Try our new research platform with insights from 80,000+ expert users
RoiNahari - PeerSpot reviewer
CEO at a tech services company with 11-50 employees
Real User
Top 5Leaderboard
Nov 21, 2024
Enhance web security with superior bot protection and automated learning
Pros and Cons
  • "The most valuable features of Radware Cloud WAF Service include its automation and learning capabilities for protection, as well as its superior bot mitigation."
  • "Radware needs to improve the certificate renewal process for customers who want to be secured with HTTPS."

What is our primary use case?

The primary use case for Radware Cloud WAF Service is DDoS protection and web application firewalls. My clients use it for these purposes as they want to be protected by a web application firewall against attacks on their websites.

What is most valuable?

The most valuable features of Radware Cloud WAF Service include its automation and learning capabilities for protection, as well as its superior bot mitigation. The precise negative security on the web application firewall is also noteworthy. Additionally, the onboarding process is smooth, allowing customers the unique ability to use the web application firewall on the cloud.

What needs improvement?

Radware needs to improve the certificate renewal process for customers who want to be secured with HTTPS. Some other web application firewalls have a mechanism that allows automatic certificate uploads, which Radware could adopt. 

Also, improvements could be made to be more precise on the negative security perspective.

For how long have I used the solution?

I have been using Radware Cloud WAF Service for about two years.

Buyer's Guide
Radware Cloud WAF Service
December 2025
Learn what your peers think about Radware Cloud WAF Service. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,899 professionals have used our research since 2012.

What do I think about the stability of the solution?

Radware Cloud WAF Service is very stable, with no experienced downtime on Radware's part. I give it a stability rating of eight out of ten.

What do I think about the scalability of the solution?

Radware Cloud WAF Service is quite scalable, with a rating of eight out of ten.

How are customer service and support?

The technical support for Radware Cloud WAF Service is excellent. They are knowledgeable, speak the technical language, respond quickly, and work collaboratively to overcome challenges. I rate the customer service nine out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward, involving adding an A record in the customer's infrastructure and ensuring the right certificate is in place.

What's my experience with pricing, setup cost, and licensing?

Radware Cloud WAF Service pricing falls on the pricier side with a rating of seven out of ten. It may not have helped reduce the total cost of ownership.

Which other solutions did I evaluate?

I evaluated other solutions like Incapsula, Impreva, and F5 before choosing Radware.

What other advice do I have?

I advise conducting a POC to ensure that Radware Cloud WAF Service meets specific needs in terms of maintenance and understanding. It takes complex tasks, like web application firewall functions, and simplifies them for customer ease. 

I rate the overall solution eight to eight and a half out of ten.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer2157408 - PeerSpot reviewer
Network Engineer at a real estate/law firm with 1,001-5,000 employees
Real User
Apr 21, 2023
Has been effective in decreasing the number of false positives, but the API gateway is expensive to utilize
Pros and Cons
  • "DDoS protection is a valuable feature that works efficiently."
  • "We've had some issues with putting certificates in."

What is our primary use case?

We utilize it as a front end for all external connections to our public-facing websites, allowing us to manage traffic and redirect it accordingly. This enables us to store data in the cloud and other remote locations, while also protecting our internal servers from potential security threats by preventing malicious traffic from reaching them.

The solution is deployed on Azure and AWS cloud.

How has it helped my organization?

Cloud WAF appears to effectively block unknown threats and attacks. We had been using the on-prem version for a long time with Radware in our applications, which is why we switched to the cloud version. Overall, it seems to perform its job very well.

The automated analytics are great.

The main benefit that I believe we receive is that if our data is in the cloud and connects back to us, we don't have to worry about any traffic hitting our edge. This seems to be the most advantageous aspect. Additionally, Radware Cloud WAF Service is very effective in stopping any exploits or patterns used in SQL injections for our homebuilt applications that are public-facing. Therefore, based on our experience and needs, it appears that Radware Cloud WAF Service is doing a good job and we haven't encountered any problems.

The solution has been effective in decreasing the number of false positives. Additionally, with the on-prem solution, I was uncertain about how to use it initially. Generally, Cloud WAF is superior because it provides monitoring and assistance with modifications. This is particularly helpful in situations where new code is added to the website and it results in incorrect blocking. However, in the event of a false block, it's straightforward for us to submit a ticket, and the response time for remediation is prompt.

When it comes to deploying and integrating Radware Cloud WAF Service into our app for new purposes, it functions exceptionally well. Its learning mode is particularly impressive, as leaving it in this mode for a while allows it to identify trends and perform auto-tuning, saving us time. While we have not yet integrated any APIs, it works seamlessly when incorporated directly into our applications. Radware Cloud WAF Service learning analytics and autonomous adaptation to the environment are both top-notch.

Radware Cloud WAF Service helped our IT team to free up time, allowing us to concentrate on other projects. As we gradually shift our on-premises systems to the cloud, it has become much less labor-intensive. Instead of spending time trying to figure out a false positive, I simply submit it to them, and they take care of it for us. It's reassuring to have a team managing those policies.

We quickly realized that there were significant deficiencies in some of our applications when using on-premises technology. As we started to migrate data to the cloud and other locations, we recognized that cloud technology was the only option. We understood that it was a crucial tool to have from the very beginning, and we saw its value immediately. Although we are still in the process of migrating data to Cloud WAF from on-premises, it is evident that managing data through Cloud WAF is much simpler. In fact, managing the five applications we have running through it is considerably easier than with on-premises technology. Additionally, the reporting capabilities are better through Cloud WAF, and this is essential for sharing information with our leadership. Overall, we noticed the benefits of Cloud WAF immediately.

What is most valuable?

DDoS protection is a valuable feature that works efficiently. Currently, we have both DDoS protection and a regular package. Although we are in the process of piloting the bot, we haven't yet implemented it or purchased it. However, it seems that the bot is successfully blocking a significant amount of traffic. This feature could be helpful in the future, but we have only been testing it for a month or so.

What needs improvement?

The reporting has room for improvement.

We've had some issues with putting certificates in.

We considered using Radware Cloud WAF Service to protect our API gateway with a WAF. However, we encountered issues with licensing since we had to obtain a license for each individual connection, which was not suitable for our API. To deploy one API Gateway, we would need to purchase 30 licenses, which was expensive. Additionally, we experienced difficulties with obtaining support and resolving the issue, which went on for several weeks. Eventually, we decided to explore other options due to the lack of time to address the problem.

The scaling is not cost-effective and has room for improvement.

For how long have I used the solution?

I have been using the solution for four years.

What do I think about the stability of the solution?

The solution is stable. We haven't had any major issues in the past four years. There was one incident where our sites were down for around thirty minutes while the team was working on it. Although it was a challenging situation at that time, I cannot recall any other significant problems that caused any major impact or caused our sites to go down for such a duration.

What do I think about the scalability of the solution?

