No more typing reviews! Try our Samantha, our new voice AI agent.
RaynielBadiola - PeerSpot reviewer
Technical Director at Secur Links
Real User
Top 5
Jul 22, 2026
Advanced protection has mitigated ddos and zero-day threats while simplifying app security
Pros and Cons
  • "Radware Cloud WAF Service can immediately determine the cause of problems and easily mitigates the vulnerabilities and attacks that it sees."

    What is our primary use case?

    The use case involves protecting applications by redirecting them to Radware Cloud WAF Service. The implementation depends on the number of applications you want to protect.

    How has it helped my organization?

    There are definitely improvements to the organization.

    What is most valuable?

    The main feature is to mitigate DDoS attacks. Radware Cloud WAF Service also provides cloud WAF services for applications to be protected, especially web applications, particularly under the OWASP Top 10 vulnerabilities.

    Cloud has a behavioral-based feature that can eliminate false positives.

    Radware Cloud WAF Service has behavioral-based AI or machine learning capability that minimizes or eliminates zero-day attacks.

    It is very important because it can eliminate zero-day using the behavioral-based feature of Radware Cloud WAF Service. It also has negative and positive security models. The positive security model determines those signature-based vulnerabilities and attacks. The negative and behavioral models eliminate zero-day attacks.

    What needs improvement?

    There is no room for improvement that I can see at this time because it is very straightforward.

    I do not think it needs improvement as it already has an AI component. Radware Cloud WAF Service has agentic AI as well, which allows you to chat with them to inquire about current vulnerabilities and resolutions. The AI will eventually provide recommendations. At this time, I do not see anything to improve. They have just added these AI features.

    Buyer's Guide
    Radware Cloud WAF Service
    September 2026
    Learn what your peers think about Radware Cloud WAF Service. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
    914,394 professionals have used our research since 2012.

    For how long have I used the solution?

    I have been using this solution for about 15 plus years.

    What do I think about the stability of the solution?

    In terms of stability, I rate it as nine out of 10.

    What do I think about the scalability of the solution?

    I rate it as eight.

    How are customer service and support?

    In terms of technical support, they are very responsive. The moment you open a case with them, they will respond to your case within a few minutes.

    How was the initial setup?

    The implementation actually depends on the requirements of the customers and how many applications there are to be protected. It will only take a couple of hours, or maybe an hour, to implement the initial setup. It is up to the customer to add applications that they want to protect.

    What about the implementation team?

    We assist them to do the implementation together with the Radware Cloud team.

    For our team, as we are the integrator or the distributor, we only have one who is assisting the Radware team to do the implementation. Radware has only one technical or support team that does the implementation and configuration of cloud.

    What was our ROI?

    There is probably a little cost reduction for their cloud WAF or cloud DDoS subscription.

    What other advice do I have?

    It is very simple to integrate with other third-party products, such as SIEMs, and there are no problems integrating with them.

    Radware Cloud WAF Service can immediately determine the cause of problems and easily mitigates the vulnerabilities and attacks that it sees.

    I give Radware Cloud WAF Service a support rating of nine out of 10. My overall review rating for this solution is 9 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
    Last updated: Jul 22, 2026
    Flag as inappropriate
    PeerSpot user
    Coordinador Nacional De TIC Y Sistemas De La Universidad Catlica Boliviana San Pablo at Bolivian Catholic University
    Real User
    Top 20
    Sep 22, 2026
    Service has kept frequent attacks under control and provides strong protection every day
    Pros and Cons
    • "What I appreciate the most about Radware Cloud WAF Service is the security that we have, as we experience many attacks constantly, and because of the service, we remain secure."
    • "I am considering moving away from Radware Cloud WAF Service because of the price."

    What is our primary use case?

    I have some experience with Radware Cloud WAF Service, as I obtained your contact information from Radware.

    I would be interested in leaving feedback about Radware Cloud WAF Service because I appreciate all aspects of the service. All of the service is very helpful for us, but we are currently evaluating whether we will continue with this service.

    I have been using Radware Cloud WAF Service for three years.

    What is most valuable?

    What I appreciate the most about Radware Cloud WAF Service is the security that we have. It is something we need greatly, and it is very helpful for us. We experience many attacks constantly, and because of the service, we remain secure.

    Radware Cloud WAF Service does an excellent job at blocking unknown threats and attacks.

    What needs improvement?

    I think Radware Cloud WAF Service could improve with application notifications. That would be very helpful.

    I expect to receive notifications when I have an incident or anything to check.

    For how long have I used the solution?

    I have been using Radware Cloud WAF Service for three years.

    What do I think about the stability of the solution?

    Regarding stability, we have received some notifications, but we did not actually notice any issues.

    What do I think about the scalability of the solution?

    I think Radware Cloud WAF Service is scalable because we experience perhaps one or two days every semester when we have some peaks in service demand, but we did not encounter limits on the service. It scales up automatically, and it did not cut the service for us. That is a very good thing, because it is not constant—it occurs only two to four days per year.

    How are customer service and support?

    I have contacted the technical support of Radware twice in three years when we needed some configuration.

    My experience with the quality of the support and the speed of response was quick.

    I think the quality of the support is good. It is a good service.

    If I were to rate them on a scale from one to ten, I would give the support a score of ten.

