AWS WAF Reviews (72)

Reviews

AWS WAF Reviews (72)

4.3
72 reviews

What do users say?

Generated using AI from real user reviews
Users consistently praise the ease of use and integration with AWS services of AWS WAF, highlighting its ability to protect web applications from common threats like SQL injection and DDoS attacks without extensive setup. Many appreciate the customizable rules that allow tailored security measures, although some note that initial configuration can be complex and pricing may become high with increased usage.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Atharva P.
AP
Atharva P.
Cloud BI Engineer
Enterprise (> 1000 emp.)
"Strong Web App Protection with AWS WAF’s Managed Rules and Seamless AWS Integrations"
4.5/5
What do you like best about AWS WAF?

What I like most about AWS WAF is that it helps protect web applications from common threats without requiring dedicated security appliances or complicated infrastructure. Features such as managed rule sets, custom rules, IP filtering, and bot protection make it easier to secure applications while still maintaining performance.

Its integration with CloudFront, Application Load Balancers, and API Gateway is especially valuable because it lets me apply security controls consistently across multiple application entry points. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

False positives can sometimes happen, especially when aggressive security rules end up blocking legitimate traffic. To maintain a good balance between strong security and a smooth user experience, ongoing rule tuning and regular monitoring are necessary. Review collected by and hosted on G2.com.

YG
Yogesh G.
Linux Administrator
Information Technology and Services
Small-Business (50 or fewer emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Strong Threat Protection with Easy Log Monitoring and Centralized Management"
4.5/5
What do you like best about AWS WAF?

It protects against threats and hackers, and it lets us manage internet traffic according to our organization’s policy. It’s also easy to monitor the logs. There’s a large community and well-maintained documentation, plus support for centralized management. Customer support has been good as well. It provides a rich feature set for targeted protection, the ability to configure Web ACLs, and managing rule sets. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

None, since the tool does deliver on the capabilities and features described in their whitepapers. That said, the pricing model is opaque, and we’ve been caught off guard by scaling costs before. Review collected by and hosted on G2.com.

Ravi R.
RR
Ravi R.
DevOps Engineer
Health, Wellness and Fitness
Mid-Market (51-1000 emp.)
"Easy AWS Integration with Powerful Managed Rules"
4/5
What do you like best about AWS WAF?

Aws integration - easy integration with aws services like api gateway , CloudFront and load balancers.

UI is good

Easy setup

Managed rules

IP based protection/rule, gro-location, rate based limiting, headers inspection.

Performance is good but need to be improve. Inbuilt Also AI related features and services added. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

Its cost is slightly expensive.

Its rules- rule order management is confusing

No.AI support Review collected by and hosted on G2.com.

Nidal S.
NS
Nidal S.
Senior DevOps Engineer
Mid-Market (51-1000 emp.)
"Flexible, Fast AWS Integration with Powerful Security Controls"
4.5/5
What do you like best about AWS WAF?

Its flexibility and fast integration with AWS services like CloudFront and ALB. It allows adding security controls such as rate limiting and IP blocking without changing the application itself. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

It is not very transparent during detections and tuning, and it still misses some attack patterns unless rules are carefully customized and monitored continuously. Review collected by and hosted on G2.com.

Verified User in Retail
AR
Verified User in Retail
Enterprise (> 1000 emp.)
"AWS WAF: Scalable Native Security with a "Pay-as-you-Go" Complexity Tax"
5/5
What do you like best about AWS WAF?

Its native integration with CloudFront and ALB eliminates external latency while offering instant protection via Amazon-managed rules against OWASP threats. The pay-as-you-go model makes it accessible for any scale, allowing you to secure your infrastructure without upfront contracts. It is the ultimate "set and forget" solution for the AWS ecosystem. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

Inspection & Capacity: Its strict 64 KB body inspection limit and 5,000 WCU cap can leave larger payloads unmonitored or force you to compromise on security depth.

Cost & Complexity: Native dashboards are basic, requiring paid CloudWatch/S3 logging and manual Athena queries just to visualize and tune frequent false positives. Review collected by and hosted on G2.com.

