200 employees
The solution mitigates DDoS attacks but provides poor technical support
Pros and Cons
- "Cloudflare DDoS mitigates DDoS attacks."
- "Cloudflare DDoS has poor technical support."
What is most valuable?
Cloudflare DDoS mitigates DDoS attacks.
What needs improvement?
Cloudflare DDoS mitigates DDoS attacks mostly by distributing the attacks through their network, which means many of their PoPs will hit your servers. When you have a huge DDoS attack, Cloudflare DDoS will stop the attack after some time. Until then, it will just register the DDoS attack through their network because they have a huge network, and then all those PoPs will hit your servers.
Cloudflare DDoS has poor technical support.
For how long have I used the solution?
I have been using Cloudflare DDoS for five years.
What do I think about the scalability of the solution?
More than 10,000 users are using Cloudflare DDoS in our company.
Which solution did I use previously and why did I switch?
I previously used F5.
What's my experience with pricing, setup cost, and licensing?
The solution's pricing lacks transparency. You never know what you're paying for, and even their team sometimes cannot give you a correct answer on how they calculate something.
What other advice do I have?
Overall, I rate Cloudflare DDoS a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Cloudflare One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Secure Access Service Edge (SASE) Email Security Secure Web Gateways (SWG) Data Loss Prevention (DLP) Cloud Access Security Brokers (CASB) Distributed Denial-of-Service (DDoS) Protection Access Management Bot Management ZTNA as a Service ZTNA Remote Browser Isolation (RBI)Popular Comparisons
Microsoft Defender for Office 365
Microsoft Entra ID
Cisco Umbrella
Darktrace
Prisma Access by Palo Alto Networks
Zscaler Internet Access
Zscaler Zero Trust Exchange Platform
Lookout
Proofpoint Email Protection
Netskope
Microsoft Exchange Online Protection (EOP)
Microsoft Purview Data Loss Prevention
Cato SASE Cloud Platform
Cisco Secure Email
Buyer's Guide
Download our free Cloudflare One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What security features does Cloudflare Bot Management provide to protect against malicious bot traffic?
- What are fullz and how can Cloudflare Bot Management help our company mitigate their misuse?
- Why is Cloudflare deprecating Railgun if it's their own product?
- What is the difference between point solutions (SD-WAN, NGFW, SWG, VPN) and SASE?
- What questions do you need to ask when choosing a Secure Access Service Edge (SASE) solution?
- When evaluating Secure Access Service Edge (SASE), what aspect do you think is the most important to look for?
- Has anyone ever heard of secureaccess.com?
- What is the difference between SASE and SD-WAN?
- What is the difference between SASE and CASB?
- What SASE solution does your company use?