Try our new research platform with insights from 80,000+ expert users

AWS WAF vs F5 Distributed Cloud Services comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (1st), WAN Optimization (4th), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (13th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Web Application Firewall (WAF) (3rd)
F5 Distributed Cloud Services
Average Rating
10.0
Reviews Sentiment
7.1
Number of Reviews
2
Ranking in other categories
CDN (10th), Web Application Firewall (WAF) (19th), API Security (6th)
 

Featured Reviews

HA
Owner at Hga consulting
Has helped manage client domains with streamlined access control and threat visibility
I don't know what areas could be improved with Cloudflare WAF; Cloudflare is constantly improving and adding features to their feature set. They're doing a good job, and as far as DNS and support for any domains that I create or my clients create, it's mandatory for me to make sure that they have Cloudflare as their DNS provider. The Cloudflare load balancing capability hasn't really helped in enhancing my website's uptime and resiliency because we don't really get that much traffic; it's mostly remote users, and web hosting is done by a web hosting service. It doesn't pay to try to host your own website.
Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
FM
IT Analyst at Atlas.cz, a.s.
Protects web applications with comprehensive security features
All features are valuable. In a multi-cloud or distributed cloud, there are many protection possibilities from data to web application or API protection, including bot mitigation. This is a comprehensive package for web application security. The main benefit is Web App Security, offering a complete security package from DDoS to web application firewall, API protection, and bot mitigation.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Easier http to https redirect using page rules"
"Its ease of integration with Office 365 and the fact that it's a good product compared to what I had before"
"It's a great product because it's scalable, has great coverage, and is mature with good defenses against DDoS attacks."
"The solution is very good at mitigating threats."
"From what I've seen so far, there are no negatives to report as of yet"
"The UI is good."
"It is a stable solution. I rate the stability a ten out of ten...I rate the scalability a ten out of ten."
"The web application firewall brought us good security and a view of the accesses/blocks of the entire domain and subdomain that were accessed both by region (country) and IPs."
"The most valuable feature is the capability to limit access based on geographical location by restricting specific IP addresses."
"The access instruction feature is the most valuable. This is what we use the most."
"The interface is good."
"The security firewall plus the features that protect against database injections or scripting,"
"We integrate AWS WAF with several platforms within cloud hosting and other security solutions and provisions in our business. Regarding AI, it's been around for about 20 years, so it's not new. It's just a new buzzword. I've been in security for 30 years and remember using AI when I started 25-30 years ago. We have multiple forms of AI within our business."
"The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors."
"AWS has flexibility in terms of WAF rules."
"The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections."
"The main benefit is Web App Security, offering a complete security package from DDoS to web application firewall, API protection, and bot mitigation."
"F5 is known for being the best load balancer in the market. Customers with an existing module can easily adopt additional modules without investing in new hardware."
"In a multi-cloud or distributed cloud, there are many protection possibilities from data to web application or API protection, including bot mitigation."
 

Cons

"Technical support is not well developed. While there are good engineers, Cloudflare does not offer hands-on technical support to fix customer problems but rather a self-service model."
"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"Cloudflare could be improved by introducing a mid-tier pricing option."
"I believe they currently have this feature, but there will most likely be integration with APIs so we can control some features through API."
"Support response time could be improved."
"We are a product integrator and reseller, and we would like to have a better partner relationship, similar to a channel sales relationship. Sometimes we are on our own or get diverted by Cloudflare because they have direct sales, which competes with us and makes it difficult to build a relationship with this company since we want to be an MSP or a managed service provider for the solution."
"Latencies are always a problem."
"We haven't faced any problems with the solution."
"In a future release I would like to see automation. There's no interaction between the applications and that makes it tedious. We have to do the preparation all over again for each of our other applications."
"An improvement area would be that it's more of a manual effort when you have to enable rules. That's one of the downsides. If that can be done in an automated way, it would be great. That's a lagging feature currently."
"The serverless product from AWS WAF could be improved. For example, they have only one serverless series, Lambda, but they should extend and improve it. Additionally, the firewall rules are not very easy to configure."
"Technical support for AWS WAF needs improvement."
"The solution is cloud-based, and therefore the billing model that comes with it could be more intuitive, in my opinion. It's very easy to not fully understand how you tag things for billing and then you can quite easily run up a high bill without realizing it. The solution needs to be more intuitive around the tagging system, which enables the billing. Right now, I have a cloud architect that does that on our behalf and it isn't something that a business user could use because it still requires quite a lot of technical knowledge to do effectively."
"For now, there is no feature to protect against attack of the bad bots"
"They should make the implementation process faster."
"The pricing could be adjusted to better meet the needs of typical customers in regions like Poland, where the product is considered too expensive."
"The main issue is integration with other parts or products of F5, like on-premise WAF."
"The main issue is integration with other parts or products of F5, like on-premise WAF. There are some problems, mainly from the perspective of implementation and customer expectations, which sometimes differ from reality."
 

Pricing and Cost Advice

"That is one of the great features. I was able to access the majority of the features and services for free."
"We are using the free version."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"I give the price a five out of ten."
"We are using the free tier of the solution."
"The price is reasonable."
"The product's pricing is cheap."
"The tool is a premium product, so it is very expensive."
"There are different scale options available for WAF."
"AWS WAF has reasonable pricing."
"Its price is fair. There is a very fair amount that they charge. It has a pay-as-you-go model, so it pretty much depends on how much a user uses it. As per the cloud norms, the more you use, the more you pay. I would rate it a five out of ten in terms of pricing."
"I would rate AWS WAF's pricing a seven out of ten."
"For our infrastructure, we probably pay around $16,000 per month for AWS WAF. Because alternative WAF solutions provide even more features, I think the AWS WAF is a bit pricey"
"The price of AWS WAF is reasonable, it is not expensive and it is not cheap."
"AWS is not that costly by comparison. They are maybe close to $40 per month. I think it was between $29 or $39."
"It's cheap."
Information not available
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
879,259 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Government
6%
Computer Software Company
14%
Financial Services Firm
12%
Insurance Company
8%
Manufacturing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise26
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What is your experience regarding pricing and costs for F5 Distributed Cloud Services?
I am not involved in sales, so I do not deal with the pricing aspect directly. I give the cost of the solution a four...
What needs improvement with F5 Distributed Cloud Services?
It's a long way to be perfect, of course, as with all solutions. The main issue is integration with other parts or pr...
What is your primary use case for F5 Distributed Cloud Services?
There are two main use cases for Distributed Call Services: DDoS or Distributed attacks protection and WAF web applic...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
Information Not Available
Find out what your peers are saying about AWS WAF vs. F5 Distributed Cloud Services and other solutions. Updated: December 2025.
879,259 professionals have used our research since 2012.