No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point CloudGuard WAF vs F5 Rules for AWS WAF comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Ranking in Web Application Firewall (WAF)
7th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
No ranking in other categories
Check Point CloudGuard WAF
Ranking in Web Application Firewall (WAF)
8th
Average Rating
8.8
Reviews Sentiment
7.1
Number of Reviews
56
Ranking in other categories
Application Security Tools (4th)
F5 Rules for AWS WAF
Ranking in Web Application Firewall (WAF)
30th
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
2
Ranking in other categories
Business Rules Management (4th)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
MK
CISO at Pink Solutions
Cloud security has strengthened risk posture and improved advanced threat visibility
There are some API gateway and API securities I mentioned. If these are incorporated with AI-related features, particularly those seven key vulnerabilities I mentioned—token theft and tool poisoning—that would be beneficial. AI-related features are not included yet in Check Point CloudGuard WAF. However, they are present in FortiGate. That is the advantage of FortiGate now. FortiGate is stopping all AI-related vulnerabilities now. FortiGate has this capability. It is unfortunate that even Palo Alto also lacks one or two of these features. Check Point Quantum is very good, without a doubt. However, their capabilities are not in comparison with Palo Alto. There are some features, but there are some gaps in comparison with Palo Alto.
Manmohan Rao - PeerSpot reviewer
Associate Vice President at Hitachi Systems India Private Limited
Managed security rules have protected our public e‑commerce sites and simplified ongoing defense
I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF. These are managed rule sets, so you do not need to worry about continuous improvements or ensuring your application is secure; F5 Rules for AWS WAF will take care of that and is always making the necessary improvements in these rule sets to ensure security. I am very impressed with the rule sets and the continuous engineering from their security team to ensure the required rule set availability. I really appreciate the fantastic job they are doing. F5 Rules for AWS WAF can be integrated with AWS CloudFront, Application Load Balancer, Lambda, and API Gateway. I am satisfied with all these services as they are our intermediary points for services exposed to the public or globally. I gave this product a rating of ten out of ten.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I'm highly satisfied. It's remarkably user-friendly, enabling me to quickly identify issues, and deploy solutions, and it offers the necessary features."
"The rate limiting features and customizations in terms of URL match and applying policies are valuable to me."
"Cloudflare is cheaper compared to Azure WAF, which I have considered before."
"It is configurable via API."
"We like that there's load balancing, firewall capabilities, DDoS protection, et cetera, all covered by Cloudflare."
"Cloudflare has positively impacted my organization by making it easier for me to handle and set up DNS for multiple clients; I can easily go in and access their accounts, make changes they need, and it's a one-stop shop."
"Cloudflare WAF provides protection through rules and functionalities like Cloudflare's SDRAP."
"The setup process is very simple for me."
"Check Point CloudGuard Application Security enabled us to develop strength and process efficiency coupled with a secure environment in the IT system."
"Machine learning is a valuable tool for this assessment because it allows for a two-phase approach: secure and non-secure."
"Before CloudGuard, we periodically had some website issues. Since we've had CloudGuard, we've never had these issues happen again."
"Check Point CloudGuard WAF has positively impacted my organization by significantly improving both security and operational efficiency, with a noticeable reduction in web-based threats, especially automated attacks and vulnerability exploits, thanks to its real-time prevention and reputation filter that has streamlined my workflow through automatic policy updates and integration smoothly with my CI/CD pipelines, allowing my DevOps teams to deploy security without delays."
"By using a cloud application security solution, our company can save costs by reducing the need for additional security hardware and software and improving operational efficiency."
"The tool performs device health checkups and updates us. It helps us to be compliant with regulatory policies."
"From a security perspective, it is quite good."
"Since we've had CloudGuard, we've never had these issues happen again."
"I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF."
"F5 Rules for AWS WAF has positively impacted our organization for security through the implementation of traffic rules in our application."
"I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF."
 