    Which solution did I use previously and why did I switch?

    I have not used any alternatives or similar solutions to Radware Cloud WAF Service in the cloud.

    How was the initial setup?

    The initial deployment of Radware Cloud WAF Service was easy.

    It took me approximately a couple of days to deploy it for the first time.

    What about the implementation team?

    Approximately three persons were involved in the deployment of Radware Cloud WAF Service.

    What other advice do I have?

    I am thinking of moving away from Radware Cloud WAF Service.

    I am considering moving away from Radware Cloud WAF Service because of the price. I love the service, but the price is very expensive for us. We have to renew the service, but we are evaluating some alternatives because of the cost.

    Radware Cloud WAF Service does not require any maintenance on my end.

    I do not use the API Discovery feature.

    I do not use any CDN services or Content Delivery Networks.

    I think the reporting and analytics provide a good reporting service.

    I would give this review an overall rating of ten.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    Last updated: Sep 22, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Radware Cloud WAF Service
    September 2026
    Learn what your peers think about Radware Cloud WAF Service. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
    914,394 professionals have used our research since 2012.
    Vladimir Castro Paulino - PeerSpot reviewer
    Analista de Infraestructura at Expreso Brasilia S.A.
    Real User
    Top 20
    Apr 15, 2026
    Protection for web apps has improved and monitoring now provides clear attack visibility
    Pros and Cons
    • "Radware Cloud WAF Service has enabled me to save time by viewing and monitoring the traffic that my applications receive, since it isolates the attacks or threats that my web applications face."
    • "To make Radware Cloud WAF Service even more useful for my organization, I believe there should be greater integration with other tools, such as log tools."

    What is our primary use case?

    The main use case for which I use Radware Cloud WAF Service is the protection of web applications. I protect a web application from denial-of-service attacks using Radware Cloud WAF Service.

    What is most valuable?

    The best features that Radware Cloud WAF Service offers include the deployment, as it is very easy to implement, and the platform management is efficient.

    The specific aspects that make the implementation process simple in my experience are the integration and the redirection to the web applications.

    Radware Cloud WAF Service has enabled me to save time by viewing and monitoring the traffic that my applications receive, since it isolates the attacks or threats that my web applications face.

    What needs improvement?

    To make Radware Cloud WAF Service even more useful for my organization, I believe there should be greater integration with other tools, such as log tools.

    I would rate it a 9 and not a 10 because the dashboard is sometimes not as intuitive as it could be for displaying the necessary information. You have to take a few extra steps in order to view the information you need.

    For how long have I used the solution?

    I have been using Radware Cloud WAF Service for approximately 3 years.

    What do I think about the stability of the solution?

    I consider Radware Cloud WAF Service to be quite stable in its daily operation.

    What do I think about the scalability of the solution?

    I would rate the scalability of Radware Cloud WAF Service as good, as it adapts well to the growth of my needs.

    How are customer service and support?

    My experience with Radware Cloud WAF Service's customer support has been excellent, as the partner we have responds to us on time and as diligently as possible.

    Which solution did I use previously and why did I switch?

    Before using Radware Cloud WAF Service, we did not have any solution previously.

    What was our ROI?

    I have seen time savings due to the visualization and monitoring of the attacks on the applications since I started using Radware Cloud WAF Service.

    What's my experience with pricing, setup cost, and licensing?

    My experience with the pricing, implementation cost, and licensing of Radware Cloud WAF Service is that it costs what it is worth for what you receive.

    Which other solutions did I evaluate?

    Before choosing Radware Cloud WAF Service, I evaluated alternatives such as Barracuda and Cloudflare WAF.

    What other advice do I have?

    The advice I would give to other companies considering implementing Radware Cloud WAF Service is to take into account that it is an excellent tool for protecting their applications. I would rate this solution a 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    Last updated: Apr 15, 2026
    Flag as inappropriate
    PeerSpot user
    Pankaj Kaushik - PeerSpot reviewer
    Security Operations Engineer at a tech vendor with 10,001+ employees
    Real User
    Top 5
    Sep 8, 2025
    Advanced security features and top-notch support help manage threat detection and API sprawl efficiently
    Pros and Cons
    • "Radware Cloud WAF Service's Web DDoS protection, HTTP L7, has significantly helped us protect our customer networks, mitigating all types of web attacks and ensuring no fluctuations or leaks even when large numbers of malicious bot IPs are attacking our network."
    • "The integration part of the Radware Cloud WAF Service is complex. Being a security operation engineer or a SOC engineer, managing complex devices can prove challenging."

    What is our primary use case?

    My use cases for Radware Cloud WAF Service are basically engaged whenever we have a huge amount of attacks on our on-prem solutions. During that specific period, we do the migration from the on-prem to the scrubbing center, and at that point of time, we have this specific subscription for Radware Cloud WAF Service, which is to manage the web filtering of the application services passing through this Radware solution. What we expect from this is a combination of both signature-based and behavioral-based security models, alongside machine learning to detect and block threats without actual manual tuning.

    How has it helped my organization?

