No more typing reviews! Try our Samantha, our new voice AI agent.

F5 Rules for AWS WAF vs Sucuri comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

F5 Rules for AWS WAF
Ranking in Web Application Firewall (WAF)
14th
Average Rating
8.4
Reviews Sentiment
7.8
Number of Reviews
10
Ranking in other categories
Business Rules Management (3rd)
Sucuri
Ranking in Web Application Firewall (WAF)
36th
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
6
Ranking in other categories
Distributed Denial-of-Service (DDoS) Protection (25th), Domain Name System (DNS) Security (25th)
 

Mindshare comparison

As of August 2026, in the Web Application Firewall (WAF) category, the mindshare of F5 Rules for AWS WAF is 0.4%, up from 0.0% compared to the previous year. The mindshare of Sucuri is 1.6%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
F5 Rules for AWS WAF0.4%
Sucuri1.6%
Other98.0%
Web Application Firewall (WAF)
 

Featured Reviews

Vibin Thomas - PeerSpot reviewer
Technical Team Lead - Content Security at Valuepoint Systems
Advanced protection has reduced web attacks and improves application performance and operations
One area where F5 Rules for AWS WAF can be improved is in simplifying the tuning process. While F5 Rules for AWS WAF is powerful, fine-tuning it to match specific application behavior can sometimes be complex and time-consuming, especially for teams without deep WAF expertise. Another improvement could be enhanced visibility and reporting. Although AWS WAF provides logs, having more intuitive and built-in dashboards or clearer categorization of rule triggers would make it easier to quickly identify and analyze attack patterns. Additionally, expanding the capabilities around bot management and behavior analysis would be beneficial compared to some dedicated bot management solutions. More advanced detection techniques could further strengthen the protection against sophisticated automated traffic. Finally, providing more predefined templates or best practice recommendations for different application types would help speed up the deployment and reduce the initial configuration effort.
JS
Hardware Engineer at Ministry of Defense
A cost-effective choice for website security and informative support with issues related to CDN quality
One area where they could improve is in providing real-time support options because now you need to open a support ticket and wait for their response. It would greatly benefit customers if they implemented an online chat or messaging system for quicker assistance. I have found their Content Delivery Network service to be lacking in quality, and it could certainly be enhanced to provide better performance. I would also like to see improvements in the deployment process, as it currently takes more time than desirable. Another significant concern is that their service when your website is down, turns it into a static site. This means that if customers try to visit your site during downtime, they will see old content from the static site, which is not ideal. The CDN and tracking services are areas that need improvement, as well as addressing their bandwidth limitations.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"F5 Rules for AWS WAF has positively impacted our organization for security through the implementation of traffic rules in our application."
"F5 Rules for AWS WAF is a strong, enterprise-focused solution for organizations that need robust web application security, centralized policy management, and better visibility into application layer threats within AWS environments."
"F5 Rules for AWS WAF should be highly recommended for AI applications, as security is a major concern, and using F5 helps prevent security issues and stabilizes organizations and applications."
"F5 Rules for AWS WAF's OWASP protection and bot protection have reduced attacks on my applications by 72 to 90%."
"After implementing F5 Rules for AWS WAF, we observed a reduction of approximately 60 to 70% in web application security incidents reaching our application team, particularly blocking common threats like bot traffic and SQL injections without impacting our downstream systems."
"Overall, the combination of reduced manual effort, improved security posture, and better application performance has delivered a strong return on investment."
"I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF."
"F5 Rules for AWS WAF is definitely recommended. It is a good tool for anyone to try and see if it matches their use case, and it is something that an organization can really benefit from."
"I use it as a WAF, which is basically a web firewall to monitor and block traffic to our web server."
"The initial setup was straightforward. Straight forward because the plugin can simply be installed and then it does its job. It's not complex, there is no learning curve. The online scan is simple, you put in the website address and the scan gives us a report on the browser itself. It's simple to use."
"For people who own a personal website, this solution is worth trying out since their security solution is somewhat full-fledged."
"Domain name scanning since it allows us to scan all our domain names and determine whether it has malware or if is reported as phishing."
"The initial setup was very easy."
"It significantly eases the workload and streamlines the initial setup required to protect a website."
"Rather than locate some things manually, the Sucuri plugin scans and allows us to pinpoint whether there is malware or some problem in the site."
"The most valuable part is the analytics and visualization."
 

