Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Fastly comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (1st), WAN Optimization (4th), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (12th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Web Application Firewall (WAF) (3rd)
Fastly
Average Rating
8.8
Reviews Sentiment
6.3
Number of Reviews
9
Ranking in other categories
CDN (8th), Web Application Firewall (WAF) (18th), Distributed Denial-of-Service (DDoS) Protection (10th)
 

Featured Reviews

HA
Owner at Hga consulting
Has helped manage client domains with streamlined access control and threat visibility
I don't know what areas could be improved with Cloudflare WAF; Cloudflare is constantly improving and adding features to their feature set. They're doing a good job, and as far as DNS and support for any domains that I create or my clients create, it's mandatory for me to make sure that they have Cloudflare as their DNS provider. The Cloudflare load balancing capability hasn't really helped in enhancing my website's uptime and resiliency because we don't really get that much traffic; it's mostly remote users, and web hosting is done by a web hosting service. It doesn't pay to try to host your own website.
Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
PP
Technical support engineer at Adobe
Optimized ecommerce performance and improved access control through image handling and IP filtering
I believe that Fastly should provide guidelines for their WAF blocking rules. It should be public what the rules are that are blocking their contents. I believe Fastly should provide regional IP addresses instead of POP IPs. Fastly should provide features similar to Cloudflare regarding a block list. Additionally, a POP address should be there with a wide range of IP addresses provided, public static IP addresses, so customers can integrate egress IPs. Fastly should provide WebP image processing on the backend instead of on the fly. It would be a very useful feature to avoid unnecessary time for browser to browser and local cookies. I believe that Fastly service has a few gaps. We are not getting quick responses from Fastly technical support engineers. Sometimes they depend on their D3 developers. There should be transparency.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is very good at mitigating threats."
"The most valuable feature of Cloudflare is the GUI. You are able to control the solution very well through the interface. There is a lot of functionality that is embedded in the service."
"From what I've seen so far, there are no negatives to report as of yet"
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"It is a fast and secure DNS."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"The solution offers the flexibility to control configuration rules."
"It's very user-friendly."
"It is a one-click WAF with no effort needed."
"The most valuable features of AWS WAF are its cloud-native and on-demand."
"The customized billing is the most valuable feature."
"The most valuable feature of AWS WAF is the extra layer of security that I have when connecting to my web applications."
"If hackers try to insert bugs, the tool blocks it."
"We preferred the product based on its cost. AWS WAF is an out-of-the-box solution and integrates with the AWS services that we use. It's natively integrated with AWS."
"AWS WAF has helped to strengthen the security of my environment; it has also helped to improve the posture of our application, prevent all DDoS attacks and unnecessary traffic and SQL injection that is reducing the performance of our application."
"The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors."
"Support is good; the product works as advertised. We have a Slack connection with them. So we can basically ask for help, live, engage, and ring when they respond. Very quickly."
"Rate limiting is a good feature that protects from volumetric attacks."
"Its initial setup process is straightforward."
"Compute@Edge features are valuable to me."
"The product helps our organization to access sites located in different regions quickly."
"Fastly combines both the CDN side and the Signal Sciences next-generation WAF, which is closely integrated with the CDN, allowing us to use both products seamlessly."
"Fastly uses configuration versioning, where you can deploy a new version in less than one minute."
"Fastly provides CDN, WAF, image optimization, and IP restriction."
 