Cons

"The notification part could be improved. It's very much connected to Web Application Firewall, rate-limiting, and DDoS protection."
"It would be ideal if the solution offered better log integration and more integration with different platforms."
"The platform's control features related to real-time authentication and response time need improvement."
"Cloudflare Web Application Firewall should include port forwarding features."
"I have experienced some difficulties with Cloudflare's support as a customer based in India."
"The rate limiting functionality could be enhanced, as we find it somewhat limited."
"It would be ideal if the solution offered better log integration and more integration with different platforms."
"They have some limitations with third-party integrations."
"CloudGuard for Application Security, like the other Check Point applications, has been presenting major latency problems when entering their administrative portal."
"The coding configurations can be simplified to save time for IT teams and developers."
"Cost reduction and trial period extension should be considered with some lucrative discount offerings in buying standard versions."
"I advise proactive threat detection intelligence offline, which can also help monitor and ensure system checks and compliances are in place."
"The documentation of each of the tools that they offer needs to be better."
"It was costlier than other solutions."
"The user interface can be improved, especially for 1st time user."
"The web user interface needs some improvement, even though the functionality is good."
"An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these rule sets."
"It's too early to talk about a return on investment with F5 Rules for AWS WAF."
"An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these rule sets."
 

Pricing and Cost Advice

"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"The solution is expensive."
"The solution's pricing option needs to be more transparent for enterprise clients."
"The annual licensing fee is $10,000 USD."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"It starts at $20 and can easily go up to $200 monthly"
"What's my experience with pricing, setup cost, and licensing? I believe the pricing is not the best, but it's reasonable and acceptable. We also use the McAfee system in parallel. In terms of pricing, its okay - not great, but not bad either. It falls in the middle, which is acceptable. In terms of support licensing, last time, we were searching for a solution, and we considered products from resellers rather than directly from the cloud provider. However, the pricing we encountered was exceptionally high. As a result, we are inclined to select support from the reseller."
"We pay $210 per month for CloudFlare WAF."
"I work for an Indian banking client. In India, companies are on a budget. The company liked Check Point very much, but it was a little bit costly compared to FortiWeb. However, it had more features compared to FortiWeb."
"I find the pricing to be reasonable."
"It is not cheap, but it is worth it."
"The tool's licensing costs are yearly and competitive."
"Check Point CloudGuard WAF is expensive compared to Azure WAF."
"If the pricing for the Infinity platform covers everything, it would be more straightforward. I had a hard time selling it to our CEO as a former CFO because of the differentials. There are different deltas year to year over a five-year period. It is very difficult to explain. It would be easier to digest for our executives if there was a flatter scale"
"As Infiniti customers, the pricing is manageable, as we have allowances dedicated to each Check Point product. The price is not as high compared to other options I have dealt with in the past."
"Check Point CloudGuard Application Security's pricing is not friendly."
Information not available
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
885,311 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
13%
Computer Software Company
9%
Manufacturing Company
8%
Comms Service Provider
8%
Computer Software Company
26%
Manufacturing Company
12%
Financial Services Firm
7%
Comms Service Provider
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business36
Midsize Enterprise20
Large Enterprise19
No data available
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What do you like most about CloudGuard for Application Security?
We have not had any incidents. We could realize its benefits immediately. We watched and monitored the traffic, and i...
What is your experience regarding pricing and costs for CloudGuard for Application Security?
Check Point CloudGuard WAF is expensive. It is a little bit expensive. You cannot avoid this from an Israeli product....
What needs improvement with CloudGuard for Application Security?
There are some API gateway and API securities I mentioned. If these are incorporated with AI-related features, partic...
What is your experience regarding pricing and costs for F5 Rules for AWS WAF?
From the pricing perspective, I found it to be comparable to other marketplace rules available in AWS Marketplace. It...
What needs improvement with F5 Rules for AWS WAF?
An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these r...
What is your primary use case for F5 Rules for AWS WAF?
We are providing support to our end customers who have e-commerce websites that need to be exposed to the public, and...
 

Also Known As

Cloudflare WAF
Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec
No data available
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Orange España, Paschoalotto
Information Not Available
Find out what your peers are saying about Check Point CloudGuard WAF vs. F5 Rules for AWS WAF and other solutions. Updated: March 2026.
885,311 professionals have used our research since 2012.