Try our new research platform with insights from 80,000+ expert users

AWS WAF vs HAProxy comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.5
Cloudflare users experienced increased performance, security, and cost-effectiveness, leading to improved loyalty and revenue despite difficult ROI calculations.
Sentiment score
6.9
AWS WAF enhances security and cost efficiency by integrating with AWS, reducing the need for additional security personnel.
Sentiment score
7.1
HAProxy's open-source load balancer cuts costs, boosts efficiency, improves uptime, reduces staffing, and enhances scalability for users.
For the small project I was working on, using the basic tier provided a huge improvement at zero cost.
Security Specialist at a tech services company with 1,001-5,000 employees
In terms of return on investment with Cloudflare, it costs my time to set them up, but basically once they're set up, it's done.
Owner at Hga consulting
With AWS WAF, it is easier for us to block unwanted malicious DDoS attacks and threats from coming into our web application.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
Operational efficiency has improved; we no longer have staff consistently monitoring backend servers during deployment or scaling events, as HAProxy's health checks and hitless reloads allow us to push changes with minimal manual intervention.
Junior System Administrator & DevOps at a tech services company with 11-50 employees
This resulted in a drastic decrease in costs and, at the same time, the accuracy of the hits coming on HAProxy was almost around 100% or 99.99%.
Head of DevOps at TripFactory
I estimate seeing a return on investment with HAProxy, as it significantly reduced staff requirements and enhanced scaling capabilities, particularly when transitioning from NGINX, which faced issues.
Principal Engineer Manager at a manufacturing company with 501-1,000 employees
 

Customer Service

Sentiment score
7.0
Cloudflare's customer service is quick, but technical support feedback is mixed, with improvement needed in responsiveness and detailed assistance.
Sentiment score
6.7
AWS WAF support receives mixed reviews, praised for responsiveness and expertise, yet criticized for cost and inconsistent communication.
Sentiment score
6.5
HAProxy's customer service and technical support are highly rated for quick, expert assistance, though documentation could improve.
Cloudflare does not offer hands-on technical support to fix customer problems but rather a self-service model.
Senior Consultant CDN at a comms service provider with 10,001+ employees
I would rate the technical support with Cloudflare as excellent every time I've had to call them.
Owner at Hga consulting
I have primarily worked not with the tool's customer support but with the product's sales engineers and technical sales engineers, who seem to know their stuff.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
Resolving issues can take time because the support personnel may lack product expertise, leading to delays.
Security Engineer at a computer software company with 1,001-5,000 employees
They reach out when you send them a ticket, and within 24 hours or less, someone is able to get back to you to solve your problem.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
Since we are utilizing the open-source edition, community forums, mailing lists, and GitHub have been invaluable, with typically someone having encountered the same problems we faced.
Junior System Administrator & DevOps at a tech services company with 11-50 employees
My interactions with HAProxy's customer support were limited, but the feedback from my team indicated satisfactory service.
Principal Engineer Manager at a manufacturing company with 501-1,000 employees
 

Scalability Issues

Sentiment score
8.1
Users praise Cloudflare for seamless scalability, effective traffic management, easy upgrades, and robust global infrastructure without disruptions.
Sentiment score
7.8
AWS WAF excels in scalability and auto-scaling, efficiently handling traffic for businesses of all sizes, though improvements are possible.
Sentiment score
7.9
HAProxy efficiently handles scalability, easily adapting configurations for growing traffic, ideal for small to medium businesses and larger environments.
It is a SaaS tool, but the fact that they have workloads deployed across the world proves that it is a highly scalable tool.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
The tool offers very good performance, even during high-traffic periods.
Engineer at SITMEXICO
I rate the solution’s scalability an eight out of ten.
Independent Consultant at Unaikui
AWS WAF does scale in the sense that it is fully managed and has automatic scaling.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
We manage an automatic load balancing feature where we add HAProxy servers dynamically behind the application load balancer to handle more traffic.
Head of DevOps at TripFactory
HAProxy's scalability is excellent; as our traffic expands, it handles load increases effortlessly.
Junior System Administrator & DevOps at a tech services company with 11-50 employees
For scalability, HAProxy meets my needs, supporting our initial horizontal scaling and then adapting to vertical scaling in a VMware environment.
Principal Engineer Manager at a manufacturing company with 501-1,000 employees
 

