Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Tenable.io Web Application Scanning comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (12th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
60
Ranking in other categories
Web Application Firewall (WAF) (2nd)
Tenable.io Web Application ...
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
17
Ranking in other categories
Application Security Tools (18th)
 

Mindshare comparison

Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
AWS WAF7.4%
F5 Advanced WAF9.0%
Microsoft Azure Application Gateway7.5%
Other76.1%
Web Application Firewall (WAF)
Application Security Tools Market Share Distribution
ProductMarket Share (%)
Tenable.io Web Application Scanning1.3%
SonarQube Server (formerly SonarQube)20.4%
Checkmarx One10.4%
Other67.9%
Application Security Tools
 

Featured Reviews

Carlos Alam Hernandez Baruch - PeerSpot reviewer
Fast and secure deployments simplify operations for government and fintech clients
It is a fast and secure DNS. It is very easy to deploy, and my customers are happy with this tool. Additionally, the CDN performance in Mexico is excellent, providing fast service and tools. It offers reliability during high-traffic periods, ensuring no impact on the environment. It helps my clients avoid using on-premise boxes, simplifying operations as they only use the prices on Cloudflare.
Azam S M - PeerSpot reviewer
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
Jahanzeb Feroze Khan - PeerSpot reviewer
Highly Recommended Solution with Latest Scanning Methods
The setup of the solution is straightforward. It involves installing the package and gaining access. It took no time at all since we deployed it on the cloud. We assigned the necessary configurations, and everything was set up and ready to go within a few seconds. I would rate the setup as a perfect ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I rate its stability a ten out of ten."
"The most valuable feature of Cloudflare DNS is security."
"The overall experience with Cloudflare is positive, with a rating of eight out of ten."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"Centralized, full-featured DNS."
"The solution offers the flexibility to control configuration rules."
"The solution is stable, and the DNS servers are simple to use."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"The most valuable feature of AWS WAF is its highly configurable rules system."
"The solution is stable."
"The solution is stable."
"We integrate AWS WAF with several platforms within cloud hosting and other security solutions and provisions in our business. Regarding AI, it's been around for about 20 years, so it's not new. It's just a new buzzword. I've been in security for 30 years and remember using AI when I started 25-30 years ago. We have multiple forms of AI within our business."
"The most valuable feature is the way it blocks threats to external applications."
"As a basic WAF, it's better than nothing. So if you need something simple out of the box with default features, AWS WAF is good."
"The access instruction feature is the most valuable. This is what we use the most."
"This product supplies options for web security for applications accessing sensitive information."
"Tenable provides the end analysis results covering all the published vulnerabilities and information on the market."
"We can get detailed information about vulnerabilities."
"The most effective feature of the product is the ability to scan the entire environment."
"We use the tool for our websites. We have a vulnerable subdomain. The tool helps to scan it for vulnerabilities."
"Tenable.io Web Application Scanning provides a detailed report, identifying functions that are complex and need to be more maintainable and readable."
"The solution's instant reports feature is the most effective for detecting threats."
"The most valuable feature is the reporting, which provides a good level of detail with respect to vulnerabilities."
"I would recommend Tenable.io Web Application Scanning to others."
 

Cons

"The pricing could be improved."
"It should have easier documentation for the configuration. It's very technical and people who aren't technical should also be able to do the configuration."
"Cloudflare should add more documentation and pricing to the cloud version."
"Cloudflare could be improved by introducing a mid-tier pricing option."
"The analytics, basically the dashboard, doesn't have much to it."
"There might be helpful if there was some web application firewall feature."
"There should be a specific price list for enterprise-level customers."
"We have noticed multiple instances where Cloudflare falsely indicates that our servers are down, even when there is no actual load on them. This makes it challenging for us to identify the exact issue."
"AWS WAF's signature sets have room for improvement due to false positives."
"We must monitor and clean up the WAF manually."
"The cost must be reduced."
"I find the documentation somewhat complex to implement during the initial stages."
"When users choose the free service, there isn't great support available to them."
"They should make the implementation process faster."
"We should be able to do proper whitelisting."
"The setup is complicated."
"The reporting has a very limited customization capability."
"It isn't easy to manage vulnerabilities in Tenable."
"Tenable.io Web Application Scanning is not very user-friendly and you need a lot of information to get proper reports. The tool's support is not very responsive."
"The platform's technical support services could be better."
"Tenable.io Web Application Scanning could improve by offering faster fuzzing."
"The technical support needs improvement. Currently, it takes time, which might be due to the free version, but providing some level of support could encourage future purchase decisions."
"They have a general dashboard for web application scanning, but the dashboards and reporting can be improved. They probably have some features in their roadmap."
"The market is standard for vulnerability scanning, however, the posture can be improved through Tenable's prioritization engine."
 

Pricing and Cost Advice

"We are using the free version."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"We don't have any issues with the price."
"I give the price a five out of ten."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"The product's pricing is cheap."
"AWS WAF has reasonable pricing."
"The solution is affordable."
"The product’s pricing is reasonable."
"The price of AWS WAF is reasonable, it is not expensive and it is not cheap."
"The product is moderately priced."
"The solution's cost depends on the use cases."
"AWS WAF costs $5 monthly plus $1 for the rule. It's cheap, cost-wise. It's worth the money."
"There are different scale options available for WAF."
"The price of the solution is reasonable compared to the competitors. The license cost is based on the number of users and the annual usage."
"For Tenable.io Web Application Scanning, it comes to around 6,50,000 Indian rupees, plus taxes."
"The pricing is okay."
"The application is extremely affordable. There are no additional costs involved with licensing. We switched to Tenable.io Web Application Scanning from other solutions due to pricing."
"I rate the product's pricing a four out of ten."
"Tenable.io Web Application Scanning is expensive for small businesses."
"It follows the same licensing scheme as Tenable.io and Tenable. sc."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
872,008 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Comms Service Provider
11%
Financial Services Firm
10%
Manufacturing Company
7%
Computer Software Company
15%
Financial Services Firm
15%
Manufacturing Company
9%
Government
6%
Financial Services Firm
12%
Computer Software Company
10%
Government
10%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise25
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise4
Large Enterprise7
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What do you like most about Tenable.io Web Application Scanning?
The most effective feature of the product is the ability to scan the entire environment.
What needs improvement with Tenable.io Web Application Scanning?
Improvements could include providing coverage reports in the free version and features related to security reports. A...
What advice do you have for others considering Tenable.io Web Application Scanning?
I would recommend Tenable.io Web Application Scanning as it provides us with good reports, which help improve our cod...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
IMDEX
Find out what your peers are saying about F5, Amazon Web Services (AWS), Microsoft and others in Web Application Firewall (WAF). Updated: October 2025.
872,008 professionals have used our research since 2012.