Introducing G2.ai, the future of software buying.Try now
Product Avatar Image
AWS WAF

By Amazon Web Services (AWS)

Unclaimed Profile

Claim your company’s G2 profile

Claiming this profile confirms that you work at AWS WAF and allows you to manage how it appears on G2.

    Once approved, you can:

  • Update your company and product details

  • Boost your brand's visibility on G2, search and LLMs

  • Access insights on visitors and competitors

  • Respond to customer reviews

  • We’ll verify your work email before granting access.

Claim Now
4.3 out of 5 stars

How would you rate your experience with AWS WAF?

It's been two months since this profile received a new review
Leave a Review

AWS WAF Reviews & Product Details

Value at a Glance

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

9 months

AWS WAF Integrations

(5)
Integration information sourced from real user reviews.
Product Avatar Image

Have you used AWS WAF before?

Answer a few questions to help the AWS WAF community

AWS WAF Reviews (68)

Reviews

AWS WAF Reviews (68)

4.3
68 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Luca P.
LP
✅ CTO - Growth Marketer full stack #MarTech | ⚡️ SaaS Advisor
Marketing and Advertising
Small-Business (50 or fewer emp.)
"Web Application Firewall inside AWS ecosystem"
What do you like best about AWS WAF?

The most practical aspect of AWS WAF is its native integration with the AWS ecosystem. The connection with CloudFront, Application Load Balancers, API Gateway, and AppSync creates a unified security layer without managing separate security tools or dealing with compatibility issues.

AWS Managed Rules handle OWASP Top 10 vulnerabilities, SQL injection, XSS, and bot traffic without writing and maintaining custom signatures. The Application Layer DDoS protection with automated mitigation actions provides protection against layer 7 attacks with detection times measured in seconds.

The bot control managed rule group mitigates persistent bot traffic, while fraud control offers account takeover and account creation fraud prevention. These features integrate with existing application workflows and provide visibility into attack patterns.

You can set thresholds based on source IP addresses, HTTP headers, or custom keys, and the five-minute aggregation window balances responsiveness with avoiding false positives. Combining rate limiting with geographic restrictions and IP reputation filtering creates layered protection.

Great Cloudwatch integration! Detailed metrics on blocked requests, allowed traffic, and rule performance. The AntiDDoS dashboard provides visibility into DDoS events with granular metrics for different mitigation actions. Sending filtered logs to OpenSearch for custom alerting supports proactive threat response. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

You cannot block specific regions within countries or implement more granular geographic filtering based on threat intelligence. This limitation affects applications that need precise geographic access controls. Review collected by and hosted on G2.com.

Pradeep R.
PR
Software Developer
Computer Software
Small-Business (50 or fewer emp.)
"Simple Yet Powerful Web Protection with AWS WAF"
What do you like best about AWS WAF?

I like that AWS WAF makes it easy to protect websites from common attacks like SQL injection and XSS without much manual setup. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

It can be a bit complex to configure at first, and the pricing can get confusing for beginners. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Small-Business (50 or fewer emp.)
"AWS WAF - Reliable Web Application Firewall"
What do you like best about AWS WAF?

1) AWS WAF is very easy to deploy and requires no additional software installation, DNS, config, or SSL/TLS certifications management.

2) We can able to create customer rules for specific needs. These rules can be based on IP addresses, UPL strings, or even HTTP body content.

3) AWS WAF provides a strong defense mechanism against SQL injection, cross-site scripting, and DDoS attacks.

4) Developers can automate rule creation and deployment using AWS APIs or cloud formation templates, streamlining security management during application development and reducing manual effort.

5) Since it offers pay-as-you-go pricing based on traffic and rules leading to variable cost. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

While AWS has more features, it can be complex to configure initially for users unfamiliar with firewall systems or automation.

Compared to other WAF scale vertically within AWS resources ecosystem. Review collected by and hosted on G2.com.

Igor Z.
IZ
Senior DevOps Manager
Small-Business (50 or fewer emp.)
"Good Firewall Service"
What do you like best about AWS WAF?

The simplicity of configuration and management Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

I actually does not have anything I don't like Review collected by and hosted on G2.com.

Hiran T.
HT
SOC Analyst
Information Technology and Services
Mid-Market (51-1000 emp.)
"Protect a web applications from common cyber attacks."
What do you like best about AWS WAF?

