Check Point WAF (formerly CloudGuard WAF) Reviews (87)

Reviews

Check Point WAF (formerly CloudGuard WAF) Reviews (87)

4.3
87 reviews

What do users say?

Generated using AI from real user reviews
Users consistently praise the strong protection and ease of management offered by Check Point WAF, highlighting its effective defense against web application attacks and automated threat detection capabilities. Many appreciate its seamless integration with cloud environments, although the initial setup can be complex for new users, requiring time to fully understand the interface and configuration options.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Samiksha C.
SC
Samiksha C.
Security operations
Small-Business (50 or fewer emp.)
"Complex Setup, but Strong Security Features"
4.5/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

I feel Check Point WAF is very basic but it does its job well in protecting the organization. It definitely helps when an employee is clicking on a suspicious link, like, preventing phishing attacks. I appreciate that it logs everything so that the SOC team stays aware. The feature I love the most is the firewall policy management and log monitoring via the smart console. I regularly work on analyzing the logs to investigate issues and validate security alerts. I also use the threat prevention features like IPS and antivirus to understand patterns and tune rules. Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

I feel the setup is very complex and quite lengthy. It also has a high cost, and the performance impact is a bit lagging. It increases latency, reduces throughput, and needs proper sizing and tuning. I request the Check Point team to hopefully make the process easier. Review collected by and hosted on G2.com.

Milan D.
MD
Milan D.
Consultant
Small-Business (50 or fewer emp.)
"Solid WAF Protection With a Learning Curve"
4/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

What I like best is the contextual AI engine that detects threats without relying on constant signature updates. It dramatically cut down our false positives compared to our previous signature-based WAF, which means less time spent tuning rules and chasing noise. Deployment across our cloud environments was straightforward, and the automatic learning of application behavior means new apps get protected without a ton of manual configuration. The unified management through the Infinity portal is also a big plus for us since we can see everything in one place. Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

The initial setup and configuration felt more complex than expected, and the learning curve for tuning rules to reduce false positives was steep. Documentation could be more thorough in places, and support response times occasionally lagged when we ran into urgent issues. Pricing also feels on the higher side compared to some alternatives, especially as you scale traffic. Better dashboards and more intuitive policy management would go a long way Review collected by and hosted on G2.com.

Ayodeji A.
AA
Ayodeji A.
Cybersecurity Home Lab & Security Projects
Small-Business (50 or fewer emp.)
"Strong, Easy-to-Manage Web App Protection with Smart Automation"
5/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

I like Check Point WAF because it provides strong protection against web application attacks while being easy to deploy and manage. Its automated policy generation, AI-driven threat detection, and low false positive rate reduce administrative effort without compromising security. I also appreciate its support for cloud environments, API protection, and centralised management, making it a reliable solution for securing modern web applications. Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

One area that could be improved is making the platform even more intuitive for new users, especially when configuring advanced security policies. However, the available documentation and automation features help reduce the learning curve, and overall the solution provides strong security capabilities and flexibility. Review collected by and hosted on G2.com.

Ijlal K.
IK
Ijlal K.
Machine Learning & Software Engineer
Small-Business (50 or fewer emp.)
"Good protection and easy to manage web security"
5/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

I like that Check Point WAF is easy to use and gives good protection without needing too much manual work all the time. It helps to block common web attacks and gives clear visibility about what is happening. The managed rules are also useful, and it is good that we can still adjust things when needed. Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

One thing I dislike is that sometimes the setup and tuning can feel a bit complicated, especially in the start. Some alerts or rules need extra checking to avoid false positives, and it can take time to understand why something was blocked. The interface is good overall, but few parts could be more simple and easier to follow. Review collected by and hosted on G2.com.

Ashith S.
AS
Ashith S.
DevOps Intern
Small-Business (50 or fewer emp.)
"Strong Web Traffic Visibility, But a Steep Learning Curve"
3/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

What I like most about Check Point WAF is its clear visibility into web traffic and blocked requests. It makes it easy to identify suspicious activity and fine-tune security policies. Once configured, it provides reliable protection with minimal day-to-day effort. Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

The biggest drawback is the learning curve, especially for first-time users. The interface can feel crowded, and fine-tuning policiesThe initial setup and policy tuning can be time-consuming, especially if you're new to WAFs. The interface isn't always intuitive, and some configuration options require extra effort to understand. takes time to avoid false positives. Some configuration tasks could also be more intuitive. Review collected by and hosted on G2.com.

