No more typing reviews! Try our Samantha, our new voice AI agent.

AWS WAF vs F5 Advanced WAF comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.7
AWS WAF offers cost-effective security by reducing the need for extra staff and effectively blocking threats.
Sentiment score
7.6
F5 Advanced WAF offers ROI by saving time, reducing costs, enhancing security, and ensuring compliance for businesses.
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
Time savings in daily operations come from the automatic learning and signature update reducing the need for constant manual rule management, allowing the security and network teams to spend significantly less time handling false positive application-related escalations.
Cyber Security Consultant at HR Software Solution
Subscription models offer clearer ROI due to a more competitive pricing scheme.
Global Channel Alliances Lead at a tech vendor with 10,001+ employees
The amount of attacks it protects against is immense, more than F5 Advanced WAF itself costs.
Security Solutions Architect at a consultancy with 1-10 employees
 

Customer Service

Sentiment score
6.6
AWS WAF support is prompt and knowledgeable, but experiences vary in resolution speed and service costs.
Sentiment score
6.9
F5 Advanced WAF's customer service is highly professional and knowledgeable, but response speed and availability need improvement for some users.
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
Security Engineer at a computer software company with 1,001-5,000 employees
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
Both response time and availability need to be improved.
Security Analyst at IBM
While they resolve issues well, the time taken for responses to non-critical issues should be shorter.
Senior Security Systems Engineer at a tech services company with 11-50 employees
If there is a bug, the support is usually understanding and resolves issues.
CEO at CyberApp
 

Scalability Issues

Sentiment score
7.5
AWS WAF is highly scalable, versatile for various infrastructures, but some users desire expanded features for broader adaptability.
Sentiment score
7.5
F5 Advanced WAF is scalable, efficiently handling large traffic, praised for flexibility, and easily upgraded to meet user needs.
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
If you need to scale up, such as moving from a lower model to a higher one, the configuration from the lower model can be migrated easily without issues.
Senior Security Systems Engineer at a tech services company with 11-50 employees
I can run it in HA mode or even divide the traffic volume to the number of instances that I have based on their resource sizing.
Security Solutions Architect at a consultancy with 1-10 employees
 

Stability Issues

Sentiment score
8.3
AWS WAF is stable, effectively blocking threats, with minor issues in custom rules, and continuous improvements enhance reliability.
Sentiment score
8.4
F5 Advanced WAF is highly reliable and stable, rarely facing downtime, with user ratings of 8-10 for performance.
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
Security Engineer at a computer software company with 1,001-5,000 employees
We faced issues with AWS WAF when writing the custom rules.
Infrastructure Lead at Danat Fz LLC
F5 Advanced WAF has been very reliable and consistent for us; in our on-premise enterprise setup, it has been stable and predictable in day-to-day operations without any unexpected crashes or WAF-related downtime in production.
Cyber Security Consultant at HR Software Solution
F5 Advanced WAF is stable, and there is no doubt it is one of the best WAFs in the market.
Senior Security Systems Engineer at a tech services company with 11-50 employees
F5 Advanced WAF is pretty stable.
Security Solutions Architect at a consultancy with 1-10 employees
 

Room For Improvement

AWS WAF requires enhanced features, security, user interface, documentation, seamless integrations, and added automation for improved effectiveness.
F5 Advanced WAF needs improvements in pricing, usability, API protection, bot detection, deployment, and advanced integration features.
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
Security Engineer at a computer software company with 1,001-5,000 employees
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Infrastructure Lead at Danat Fz LLC
The level of granularity is not great, and as you cross a certain threshold, the cost goes up by twenty or thirty percent every time.
Security Engineer Dev Sec Ops at a outsourcing company with 1,001-5,000 employees
Deployment training for F5 Advanced WAF is lacking and restricts growth by being inaccessible and costly for partners.
Global Channel Alliances Lead at a tech vendor with 10,001+ employees
Overall, these are not blockers, merely enhancement opportunities, and once tuned, F5 Advanced WAF is very stable and reliable; improving usability, reporting, and onboarding would make it even more effective for larger environments.
Cyber Security Consultant at HR Software Solution
Another improvement could be refining the bot detection to minimize false positives; it should be able to verify more granularly between legitimate and non-legitimate clients.
Senior Security Systems Engineer at a tech services company with 11-50 employees
 