    The Source Blocking feature has been used for IP agnostic device fingerprinting, especially when there is a major challenge with simple IP-based sources and multiple source IPs attacking the networks. This device fingerprinting helped us collect dozens of browsers and devices, enabling us to create a unique fingerprint for each user. By doing this, we could block around 1500 or 1600 malicious source IPs, which were basically bot switch IPs. This has significantly narrowed down the attacks, stabilizing our service and ensuring no fluctuations or leaks, especially when a large number of malicious bot IPs are attacking our network.

    We use the Radware Bot Manager, particularly when there are numerous registered bot devices, leveraging the Internet-based Deep Behavior Analysis (IDBA) to check movements, keystrokes, scrolling patterns, and other human interactions. This capability helps us collect unique attributes and create specific responses, such as blocking malicious bot IPs. In instances where we lack in-house expertise to manage and fine-tune bot policies, this feature effectively manages those services. The Radware ERT (Emerging Response Team) monitors and responds to bot attacks 24/7, providing human oversight that complements all automated systems to further reduce false positives and ensure continuous protection from incoming attacks.

    Radware Cloud WAF Service's Web DDoS protection, HTTP L7, has significantly helped us protect our customer networks, earning a performance score of 10 out of 10. This DDoS protection mitigates all types of web attacks. It could be problematic for the customer if even a single attack got through.

    What is most valuable?

    Radware API Discovery is an advanced feature of Radware because it's used whenever there is a huge amount of phenomena called API sprawl. The results might be shadow APIs, zombie APIs, and redundancy. Radware API is about identifying and cataloging all these APIs used within organizations to ensure it includes all third parties, the managed and unmanaged APIs, and secure them so that consumers do not face any disturbances in the services they are using. It ensures that an alert has been generated to the monitoring teams at the time of detection, taking zero or milliseconds to create an alert and notify all monitoring parties about an attack based on such APIs, while also providing the best approaches to mitigate it in the least period of time.

    We use CDN services because they are a basic part of the Radware Cloud WAF Service. If we don't use the CDN services, then it might not be the best security configuration to protect a network. The Radware Cloud WAF Service protects against zero-day attacks at definitely 9.5 to 10. The performance in these cases is really good; I don't even see it utilizing half of the resources while effectively mitigating all the attacks.

    What needs improvement?

    It's medium to difficult to use the Radware API Discovery due to its complexity. I have almost two and a half years of experience, so I'm familiar with this service, but recently, we have had new engineers rolled into our operations teams, and they are finding it challenging to understand from the start because of this complexity and the different approaches for hardening and best practices to ensure everything runs smoothly. So, for a new user, it's between medium to difficult based on the complexity.

    The implementation of Radware Cloud WAF Service is complex. However, this complexity is not solely attributed to the Cloud WAF, as we have experienced compatibility issues with different vendor devices that have hindered integration. While we can integrate it, we definitely face challenges if the engineer does not know exactly how to execute it. The command for the integrations and the procedure are somewhat complex, yet it's really helpful overall. We haven't encountered a single device suggesting that Radware is not compatible for integration. We wanted to integrate with some Cisco devices, but due to version gaps, Cisco TAC informed us that those devices are not compatible for integration with Radware.

    For how long have I used the solution?

    I have been using Radware Cloud WAF Service for almost two years and six months.

    What do I think about the stability of the solution?

    We haven't seen any instability such as lagging, crashing, or downtime. If there had been a downtime, Radware wouldn't be our go-to solution partner because we have critical customers. If downtime occurred, customers would abandon the solution. Our telecom customer is the second largest telecom provider in the UK.

    What do I think about the scalability of the solution?

    For the scalability part of Radware Cloud WAF Service, I would rate it nine out of ten. It's good, but it can be improved.

    How are customer service and support?

    We have contacted Radware technical support on several occasions when a new attack has been detected or if we notice disturbances in the network. We manage different services through various teams, and whenever there is a significant impact, or we observe extreme attack patterns or anomalies in the logs, we reach out to the technical teams to understand the unusual behavior. Most of the time, these issues have arisen due to required version updates.

    I would give the Radware technical support a ten out of ten. They are definitely outstanding.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Before Radware Cloud WAF Service, we used a feature in the FortiGate firewall. Initially, it was a centralized solution, and we had multiple firewalls deployed between the outside network and the intranet. At that time, we had this WAF feature in those FortiGate firewalls that helped us do the work. But when the deployment changed from the centralized in-house solution to an out-of-path approach, Radware pitched the idea of removing the multiple firewalls with a single WAF feature. The customer agreed, and after that, the implementation of the WAF started.

    How was the initial setup?

    The integration part of the Radware Cloud WAF Service is complex. Being a security operation engineer or a SOC engineer, managing complex devices can prove challenging. The integration should not be so complex that engineers expend excessive time just to understand the behavior after entering a single command. I believe the deployment can be simplified by providing exact commands or parameters. However, if Radware adopts this approach, it may unintentionally create vulnerabilities or loopholes. I think if Radware focuses on customer usage and emphasizes making it easier for engineers to work on necessary changes or modifications promptly, it would benefit overall functionality.

    Annual maintenance is not required for the Radware Cloud WAF Service, but we perform quarterly checks on configurations, performance, and the health of devices and resources. Over the past two years, we haven't required maintenance or encountered any configuration issues or device replacements.

    What was our ROI?