Hazem H.
HH
Hazem H.
Cyber Security Trainee Network Security Trainee Self Learning – Cyber & Network Security
Mid-Market (51-1000 emp.)
"Strong Protection with Room for Onboarding Improvement"
4.5/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

I use Check Point WAF to protect web applications and APIs from a wide range of cyber threats like SQL injection and cross-site scripting (XSS). What I like most about Check Point WAF is its ability to provide strong, automated protection for web applications while remaining easy to manage on a day-to-day basis. The platform effectively detects and blocks traffic. The initial setup of Check Point WAF was relatively straightforward, especially with the available documentation and guided configuration options. It provides strong protection against modern web application threats and offers good visibility through a centralized management interface. Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

One challenge is the initial onboarding and policy tuning process. For organizations with complex or highly customized web applications, achieving the right balance between strong protection and minimizing false positives can require additional time and expertise. Review collected by and hosted on G2.com.

UTSAV A.
UA
UTSAV A.
Network Lead
Mid-Market (51-1000 emp.)
"Intuitive and Secure Firewall Solution"
4.5/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

I find Check Point WAF very easy to use. Even if someone is new to firewall stuff, they can handle it effectively with some guidance on using its GUI. The setup is also quite straightforward; you can set it up in five to ten minutes using the GUI interface, which is quite comfortable for first-timers. Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

As of now, I've used many firewalls, and while Check Point WAF's interface is good, I feel it could be improved a little bit. Compared to Fortinet, their GUI interface is slightly better than Check Point's. That's pretty much the only thing I would say needs improvement, although Check Point does have very good features compared to Palo Alto and ForteGate. Review collected by and hosted on G2.com.

Merin K O.
MO
Merin K O.
Core Team Member (Cybersecurity)
Small-Business (50 or fewer emp.)
"Powerful Security with a Complex Setup"
4.5/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

I use Check Point WAF to protect our internet-facing web application and APIs from web-based threats like SQL injection and cross-domain issues. The solution provides advanced threat prevention and automated policy cleaning. I appreciate the traffic inspection and reverse migration capabilities that ensure application availability and maintain security compliance. It supports both community and hybrid environments. We also integrate it with our broader security ecosystem, which helps in monitoring and provides better visibility for threat detection. Cloud integration capabilities have simplified development, providing better visibility to application networks and stronger protection against top vulnerabilities. Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

While Check Point WAF provides strong application security and configuration capabilities, there are some areas that could be improved. The initial set of policy tuning process can be complex for new administrators, requiring a good understanding of web application traffic patterns. The interface could be more user-friendly, and the reporting and dashboard customization options could be enhanced to provide more actionable insights. Additionally, licensing can be challenging for smaller organizations, I assume. Faster deployment templates for cloud-native applications would further simplify the implementation. Review collected by and hosted on G2.com.

Nijat I.
NI
Nijat I.
Full-stack Developer
Information Technology and Services
Small-Business (50 or fewer emp.)
"Excellent Traffic Insights for Securing Web Apps and APIs"
4.5/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

Check Point WAF was mostly used for monitoring and securing internet-facing applications and APIs receiving traffic from outside clients. The majority of daily operations entailed examining rejected requests, analyzing security events post-deployment, and tuning protection rules in case legitimate traffic was impacted.

The main asset in terms of operational activities was insight provided at the HTTP and API level. This allowed for examination of request patterns, header details, path and URL parameters and, if needed, the actual contents of blocked requests, rather than looking at basic network data. It made things more clear whether strange behavior was caused by legitimate application operation, automated scanning, or attack attempts against available services.

Post-updates policy tuning was done occasionally because even minor front-end or API changes were affecting some protection settings. Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

The tuning phase can be a lengthy one due to traffic fluctuations or custom APIs. Initially, I had to spend quite some time ensuring that blocked calls were indeed malicious or a result of the application's normal activity misinterpreted as something else.

Additionally, there is a need for constant tuning when dealing with multiple applications as well as keeping a balance between tight protection and not interrupting the production traffic.

Only after acquiring a good understanding of how signature definitions, exceptions, and policies worked internally did troubleshooting become easier. Review collected by and hosted on G2.com.

Luciano P.
LP
Luciano P.
Cybersecurity Analyst
Mid-Market (51-1000 emp.)
"Strong OWASP Protection and AI-Driven Threat Prevention That Scales"
5/5
What do you like best about Check Point WAF (formerly CloudGuard WAF)?

Strong protection against OWASP Top 10 attacks

Easy integration with cloud environments

Good real-time threat prevention and bot protection

Centralized management and visibility

AI-driven threat intelligence from Check Point

Scalable for enterprise workloads

Helpful automation and policy tuning feature Review collected by and hosted on G2.com.

What do you dislike about Check Point WAF (formerly CloudGuard WAF)?

Initial setup can be complex

Can be expensive for smaller companies

Some advanced configurations require expertise

Dashboard/UI can feel overwhelming at first

Occasional false positives that need tuning

Support response time may vary depending on the plan Review collected by and hosted on G2.com.