AWS WAF protects web applications from common web exploities. The user can create a policy and take control over the block and filters. AWS WAF can easily be integrated and managed by the Amazon firewall manager and can be easily implemented in the Amazon cloud platform. The user can monitor and frequently analyze the incoming network traffic. Customer support is very responsive and satisfactory which help the user to fix issues in less time. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

The pricing of AWS WAF is based on the components like Web ACL, Rule, Bot control and fraud Control. which make a user to pay part by part which is bit annoying. Review collected by and hosted on G2.com.

Ajay S N.
AN
Junior Devops Engineer
Small-Business (50 or fewer emp.)
"WAF for Additional Security"
What do you like best about AWS WAF?

WAF can provide different levels of security. We will be able to implement it in the root level. We can make rules to allow or block access that meets conditions. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

Initially it was too tough for me to tackle WAF as the concepts are bit complex to understand. Review collected by and hosted on G2.com.

mugdha S.
MS
Senior Consultant
Enterprise (> 1000 emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Mitigate Ddos attacks"
What do you like best about AWS WAF?

AWS waf comes with best set of Rules for filtering out the malicious IP's. It is very easy to implement as we can create the rules using AWS rules. Also , we can create large number of rules according to the priority . It is great platform to integate with load balancers etc. I liked how the customer support is avalialble 27 7 for any issues. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

Cost can be addded when we set up more rules Review collected by and hosted on G2.com.

Khushboo R.
KR
Accounts Receivable Associate
Marketing and Advertising
Mid-Market (51-1000 emp.)
"AWS WAF won't comprise on the Security"
What do you like best about AWS WAF?

The most helpful aspects and upsides of using AWS WAF are:

1.Security enchancement - AWS WAF helps in enchancing the security of your web applications by protecting them from a wide range of online threats, such as SQL injection, cross-site scripting(XSS) and more.

2.Customizable Rules: AWS WAF offers a high degree of customization, allowing you to creates rules and regulations tailored to your specific application's needs.

3.Scalability: AWS WAF scales with your's applications needs. you can handle varying level of traffic and adjust your rules and policies accordingly. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

While AWS WAF offers many benefits, there are also some potentials downsides of using AWS WAF, which are states below:

1.Costs: While the AWS WAF offers pay-as-you go pricing model, cost can add up, especially for large scale application with high traffic volumes and complex rules sets.

2.Regional Deployment:AWS WAF is deployed regionally, which means you need to configure it separately in each AWS Region where application is hosted. this can add up complexity if your application spans multiple regions. Review collected by and hosted on G2.com.

Srinivas P.
SP
Engineering Manager
Small-Business (50 or fewer emp.)
"Best Firewall service for AWS resources with easy integration"
What do you like best about AWS WAF?

- Easy integration setup for AWS cloudfront and load balancers

- Bot traffic and maliciuos requests can be easily blocked

- AWS Managed rules provides a quick start to secure requests

- Allows to customize response when requests are blocked

- Has a Count feature which allows to validate requests before enabling action on the rule Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

- Multiple rule setup and priority leads to complications

- Costs can add up as it proportional to the request count Review collected by and hosted on G2.com.

Prashant G.
PG
Cloud Network Security
Information Technology and Services
Enterprise (> 1000 emp.)
"AWS WAF needs more improvement"
What do you like best about AWS WAF?

AWS native WAF can be easily integrated with Application Load Balancer with which we can allow Internet bound Inbound traffic directly on ALB. Same ALB can be protected by AWS Shield, with this we can achieve DDoS L3, L4 & L7 protection. Also AWS WAF supports third party vendor managed rules i.e. F5, Imperva etc to add in WEB ACL Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

AWS managed WAF rules has limitations of protecting against OWASP top 10 attack pattern i.e. if you change SQL injection attack pattern, AWS Managed WAF rules failed to block it. AWS needs to work on such sort of things. Review collected by and hosted on G2.com.

Pricing Insights

Averages based on real user reviews.

Time to Implement

2 months

Return on Investment

9 months

Average Discount

7%

AWS WAF Comparisons
Product Avatar Image
Palo Alto Networks Next-Generation Firewalls
Compare Now
Product Avatar Image
Netgate pfSense
Compare Now
Product Avatar Image
ModSecurity
Compare Now
AWS WAF Features
Logging and Reporting
Issue Tracking
Security Monitoring
Application-Layer Controls
Traffic Controls
Network Controls
API / Integrations
Extensibility
AI Text Summarization
Product Avatar Image
AWS WAF
View Alternatives