    When we talk about the cost, the Radware API Discovery has definitely helped us because once it was implemented, we are not facing any SLA breach issues with the customers whose network we are protecting via this service, helping us save a lot of money. When there is an SLA breach, the critical part is identifying the issue, so this is helping us do that within the minimum period of time, allowing us to mitigate it as soon as possible. It helps us in those scenarios where we are not paying a huge penalty to the customers whose network we protect. Also, it helps narrow down manpower costs since we don't need many engineers to manage this solution; only one or two engineers are enough to maintain it.

    What other advice do I have?

    I haven't discovered anything new about incoming bot traffic by using the Radware Bot Manager. We haven't seen any new behavior that is suspicious or problematic.

    Regarding real-time BLA detection and mitigation, this feature is not used much in our environment. We have it enabled, but we have not utilized it frequently since it focuses on real-time protection against all business logical attacks. Our emphasis is on consumer services in telecommunications, and the primary feature we use is behavior-based detection. For example, the Radware BLA can detect forced browsing, where an attacker bypasses normal navigation behavior to access restricted pages or files. However, we get attacks primarily disturbing services calls and SMS, not in business areas banking; thus, we don't leverage this feature much.

    We have seen a reduction in the false positives with the Radware Cloud WAF Service. However, the number is still not that low; it has helped us identify false positives, but in some cases, out of 100, there are still seven to eight false positives. That number is not good for us from a security perspective.

    I would rate Radware Cloud WAF Service a nine out of ten.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
    PeerSpot user
    Roberto Carlos Castellar Ardila - PeerSpot reviewer
    Coordinador de Innovacion Tecnologica y SAP at Expreso Brasilia
    Real User
    Top 5
    Apr 16, 2026
    Cloud security has strengthened API protection and now reduces downtime for critical transactions
    Pros and Cons
    • "Other companies considering using Radware Cloud WAF Service will find a very robust tool that has different types of applications for managing all the APIs, all the applications, and controlling the security of all the entities."
    • "Something that could be added to Radware Cloud WAF Service would be a bit more training and not having to depend so much on the vendor, because sometimes when you have to configure advanced policies it requires a lot of experience and dependence on the vendor to provide support throughout the implementation of those advanced policies."

    What is our primary use case?

    Radware Cloud WAF Service protects the web applications that are the APIs and transactional systems. In the WAF, all the protection is configured for the website and internal ticket sales system. In addition to everything related to the tickets, all APIs are protected, which is very useful for the microservices architecture and all the integrations with the different providers.

    What is most valuable?

    The best features offered by Radware Cloud WAF Service are the ease of integration, in addition to all the security it offers, the high availability it has, and the automatic updating of the solutions.

    Radware Cloud WAF Service has had a positive impact with improvements in security. All issues related to incidents have been reduced, and it informs and gives control over any latency or any misuse that someone might try with an API.

    Denial-of-service issues and the downtime of those APIs have been mitigated by approximately 30%, since previously, over a period of time, there were quite a few outages. With this integration of the tool to mitigate all those issues, it has improved in that sense.

    What needs improvement?

    Something that could be added to Radware Cloud WAF Service would be a bit more training and not having to depend so much on the vendor, because sometimes when you have to configure advanced policies it requires a lot of experience and dependence on the vendor to provide support throughout the implementation of those advanced policies.

    The interface is quite intuitive, and there are no other improvements needed.

    For how long have I used the solution?

    Radware Cloud WAF Service has been used for approximately two years.

    What do I think about the stability of the solution?

    Radware Cloud WAF Service is quite stable.

    What do I think about the scalability of the solution?

    Radware Cloud WAF Service has been able to adapt as the organization has grown a lot in applications and APIs, and the tool has worked without any issues.

    How are customer service and support?

    The experience with Radware Cloud WAF Service's customer support has been quite positive. They have always assisted quickly and without any issues whenever assistance has been needed.

    Which solution did I use previously and why did I switch?

    No other solution was used before implementing Radware Cloud WAF Service.

    How was the initial setup?

    The process of integrating Radware Cloud WAF Service into the environment was very quick. Everything really was very fast, and with the documentation provided, it was possible to do it easily and achieve the objective, which was to integrate the platform.

    What about the implementation team?

    The organization is only a customer of the vendor.

    What was our ROI?

    All the benefits obtained have been in security, in prestige, and from using this type of tool for the operation.

    What's my experience with pricing, setup cost, and licensing?

    The cost of Radware Cloud WAF Service is actually a bit high, but given all these benefits, the investment makes sense.

    Which other solutions did I evaluate?

    Other options in the market were evaluated, looking at different alternatives from different vendors. Palo Alto and Check Point were evaluated before deciding on Radware Cloud WAF Service.

    What other advice do I have?

    Radware Cloud WAF Service is deployed in public cloud, directly on Radware's cloud in the public cloud. Being in the cloud is quite a strong point for Radware Cloud WAF Service.

    Other companies considering using Radware Cloud WAF Service will find a very robust tool that has different types of applications for managing all the APIs, all the applications, and controlling the security of all the entities.

