Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard WAF vs The Fastly Next-Gen WAF (powered by Signal Sciences) comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 1, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
75
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (14th)
Check Point CloudGuard WAF
Average Rating
8.8
Reviews Sentiment
7.8
Number of Reviews
46
Ranking in other categories
Application Security Tools (10th), Web Application Firewall (WAF) (14th)
The Fastly Next-Gen WAF (po...
Average Rating
7.6
Reviews Sentiment
7.1
Number of Reviews
3
Ranking in other categories
Web Application Firewall (WAF) (26th)
 

Featured Reviews

Spencer Malmad - PeerSpot reviewer
It's easy to set up because you point the DNS to it, and it's working in under 15 minutes
Cloudflare is highly scalable. Cloudflare is a system with a web portal that the end users like me see. It's a console where we can adjust the DNS, caching, and security features all in that console. Cloudflare owns thousands of servers across the world that cache the data. It's a powerful solution. When clients sign up for Cloudflare, they're getting this monster content delivery network, security, and a web application firewall in one. It's all rolled into one, and it's massive. Unless you have your website hosted on a massive hosting provider, there's no way that you can deliver the amount of data that Cloudflare can provide to the end users. If you have static content, there's no way that you can ever match what Cloudflare can do. Obviously, there are competitors to Cloudflare that do the same, but I'm saying other types of solutions. Let's say you go with F5. Great, that's on-prem. That's in your colo. You can't deliver as much data to the internet as you can with a CDN. You don't have to spend $20,000 on a net scaler, F5, or whatever Cisco's selling now. You don't have to buy that. You pay them $50 a month or $150 a month. It's totally worth it because even in five years, you'll never get the performance value, not just the actual ROI. You have to consider how much throughput you can get with Cloudflare.
Dialungana Malungo - PeerSpot reviewer
Protects our web applications and APIs and has a very low false positive rate
CloudGuard WAF is a very straightforward solution. I do not have to worry about signatures. Most of the solutions that are out there are mainly based on signatures, and I have to do a lot of maintenance to get the signature updates, and sometimes, due to a lack of resources, I am not able to do so. With CloudGuard WAF, I have peace of mind, because most of the features are AI-based, and there is not much configuration that needs to be done on my side. Once set, I only go to CloudGuard WAF to check. I do not have to worry about signatures or updates. Everything is done perfectly, and I have a sense of peace because I know our applications are safe. It is very important for us that CloudGuard WAF protects our applications against threats without relying on signatures. That is definitely one of the key features I need.
Archana Heeralal - PeerSpot reviewer
A good solution to implement web application firewall for applications
There are some lags in Signal Sciences for the web application firewalls. Even if we create some custom rules, Signal Sciences cannot capture some of the malicious traffic. There is a little bit of complexity with custom rules that should be removed. Signal Sciences should add a feature called rate limiting with multiple options, wherein I can create a rate limiting based on the cookie request or the IP.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The overall experience with Cloudflare is positive, with a rating of eight out of ten."
"What I like best about Cloudflare is that my company can use it to trace and manage applications and monitor traffic. The solution tells you if there's a spike in traffic. Cloudflare also sends you a link to check your equipment and deployment and track it through peering, so it's a valuable tool."
"Cloudflare is a security SaaS provider that provides security and protects us from any application layer attack."
"The tool is user-friendly."
"The UI is good."
"I rate its stability a ten out of ten."
"Its ease of integration with Office 365 and the fact that it's a good product compared to what I had before"
"The most valuable feature is its usability."
"The ability to preemptively block zero day attacks and detect hidden anomalies is exactly its advantage."
"It is a highly scalable solution with a quick turnaround time for deployment and running of the software across any IT system."
"It is a very scalable and stable solution."
"Whenever there was a new CVE, Check Point CloudGuard WAF used to block them."
"Check Point CloudGuard Network Security helped reduce the cost of ownership for our web application firewall by 50%."
"I have thousands of exposed websites and APIs. Being able to control what is happening and try to prevent any attack is the best feature."
"The first valuable feature is that it is not a complex process to get it up and running. It was not complex at all. We were in a close relationship with the team that developed the app, and it worked in a few hours. The second valuable feature is the information that comes out of it."
"It provides advanced analytics that gives each team time to prepare for any threat that might occur in the future."
"When configuring a web application firewall using Signal Sciences, we configure a rule whereby no one except a few people can access the application."
"The product's most valuable feature is its ability to set up the rules easily."
"Fastly (Signal Sciences) integrates and tags the intermittent traffic based on patterns. It generates signals and provides them in a dashboard where we can view them and decide whether to allow or deny traffic. It's a more advanced and easy-to-navigate dashboard."
 