Our deployment is relatively small, but I believe the solution has great scalability potential. All we need to do is purchase extra licenses. However, the API gateways have been causing issues for us.

How are customer service and support?

The level of support provided by the team is inconsistent but generally good. However, we have noticed that the ERT team may take a day or two to respond to low-priority tickets, but they are prompt in responding to high-priority tickets and resolving the issue quickly. One area where we faced challenges was with the new API gateway deployment, as we did not receive the required level of support. Additionally, there were restrictions on using Logstash in Amazon SQS, which limited our logging capabilities, and this could be improved. Although we did face issues with the CERT page and had to reach out to support to obtain intermediate CERTs, it took a long time to resolve the issue, but it has since been resolved.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We previously used Radware WAF Service on-prem before switching to the cloud.

How was the initial setup?

The initial setup is simple, but there are some issues with the logging sources and how we import the logs into SIM. This aspect could be improved, but overall everything else went smoothly. We were able to easily configure the search function, assign an IP address to the back end, create the tunnel, and get the system up and running within a matter of days.

The deployment required two people.

What about the implementation team?

The implementation was completed in-house with the vendor support team.

What was our ROI?

It's difficult to quantify the value of security, but implementing a solution can give us a sense of comfort. Based on my experience, I believe we see a positive return on investment, especially considering the amount of time and manual effort required for on-premises security compared to using a Cloud WAF. Therefore, I'm confident that our investment is paying off.

What's my experience with pricing, setup cost, and licensing?

We are paying $20,000 annually for six licenses that provide basic WAF functionality. However, the cost of API gateways is exorbitant.

To utilize extra WAF bandwidth, an additional fee is applicable, and the same goes for the bot.

Which other solutions did I evaluate?

We are also evaluating AWS WAF and Pulse vWAF.

What other advice do I have?

I give the solution a seven out of ten.

I am not sure if there is a TCO. We could disable the solution immediately, and the affected websites would function normally. However, in the event of a security breach, exploitation of a site, or unauthorized data access, what would be the potential cost? While it may be difficult to quantify security costs, I do not believe that using Radware Cloud WAF Service has reduced overall expenses because we could operate without it. Nonetheless, in terms of the time invested in on-premises versus cloud WAFs, I would say that it is roughly equal to other WAFs. Ultimately, security is something that we cannot put a price on, and it is a necessary investment regardless of the expenses incurred.

This solution is publicly available, and we have numerous customers throughout the United States and Canada. While it's difficult to provide an exact figure, we typically have around a thousand active connections to the website per minute, adding up to several thousand users across the US.

Refreshing certificates are probably the most important part of maintenance. If new code is deployed and it doesn't integrate well, we need to ensure that our refinements are done correctly or seek support. We often identify these issues while working with our internal team to correct them, and Cloud WAF has helped to identify many of them. When we encounter issues, we contact the team who will confirm the issues. We then retrieve a portion of the code and realize that something was not deployed correctly on the website.

Radware Cloud WAF Service can be integrated with various systems, such as firewalls, endpoints, and clouds. This solution is highly flexible and efficient. Its implementation is straightforward and not complex. No additional service fees are required when working with Radware. As long as there is a skilled networking professional in charge, the integration process should run smoothly.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Radware Cloud WAF Service
December 2025
Learn what your peers think about Radware Cloud WAF Service. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,899 professionals have used our research since 2012.
Eddy Ramirez - PeerSpot reviewer
IT Security Director at a financial services firm with 1,001-5,000 employees
Real User
Top 20
Mar 2, 2023
Helps protect against low and slow DDoS attacks and enabled us to reduce our security headcount
Pros and Cons
  • "The isolation feature is the most important one because everything is going directly to Radware first and then it goes into our system. What we get is the filtered version of everything that would otherwise come directly to us."
  • "The implementation was hit or miss for the first few months. They did some tweaking and, since then, there have been no problems."

What is our primary use case?

Our company does collections of debt and we have a number of public websites. We usually send emails or snail mail to the clients and they reach us through any of our three of our main sites. Because those sites are exposed to the internet, we use the web application firewall from Radware to protect them. It protects us from attacks like denial service, SQL injections, et cetera. It is an application-oriented firewall for everything that is exposed over the internet.

How has it helped my organization?

On the InfoSec side, it helps us to know who is trying to access our site but is not legitimate. The protection against low and slow DDoS attacks is helpful because they are another way that malicious actors try to get into our system.

Also, with Radware Cloud WAF, we have reduced our security headcount. Before we had it, we had to have at least one person going over all the elements of our firewall and fine-tune it against whatever attacks and elements were there. Now, that position is no longer needed because we can receive reports. We went from having almost daily conversations about elements that we were seeing in our firewall, to just presenting monthly reports of what we were protected against to senior management. We go in through Radware to the dashboard and get the information.

They do have an API for getting reports and we are in the middle of trying to get those reports automated. But, for the time being, everything is on the really nice and well-organized dashboard that we use for those executive reports. By the end of the month, we will actually have executive reports that go to our senior level.

Also, if Radware finds some sort of a legitimate attack, they actually call us, like a SOC would, and report it to us.

Another benefit is that it has reduced our false positives. Usually, we would have five to eight in a week. We're down to almost one a month. That's impressive. We were doing reactive fine-tuning, whereas this is more of an AI and machine-learning implementation, which is way better. Each of those false positives we used to have required between 10 minutes and almost an hour from us. In the worst-case scenario, we were putting in one hour daily on false positives, or 20 hours monthly.

What is most valuable?

The isolation feature is the most important one because everything is going directly to Radware first and then it goes into our system. What we get is the filtered version of everything that would otherwise come directly to us.

For blocking unknown threats and attacks, it uses machine learning. It actually learns what is normal traffic from clients. Once we got the solution, they asked us to open all requests to do some type of machine learning to understand what normal traffic is. With other elements that Radware has in its arsenal, it can differentiate between normal, human traffic and bots or even DDoS attacks.

And we haven't had any false positives so far from the solution's automated analytics. On top of that, it's a very good tool because we can actually see the locations that traffic is coming from, and we can prohibit it from very specific areas of the world. One thing we have learned is how to optimize some of our code to make the application faster. The solution can react to attacks from different parts of the world and block them from entering our servers.

We also use the API Discovery feature and the analysis of the contents of the API is very good. Because we are PCI-certified, we usually use external penetration tests and obfuscation of malicious code through API, and what is discovered by Radware, and blocked, is very impressive. It won't allow any callbacks unless they are from our IP. It also offers VPN connectivity that we are testing, to provide end-to-end protection. What it comes down to is that no one reaches out to our server that is publicly exposed; that exposure is only to Radware. We like that.

It's easy to use the API Discovery, but you must know what you're doing. You just enable it but there are some elements that you need to provide to Radware. The only downside there is the learning process on the Radware side. You need to run it without any filters so it can actually see what normal traffic is and then it can apply the protection.