    Everything important about Radware Cloud WAF Service has been covered in this interview. This interview is considered very complete and appropriate for the moment and for the product. This review has been given a rating of 9.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    Last updated: Apr 16, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2754852 - PeerSpot reviewer
    Deputy Manager at a energy/utilities company with 10,001+ employees
    Real User
    Top 20
    Sep 6, 2025
    Email alerts and early warnings effectively manage DDoS and zero-day threats
    Pros and Cons
    • "The most advanced feature is the DDoS protection and the way this web handles DDoS attacks, as I am currently working in the SOC team and managing the Radware administration part."
    • "The dashboard of Radware Cloud WAF Service could be more interactive and user-friendly."

    What is our primary use case?

    The core use cases for Radware Cloud WAF Service are web application firewall functionality, DDoS protection, and protection against zero-day vulnerability and emerging threats.

    What is most valuable?

    The most valuable aspect of Radware Cloud WAF Service is that it supports mode detection and provides email alerts on sudden alert spikes and early warnings. The most advanced feature is the DDoS protection and the way this web handles DDoS attacks, as I am currently working in the SOC team and managing the Radware administration part.

    Regarding zero-day attacks, Radware Cloud WAF Service helps us actively receive early warnings, and we raise those to the relevant teams. The services related to zero-day attacks and threat intelligence are very effective.

    What needs improvement?

    The dashboard of Radware Cloud WAF Service could be more interactive and user-friendly. While implementing it for the first time, it requires core technical knowledge, and without that knowledge, implementation can be quite challenging. However, the support from Radware is excellent when support cases are raised.

    For how long have I used the solution?

    I have been using Radware Cloud WAF Service for three and a half years in my career after joining my current organization.

    What do I think about the stability of the solution?

    Regarding stability, I have not experienced any lagging, crashing, or downtime in my experience with Radware Cloud WAF Service.

    What do I think about the scalability of the solution?

    Radware Cloud WAF Service is scalable; once we set up the entire service and it is up to date, we can onboard as many applications as our license allows.

    How are customer service and support?

    I have contacted Radware's technical support many times, and their quality is very good as we receive timely support according to the case priority. Their engineers are skilled and capable enough to resolve issues quickly.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I have used alternatives to Radware Cloud WAF Service, specifically Akamai Web Service, which is a very popular service. One of its disadvantages is that it does not support custom ports like Radware does.

    How was the initial setup?

    The entire process of onboarding the application for the first time with Radware Cloud WAF Service requires core technical knowledge, but with the support of Radware, it becomes much easier.

    Which other solutions did I evaluate?

    The pricing of Radware Cloud WAF Service is lower compared to Akamai, and while the price in the industry is acceptable, it is not too expensive.

    What other advice do I have?


    The combination of negative and behavioral-based positive security models provided by Radware Cloud WAF Service is very important for my organization's security strategy, as the main purpose of Radware WAF is security.

    Regarding maintenance, we receive quarterly reports, which are sufficient.

    On a scale of 1-10, I rate Radware Cloud WAF Service an 8.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Pranav-Patel - PeerSpot reviewer
    IT Manager at Adani Enterprises Ltd
    Real User
    Top 20
    Sep 3, 2025
    Ease of use allows effective investigation and real-time anomaly detection
    Pros and Cons
    • "Radware Cloud WAF Service is great in terms of blocking unknown threats and attacks; everything seems perfect to me, and I have no complaints or issues regarding the blocking capability."
    • "Radware Cloud WAF Service has drawbacks when compared to other WAF solutions, particularly because we were checking other solutions that support custom ports for application onboarding."

    What is our primary use case?

    Radware Cloud WAF Service is utilised for analysis. As part of a SOC team and Incident Response Manager role, the team investigates incoming traffic to onboarded applications, identifies potentially malicious traffic, and takes appropriate action. This includes creating and modifying WAF rules and making decisions about which traffic is allowed or blocked, as well as IP blocking and related measures.

    How has it helped my organization?

    Radware Cloud WAF Service effectively blocks unknown threats and attacks, with no issues regarding its blocking capabilities.

    The automated analytics meet my expectations for event analysis.

    Its real-time, behavior-based anomaly detection benefits our threat management by reliably detecting and blocking malicious traffic.

    What is most valuable?

    Radware Cloud WAF Service is easy to use and requires little experience or resources. Basic tasks can be completed with minimal effort.

    Integration was seamless, and the source blocking feature works well.


    What needs improvement?

    Radware Cloud WAF Service could improve its application onboarding process, as it only supports ports 80, 443, and 1024–65535; key ports like 993 and 995 needed for SMTP are unsupported, limiting email app protection. For IP whitelisting, the current setup allows all traffic from a specific allowed(whitelisted) IP without detection, which exposes threat. A more granular approach—allowing both page- and IP-specific access while detecting threats—is recommended.

    The service earns eight out of ten for reducing false positives, but some legitimate traffic is still blocked due to header parameters. Whitelisting helps, but further improvements and AI-driven behavior analysis could enhance accuracy.

    For how long have I used the solution?

    I have been using Radware Cloud WAF Service for more than two years.

    What do I think about the stability of the solution?

    The stability of Radware Cloud WAF Service is perfect; I would rate it a ten out of ten.

    What do I think about the scalability of the solution?

    I find the scalability of Radware Cloud WAF Service to be perfect, rating it a ten out of ten.

    How are customer service and support?

