AWS Shield vs Cloudflare SASE & SSE Platform comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

AWS Shield
Ranking in Distributed Denial of Service (DDOS) Protection
6th
Average Rating
8.6
Number of Reviews
6
Ranking in other categories
No ranking in other categories
Cloudflare SASE & SSE Platform
Ranking in Distributed Denial of Service (DDOS) Protection
5th
Average Rating
8.6
Number of Reviews
19
Ranking in other categories
Email Security (15th), Secure Web Gateways (SWG) (9th), Data Loss Prevention (DLP) (10th), Access Management (6th), Bot Management (3rd), ZTNA as a Service (6th), ZTNA (1st), Secure Access Service Edge (SASE) (8th), Remote Browser Isolation (RBI) (1st)
 

Mindshare comparison

As of July 2024, in the Distributed Denial of Service (DDOS) Protection category, the mindshare of AWS Shield is 6.6%, up from 6.5% compared to the previous year. The mindshare of Cloudflare SASE & SSE Platform is 7.2%, up from 5.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Distributed Denial of Service (DDOS) Protection
Unique Categories:
No other categories found
Email Security
1.9%
Secure Web Gateways (SWG)
1.5%
 

Featured Reviews

SteveNg - PeerSpot reviewer
Jan 23, 2023
The solution automatically scales according to traffic, only takes minutes to deploy, and is maintenance-free
The primary use case of the solution is firewall protection. Having a firewall is important for protecting our website from DDoS attacks. Just in case our services are running and we do get attacked, having a firewall can help keep our website alive The solution gives us a better sense of…
FS
May 24, 2024
Protects and regulates access to internal applications based on policies
Cloudflare Access has strong integration with Microsoft, among other platforms. However, when it comes to Kaspersky, we have clients who typically encounter challenges. The usual setup involves configuring a forward proxy, an IDP, and a CASB. Orchestrating these solutions can be challenging if the client already uses a VPN client such as Check Point or Mobile VPN. Clients typically do not replace their VPNs all at once; instead, they gradually phase out the old solution. The interaction between Cloudflare Access and the legacy VPN solution can be complex, particularly ensuring seamless access without introducing new restrictions. This complexity arises not from the product itself but from the nature of migrating to a new system. Migrating ten thousand employees daily is impractical, so a step-by-step approach throughout about a year is often necessary to facilitate a smoother transition.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is integrated with AWS. So, it gives you a good first step."
"I am impressed with the product's multiple features like security."
"The solution's ease of use is the most valuable feature."
"The product has a good mechanism to analyze trends and trigger events."
"The product is easy to use."
"We have integrated the tool with Active Directory. The most important feature is that it's transparent and doesn't degrade the performance of our solution. Additionally, it's easy to configure, which is crucial for us. It's easy to use and set up and stops attacks on our servers. We haven't encountered any attack problems because the solution stops them in real-time. AWS Shield specifically focuses on defending against denial-of-service attacks, making it a great solution for that type of threat."
"For Cloudflare Access, I am using the free plan...The most valuable feature is their protection."
"Cloudflare is simple to use."
"Cloudflare, in my opinion, was easy to implement."
"Cloudflare is by far the most effective solution that I have come across."
"The solution has different options that can be used to differentiate DDoS attacks."
"It's the endpoint exposition. We don't need to expose our VPN server to the internet and need a zero-test solution. I can apply some conditional access to the endpoint that's connecting to our network to check their security policies or the security condition of their workstation. Once the workstation is trying to connect to my internal network, then I would like to check the discrete condition of these endpoints that are trying to access my internal network. We created some conditional access. We have CrowdStrike, to check if the CrowdStrike is installed, to check if it's updated, and to check for Windows updates. We created some conditional policies to check it."
"The simplicity of the solution is its valuable features as almost no effort was needed to learn the configurations. It is also one of the cheapest firewalls available in this category."
"Cloudflare Zero Trust Platform removes the risk of exposing the applications to the public."
 

