We are using Cloudflare for two purposes. The first is for our in-house self-service platform to manage all customers, and the second is for reselling.
Head of Cloud & Cyber Security Services (Garaj) at a comms service provider with 1,001-5,000 employees
Easy-to-scale product with efficient integration feature
Pros and Cons
- "The integration of Cloudflare with Cloud Suite is its most valuable feature."
- "If they add logs history within the Cloudflare offering, that would be a great benefit."
What is our primary use case?
What is most valuable?
The integration of Cloudflare with Cloud Suite is its most valuable feature. This is where it stands out, as it can be integrated according to multiple scenarios.
What needs improvement?
The first one is the log management and reporting part. If they add logs history within the Cloudflare offering, that would be a great benefit.
There are a few features that come free with Cloudflare WAF, such as bot management. When users use it they ask for a fee. Users are not usually aware of these features in the initial phase. Users should know that these features are free for three or four months, and after that, they have to pay for them. This would help to align their expectations from the very first day.
There should be training modules that we use for our sales teams and product experts similar to Fortinet and VMware.
For how long have I used the solution?
I have been using Cloudflare Web Application Firewall for three months.
Buyer's Guide
Cloudflare Web Application Firewall
July 2025

Learn what your peers think about Cloudflare Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
864,053 professionals have used our research since 2012.
What do I think about the stability of the solution?
I rate the product’s stability an eight out of ten.
What do I think about the scalability of the solution?
Cloudflare Web Application Firewall is easy to scale. As users scale it, it integrates more features, but they may have to pay for these additional features. It is challenging to convince smaller companies that are using open-source solutions. Upon comparison, Cloudflare's features stand out over open-source solutions, but the cost element is still the factor people are most concerned about.
How are customer service and support?
The technical support is good.
How was the initial setup?
The initial setup of the product is simple because we have a good technical team that can manage it. We reach out to small companies if they don't have that sort of technical expertise to see if they can easily integrate it.
What other advice do I have?
Overall, I rate Cloudflare Web Application a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller

Network Security Manager at a computer software company with 201-500 employees
Provides ready-to-use policies with little configuration and easy integration
Pros and Cons
- "Cloudflare WAF provides protection through rules and functionalities like Cloudflare's SDRAP."
- "Support can be challenging at times."
What is our primary use case?
It is used in the banking sector.
How has it helped my organization?
Cloudflare WAF provides protection through rules and functionalities like Cloudflare's SDRAP. Machine learning enables numerous policies that protect traffic flowing through Cloudflare's CDN and endpoints of the application. Additionally, specific protections are implemented against DDoS attacks and to block suspicious IP addresses attempting to access the sites.
What is most valuable?
Cloudflare provides numerous ready-to-use policies that can be easily enabled with minimal configuration. One such policy is WAF, which includes predefined rulesets for common threats like DDoS attacks. These policies are pre-configured for immediate use, making tuning straightforward. Adjustments may be needed for specific configurations, but the majority are ready to be deployed directly.
What needs improvement?
Support can be challenging at times. Personally, I recently had an issue with costs and contacted support—they promptly resolved my problem. However, understanding features can be more complex. While much information is freely available, for specific needs, professional support might be necessary and could pose difficulties, if there isn't an in-house engineering team. Despite this, Cloudflare facilitates easy development of custom functionalities. Alternatively, engaging with dedicated communities can also yield valuable insights with the right investment of time.
For how long have I used the solution?
I have been using Cloudflare Web Application Firewall as an integrator for one year.
What do I think about the stability of the solution?
Sometimes, as a software vendor, Cloudflare needs to upgrade their software, which can encounter faults but resolve such issues.
I rate the solution's stability an eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable. I rate the solution's scalability a nine out of ten.
How are customer service and support?
It's challenging to find technical expertise, for technical issues. While there is a network for sales, finding knowledgeable technical support can be difficult.
How would you rate customer service and support?
Neutral
What was our ROI?
This level of protection is essential, whether the website is an e-commerce platform or simply a gateway for customers accessing banking services. Maintaining visibility and ensuring the site is consistently up and running are critical requirements for such services.
What other advice do I have?
Integration is quite easy when migrating DNS to Cloudflare, as they manage DNS implementation. Once DNS is set up, traffic redirection to their platform is straightforward. However, it's important to manage your IP addresses carefully, possibly using additional tools or configurations to ensure they are properly protected and directed.