    I would rate their technical support an eight out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We have several other tools for threat management, but we primarily rely on Radware Cloud WAF Service. It effectively identifies, detects, and blocks malicious traffic. This is the main feature we are looking for, and Radware Cloud WAF Service performs exceptionally well in this regard.

    What was our ROI?

    Implementing Radware Cloud WAF Service saves 20–30 minutes per traffic analysis incident.

    Which other solutions did I evaluate?

    I notice that Radware Cloud WAF Service has drawbacks when compared to other WAF solutions, particularly because we were checking other solutions that support custom ports for application onboarding. Many custom-built applications run on different ports, and that is something that needs to be addressed; it should support custom ports. Other WAFs in the market currently support custom ports, which poses a major drawback for Radware Cloud WAF Service.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Jefe especialista de ciberseguridad at a insurance company with 1,001-5,000 employees
    Real User
    Top 20
    Apr 27, 2026
    Security has strengthened customer transactions and now protects critical online services
    Pros and Cons
    • "Radware Cloud WAF Service is very top-notch and we in the banking institution are happy with it."
    • "The only improvement I have directly for Radware is its costs, because they are very high."

    What is our primary use case?

    Our primary use case for Radware Cloud WAF Service is DDoS attacks that we suffer against some servers, which in this case affect the services provided to customers.

    We directly proceeded to activate the module from Radware Cloud WAF Service for the site that was being affected, and the impact on the customer was service downtime, but after an estimated period of time, the service was restored for the customers.

    At that time, Radware Cloud WAF Service helped a lot because it provided the cybersecurity that the site itself needs, as they are transactional, and it made us see directly that all the WAF modules are necessary for our institution and for the protection of the services or sites that we provide to customers.

    What is most valuable?

    From my perspective, the best features of Radware Cloud WAF Service are that it has very low false positives and additionally has a very user-friendly interface and easy configuration.

    With a very easy-to-use interface, Radware Cloud WAF Service becomes very easy for us as users to perform a search or investigation related to any specific issue that is being blocked and by having low false positives, it makes the search or investigation of a specific issue easier to carry out.

    It has had the best possible impact, since we have more than 25 sites exposed to the Internet that are transactional. By providing this security layer, we directly provide better results and better security for customers who can access our sites, and we can avoid any type of infection.

    We have directly seen improvement in the main dashboards of Radware Cloud WAF Service; they have become more specific in the direct migration of the site itself.

    What needs improvement?

    The only improvement I have directly for Radware is its costs, because they are very high.

    Having support directly from the manufacturer of Radware Cloud WAF Service and not from the partner would be beneficial, since support becomes a bit slower and more tedious through the current channel.

    Regarding costs of Radware Cloud WAF Service, it was a bit tedious because management did not want to approve them due to how high they are.

    What do I think about the stability of the solution?

    I consider Radware Cloud WAF Service to be very stable.

    What do I think about the scalability of the solution?

    I would rate the scalability of Radware Cloud WAF Service a nine.

    How are customer service and support?

    As I mentioned, sometimes it can be a bit tedious because we have a partner and we have to escalate it to them and then they escalate it to Radware.

    Which solution did I use previously and why did I switch?

    Since I joined the banking institution, we have been using Radware's WAF.

    How was the initial setup?

    The configuration has been very easy, we have not had any issues, and when acquiring the license, it is released very easily at the time of purchase and thus protects the sites.

    Which other solutions did I evaluate?

    I don't have information on this matter, since it is handled directly by the management of the banking institution.

    What other advice do I have?

    Radware Cloud WAF Service is very top-notch and we in the banking institution are happy with it.

    The sites that are onboarded for protection in Radware Cloud WAF Service should be transactional in order to avoid costs for sites that are not worth protecting or are not a main target for attackers.

    Radware Cloud WAF Service is an exceptional tool and very useful for protecting sites.

    I gave this product a rating of nine out of ten.

    Which deployment model are you using for this solution?

    Private Cloud
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    Last updated: Apr 27, 2026
    Flag as inappropriate
    PeerSpot user
    Kartik Pandit - PeerSpot reviewer
    Manager - SOC at a energy/utilities company with 10,001+ employees
    Real User
    Top 5
    Sep 9, 2025
    User-friendly interface significantly improves threat blocking and strengthens web application defenses
    Pros and Cons
    • "The interface is quite concise and clear, and it is easy to navigate."
    • "Malicious user agents are something that we get frequently and it has been blocking the majority of the threats, almost about 97-98% of threats are blocked, almost to 99% itself."
    • "They can work more on the documentation part. The documentation I found is quite vague."

    What is our primary use case?

    Since many of our businesses are on this application and web applications, we have a huge environment. There are more than hundreds of applications that we have. We are using it for WAF-based production, for bot and for DDoS protection.

    What is most valuable?

    The interface is quite concise and clear, and it is easy to navigate. I have worked with other WAFs, however, Radware Cloud WAF Service is quite easy to navigate compared to others. 

    I have never had a problem with the application or any websites. Many threats are getting blocked here. Since I joined this organization and had the opportunity to compare early deployment statistics with current ones, we can see that many threats have been blocked, resulting in a very good return on investment.