Stability Issues

Sentiment score
7.6
Cloudflare is highly rated for stability and uptime, with few past issues, especially on higher-tier plans.
Sentiment score
8.3
AWS WAF is highly rated for stability due to reliable performance, strong protection, and effective redundancy features.
Sentiment score
8.1
HAProxy is reliable, handles heavy traffic efficiently, with minimal downtime, quick support, and frequent updates enhancing stability and performance.
I rate the solution’s stability an eight out of ten.
Independent Consultant at Unaikui
The service is very stable with no impacts during high-traffic periods.
Engineer at SITMEXICO
Since it protects web applications from common attacks such as SQL injection and XSS, it is very stable.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
In terms of reliability, I would rate AWS WAF about six out of ten due to the need for improved signature sets.
Security Engineer at a computer software company with 1,001-5,000 employees
We faced issues with AWS WAF when writing the custom rules.
Infrastructure Lead at Danat Fz LLC
This reliability serves as a key reason for our choice, providing us with confidence even when faced with heavy traffic.
Junior System Administrator & DevOps at a tech services company with 11-50 employees
The hot reload feature of HAProxy also really helped us so that we never had to shut it down to reload it.
Co-Founder, CEO at a tech services company with 1-10 employees
We have reduced a lot of servers, replacing them with one or two HAProxy servers which deliver better performance, accuracy, and an almost 100% success rate with requests.
Head of DevOps at TripFactory
 

Room For Improvement

Enhancements needed in Cloudflare: analytics, CDN latency, API integration, user support, DNS, pricing, documentation, server coverage, WAF, and cache.
AWS WAF requires improved integration, usability, security features, and flexible pricing to better support global users and services.
HAProxy needs a revamped GUI, improved APIs, better AWS integration, real-time config, enhanced docs, and stronger monitoring and security.
Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor.
Managed Services Manager at Adapture Technology Group
Areas like how assessment, discovery, and payload are dealt with and how it all comes into your organization can be considered when trying to make suggestions to Cloudflare for improvements.
Senior Cloud Solution Architect at Integrated Technology Solution Group (ITSG)
There are some performance considerations when it comes to dynamic content that involves fetching data from databases or using APIs.
Senior Solutions Architect at Think Power Solutions
Compared to firewalls, WAFs generally provide limited stateful analysis capabilities.
Security Engineer at a computer software company with 1,001-5,000 employees
The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information.
Infrastructure Lead at Danat Fz LLC
Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF.
Security Analyst at M2P Fintech
The configuration syntax is powerful yet can become overwhelming for newcomers; a more beginner-friendly interface or a native GUI without relying on third-party tools would ease the onboarding process.
Junior System Administrator & DevOps at a tech services company with 11-50 employees
An easier desktop interface to connect to a remote server and make changes on my PC would be beneficial.
DevOps engineer at a tech services company with 1-10 employees
The reloading functionality is effective as it allows soft reloads without interrupting traffic patterns.
Principal Engineer Manager at a manufacturing company with 501-1,000 employees
 

Setup Cost

Cloudflare offers scalable pricing, from free to enterprise plans, providing significant value especially for mid-sized companies.
AWS WAF offers cost-effective, pay-as-you-go pricing, starting at $5 monthly, valued for integration with AWS services.
Enterprise users value HAProxy's competitive pricing and cost-effective licensing, especially compared to F5 and Citrix, despite initial setup costs.
I find it to be cheap.
Engineer at SITMEXICO
I rate the product’s pricing a five out of ten, where one is cheap, and ten is expensive.
Senior Solutions Architect at Think Power Solutions
The tool is a premium product, so it is very expensive.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
Due to our status as an AWS shop, AWS WAF is cost-effective for us, and we benefit from discounts due to our extensive use of AWS services.
Security Engineer at a computer software company with 1,001-5,000 employees
The licensing cost for AWS WAF is just pay-as-you-go; it is a service-based model.
Infrastructure Lead at Danat Fz LLC
Since we use the open-source edition, there are no licensing fees, with the main cost being the infrastructure running on EC2 instances in AWS, which helps maintain low expenses.
Junior System Administrator & DevOps at a tech services company with 11-50 employees
Setting up HAProxy didn't cost anything for me.
DevOps engineer at a tech services company with 1-10 employees
The pricing remains competitive compared to other vendors.
Principal Engineer Manager at a manufacturing company with 501-1,000 employees
 

