Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Tenable.io Web Application Scanning comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
76
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (13th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.6
Number of Reviews
59
Ranking in other categories
Web Application Firewall (WAF) (2nd)
Tenable.io Web Application ...
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
17
Ranking in other categories
Application Security Tools (18th)
 

Mindshare comparison

Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
AWS WAF7.7%
F5 Advanced WAF9.2%
Microsoft Azure Application Gateway7.8%
Other75.3%
Web Application Firewall (WAF)
Application Security Tools Market Share Distribution
ProductMarket Share (%)
Tenable.io Web Application Scanning1.3%
SonarQube Server (formerly SonarQube)20.8%
Checkmarx One10.2%
Other67.7%
Application Security Tools
 

Featured Reviews

Carlos Alam Hernandez Baruch - PeerSpot reviewer
Fast and secure deployments simplify operations for government and fintech clients
It is a fast and secure DNS. It is very easy to deploy, and my customers are happy with this tool. Additionally, the CDN performance in Mexico is excellent, providing fast service and tools. It offers reliability during high-traffic periods, ensuring no impact on the environment. It helps my clients avoid using on-premise boxes, simplifying operations as they only use the prices on Cloudflare.
Abdalla Kenawy - PeerSpot reviewer
Provides great insights about requests, helping secure our infrastructure
I am working on AWS Web Services to manage infrastructure as a platform. I use services like KMS, EBS, CloudFront, S3, and EC2. I also work on WAF version two AWS WAF has provided great insights about requests, helping secure our infrastructure. It contributes by continuing to get the latest…
Jahanzeb Feroze Khan - PeerSpot reviewer
Highly Recommended Solution with Latest Scanning Methods
The setup of the solution is straightforward. It involves installing the package and gaining access. It took no time at all since we deployed it on the cloud. We assigned the necessary configurations, and everything was set up and ready to go within a few seconds. I would rate the setup as a perfect ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its most significant benefit to date is the speed with which it refreshes DNS records on the internet once you change it. If you are changing a website or registering a new record, it is very quick."
"The most valuable feature of Cloudflare DNS is security."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"The solution provides good load balancing and protection against DDoS attacks."
"The most valuable feature of Cloudflare is that it has a free version. They give us the free version with the anti-DDoS features and also the load balancing solution."
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"The most valuable feature is the scalability because it automatically scales up or scales down as per our requirements."
"This product supplies options for web security for applications accessing sensitive information."
"The cloud-native nature of AWS is crucial since most of our workload is in AWS, making AWS WAF native to Amazon Web Services."
"The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections."
"The customized billing is the most valuable feature."
"As a basic WAF, it's better than nothing. So if you need something simple out of the box with default features, AWS WAF is good."
"AWS WAF is very easy to use and configure on AWS."
"The solution's initial setup process is easy."
"The solution's instant reports feature is the most effective for detecting threats."
"It is fully automated."
"I would recommend Tenable.io Web Application Scanning to others."
"The most effective feature of the product is the ability to scan the entire environment."
"The most valuable feature is the reporting, which provides a good level of detail with respect to vulnerabilities."
"All the features are valuable to us as they offer cutting-edge scanning methods and address the latest issues with a contemporary approach. Tenable.io Web Application Scanning is highly stable. I rate it a nine out ten. Since the solution works on the Cloud, it's highly scalable. I rate the scalability a nine out of ten. The setup of the solution is straightforward. The Return on Investment is substantial. I recommend the solution to all."
"It has good unified web application scanning and exposure management."
"We can get detailed information about vulnerabilities."
 

Cons

"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"Support response time could be improved."
"The product support needs to be accessible from more places, a wider area of coverage."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"Latencies are always a problem."
"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"Integration involving API with other products could be more user-friendly."
"The product needs to improve its automation."
"They have to do more to improve, to innovate more features. They need to increase the security. It has to be more active in detecting threats."
"It will be helpful if the product recommends rules that we can implement."
"Rule exclusion could be a bit more transparent."
"The rate at which AWS updates their managed rule sets could be better. Features like bot protection or DDoS mitigation, available with other WAF vendors, do not come natively with AWS WAF."
"They should make the implementation process faster."
"AWS WAF's signature sets have room for improvement due to false positives."
"We haven't faced any problems with the solution."
"I would like to be able to view a graphical deployment map in the user interface that will give me an overview of the configuration and help to determine whether I have missed any steps."
"They have a general dashboard for web application scanning, but the dashboards and reporting can be improved. They probably have some features in their roadmap."
"Tenable.io Web Application Scanning conducts a general scan, which wastes time. The scan needs to be specific."
"Tenable.io Web Application Scanning is not very user-friendly and you need a lot of information to get proper reports. The tool's support is not very responsive."
"The technical support needs improvement. Currently, it takes time, which might be due to the free version, but providing some level of support could encourage future purchase decisions."
"The market is standard for vulnerability scanning, however, the posture can be improved through Tenable's prioritization engine."
"The cloud and the on-premises versions have their own controllers, and there is no way to centrally manage controllers."
"It isn't easy to manage vulnerabilities in Tenable."
"Tenable.io Web Application Scanning could improve by offering faster fuzzing."
 

Pricing and Cost Advice

"We are using the free tier of the solution."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"The tool is a premium product, so it is very expensive."
"So far I use free tier and happy with it. You can subscribe to business package if needed."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"A free version of the solution is available."
"There are different scale options available for WAF."
"AWS is not that costly by comparison. They are maybe close to $40 per month. I think it was between $29 or $39."
"The product’s pricing is reasonable."
"The pricing is good and manageable."
"AWS WAF has reasonable pricing."
"Its price is fair. There is a very fair amount that they charge. It has a pay-as-you-go model, so it pretty much depends on how much a user uses it. As per the cloud norms, the more you use, the more you pay. I would rate it a five out of ten in terms of pricing."
"It's cheap."
"I would rate AWS WAF's pricing a seven out of ten."
"The pricing is okay."
"The price of the solution is reasonable compared to the competitors. The license cost is based on the number of users and the annual usage."
"It follows the same licensing scheme as Tenable.io and Tenable. sc."
"For Tenable.io Web Application Scanning, it comes to around 6,50,000 Indian rupees, plus taxes."
"The application is extremely affordable. There are no additional costs involved with licensing. We switched to Tenable.io Web Application Scanning from other solutions due to pricing."
"Tenable.io Web Application Scanning is expensive for small businesses."
"I rate the product's pricing a four out of ten."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
867,497 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Comms Service Provider
11%
Financial Services Firm
10%
Manufacturing Company
7%
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
9%
Government
6%
Computer Software Company
13%
Financial Services Firm
13%
Government
10%
Retailer
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise11
Large Enterprise25
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise4
Large Enterprise7
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What do you like most about Tenable.io Web Application Scanning?
The most effective feature of the product is the ability to scan the entire environment.
What needs improvement with Tenable.io Web Application Scanning?
Improvements could include providing coverage reports in the free version and features related to security reports. A...
What advice do you have for others considering Tenable.io Web Application Scanning?
I would recommend Tenable.io Web Application Scanning as it provides us with good reports, which help improve our cod...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
IMDEX
Find out what your peers are saying about F5, Amazon Web Services (AWS), Microsoft and others in Web Application Firewall (WAF). Updated: August 2025.
867,497 professionals have used our research since 2012.