Cons

"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"Latencies are always a problem."
"One area of improvement is in the Access Rules. Hypothetically, if we wanted to block or challenge traffic outside of the United States, the only way to currently do that (as far as I know) is to enter every single country outside of the United States. That could be a labor intensive job. A solution could be to enable users to create a rule where traffic is only allowed within a certain country."
"They lack a good way to manage DNS as a company, since everything is relegated to single account logins until you get to the higher levels. They have come out with a paid feature to remedy this, but I have not had a chance to fully review it yet to know if it fixes the access problem."
"Areas like how assessment, discovery, and payload are dealt with and how it all comes into your organization can be considered when trying to make suggestions to Cloudflare for improvements."
"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"For large enterprises, the pricing is okay. However, the enterprise price for small projects is a bit high. A mid-tier pricing option would be beneficial."
"Cloudflare doesn't have a reverse lookup. We can only do a DNS lookup to get the IP address from the hostname. It doesn't work if you want to look up the hostname from an IPA address."
"When I migrate the traffic from our mobile application to CloudGuard, we are not getting what we expected."
"It doesn't detect user activity like some of its competitors. It's not a vulnerability, but it's a legitimate activity that it doesn't detect. It only detects vulnerabilities or misconfigurations."
"Pricing is high, although possibly justified by the service received."
"Support could be improved, particularly in terms of availability."
"I am pretty happy with the current version. I have not yet used it to its full potential, but there could be improvements as I explore it further."
"The reporting can be improved."
"One of the big problems we found in Check Point, in general, is the support."
"I have encountered issues with Check Point CloudGuard Application Security's technical support. It also has missing configuration features."
"Even if we create some custom rules, Signal Sciences cannot capture some of the malicious traffic."
"The areas that could be improved in Signal Sciences include the effectiveness of rules, as many didn't function optimally and required custom rule-writing to address bypasses for WAF."
"Fastly don't support caching for China users. That's the only feature lacking compared to Akamai."
 

Pricing and Cost Advice

"We don't have any issues with the price."
"The price of the solution is expensive."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"The solution is expensive when compared to other products but offers unlimited bandwidth."
"So far I use free tier and happy with it. You can subscribe to business package if needed."
"That is one of the great features. I was able to access the majority of the features and services for free."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"I believe their performance has improved, but I'd like to refrain from discussing the pricing aspect related to the cloud. The pricing, in my opinion, could be simplified, and I think they should consider reevaluating the pricing for support, as it can be quite high. At times, this cost can make it challenging to choose CARFAGuard or opt for the support."
"The pricing is not that expensive considering what it offers."
"The tool's licensing costs are yearly and competitive."
"I work for an Indian banking client. In India, companies are on a budget. The company liked Check Point very much, but it was a little bit costly compared to FortiWeb. However, it had more features compared to FortiWeb."
"The pricing is competitive compared to other solutions on the market. So, the licensing cost is average."
"Considering all the benefits we've observed, we find the price to be satisfactory."
"The sales team or account managers from Check Point are top-notch. As I am using other products as well, my pricing was competitive compared to others."
"As Infiniti customers, the pricing is manageable, as we have allowances dedicated to each Check Point product. The price is not as high compared to other options I have dealt with in the past."
"Check Point CloudGuard Application Security's pricing is not friendly."
"The pricing is 50% less than Akamai."
"Signal Sciences is pretty cheap compared to other solutions."
"The product has an affordable cost."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
17%
Computer Software Company
14%
Comms Service Provider
9%
Financial Services Firm
8%
Computer Software Company
16%
Financial Services Firm
14%
Manufacturing Company
12%
Government
7%
Educational Organization
17%
Computer Software Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What do you like most about CloudGuard for Application Security?
We have not had any incidents. We could realize its benefits immediately. We watched and monitored the traffic, and i...
What is your experience regarding pricing and costs for CloudGuard for Application Security?
I am less knowledgeable with prices because I only define the requirements and look at the execution. I know that its...
What needs improvement with CloudGuard for Application Security?
I would like it to be able to analyze more complex functions, although I did not examine the case study of more compl...
What do you like most about Signal Sciences?
The product's most valuable feature is its ability to set up the rules easily.
What needs improvement with Signal Sciences?
Fastly don't support caching for China users. That's the only feature lacking compared to Akamai.
 

Also Known As

Cloudflare DNS
Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec
Signal Sciences Next-Gen WAF, Signal Sciences RASP
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Orange España, Paschoalotto
Chef, Adobe, Datadog, Etsy, GrubHub, Vimeo, SendGrid, Under Armour, Duo, AppNexus
Find out what your peers are saying about Check Point CloudGuard WAF vs. The Fastly Next-Gen WAF (powered by Signal Sciences) and other solutions. Updated: April 2025.
850,028 professionals have used our research since 2012.