

AWS WAF and F5 Advanced WAF are leading competitors in the web application firewall market. While AWS WAF offers a cost-effective, scalable cloud-native solution that's easily deployable, F5 Advanced WAF is favored for its advanced protection features and comprehensive security capabilities.
Features: AWS WAF provides scalability, ease of use, and integration with AWS services, allowing quick deployment and rule management. F5 Advanced WAF offers anti-bot protection, DDoS protection, and advanced configuration options, excelling in behavior analysis and traffic learning.
Room for Improvement: AWS WAF could benefit from better automation, third-party integrations, and more thorough documentation. Enhancements in support for user-defined rules and a more predictable pricing model are also desired. F5 Advanced WAF has room to improve its interface and reporting features, integration capabilities, and policy configuration simplicity, along with adopting more transparent pricing models.
Ease of Deployment and Customer Service: AWS WAF is praised for its easy deployment within AWS's ecosystem, though support varies in depth and speed. F5 Advanced WAF, often deployed on-premises or in hybrid models, provides good customer service but faces challenges with initial deployment complexity.
Pricing and ROI: AWS WAF's pay-as-you-go pricing is attractive for its affordability and flexibility, although unexpected costs can occur with increased usage. F5 Advanced WAF is more expensive, aligning with its extensive feature set. Despite higher costs, it is suited for high-demand environments, providing ROI in enterprise setups, whereas AWS WAF is seen as budget-friendly with scalable costs.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
Time savings in daily operations come from the automatic learning and signature update reducing the need for constant manual rule management, allowing the security and network teams to spend significantly less time handling false positive application-related escalations.
Subscription models offer clearer ROI due to a more competitive pricing scheme.
The amount of attacks it protects against is immense, more than F5 Advanced WAF itself costs.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
Both response time and availability need to be improved.
While they resolve issues well, the time taken for responses to non-critical issues should be shorter.
If there is a bug, the support is usually understanding and resolves issues.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
If you need to scale up, such as moving from a lower model to a higher one, the configuration from the lower model can be migrated easily without issues.
I can run it in HA mode or even divide the traffic volume to the number of instances that I have based on their resource sizing.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
We faced issues with AWS WAF when writing the custom rules.
F5 Advanced WAF has been very reliable and consistent for us; in our on-premise enterprise setup, it has been stable and predictable in day-to-day operations without any unexpected crashes or WAF-related downtime in production.
F5 Advanced WAF is stable, and there is no doubt it is one of the best WAFs in the market.
F5 Advanced WAF is pretty stable.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
The level of granularity is not great, and as you cross a certain threshold, the cost goes up by twenty or thirty percent every time.
Deployment training for F5 Advanced WAF is lacking and restricts growth by being inaccessible and costly for partners.
Overall, these are not blockers, merely enhancement opportunities, and once tuned, F5 Advanced WAF is very stable and reliable; improving usability, reporting, and onboarding would make it even more effective for larger environments.
Another improvement could be refining the bot detection to minimize false positives; it should be able to verify more granularly between legitimate and non-legitimate clients.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Licensing is capacity-driven, so you need careful planning based on traffic volume and use cases, and adding features such as Bot Protection impacts costs; once licensing is clear and sized correctly, there are no surprises.
Subscription models have competitive pricing, while perpetual licenses involve an upfront higher cost.
The price is affordable and satisfactory.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
The specific outcomes showing how AWS WAF has helped our organization include improving our security posture by reducing the attack surface and reducing malicious attacks.
The Advanced Attack Signature database is very strong and regularly updated, effectively blocking SQL injections, cross-site scripting, command injections, and file inclusion attacks while allowing selective enabling or disabling of signatures to avoid blocking genuine traffic.
The perpetual license, despite an initial higher cost, lacks transparency regarding support expiration.
It contains the logic of both negative and positive security combined.
| Product | Mindshare (%) |
|---|---|
| F5 Advanced WAF | 3.6% |
| AWS WAF | 3.9% |
| Other | 92.5% |

| Company Size | Count |
|---|---|
| Small Business | 22 |
| Midsize Enterprise | 12 |
| Large Enterprise | 28 |
| Company Size | Count |
|---|---|
| Small Business | 27 |
| Midsize Enterprise | 16 |
| Large Enterprise | 31 |
AWS WAF provides configurable rules, integration with AWS services, and scalable protection against web threats like SQL injections and DDoS attacks. Its automation and reliable performance are highly valued by users.
AWS WAF is a web application firewall offering significant security features like geo-restriction, custom rules, and IP filtering. Designed for seamless orchestration within AWS environments, it facilitates easy configuration and threat automation. Users benefit from its security policies, enhancing application performance by protecting against threats such as cross-site scripting. Despite its strengths, there is a call for enhanced user interfaces, better documentation, flexible pricing, and improved support. Expanding features like real-time analysis, bot protection, and AI integration can further elevate its utility.
What are the key features of AWS WAF?AWS WAF is extensively used in industries hosting applications on AWS, protecting sensitive data, and monitoring for unauthorized access. Custom and managed rules help cater to infrastructure needs, serving a vital role in maintaining application security across various sectors.
F5 Advanced WAF delivers robust web security with features like signature-based threat protection and behavior analysis, ensuring app stability and security.
F5 Advanced WAF integrates advanced security with functionalities such as SQL injection defense and real-time threat intelligence. It enhances security for applications with load balancing, bot detection, and DDoS protection alongside comprehensive attack monitoring capabilities. Popular among diverse sectors, its usability and easy integration make it a practical choice by providing a stable security infrastructure across both on-premises and cloud environments.
What are the key features?Particularly relevant in banking and financial services, F5 Advanced WAF safeguards applications from threats like SQL injections and DDoS attacks, ensuring compliance and API security. Its capabilities are leveraged for both load balancing and application defense, offering a versatile deployment model suited for protecting critical infrastructure in competitive and demanding industries.
We monitor all Web Application Firewall (WAF) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.