Try our new research platform with insights from 80,000+ expert users

F5 Rules for AWS WAF vs The Fastly Next-Gen WAF (powered by Signal Sciences) comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (1st), WAN Optimization (4th), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (12th)
F5 Rules for AWS WAF
Average Rating
9.0
Reviews Sentiment
7.5
Number of Reviews
2
Ranking in other categories
Business Rules Management (4th), Web Application Firewall (WAF) (29th)
The Fastly Next-Gen WAF (po...
Average Rating
7.6
Reviews Sentiment
4.8
Number of Reviews
4
Ranking in other categories
Web Application Firewall (WAF) (25th)
 

Featured Reviews

HA
Owner at Hga consulting
Has helped manage client domains with streamlined access control and threat visibility
I don't know what areas could be improved with Cloudflare WAF; Cloudflare is constantly improving and adding features to their feature set. They're doing a good job, and as far as DNS and support for any domains that I create or my clients create, it's mandatory for me to make sure that they have Cloudflare as their DNS provider. The Cloudflare load balancing capability hasn't really helped in enhancing my website's uptime and resiliency because we don't really get that much traffic; it's mostly remote users, and web hosting is done by a web hosting service. It doesn't pay to try to host your own website.
reviewer2783919 - PeerSpot reviewer
Associate Vice President at a tech services company with 10,001+ employees
Managed security rules have protected our public e‑commerce sites and simplified ongoing defense
I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF. These are managed rule sets, so you do not need to worry about continuous improvements or ensuring your application is secure; F5 Rules for AWS WAF will take care of that and is always making the necessary improvements in these rule sets to ensure security. I am very impressed with the rule sets and the continuous engineering from their security team to ensure the required rule set availability. I really appreciate the fantastic job they are doing. F5 Rules for AWS WAF can be integrated with AWS CloudFront, Application Load Balancer, Lambda, and API Gateway. I am satisfied with all these services as they are our intermediary points for services exposed to the public or globally. I gave this product a rating of ten out of ten.
reviewer2161107 - PeerSpot reviewer
Staff Engineer at a retailer with 1,001-5,000 employees
Room for improvement with user interface while competitive pricing impresses
It is managed through Infrastructure as Code, so all configurations can be managed in the code itself, which is beneficial. Because it uses rules, it is easy to set up, and we have many different sites where the configurations are straightforward. Though the UI is not very interactive, which is a downside, we can manage many things. The UI is not very intuitive and could be better. However, we manage all the configurations through code, which is easy to maintain. It has extensive anomaly detection capabilities, so the traffic is classified into several categories where thresholds can be defined and customized based on false positives and false negatives. This is advantageous because you do not need to tweak it very often. Once you set it up, an audit once a quarter would suffice. Because The Fastly Next-Gen WAF (powered by Signal Sciences) is API-driven, we have integrations with the CI/CD pipeline through GitHub Actions, making it easy to integrate.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I rate its stability a ten out of ten."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"It's a great product because it's scalable, has great coverage, and is mature with good defenses against DDoS attacks."
"Cloudflare consolidates various capabilities into one product, streamlining processes."
"Cloudflare makes it easier for me to handle and set up DNS for multiple users and multiple clients, and basically go in and access their account, make the changes they need, and it's a one-stop shop."
"When using services like Heroku, Cloudflare is very useful for CNAME flattening. I also use it for their end-to-end SSL with TLS authentication on nginx for securing servers."
"It's very user-friendly."
"The most valuable feature is the web application firewall."
"F5 Rules for AWS WAF has positively impacted our organization for security through the implementation of traffic rules in our application."
"I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF."
"I advise anyone looking for a great tool to secure their public-facing applications to start using F5 Rules for AWS WAF."
"Because The Fastly Next-Gen WAF (powered by Signal Sciences) is API-driven, we have integrations with the CI/CD pipeline through GitHub Actions, making it easy to integrate."
"When configuring a web application firewall using Signal Sciences, we configure a rule whereby no one except a few people can access the application."
"The product's most valuable feature is its ability to set up the rules easily."
"Fastly (Signal Sciences) integrates and tags the intermittent traffic based on patterns. It generates signals and provides them in a dashboard where we can view them and decide whether to allow or deny traffic. It's a more advanced and easy-to-navigate dashboard."
 