Cons

"The time taken to detect anomalies must be reduced."
"The product should give users more flexibility to customize their security policies according to their requirements."
"The product needs to improve its logs and reports to make it read better."
"The management of it is a bit hard. If you don't engineer it on the front side, it is hard to go back in and change it. It could be improved in terms of architecture requirements and then ongoing support requirements as a secondary component to it. People tend to set up things like this, and they just expect it to work without the care and feeding that needs to go back into it either from an application team or a network environment team."
"We end up having to pay extra for features that AWS adds that we don't need."
"The product is expensive."
"The free plan has limitations. For example, I can only set up three rules, and the application firewall is unavailable."
"The onboarding process can be improved a little bit."
"There are premium tier live service and lower tier live service, so we opted for the lower tier. But there is no medium tier where we pay a little extra and get a bit more service. So if that can be improved."
"When there are any dynamic changes in complex applications, the tool takes a lot of time, making its analytics-related area a major matter of concern where improvements are needed."
"The response time for support must be reduced."
"For the topic of improvement, providing some training material is one of my suggestions."
"Cloudflare DDoS has poor technical support."
"The tool should provide on-premise versions. Currently, all versions are cloud-based."
 

Pricing and Cost Advice

"The cost depends on traffic each month, so on average, it costs us between US$200 and US$300 per month."
"The tool is cheap."
"It depends on your subscription level and the volume that you're spending with AWS. So, it is very relative to the consumption alignment in your subscription level. It is a well-constructed, scalable pricing option, but it is relative to how much you're spending on AWS. Because the more you spend, typically, the more you get off on services like this. I find it to be comparable to other solutions."
"We pay $3000 per month for the solution."
"The tool's pricing is good."
"The price tag is no longer $200,000, but rather $300,000 to $400,000. It's twice."
"The pricing is somewhere in the middle. I would rate the pricing a seven out of ten."
"The prices are slightly expensive."
"The solution's pricing lacks transparency."
"My company has to make yearly payments towards the licensing costs attached to the solution. There are no hidden charges apart from the licensing costs of the solution."
"Cloudflare Zero Trust Platform's pricing is good."
"The pricing of the solution is cheap. The licensing cost is also very low. I rate the cost and pricing a three out of ten."
"The solution is not that expensive."
report
Use our free recommendation engine to learn which Distributed Denial of Service (DDOS) Protection solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
18%
Manufacturing Company
7%
Insurance Company
6%
Computer Software Company
16%
Financial Services Firm
10%
Manufacturing Company
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about AWS Shield?
We have integrated the tool with Active Directory. The most important feature is that it's transparent and doesn't degrade the performance of our solution. Additionally, it's easy to configure, whi...
What needs improvement with AWS Shield?
The time taken to detect anomalies must be reduced. The tool has a few parameters based on which it tries to understand anomalies. It would be better if the anomalies were identified quickly.
What do you like most about Cloudflare Access?
The tool also offers good scalability, and the dashboard, along with real-time analytics, is very good.
What is your experience regarding pricing and costs for Cloudflare Access?
The price of Cloudflare Access is the same as compared to Akamai, but I get better performance from Cloudflare. My company has to make yearly payments towards the licensing costs attached to the so...
What needs improvement with Cloudflare Access?
Cloudflare Access has strong integration with Microsoft, among other platforms. However, when it comes to Kaspersky, we have clients who typically encounter challenges. The usual setup involves con...
 

Also Known As

No data available
Cloudflare Area 1 Email Security, Cloudflare Bot Management, Cloudflare Gateway, Cloudflare Zero Trust Platform, Cloudflare DDoS
 

Overview

 

Sample Customers

netflix, dow jones, mapbox, pearson, rovio, youview, moviestar planet, asurion, payplug, hour of code
23andMe
Find out what your peers are saying about AWS Shield vs. Cloudflare SASE & SSE Platform and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.