We use Radware to protect our applications and the portals that we share with our clients and business partners.
Jefe de Infraestructura y Seguridad at a comms service provider with 51-200 employees
Detects and blocks threat behavior patterns, giving us automatic protection
Pros and Cons
- "One of the most valuable features we have found in the solution is protection against attacks from botnet networks and the requests that these remote networks can generate that are blocked from our servers. That frees us from having to deal with that traffic."
- "If we want to publish services to a limited number of providers and we only want those providers to connect, we need to forward those requests to the Radware support team and they apply them, but it takes some time."
What is our primary use case?
How has it helped my organization?
Among the improvements to our organization is that we are calmer regarding the use of the applications that we publish. Radware gives us a level of confidence that assures us that, if there is an attack, we have a tool that will protect us and that will block suspicious behavior.
Cloud WAF Service has also helped us reduce false positives. I don't have the exact data on how much they have decreased, but once we enter the portal we can see network connections that have an unknown IP and we can scan and block applications automatically from countries in which we do not have clients.
It has also helped save time for our IT team. We don't dedicate so much time to the threats, but we directly review the reports. We have saved about 30 percent in time invested.
What is most valuable?
One of the most valuable features we have found in the solution is protection against attacks from botnet networks and the requests that these remote networks can generate that are blocked from our servers. That frees us from having to deal with that traffic.
Cloud WAF Service has also been useful for us in terms of blocking threats because it automatically detects them, detects behavior patterns that have a threat pattern, and directly blocks them. Without making any changes or decisions, we automatically have protection.
Also, regarding the classification of events, the solution does productive work in detecting the logs where there could be threats to our applications, and that is quite useful.
What needs improvement?
We have had difficulties with the configuration of rules when it comes to allowing connections and having a list of IPs that are authorized to use a specific service. We have not been able to make a whitelist work.
For example, if we want to publish services to a limited number of providers and we only want those providers to connect, we need to forward those requests to the Radware support team and they apply them, but it takes some time. It seems to me that this long process would be faster if the configuration could exist directly in the portal. That would make things easier.
Buyer's Guide
Radware Cloud WAF Service
August 2026
Learn what your peers think about Radware Cloud WAF Service. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,069 professionals have used our research since 2012.
For how long have I used the solution?
We are in our third year of use of Radware Cloud WAF Service.
What do I think about the stability of the solution?
We have only had one network outage which happened a while ago. Fortunately, it was short and we were quickly back in business.
What do I think about the scalability of the solution?
We have plans to increase the use of Radware in our enterprise. There are a couple of applications that are going to be added.
How are customer service and support?
The technical support is very good.
Which solution did I use previously and why did I switch?
We did not have a previous solution. It was a fairly quick decision to go with Radware. It was chosen because Cisco offered a package of security solutions in which Radware was included.
How was the initial setup?
The initial setup was pretty easy. An engineer from Radware helped us. We scheduled a meeting, discussed the changes that we had to make internally at the DNS level, and that's it. The engineer who helped us was assigned by Radware and we had a pretty good experience with him. On our side it required two people, our system administrator and security analyst.
The programming process and our first use of the solution were quite successful. It was deployed with a set of default rules and policies in a short amount of time, and these gave a certain level of protection for our applications. When we started using it, we understood its features and potential.
In terms of maintenance, there are changes and revisions that need to be made from time to time, mainly to check for false positives. Generally, only one person participates in that process.
What was our ROI?
We have seen return on investment through the level of reliability of the application and the optimal stability that it gives to our users.
In terms of TCO, it has not been an expense. More than anything, it has been a beneficial service that has reduced TCO by approximately 70 percent.
What other advice do I have?
Radware Cloud WAF Service is a good option. It is a good tool that will definitely give you the protection you are looking for.
The most important lesson that Radware has taught me is that, as a service, it can relieve you of many application security tasks.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Executive Director at a financial services firm with 10,001+ employees
Provides the first level of defense and useful insights, but lookback, integration, and API Discovery need a lot of work
Pros and Cons
- "It provides the first level of defense against external threats trying to come into the environment, but it's one of the many toolkits we use."
- "There is a lot more that is expected from Radware's automated analytics for looking at events. There needs to be more context of where protection is required these days."
What is our primary use case?
We have external facing sites that our clients use, and it's important that those are protected. It's a traditional use case. The end-users are the firm clients trying to come into the firm using firm applications. So, this is the external perimeter, and that's the typical use case.
How has it helped my organization?
It gives you more insights into what may be happening in your environment. It doesn't free up people's time, but it helps them add an additional data point so that they can be better informed. In that sense, it improves efficiency. When you are in the security mindset, you want to make sure you have the ability to gain as many insights as possible for a potential attack. The intent is never around freeing up time.