Cons

"It should confirm audit findings of the assigned area with auditees to ensure that the audit conclusions are based on an accurate understanding of the issues."
"Cloudflare doesn't have a reverse lookup. We can only do a DNS lookup to get the IP address from the hostname. It doesn't work if you want to look up the hostname from an IPA address."
"Even if I wanted to, I wouldn't be able to buy Cloudflare in my country."
"There should be a specific price list for enterprise-level customers."
"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"Although I think it's quite good, it doesn't provide me with all the features I would expect to have if I were using Imperva."
"The product support needs to be accessible from more places, a wider area of coverage."
"Latencies are always a problem."
"The cost must be reduced."
"It would be better if AWS WAF were more flexible. For example, if you take a third-party WAF like Imperva, they maintain the rule set, and these rule sets are constantly updated. They push security insights or new rules into the firewall. However, when it comes to AWS, it has a standard set of rules, and only those sets of rules in the application firewalls trigger alerts, block, and manage traffic. Alternative WAFs have something like bot mitigation or bot control within the WAF, but you don't have such things in AWS WAF. I will say there could have been better bot mitigation plans, there could have been better dealer mitigation plans, and there could be better-updated rule sets for every security issue which arises in web applications. In the next release, I would like to see if AWS WAF could take on DDoS protection within itself rather than being in a stand-alone solution like AWS Shield. I would also like a solution like a bot mitigation."
"AWS WAF should provide better protection to its users, and the security features need to improve."
"The pricing model is complicated."
"The user experience, the interface, is lacking. Sometimes it's hard to find certain areas that it has alerted on."
"It is sometimes a lot of work going through the rules and making sure you have everything covered for a use case. It is just the way rules are set and maintained in this solution. Some UI changes will probably be helpful. It is not easy to find the documentation of new features. Documentation not being updated is a common problem with all services, including this one. You have different versions of the console, and the options shown in the documentation are not there. For a new feature, there is probably an announcement about being released, but when it comes out, there is no actual documentation about how to use it. This makes you either go to technical support or community, which probably doesn't have an idea either. The documentation on the cloud should be the latest one. Finding information about a specific event can be a bit challenging. For this solution, not much documentation is available in the community. It could be because it is a new tool. Whenever there is an issue, it is just not that simple to resolve, especially if you don't have premium support. You have pretty much nowhere to look around, and you just need to poke around to try and make it work right."
"I would like to see it more tightly integrated with other AWS services."
"The product could be improved by expanding the weightage units of rules."
"The product should provide improved bot detection and management."
"The solution's pricing could be better."
"What I don't like about Fastly is that they charge a heavy price."
"It is missing a "staging" platform to deploy a test configuration with all of the real settings, which would allow us to properly test before putting it into production."
"Fastly's customer service area needs improvement."
"Stronger analytics would be helpful, like showing configurations that haven't served a certain amount of traffic in a while. With many properties, things can get lost track of - duplicates or unused configurations not properly decommissioned."
"We are not getting quick responses from Fastly technical support engineers. Sometimes they depend on their D3 developers."
"Support is not that great."
 

Pricing and Cost Advice

"The price of the solution is expensive."
"We don't have any issues with the price."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"There are no additional costs beyond the standard licensing fees."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"That is one of the great features. I was able to access the majority of the features and services for free."
"AWS WAF has reasonable pricing."
"Its price is fair. There is a very fair amount that they charge. It has a pay-as-you-go model, so it pretty much depends on how much a user uses it. As per the cloud norms, the more you use, the more you pay. I would rate it a five out of ten in terms of pricing."
"The pricing should be more affordable, especially as it pertains to small clients."
"The product is moderately priced."
"AWS is not that costly by comparison. They are maybe close to $40 per month. I think it was between $29 or $39."
"For Kubernetes microservices, AWS is more expensive compared to OCI. AWS costs approximately 70 cents per hour, while OCI is 50% cheaper."
"AWS WAF costs $5 monthly plus $1 for the rule. It's cheap, cost-wise. It's worth the money."
"The price is average."
"The solution is cheaper than other products in the market."
"I've generally found Fastly to be very competitive in pricing, especially around Compute@Edge."
"It is an expensive solution."
"Fastly is less expensive than one of its competitors."
"In my opinion, Fastly is priced competitively."
"The pricing has been very competitive."
"You need to pay a premium price for the tool."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
879,672 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Government
6%
Computer Software Company
12%
Comms Service Provider
10%
Financial Services Firm
10%
Retailer
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise26
By reviewers
Company SizeCount
Small Business5
Large Enterprise5
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What do you like most about Fastly?
Support is good; the product works as advertised. We have a Slack connection with them. So we can basically ask for h...
What needs improvement with Fastly?
I believe that Fastly should provide guidelines for their WAF blocking rules. It should be public what the rules are ...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
Twitter, Airbnb, Alaska Airlines, Pinterest, Vimeo, The Guardian, The New York Times, Ticketmaster, The Drupal Association, Opera, about.com, imgur, Etsy, Foursquare, GitHub, New Relic, shopify, Shazam, Firebase
Find out what your peers are saying about AWS WAF vs. Fastly and other solutions. Updated: December 2025.
879,672 professionals have used our research since 2012.