Valuable Features

Cloudflare enhances performance and security with CDN caching, DDoS protection, and an easy-to-use dashboard, benefiting many users.
AWS WAF offers threat blocking, scalability, automation, and seamless integration, enhancing security and performance with easy deployment and affordability.
Users praise HAProxy for reliable load balancing, customization, low latency, open-source benefits, and advanced features like secure traffic management.
The most valuable features of the solution are performance and security.
Senior Cloud Solution Architect at Integrated Technology Solution Group (ITSG)
Techniques like minification and image compression reduce the size of assets, leading to better performance and faster user load times.
Senior Solutions Architect at Think Power Solutions
The solution has been able to compare it to the market, and I think the product has taken great strides in automating quite a bit of things, and they use a lot of AI.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
The biggest benefit of AWS WAF for us is to filter malicious requests, so we can protect our environment and application from malicious actors.
Infrastructure Lead at Danat Fz LLC
It has also helped to improve the posture of our application, prevent all DDoS attacks, and unnecessary traffic and SQL injection that is reducing the performance of our application.
DevOps Engineer at a tech vendor with 1,001-5,000 employees
The cloud-native nature of AWS is crucial since most of our workload is in AWS, making AWS WAF native to Amazon Web Services.
Security Analyst at M2P Fintech
By moving all SSL termination to the load balancer, I now manage certificates in a single place, and I can also utilize Let's Encrypt with HAProxy's built-in ACME support, making renewal automatic.
Junior System Administrator & DevOps at a tech services company with 11-50 employees
HAProxy positively impacted our organization by exceeding scalability expectations, initially projected at 200k requests but ultimately handling over 15 million transactions per second without any issues.
Principal Engineer Manager at a manufacturing company with 501-1,000 employees
As a production engineer at that time, I definitely wanted to ensure that the system could handle massive connections, especially since we operated an e-commerce platform where we could not lose any customer calls.
Co-Founder, CEO at a tech services company with 1-10 employees
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (1st), WAN Optimization (4th), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (12th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Web Application Firewall (WAF) (3rd)
HAProxy
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
47
Ranking in other categories
Application Delivery Controllers (ADC) (3rd), Web Application Firewall (WAF) (14th), Distributed Denial-of-Service (DDoS) Protection (6th), Bot Management (7th), Service Mesh (2nd)
 

Featured Reviews

HA
Owner at Hga consulting
Has helped manage client domains with streamlined access control and threat visibility
I don't know what areas could be improved with Cloudflare WAF; Cloudflare is constantly improving and adding features to their feature set. They're doing a good job, and as far as DNS and support for any domains that I create or my clients create, it's mandatory for me to make sure that they have Cloudflare as their DNS provider. The Cloudflare load balancing capability hasn't really helped in enhancing my website's uptime and resiliency because we don't really get that much traffic; it's mostly remote users, and web hosting is done by a web hosting service. It doesn't pay to try to host your own website.
Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
Shrinivas Devarkonda - PeerSpot reviewer
Head of DevOps at TripFactory
Handles high traffic efficiently and simplifies complex routing with rule-based logic
I think HAProxy is good as it stands now, but I believe there could be improvements. gRPC has recently been implemented, which is great, along with TLS 1.2 and 1.3 support, and HTTP 2.0 is also available. However, I'm unsure about the benchmark of those HTTP 2.0 requests on HAProxy. If there were any other protocol with better performance than HTTP 2.0, or perhaps mTLS and other similar features, including that in HAProxy would be really great. For improvements, I think that during setup and configuration, the steps provided are neat and clear. Anyone can easily install and configure it. There are many kernel tuning parameters also available, which is great. For specific improvement, in terms of logging, I think printing the full object of the request may help, or if there's a way to reference two requests, it would be beneficial to find a complete session history from a logged-in customer, as it would help analyze customer and user analytics.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
879,853 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Government
6%
Computer Software Company
17%
Financial Services Firm
11%
Comms Service Provider
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise26
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise15
Large Enterprise16
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
Do you recommend HAProxy?
I do recommend HAProxy for more simple applications or for companies with a low budget, since HAProxy is a free, open...
What do you like most about HAProxy?
The solution is effective in managing our traffic.
What is your experience regarding pricing and costs for HAProxy?
Since we used the open-source version, we were not concerned about pricing, setup cost, or licensing.
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
HAProxy Community Edition, HAProxy Enterprise Edition, HAPEE
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
Booking.com, GitHub, Reddit, StackOverflow, Tumblr, Vimeo, Yelp
Find out what your peers are saying about AWS WAF vs. HAProxy and other solutions. Updated: December 2025.
879,853 professionals have used our research since 2012.