Cons

"We have noticed multiple instances where Cloudflare falsely indicates that our servers are down, even when there is no actual load on them. This makes it challenging for us to identify the exact issue."
"The product needs to improve its automation."
"It should confirm audit findings of the assigned area with auditees to ensure that the audit conclusions are based on an accurate understanding of the issues."
"One area of improvement is in the Access Rules. Hypothetically, if we wanted to block or challenge traffic outside of the United States, the only way to currently do that (as far as I know) is to enter every single country outside of the United States. That could be a labor intensive job. A solution could be to enable users to create a rule where traffic is only allowed within a certain country."
"DNS Management."
"It would be beneficial for us if Cloudflare could offer a scrubbing solution. This would involve taking a snapshot of my website and keeping it live during a DDoS attack, ensuring uninterrupted service for our users. DDoS attacks are typically short in duration, and having Cloudflare maintain the site's availability from its secure network would enhance the overall user experience. I would appreciate it if Cloudflare could consider implementing this feature. Many organizations already utilize similar capabilities in their CDN platforms, where a static snapshot of the web page is displayed during DDoS attacks. In terms of features, Cloudflare needs to enhance its resilience and stay more focused on adopting new technologies. For instance, solutions like F5 XC Box, Access Solution, and Distributed Cloud Solution have impressive features, and Cloudflare should strive to match and exceed those capabilities. There's a need for improvement in areas like AI-based DDoS attacks and Layer 7 WAF features. Cloudflare should prioritize enhancements in areas such as behavioral DDoS and protection against SQL injection attacks, considering the prevalent trend of public exposure to the internet for business reasons. Overall, Cloudflare needs to invest more in advancing its feature set."
"Cloudflare does not have an on-premise solution. If they had different approaches they could be better suited to accommodate more customers, such as on-premise and hybrid deployments. For example, hybrid deployments would be useful where you could move the traffic from the enterprise to the cloud."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these rule sets."
"It's too early to talk about a return on investment with F5 Rules for AWS WAF."
"An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these rule sets."
"The areas that could be improved in Signal Sciences include the effectiveness of rules, as many didn't function optimally and required custom rule-writing to address bypasses for WAF."
"Even if we create some custom rules, Signal Sciences cannot capture some of the malicious traffic."
"Fastly don't support caching for China users. That's the only feature lacking compared to Akamai."
"The UI is not very intuitive and could be better."
 

Pricing and Cost Advice

"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"We don't have any issues with the price."
"There are no additional costs beyond the standard licensing fees."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"I give the price a five out of ten."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"For Cloudflare, I recommend it heavily for small businesses with revenue under a couple of million dollars. Onboarding is easy, and they even have a free plan. This makes it simple for businesses in the $100,000-$500,000 range to try it out and see its value, allowing them to scale up their infrastructure as needed."
"The cost primarily depends on the size of the organization."
Information not available
"Signal Sciences is pretty cheap compared to other solutions."
"The product has an affordable cost."
"The pricing is 50% less than Akamai."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
879,768 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
8%
No data available
Manufacturing Company
12%
Computer Software Company
12%
Retailer
10%
Financial Services Firm
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise25
No data available
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What is your experience regarding pricing and costs for F5 Rules for AWS WAF?
From the pricing perspective, I found it to be comparable to other marketplace rules available in AWS Marketplace. It...
What needs improvement with F5 Rules for AWS WAF?
An area for improvement I see is that while everything is in good shape, I demand continuous improvisation of these r...
What is your primary use case for F5 Rules for AWS WAF?
We are providing support to our end customers who have e-commerce websites that need to be exposed to the public, and...
What do you like most about Signal Sciences?
The product's most valuable feature is its ability to set up the rules easily.
What is your experience regarding pricing and costs for Signal Sciences?
The pricing is very competitive compared to other providers. The pricing is definitely a factor in our decision-makin...
What needs improvement with Signal Sciences?
We do use it, but the UI can be improved as we mostly work through the CI/CD. It provides support, but sometimes it i...
 

Also Known As

Cloudflare DNS
No data available
Signal Sciences Next-Gen WAF, Signal Sciences RASP
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Information Not Available
Chef, Adobe, Datadog, Etsy, GrubHub, Vimeo, SendGrid, Under Armour, Duo, AppNexus
Find out what your peers are saying about F5 Rules for AWS WAF vs. The Fastly Next-Gen WAF (powered by Signal Sciences) and other solutions. Updated: December 2025.
879,768 professionals have used our research since 2012.