Luca P.
LP
Luca P.
Chief Operations Officer DEQUA Studio | Formerly CTO in MarTech
Marketing and Advertising
Small-Business (50 or fewer emp.)
"Web Application Firewall inside AWS ecosystem"
4.5/5
What do you like best about AWS WAF?

The most practical aspect of AWS WAF is its native integration with the AWS ecosystem. The connection with CloudFront, Application Load Balancers, API Gateway, and AppSync creates a unified security layer without managing separate security tools or dealing with compatibility issues.

AWS Managed Rules handle OWASP Top 10 vulnerabilities, SQL injection, XSS, and bot traffic without writing and maintaining custom signatures. The Application Layer DDoS protection with automated mitigation actions provides protection against layer 7 attacks with detection times measured in seconds.

The bot control managed rule group mitigates persistent bot traffic, while fraud control offers account takeover and account creation fraud prevention. These features integrate with existing application workflows and provide visibility into attack patterns.

You can set thresholds based on source IP addresses, HTTP headers, or custom keys, and the five-minute aggregation window balances responsiveness with avoiding false positives. Combining rate limiting with geographic restrictions and IP reputation filtering creates layered protection.

Great Cloudwatch integration! Detailed metrics on blocked requests, allowed traffic, and rule performance. The AntiDDoS dashboard provides visibility into DDoS events with granular metrics for different mitigation actions. Sending filtered logs to OpenSearch for custom alerting supports proactive threat response. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

You cannot block specific regions within countries or implement more granular geographic filtering based on threat intelligence. This limitation affects applications that need precise geographic access controls. Review collected by and hosted on G2.com.

Pradeep R.
PR
Pradeep R.
Software Developer
Computer Software
Small-Business (50 or fewer emp.)
"Simple Yet Powerful Web Protection with AWS WAF"
4/5
What do you like best about AWS WAF?

I like that AWS WAF makes it easy to protect websites from common attacks like SQL injection and XSS without much manual setup. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

It can be a bit complex to configure at first, and the pricing can get confusing for beginners. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
UI
Verified User in Information Technology and Services
Small-Business (50 or fewer emp.)
"AWS WAF - Reliable Web Application Firewall"
4.5/5
What do you like best about AWS WAF?

1) AWS WAF is very easy to deploy and requires no additional software installation, DNS, config, or SSL/TLS certifications management.

2) We can able to create customer rules for specific needs. These rules can be based on IP addresses, UPL strings, or even HTTP body content.

3) AWS WAF provides a strong defense mechanism against SQL injection, cross-site scripting, and DDoS attacks.

4) Developers can automate rule creation and deployment using AWS APIs or cloud formation templates, streamlining security management during application development and reducing manual effort.

5) Since it offers pay-as-you-go pricing based on traffic and rules leading to variable cost. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

While AWS has more features, it can be complex to configure initially for users unfamiliar with firewall systems or automation.

Compared to other WAF scale vertically within AWS resources ecosystem. Review collected by and hosted on G2.com.

Igor Z.
IZ
Igor Z.
Senior DevOps Manager
Small-Business (50 or fewer emp.)
"Good Firewall Service"
5/5
What do you like best about AWS WAF?

The simplicity of configuration and management Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

I actually does not have anything I don't like Review collected by and hosted on G2.com.

Hiran T.
HT
Hiran T.
SOC Analyst
Information Technology and Services
Mid-Market (51-1000 emp.)
"Protect a web applications from common cyber attacks."
4/5
What do you like best about AWS WAF?

AWS WAF protects web applications from common web exploities. The user can create a policy and take control over the block and filters. AWS WAF can easily be integrated and managed by the Amazon firewall manager and can be easily implemented in the Amazon cloud platform. The user can monitor and frequently analyze the incoming network traffic. Customer support is very responsive and satisfactory which help the user to fix issues in less time. Review collected by and hosted on G2.com.

What do you dislike about AWS WAF?

The pricing of AWS WAF is based on the components like Web ACL, Rule, Bot control and fraud Control. which make a user to pay part by part which is bit annoying. Review collected by and hosted on G2.com.