Cloudflare leverages AI-driven solutions, with policies set using machine learning, which forms the foundation of their AI capabilities. They offer AI functionalities for developers looking to optimize or distribute their applications, such as Workers, a serverless solution enabling application deployment without the need for dedicated machines. This setup is also AI-enabled, enhancing its capabilities
Overall, I rate the solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer.
Buyer's Guide
Cloudflare Web Application Firewall
July 2025

Learn what your peers think about Cloudflare Web Application Firewall. Get advice and tips from experienced pros sharing their opinions. Updated: July 2025.
864,053 professionals have used our research since 2012.
Solutions Architect at Amazure Technologies Private Limited
With just the basic understanding of networking and security, one can use this solution easily
Pros and Cons
- "Someone with a basic understanding of networking and security will be able to implement the firewall's basic features within 15 minutes."
- "I have experienced some difficulties with Cloudflare's support as a customer based in India."
What is our primary use case?
I am using Cloudflare Web Application Firewall to develop web applications and mobile applications for a business belonging to the manufacturing industry which wishes to migrate its entire applications from its existing AWS system to Cloudflare.
What is most valuable?
The enterprise bundle includes a variety of features, such as a Web Application Firewall, rate limiting, CDN, DDoS protection, remote management, performance monitoring, and more. It is a really nice product.
What needs improvement?
The additional features I wish to see in the next release include rate limiting on Cloudflare Web Application Firewall and advanced DDoS protection. The current product is highly explorable and does not have many limitations. However, there are some limitations in terms of administrative privileges and the way it manages auto-alerts.
Cloudflare needs to improve its customer support for Indian customers and work on the monitoring and reporting features.
For how long have I used the solution?
I am a reseller and a direct user. I have been working on the enterprise version of Cloudflare Web Application Firewall for the past year.
What do I think about the stability of the solution?
The product is stable, and we have been working with a customer who uses it for their manufacturing and connecting car applications, as well as some API-related systems. The customer was previously using AWS Web Application Firewall. However, they have now decided to switch to Cloudflare. In Cloudflare, the rate-limiting feature helps protect against attacks and mitigates brute-force attacks. The DDoS mechanism automatically defends against DDoS attacks. Cloudflare's Web Application Firewall also has 700 signatures and provides intelligence on 10 vulnerabilities. It offers IP, URI, and domain-based filtering options.
What do I think about the scalability of the solution?
The solution is not deployed in my company, but it is used in the company of one of my customers. The customer I mentioned has around 12,000 users working on this solution. I rate the scalability a 10 out of 10.
How are customer service and support?
I have experienced some difficulties with Cloudflare's support as a customer based in India. Despite the company offering 24/7 support, I feel that administrative support does not meet the expectations of its customers.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I previously worked with an on-premise version of the F5 tool more than five years ago, and at that time, the concept of SaaS was not prevalent. Currently, the Cloudflare product is considered to be a SaaS-based product since they have CDN, which is different from my previous experience with the F5 tool. Since it has been a long time since I worked with the on-premises version, I am unable to provide a relevant comparison between the two.
How was the initial setup?
I find the deployment process for Cloudflare's firewall to be very smooth. Someone with a basic understanding of networking and security will be able to implement the firewall's basic features within 15 minutes. The deployment of a new domain on Cloudflare can be completed within 15 minutes if the necessary administrative authority and support from the DNS team are available during the process. It also includes the time needed for domain registration. We are working for an ITSM organization and have multiple administrators. During the deployment phase of the solution in the organization, we have limited the number of administrators to just five to ten individuals. We also arranged a few KT sessions to help the company employees who are involved in working with this solution. As of now, they have started working on the tool.
What's my experience with pricing, setup cost, and licensing?
In terms of the licensing cost perspective, it is a subscription-based pricing model. Usually, customers opt for a yearly subscription. However, I don't have a specific or exact figure on the actual cost. Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable. The enterprise-level subscription provides multiple options, such as the ability to enable advanced Web Application Firewall and DDoS protection. This means that customers have multiple subscription options.
What other advice do I have?