In terms of integrating Radware Cloud WAF Service with the other systems and applications, everything is API-connected so it was really easy. There is a testing period and, in one case, it took us 90 days, but in another, it was only two weeks. But it integrates really well with our systems.

What needs improvement?

There is a learning curve for the API for reporting. It is not as easy as other APIs.

Also, the implementation was hit or miss for the first few months. They did some tweaking and, since then, there have been no problems. 

Another issue is that they don't go back into information beyond 90 days. We have to pull the information so we can have, let's say, a year of threats, attacks, and data to help us make decisions about providing more or fewer resources, depending on the year-long data.

For how long have I used the solution?

I have been using Radware Cloud WAF Service since 2019.

What do I think about the stability of the solution?

The stability is good. There was one instance of downtime but it was basically our systems.

What do I think about the scalability of the solution?

We haven't needed to scale, for the moment. But I know on their side that they have a huge number of denial-of-service attacks and we haven't had any feedback from our clients about not being able to reach our website. So the solution is working. I don't know how they scale it because, with a DDoS attack, if you don't know how to treat it, you will need to scale it so you can actually allow safe users into your system.

Our number of users is more than 5,000 with two locations. The number of people involved in the Cloud WAF project, on our team plus the networking team, is about 10.

How are customer service and support?

Tech support is ticket-based. We have a 24-hour SLA that they have committed to, but we are more into having communication directly with them. Even though they have the ticket system and ask us to create tickets, we usually reach out to our contacts and try to expedite support requests.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were using Cisco Firepower as our main firewall, but that is not a web application firewall. We switched to Radware Cloud WAF because we evaluate our InfoSec roadmap every year. Based on the capabilities that Radware offered, and on recommendations from each year's pen test, and because we are trying to evolve our security to make it more mature, it was the decision that we took. It was a good one.

How was the initial setup?

The deployment is hybrid. There are elements that go to AWS and elements that go to our co-location services in Jacksonville. Eventually, everything is going to be exclusively cloud-based.

We are currently migrating everything to AWS. Setting things up, at that moment in time, was kind of hectic, but that was more because of our side. What Radware asked us to do was to redirect everything into our DNS, so it was fairly in terms of what their side needed. It was more an issue of understanding how we could tweak the solution on our side. With the planning included, it took less than a month.

In terms of maintenance, it mostly just works. But from time to time, based on the changes that we make to our web application code, we need to tweak some of the settings of the web application firewall.

What about the implementation team?

Everything was in-house and we had four people involved.

What was our ROI?

Imagine those 20 hours we used to spend on false positives multiplied by the employees' salaries and you have an ROI. I can't tell you if the ROI takes less than a year or two years, but this solution is one of our main layers of defense and it is a requirement for everything we do.

What's my experience with pricing, setup cost, and licensing?

The pricing is fair. We compared Radware to others using industry reviews and Radware is at the top right now.

Which other solutions did I evaluate?

Radware Cloud WAF is way better than what we had. It's more self-sufficient. When we used the regular firewall, we were the ones trying to build up the different signatures and create some sort of access control list based on location. And there was no API filtering. It is a night and day change.

What other advice do I have?

My main advice would be to include the development team, because the adoption of really good API-based protection is going to happen by having really good communication with your development team. They actually consume some of the rules that we use to create those APIs, and they pass that to their machine-learning processes. That's what is going to customize the web application firewall for your environment. 

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Joaquim Colome - PeerSpot reviewer
IT Unit Chief at a transportation company with 11-50 employees
Real User
Feb 21, 2023
A reliable, lightweight, and secure solution with excellent technical support
Pros and Cons
  • "The solution requires very little maintenance; we install it, it works without any problems, is reliable, and we can almost forget about it."
  • "The primary area for improvement is in issue detection and understanding whether a log is a false positive. It can sometimes be a challenge to take the data of a given security event and determine if it's a genuine threat using a Wiki etc."

What is our primary use case?

We use the solution to protect our main public application for transportation tickets. We have the product in the cloud set up before our infrastructure, so there is no need to integrate it as if it were an appliance etc.  

How has it helped my organization?

Most importantly, the solution put our security team at ease. We previously had some other infrastructure to protect our servers, but having Radware in the cloud gives us confidence.

The tool helped free up our IT team for other projects and saved us significant time. It eased our workload, allowing us to work in other areas. Overall, the time savings are in the region of 10-15%.

Cloud WAF helped to reduce our false positives; we initially had a lot, but once we learned, we had very few. The solution reduced our false positives by about 80%.  

What is most valuable?

The solution requires very little maintenance; we install it, it works without any problems, is reliable, and we can almost forget about it.

Radware Cloud WAF works very well to block unknown threats and attacks; we set up some products and infrastructure beyond the solution, and they aren't detecting any threats.   

The tool's automated analytics work fine for looking at events; the fact is, we're preparing to renew our license for another three years. 

What needs improvement?

The primary area for improvement is in issue detection and understanding whether a log is a false positive. It can sometimes be a challenge to take the data of a given security event and determine if it's a genuine threat using a Wiki etc.

Navigating to find specific options can sometimes be challenging, but we only do this occasionally; we primarily control the logs, so it's not particularly significant for us.

We had some issues with the initial implementation, especially around tuning the solution to avoid false positives. 

For how long have I used the solution?

I've been using the solution for three to four years. 

What do I think about the stability of the solution?

The solution was relatively unstable during the first year, and we encountered issues, but after that, it was very stable.

How are customer service and support?

The technical support is excellent; they ask questions, and on rare occasions, they haven't been able to help us. However, they looked into the issues on these occasions and provided a solution a few months later.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Radware Cloud WAF is the first WAF solution we've used.

How was the initial setup?

The initial setup was relatively complex; we had some DNS certificate issues, and the deployment took much longer than we expected. However, the second implementation was straightforward and much faster. We experienced DNS issues again, but we had the benefit of experience.

The initial deployment took a few weeks and was carried out by two staff members. We outsourced the solution's management to a civil security team of around ten members.

What was our ROI?

The product is excellent in terms of ROI because it has saved us a lot of time.

What's my experience with pricing, setup cost, and licensing?

The pricing is fair; it's neither particularly cheap nor expensive.

What other advice do I have?

I rate the solution eight out of ten, and I recommend it.

We have seen time to value with Cloud WAF, and we saw this value after around three months. Once we tuned the application to avoid false positives, we started to see a return on our investment.  

We don't currently use the API Discovery feature but plan to implement it soon.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
reviewer2186772 - PeerSpot reviewer
System Administrator at a comms service provider with 1,001-5,000 employees
Real User
May 25, 2023
Is user-friendly, helps save time, and has good end-to-end API protection
Pros and Cons
  • "Radware Cloud WAF Service is user-friendly and easy to deploy."
  • "Radware Cloud WAF Service should provide SSL certificates for its hosting customers."

What is our primary use case?

We have multiple use cases for Radware Cloud WAF Service. We use it to protect our voice domain, our banking solution, and any other applications that are open to the Internet. We use the same Radware WAF for our applications on AWS.

