Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard WAF vs F5 Rules for AWS WAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (1st), WAN Optimization (4th), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (12th)
Check Point CloudGuard WAF
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
51
Ranking in other categories
Application Security Tools (5th), Web Application Firewall (WAF) (9th)
F5 Rules for AWS WAF
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
2
Ranking in other categories
Business Rules Management (4th), Web Application Firewall (WAF) (29th)
 

Featured Reviews

HA
Owner at Hga consulting
Has helped manage client domains with streamlined access control and threat visibility
I don't know what areas could be improved with Cloudflare WAF; Cloudflare is constantly improving and adding features to their feature set. They're doing a good job, and as far as DNS and support for any domains that I create or my clients create, it's mandatory for me to make sure that they have Cloudflare as their DNS provider. The Cloudflare load balancing capability hasn't really helped in enhancing my website's uptime and resiliency because we don't really get that much traffic; it's mostly remote users, and web hosting is done by a web hosting service. It doesn't pay to try to host your own website.
reviewer2751468 - PeerSpot reviewer
Assistant Manager at a computer software company with 201-500 employees
Robust threat protection improves security and operational efficiency
Areas where Check Point CloudGuard WAF can improve include simple policy tuning, as the protection seems strong, though initial rule tuning can be complex. More guided workflows or templates would help speed up deployment, along with deeper integration with the DevOps pipeline, and while it handles API well, more dedicated API security would add value. In addition, it could be improved with better integration with the DevOps pipeline, more granular reporting, as the dashboards provide good high-level visibility, but sometimes digging into specific attack patterns or trends requires manual effort, and simple tuning of the ML models would be beneficial.
reviewer2783919 - PeerSpot reviewer
Associate Vice President at a tech services company with 10,001+ employees
Managed security rules have protected our public e‑commerce sites and simplified ongoing defense
I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF. These are managed rule sets, so you do not need to worry about continuous improvements or ensuring your application is secure; F5 Rules for AWS WAF will take care of that and is always making the necessary improvements in these rule sets to ensure security. I am very impressed with the rule sets and the continuous engineering from their security team to ensure the required rule set availability. I really appreciate the fantastic job they are doing. F5 Rules for AWS WAF can be integrated with AWS CloudFront, Application Load Balancer, Lambda, and API Gateway. I am satisfied with all these services as they are our intermediary points for services exposed to the public or globally. I gave this product a rating of ten out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Cloudflare DNS is security."
"From what I've seen so far, there are no negatives to report as of yet"
"The solution is stable, and the DNS servers are simple to use."
"I like Cloudflare's application gateway and DDoS protection."
"The solution offers the flexibility to control configuration rules."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"Cloudflare allows us to self-host services such as Rocket.Chat and Node-RED, in high-availability mode, thanks to round robin DNS which allows us to share one hostname between our two locations."
"The technical support is good."
"It helps us streamline our revenue streams, and we're spending less money on application security."
"The DirectStorage gives me a vision that I did not have of the check that occurs on the web servers."
"Check Point CloudGuard WAF has been especially helpful here, automatically learning and adjusting protection without requiring constant manual tuning."
"The solution's strongest point is that you can connect everything to it, giving you a full view of what's connected."
"The ability to preemptively block zero day attacks and detect hidden anomalies is exactly its advantage."
"It provides security for our customers and our products."
"CloudGuard WAF has been great."
"The best feature of Check Point CloudGuard WAF is advanced threat prevention integrated with Check Point threat cloud intelligence, which provides real-time protection against web application attacks including zero-day threats, automatically receiving updates from the threat cloud and analyzing millions of indicators of compromise daily."
"I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF."
"I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF."
"F5 Rules for AWS WAF has positively impacted our organization for security through the implementation of traffic rules in our application."
 

Cons

"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"The solution could use more analytics on the backend to give us more insights into everything. More reports would be helpful."
"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"The integration of LLMs on the dashboard is something that is needed in the tool."
"The timing aspect can lead to it being considered overpriced. This is a particular concern we have with Cloudflare, as they may struggle with accurately detecting the client."
"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"For large enterprises, the pricing is okay. However, the enterprise price for small projects is a bit high. A mid-tier pricing option would be beneficial."
"We have noticed multiple instances where Cloudflare falsely indicates that our servers are down, even when there is no actual load on them. This makes it challenging for us to identify the exact issue."
"You need to know exactly the system. You cannot have someone running the system if they don't have the knowledge to do so."
"They might be able to add more integrations."
"The web user interface needs some improvement, even though the functionality is good."
"In terms of features, I do not have any negatives. Their integration is extremely quick. It is better than others I have been involved with in the past. Their pricing model, however, can be better."
"Check Point CloudGuard WAF can be improved; initially, the setup is very complicated, and there's not a lot of documentation available, plus it didn't have something for anti-bot, but other than that, it is fine."
"For the next release, I would suggest considering features like enhanced threat intelligence integration."
"I feel like I need more clarity in understanding pricing for DDoS protection."
"They need improved latency in the main window."
"An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these rule sets."
"An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these rule sets."
"It's too early to talk about a return on investment with F5 Rules for AWS WAF."
 

Pricing and Cost Advice

"We don't have any issues with the price."
"So far I use free tier and happy with it. You can subscribe to business package if needed."
"The price is reasonable."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"In terms of licensing costs, we don't pay for licensing for Cloudflare. We only establish communication, then for peering, Cloudflare takes care of the cross-connection in different data centers."
"I give the price a five out of ten."
"The cost primarily depends on the size of the organization."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"Check Point CloudGuard Application Security's pricing is not friendly."
"The pricing is competitive compared to other solutions on the market. So, the licensing cost is average."
"I work for an Indian banking client. In India, companies are on a budget. The company liked Check Point very much, but it was a little bit costly compared to FortiWeb. However, it had more features compared to FortiWeb."
"Check Point CloudGuard Application Security's pricing is comparable to other products in the market."
"The tool's licensing costs are yearly and competitive."
"I find the pricing to be reasonable."
"If the pricing for the Infinity platform covers everything, it would be more straightforward. I had a hard time selling it to our CEO as a former CFO because of the differentials. There are different deltas year to year over a five-year period. It is very difficult to explain. It would be easier to digest for our executives if there was a flatter scale"
"Check Point CloudGuard WAF is expensive compared to Azure WAF."
Information not available
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
879,768 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
8%
Computer Software Company
19%
Manufacturing Company
15%
Financial Services Firm
8%
Security Firm
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise19
Large Enterprise16
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about CloudGuard for Application Security?
We have not had any incidents. We could realize its benefits immediately. We watched and monitored the traffic, and i...
What is your experience regarding pricing and costs for CloudGuard for Application Security?
The setup cost was taken with the head of the department, who handled the pricing and everything.
What needs improvement with CloudGuard for Application Security?
Currently, there is nothing in the areas of Check Point CloudGuard WAF that I would like to see improved or enhanced ...
What is your experience regarding pricing and costs for F5 Rules for AWS WAF?
From the pricing perspective, I found it to be comparable to other marketplace rules available in AWS Marketplace. It...
What needs improvement with F5 Rules for AWS WAF?
An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these r...
What is your primary use case for F5 Rules for AWS WAF?
We are providing support to our end customers who have e-commerce websites that need to be exposed to the public, and...
 

Also Known As

Cloudflare DNS
Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec
No data available
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Orange España, Paschoalotto
Information Not Available
Find out what your peers are saying about Check Point CloudGuard WAF vs. F5 Rules for AWS WAF and other solutions. Updated: December 2025.
879,768 professionals have used our research since 2012.