To effectively use Cloudflare Web Application Firewall, it is important for a person to have an internet connection, an understanding of the internet, how the DNS works, and how websites and their administration domains function. I rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
General Manager at Centralschweizerische Kraftwerke AG
Enhanced security with seamless DNS and zero trust integration
Pros and Cons
- "Some of the most valuable features of Cloudflare Web Application Firewall include its DNS zone setup and the zero trust policy."
- "The dashboard could be more user-friendly."
What is our primary use case?
The primary use case of Cloudflare Web Application Firewall involves setting up DNS zones and implementing zero trust policies.
How has it helped my organization?
Cloudflare Web Application Firewall has enhanced security by effectively managing and cutting off unwanted traffic.
What is most valuable?
Some of the most valuable features of Cloudflare Web Application Firewall include its DNS zone setup and the zero trust policy.
What needs improvement?
The dashboard could be more user-friendly, and a console approach like Cloudflare CLI could enhance its usability.
For how long have I used the solution?
We have been using Cloudflare Web Application Firewall for four years.
What do I think about the stability of the solution?
On a scale from one to ten, the stability of Cloudflare is a nine.
What do I think about the scalability of the solution?
The scalability of Cloudflare is a ten out of ten.
How are customer service and support?
I had to contact technical support twice, and both times, my issues were resolved satisfactorily. Therefore, I rate them a ten out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was straightforward, taking only five minutes using Terraform.
What's my experience with pricing, setup cost, and licensing?
From my perspective, the price of Cloudflare Web Application Firewall is quite affordable, rating around an eight or nine.
What other advice do I have?
I highly recommend Cloudflare Web Application Firewall due to its extensive knowledge base and ease of integration with Terraform.
I'd rate the solution ten out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managed Services Manager at Adapture Technology Group
Custom rules are the best tool and there are many other important sections in Cloudflare WAF, like IP access rules, zone lockdown, and user agent blocking
What is our primary use case?
The main use cases for Cloudflare Web Application Firewall (WAF) are to protect organizations from attacks by bad actors and hackers. We have a process for this, where we first whitelist employees and third-party clusters to prevent attacks.
Then, we divide WAF into three main sections: WAF Protect score, WAF score, and threat score. We also make adjustments based on the specific needs of each organization. These are the general steps at a high level.
Cloudflare WAF is a comprehensive system with many aspects and in-depth documentation that can be tailored to specific client requirements.
The use cases vary depending on the client, whether they are retail or banking sectors, as each has different needs and requirements. We maintain the WAF configurations based on these specific needs.
How has it helped my organization?
There are many incidents we handle daily. We have a large client. We implemented rate limiting and deployed a worker in correlation with the WAF to protect their API endpoints regarding pricing and inventory.
We successfully mitigated a bot attack with that combination of measures for our customer recently. It is one of the successful mitigation.
Cloudflare is very flexible.
What is most valuable?
Cloudflare has many features, but the custom rules are the best tool. There are many fields you can use to protect an organization.
There is also a very good system in the managed toolset, with different parts. One is the Cloudflare Managed Ruleset, which protects the application from malicious signatures.
The second is the OWASP ModSecurity Core Rule Set, which protects from the top ten vulnerabilities and zero-day attacks.
The third is the anomaly detection checks and credential checks, which identify potential threats like leaked credentials.
There are many other important sections in Cloudflare WAF, like IP access rules, zone lockdown, and user agent blocking.
Another important feature is rate limiting, which limits specific requests to prevent attacks like brute force attacks on URLs.
These are some of the important features of Cloudflare WAF.
What needs improvement?
Account-level features would be a very good option. Some clients want to implement the same checks on multiple zones (URLs or websites). Cloudflare recently introduced account-level features, but it's not widely used by clients yet. We are working with Cloudflare on different aspects of zone-level implementation. If account-level features are implemented for certain use cases, it would be a big improvement.
So, pushing more awareness around account-level features would be a plus.
For how long have I used the solution?
I have been using it for three years now.
What do I think about the stability of the solution?
It is a stable product. I would rate the stability a ten out of ten.
How was the initial setup?
It is a technical process, but for us, it is very easy. We have standards and internal scripts that we use for deployment. It is a very easy process on our side because we have been working on it for three years. But for new users, it might require some learning.
I would rate my experience with the initial setup a nine out of ten, with ten being very easy. Cloudflare WAF is only for public URLs, so it is only for public cloud.
Deploying the WAF itself is a click of a button, but implementing it with a company's or client's specific requirements takes time. The process varies from company to company and client to client, but implementation is very simple.