How has it helped my organization?

The effectiveness of Radware Cloud WAF Service in blocking unknown threats and attacks depends on the situation. Usually, when we deploy applications, we have everything planned in advance. In this case, we can simply log in to the portal and configure the WAF. However, if we are dealing with a repeated case or if we need to update a certificate, we can use automation to make the changes. In most cases, we do not need to make any changes to the WAF configuration. For example, if we need to block a specific IP address, we can create a template and apply it to all of our web applications. This allows us to use WAF for both web applications and API code.

Radware Cloud WAF Service's automated analytics for looking at events is good. We actually had something similar before, but this service gives us a better understanding of how we use WAF for different products. For example, DDoS protection is also included. This allows me to analyze which users are coming from which locations, what my status is, and if I have a SQL injection or something similar. There are a lot of features, so I definitely know my application better and can identify any security events that are happening on my web or application.

The end-to-end API protection offered by Radware Cloud WAF Service's API discovery feature is a good tool. However, it can only be effective if we understand the WAF portal concept and know what the tool does. Before we use the tool, we should read its documentation. Radware also has a universal university where we can learn more about how Radware works in a web application. This is helpful because different vendors have different ways of using the same application. I have been part of this learning experience and found it to be very helpful.

API Discovery is easy to use for those who are familiar with WAFs and APIs. However, we need to use a document to configure it, which is not a big deal.

Using Radware CDN services and Cloud WAF together is easy. However, it requires coordination between two different teams. The security team is responsible for CDN, while the development team is responsible for the application. If these teams communicate effectively, it is very easy to use the combined services. Even if the development team does not have experience with CDN, it is not difficult to learn. I have been part of both teams, and I can confirm that using Radware CDN services and Cloud WAF together is easy.

Radware Cloud WAF Service is user-friendly. It provides us with what we need and tells us where to click. Even if we are new to using it, we will not get lost or confused. Once we log in, we can simply click through the steps and understand what is happening. The application is easy to configure and does not require highly technical knowledge.

Radware Cloud WAF Service helped reduce the overhead on one team. In a previous product preview event, only two teams were configuring everything for the project team. However, now even the user developer can develop applications. They develop the application, put their endpoint, and go to Radware to create everything. The system management and network teams are no longer involved. This reduced the dependency on a team by 70 percent. Additionally, any individual team can now configure and use the service.

Radware Cloud WAF Service helped reduce our TCO by ten percent.

We noticed the time to value within two months of using Radware Cloud WAF Service.

What is most valuable?

Radware Cloud WAF Service is user-friendly and easy to deploy. All we need is our domain name, and we can easily configure it. I migrated from old products to new products using Radware Cloud WAF Service. Migration can be a complex process, but Radware makes it easy by providing a step-by-step guide. We can migrate one application at a time, or we can migrate multiple applications at once. Radware also provides an API that we can use to automate the migration process.

What needs improvement?

Radware Cloud WAF Service should provide SSL certificates for its hosting customers. Currently, customers must purchase an external certificate and upload it to their hardware. This is a major inconvenience, and I would like to see Radware offer a certificate solution.

The technical support has room for improvement.

For how long have I used the solution?

I have been using Radware Cloud WAF Service for six months.

What do I think about the stability of the solution?

Radware Cloud WAF Service is stable.

What do I think about the scalability of the solution?

Radware Cloud WAF Service is scalable. We have multiple teams but we are all on one cloud. We have approximately 50 people using Radware Cloud WAF Service.

How are customer service and support?

Overall, the technical support team resolves our issues, but they take some time to understand the issues.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We previously used Imperva Web Application Firewall, but it was too expensive. We switched to the Radware Cloud WAF Service, which is more affordable.

We did not use the automation with Imperva in the same way that we do with Radware Cloud.

How was the initial setup?

The initial setup was straightforward. The deployment took one month because we wanted Radware to learn about our footprint. We started blocking after a month, once they developed an algorithm to understand how the application works and what the major use cases are. Initially, we were not in a blocking mode. We were just configuring everything and learning more about the application. We initially required six people because we were building the policies.

What about the implementation team?

The implementation was completed in-house.

What was our ROI?

We are still in the early stages of using Radware Cloud WAF Service, but we have already seen a 10 percent return on investment due to a reduction in team dependency.

What's my experience with pricing, setup cost, and licensing?

For the current market, the price for Radware Cloud WAF Service is exactly where we want it to be.

We are using two services, WAF and CDN, and we have a three-year contract for these services.

What other advice do I have?

I give Radware Cloud WAF Service an eight out of ten.

I recommend conducting a proof of concept before purchasing Radware Cloud WAF Service.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Wilmer Beltran - PeerSpot reviewer
Engineer at a transportation company with 51-200 employees
Real User
May 1, 2023
Features geo-blocking, protection against unknown threats, automated analytics, and excellent support
Pros and Cons
  • "Geo-blocking is one of the most valuable features we use the most; most of our users are in North, Central, and South America, so we use geo-blocking to block access from other countries."
  • "We receive many reports from our security team of IPs flagged by our security tools, such as Palo Alto. I cannot add the file containing the IPs to get them blocked; instead, I have to contact Radware support and open a ticket for them to do it. I need to be able to block flagged IPs myself, as it currently takes more time to open a ticket, contact the support team, and wait four to six hours for a response. I want to be able to upload a file with 2,000-3,000 IPs in the console and then apply and save the configuration."

What is our primary use case?

Our company infrastructure is supported in AWS, and we use Cloud WAF to protect most of our applications, including mobile apps, our main website, and other business-related apps. 

We have many applications in the AWS cloud, including API gateways and balancers, so the backend is made up of all our apps and network load balancer. We use the solution as a frontend protection tool, and the integration is simple, uncomplicated, and works fine.  

How has it helped my organization?

The most significant benefit of using Cloud WAF is the robust protection it provides, particularly against Layer 7 attacks. We've been protected against attacks on our website, and in the case of one DDoS attack, Radware supported us in detecting the attack behavior and blocking the threat. The block took five to ten minutes, we configured the solution to account for the specific behavior of the attack, and we re-established our website. 

The product significantly reduced our false positives, as we previously had many. We had more false positives just after the implementation, but following some reconfiguration and changing some features with the help of Radware's implementation team, the tool works fine. We only have a few false positives; we've seen a reduction of around 80%.  

Cloud WAF helps to free up our IT staff for other projects and saves us significant time. I manage the solution and log into the console around once a week; it takes very little time to configure. The tool doesn't require continuous supervision, just infrequent configuration changes, five times a month.  

What is most valuable?

Geo-blocking is one of the most valuable features we use the most; most of our users are in North, Central, and South America, so we use geo-blocking to block access from other countries.