    With Bot Manager, we get many detections which are actually blocked, especially related to application headers. Malicious user agents are something that we get frequently and it has been blocking the majority of the threats, almost about 97-98% of threats are blocked, almost to 99% itself.

    Our first line of defense for our web applications, especially on the cloud, is Radware Cloud WAF Service. Whatever comes through, including reconnaissance attempts, different types of targeted attacks, targeted threat vectors and many APT groups targeting our environment, they are getting blocked in the recon phase itself thanks to the Bot Manager.

    What needs improvement?

    They can work more on the documentation part. The documentation I found is quite vague. There can be more practical examples, and since we are a paid customer, they can give us arranged training. They can arrange sessions or trainings regarding using Radware Cloud WAF Service and what further things we can do. I recently learned about source blocking, so training or sessions can be organized, along with improving documentation with practical examples.

    For how long have I used the solution?

    I have been using it for two and a half years since joining the new company. The company has been using the solution for quite a long time.

    What do I think about the stability of the solution?

    In the last two and a half years, I have not seen any kind of lags or issues.

    What do I think about the scalability of the solution?

    Scalability is good. Our organization is quite big, so we keep on adding applications behind it. I never found an issue with lagging or non-working components due to scaling limitations. The solution is providing scalability in all aspects.

    How are customer service and support?

    The speed and quality was good. We got a good quick turnaround time, especially in cases where we were actually under attacks and wanted blocking to work as soon as possible.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    In my previous company, I have worked with other WAFs, including the F5 WAF and the cloud native WAF. I have also worked with Akamai. I found Radware Cloud WAF Service to be better compared to others.

    How was the initial setup?

    The initial setup was quite easy. I moved around, did some R&D on my own, and it was easy to navigate.There are clear and concise filters that I can apply. Everything was on the screen. Whatever I wanted to try or do was available on the screen. I could move around in the console and try all kinds of experiments. It was quite easy and user-friendly.

    What was our ROI?

    Since I joined this organization and had the opportunity to compare early deployment statistics with current ones, we can see that many threats have been blocked, resulting in a very good return on investment.

    What's my experience with pricing, setup cost, and licensing?

    Pricing is something that is decided by the top management. I am more of an operations person.

    Which other solutions did I evaluate?

    We do not use the CDN services.

    What other advice do I have?

    I have not used the API Discovery completely, however, I have checked out the API security that comes under the WAF part, specifically the threat detection part that we are focused on. I am hearing about source blocking for the first time, which would be helpful as we would not have to manually block it.

    We are using the DDoS protection and it has been blocking many DDoS attacks that we have observed. Many times when traffic slips through our DDoS protection pipelines, they are definitely getting blocked by Radware Cloud WAF Service, including anomalous rate limiting.

    It took me about a week to learn the system, as I am a quick learner. There is no required maintenance as it is already taken care of by Radware. We get notifications regarding maintenance upgrades and everything, mainly for the IP blocking parts.

    On a scale of one to ten, I rate this solution a nine.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Application Supervisor at a government with 1,001-5,000 employees
    Real User
    Top 20
    Jun 23, 2025
    Eliminates maintenance tasks and strengthens security with AI-driven and API security functionalities
    Pros and Cons
    • "It has features such as API security that protect against advanced attacks, including business logic attacks. It comes with additional functionalities such as bot protection and AI-driven threat signatures, along with threat intelligence, making it much more than the traditional WAF that we have on-prem."
    • "Radware Cloud WAF Service offers better protection and can even provide significantly better security."
    • "The dashboard of Radware Cloud WAF Service has room for improvement. While it works effectively, it can feel complex and might need some initial guidance, but once users become familiar with it, the operation becomes smooth."

    What is our primary use case?

    We have both infrastructure protection and web application protection. Infrastructure protection is against network-level denial of service attacks, and we use the application protection for our web application firewall, which provides layer seven security.

    How has it helped my organization?

    Being a cloud service, it removes the maintenance tasks for system uptime and the maintenance of on-prem appliances. It gives security analysts much more time for SOC work in analyzing alerts and threats. With on-premises solutions, there is a lot of maintenance involved to ensure that everything is functioning properly. Much time is dedicated to maintaining on-premises products. In contrast, as a cloud product, we don't have to worry about issues related to high availability or managing multiple instances of security solutions. Maintenance tasks such as operating system upgrades and other related issues are handled for us. This allows us to focus our efforts on SOC analysis work without the burden of these maintenance responsibilities.

    It helps reduce the number of false positives and also addresses sophisticated attacks that may not be detected by our traditional systems on-premises.

    Alerts help us quickly narrow down the issue, allowing us to spend less time on analysis and more time addressing active threats as they occur. Automation plays a significant role in this process.

    Bot Manager has been quite positive. I find it to be more than just your traditional method of examining signatures or even looking at user agent headers. It goes beyond that; it analyzes the behavioral patterns of requests. Bots have become more advanced, often trying to imitate human behavior as closely as possible. With this bot protection, certain traffic gets blocked and flagged as bot traffic. However, when I review the requests from a human perspective, it can be challenging to identify what was actually bot traffic. Fortunately, the system provides a description of why a particular request was blocked and flagged as bot traffic. Bot traffic is a lot compared to normal human traffic, about 50% more. That alone frees up a lot of compute for our applications. The performance of the applications is significantly better because the bot's traffic is effectively filtered in the cloud. Only clean traffic reaches the applications, ensuring optimal performance.