Cons

"One area where F5 Rules for AWS WAF can be improved is in simplifying the tuning process."
"It's too early to talk about a return on investment with F5 Rules for AWS WAF."
"There are potential false positives in F5 Rules for AWS WAF that sometimes require tuning."
"I think F5 Rules for AWS WAF could be improved mainly around visibility, specifically having more actionable recommendations for false positives."
"From an improvement standpoint, one area where F5 Rules for AWS WAF could improve is in simplifying policy management and making advanced configurations more intuitive, especially for teams that are newer to enterprise WAF technologies."
"F5 Rules for AWS WAF could be improved with deeper integration with Infrastructure as Code tools like Terraform for simplification, as well as more AI-driven recommendations for rules tuning to reduce false positives and better dashboards for visibility at the CXO level."
"An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these rule sets."
"F5 Rules for AWS WAF can be improved by simplifying the tuning process to reduce false positives and providing more built-in dashboards for better visibility and further customization."
"In terms of improvement, the cost factor is always there."
"It would greatly benefit customers if they implemented an online chat or messaging system for quicker assistance."
"The main improvement I would like to see is support for .NET applications. If they could include this feature, I would include more sites in the protection."
"Confident score: Currently it does not have one and there are cases that most websites flagged are false-positives."
"I would rate this solution an eight out of ten. The reason is that we have found sometimes customers or Google saying that there is something wrong with the website but Sucuri says that the site is clean so we do have to look at the site manually which means that the Sucuri scan does not pick up anything and everything."
"Sucuri could provide help for specific security alerts in-line instead of requiring users to search for it in the help section."
 

Pricing and Cost Advice

Information not available
"It stands out as a more cost-effective option compared to other cloud-based security services like Cloudflare or JetPass."
"Sucuri offers different plans, both the standard plan and an advanced plan. So there are different plans to choose from."
"The ROI has been very good. Because of the solution, I have a tax break. The site developers were not always experienced people. We used to pay more for cleaning up the site when it was infected. Now, we have peace of mind knowing that the solution will clean up the site and that we won't have to go through the unnecessary process of restoring it from a backup. The protection on the WAF and the measures for backups have also prevented our site from going down."
"I’d simply say it’s really worth it."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
33%
Comms Service Provider
16%
Computer Software Company
6%
Energy/Utilities Company
5%
Comms Service Provider
14%
Construction Company
13%
Financial Services Firm
10%
Outsourcing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise1
Large Enterprise7
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for F5 Rules for AWS WAF?
My experience with the pricing, setup cost, and licensing for F5 Rules for AWS WAF was good with purchasing and the setup cost.
What needs improvement with F5 Rules for AWS WAF?
The additional costs for F5 Rules for AWS WAF are quite high, as F5 managed rules require a separate subscription on top of the standard AWS WAF charges; it would be great if it would be pre-integr...
What is your primary use case for F5 Rules for AWS WAF?
F5 Rules for AWS WAF manages the security rule set by applying the rules and setting the block directly in AWS WAF to provide advanced protection against web application attacks, bots, threats, and...
Ask a question
Earn 20 points
 

Comparisons

 

Overview

 

Sample Customers

Information Not Available
The Loft Salon, Tom McFarlin, WPBeginner, Taylor Town, Everything Everywhere, Financial Ducks in a Row, Chubstr, Real Advice Gal, Sujan Patel, Wallao, List25, School the World
Find out what your peers are saying about F5 Rules for AWS WAF vs. Sucuri and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.