In our experience, Cloud WAF effectively prevents unknown threats and attacks. We have received reports of attacks in the past, but the product successfully blocked them. In a few instances, we contacted Radware support for assistance in blocking specific attacks. Despite experiencing around three incidents over the past four years, we are satisfied with the solution's performance and have not encountered any further issues.  

The solution's automated analytics for looking at events works great, as it has a model that can analyze the traffic and respond to an attack. We can also configure the tool to block or allow specific traffic based on the analytics.

What needs improvement?

We receive many reports from our security team of IPs flagged by our security tools, such as Palo Alto. I cannot add the file containing the IPs to get them blocked; instead, I have to contact Radware support and open a ticket for them to do it. I need to be able to block flagged IPs myself, as it currently takes more time to open a ticket, contact the support team, and wait four to six hours for a response. I want to be able to upload a file with 2,000-3,000 IPs in the console and then apply and save the configuration.

For how long have I used the solution?

We've been using the solution for four to five years. 

What do I think about the stability of the solution?

The solution is highly stable; we never had a direct issue with the tool in four years, so it's very solid. 

What do I think about the scalability of the solution?

The solution is highly scalable; we can apply multiple servers and add applications to Radware almost immediately. 

How are customer service and support?

We have contacted support on multiple occasions, and they are excellent, though it depends upon the case. If we have a P1 issue, we can contact support by calling them directly, which takes up to 15 minutes. For non-critical regular tickets, these can take between four and six hours, which is good. If we have multiple issues, we can enter a Zoom call with support, and they will help us to block malicious traffic, for example. I rate them nine out of ten.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was very straightforward, and we implemented with a team of three or four staff. The product doesn't require any maintenance on our side; we sometimes receive emails informing us Radware will carry out maintenance, but it never affects the company.

What's my experience with pricing, setup cost, and licensing?

We are based in El Salvador and don't have a direct license with Radware; we purchase the license through resellers. The pricing is reasonable, as I managed an Akamai product in a previous position, and Cloud WAF is competitively priced.

What other advice do I have?

I rate the solution nine out of ten. 

Radware is very valuable to our business, the deployment is simple, and it only took a couple of weeks to see that value. 

My advice to others considering the solution is that it's a good tool. Regarding security, it's an excellent and feature-rich product that can protect your website, is easy to configure, and has strong support. The Radware technical support staff are very experienced and knowledgeable about their product. We can also generate periodic reports, and Cloud WAF is a great solution that will help improve your work.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Consultor with 501-1,000 employees
Real User
Apr 24, 2023
Simple to use and reduces risks of attack and information leakage
Pros and Cons
  • "The API Discovery is also very good because the application is outsourced, which means that we don't have the code. API Discovery allowed me to discover precisely how to orchestrate the API so that I could see the results."
  • "They have a portal for webinar training but because we are in a Spanish-speaking country, it is difficult for us to watch them. Not all of us are fluent in English, but most of the courses and webinars are in English. That part could be improved..."

What is our primary use case?

We have been using this solution for a number of use cases. For example, we use it for SQL inspection, cross-site scripting. We also have load sharing and we create our own custom rules for our situation, based on our business. For instance, products, articles, and other parameters that we manage in our applications are packaged in Radware.

We also tested the Bot Manager for a month and it seemed quite useful, but due to a matter of project priorities, we could not implement it.

How has it helped my organization?

Radware Cloud WAF visibly improves our security posture and reduces the risks of an attack. It also helps us a lot in avoiding information leakage. These advantages are particularly true for us because the applications that we have protected are outsourced developments, they are not in-house. Radware helps us guarantee a level of security for our infrastructure such as our databases.

The API Discovery is also very good because the application is outsourced, which means that we don't have the code. API Discovery allowed me to discover precisely how to orchestrate the API so that I could see the results. Based on them, we were able to raise new cases. It's nice not to have that limitation. We are using API Discovery on a trial basis for one month, but I believe that if we enable it next year we will see a decrease in traffic and consumption.

In addition, it has helped reduce false positives by 30 percent. In the second year, the change hasn't been very noticeable because the cases that we started with in the previous year have already been configured and saved. In other words, we are increasing the system's capacity, fixing the rules, but we are not erasing the previous ones.

It has also helped free up the IT team because several risk points are automatically covered. For example, we have a SIEM to which we send the Radware logs and the integration with the SIEM, as well as sending these logs, was simple, a matter of five minutes. The logs that Radware sends are complete and we can create use cases based on our needs. I estimate it has saved 50 percent of my time.

What is most valuable?

Among the most valuable features is the ease of managing the platform. It is user-friendly.

The platform has also worked quite well when it comes to blocking unknown threats and attacks. A great example over the last year was a new threat that our system perceived. Radware responded very well for the use cases that we created, as well as to the SQL injection-type of threat. When we received Cloud WAF we enabled the automated rules. That's good because basic rules are already built-in and can't be modified, so if an analyst doesn't have abundant knowledge or experience and couldn't manage such a threat, he would find a lot of help from Cloud WAF itself. The platform has a great security system and is well-managed.

The automated analytics for looking at events are also good. The support that we can generate every week is also good. And the API Discovery feature is extremely easy to use. You simply click on it to activate it.

We also use the CDN services offered by Radware and it hasn't really been complicated because it's quite user-friendly and, when I've had any questions, support has always been there to help me resolve them immediately.

I rate it well for integrating with other systems and applications and I would recommend it to other companies. We have integrated it with various solutions. We have AWS and private clouds as well, so the DNS redirection was obviously more on our side. But setting up and provisioning Radware itself is extremely simple. It didn't take us more than 10 minutes, and even less to load certificates. It's extremely easy. Other solutions take longer.

What needs improvement?

They have a portal for webinar training but because we are in a Spanish-speaking country, it is difficult for us to watch them. Not all of us are fluent in English, but most of the courses and webinars are in English. That part could be improved, with more options for people for whom English is not their native language.

For how long have I used the solution?

I have been using Radware Cloud WAF Service for two years.

What do I think about the stability of the solution?

It is very stable. We have not had a cut or suffered from unavailability of the service.

What do I think about the scalability of the solution?

The scalability of the solution is also good. It has allowed us to build sites in different clouds and to integrate with other security tools.

How are customer service and support?

One aspect that has drawn my attention the most is the support. It is very successful and the response to something I want to modify is very fast. They are excellent.

For example, if a rule has been blocked or I need to delete an expired certificate and, for some reason, it has prevented me from doing so, the customer service response has always been fast and assertive.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

The solution we had before was from Trustware. We changed to Radware because of its cost and because the support for our old solution was not optimal in response time. Also, the configuration wasn't as flexible. Setting up the rules took a long time.

How was the initial setup?

The initial setup was super simple, uploading the certificates was super fast,  and redirecting to the DNSs was extremely simple. It was a matter of five or 10 minutes. Entering the blocking stage only took a few seconds.

We started with a platform that had fewer clients and did so at times with fewer transactions. We then did functionality testing before provisioning. After that, we entered a learning stage of 10 to 15 days so that Radware could learn the patterns that are handled in the applications, such as input and output parameters. Once those parameters were validated with the development area, the next thing was the blocking.