What is most valuable?
It provides the first level of defense against external threats trying to come into the environment, but it's one of the many toolkits we use.
What needs improvement?
I'm the global head of cybersecurity across all business lines with a prime focus on audit risk and compliance. I look at Radware in terms of the ability to do two things. One is being very well aware of what's happening in the industry and the threat landscape, and the relative to that is the right sizing of the product so that the product can identify those emerging threats in time and then block them. That's essentially what I'm expecting Radware to do. The ability to provide some insights into lookback is equally important, which means you found something today but that doesn't mean that it happened today. It could have happened many moons ago. That lookback is equally important. There is a lot more that is expected from Radware's automated analytics for looking at events. There needs to be more context of where protection is required these days.
I have used the API Discovery feature. It's relatively easy to use, but it pales to some of the tools that currently exist in the marketplace. They may be a little more sophisticated than what Radware provides. A lot of work needs to be done out there for the end-to-end API protection offered by the API Discovery feature. It's a good first step, but Radware isn't there yet. Similarly, in terms of integrating with other systems and applications in our environment, a lot more work needs to be done out there.
The visibility of API relative to data flow and contextual understanding of what that is for a business is extremely important, and APIs don't seem to cut it. The majority of the attacks take place in memory, so you need to make sure that there is close alignment around how you view that and draw conclusions based on that data. Right-sizing is based on the industry because some of them have the same set of APIs and the same set of structures from which you can easily draw context and draw conclusions in terms of what's happening.
For how long have I used the solution?
We've been using it for two years. It came to us with an acquisition.
What do I think about the stability of the solution?
They've had one odd outage. You can't have an outage in that business. They got to get a little better for enterprise-grade.
How are customer service and support?
They have been collaborative. They were eager to have the firm's business, so we received the kind of support we wanted, and that's fair. We have no complaints, and there is nothing that stands out of the ordinary. I'd rate them a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
In an organization of our size, you don't have one single vendor. It's a layered defense model. You don't have one single product that you're heavily reliant on. From that perspective, Radware is a part of the ecosystem.
In terms of blocking unknown threats and attacks, Radware is at par with other firms. There is nothing extraordinary. The protection it provides is comparable. It isn't superior. It's amongst the top three or four, but it's definitely not number one.
How was the initial setup?
It required tuning to meet our requirements, but that's true for all products.
What about the implementation team?
It was implemented in-house. There were four people involved in its implementation.
What was our ROI?
The value proposition of a product is based on not just one feature set. It's based on the suite of features and the impact. It's no different than the value of a security guard outside the building. It's justified in case you have a major attack and it has been able to thwart that attack, but up until that point, you won't be able to say, "Hey, what is the true value that I'm getting out of this?"
What other advice do I have?
When you're getting this or any other solution, you need to look at three things.
- Is it fit for purpose? What are you getting it for, or does the solution meet the need?
- Is it going to add value and be a strategic partner going forward? Do you see it evolving with where the threat landscape is heading and where the market is heading? Do you see a relationship?
- Do they get it right? Are they aligned or in sync with the industry and with what the regulators are looking at? This one is generally missing in this case.
I've used CDN services offered by Radware in conjunction with Cloud WAF. Radware is in the same ballpark compared to the industry leaders, though some of the industry leaders are a little sophisticated in terms of features and offerings. However, there are certain areas towards which the industry isn't evolving, and Radware can obviously position itself so that it can succeed.
Overall, I'd rate Radware Cloud WAF Service a seven out of ten. There is a lot they can do. They're in a good position. They have their foot in the door. They need to just up their game.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Web Application Firewall (WAF)Popular Comparisons
Prisma Cloud by Palo Alto Networks
Cloudflare Web Application Firewall
Imperva Application Security Platform
Fortinet FortiWeb
Azure Front Door
Akamai App and API Protector
Check Point WAF (formerly CloudGuard WAF)
F5 Advanced WAF
Microsoft Azure Application Gateway
Aikido Security
F5 Distributed Cloud Services
Radware Alteon
Buyer's Guide
Download our free Radware Cloud WAF Service Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which lesser known firewall product has the best chance at unseating the market leaders?
- Which WAF solution would you recommend to cater to 100 to 125 concurrent sessions?
- What do you recommend for a securing Web Application?
- Fortinet vs Sophos? Help choose a NGFW solution that can replace Microsoft TMG.
- Imperva WAF vs. Barracuda: Which One is Better?
- F5 vs. Imperva WAF?
- When should companies use SSL Inspection?
- How does a WAF help to protect against DDoS attacks?
- NGFW with URL Filtering vs Web Proxy
- What's right for me? Fortinet or Citrix?














