What is our primary use case?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so every employee needs to check DNS requests and network traffic. We have strict network rules and access lists, and we can do triage if we have any data leakage. For that, we are using Datadog SIEM, and we are ingesting all logs from Defender, Azure Defender, Cloudflare Zero Trust into our Datadog SIEM, and then from Datadog SIEM we are doing triage if there is a need.
If we need to investigate a DDoS attack, then we are only using Cloudflare, nothing else.
We are using the rule-based logic feature with Cloudflare Web Application Firewall Zero Trust.
What is most valuable?
The impact of Cloudflare Web Application Firewall's integration with existing web technologies on our site's performance and security measures is quite great, actually. We never know when we have any issues. We are in the gambling business, in the betting business, so we have constant daily DDoS attacks, and it's always working fine.
Cloudflare Web Application Firewall automatically scales. We do not use any other tool from Cloudflare such as Workers, so for scaling, we do everything by ourselves. We don't even use Cloudflare Bot Management because it's too expensive; you need to pay per request, and it's much cheaper to get one or two additional machines.
In terms of metrics for Cloudflare Web Application Firewall effectiveness in mitigating threats, we always measure the number of requests, nothing else. We compare the number of requests that are not good and we have metrics per request that we send to Datadog. That means that we know how many requests came from the public internet to our services and what is the percentage of those requests that should not hit our servers.
What needs improvement?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare.
I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
For how long have I used the solution?
I've been using it in my current company for eight years, not as a consultant.
What do I think about the stability of the solution?
We have zero issues with Cloudflare Web Application Firewall, so it's a 10 out of 10.
Which solution did I use previously and why did I switch?
We tested another WAF solution, Fastly, and one from Amazon, CloudFront. At the end, we were always missing certain features. On Fastly, you need to code everything, and then there was no direct VPN to your network. The same was the case with CloudFront, same issue, and on CloudFront, you're missing advanced features such as URL rewrites and headers. Some features you can do, but you need to create Lambda functions and that will dramatically increase your price.
Which other solutions did I evaluate?
I've just tested F5 Web Application Firewall. We have a proof of concept with F5, the cloud solution, I think it's BIG-IP or something similar. What we found out was quite good. Everything worked okay. We appreciate their option to connect different networks and different data centers; that worked well. The only issue was caching, which was quite hard to configure and not as user-friendly as Cloudflare. But everything else compared to Cloudflare was a Swiss knife for network administrators.
What other advice do I have?
We're not using Cloudflare Workers anymore, but we are dealing with Cloudflare Web Application Firewall, Cloudflare One, Image Resizing, Rate Limiting, Analytics, Load Balancers, and Argo Tunnels.
For Cloudflare Web Application Firewall, we did not try to integrate it with any products, but we did migrate from Azure to AWS.
I purchased Cloudflare directly, not from the AWS Marketplace.
I think the licensing model of Cloudflare is quite reasonable.
I give this review a rating of 10 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?