For the technical administration, we have four users who manage it, but I am the main manager. There isn't any maintenance. There are updates made by Radware, but for us, it has been practically transparent. The one thing we do is refine the rules due to new attacks and malicious threats.

What about the implementation team?

We did it with the supplier. There were two people involved: me, representing our company, and a Radware consultant who was running the project.

What was our ROI?

Obviously, the ROI is the security it provides. It keeps our services available and complete. And a good reputation for our brand is much more than a return on investment.

I do not see it from the point of view of reducing our TCO, since it is a service that has to be available 24/7 in our retail services. This guarantees that customers will be able to carry out their purchases at any time of the day.

There was no delay in time to value, from before provisioning to after.

What's my experience with pricing, setup cost, and licensing?

The pricing has been quite manageable for our line of business. The license letter was done once and we no longer have to reload the annual renewal. That has been handled quite well during these two years.

Which other solutions did I evaluate?

I have worked previously with other solutions. I started working with Radware two years ago and I really like this solution because it is very user-friendly. Another advantage is that there is one portal/dashboard. I  don't need two portals to manage the Bot Manager and other aspects. I can view, configure, and do everything through just one, which makes administration easier.

We evaluated other options and, if I remember correctly, one of them was Fortinet, but they didn't seem as effective as Radware. But the price was the biggest difference. Radware had the best price for our type of network and level of scaling.

What other advice do I have?

When we tried the Bot Manager in one of our applications it did not have an effect because its work style didn't fit the application. But in the second application, it did work and it has been striking. It was useful for us to create new blocking rules in certain cases that we had not mapped from the time the project was launched.

My advice is to try the API. It's actually very simple and it helps a lot when identifying new risks that can be mapped with various rules.

The most important thing is the response time. It also benefits the tools a lot because slower solutions mean several minutes of service unavailability.

In the two years since we started using Radware, it has responded very well and we have not had any incidents of code indexing or denial of service. We have not had a single incident that has compromised our service availability, which is pretty good.

Foreign Language: (Spanish)

¿Cuál es nuestro caso de uso principal?

Hemos estado usando esta solución para varios casos de uso. Por ejemplo, lo usamos para la inspección de SQL, secuencias de comandos entre sitios. También tenemos carga de trabajo compartida y creamos nuestras propias reglas personalizadas para nuestra situación, en función de nuestro negocio. Por ejemplo, los productos, artículos y otros parámetros que gestionamos en nuestras aplicaciones están empaquetados en Radware.

También probamos el Bot Manager durante un mes y nos pareció bastante útil, pero por una cuestión de prioridades del proyecto no pudimos implementarlo.

¿Cómo ha ayudado a mi organización?

Radware Cloud WAF mejora visiblemente nuestra postura de seguridad y reduce los riesgos de un ataque. También nos ayuda mucho a evitar la fuga de información. Estas ventajas son particularmente ciertas para nosotros porque las aplicaciones que hemos protegido son desarrollos subcontratados, no son internos. Radware nos ayuda a garantizar un nivel de seguridad para nuestra infraestructura, como a nuestras bases de datos.

La API Discovery también es muy buena para las aplicaciónes que están subcontratadas, ya que al ser subcontratadas significa que no tenemos el código. API Discovery me permitió descubrir con precisión cómo orquestar la API para poder ver los resultados. En base a ellos, pudimos plantear nuevos casos. Es bueno no tener esa limitación. Estamos usando API Discovery a modo de prueba durante un mes, pero creo que si lo habilitamos el próximo año, veremos una disminución en el tráfico y el consumo.

Además, ha ayudado a reducir los falsos positivos en un 30 por ciento. En el segundo año el cambio no se ha notado mucho porque los casos que empezamos el año anterior ya están configurados y guardados. Es decir, estamos aumentando la capacidad del sistema, arreglando las reglas, pero no borrando las anteriores.

También ha ayudado a liberar al equipo técnico porque varios puntos de riesgo se cubren automáticamente. Por ejemplo, tenemos un SIEM al que enviamos los logs de Radware, la integración con el SIEM además de enviar estos logs, es sencilla, se hace en cinco minutos. Los registros que envía Radware están completos y podemos crear casos de uso según nuestras necesidades. Estimo que ha ahorrado el 50 por ciento de mi tiempo.

¿Qué es lo más valioso?

Entre las características más valiosas está la facilidad de manejo de la plataforma. Es fácil de usar.

La plataforma también ha funcionado bastante bien cuando se trata de bloquear amenazas y ataques desconocidos. Un gran ejemplo de esto es que durante el último año nuestro sistema percibió una nueva amenaza. Radware respondió muy bien a los casos de uso que creamos, así como al tipo de amenaza de inyección SQL. Cuando recibimos Cloud WAF, habilitamos las reglas automatizadas. Esto es bueno porque las reglas básicas que ya están integradas no se pueden modificar, por lo que si un analista no tiene muchos conocimientos o experiencia y no puede manejar una amenaza de este tipo, podrá encontrar mucha ayuda en Cloud WAF. La plataforma tiene un gran sistema de seguridad y está bien administrada.

Los análisis automatizados para observar eventos también son buenos. El apoyo que podemos generar cada semana también es bueno. Y el API Discovery es extremadamente fácil de usar. Simplemente haces clic en él para activarlo.

También usamos los servicios de CDN que ofrece Radware y realmente no ha sido complicado porque es bastante fácil de usar y cuando he tenido alguna pregunta, el soporte siempre ha estado ahí para ayudarme a resolverla de inmediato.

Lo califico bien para integrarse con otros sistemas y aplicaciones y lo recomendaría a otras empresas. Lo hemos integrado con varias soluciones. También tenemos AWS y nubes privadas, por lo que la redirección de DNS obviamente estuvo más de nuestro lado. Pero configurar y aprovisionar Radware en sí mismo es extremadamente simple. No tardamos más de 10 minutos, y cargar los certificados nos tomó mucho menos. Es extremadamente fácil. Otras soluciones toman más tiempo.

¿Qué necesita mejorar?

Tienen un portal de seminarios web para capacitación, pero como estamos en un país de habla hispana, se nos hace difícil verlos ya que no todos hablamos inglés con fluidez. La mayoría de los cursos y seminarios web son en inglés. Esa parte podría mejorarse, con más opciones para las personas para quienes el inglés no es su idioma nativo.

¿Por cuánto tiempo he usado la solución?

He estado usando Radware Cloud WAF Service durante dos años.

¿Qué pienso sobre la estabilidad de la solución?

Es muy estable. No hemos tenido cortes de red ni sufrido indisponibilidad del servicio.

¿Qué opino de la escalabilidad de la solución?

La escalabilidad de la solución también es buena. Nos ha permitido construir sitios en diferentes nubes e integrarnos con otras herramientas de seguridad.