What was our ROI?
WAF doesn't directly affect bandwidth costs. It saves costs on protection. However, with the correct setup, it's difficult to determine if it saves costs overall due to the fixed enterprise plan fee.
The caching system can save bandwidth by caching static content, but WAF itself isn't a major factor in cost savings. There are many other factors involved.
What other advice do I have?
It protects public-facing URLs. That is the biggest advantage.
Overall, I would rate the solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
Senior Solutions Architect at Think Power Solutions
Creates shield between a web app and the Internet & this shield can help mitigate many common attacks as CSF, XSS & SQL Injection. Provides good scalability but has certain limitations on rule define.
Pros and Cons
- "The initial setup process is simple."
- "There could be an option to duplicate the cluster to maintain the consistency of rules."
What is our primary use case?
We use Cloudflare Web Application Firewall for verification of applications from various domains. Also protecting the server from exposure by implementing the Proxy Server feature on front end i.e. on client's side. Also implemented both hosts based & Cloud based WAF.
What needs improvement?
We are required to follow a specific and separate set of rules for web applications for DDoS attacks while working with AWS and Azure. Instead, there could be an option to duplicate the cluster to maintain the consistency of rules.
For how long have I used the solution?
We have been using Cloudflare Web Application Firewall for three to four years.
What do I think about the stability of the solution?
I rate Cloudflare Web Application Firewall's stability a nine out of ten.
What do I think about the scalability of the solution?
It is a scalable platform. Although it lacks some features. We have two to three users for it. I rate its scalability an eight out of ten.
How was the initial setup?
The initial setup process is simple.
What about the implementation team?
I implemented the product myself.
What other advice do I have?
Cloudflare Web Application Firewall has certain limitations for rules. I rate it a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security and Compliance Manager at a tech vendor with 11-50 employees
Improves security posture by blocking bad actors
Pros and Cons
- "The product has improved our security posture by blocking bad actors."
- "The blocked logs are difficult to read at times."
What is our primary use case?
I use Cloudflare Web Application Firewall to stop attacks on web application firewalls.
How has it helped my organization?
The product has improved our security posture by blocking bad actors.
What needs improvement?
The blocked logs are difficult to read at times.
What do I think about the stability of the solution?
I rate the solution's stability a ten out of ten.
What do I think about the scalability of the solution?
I rate the product's scalability a ten out of ten.
How are customer service and support?
I have not used technical support.
How was the initial setup?
Cloudflare Web Application Firewall's deployment was easy.
What was our ROI?
The tool's ROI is pretty immediate.
Which other solutions did I evaluate?
We evaluated the Amazon Web Application Firewall.
What other advice do I have?
I rate the product a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Digital Transformation Department at MERUTE
An easy-to-use solution but its feature for application accessibility need improvement
Pros and Cons
- "It protects web applications efficiently."
- "Its stability could be better."
What is our primary use case?
We use the solution to protect web applications.
What is most valuable?
The solution is easy to use.
What needs improvement?
Sometimes, it is challenging to access our applications using the solution. They should work on this particular area. Also, its availability needs improvement.
For how long have I used the solution?
We have been using the solution for two years.
What do I think about the stability of the solution?
We encounter stability issues regarding the solution's availability to access applications.
What do I think about the scalability of the solution?
We have 200 solution users in our organization. We use it extensively and plan to increase the usage.
How are customer service and support?
We contact our service provider for any technical issues with the solution.
How was the initial setup?
The solution's deployment takes two to three days to complete.
What about the implementation team?
Our service provider helps us install the solution.
What's my experience with pricing, setup cost, and licensing?
The solution is expensive. We purchase a yearly based license for it.
What other advice do I have?
I recommend the solution to others and rate it a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Cloudflare Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2025
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Microsoft Azure Application Gateway
Azure Front Door
F5 Advanced WAF
Fortinet FortiWeb
Imperva Web Application Firewall
Akamai App and API Protector
Azure Web Application Firewall
Radware Alteon
NGINX App Protect
Radware Cloud WAF Service
Check Point CloudGuard WAF
Buyer's Guide
Download our free Cloudflare Web Application Firewall Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- NGFW with URL Filtering vs Web Proxy
- How does a WAF help to protect against DDoS attacks?
- What's right for me? Fortinet or Citrix?