Setup Cost

AWS WAF pricing is seen as affordable but can be costly in high-demand scenarios like DDoS attacks.
Enterprise buyers find F5 Advanced WAF's pricing high but justified in banking, with complex licensing and higher setup costs.
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
Security Engineer at a computer software company with 1,001-5,000 employees
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Infrastructure Lead at Danat Fz LLC
Licensing is capacity-driven, so you need careful planning based on traffic volume and use cases, and adding features such as Bot Protection impacts costs; once licensing is clear and sized correctly, there are no surprises.
Cyber Security Consultant at HR Software Solution
Subscription models have competitive pricing, while perpetual licenses involve an upfront higher cost.
Global Channel Alliances Lead at a tech vendor with 10,001+ employees
The price is affordable and satisfactory.
CEO at CyberApp
 

Valuable Features

AWS WAF enhances security with configurable rules, seamless AWS integration, scalability, and ease of deployment for threat protection.
F5 Advanced WAF offers robust application security with bot protection, DDoS mitigation, and customizable threat detection for improved efficiency.
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
Infrastructure Lead at Danat Fz LLC
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
Dev Ops Engineer at a tech vendor with 1,001-5,000 employees
The specific outcomes showing how AWS WAF has helped our organization include improving our security posture by reducing the attack surface and reducing malicious attacks.
Senior Cloud Security at a healthcare company with 5,001-10,000 employees
The Advanced Attack Signature database is very strong and regularly updated, effectively blocking SQL injections, cross-site scripting, command injections, and file inclusion attacks while allowing selective enabling or disabling of signatures to avoid blocking genuine traffic.
Cyber Security Consultant at HR Software Solution
The perpetual license, despite an initial higher cost, lacks transparency regarding support expiration.
Global Channel Alliances Lead at a tech vendor with 10,001+ employees
It contains the logic of both negative and positive security combined.
CEO at CyberApp
 

Categories and Ranking

AWS WAF
Ranking in Web Application Firewall (WAF)
8th
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
63
Ranking in other categories
No ranking in other categories
F5 Advanced WAF
Ranking in Web Application Firewall (WAF)
3rd
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
72
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2026, in the Web Application Firewall (WAF) category, the mindshare of AWS WAF is 3.9%, down from 6.9% compared to the previous year. The mindshare of F5 Advanced WAF is 3.6%, down from 8.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
F5 Advanced WAF3.6%
AWS WAF3.9%
Other92.5%
Web Application Firewall (WAF)
 

Featured Reviews

Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
reviewer2797602 - PeerSpot reviewer
Senior Security Systems Engineer at a tech services company with 11-50 employees
Granular security policies have protected critical applications and ensure safe user and admin access
Improvements could be made regarding the log information from the backend CLI. There are enhancements needed; if a request gets blocked on the TCP layer, there should be traces or data to verify which source generated these requests, including the source and port information for initiation. These data are missing from F5 Advanced WAF. Besides that, another improvement could be refining the bot detection to minimize false positives; it should be able to verify more granularly between legitimate and non-legitimate clients. Overall, I find everything else good. A wish list feature I have is for the Technical Assistance Center (TAC) to respond more promptly. Their response time needs improvement; while they do not take excessive time, it can be enhanced, especially given it is a security product.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
911,994 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
9%
Comms Service Provider
7%
Computer Software Company
7%
Financial Services Firm
15%
Comms Service Provider
9%
Computer Software Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise28
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise16
Large Enterprise31
 

Questions from the Community

What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Imperva WAF 2. F5 WAF 3. Polarisec Cloud WAF Typical limitations on cloud WAF is t...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft Azure Application Gateway web application firewall software was the better fit ...
What is your experience regarding pricing and costs for AWS WAF?
AWS WAF is affordable; it depends on the number of rules you apply. The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
What is your experience regarding pricing and costs for F5 Advanced WAF?
F5 Advanced WAF is somewhat costly compared to other vendors, but it is worth the investment due to the stability it provides to the environment and infrastructure.
What needs improvement with F5 Advanced WAF?
Improvements could be made regarding the log information from the backend CLI. There are enhancements needed; if a request gets blocked on the TCP layer, there should be traces or data to verify wh...
What is your primary use case for F5 Advanced WAF?
My main use case for F5 Advanced WAF is to protect external and internal applications from cyber attacks and to prevent malicious payloads and malicious data from reaching servers. Even if maliciou...
 

Also Known As

AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

eVitamins, 9Splay, Senao International
MAXIMUS, Vivo, American Systems, Bangladesh Post Office, City Bank
Find out what your peers are saying about AWS WAF vs. F5 Advanced WAF and other solutions. Updated: August 2026.
911,994 professionals have used our research since 2012.