¿Cómo son el servicio de atención al cliente y el soporte?

Uno de los aspectos que más me ha llamado la atención es el soporte. Tiene mucho éxito y la respuesta a algo que quiero modificar es muy rápida. son excelentes

Por ejemplo, si me han bloqueado una regla o necesito borrar un certificado caducado y, por algún motivo, me lo ha impedido, la respuesta del servicio de atención al cliente siempre ha sido rápida y asertiva.

¿Cómo calificaría el servicio y soporte al cliente?

Positivo

¿Qué solución usé anteriormente y por qué cambié?

La solución que teníamos antes era de Trustware. Cambiamos a Radware por su costo y porque el soporte para nuestra antigua solución no era óptimo en tiempo de respuesta. Además, la configuración de Trustware no era tan flexible y establecer las reglas llevó mucho tiempo.

¿Cómo fue la configuración inicial?

La configuración inicial fue súper simple, la carga de los certificados fue súper rápida y la redirección a los DNS fue extremadamente simple. Era cuestión de cinco o diez minutos. Nos tomó sólo unos segundos entrar en la etapa de bloqueo.

Empezamos la implementación con una plataforma que tenía menos clientes y lo hacíamos en los tiempos que menos tenían transacciones. Luego hicimos pruebas de funcionalidad antes del aprovisionamiento. Después de eso, entramos en una etapa de aprendizaje de 10 a 15 días para que Radware pudiera aprender los patrones que se manejan en las aplicaciones, como los parámetros de entrada y salida. Una vez validados estos parámetros con el área de desarrollo, lo siguiente fue el bloqueo.

Para la administración técnica tenemos cuatro usuarios que la manejan, pero yo soy el administrador principal. No hay mantenimiento. Hay actualizaciones hechas por Radware, pero para nosotros ha sido prácticamente transparente. Lo único que hacemos es refinar las reglas debido a nuevos ataques y amenazas maliciosas.

¿Y el equipo de implementación?

Lo hicimos con el proveedor. Había dos personas involucradas: yo, en representación de nuestra empresa, y un consultor de Radware que dirigía el proyecto.

¿Cuál fue nuestro Retorno de Inversión ?

Obviamente, el Retorno de Inversión es la seguridad que proporciona. Mantiene nuestros servicios disponibles y completos. Y una buena reputación de nuestra marca es mucho más que un retorno de la inversión.

No lo veo desde el punto de vista de reducir nuestro TCO, ya que es un servicio que tiene que estar disponible 24/7 en nuestros servicios de retail. Esto garantiza que los clientes puedan realizar sus compras en cualquier momento del día.
No hubo demora en el tiempo de valorización, desde antes del aprovisionamiento hasta después.

¿Cuál es mi experiencia con los precios, el costo de configuración y las licencias?

El precio ha sido bastante manejable para nuestra línea de negocio. La carta de licencia se hizo una vez y ya no tenemos que recargar la renovación anual. Eso se ha manejado bastante bien durante estos dos años.

¿Qué otras soluciones evalué?

He trabajado anteriormente con otras soluciones. Empecé a trabajar con Radware hace dos años y me gusta mucho porque es muy fácil de usar. Otra ventaja es que hay solo un portal/tablero. No necesito dos portales para administrar el Bot Manager y otros aspectos. Puedo ver, configurar y hacer todo a través de uno solo, lo que facilita la administración.

Evaluamos otras opciones y si no recuerdo mal, una de ellas era Fortinet, pero no parecían tan efectivas como Radware. El precio fue la mayor diferencia. Radware tenía el mejor precio para nuestro tipo de red y nivel de escalabilidad.

¿Qué otro consejo tengo?

Cuando probamos el Bot Manager en una de nuestras aplicaciones no surtió efecto porque su estilo de trabajo no se ajustaba a la aplicación. Pero en la segunda aplicación sí funcionó y ha sido llamativo. Nos resultó útil para crear nuevas reglas de bloqueo en ciertos casos que no teníamos mapeados desde que se lanzó el proyecto.

Mi consejo es probar la API. En realidad, es muy simple y ayuda mucho a la hora de identificar nuevos riesgos que se pueden mapear con varias reglas.

Lo más importante es el tiempo de respuesta. También beneficia mucho a las herramientas porque las soluciones más lentas significan varios minutos de indisponibilidad del servicio.

En los dos años que llevamos usando Radware ha respondido muy bien y no hemos tenido ningún incidente de indexación de código o denegación de servicio. No hemos tenido un solo incidente que haya comprometido la disponibilidad de nuestro servicio, lo cual es bastante bueno.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1579545 - PeerSpot reviewer
Network Architect at a financial services firm with 10,001+ employees
Real User
Mar 1, 2023
We no longer need to appropriate more horsepower to our backend web servers to service malicious requests because the solution blocks bots from accessing our web page
Pros and Cons
  • "From a financial point of view, we no longer need to appropriate more horsepower to our backend web servers constantly to service these requests because Cloud WAF is preventing malicious bots from accessing our web page. It reduced the load on our backend."
  • "Our only complaint is the reporting on the DDoS side. We also use Radware for on-premises DDoS protection and their Vision product. I just want to give paint you an example. We face so many Layer 3 and Layer 4 DDoS attacks on Cloud WAF. The reporting on those types of attacks can be improved."

What is our primary use case?

We had adware attack mitigation systems and DDoS appliances in place, but these are primarily designed to handle flood attacks. We found that our frontend pages, including our online banking, were being attacked by bots. Hundreds of these connections created such a high load on our backend web servers that they failed to respond to legitimate requests. 

Our primary use case for Cloud WAF is to stop these malicious bots from continuously calling up web pages. They look legitimate, but they constantly call or refresh the web page.

We haven't integrated much yet. Cloud WAF is protecting our frontend pages, but our banking profile for logging our backend financial transactions sits behind our corporate frontend pages. Cloud WAF is also protecting that piece. Once we've completed protecting our landing pages, we'll start working on our other applications. 

How has it helped my organization?

From a financial point of view, we no longer constantly need to appropriate more horsepower to our backend web servers to service these requests because Cloud WAF is preventing malicious bots from accessing our web page. It reduced the load on our backend. 

We don't have all the in-house expertise to investigate a typical HTTPS request to see what's happening. We rely on Radware's emergency response team to provide us with biweekly feedback saying, "This is what we've observed and what we recommend." 

By using Radware Cloud WAF, we don't need to hire web threat specialists. We can rely on Radware's emergency response team to fine-tune our policies. Spinning up a web application firewall on our own is a long and challenging process. It's far easier to outsource that job to Radware.

Using Radware freed up resources, especially on the web side. We would typically require an internal team to look after the web pages, but that has been outsourced to Radware. Now, those employees can shift their focus to other projects, and they need not worry about what Radware's doing because they know that it's in the capable hands of an experienced team. 