    The detection for bad bots and layer seven anomaly detection is ingrained within the logic. First of all, it examines normal signatures and user agents. Additionally, there is a significant reliance on AI-driven signatures that it looks out for. It also incorporates threat intelligence, which may include insights from various sources. Another important aspect is IP reputation, which is gathered from other clients with whom these bots have interacted. Overall, I think this solution is very effective; it has worked well for us and is actually blocking the traffic as advertised.

    We rely heavily on Web DDoS protection, with about ninety percent of our services being application-based. Therefore, ensuring their security is very important to us. Radware provides the security we need and guarantees that the traffic reaching our web applications and servers is clean. This gives us peace of mind. While we monitor our systems closely, knowing that Radware Cloud WAF Service has our back is essential. Overall, it plays a crucial role in our business continuity as a security solution.

    What is most valuable?

    As compared to the traditional WAF that had on-prem systems, Radware Cloud WAF Service has many functionalities, such as AI-driven functionalities. It has features such as API security that protect against advanced attacks, including business logic attacks. It comes with additional functionalities such as bot protection and AI-driven threat signatures, along with threat intelligence, making it much more than the traditional WAF that we have on-prem. This is a key advantage I've seen since we onboarded it.

    What needs improvement?

    The dashboard of Radware Cloud WAF Service has room for improvement. While it works effectively, it can feel complex and might need some initial guidance, but once users become familiar with it, the operation becomes smooth.

    For how long have I used the solution?

    We have been using Radware Cloud WAF Service since the beginning of this year. It has not yet been a full year.

    What do I think about the stability of the solution?

    I would rate the stability of Radware Cloud WAF Service a nine out of ten. While the functionality is a 10 out of 10, occasional internet connectivity issues cause temporary access problems.

    What do I think about the scalability of the solution?

    The scalability of Radware Cloud WAF Service rates as a perfect ten out of ten, as we haven't encountered any scaling issues.

    In the security team, four of us work with this solution. We have about 4,000 employees.

    How are customer service and support?

    Technical support from Radware rates as a nine out of ten, as their support is very good.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Radware Cloud WAF Service is the first cloud WAF solution we have used. We were using only an on-premises physical appliance.

    As compared to our on-premises solution, Radware Cloud WAF Service offers better protection and can even provide significantly better security. In baseline protection, it matches our on-premises solution but has additional functionalities, including AI-driven signatures. This upgrade brings many more security features that we didn't have before. Overall, I would rate it much higher.

    Radware Cloud WAF Service works well. There are many instances that we could not flag bot traffic using our traditional on-premises WAF. We use them concurrently. We compare the clean rate of what passes through the cloud instance with what passes through our on-premises instance. It has freed up many of the compute resources we have on-premises. Thus, much of the malicious traffic is stripped away at the cloud level before the clean traffic reaches our on-premises sites.

    How was the initial setup?

    The deployment of the Radware Cloud WAF Service was quite easy and took about two to three days, thanks to the helpful and responsive support team from Radware.

    Apart from fine-tuning the security policies, much of the maintenance work is effectively handled in the background by the Radware team. As a result, there is very little to no maintenance required on our end.

    What about the implementation team?

    We were supported by Radware's onboarding team. They prepared our dashboard.

    What was our ROI?

    The Radware Cloud WAF Service saves us a significant amount of time, estimating around 30% to 40%.

    With our on-prem solution, we spent a lot of time on maintenance tasks, OS updates, and ensuring appliances ran smoothly, but with Cloud WAF, all that is managed by the cloud team, allowing us to focus on alert analysis.

    What other advice do I have?

    For false positives, you need to properly tune the detection rules. In the beginning, it operates in a learning mode, which Radware refers to as "reporting mode." This mode simply reports on what is happening but doesn’t actively block any threats. When you transition to active protection, it’s crucial to take care when defining your threat signatures. If you don't, there can be some false positives. However, with excellent support from the onboarding team, we were able to resolve those issues very quickly, and after that, everything went smoothly. In the initial stages, it can be a bit tricky. There are some false positives, but they can be adjusted and fine-tuned. Once in a while, a false positive occurs, but we now have the knowledge on how to mitigate that.

    A lot of applications are currently hosted on-premises. With a Cloud WAF, you need to redirect traffic to the cloud instance, and then the traffic is routed back. Initially, our main challenge was addressing internal threats, specifically insider threats. These applications are accessible both within our environment and to external users. However, since we began using cloud protection, it has primarily catered to external source traffic, leaving internal source traffic unprotected. Fortunately, Radware quickly developed a secure pathway functionality that can also redirect internal traffic to be inspected in the cloud. This feature is something we haven't implemented yet, but it is definitely on our agenda for implementation very soon.

    The application protection from Radware Cloud WAF Service has API security, which protects the APIs we define against the different OWASP Top 10 API security threats.

    I would rate the Radware Cloud WAF Service as a nine out of ten. Overall, it is a very effective solution that meets our expectations and blocks traffic as advertised.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Buyer's Guide
    Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros sharing their opinions.
    Updated: September 2026
    Buyer's Guide
    Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros sharing their opinions.