Cloud WAF reduced our false positives. That's one feature Radware is known for. We get very few false positives, but when we do, we bring them up during our biweekly meeting with the Radware team. They help refine our policies so we no longer see the same issue. Most Radware products perform exceptionally well at eliminating false positives.

It's hard for us to quantify the reduction of false positives because it's a relatively new product. We'll start collecting these metrics toward the end of 2023. Based on our customer call center's feedback, we haven't received complaints about blocking legitimate traffic. When we adopted Cloud WAF, that was a concern our business units had. Some were worried we would deny a lot of traffic. That hasn't been a problem thus far. 

We now have more accurate statistics about legitimate website visitors because we've eliminated those malicious bots that artificially inflated the number of hits on our website. It was creating a false impression that we had an unusually high number of hits. Traditionally, they were there for web scraping, but we eliminated unwanted traffic pushing up our analytics. Google Analytics gave us the impression that we had a ton of traffic. Those figures have gone down because we've eliminated the baddies.

What is most valuable?

The most valuable components are the bot manager Radware offers as part of graph services and the WAF component. We haven't begun using the API protection, but we plan to implement that in the latter half of 2023. We're also looking at the content delivery network feature. CDN serves static web pages from the Cloud WAF to speed up processes. 

We recognize the potential value of the CDN function. It's part of Cloud WAF, so it can also be enabled relatively quickly. The CDN function offers specific bolt-on security because the application services are protected, and the CDN function is a click away. It doesn't require changes to our backend applications. We only need to use a TNA, and we will have access to the CDN features.

We're currently getting our money's worth from the WAF, the bot manager, and the DDoS components. We see a lot of value in these three components of Cloud WAF.

Our current web protection relies on a negative security model. In other words, we use signatures for known threats. We will eventually transition to a proactive security model Cloud WAF can accommodate where we deny everything by default and only allow specific things. 

We're currently vulnerable to zero-day attacks because we depend on known signatures. We're looking forward to shifting to a positive security model from the WAF we use in conjunction with the bot manager. Radware's intelligence about known bots is an extreme value add to us. 

The automated analysis of events is intuitive and user-friendly because we're not flooded with thousands and thousands of events. The analytics features provide a summary, so there's no need to look for something line by line. It's aggregated into a nice simplified event with the option to drill down for more details. 

We can investigate if we experience issues from a specific subset of customers. For example, we can search by ISP, URL, or IP address. Cloud WAF adds a lot of value by enabling us to pinpoint where we are experiencing an issue.

What needs improvement?

Our only complaint is the reporting on the DDoS side. We also use Radware for on-premises DDoS protection and their Vision product. I just want to paint you an example. We face so many Layer 3 and Layer 4 DDoS attacks on Cloud WAF. The reporting on those types of attacks can be improved.

For how long have I used the solution?

We started a pilot project in April 2022 and purchased Cloud WAF in November 2022.

What do I think about the stability of the solution?

Cloud WAF has been extremely stable. We only had one service interruption during our proof of concept, but it has been reliable since we went live. We've never needed to make a DNS entry change and redirect that web traffic back to our perimeter. 

In the beginning, we were constantly watching it, but we don't have to check on it now that we know it's working. 

What do I think about the scalability of the solution?

We haven't experienced any scalability issues because we requested all the throughput needed for our necessary applications or services from a bandwidth and billions of transactions per month. 

How are customer service and support?

I rate Radware support a ten out of ten. I'm pleased so far. Everything was new to us in the initial phases. We called or emailed them, and they helped us within five minutes. Now, we follow the standard process where we log a case ticket and get a response in ten minutes. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used on-premises security solutions, but we are moving to cloud-based applications. Radware has done such an excellent job with our perimeter and cloud DDoS services. They were the only ones who correctly identified our issue with these small low-bandwidth usage attacks coming that look legitimate to the existing web solution. We piloted the web and bot manager solutions, and we were astonished by the number of malicious bots accessing our website and how that impacts our KPIs.

How was the initial setup?

The WAF service runs on Radware's cloud. Their infrastructure is in a neutral co-location. Radware is able to offer the same protection for our on-prem equipment because it uses Nginx. Cloud WAF can protect on-prem systems plus AWS and Azure clouds.

The onboarding was quick. We finished within half an hour and moved some services onto the Cloud WAF within an hour. The beauty of the solution is that it requires no major changes on the customer side. You make a DNS entry change to point your website to the Radware hardware.

There is no maintenance on our side. We have a strict SLA with Radware that requires notification far in advance about maintenance on their end. They typically avoid maintenance at the end of the month, which is a busy period because people need to do banking. They also do not do maintenance during a year-end freeze. They only do maintenance on one location at a time, so if they take one down, we can continue working on the other. They have built that availability in South Africa.

What was our ROI?

We haven't seen a return on investment, but we expect to see that in the third year. If we set this up ourselves, we would need to pay for all the necessary appliances, hardware, VMs, and internal staff. Outsourcing to the Cloud WAF solution saved us capital expenses but increased our operational expenditures. We'll have some stats on the total cost of ownership by the end of the year. The time to spin up our own WAF service would be a lot longer than paying for Cloud WAF to protect our applications. 

What's my experience with pricing, setup cost, and licensing?

A yearly license worked out to be a lot cheaper than what other competitors offered for an on-prem solution. We negotiated with Radware and managed to strike a good deal. The company was accommodating to our particular needs as a financial institution. We had to test things for pre-production and spin-up because they charge per FQDN as a service or an application.

When it came to pre-production testing, they set it up for us with a minimal charge, so our QA and UA teams could do testing. We saw the value added from DDoS protection for Layer 3 and Layer 4 attacks. It includes API protection. We had to pay extra for bot managers, but the pricing is competitive overall.

If you plan to deploy Cloud WAF, keep in mind that the product is priced based on the megabits of traffic that pass through and the number of transactions. You should get your requirements correct up front. The active attackers feed and CDN services cost extra, so you need to negotiate these features up front. 

Which other solutions did I evaluate?

Another company had a similar service but didn't have a presence in South Africa. Radware has got two locations in the country, and that was a deciding factor. There were other financial institutions and retailers on the cloud, so it was easy to decide that we no longer wanted to do this on-premises. We decided that it was better to let Radware spin up and maintain the hardware.

What other advice do I have?

I rate Radware Cloud WAF a ten out of ten. 

No experts are required from our side, the onboarding is straightforward, maintenance is easy, and Radware's security operations enable us to stay agile. 

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Sharon-Levin - PeerSpot reviewer
Sharon-LevinCustomer Marketing Manager at a tech vendor with 1,001-5,000 employees
Top 20Real User

 Hi, Regarding the note concerning the pricing, please note that in 2023 our Cloud Application Protection services pricing model has been changed and simplified.

We now offer only three plans to choose from: Standard, Advanced, and Complete


Each plan is designed to cater to different cybersecurity needs and risk exposure, as well as different levels of managed services.


Please feel free to contact us to learn more

Buyer's Guide
Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros sharing their opinions.